Location: NIST Campus in Gaithersburg, Maryland
Registration: (click here)
Agenda: (Conference Agenda)
Conference Flier: (Flier)
Time: 8:30am - 5:00pm both days.
Conference Purpose:
Implementing cost-effective, risk-based information security programs
continues to be a top priority for federal, state, and local
governments as well as private sector enterprises. Improving the
security of information systems and demonstrating compliance to laws,
directives, regulations, standards, and guidance can present some unique challenges to organizations. These challenges can include, for example, the selection and implementation of appropriate security controls for information systems and the associated compliance-related activities to demonstrate security control effectiveness.
This conference and workshop presents business needs, projects, and
integration efforts that propose to automate certain technical aspects
of an organization's information security program. These automation
efforts include, for example, converting English text contained in
various security-related publications (i.e., NIST SP 800-53, DISA
STIGs, configuration guides, checklists, etc) into machine readable
formats (e.g., XML/XCCDF and OVAL). The objective of such automationefforts is to provide a common understanding and semantic context for organizations and individuals using scanning tools and
checklists/configuration guides and auditors conducting assessments of security control effectiveness. The end result will promote the use of
commercial off-the-shelf (COTS) tools to automatically check the
security properties of information systems and effectively map to security compliance requirements.
Who Should Attend?
- Professionals responsible for the management or operational components of
information security and the automation thereof.
- Product vendors concerned with security and various policy compliance
issues for their clients (including FISMA).
- Enterprise Developers, Infrastructure and Software Architects, Software
Engineers, Web Developers, and Web Development Managers.
To register online (click here) or please contact:
teresa.vicente@nist.gov
301.975.3883
If you are having trouble accessing online registration, (click here) |