Mr. Thomas Parenty,
Managing Director, Parenty Consulting Limited
   
  Biography
 

Thomas Parenty has over twenty years of experience in the computer security and cryptography fields, including employment with the National Security Agency.  He has designed and evaluated the information security protection of numerous national and global systems, including those for banking, electronic commerce, healthcare, and nuclear command and control.  In addition, Parenty has designed security features in enterprise applications that are currently used by governments and businesses across the globe.         

Mr. Parenty has testified five times before the United States Congress on global competitiveness, national security, law enforcement, and encryption.  In addition, he has served as an advisor to the National Academy of Sciences and the Presidentˇ¦s Commission on Critical Infrastructure Protection.  Harvard Business School Press published Parenty's book, Digital Defense: What You Should Know About Protecting Your Companyˇ¦s Assets.  His consulting practice currently focuses on the enablement of electronic commerce and the protection of intellectual property in Asia.
   
  Topic - Breakout 2.2
  Sacrificing the Possible for the Perfect: Why ISO27001 Undermines Security
   
Abstract

The security community has long recognized that technologies, such as encryption and passwords, can't by themselves protect a company, its information or its computer systems. And so there is a recognized need for organizations to apply policies and a unified framework to addressing their information security needs. However, the process of developing polices and Information Security Management Systems can easily become unwieldy, draining corporate resources and interest, without substantively improving the state of security. This presentation will discuss the fundamental elements that make security policies actionable. Covering topics from data classification to end user behavior to outsourcing, we'll examine the core security issues and provide guidance on developing effective policy.