Difference between revisions of "December 2012"

From mn/ifi/AFSecurity
Jump to: navigation, search
(Created page with "==''AF''Security Seminar: ''Risk Analysis''== Date: 12 December 2012. Location: Meeting Room Awk (room 3118), Ole-Johan Dahls hus (IfI). '''Agenda''' 14:00h Welcome at IfI 1...")
 
 
(5 intermediate revisions by the same user not shown)
Line 1: Line 1:
==''AF''Security Seminar: ''Risk Analysis''==
+
==AF''Security'' Seminar: ''Risk Management''==
 +
 
  
 
Date: 12 December 2012.
 
Date: 12 December 2012.
Line 11: Line 12:
 
14:15h Invited talk
 
14:15h Invited talk
  
'''TITLE:''' x86 Stack Buffer Overflow Exploitation
+
'''SPEAKER:''' Roy Stranden (Ernest & Young)
 +
 
 +
'''TITLE:''' New Standards for Security Risk Management and Security Risk Analysis
 +
 
 +
Presentation slides: [[Media:AFSec20121212-Stranden-EY.pdf]]
 +
 
  
 
'''ABSTRACT:'''
 
'''ABSTRACT:'''
Despite being around for well over 20 years, buffer
+
There are a number of different methods for risk analysis that serves different needs.  However, few address the challenges in assessing risks concerning security issues. 
overflows still pose a huge threat. This talk gives a technical
+
 
introduction to stack buffer overflows and describes methods how they
+
A working group under Standard Norge has focused on this issue and developed a series of new standards that serve to address this issue.
are usually exploited. Other topics covered are current mitigation
+
 
techniques and how they can be bypassed under certain conditions.
+
This talk will introduce the new standards and justify the need for a new way of thinking concerning security risks.  
  
'''SPEAKER:''' Andreas Follner, EC-SPRIDE, Center for Advanced Security Research Darmstadt
+
'''SPEAKER BIO:'''
 +
Roy Stranden has worked within security for more than 20 years for, among others, the Norwegian Police Security Service and the Norwegian Intelligence Service.  Roy is currently working for Ernst & Young.  Roy has an MSc in Risk, Crisis and Disaster Management, a Postgraduate Diploma in Security Management, a Certificate in Applied Intelligence and is currently studying for a Certificate in Terrorism Studies.  Roy is also a Certified Information Security Manager (CISM).
  
'''BIO:'''
+
Currently, Roy leads the working group that is developing the new standards prNS 5831 Risk Management and prNS 5832 Risk Analysis.
Andreas Follner holds a Master's Degree in Information Security
 
and is currently working as a research assistant at EC-SPRIDE.
 
  
 
15:00h Discussion
 
15:00h Discussion
  
 
15:30h End
 
15:30h End

Latest revision as of 08:29, 31 October 2013

AFSecurity Seminar: Risk Management

Date: 12 December 2012.

Location: Meeting Room Awk (room 3118), Ole-Johan Dahls hus (IfI).

Agenda

14:00h Welcome at IfI

14:15h Invited talk

SPEAKER: Roy Stranden (Ernest & Young)

TITLE: New Standards for Security Risk Management and Security Risk Analysis

Presentation slides: Media:AFSec20121212-Stranden-EY.pdf


ABSTRACT: There are a number of different methods for risk analysis that serves different needs. However, few address the challenges in assessing risks concerning security issues.

A working group under Standard Norge has focused on this issue and developed a series of new standards that serve to address this issue.

This talk will introduce the new standards and justify the need for a new way of thinking concerning security risks.

SPEAKER BIO: Roy Stranden has worked within security for more than 20 years for, among others, the Norwegian Police Security Service and the Norwegian Intelligence Service. Roy is currently working for Ernst & Young. Roy has an MSc in Risk, Crisis and Disaster Management, a Postgraduate Diploma in Security Management, a Certificate in Applied Intelligence and is currently studying for a Certificate in Terrorism Studies. Roy is also a Certified Information Security Manager (CISM).

Currently, Roy leads the working group that is developing the new standards prNS 5831 Risk Management and prNS 5832 Risk Analysis.

15:00h Discussion

15:30h End