OSEC

Neohapsis is currently accepting applications for employment. For more information, please visit our website www.neohapsis.com or email hr@neohapsis.com
 
SANS First Wednesday Webcast: "Insider Threat: Web Application Security"

From: The SANS Institute (Webcastsans.org)
Date: Mon May 01 2006 - 22:03:33 CDT


SANS is happy to bring you the latest in our complimentary series
of Webcasts. Please join us on Wednesday, May 03 at 1:00 PM EDT as
SANS presents:

First Wednesday Webcast: "Insider Threat: Web Application Security"
Featuring: Eric Cole and Dave Grant
Sponsored by: Watchfire
Wednesday, May 03 at 1:00 PM EDT (1700 UTC/GMT)

You can now download or subscribe to the SANS webcast calendar -
http://www.sans.org/webcasts/calendar.ics

SANS live webcasts allow you to hear a knowledgeable speaker while
viewing presentation slides you can download in advance. If you've
never tuned in to a SANS webcast before, see the simple instructions
at the end of this message to learn how to connect to the SANS Portal
and join us for these free educational webcasts.

"Insider Threat: Increasing Your External Threat"
Featuring: Eric Cole
Since so many organizations have focused on external threats for so
long, their internal security has been minimal. Many people refer
to this as having a hard outer shell and a soft center. While
more organizations are starting to understand the importance of
insider threats, what they fail to realize is that not properly
protecting against the insider can not only cause internal problems,
but also weaken your external security. This is highlighted with web
applications. Since web applications tend to be the bridge between the
external world and your internal network, poor internal security can
actually weaken your overall security and make your web applications
more vulnerable.

"Your Biggest Insider Threat? Don't Overlook Your Intranet"
Featuring: Dave Grant
Corporate intranets are rapidly growing and because they are often
poorly managed, the risks are increasing. A company?s intranet can
be one of its most valuable communication tools and as a result,
organizations need to have comprehensive privacy and security
management processes in place. Understanding and assessing your
potential risks is a good place to start.

When you leave this session, you will learn:

    * How to better understand specific Intranet risk management
issues, including web application security vulnerabilities
    * Understand what employee and customer information is being
collected and consider applicable legislation such HIPAA.
    * How to establish enterprise risk management processes and better
understand exactly who has access to this sensitive information

Eric Cole has received his PhD from Pace University and has been
recognized as an information security expert for more than 10
years. Eric holds several professional certifications and helped
develop several of the SANS GIAC certifications and corresponding
courses. Eric is currently chief scientist for The Sytex Group's
Information Warfare Center, where he heads cutting edge research in
technology and various areas of network security. His writing credits
include: "Hackers Beware", "SANS GIAC: Security Essentials Cookbook"
and his latest work "Hiding in Plain Sight: Steganography and the
Art of Covert Communication".

David Grant brings almost 10 years of software industry marketing
experience and expertise to Watchfire. As the company's senior
director of marketing, David is responsible for global marketing
and product management, which includes overall product strategy and
all facets of marketing communications. David holds a Bachelor of
Science degree in Marketing from Saint Mary's University in Halifax,
Canada and an MBA in Finance from Dalhousie University.

***************************************************************************

Additional FREE SANS Webcast coming in May 2006

Ask The Expert Webcast: "Who's Guarding the Guards?"
Tuesday, May 09 at 1:00 PM EDT (1700 UTC/GMT)
Featuring: Dave Shackleford and Kristin Gallina Lovejoy
https://www.sans.org/webcasts/show.php?webcastid=90724
Sponsored by Consul risk management, Inc.

Internet Storm Center (ISC): Threat Update
Wednesday, May 10 at 1:00 PM EDT (1700 UTC/GMT)
Featuring: Johannes Ullrich
https://www.sans.org/webcasts/show.php?webcastid=90621
Sponsored by Prism Microsystems,Inc.

********************************************************************

For additional information on any of the above webcasts, please go to
http://www.sans.org/webcasts

********************************************************************
July 5-13 - Bring your family for the fireworks and stay for SANS
largest conference in Washington.

The industry's best security courses - extraordinary faculty;
authoritative up-to-the-minute material - shows you how to do the job
and gives you the confidence to go back and do it immediately.

"Jacked my paranoia level up around my ears, and then gave me the tools
to manage the threat." (Don Geiger, DCPS Division of Technology)

Offers every one of SANS' 17 immersion training courses plus 12 short
courses and a big exposition: SANS Security Essentials, Hacker
Exploits, System Forensics, Intrusion Detection, Auditing, plus training
for CISSP exam and all Technical certification required for DoD 8570 and
more. Plus special evening sessions by the global security leaders who
staff the Internet Storm Center.

http://www.sans.org/sansfire06/

********************************************************************

In order to access the webcasts, you will need a SANS portal
account and either Real Audio Player or Windows Media Player (free
downloads are available at our website). If you do not already
have a portal account, just go to http://portal.sans.org and
fill in the simple registration form, it's free! Your account
gives you access to the archive of past webcasts. Log on to
http://www.sans.org/webcasts/archive.php

********************************************************************
To change your subscription, address, or other information, visit
http://portal.sans.org. If you wish to have your name removed from
our mailing list, visit the site above, click on "update your account"
and check the box "Do not send any email".