CSA HKM Knowledge Sharing Event – January 2017

CSA Knowledge Sharing Event provides an excellent opportunity for cybersecurity professionals to discuss the latest trends and developments in IT and in the process build a close-knitted cybersecurity community in Hong Kong and Macau.

This month we have invited Mr Jeffrey Lau, Platform Lead of Ribose to deliver a talk entitled “Management of SaaS-specific risks”.

TOPIC:

SaaS providers have exploded in numbers in recent years. Practically every organization today has adopted SaaS services in one way or another. However, given the ease of adoption, coupled with a consumer-driven and instant gratification mindset, organizations often onboard SaaS services without necessary precaution and scrutiny.

By nature of the cloud, SaaS services are subject to much greater threats than traditional IT. Without proper management of SaaS risks, SaaS services can easily become the weakest link in your organization, potentially endangering organization survival. In this session, we will enumerate risks and mitigation measures of adopting SaaS services from the cloud customer’s perspective to help protect your organization from SaaS-specific threats.

Presented by Jeffrey Lau, co-lead of the privacy practice at Ribose and member of CSA’s SaaS Governance workgroup, this session explains the notion of SaaS-specific risks including privacy risks, and best practices in managing them in this age of uncertainty.

THE SPEAKER

Jeffrey is Ribose’s Platform Lead, responsible for service-wide improvements of the Ribose secure collaboration platform. With a decade of software engineering experience, he holds bachelors and masters degrees in Computer Science from the University of Cambridge. He is passionate in protecting individual privacy rights, particularly on the privacy impact of technology as well as methods to mitigate them through technology. Jeffrey is a part of the CSA SaaS Governance and Internet of Things working groups, serves technical committees at the OpenID Foundation and is a lead auditor in information security management systems (ISO/IEC 27001), IT service management (ISO/IEC 20000-1) as well as business continuity management systems (ISO 22301).

Please do not miss this opportunity to learn from the expert and get connected with your peers.

Participants can claim 1.5 CPE.

DATE: January 5, 2017 (Thursday)

TIME: 4:30 – 6:30 pm

VENUE: Room Z414, Core Z, The Hong Kong Polytechnic University, Hung Hom

 

CSA HKM Knowledge Sharing Event – November 2016

Two months ago, we have organized an introductory talkabout Software Defined Network. As SDN and NFV play an important role in IaaS Cloud computing, we would like to organize another talk about SDN.

This month we have invited Mr Ian Christofis, Managing Principal Consultant of Thales Critical Information Systems and Cybersecurity to deliver a talk entitled “Security Implications of Software Defined Networking and Network Function VIrtualisation”.
In this talk, the speaker will talk about the security implications of Software Defined Networking (SDN) and Network Function Virtualisation (NFV). This session will briefly introduce SDN and NFV, and why these technologies are important, then discuss the pros and cons of SDN & NFV from a security perspective.

Please do not miss this opportunity to learn from the expert and get connected with your peers.

Participants can claim 1.5 CPE.

DATE: November 10, 2016 (Thursday)

TIME: 4:30 – 6:30 pm

VENUE: Room Z409, Core Z, The Hong Kong Polytechnic University, Hung Hom

SPEAKER:

Mr Ian Christofis, Managing Principal Consultant, Thales Critical Information Systems and Cybersecurity

TOPIC:

Security Implications of Software Defined Networking and Network Function Virtualisation

THE SPEAKER:

Ian is a specialist in information security (cryptographic security, Public Key Infrastructure (PKI), identity & access management, smart cards, risk management, etc), personal data privacy and electronic commerce. He combines a strong understanding of the commercial and strategic business issues with a detailed knowledge of the technology. He is Managing Principal Consultant with Thales, driving security consulting and professional services for Thales security products in APAC.

CSA HKM Knowledge Sharing Event – September 2016

Cloud computing is the trend for delivering IT environment for new business operations.

This month we have invited Mr Roger Chung, Managing Director of Maximus Contulting to deliver a talk entitled “Cloud Security: A Business Transformation Perspective”.

In this talk, the speaker will talk about the security implications in different business perspective when consider cloud adoption or migration, such as Strategy planning, Technology architecture, Solution framework, Operation control & process, CyberSecurity prevention & protection, and last but not the least, Policy and Governance compliance.

The speaker will also share cases that would provide insights on the importance of information security measures in Enterprise Cloud Infrastructure and Application.

DATE: September 8, 2016 (Thursday)

TIME: 6:30 – 8:30 pm

VENUE: Room Z414, Core Z, The Hong Kong Polytechnic University, Hung Hom

SPEAKER: Mr Roger Chung, Managing Director, Maximus Consulting

TOPIC: Cloud Security: A Business Transformation Perspective

THE SPEAKER: Roger Chung is a 25-years veteran of the technical and business consulting industry. He has track record growing small and medium size companies with process reinvention and innovation in technology. He grew a leading security vendor, Valicert in Asia from essentially zero to over US$2 Million in less two year, then established Maximus, one of the first pioneer in information security compliance and security services provider since year 2003.

As the CEO of Maximus, Roger is responsible for business strategy, overall financial and operational management. He has grown Maximus’s revenue by a factor of 10 and established the company as a one-stop service provider for information security the past decade.

Please do not miss this opportunity to learn from the expert and get connected with your peers.

Participants can claim 1.5 CPE.

register-button_0

 

CSA HKM Knowledge Sharing Event – August 2016

Office 365 (O365) is getting more popular daily. According to the latest financial news updates, Microsoft has a huge growth in their cloud business. O365 is definitely one of the driving force in this SaaS business segment. In Hong Kong, many individuals as well as corporates switched to use Office 365 in their personal as well as business purpose.

Traditionally, SaaS system is considered to be solely managed and controlled by the Cloud Service Providers. However, in the Microsoft environment, O365 has a number of built-in security features implemented and also have a number of security features that user can enable in their business version of O365.

In this talk, Microsoft representative – Andy Fung will talk about the underlying built-in security features in O365 as well as how Microsoft address major concerns about security, privacy, and compliance. Best practices for corporate in using O365 will also be covered. Through this talk, corporate administrator can also learn how to manage their O365 securely.

DATE: August 4, 2016 (Thursday)

TIME: 4:30 – 6:30 pm

VENUE: Room Z414, Core Z, The Hong Kong Polytechnic University, Hung Hom

SPEAKER: Mr Andy FUNG, Account Technology Strategist, Microsoft

TOPIC: How to securely configure and use Office 365 from enterprise perspective?

THE SPEAKER: Andy Fung has been in the IT services industry for 17+ years and possesses experience in range of enterprise system integration. He joins Microsoft for ~9 years and worked as a technology consultant for Public sector, including Government, and Educations sector. He plays an influencer role to business and technical decision people on technology adoption with referenced guidelines, recommendations, and policy.

Please do not miss this opportunity to learn from the expert and get connected with your peers.

Participants can claim 1.5 CPE.

register-button_0

CSA HKM Knowledge Sharing Event – July 2016 (Revised)

CSA Knowledge Sharing Event provides an excellent opportunity for cybersecurity professionals to discuss the latest trends and developments in IT and in the process build a close-knitted cybersecurity community in Hong Kong and Macau.

The original talk by Mr Erick Borsboom, Security Lead of Ribose, on “Linux Operation System Hardening for Cloud Images and Containers” will be replaced by a presentation on how to achieve ISO 27017 from Ronald Tse, founder of Ribose who is the first organisation to receive certifications for both ISO27017 and ISO 27018.
ISO/IEC 27017 and ISO/IEC 27018 are the latest international standards relating to security in the cloud. Given that different cloud security assurance schemes already exist, including the authoritative CSA STAR programs, what do these new standards mean, to the cloud service user and to the cloud service provider? How do different assurance schemes compare?
In this talk, Ronald will dive into these standards and their background to discover the benefits they bring and how they affect the assurance landscape.

DATE: July 14, 2016 (Thursday)

TIME: 4:30 – 6:30 pm

VENUE: Room Z414, Core Z, The Hong Kong Polytechnic University, Hung Hom

SPEAKER: Mr Ronald Tse, founder of Ribose

TOPIC: Experience sharing on achieving ISO 27017 and 27018

THE SPEAKER: Ronald TSE, founder of Ribose

Please do not miss this opportunity to learn from the expert and get connected with your peers.

Participants can claim 1.5 CPE.

Participated in HK Computer Society Networking Hour

Thanks a lot for Dennis Lee, HKCS CCSIG Chairperson, in inviting us to participate in the wonderful networking event on 30 Jun 2016. It was a good opportunity for me to meet with old and new friends as well as listening to the talk by Thomas Lee on Intercloud computing.

Hopefully, in the future, we can jointly organise events with HKCS together as well.

13512073_1224051460940810_8911746459217328358_n

CSA HKM supports BSI Cloud Security and Green Data Center Conference 2016

Nowadays, the need for more costeffective storage and software solutions together with mobile access has led to a rise in the adoption of cloud computing.

While the benefits of cloud computing are clear, the flexibility and openness of the cloud computing model has created a number of security concerns about the privacy integrity and availability of data.

In fact, apart of the cyber trust issues, the high running costs of data centre, is also another key problem to data centre owers as the energy cost of data centres is known to make up a significant percentage of a business operating costs.

In this conference, we are going to discuss the latest cyber security and data greening issues, explore the solutions to the above challenges and the latest market information of cloud security and green data centre applications !

DATE: 7 July 2016 (Thursday)

TIME: 9:30am – 5:30pm (Reception starts at 9:00am)

VENUE: Function Rooms, Level 3, Core E Cyberport 3, 100 Cyberport Road Hong Kong

ADMISSION: Free (Refreshment available)

MEDIUM: English

SHUTTLE BUS: Complimentary Tsim Sha Tsui to Cyberport : 8:15am / 8:30am , Admiralty to Cyberport : 8:30am / 8:45am , Cyberport to Tsim Sha Tsui / Admiralty: 5:30pm

Click HERE for detailed agenda.

CSA HKM Knowledge Sharing Event – July 2016

CSA Knowledge Sharing Event provides an excellent opportunity for cybersecurity professionals to discuss the latest trends and developments in IT and in the process build a close-knitted cybersecurity community in Hong Kong and Macau.

This month we have invited Mr Erick Borsboom, Security Lead of Ribose, to deliver a talk entitled “Linux Operation System Hardening for Cloud Images and Containers”.

In this talk, Mr Borsboom will give an overview of hardening best practices for securing Linux operating systems used in cloud images and containers. Best practices covered are NIST standards and DISA/DOD STIG guides, PaX kernel hardening and role based security to avoid passwords and secret keys inside cloud images and containers.

DATE: July 14, 2016 (Thursday)

TIME: 4:30 – 6:30 pm

VENUE: Room Z414, Core Z, The Hong Kong Polytechnic University, Hung Hom

SPEAKER: Mr Erick Borsboom, Security Lead, Ribose

TOPIC: Linux Operation System Hardening for Cloud Images and Containers

THE SPEAKER

Erick Borsboom leads the security practice of Ribose and has over 15 years of experience in cybersecurity, compliance and infrastructure.

Prior to his current role, Erick helped perform major security reviews and protect critical assets of large European government agencies, including law enforcement and infrastructure providers, as well as safeguarding U.S. EAR and ITAR compliance for exports of dual-use technology to embargoed countries in the Middle East in the oil and gas industry.

Please do not miss this opportunity to learn from the expert and get connected with your peers.

Participants can claim 1.5 CPE.

register-button_0

“Security & Privacy on Cloud” Seminar in Macau

Invitation: Office for Personal Data Protection “Security & Privacy on Cloud” Seminar

“Security & Privacy on Cloud” Seminar is organized by the Office for Personal Data Protection, co-organized by Macau New Technology Incubator Centre (Manetic), Macau Computer Emergency Response Team Coordination Centre (MOCERT), ISACA Macao Chapter and Cloud Security Alliance Hong Kong & Macau Chapter. The seminar will be held on June 15, 2016 (Wednesday) with details as follow:

Date:     June 15, 2016 (Wednesday)
Time:     15:00 – 17:00
Venue:   Tourism Activities Centre Congress Hall AB, 2/F Rua Luis Gonzaga Gomes, No 431, Macau

RSVP Here for the event before June 8, 2016(Wednesday).