Social Security Administration Small Business Procurement Conference

June 11, 2010
Altmeyer Building
Baltimore, MD

Agenda

June 21, 2010
Registration2:00 - 4:00
Exhibitor Set-Up2:00 - 4:00
June 22, 2010
Registration & Continental Breakfast7:00 - 8:00
Welcome & Introduction8:00 - 8:15
Break8:15 - 8:30
Session 18:30 - 9:45
Track A: Certification & Accreditation Process Update
Track B: Identity Management
Break9:45 - 10:00
Keynote Speaker10:00 - 10:45
Exhibit Hall Open10:30 - 3:00
Break10:45 - 11:00
Session 211:00 - 12:15
Track A: Risk Management
Kelley Dempsey, CISSP, Senior Information Security Specialist, National Institute of Standards and Technology, Information Technology Lab/Computer Security Division
Track B: Enterprise Messaging
Developing the DoD Cybersecurity Workforce
George Bieber, Deputy, IA Human Resources and Training, DoD Chief Information Officer (CIO), Defense-wide Information Assurance Program (DIAP)
This session will provide an overview of DoD's approach to developing the Cybersecurity workforce of today and tomorrow. Participants will learn more about the Department's strategy for addressing workforce management, training and personnel certification, including the latest enhancements to the IA Workforce Improvement Program, DoD 8570. Key activities and initiatives to Expand Cyber Education under the Comprehensive National Cyber Initiative will be addressed, including specifics on how attendees can directly contribute to enhancing the pipeline of cyber security personnel for the future.
Lunch12:15 - 1:15
Break1:15 - 1:30
Session 31:30 - 2:45
Track A: Secure Networks
Track B: Mobile Security Threats
Break2:45 - 3:00
Session 43:00 - 4:00
Track A: Intrusion Prevention & Detection
David L. Willson
Track B: Virtualization
Adjourn for the day4:00
June 23, 2010
Registration & Continental Breakfast7:00 - 8:00
Administrative Announcements8:00 - 8:15
Exhibit Hall Open8:00 - 1:45
Break8:15 - 8:30
Session 58:30 - 9:45
Track A: Cloud Computing
Cloud Computing - Overview of Information Assurance Concerns and Opportunities
Trent Pitsenbarger, National Security Agency
Cloud computing is an emerging trend which has progressed to the point of serious adoption in public and private sector organizations, yet it remains a relatively immature paradigm, one which dictates a revision to the traditional characterization of risk in information technology environments. As a means of an introduction to those changes, this presentation offers an overview of the information assurance aspects of cloud computing with a focus on potential security advantages and pitfalls. While many of the security concerns associated with cloud computing are shared with traditional computing models, the presentation will focus on those issues unique to cloud computing or that are
exacerbated by it, and offer some real-world examples of issues that have arisen. The intended audience is anyone considering the adoption of cloud computing and who needs to understand the security risks and potential opportunities cloud computing provides as part of a risk management process.
Track B: SCAP
Exhibit Viewing9:45 - 10:30
Session 610:30 - 11:45
Track A: Security & Privacy Policies
What your "Net Searches" really say about you!
Derek Isaacs, Computer Security/Information Assurance professional, Boecore (MDA)
In our "Wild Webbed World" of Cyberspace - privacy has come under increasing scrutiny and risk based upon operational needs and situational issues. This presentation will examine newly introduced technologies and their effect on privacy - (that's yours and my PII information) - that have long been held sacrosanct in a non-technology-based environment. This presentation will attempt to describe and discuss the impacts and effects these new efforts premises will have in regards to our personal and professional interactions on the Internet.
Track B: Access Management
Lunch11:45 - 12:45
Session 712:45 - 1:30
Track A: Key Management
Track B: Application Security
Using Software Security Assurance to Secure Mission Critical Applications
Rob Roy, Federal CTO, Fortify Software
Security today isn't just about firewalls and encryption. Applications are woefully vulnerable to attack and breached daily, regardless of where they reside and how secure the network might be. There is much talk today of the benefits of cloud computing and while those are legit, there are many security concerns that cannot be ignored.

Government agencies can only really be rest assured that their mission critical applications are secure in the cloud if their service provider makes it a priority to apply application security best practices: ongoing vulnerability testing, remediation and management. Application security is the "new frontier", as important now as network security, identity management and other forms of security were 10 years ago. Hackers have resorted to applications as their new way "in", and as a result, businesses - and the cloud infrastructure providers that support them - must proactively identify and resolve security vulnerabilities that reside in applications.

This presentation will discuss the importance of Software Security Assurance (SSA) for applications in the cloud. It will be presented by Rob Roy, Federal CTO of Fortify Software (www.fortify.com).
Break1:30 - 1:45
Session 81:45 - 3:00
Track A: Web 2.0
Track B: Data Recovery Software
Conference Adjourns3:00