SecureCloud 2010
About SecureCloud 2010
SecureCloud 2010 is a premier educational and networking event hosted by the European Network and Information Security Agency, the Cloud Security Alliance and ISACA, three of the leading organizations shaping the future of Cloud Computing Security. It is the first event to focus specifically on state of the art practices to promote security, privacy and trust within cloud computing from technical, assurance and governance perspectives. This event is a unique opportunity not only to learn, but to make important global contacts and participate in interactive strategy sessions
January 26, 2010: We are pleased to have the IEEE joining us as a conference organizer, leading our cloud standards discussions
SecureCloud 2010 will feature presentations by thought leaders from industry, academia and government, including keynote speeches by Dave Cullinane, CISO at eBay, Inc., and Chairman of the Board of the CSA, and Dr Udo Helmbrecht, Executive Director of ENISA.
SecureCloud 2010 Call for Papers is Now Closed
The SecureCloud 2010 program will feature two tracks:
- Track One: Legal, Assurance & Compliance. Topics include provider & professional certifications, standards, governance frameworks, breach reporting, international regulations, legal impacts and many more.
- Track Two: Security & Privacy. Topics include virtualisation, identity and access management, encryption, key management, virtual private clouds and many more.
Email us to inquire about an existing CFP submission
Agenda
Day 1, March 16
| 8:45 – 9:30 | Registration |
|---|
Plenary
| 9:30 – 10:15 | Keynote Speaker: Dr Udo Helmbrecht, Executive Director of ENISA. |
|---|
Track Sessions
| 10:15 – 11:15 | Track One: Alexander Seger (Council of Europe) - Security and Data Protection in the Cloud | Track Two: Dominik Birk (Horst Goetz Institute for IT Security) - Forensics 2.0: Challenges in the Cloud” Jesus Molina (Fujitsu Laboratories of America) - Practical Applications of Trusted Computing in the Cloud |
|---|---|---|
| 11:15 – 11:30 | Coffee Break |
Track Sessions
| 11:30 – 12:00 | Track One: Wendy Goucher (Idrach Ltd) - In the cloud, out of mind: The challenge of caring about virtual data | Track Two: Ajit Jaokar (Futuretext) - Mobile Cloud Computing: Issues and Risks from a Security Privacy Perspective |
|---|---|---|
| 12:00 – 13:00 | Track One: Panel - Cloud Legal Issues | Track Two: Panel - Data Assurance - Hart Rossman (SAIC), Nadeem Bukhari (Kinamik), Gorka Sadowski (LogLogic) |
| 13:00 – 14:15 | Lunch |
Track Sessions
| 14:15 – 15:00 | Track One: Grobauer Bernd (Siemens CERT) - Towards a Cloud Specific Risk Analysis Framework | Track Two: Joram Borenstein (RSA) - Fighting Fraud from the Cloud: Metrics War-Stories from the Past 5 Years |
|---|---|---|
| 15:00 – 15:45 | Track One: Cloud Security Alliance Metrics Working Group - Overview of CSA Metrics Framework | Track Two: Thomas Schreck (Siemens AG) - Towards Incident Handling in the Cloud: Challenges and Approaches |
| 15:45 – 16:00 | Coffee Break |
Plenary
| 16:00 – 17:30 | Panel: International Government Speakers - Government Uses of Cloud | |
|---|---|---|
| 17:30 – 18:00 | Keynote Speaker: Philippe Courtot, CEO, Qualys |
Day 2, March 17
Plenary
| 9:30 – 10:15 | Keynote Speaker: TBD |
|---|
Track Sessions
| 10:15 – 11:00 | Track One: Randolph Barr (Qualys) - How to Gain Comfort in Losing Control in the Cloud | Track Two: Venkata Achanta (Juniper Networks) - Securing the Cloud Infrastructure: A Network Centric Approach |
|---|---|---|
| 11:00 – 11:15 | Coffee Break |
Track Sessions
| 11:15 – 12:15 | Track One: Panel - Emerging framework for Assurance and Certification - Raj Samari, Ohki Eijiroh, Rolf Vom Stein, Douglas Barbin | Track Two: Panel - Identity Management in the Cloud - Tobias Dussa (KIT-CERT), Kurt Anderson (Pfizer), Marcus Lasance (Verizon) |
|---|---|---|
| 12:15 – 13:00 | Track One: Marc Andersen (Danish National IT Telecommunications Agency) - Avoiding Governmental Mist in Cloud Computing - Designing for ICT-Security and Privacy | Track Two: Maryann Hondo (IBM WebSphere Technology Institute) - Securing Inter-Cloud Communication |
| 13:00 – 14:15 | Lunch |
Track Sessions
| 14:15 – 15:00 | Track One: Ohki Eijiroh (Kogakuin University) - Possible direction of Cloud Service Certification and Assurance | Track Two: Craig Balding (CloudSecurity.org) - Skylab: How To Create A Simple Security Test Lab With No Hardware |
|---|---|---|
| 15:00 – 15:45 | Track One: IEEE Panel - Better Cloud Living through Standards | Track Two: Theo Dimitrakos (BT) - Virtual Hosting on Federated Clouds |
| 15:45 – 16:00 | Coffee Break |
Plenary
| 16:00 – 17:30 | Panel: Cloud Providers | |
|---|---|---|
| 17:30 – 18:00 | Keynote Speaker: Dave Cullinane, CISO, eBay, Inc. |
SecureCloud 2010 Speakers
Dr Udo Helmbrecht, Executive Director, ENISA
Dr Udo Helmbrecht was born in 1955, Castrop-Rauxel, North Rhine-Westphalia, Germany. He has more than 30 years of professional, management experience in the IT sector.
His experience has been gained in various sectors of society. This includes e.g. energy industry, insurance company engineering, aviation, defence, and space industry, before becoming President of BSI in 2003. Prior to that, Dr Helmbrecht was Director Information Processing (CIO) at Bayerische Versorgungskammer in Munich, Germany
Dave Cullinane, CISO, eBay
Dave Cullinane is the CISO for eBay. Prior to joining eBay, Dave was the CISO for Washington Mutual. Prior to Washington Mutual, Dave was a Senior Consultant for nCipher, Inc.; the Director of Information Security for Sun Life of Canada's U.S. operations and helped create Digital Equipment Corporation's Security Consulting Practice.
Dave is the Chairman of the Board of the Cloud Security Alliance. Dave is a Charter Member of the Alliance for Enterprise Security Risk Management (AESRM) – an alliance of security professional associations dedicated to advancing the Profession. He is the current Past International President of the Information Systems Security Association (ISSA); and a Charter Member of the Global Council of Chief Security Officers. He serves on ASIS International's Information Technology Security Committee (ITSC) and is on the Editorial Advisory Board of CSO Magazine and SC Magazine. He was nominated for Information Security Executive of the Year for 2004 and 2005 and awarded SC Magazine's Global Award as Chief Security Officer of the Year for 2005. He was awarded CSO Magazine’s 2006 Compass Award as a "Visionary Leader of the Security Profession".
Alexander Seger, Head of Economic Crime Division, Council of Europe
Alexander Seger has been with the Council of Europe (Strasbourg, France) since 1999. He is currently the Head of Economic Crime Division and responsible for the Council of Europe’s cooperation programmes against cybercrime, corruption, money laundering and trafficking in human beings (www.coe.int/economiccrime). From 1989 to 1998 he was with what now is the United Nations Office on Drugs and Crime in Vienna (Austria), Laos and Pakistan and a consultant for German Technical Cooperation (GTZ) in drug control matters. Alexander Seger is from Germany and holds a PhD in political science, law and social anthropology after studies in Heidelberg, Bordeaux and Bonn.
The Council of Europe (www.coe.int) was founded in 1949 and now comprises 47 European countries. Its primary purpose is to promote human rights, democracy and the rule of law. On the basis of these fundamental values, the Council of Europe tries to find shared solutions to major problems such as terrorism, organised crime and corruption, cybercrime, bioethics and cloning, violence against children and women, and trafficking in human beings. International co-operation is the only way to solve the major problems facing society today. While its more than 200 treaties and protocols are aimed at the 47 member states, some important treaties - such as the Convention on Cybercrime - are open for accession by other countries (www.coe.int/cybercrime).
Philippe Courtot, Chairman and CEO, Qualys
Demonstrating a unique mix of technical vision, marketing and business acumen, Philippe Courtot has repeatedly built innovative companies into industry leaders. As CEO of Qualys, Philippe has worked with thousands of companies to improve their network security. Philippe received the SC Magazine Editor's Award for bringing on demand technology to the network security industry and for co-founding the CSO Interchange to provide a forum for sharing information in the security industry.
Before joining Qualys, Philippe was the Chairman and CEO of Signio, an electronic payment start-up that he repositioned to become a significant e-commerce player. In February 2000, VeriSign acquired Signio for more than a billion dollars. Today, VeriSign's payment division, based on the Signio technology, handles 30% of electronic transaction in the U.S., processing $100-million in daily sales. Prior to Signio, Philippe was President and CEO of Verity, where he re-engineered the company to become the leader in enterprise knowledge retrieval solutions. Under Philippe's direction, the company completed its initial public offering in November 1995. Philippe also turned an unknown company of 12 people, cc:Mail, into the dominant e-mail platform provider, achieving a 40% market share while competing directly against IBM and Microsoft. Acknowledging the market leading position of cc:Mail and the significance of e-mail in corporate environments, Lotus acquired the company in 1991.
Raj Samani, Vice President for Communications, ISSA UK Chapter
Raj is an active member of the Information Security industry, through involvement with numerous initiatives to improve the awareness and application of security. He is currently working as CISO for a large public sector organisation in the UK, having previously worked for and within some of the largest private and public sector organisations in the world.
In addition, Raj is currently the Vice President for Communications in the ISSA UK Chapter, having previously established the UK mentoring programme. He is also on the advisory council for the Infosecurity Europe show, Infosecurity Magazine, and expert on both searchsecurity.co.uk, and infosec portal. He has had numerous security papers published, and appeared on television (ITV and More4). As well as providing assistance in the 2006 RSA Wireless Security Survey and part of the consultation committee for the RIPA Bill (Part 3).
Next to his work Raj has also obtained: CESG Listed Advisor Scheme, (CLAS), Certified Information Systems Security Professional (CISSP), Certified Ethical Hacker (CEH), Microsoft Certified Systems Engineer (MCSE – in NT4, Win2k, Win2003), Check Point Certified Security Administrator (CCSA in NG and 4.1), Check Point Certified Security Expert (CCSE - NG), Citrix Certified Administrator (CCA), QualysGuard Certified, RSA Certified Systems Engineer (SecurID), Cisco Certified Network Administrator (CCNA), as well as a BA (Hons), and MSc.
Nadeem Bukhari CISSP, CISM, VP of Product Strategy, Kinamik Data Integrity
Nadeem has more than 12 years of exclusive experience within the Information Security Industry 8 of which were spent within the management consulting firms of Ernst and Young and Deloitte. Subsequently he has provided strategic information security and risk management consultancy to global blue chip organizations and has held a senior positions within high technology software start-ups.
He is a graduate in Information Technology Security from the University of Westminster, a CISSP and CISM.
Marcos Gómez, Inteco
Marcos Gómez Hidalgo, 37 years old, Bachelor of Science in Mathematics of the University Complutense of Madrid. He has held different positions of responsibility in Sema Group and Atos Origin. He Worked in Red.es of the Spanish Ministry of Industry, Tourism and Trade, as the person responsible for the Information Systems and the Early Alert Centre of Virus and Information Security. Currently is the Deputy Director of Programmes of INTECO, National Institute of Communication Technologies, depending on the Spanish Ministry of Industry, Tourism and Trade. He Manages the line of e-Trust (electronic trust) set by the Plan Avanza, the line that involves among others the services of the IT Incidents Response Centre (INTECO-CERT), the Security Helpdesk for the Internet Users and the Security Show-Room. He has also worked as a lecturer of informatics engineering in the University Camilo José Cela of the educational institution SEK, and in various seminars, postgraduate and master courses in the field of information security.
Craig Balding
Craig Balding is an IT Security Practitioner at a fast paced banking and finance Fortune 500 where he leads a global team of technical security specialists.
He has a decade of hands-on IT Security experience, with over 15 years in the IT industry. He is co-author of “Maximum Security: A Hackers Guide to Protecting Your Network”, CISSP and CISA certified and a British Computing Society Chartered IT Professional (MBCS CITP). He specialises in penetration testing, incident response, forensics, UNIX/Linux and ORACLE security.
Craig founded cloudsecurity.org where he blogs about Cloud Computing and Security. He is frequently asked to comment on Cloud Security issues for both IT and mainstream media (e.g. NPR, BBC). He has presented at Black Hat Europe, eCrime London, the World Cloud Computing Summit, Brucon and RSA Europe.
SecureCloud 2010 Sponsors
Sponsorship Brochure
Please contact sc2010sponsor@cloudsecurityalliance.org with additional sponsorship questions.
SecureCloud 2010 Attendee Registration
Register Today
You can also keep in touch at our LinkedIn SecureCloud 2010 Event listing
SecureCloud 2010 Hotel Information
SecureCloud 2010 will be held at the Majestic Hotel & Spa Barcelona. Special room rates of €139 euros are available through January 30, 2010. Reservation form can be downloaded here (doc | pdf), or contact the hotel, referencing ENISA GROUP.
The Majestic Hotel & Spa Barcelona was built in 1918 and provides ultimate luxury, renowned quality of service and prime location in the center of Passeig de Gràcia. Surrounded by fine brand shopping, historical Gaudi masterpieces and outdoor restaurants, cafés and tapas bars, the Majestic is only 10 minutes walk to Plaza Catalunya and the popular Rambla.
View Larger Map



