New User, Welcome!     Login

Next Page >>

Risk Management

CFP - Security Byte / OWASP Asia 2009

Conference Tracks (17 – 18 Nov, 2009)
You can submit your response for any the following three conference tracks

* CT 1 - Application, Database & Web Security
* CT 2 - Infrastructure Security (Network / Wireless/ Bluetooth / Malware / Forensics / Cyber- terrorism / Physical Security / Information warfare etc.)
* CT 3 - Risk Management / Compliance

 
Session will have to be delivered in any one of the following Session format for Conference talks:

* Coldfire Sessions (60 Minutes): These sessions are primarily core technical talks and will cover the following categories:

IRM Security Advisory : Barracuda Networks Spam Firewall Cross-Site Scripting Vulnerability

The vendor has confirmed the issue exists in all versions prior to
3.5.11.025.

Credits

Research and Advisory: Information Risk Management Plc.

About IRM:

Information Risk Management Plc (IRM) is a vendor independent
information risk consultancy, founded in 1998. IRM has become a leader

TSSA-2011-03 - Perl : multiple functions null pointer dereference uppon parameters injection

    Toucan System is a French computer security company providing
    cutting edge research and security consulting to Fortune 500
    as well as smaller companies globally, thanks to a wide range
    of expertise ranging from Reverse Engineering and binary
    analysis to cryptography and Risk Management.



Top 5-ish Threats to Watch for in 2009

3. Can you tell how many flies are in your home by the number of dead
ones on your front doorstep?  If not then you're using the wrong
metrics.  Study from the masters- that's right, this new year more and
more people will learn metrics from anti-malware or intrusion
detection companies.  As security metrics steps away from being the
little helper in Risk Management to become a booming industry in
itself it needs to wear its big-boy pants (the ones that can hold the
fat wallet). So its status as a threat to business management,
procurement, security decision-making, and the bottom line has never
be higher. That means they want your money. Badly. That makes them a
the same type of nasty threat you can expect from any aggressive yet

=?WINDOWS-1252?Q?Call_For_Papers_=96_ACM_CCS_2009_Workshops?=

Workshop on Information Security Governance (WISG 2009)
http://ait.gmu.edu/~csis/wisg2009/

Information Security Governance is to establish a framework to drive
implementation of effective information security strategies in
organizations involving risk management, reporting, and
accountability. Recent changes in business environment such as
outsourcing, global supply chain, and cross organizational
collaborations is forcing users to access and retrieve business data
across organizational boundaries. This is making data governance in
enterprise intractable. These new disruptive trends will greatly

CfP: GameSec 2010 - 5 days left to the deadline

GameSec will fill an important void and serve as a distinguished forum of
highest standards for years to come.

Topics of interest include (but are not limited to):
* Security games
* Security and risk management
* Mechanism design and incentives
* Decentralized security algorithms
* Security of networked systems
* Security of Web-based services
* Security of social networks

IRM025: TIBCO Rendezvous RVD Daemon Remote Memory Leak DoS

Research & Advisory: Varun Uppal and Andy Davis

About IRM:

Information Risk Management Plc (IRM) is a vendor independent
information risk consultancy, founded in 1998. IRM has become a leader
in client side risk assessment, technical level auditing and in the
research and development of security vulnerabilities and tools. IRM is
headquartered in London with Technical Centres in Europe and Asia as
well as Regional Offices in the Far East and North America. Please visit

TSSA-2011-02 - Opera : SELECT SIZE Arbitrary null write

    Toucan System is a French computer security company providing
    cutting edge research and security consulting to Fortune 500
    as well as smaller companies globally, thanks to a wide range
    of expertise ranging from Reverse Engineering
    and binary analysis to cryptography and Risk Management.



Shakacon Security Conference - Trainers and Speakers Finalized

 
Alberto Revelli and Nico Leidecker
   \__Playing with Heyoka: Spoofed Tunnels and Undetectable Data
 
Daniel Blander
   \__Emerging Trends in Security and Risk Management
 
Andrea Barisani & Daniele Bianco, Inverse Path
   \__Sniff keystrokes with lasers/voltmeters: Side Channel Attacks
 
Paul Craig

Cyber Warfare Conference: Agenda

Roelof Temmingh, CEO, Paterva
Evaluating the Credibility of a Cyber Threat

Amit Yoran, Chairman and CEO, NetWitness Corporation
Removing the Uncertainty and Doubt (but not the Fear) from Information
Risk Management

Billy Rios and Jeff Carr, Microsoft
Sun Tzu was a Hacker - A Examination of the Tactics and Operations
from a Real World Cyber Attack


TSSA-2011-01 xpdf : multiple vulnerabilities allow remote code execution

    Toucan System is a French computer security company providing
cutting edge
research and security consulting to Fortune 500 as well as smaller companies
globally, thanks to a wide range of expertise ranging from Reverse
Engineering
and binary analysis to cryptography and Risk Management.



Academic Computer Security Conference

    to secure computing.


Topics include, but are not limited to:
    -- Secure and Trusted Computing
    -- Security and Risk Management
    -- Metrics and Benchmarking
    -- Identity Management and Theft
    -- Egovernment, Ecommerce and Ebanking Security
    -- Application Security
    -- AOP and Security

CfP: GameSec 2010 - Deadline extended to 31 May 2010

GameSec will fill an important void and serve as a distinguished forum of
highest standards for years to come.

Topics of interest include (but are not limited to):
* Security games
* Security and risk management
* Mechanism design and incentives
* Decentralized security algorithms
* Security of networked systems
* Security of Web-based services
* Security of social networks

IRM Vendor Alerts: Six critical remote vulnerabilities in TIBCO SmartPGM FX

Andy Davis | Chief Research Officer

Information Risk Management Plc
8th Floor | Kings Building | Smith Square | London SW1P 3JJ
Tel: +44 (0) 1242 225 205
Fax: +44 (0) 1242 225 215
www.irmplc.com


CfP: GameSec 2010 - Deadline is 3 weeks away!

GameSec will fill an important void and serve as a distinguished forum of
highest standards for years to come.

Topics of interest include (but are not limited to):
* Security games
* Security and risk management
* Mechanism design and incentives
* Decentralized security algorithms
* Security of networked systems
* Security of Web-based services
* Security of social networks

CFP - GameSec 2010 - Conference on Decision and Game Theory for Security

GameSec will fill an important void and serve as a distinguished forum of
highest standards for years to come.

Topics of interest include (but are not limited to):
* Security games
* Security and risk management
* Mechanism design and incentives
* Decentralized security algorithms
* Security of networked systems
* Security of Web-based services
* Security of social networks

Adobe Reader 9.3.4 Multiple Memory Corruption - Security Advisory - SOS-10-003

Discovered by.
Brett Gervasoni from Sense of Security Labs.

About us.
Sense of Security is a leading provider of information
security and risk management solutions. Our team has expert
skills in assessment and assurance, strategy and architecture,
and deployment through to ongoing management. We are
Australia's premier application penetration testing firm and
trusted IT security advisor to many of the countries largest
organisations.

Elcom CommunityManager.NET Auth Bypass Vulnerability - Security Advisory - SOS-10-004

Discovered by.
Sense of Security Labs.

About us.
Sense of Security is a leading provider of information
security and risk management solutions. Our team has expert
skills in assessment and assurance, strategy and architecture,
and deployment through to ongoing management. We are
Australia's premier application penetration testing firm and
trusted IT security advisor to many of the countries largest
organisations.

Call for Papers: The International Conference on Cyber Conflict, Estonia

alliances
- Doctrine of using cyber power, deterrence

Cyber Battlefield Intelligence
- Tactical and Operational issues: target selection, validation and
prioritisation, collateral damage, risk management, traffic flow
analysis
- Attribution and anonymity
- Information gathering from the underground hacker community
- Situational awareness and management in cyberspace
- Heuristic and early warning notification, event identification, data

Oracle Sun GlassFish Enterprise Server Stored XSS Vulnerability - Security Advisory - SOS-11-009

Discovered by.
Sense of Security Labs.

About us.
Sense of Security is a leading provider of information
security and risk management solutions. Our team has expert
skills in assessment and assurance, strategy and architecture,
and deployment through to ongoing management. We are
Australia's premier application penetration testing firm and
trusted IT security advisor to many of the country's largest
organisations.

cPassMan v1.82 Arbitrary File Download - SOS-11-004

Discovered by.
Kaan Kivilcim - Sense of Security Labs.

About us.
Sense of Security is a leading provider of information
security and risk management solutions. Our team has expert
skills in assessment and assurance, strategy and architecture,
and deployment through to ongoing management. We are
Australia's premier application penetration testing firm and
trusted IT security advisor to many of the country's largest
organisations.

IRM Security Advisory : RedDot CMS SQL injection vulnerability

Credits:
Research and Advisory: Mark Crowther and Rodrigo Marcos


Disclaimer:
All information in this advisory is provided on an 'as is' basis in the hope that it will be useful. Information Risk Management Plc is not responsible for any risks or occurrences caused by the application of this information.




TheGreenBow VPN Client Local Stack Overflow Vulnerability - Security Advisory - SOS-10-001

Discovered by.
Brett Gervasoni from SOS Labs.
About us.
Sense of Security is a leading provider of information security and risk 
management solutions. Our team has expert skills in assessment and 
assurance, strategy and architecture, and deployment through to ongoing 
management. We are Australia's premier application penetration testing firm 
and trusted IT security advisor to many of the countries largest 
organisations.


Cisco TelePresence Multiple Vulnerabilities - SOS-11-010

Discovered by.
David Klein, Sense of Security Labs.

About us.
Sense of Security is a leading provider of information
security and risk management solutions. Our team has expert
skills in assessment and assurance, strategy and architecture,
and deployment through to ongoing management. We are
Australia's premier application penetration testing firm and
trusted IT security advisor to many of the countries largest
organisations.

=?iso-8859-1?Q?PHPCaptcha_/_Securimage_2.0.2_-_Authentication_Bypass_-_SO?= =?iso-8859-1?Q?S-11-007?=

Discovered by.
Phil Taylor from Sense of Security Labs.

About us.
Sense of Security is a leading provider of information security and 
risk management solutions. Our team has expert skills in assessment
and assurance, strategy and architecture, and deployment through to
ongoing management. We are Australia's premier application penetration
testing firm and trusted IT security advisor to many of the country's
largest organisations.


(CFP) LACSEC 2012: 7th Network Security Event for Latin America and the Caribbean

* Computer security incident response teams (CSIRTs): creation,
management, experiences
* Security in corporate environments, compliance and auditing, return on
security investments
* Security management (procedures, operational logs, records, etc.)
* Risk management in Information Security
* Computer forensics
* Protection of privacy
* Legal aspects relating to computer security



IRM Advisory: Cisco IOS LPD Remote Stack Overflow

Research & Advisory: Andy Davis

Disclaimer:

All information in this advisory is provided on an 'as is' basis in the
hope that it will be useful. Information Risk Management Plc is not
responsible for any risks or occurrences caused by the application of
this information.

www.irmplc.com


[CFP] LACSEC 2011: 6th Network Security Event for Latin America and the Caribbean

* Computer security incident response teams (CSIRTs): creation,
management, experiences
* Security in corporate environments, compliance and auditing, return on
security investments
* Security management (procedures, operational logs, records, etc.)
* Risk management in Information Security
* Computer forensics
* Protection of privacy
* Legal aspects relating to computer security



National Computer and Information Security Conferences ACIS 2008 - COLOMBIA

        OS security
        Web Services Security
        Computer and digital forensics
        Incident Handling
        Digital Evidence
        IT Risk management
        Ethical and legal issues in Computer and Information
Security
        Biometrics
        VoIP Security
        Telecommunications Security

WordPress Plugin BackWPUp 2.1.4 - Security Advisory - SOS-11-012

Discovered by.
Phil Taylor from Sense of Security Labs.

About us.
Sense of Security is a leading provider of information security and risk
management solutions. Our team has expert skills in assessment and 
assurance,
strategy and architecture, and deployment through to ongoing management.
We are Australia's premier application penetration testing firm and trusted
IT security advisor to many of the country.s largest organisations.


Next Page>>

Copyright © 1995-2012 LinuxRocket.net. All rights reserved.

Nearly all of LinuxRocket's features are free. Be kind and donate to the cause!