BEGIN:VCALENDAR
VERSION:2.0
PRODID:Data::ICal 0.24
BEGIN:VEVENT
DESCRIPTION:   'Title: Challenges in Control Validation\n   When: Saturday\
 , Aug 13\, 15:00 - 15:59 PDT\n   Where: Flamingo - Savoy Ballroom - BTV Ma
 in Stage (In-person) - [1]Map\n   Speakers:Jake Williams\,Kristen Cotten\,
 AJ King\n\n   SpeakerBio:Jake Williams\n   Jake Williams is the Executive 
 Director of Cyber Threat Intelligence\n   at SCYTHE. Williams is an IANS F
 aculty Member and also works as a SANS\n   Analyst. He is a prolific speak
 er on topics in information security\n   and has trained thousands of peop
 le on incident response\, red team\n   operations\, reverse engineering\, 
 cyber threat intelligence\, and other\n   information security topics. Jak
 e is the two time winner of the DC3\n   Digital Forensics Challenge\, a re
 cipient of the DoD Exceptional\n   Civilian Service Award\, and is one of 
 only a handful of people to ever\n   be certified as Master Network Exploi
 tation Operator by the US\n   Government.\n   Twitter: [2]@MalwareJake\n\n
    SpeakerBio:Kristen Cotten\n   Kristen is a Cyber Threat Intelligence An
 alyst at SCYTHE. Prior to\n   joining the herd she worked for the United S
 tates Department of the\n   Army in various roles ranging from network and
  system administration\n   to vulnerability management and cyber complianc
 e. She has a penchant\n   for solving technical puzzles\, leaping from per
 fectly good airplanes\n   (or cliffs)\, and finding the best local hole-in
 -the-wall restaurants.\n   If you want to talk about foreign travel\, spor
 ts nutrition\, or why\n   Episodes 4-6 are the only Star Wars movies that 
 matter\, she's your\n   girl!\n\n   SpeakerBio:AJ King\n   No BIO availabl
 e\n\n   Description:\n   Sample panel questions may include:\n   How is co
 ntrol validation different from red teaming? Isn’t control\n   validatio
 n just purple teaming? (it’s not) How do you recommend my\n   organizati
 on starts its first control validation exercise? What’s\n   you #1 recom
 mendation for maturing a control validation program? What\n   are methods 
 for scaling control validation programs? How much\n   validation is too mu
 ch? When is the cost no longer justified?\n\n   Testing security controls 
 is hard. Really hard. Every incident\n   responder has lived with victims 
 who are sure existing security\n   controls should have prevented or detec
 ted the intrusion. While some\n   organizations don’t do any security co
 ntrol validation\, those that\n   do understand the challenges. While red 
 team operations allow for\n   point-in-time validation\, how are organizat
 ions dealing with control\n   validations during product updates or config
 uration changes? By and\n   large the answer is “they aren’t.” On th
 is panel\, we’ll\n   discuss why control validation is difficult. Then w
 e’ll discuss\n   recommendations for scaling control validation operatio
 ns in\n   practically any organization.\n\n   '\n\n   1. https://defcon.ou
 tel.org/consolidated_page.html#FlamingoThirdFloor\n   2. https://twitter.c
 om/MalwareJake\n\n\n
DTEND:20220813T225900Z
DTSTART:20220813T220000Z
LOCATION:BTV - Flamingo - Savoy Ballroom - BTV Main Stage (In-person)
SUMMARY:Challenges in Control Validation
END:VEVENT
END:VCALENDAR
