SaaS identity security poses unique challenges for businesses and their CISOs. The rapid adoption of new apps and decentralized acquisition process of SaaS makes it difficult to apply traditional cybersecurity frameworks that assume the company controls the endpoint, network access, or authentication method. This leaves businesses vulnerable to data breaches and other security threats. The Cloud Security Alliance has developed a best practices guide for SaaS security, which requires a different governance mindset and the implementation of robust identity and access management strategies. Gartner suggests that identity has become the ultimate control point in a world where data is accessible from anywhere. As such, businesses must prioritize their SaaS security efforts to ensure they can leverage the productivity and scale benefits of SaaS without exposing themselves to undue risks. CISOs must lead this effort, working with business leaders and IT teams to develop and implement effective SaaS security strategies that protect their company's valuable data assets.
CISO
CISO Council
How SaaS Identity Risk is Transforming Cybersecurity
Speakers & Visionaries
May 23, 2023
Attend this event
Agenda
All times Eastern Time
3:00 PM - 4:15 PM
How SaaS Identity Risk is Transforming Cybersecurity
Panelists
Lior Yaari
CEO & Co-Founder
Grip Security
Dustin Sachs
Sr. Manager, Governance Risk & Compliance
World Fuel Services
Nancy Good
Director, Delivery Excellence
Knights of Columbus
Sai Iyer
CISO
Ziff Davis
Tim Swope
CISO
Catholic Health System
Mr. Swope brings over 20 years of experience in IT Project Management, BI Solutions Development, IT Security, IT Controls (CoBIT, SOX 404/MAR, etc) IT Risk Management, and HealthCare Compliance, to both the public and private sectors. His focus is on identifying gaps relating to key IT security processes and the implementation of IS Security and Risk Management programs to Health Care, Pharmaceutical and various commercial clients.
Has a proven track record of delivering the following:
• Interpreting and applying 21 CFR Part 11, GLP, GMP, GCP, and QSR regulations
• MDM and Data Governance
• Identity Access Management
• HIPAA Risk Assessments and GAP analysis
• Information Assurance Program Management - SCRUM, AGILE, SDLC, Six Sigma
• Implemented large security, risk and compliance initiatives of SOX-404 IT, HIPAA/HITECH, including security policies, procedures and controls.
• "Big Data", Data Management and Health Care Data Analytics
• Federal Information Security Management Act (FISMA) Compliance Reviews
• Implemented the security standards - 45 CFR Parts 160, 162, and 164 Health Insurance Reform: Security Standards; Final Rule
He has supported these Information Assurance and IS Security initiatives for organizations that include: Excellus BCBS, Medimmune/Astra Zeneca, ENDO Pharmaceuticals, Novo Nordisk, Daiichi-Sankyo Solutions, Catalent Pharma Solutions, Johnson and Johnson, District of Columbia Government office of the Chief Financial Officer, District of Columbia Water and Sewer Authority, City of Richmond, Virginia Department of Public Utilities, Virginia State Department of Health, and the Kentucky Department of Health Services, as well as the U.S. Department of Labor.