Day 1

  

Wednesday, April 4, 2012

1:00PM - 5:30PM
WORKSHOP 1: Control Environment Operations 101
It can be quite an eye opener for an IT security professional stepping into the fray of control system technology for the first time. Finding the right balance for implementing IT security concepts within the industrial control systems takes as much art as it does science. There is no doubt awareness of the control operations is an essential ingredient to a successful ICS security program. This workshop will explore the basic components of control systems and how they are used in day to day control system operations. Participants should expect to come away with a greater knowledge of ICS devices such as PLCs and RTUs, a sense of how important each component is to the reliability of the system and a general understanding of the differences between control system security and IT security.

1:00PM - 5:30PM
WORKSHOP 2: Operation Security: A View Into Offensive techniques & tactics
This workshop will explore a number of techniques that can be employed during Factory Acceptance Testing (FAT), Site Acceptance Testing (SAT) and other areas of utility operations. Methods and techniques will be covered to identify common, existing vulnerabilities in control systems. Additionally, the workshop will explore techniques that are currently being used to exploit these vulnerabilities in the wild. Participants should expect to take away a better understanding of how to approach these topics with current and future vendors prior to deployment, as well as identify opportunities to perform validation testing in-house once systems have been deployed.

1:00PM - 5:30PM
WORKSHOP 3: Red Team Exercise
A Red Team is a group of penetration testers who asses the security of an organization. The organization is often unaware of the exact goals of the team and most employees are unaware that they have been hired. This workshop will introduce the basic concepts of a Red Team exercise, discuss the benefits of this activity and review various case studies. Participants should expect to have a better understanding of the security advantages of performing a Red Team exercise, increased knowledge of the techniques and equipment used by red team testers and general idea of how to implement a Red Team program in their organization.

Day 2

Thursday, April 5, 2012

7:00AM - 10:30AM
Registration Opens -- Continental Breakfast and Networking

8:45AM - 9:00AM
9:00AM - 9:30AM
Keynote Presentation

9:45AM - 10:30AM
Existing and Emerging Threats to the Energy and Power Industry:
The effectiveness of the activities vendors, utilities, and stakeholders in general partake in as we work towards securing the Smart Grid are difficult to gauge without metrics. What is particularly challenging today is trying to determine what to measure, and against what baseline. Join this session for an open discussion about establishing and auditing Smart Grid security metrics, and what value we hope to derive from them.

10:15AM - 10:30AM
Networking Break - In Exhibit Area

10:15AM - 11:00AM
Cyber Security Metrics
The effectiveness of the programs, solutions and processes implemented by vendors, enterprises and supply chain partners are difficult to quantify without an adequate structure and system for measurement. What is particularly challenging today is to determine what to measure, and against what baseline. This session offers discussion about establishing and auditing security metrics, and what value we hope to derive from them.

10:30AM - 10:45AM
Networking Break -- Exhibit Area

10:45AM - 11:30AM
Case Study: Lessons Learned from the Utility Sector
This first of several Case Studies details the challenges, internal decision-making process and outcomes from a recent cyber security strategic plan. Understand where this company met with success and where it did not, and use their lessons in formulating your enterprise security plan.

12:25PM - 12:45PM
LIGHTNING ROUND: Situational Awareness
These are brief, powerpoint free presentations from individuals espousing a specific slant on the topic at hand, with key points and concepts to differentiate from other perspectives.

12:45PM - 1:30PM
Hosted Lunch Break

2:00PM - 2:45PM
Track 1: Defining A Technical Reference Architecture For Smart Grid Security

2:00PM - 2:45PM
Track 2: Intrusion Detection in the SCADA and Industrial Control Systems

2:00PM - 2:45PM
Track 3: Security Policy: Adapting Security Policy for Today’s Threats

2:00PM - 2:45PM
Track 4: Access Management

2:45PM - 3:30PM
Track 1: Addressing the security risks of increased interconnectivity

2:45PM - 3:30PM
Track 2: ICS Defense Success Story

2:45PM - 3:30PM
Track 3: Future Compliance in the Energy Sector: What’s on the Horizon

2:45PM - 3:30PM
Track 4: Practical Approaches to Information Access Risk

3:30PM - 3:45PM
Networking Break - In Exhibit Area

4:00PM - 4:45PM
Track 1: Demand Response: Is it worth the potential security risks?

4:00PM - 4:45PM
Track 2: Control Network Isolation Strategies

4:00PM - 4:45PM
Track 3: Dealing with Residual Risk

4:00PM - 4:45PM
Track 4: Managing Supplier and Supply Chain Partner Access

4:50PM - 5:30PM
Track 1: An explanation of Syncrophaser Security Solutions

4:50PM - 5:30PM
Track 2: Vulnerability Assessment Approach for ICS Environments

4:50PM - 5:30PM
Track 3: What Regulation Can and Cannot Do

4:50PM - 5:30PM
Track 4: Identifying and Managing Network Zones

5:30PM - 6:30PM
Hosted Reception

Day 3

Friday, April 6, 2012

7:00AM - 9:00AM
Registration Opens, Continental Breakfast and Networking

8:45AM - 9:00AM
9:00AM - 9:30PM
Morning Keynote Address

9:30AM - 10:30AM
CISO ROUNDTABLE:
This roundtable discussion features leading CISOs from various sectors of the energy and power industry as they offer insight and experience on the current threats to the energy sector and the suite of solutions and operational changes to mitigate risk.

10:30AM - 10:45AM
Networking Break -- In Exhibit Area

10:45AM - 11:30AM
Case Study: Lessons Learned from the Oil/Gas Sector
This first of several Case Studies details the challenges, internal decision-making process and outcomes from a recent cyber security strategic plan. Understand where this company met with success and where it did not, and use their lessons in formulating your enterprise security plan.

11:30AM - 12:15PM
Cyber Response Exercise: A Coordinated Approach To An Advanced Cyber Attack
A coordinated public-private response to an advanced cyber attack through next generation methods and technologies encapsulated in a new notion of Security Operation Centers for the Smart Grid. Asset owners, vendors, and government are continuously working to develop and improve the cybersecurity of smart grid systems. Our diligent efforts are necessary to proactively reduce, mitigate or even thwart cyber attacks against the smart grid resulting in minimal disruptions to consumers, businesses, federal agencies, and the Nation. A key element to addressing a cyber attack is our ability to detect and respond to an event in a timely manner. Join this session where representatives from the public and private sectors will walk us through a simulated and an intelligent coordinated response to an advanced cyber attack

12:15PM - 12:45PM
LIGHTNING ROUND: Compliance or Security – What is the Best Strategy?
These are brief, powerpoint free presentations from individuals espousing a specific slant on the topic at hand, with key points and concepts to differentiate from other perspectives.

12:45PM - 1:45PM
Hosted Lunch

2:00PM - 2:45PM
Track 1: Automation at What Cost?

2:00PM - 2:45PM
Track 2: Host Intrusion Prevention Concepts: Beyond HIPS

2:00PM - 2:45PM
Track 3: Managing the Risk of a Roaming Workforce

2:00PM - 2:45PM
Track 4: Physical Security Facility Practices

2:45PM - 3:30PM
Track 1: Security as an Integrated Activity

2:45PM - 3:30PM
Track 2: Applying Engineering Discipline to ICS Security

2:45PM - 3:30PM
Track 3: Aware Person System

2:45PM - 3:30PM
Track 4: Common Approaches for Video Surveillance

3:30PM - 4:00PM
Track 1: Researcher’s Perspective: Smart Grid Vulnerability Year in Review

3:30PM - 4:00PM
Track 2: Revisiting Reliability Considering Current Attack Vectors

3:30PM - 4:00PM
Track 3: Cloud Service: Your Friend or Enemy?

3:30PM - 4:00PM
Track 4: Designing a Physical Access Control System

4:00PM - 4:00PM
Conference Concludes

Industry Buzz