April 26, 2012 Disaster Recovery/Business Continuity - Resilient
Infrastructure Info
May 10, 2012 IT Leadership Strategies Info
May 31, 2012 Desktop Virtualization Strategies Info
June 14, 2012 BI/Big
Data/Analytics Info
June 21, 2012 Enterprise IT Risk/Security Management Info
July 12, 2012 IT Infrastructure, Operations & Management Info
Sep 6, 2012
Disaster Recovery/Business Continuity - Resilient Infrastructure Info
Sep 24, 2012
Cloud Computing Strategies Info
Oct 9-10, 2012
IT Portfolio Management
Info
Oct 18, 2012 Enterprise Mobility Strategies Info
Oct 25, 2012 Desktop Virtualization Strategies Info
Nov 6, 2012 IT Leadership Strategies Info
Nov 29, 2012
Disaster Recovery/Business Continuity - Data Protection Info
Dec 13, 2012 BI/Big
Data/Analytics Info
(Click here to add any of our upcoming
events to your calendar)
Upcoming Targeted IT Conferences
Upcoming 2012 Targeted IT Conferences
April 12, 2012 -
Thursday
Rosemont (O'Hare), IL |
Enterprise
Mobility Strategies
Strategies to help solve today's current mobility challenges |
April 26, 2012 -
Thursday
Rosemont (O'Hare), IL |
Disaster Recovery/Business Continuity – Resilient
Infrastructure
Strategies to help design,
implement and manage disaster recovery and business
continuity framework to protect your organization's core IT
assets, people, and processes |
May 10, 2012 -
Thursday
Rosemont (O'Hare), IL |
IT
Leadership Strategies
Strategies and techniques for
leading and guiding IT through a business approach during
dynamic times |
May 31, 2012 -
Thursday
Rosemont (O'Hare), IL |
Desktop Virtualization Strategies
Strategies to help the business
and IT benefit from virtualization strategies through
effective management, security, and recovery techniques |
June 14, 2012 -
Thursday
Rosemont (O'Hare), IL |
Business
Intelligence/Big Data/Analytics
Strategies to help leverage
full value from your design and implementation of an
effective Business Intelligence framework |
June 21, 2012 -
Thursday
Rosemont (O'Hare), IL |
Enterprise IT Risk/Security Management
Strategies for adopting a
comprehensive IT GRC (Governance/Risk Management/Compliance)
approach to managing information adhering to business needs |
July 12, 2012 -
Thursday
Rosemont (O'Hare), IL |
IT
Infrastructure, Operations & Management
Strategies to help IT best align operations and
infrastructure management to business needs |
Sep 6, 2012 -
Thursday
Rosemont (O'Hare), IL |
Disaster Recovery/Business Continuity – Resilient
Infrastructure
Strategies to help design, implement
and manage disaster recovery and business continuity
framework to protect your organization's core IT assets,
people, and processes |
Sep 24, 2012 -
Monday
Rosemont (O'Hare), IL |
Cloud
Computing Strategies
Strategies for determining how
and if moving to the cloud will benefit your organization |
Oct 9-10, 2012 -
Tuesday, Wednesday
Rosemont (O'Hare), IL |
IT
Portfolio Management
Strategies to help IT best
align, prioritize and manage projects according to business
needs |
Oct 18, 2012 -
Thursday
Rosemont (O'Hare), IL |
Enterprise
Mobility Strategies
Strategies to help solve today's current mobility challenges |
Oct 25, 2012 -
Thursday
Rosemont (O'Hare), IL |
Desktop Virtualization Strategies
Strategies to help the business
and IT benefit from virtualization strategies through
effective management, security, and recovery techniques |
Nov 6, 2012 -
Tuesday
Rosemont (O'Hare), IL |
IT
Leadership Strategies
Strategies and techniques for
leading and guiding IT through a business approach during
dynamic times |
Nov 29, 2012 -
Thursday
Rosemont (O'Hare), IL |
Disaster Recovery/Business Continuity
-
Data Protection
Strategies to help protect and
recover your organization's most critical data |
Dec 13, 2012 -
Thursday
Rosemont (O'Hare), IL |
Business
Intelligence/Big Data/Analytics
Strategies to help leverage
full value from your design and implementation of an
effective Business Intelligence framework |
General Information
Are you an IT professional interested in speaking? Call us at
1-312-527-2800 or
click here.
To be added to the CAMP IT Conferences mailing list,
click here.
To contact CAMP IT Conferences,
click here.
Directions
Lodging Information
(The Hyatt Regency O'Hare, Sofitel O'Hare, Double Tree O'Hare,
Embassy Suites Chicago O'Hare and the Crowne Plaza O'Hare are all on
River Road across the street from the conference location.
Village of Rosemont website
CAMP IT Conferences events are held at the Donald E. Stephens
Convention Center in Rosemont, Illinois. The center is located 2
miles east of the main terminal at O'Hare Airport. The CTA Blue Line
"L" train, that runs from downtown Chicago to O'Hare Airport, stops
in Rosemont about three blocks north of the Convention Center. The
center is one mile from Interstates 294, I-90 and the the Kennedy
Expressway.
|
Home
| Attending
| Speaking |
Sponsoring
|
About
| Contact
Conferences
that solve current IT challenges
 |
|
Web Application Security
Strategies & Tactics for Improving Web Application Security
March 28, 2006
9:00 a.m. to 5:00 p.m.
Stephens Convention Center
Rosemont (O'Hare) Illinois
|
|
Overview |
|
As enterprises are capitalizing on the web to
grow their respective businesses, they must be
aware of the security vulnerabilities that exist
when designing their web applications. This one
day conference will provide IT departments with
strategies and tactics to identify and eliminate
critical vulnerabilities in their web
applications.
Conference Program
8:00 am - 9:00
am - Registration and Continental
Breakfast
9:00 am - 10:00 am
Understanding the Top 10 Web Application
Attacks. Are You a Victim?
Danny Allan, Security Analyst, Watchfire
The OWASP (Open Web Application Security
Project) Top Ten was created to help
organizations and government agencies
focus on the most serious web
application security vulnerabilities.
Adopting a process to monitor for,
identify and remediate these “Top Ten”
flaws is perhaps the most effective
first step towards ensuring the security
of your web applications. Are you at
risk for an attack? Find out now!
10:00 am - 10:30 am -
Refreshment Break
10:30 am - 11:30 am
Designing a Framework for
Effectively Securing
Enterprise Web Applications
Gary Alterson, Security Risk
Management, Corp-Sec Project
To effectively combat
against web application
security threats and
attacks, organizations need
to have a well formulated
plan in place. The
framework should be designed
to incorporate the
following:
*
Application Architecture
- Multiple services must
act securely together so
that there is no single
point of failure.
*
Application Complexity -
When application
functionality broadens
the risk & probability
increases that more bugs
exist.
*
Manipulation of Data -
The collection and
presentation of data
must be managed properly
to meet legal, privacy
and financial
regulations and
guidelines.
*
Application Deployment -
The application and its
environment must be
secured. A
vulnerability in a web
server negates security
implemented in the
application.
* Application
Security
Requirements -
Properly engineered
and clearly stated
security
requirements form
the basis for
designing
appropriately secure
systems.
* SDLC Integration -
Integrating security
into the regular SDLC lifecyle embeds
controls where they
are most effective -
within applications
themselves.
During this presentation you
will learn how the
components fit together and
how you can overcome many of
the challenges inherent in
securing your organization’s
web applications
11:30 am - 12:30 am
Assessing the Vulnerabilities: How to
Effectively Use Application Penetration
Testing
Ambarish Malpani, CTO and VP of
Engineering, Cenzic
|

Malpani |
Application Penetration Testing can be very
effective at identifying and validating the
security risks in your web applications.
Since these web applications are usually vital to the organization’s core business,
it is essential that organizations go beyond
just vulnerability scanning and testing and
focus on how your system can handle
unexpected situations. This presentation
will show attendees how to use application
penetrating testing to accomplish the
following:
* Get actionable data to quickly address
security holes
* Protect information and critical business
assets against data theft and hacking
* How to develop proactive protection
measures through receipt of updated
vulnerability information
* How to validate that your security
procedures are up-to-date
12:30 pm - 1:30 pm - Luncheon
1:30 pm - 2:30 pm
Extending Web Application Security
Beyond the Application
Jason
Wilcox, Security Practice Lead, Yash
Technologies
Web Application security extends far
beyond the application itself.
Everything surrounding the application
such as authentication processes, user
management, password management, Single
Sign On solutions and Federating access
to an application are all points of
attack and potential weaknesses in your
applications security. Identity and
Access Management can no longer be
treated as separate entities in today’s
enterprise, and must be integrated from
the beginning.
In this session you will learn:
-
Key Identity Management Challenges
and how they affect application
security
-
Key Integration points for Identity
Management
-
Methods to Leverage Identity
Management in Web Single Sign On
-
About Identity Federation
Technologies, e.g., SAML, Liberty
Alliance
-
Methods to Leverage Identity
Federation technologies to secure
your application
2:30 pm - 3:00 pm Break
3:00 pm
- 4:00 pm
Security Throughout the Software
Development Lifecycle
Danny
Allan, Security Analyst, Watchfire
The shift in focus from network-based
vulnerabilities to application-based
vulnerabilities has left many
organizations exposed. A leading IT
analyst company estimates that 75% of
online attacks are targeting web
applications yet many organizations are
doing very little to protect online
applications. Many companies are
struggling to effectively combat this
growing problem and handle the volume of
application testing.
Only through strict processes can web
application vulnerabilities be
identified, reducing exposure. Our
speaker will discuss techniques and best
practices to proactively manage web
application security and how to
effectively build application security
testing into the software development
lifecycle (SDLC) including: secure
coding techniques, building application
security into the development lifecycle
and understanding legislative
compliance, as well as ways to safeguard
the privacy and confidentiality of
highly sensitive online information.
In this
session
you will learn:
* How to better understand potential web
application security vulnerabilities
* Best practices and how to effectively
integrate application security testing
into the software development lifecycle.
* The importance of detecting and
removing software vulnerabilities during
application development
4:00 pm-5:00 pm
You’ve Built It, But Who’s Really Using
It? – Achieving Post Deployment Web
Application Security by Identifying and
Guarding Against Potential Threats
Dave Armstrong, Director of Research,
Authentify
Web applications pose a particularly
tough security challenge in that once an
application is deployed, it exists in an
environment where security threats are
potentially as diverse as the people who
create them. Developing an identity
focused strategy for safeguarding web
applications and their legitimate users
is a post-deployment step necessary to
ensure the ongoing viability for your
application. Identity focused security
centers on:
• Human Identification –
Methods such as PIN / password
strategies, digital certificates and
biometrics for protecting legitimate
application users while guarding against
malicious users.
• Site Identification –
Protecting your application from
security threats such as phishing and
other identity-related attacks.
In this session you will see actual
examples of how enterprises employ
identity focused strategies to protect
their web application.
What You Will Learn
In this one day conference you, will learn the
following:
-
How to determine the top web application security
vulnerabilities
-
How to protect your organization against coding errors
and design flaws
-
How to build a checklist to help enable secure
application delivery
-
How to build a blueprint for an effective approach to
securing enterprise web applications
-
How to use application penetration testing and analysis
of automated source code to assess web
application security
-
How to protect databases that are connected to your web
applications
-
How to protect against identity theft from your web
applications
-
How IT departments are working through the challenges of
web applications security
Each attendee will receive a certificate
awarding 7 CPE credits for CISSP continuing
education,
in addition to 0.7 CEUs and 7 PDUs.
CISSP is a registered certification mark of
(ISC)², Inc.

Conference price: $179 per person per conference.
Exhibits
As is always the case at CAMP IT Conferences events, the talks
will not include product presentations. During the
continental breakfast, coffee breaks, and the
luncheon break you will have the opportunity to
informally meet representatives from the
following sponsoring companies, who have
solutions in the area of the conference.
|
| |
|