Day 1 – Tues June 11 2013:
9am – “Addressing today’s security challenges in the data centre”, hosted by Peter Cresswell, senior solutions architect, Trend Micro.
Peter provided a good overview of the security challenges that face the industry today. Of particular interest to me was the Cloud Security Alliance GRC Stack Toolkit. GRC = Governance, Risk Management & Compliance. The kit includes the following tools:
- Cloud Audit
- Cloud Controls Matrix
- Consensus Assessments Initiative
The GRC toolkit can be found at https://cloudsecurityalliance.org/research/grc-stack/
Peter talked about the types of attacks that are out there and he spent time reviewing Advanced Persistent Threats (APTs). A couple of resources that he referenced include:
- Rik Ferguson’s Frustrate, Disrupt, Evade post
- ISACA.org’s Advanced Persistent Threat Awareness Study Results
One final resource from this presentation is ISACA.org’s APT Infographic: