Agenda

  Training & Certification (Class Now Full)  
8:30 - 9:00am Breakfast/Registration  
9:00 - 9:30am Vulnerability Management in the Enterprise  
  - The Vulnerability Management Process  
  - Enterprise Case Studies/Best Practices  
9:30 - 10:00am Network Discovery & Mapping  
  - Discover, Organize and Manage Network Assets & Services  
  - Automate Vulnerability Discovery Within a Global Network  
10:00 - 11:00am Security Auditing  
  - Automate Vulnerability Discovery Within a Global Network  
11:00 - 12:00pm Lab Part I  
  - User Account Setup  
  - Launch Maps and Vulnerability Scans  
12:00 - 1:00pm Lunch  
1:00 - 1:30pm Scanning Engine Architecture  
  - Scan and Map Functionality and Internals  
1:30 - 2:00pm Enterprise Reporting & Management  
  - Enterprise-wide Security Compliance Reporting  
  - View Your Security Posture with the Executive Dashboard  
  - Enterprise User Management  
2:00 - 2:30pm Enterprise Remediation  
  - How Remediation Works  
  - Customize Remediation Rules for Your Enterprise  
2:30 - 3:30pm Lab Part II  
  - Create Report Templates  
  - Create Technical and Executive Reports  
  - Remediate Critical Vulnerabilities  
3:30 - 4:30pm Overview of the QualysGuard APIs  
  - Introduction to APIs and Their Uses  
  - Sample API Application  
4:30 pm Certification Exam  
7:30 - 8:30am Breakfast/Registration: Welcome and Introduction  
8:30 - 9:15am Security and Compliance as a Service: Where are we now and where are we going? Philippe Courtot, Chairman and CEO, Qualys
9:15 - 10:15am QualysGuard Enterprise Suite and 2008 Engineering Road Map Wolfgang Kandek, CTO, Qualys
Ken Okumura, VP of Engineering, Qualys
10:15 - 10:30am Break - 15 minutes  
10:30 - 12:00pm Real World Experience From Qualys Users  
  - QualysGuard at Cisco Doug Dexter, Audit Team Lead, Cisco Systems
  - Building VM Reports with Crystal Reports Desiree Corwin, Senior Analyst, Information Security, Medimmune
12:00 - 1:15pm Lunch/Keynote Address: The Next Wave of Security Applications John Pescatore, VP, Gartner
1:15 - 1:30pm Break - 15 minutes  
1:30 - 2:30pm QualysGuard Policy Compliance Qualys Speaker
2:30 - 3:00pm QualysGuard PCI and Introducing Partner Auditing Service Qualys Speaker
3:00 - 3:15am Break - 15 minutes  
3:15 - 3:45pm QualysGuard Reporting Qualys Speaker
3:45 - 4:15pm Best Practices for Adopting QualysGuard to Compliance Controls Abdellah Cherkaoui, CISO, Sodexo
4:15 - 4:30pm Break - 15 minutes  
4:30 - 5:30pm QualysGuard Scanning Technology Update  
  - QualysGuard Scanning Engine Qualys Speaker
  - Web Application Scanning Qualys Speaker
  - On Demand Agents Qualys Speaker
5:30 - 6:30pm Break - 1 Hour  
6:30 - 7:00pm Transportation Shuttle to the Bently Reserve  
7:00 - 10:15pm Cocktails, Reception and Dinner at the Bently Reserve  
10:15 - 10:45pm Transportation Shuttle to The Palace Hotel  
8:00 - 8:30am Breakfast: Welcome and Introduction Amer Deeba, CMO and VP Product Marketing, Qualys
8:30 - 9:30am Best Practices for Remediation and Compliance David French, Director of US Field Operations, Qualys
9:30 - 10:30am QualysGuard APIs  
  - New APIs and Scripts Qualys Speaker
  - Customer Case Study: Using QG API to Automate Vulnerability Management and Remediation Josh Lemos, Senior Security Analyst, CNET
10:30 - 10:45am Break - 15 minutes  
10:45 - 11:45am QualysGuard Hands-On Demonstration Qualys Speaker
11:45 - 12:00pm Break - 15 minutes  
12:00 - 1:00pm Best Practices Roundtables  
  - Reporting  
  - Scanning  
  - PCI  
  - Policy Compliance  
  - Risk & Asset Management  
  - Customer Support  
1:00 - 2:00pm Lunch, Q&A, Closing Remarks Philippe Courtot, Chairman and CEO, Qualys

Security as a Service: Where are we now and where are we going

Length:
45 minutes
Overview:

Desiree Corwin serves as the senior analyst, information security. In this role, she performs risk, security, and vulnerability assessments along with providing technical guidance for security projects. Ms. Corwin joined MedImmune in 2001 as senior database administrator and moved into the enterprise engineering group as a systems engineer in 2006. She has more than ten years of experience administrating, developing on and securing Microsoft SQL server along with a strong background in programming (C, VB, ASP, PHP) and web server administration and security. Ms. Corwin holds a master's degree in information systems management along with the following industry certifications: MCSE (Microsoft Certified Systems Engineer), MCDBA (Microsoft Certified Database Administrator).

Speaker:

Abdellah Cherkaoui, CISO, Sodexo

Abdellah Cherkaoui is the Chief Information Security Officer for the Service Vouchers & Cards activity of Sodexo. Dr. Cherkaoui oversees all aspects of global information and systems security across the corporation, including the definition and implementation of enterprise-wide security policies and guidelines, the benchmarking of systems and infrastructures security for Sodexo Service Vouchers & Cards operations and the development of an IT risk management culture. Abdellah holds a Ph.D. degree in marine geophysics from the University of Washington in Seattle and a Master's degree in geotechnical engineering from the Rabat National School of Mines in Morocco. Abdellah has been awarded a NASA International Fellowship in 1987 and a Fulbright Doctoral Fellowship in 1993.

Security as a Service: Where are we now and where are we going

Length:
45 minutes
Overview:

Desiree Corwin serves as the senior analyst, information security. In this role, she performs risk, security, and vulnerability assessments along with providing technical guidance for security projects. Ms. Corwin joined MedImmune in 2001 as senior database administrator and moved into the enterprise engineering group as a systems engineer in 2006. She has more than ten years of experience administrating, developing on and securing Microsoft SQL server along with a strong background in programming (C, VB, ASP, PHP) and web server administration and security. Ms. Corwin holds a master's degree in information systems management along with the following industry certifications: MCSE (Microsoft Certified Systems Engineer), MCDBA (Microsoft Certified Database Administrator).

Speaker:

Desiree Corwin, Senior Analyst, Information Security, Medimmune

Desiree Corwin serves as the senior analyst, information security. In this role, she performs risk, security, and vulnerability assessments along with providing technical guidance for security projects. Ms. Corwin joined MedImmune in 2001 as senior database administrator and moved into the enterprise engineering group as a systems engineer in 2006. She has more than ten years of experience administrating, developing on and securing Microsoft SQL server along with a strong background in programming (C, VB, ASP, PHP) and web server administration and security. Ms. Corwin holds a master's degree in information systems management along with the following industry certifications: MCSE (Microsoft Certified Systems Engineer), MCDBA (Microsoft Certified Database Administrator).

Security as a Service: Where are we now and where are we going

Length:
45 minutes
Overview:

John Pescatore is a Vice President and Research Director at Gartner Group in the area of Network Security.

Speaker:

Doug Dexter, Audit Team Lead, Cisco Systems

Doug Dexter has been with the Cisco Systems Corporate Information Security Department for ten years. During his tenure he has done everything from maintain the internal firewalls to lead architecture development for a variety of enterprise-wide solutions. As the Team Lead for Cisco's internal PKI deployment, he built a team of people and solutions to provide certificates and sign the production code for IP phones, call managers, and cable modems. For the past four years Doug has been Cisco's internal Audit Team Lead, responsible for a global team of auditors who handle Cisco's acquisitions, vulnerability assessments, and site assessments. Prior to working at Cisco, Doug was active duty in the US Army for 11 years and is currently a Major in an Army Reserve Information Assurance unit. He holds an MBA from the University of Texas at Austin with a concentration in Information Systems, Controls, and Assurance, and is a CISM, CISA, and CISSP-ISSMP.

Security as a Service: Where are we now and where are we going

Length:
45 minutes
Overview:

Speaker:

Josh Lemos, Senior Security Analyst, CNET

Josh Lemos is the Senior Security Analyst for CNET Networks, the organization behind dozens of technology focused web properties. In his primary role, he provides in-house security consulting services for software development teams both domestically and internationally across the entire collection of CNET-owned URLs. Mr. Lemos is tasked with the timely assessment of thousands of custom-written web applications in addition to traditional host vulnerability assessment, network penetration testing, and audits of the underlying web infrastructure. During high-profile attacks, he leads a team of rapid response security professionals that specialize in neutralizing in-progress attacks. Prior to CNET, Mr. Lemos honed his attack and penetration tradecraft as the Director of Consulting Services for Special Ops Security, a private information security assessment firm made up of former Foundstone alumni. He has earned a Bachelor of Science degree in Information Systems from the University of San Francisco as well as the CISSP and other industry-specific certifications.

Security as a Service: Where are we now and where are we going

Length:
45 minutes
Overview:

John Pescatore is a Vice President and Research Director at Gartner Group in the area of Network Security.

Speaker:

John Pescatore, Vice President, Gartner

John Pescatore is a Vice President and Research Director at Gartner Group in the area of Network Security. He has 22 years experience in computer, network and information security. Prior to joining Gartner Group, John was Senior Consultant for Entrust Technologies and Trusted Information Systems, where he started, grew and managed security consulting groups focusing on firewalls, network security, encryption and Public Key Infrastructures. Prior to that, John spent 11 years with GTE developing secure computing and telecommunications systems. John began his career at the National Security Agency, where he designed secure voice systems, and the United States Secret Service, where he developed secure communications and surveillance systems. He holds a Bachelor's degree in Electrical Engineering from the University of Connecticut and is a NSA Certified Cryptologic Engineer. He is an Extra class amateur radio operator, callsign K3NT.

Security as a Service: Where are we now and where are we going

Length:
45 minutes
Overview:

Demonstrating a unique mix of technical vision, marketing and business acumen, Philippe Courtot has repeatedly built innovative companies into industry leaders. As CEO of Qualys, Philippe has worked with thousands of companies to improve their network security. In 2004, Philippe received the SC Magazine Editor's Award for bringing on demand technology to the network security industry and for co-founding, with former White House advisor Howard Schmidt, the CSO Interchange to provide a forum for sharing information in the security industry.

Speaker:

Philippe Courtot, Chairman & CEO, Qualys

Philippe Courtot is the chairman and CEO of Qualys, Inc. a leading provider of on demand vulnerability management.

Demonstrating a unique mix of technical vision, marketing and business acumen, Philippe Courtot has repeatedly built innovative companies into industry leaders. As CEO of Qualys, Philippe has worked with thousands of companies to improve their network security. In 2004, Philippe received the SC Magazine Editor's Award for bringing on demand technology to the network security industry and for co-founding, with former White House advisor Howard Schmidt, the CSO Interchange to provide a forum for sharing information in the security industry.

Before joining Qualys, Philippe was the Chairman and CEO of Signio, an electronic payment start-up that he repositioned to become a significant e-commerce player. In February 2000, VeriSign acquired Signio for more than a billion dollars. Today, VeriSign's payment division, based on the Signio technology, handles 30% of electronic transaction in the U.S., processing $100-million in daily sales. Prior to Signio, Philippe was President and CEO of Verity, where he re-engineered the company to become the leader in enterprise knowledge retrieval solutions. Under Philippe's direction, the company completed its initial public offering in November 1995. Philippe also turned an unknown company of 12 people, cc:Mail, into the dominant e-mail platform provider, achieving a 40% market share while competing directly against IBM and Microsoft. Acknowledging the market leading position of cc:Mail and the significance of e-mail in corporate environments, Lotus acquired the company in 1991. In 1986, as CEO of Thomson CGR Medical, a medical imaging company, Philippe received the Benjamin Franklin award for his role in the creation of a nationwide advertising campaign promoting the life-saving benefits of mammography. Philippe served on the Board of Trustees for The Internet Society, an international non-profit organization that fosters global cooperation and coordination on the development of the Internet. French and Basque born, he holds a Masters Degree in Physics from the University of Paris, came to the US in 1981 and has lived in Silicon Valley since 1987.

Security as a Service: Where are we now and where are we going

Length:
45 minutes
Overview:

Philippe Courtot is the chairman and CEO of Qualys, Inc. a leading provider of on demand vulnerability management.

Speaker:

Wolfgang Kandek, Chief Technical Officer, Qualys

As the CTO for Qualys, Wolfgang is responsible for product direction and all operational aspects of the QualysGuard platform and its infrastructure. Wolfgang has over 20 years of experience in developing and managing information systems. His focus has been on Unix-based server architectures and application delivery through the Internet. Prior to joining Qualys, Wolfgang was Director of Network Operations at the Online Music streaming company myplay.com and at iSyndicate, an Internet media syndication company. Earlier in his career, Wolfgang held a variety of technical positions at EDS, MCI and IBM. Wolfgang earned a Masters and a Bachelors degree in Computer Science from the Technical University of Darmstadt, Germany.

Security as a Service: Where are we now and where are we going

Length:
45 minutes
Overview:

As Vice President of Engineering, Ken is responsible for developing anddeploying Qualys' suite of SaaS solutions. He brings to Qualys over 22 years of experience building and scaling core internet infrastructure. Ken was most recently at Google through the acquisition of Postini where he was Vice President of Engineering responsible for building its messaging security and management systems. Before Postini, he was Vice President of Engineering at VeriSign where he developed and managed its cryptographic, PKI and payments systems. Earlier in his career he held engineering management positions at VISA International and GTE Government Systems. Ken earned a Bachelor of Science degree in Computer Science and a Bachelor of Architecture degree from Cal Poly, San Luis Obispo.

Speaker:

Ken Okumura, Vice President of Engineering, Qualys

As Vice President of Engineering, Ken is responsible for developing anddeploying Qualys' suite of SaaS solutions. He brings to Qualys over 22 years of experience building and scaling core internet infrastructure. Ken was most recently at Google through the acquisition of Postini where he was Vice President of Engineering responsible for building its messaging security and management systems. Before Postini, he was Vice President of Engineering at VeriSign where he developed and managed its cryptographic, PKI and payments systems. Earlier in his career he held engineering management positions at VISA International and GTE Government Systems. Ken earned a Bachelor of Science degree in Computer Science and a Bachelor of Architecture degree from Cal Poly, San Luis Obispo.

Security as a Service: Where are we now and where are we going

Length:
45 minutes
Overview:

Philippe Courtot is the chairman and CEO of Qualys, Inc. a leading provider of on demand vulnerability management.

Speaker:

Amer Deeba, Chief Marketing Officer & VP of Product Marketing, Qualys

Responsible for branding, product management and customer relations activities, Amer has a proven track record in driving company growth in fast moving technology fields. Amer came to Qualys from VeriSign, where he was the General Manager for the Payment Services Division, and helped establish VeriSign as a leader in the online payments space - where 40% of all credit card transactions were processed by VeriSign across the Internet. Amer joined VeriSign as part of its acquisition of online payments pioneer Signio, where he served as Director of Product Marketing. Prior to VeriSign and Signio, Amer spent five years at Adobe where he led the development of Web-enabling PDF. Before that, he held a variety of technical and management positions at Verity, and Amdahl. Amer earned MS and BS degrees in Computer Sciences.

Security as a Service: Where are we now and where are we going

Length:
45 minutes
Overview:

Speaker:

David French, Director of US Field Operations, Qualys

David overseas the US Field Operations team at Qualys, responsible for delivering proactive IT security and compliance solutions to large multinational organizations. The US Field Operations team executes on account management and growth, development of customer requirements, new product introduction to the market, and continuous customer education. Prior to joining Qualys, David was a Senior Security Consultant for Ernst & Young, where he performed security assessments, threat and vulnerability analysis, and architectural reviews for Fortune 500 clients. David is a frequent presenter on topics related to information security and audit at conferences and for professional organizations. David holds the CISSP, CISA, and SANS GIAC industry certifications. David earned his Bachelors of Science in Business Administration with a special focus on Information Systems Audit and Control.