HDI Ottawa header   HDI Ottawa header
HDI Ottawa header   HDI Ottawa header
Home

About HDI-Ottawa

Membership

Events

Articles

Newsletters

Industry Resources

Presentations

Contact Us

HDI Ottawa logo

 

Newsletter                                      February 2008

 “Process Integration Between Service Desk and the Security Team”

with

Arnaud Boutoille and John Hersey

 

With the ever increasing complexity of the regulatory and compliance minefield, organizations are struggling with these new challenges.  More business information assets are being accessed from different places (remote workers, wireless, PDA) and in different manners (customer self-help, order entry etc.) than ever before Suppliers and business partners have embedded their systems directly into other organizations (point-of-sale integrated into supplier systems for inventory and warehousing, products being sold through other storefronts, etc.)

The Challenge

Security is a cross-functional responsibility.  There are incidents that are obvious (theft of equipment, virus infections) but there are classes of incidents that have security implications.  A database corruption that requires recovery from back up re-enables previously suspended account access.  Network traffic analysis study commandeers a switch span port thereby disabling the IDS that was using the span port to detect network attack signatures.  Service disruption on a server.  Sys admin disables/uninstalls host IDS or AV agent software.  Syslog servers failed backup.  Compliance requires syslog storage for 180 days on line and 7 years off-line.  Audit discovers two years later that the logs have been overwritten and no evidence is available. 

 Security cannot be involved in every incident but from an escalation perspective, how can the Service Desk reach the resources it needs for complete incident handling?  Process integration between Service Desk and the security team is mandatory. 

 The Objective

 To present the common model and branch out into some scenarios (such as those listed above) of how this issue can be resolved within the small organization, large organizations with in-sourced services and those businesses with outsourced IT.

 

 

Arnaud Boutoille has a background as an Operations Manager for large security operations (servicing businesses with more than 25,000 employees).  He has focused on organizational turnarounds through the development of continuous process improvement paired with financial modeling and activity-based costing. 

 

John Hersey is a security professional with 15 years experience from military command and control systems, to the development of large outsourcing security solutions within the financial services industry vertical ($100M plus).  He has worked throughout the US and Canada for federal and state governments as well as in the private industry, working with customers to develop risk-based security solutions appropriate for their business environments. 

 

We look forward to seeing you at our meeting on February 20, 2008 at 8:00 AM.

 

EBHC_Side_2

 The meeting will be held at the Élisabeth Bruyère Health Centre on Bruyère Street downtown Ottawa.

Patrick Gillin Board Room

There is parking on the street (1 & 2 hour meters) or in the Élisabeth Bruyère Health Centre parking lot.

 

 

 

Theme:

“Process Integration Between Service Desk and the Security Team”

Date:

February 20th , 2008

Registration:

8:00 to 8:30 am

Breakfast:

8:00 to 8:30 am

Meeting Time:

8:30 to 10:00 am

Place:

Patrick Gillin Board Room

Élisabeth Bruyère Health Centre

43 Bruyère St, Ottawa

Parking on street in front & behind the hospital or in the parking lot behind the hospital.

Cost:   Members:

Free

Non-members:

$10 per person for a hot breakfast & meeting

 

Scheduled Meetings

Circle the following dates on your calendar.  We meet on every 3rd

Wednesday morning of the month (except December).  The dates are:

February 20  -

“Process Integration Between Service Desk and the Security Team”

March 19  -

TBD

April 16  -

TBD

May 15  -

(All day conference),   More than last year.  Great speaker list where the theme is:

Invest in the Future

 

R.S.V.P. 

To confirm your attendance e-mail at hdi@magma.ca, fill out on-line Registration form or call us at (613) 860-3330.  We ask you to RSVP at least 24 hours before the meeting.

 

For Questions and Comments hdi@magma.ca