If you are interested in attending any of the events listed on this page, you must identify your interest during the Conference Registration process. There is no additional cost for attending these sessions. If you have already registered and want to add one of these sessions to your registration, please click on the registration link and log in. Once logged in, click on the User Account icon and then click continue. From there you can select the event(s) you would like to add. Please note: identifying your interest in a session does not guarantee you a seat, it only indicates your interest in attending.
ISB-001: Innovation Sandbox
1:00 PM – 5:30 PM
Innovation Sandbox is an exciting half-day program where you can explore new technologies and meet the innovators that promise to transform the information security industry, now and in the future. Innovation Sandbox will feature sessions such as:
Open to Delegate and Expo Plus registrants only.
RSA® Conference offers a full day of seminars at no additional charge to full Conference Delegates.
SEM-001: Security Basics Seminar – Full Day
8:30 AM – 4:30 PM
Overview:
The Security Basics Seminar explains some of the most important security principles and technologies designed for practitioners with three years or less of information security experience or those new to the field. It is engineered to lay a foundation of essential concepts that will enhance your understanding of the more advanced security issues that will be discussed during the week. The seminar will feature some of the giants of the security industry today.
| Start Time | End Time | Title | Speaker |
| 8:30 AM | 8:45 AM | Introduction | Hugh Thompson, Program Committee Chairman, RSA Conference |
| 8:45 AM | 9:30 AM | Security Industry and Trends | Hugh Thompson, Program Committee Chairman, RSA Conference |
| 9:30 AM | 10:15 AM | Viruses, Malware and Threats | Uri Rivner, Head of Cyber Strategy, BioCatch |
| 10:15 AM | 10:30 AM | Break | |
| 10:30 AM | 11:15 AM | Governance, Risk and Compliance | Justin Peavey, SVP Information Services & Security, CISO, Omgeo |
| 11:15 AM | 12:00 PM | Application Security | Jason Rouse, Security Architect, Bloomberg LP |
| 12:00 PM | 1:15 PM | Break | |
| 1:15 PM | 2:00 PM | Crypto 101/Encryption Basics, SSL & Certificates | Ben Jun, Vice President and Chief Technology Officer, Cryptography Research, Inc. a Rambus Company |
| 2:00 PM | 2:45 PM | Mobile and Network Security | Paul Youn, Technical Director, iSEC Partners Marc Blanchou, Senior Security Consultant, iSEC Partners |
| 2:45 PM | 3:00 PM | Break | |
| 3:00 PM | 3:45 PM | Authentication Technologies | Bill Duane, Distinguished Engineer, RSA Office of the CTO, RSA, The Security Division of EMC |
| 3:45 PM | 4:30 PM | Firewalls and Perimeter Protection | Bill Cheswick, Researcher, cheswick.com |
| 4:30 PM | Seminar Adjourns |
SEM-003: Information Security Leadership Development: Surviving as a Security Leader Seminar – Half Day
8:30 AM – 11:30 AM
Overview:
In conventional security training, there are few opportunities to learn how to develop and direct a successful information security program. Experienced security leaders deliver a morning seminar focused on bridging this gap.
| Start Time | End Time | Title | Speaker |
| 8:30 AM | Intro | ||
| 8:35 AM | 9:10 AM | Maturity Lifecycle of a Security Program | John Iatonna, SVP, Information Security, Edelman, Inc. |
| 9:10 AM | 9:40 AM | Building Your Team | Justin Peavey, SVP Information Services & Security, CISO, Omgeo |
| 9:40 AM | 10:15 AM | Role of the CISO: Influence & Decision Support | Derek Brink, Vice President and Research Fellow, IT Security, Aberdeen Group, a Harte-Hanks Company |
| 10:15 AM | 10:30 AM | Break | |
| 10:30 AM | 11:00 AM | Are You Fighting the Wrong Battles? | Bob Rudis, Director Enterprise Information Security and IT Risk Management, Liberty Mutual Insurance |
| 11:00 AM | 11:30 AM | CISO Roundtable: Security Intelligence Gathering for Leaders | Evan Wheeler, Director, Information Security, Omgeo John Iatonna, SVP, Information Security, Edelman, Inc. Derek Brink, Vice President and Research Fellow, IT Security, Aberdeen Group, a Harte-Hanks Company Bob Rudis, Director Enterprise Information Security and IT Risk Management, Liberty Mutual Insurance James Burrell, Deputy Assistant Director, Federal Bureau of Investigation Dave Notch, President, Intensity Analytics |
| 11:30 AM | Seminar Adjourns | ||
| 12:00 PM | 1:00 PM | Break |
SEM-004: Advancing Information Risk Practices Seminar – Half Day
1:00 PM – 4:30 PM
Overview:
Many challenges face today’s Risk Management programs, including how to risk rank security gaps, handling business interactions, and building a qualified resource pool. This half day seminar will be packed with practical information from a series of respected industry leaders who have set out to challenge conventional ideas and pursue cutting edge tactics, discussing successes and pitfalls.
| Start Time | End Time | Title | Speaker |
| 12:00 PM | 1:00 PM | Break | |
| 1:00 PM | 1:55 PM | Risky Business: Quantifying Risk in the Absence of Statistical Data | Brook S.E. Schoenfield, MBA, GWEB Speaker, Principal Software Security Architect, McAfee, Inc. |
| 1:55 PM | 2:45 PM | Risk Management: The Perspective of the Business Stakeholder | Douglas Graham, Sr. Director, Risk Management, EMC Corporation |
| 2:45 PM | 3:00 PM | Break | |
| 3:00 PM | 3:50 PM | Educating the Next Generation of Information Security Risk Managers | Richard Caralli, Technical Director, CERT Cyber Enterprise and Workforce Management Directorate |
| 3:50 PM | 4:30 PM | Automation and Risk Management, Do They Mix? | Evan Wheeler, Director, Information Security, Omgeo Richard Caralli, Technical Director, CERT Cyber Enterprise and Workforce Management Directorate Doug Graham Sr. Director, Risk Management, EMC Corporation Brook S.E. Schoenfield, MBA, GWEB Speaker, Principal Software Security Architect, McAfee, Inc. Ben Tomhave, Principal Consultant, LockPath |
| 4:30 PM | Seminar Adjourns |
RSA® Conference offers association events at no additional charge to all pass types.
![]() |
CSA Summit – The Next Generation |
CSA's fourth summit will once again feature industry luminary keynotes and top experts debating key cloud security issues. Expanded research includes provider certification, mobile, Big Data, threats, software-defined networking and more. The next generation of the Infosec industry is here. The summit features the following keynotes and panels:
National Security and the Cloud, Mark Weatherford, Deputy Under Secretary for Cybersecurity, Department of Homeland Security; Tech Innovation, Macroeconomics and the Future Security Mandate, Jim Robinson, former AmEx CEO and Wall Street Legend; Why the Cloud Manages Security Better Than You Do, Dave Asprey, Vice President of Cloud Security, Trend Micro
Panels: Managing Enterprise Global Security in an era of Hybrid Cloud and Smart Mobile; Mobile Security Insights
CSA Speed Talk: CSA STAR – an Update on Cloud Provider Transparency and Certification, Jim Reavis, Executive Director, CSA; Revolutionary Evolution – The Internet of Things, Jerry L. Archer, Board Member, CSA
![]() |
OWASP: Approaching Secure Code – Where do I start? |
Instructors: Jim Manico, OWASP;
Eoin Keary, OWASP
Overview:
Regardless of your chosen/mandated framework for building web applications: Spring, Struts, Rails, PHP, Python, etc., you want to make your life easier, and potentially less embarrassing. Don't be the one who left the door open for hackers. Learn handy tips from one of the world's leading AppSec experts.
![]() |
TCG: Trusted Computing: Billions of Secure Endpoints in 10 Years |
Speakers: Phyllis Lee, IAD Security Automation Program Manager, National Security Agency;
Charles Kolodgy, Research Vice President IDC.
Eric Ogren, Founder, Ogren Group;
Paul Roberts, Editor in Chief, Security Ledger.
Phil Schacter, Managing Vice President, Gartner;
Steve Venema, Associate Technical Fellow, The Boeing Company
Overview:
The Trusted Computing category is now widespread with support from governments, developers and users across the globe. As the technology's flagship security advocate and the creator of industry security standards, the Trusted Computing Group (TCG) approaches its 10th anniversary at RSA Conference 2013 with a look at current and emerging applications for trusted systems.
Opening with a provocative keynote focused on the day-to-day security challenges in a complex, many-user, sprawling enterprise environment, with some insight into the role of trusted systems.
Sessions to follow include
One of the industry's most thoughtful analysts on malware, advanced persistent threats and other security challenges, Charles Kolodgy, IDC, will address today's and tomorrow's threats and lead a panel of users and technologists on the pros and cons of various solutions. Industry participants will follow to talk about:
Phil Schacter, Managing Vice President, Security and Risk Management, Gartner for Technical Professionals, will highlight network security trends from an industry perspective, featuring:
This session will include input from industry panelists around TNC deployment, leveraging the TCG IF-MAP protocol for monitoring and TPM-based strong identity in mobile devices.
Eric Ogren, Ogren Group, will lead a third session focused on data protection.
Also make sure to catch a host of demonstrations that employ a variety of TCG technologies, including SEDs for data protection, network security and multi-factor authentication and assurance. Register now to join us for this exciting event!
| Start Time | Session | Speaker |
| 10:00 AM | Welcome and Opening Remarks | Brian Berger, Trusted Computing Group Director |
| 10:05 AM | Keynote Session: Top 10 Priorities in IT Security for the County of Los Angeles and the Importance of Industry Standards | Robert Pittman, MPA, CISM Chief Information Security Officer County of Los Angeles |
| 10:30 AM | Panel Session: Advanced Persistent Threats and NIST SP 800-147 and NIST SP 800-155 | Moderator: Paul Roberts, Editor in Chief, Security Ledger Panelists: Frank Molsberry, Technologist Office of the CTO, Dell Stacy Cannady, Distinguished Technologist, DMI Sunil Gottumukkala, Principal Lead Program Manager, Microsoft Dave Waltermire, Specification Architect, Security Automation Program, NIST |
| 11:15 AM | Networking Break and Demonstration Showcase | |
| 11:30 AM | Panel Session: Network Security, Critical Infrastructure and BYOD | Moderator: Phil Schacter, Managing Vice President, Gartner Panelists: Phyllis Lee, IAD Security Automation Program Manager, NSA Steve Venema, Associate Technical Fellow, The Boeing Company Bob Thibadeau, Chief Scientist, Wave Systems Corp. |
| 12:15 PM | Lunch and Demonstration Showcase | |
| 1:00 PM | Panel Session: Protecting Content from Unauthorized Access | Moderator: Eric Ogren, Founder, Ogren Group Panelists: Jon Rolf, Technology Lead, NSA Michael Willett, Michael Willett, Samsung Hussein Syed, Director of IT Security, Barnabas Health Clain Anderson, Director of Software, Lenovo |
| 1:45 PM | Closing Remarks and Raffle Drawing | |
| 1:55 PM | Networking Break and Demonstration Showcase |
![]() |
(ISC)2® Half Day CSSLP® Credential Clinic |
Instructor: Mano Paul, Software Assurance Advisor, (ISC)²
Overview:
Software must be developed with security in mind in order to defend and mitigate hackers. We all know this is critical but now is the time to ensure it happens. In this clinic, we will cover two of the seven domains from the CSSLP certification that ensures that security is considered for each phase of the software lifecycle. The CSSLP is for everyone involved in the SDLC with at least 4 years' experience.
![]() |
(ISC)2® Half Day CISSP® Credential Clinic |
Instructor: Mano Paul, Software Assurance Advisor, (ISC)²
Overview:
The CISSP is a globally recognized objective measure of excellence and is considered the gold standard in information security. The vast breadth of knowledge and the experience it takes to pass the exam is what sets the CISSP apart. For those information security professionals that are considering becoming a CISSP, (ISC)² is offering a FREE half-day credential clinic that will tackle two of the most intense domains of the CISSP. The clinic is taught by an authorized (ISC)² Instructor and is taught in the same manner as our Official Review Seminars, utilizing the course materials. Space is limited. Register today.