CSO Advisory Board \ Overview

The Qualys CSO Advisory Board is composed of industry security leaders, whose real-world expertise in forging security policies and implementing security best practices, help guide the strategic direction in the further development of Qualys's vulnerability management web service.

Howard A. Schmidt \ Former Special Adviser for Cyberspace Security, White House

Howard A. Schmidt has had a long distinguished career in defense, law enforcement and corporate security spanning almost 40 years. He has served as Vice President and Chief Information Security Officer and Chief Security Strategist for online auction giant eBay. In the fall of 2004 he assumed the position of Chief Security Strategist for the US CERT Partners Program for the National Cyber Security Division. He retired from the White House after 31 years of public service. He was appointed by President Bush as the Vice Chair of the President's Critical Infrastructure Protection Board and as the Special Adviser for Cyberspace Security for the White House in December 2001. He assumed the role as the Chair in January 2003 until his retirement in May 2003.

Prior to the White House, Howard was chief security officer for Microsoft Corp., where his duties included CISO, CSO and forming and directing the Trustworthy Computing Security Strategies Group.

Before Microsoft, Mr. Schmidt was a supervisory special agent and director of the Air Force Office of Special Investigations (AFOSI) Computer Forensic Lab and Computer Crime and Information Warfare Division. While there, he established the first dedicated computer forensic lab in the government.

Before AFOSI, Mr. Schmidt was with the FBI at the National Drug Intelligence Center, where he headed the Computer Exploitation Team. He is recognized as one of the pioneers in the field of computer forensics and computer evidence collection. Before working at the FBI, Mr. Schmidt was a city police officer from 1983 to 1994 for the Chandler Police Department in Arizona.

Mr. Schmidt served with the U.S. Air Force in various roles from 1967 to 1983, both in active duty and in the civil service. He had served in the Arizona Air National Guard from 1989 until 1998 when he transferred to the U.S. Army Reserves as a Special Agent, Criminal Investigation Division where he continues to serve. He has testified as an expert witness in federal and military courts in the areas of computer crime, computer forensics and Internet crime.

Mr. Schmidt had also served as the international president of the Information Systems Security Association (ISSA) and the first president of the Information Technology Information Sharing and Analysis Center (IT-ISAC). He is a former executive board member of the International Organization of Computer Evidence, and served as the co-chairman of the Federal Computer Investigations Committee. He is a member of the American Academy of Forensic Scientists. He serves as an advisory board member for the Technical Research Institute of the National White Collar Crime Center, and was a distinguished special lecturer at the University of New Haven, Conn., teaching a graduate certificate course in forensic computing.

He served as an augmented member to the President's Committee of Advisors on Science and Technology in the formation of an Institute for Information Infrastructure Protection. He has testified before congressional committees on computer security and cyber crime, and has been instrumental in the creation of public and private partnerships and information-sharing initiatives. He is regularly featured on CNN, CNBC, and Fox TV as well as a number of local media outlets talking about cyber-security.

Mr. Schmidt has been appointed to the Information Security Privacy Advisory Board (ISPAB) to advise the National Institute of Standards and Technology (NIST), the Secretary of Commerce and the Director of the Office of Management and Budget on information security and privacy issues pertaining to Federal Government information systems, including thorough review of proposed standards and guidelines developed by NIST.

Howard holds board positions on a number of corporate boards in both advisory and director positions.

Mr. Schmidt holds a bachelor's degree in business administration (BSBA) and a master's degree in organizational management (MAOM) from the University of Phoenix. He also holds an Honorary Doctorate degree in Humane Letters.

Larry L. Brock \ Chief Information Security Officer, DuPont

Larry Brock directs information technology security initiatives and operations globally at E. I. DuPont de Nemours. His 27-year IT career at DuPont includes broad business experience across the global science and technology company, including Corporate IT and the Imaging, Fibers and Nylon business units. He has led the development and implementation of several large systems such as manufacturing product control, materials management, engineering maintenance, quality management, and data warehouse. Brock spearheaded DuPont's migration to open-based systems for networking and computing. He also led development and deployment of several imaging based systems, including a patented system to electronically move radiographs between hospitals and remote physicians. Prior to DuPont, Brock was an information security officer in the U.S. Air Force at the National Security Agency. He served 26 years in the reserves and retired as a Lt Colonel. Brock has Bachelor and Master degrees in electrical engineering.

Jaime Chanaga \ Chairman, The CSO Board, LLC

Jaime Chanaga, CISSP, CISA, is a leading executive, consultant, speaker, author, and information security management professional. He has served organizations such as Ameritech, Lucent Technologies, CA, Geisinger Health System, McDonald's Corp, the American Medical Association and other Fortune 500 organizations. Jaime sits on SC Magazine's Editorial Advisory Board and engages in frequent technology industry conferences. He is Chairman, of The CSO Board LLC, a security management consulting firm. Previously he served as Chief Information Security Officer (CISO) for the Geisinger Health System where he was responsible for protecting the electronic medical records of over 2.3 million patients. Because of his leadership, Geisinger received an InfoWorld Top 100 Award for their secure medical records systems in 2004. Prior to this, Chanaga was Lead IT Security Specialist at OAG.com. Jaime is actively involved in the business community and serves as a Member of InfraGard. Chanaga is a co-author of the book "Corporate Security in the Information Age: Industry Leaders on Security Options, Protecting Assets, & Implementing a Strategy."

Dennis Devlin \ Former Chief Security Officer, The Thomson Corporation

During his tenure at Thomson, Devlin led Thomson's information security and privacy program, as well as corporate-wide initiatives in identity management and directory services. The Thomson Corporation is a leading global provider of integrated information-based solutions to business and professional customers. Devlin has more than 35 years of information technology leadership experience in private industry and higher education. Before Thomson, Devlin filled multiple IT leadership roles at Harvard University and served on higher education technology advisory councils for major manufacturers such as Microsoft, IBM and Apple. Devlin graduated from the University of Pennsylvania, has lectured at the UCLA Anderson School of Management, Babson College Center for Information Management Studies, University of Massachusetts Strategic Information Technology Center, and at many industry conferences.

Stephen Hansen \ Information Security Consultant

Stephen E. Hansen is currently acting as adviser and consultant in the fields of information, computer, and network security. Previously, Mr. Hansen served as information security officer at Google, the world's premier information search web service, where he was responsible for all aspects of information security and privacy. Prior to that, Hansen served as the computer security officer at Stanford University, where he maintained and improved the level of computer and network security through security infrastructure and program oversight, policy and procedure development, education, and incident handling and resolution. Hansen has specialized in computer security since 1986, including extensive work with federal and local law enforcement, and computer incident response teams around the world. Hansen frequently speaks about digital security at industry conferences and workshops. He has B.S. and M.S. degrees in electrical engineering from Stanford University, and belongs to IEEE, ACM, Sigma Xi, Sage and Usenix.

Lisa (LJ) Johnson \ Global Information Security Manager, Nike, Inc.

LJ Johnson defines and drives Nike's worldwide security program, including technology architecture, policy management, regional implementation, security awareness and global operations. Nike is one of the world's largest makers of footwear, apparel, sports equipment and accessory products. Johnson's work in information security spans two-thirds of her 18-year career in information technology. She is the founding president of the Portland, Oregon Chapter of ISSA. Johnson is also on the ITT Technical Advisory Board for the Information Systems Security academic program and is a mentor for women and minority students enrolled in the CASE program at Portland Community College. Johnson holds the Ethics Chair for the Generally Accepted Information Security Principles (GAISP) Working Group. She has a B.S. degree from the University of Wisconsin, a Certificate of Management Studies in Science and Technology from the Oregon Graduate Institute, and Information Systems Security Professional Certification (CISSP).

Daniel Klinger \ Manager of Information Executive, Hershey Foods Corporation

Daniel Klinger leads information security efforts at Hershey Foods Corporation, the world's largest chocolate candy company selling more than 50 brands in over 90 countries. His responsibilities include implementing industry-leading security policies, standards and practices to ensure the confidentiality, integrity and availability of Hershey's critical information assets. Klinger also has pioneered IT security assessment and documentation processes at Hershey that satisfy auditor requirements for corporate compliance with the Sarbanes-Oxley Act. His career in information security spans 13 years, including safeguards for network and application security. Klinger is a Certified Information Security Manager (CISM).

Dr. John I. Meakin \ Group Head of Information Security, Standard Chartered Bank

John Meakin leads a global information security team at Standard Chartered Bank, one of the world's most international banks with 30,000 employees in more than 50 countries and a management team comprised of 70 nationalities. Meakin has 18 years of experience in information systems security. His specialty is better modeling and managing the costs and benefits of security for large businesses, particularly enabling dynamic management and monitoring instead of traditional static prevention processes. Previously, Meakin led systems security policy and strategy for Reuters, the Royal Bank of Scotland, Swiss Bank Corporation, and the investment-banking arm of Dresdner Bank. Meakin has also provided information security consultancy support to several blue chip clients aimed at improving systems security and effectiveness. He has a Ph.D. in experimental solid state physics from Cambridge University, plays football regularly and builds computers in his spare time. Meakin is a regular speaker at industry conferences and public forums.

Paul Simmonds \ Global Information Security Director, Imperial Chemical Industries Plc.

Paul Simmonds heads up information security for ICI, working from corporate headquarters in London. ICI makes ingredients for paints, foods, fragrances and personal care products with 36,000 employees worldwide. He has an extensive background in security. Prior to ICI, Simmonds was head of information security for a high security European web hosting company and served seven years in a global security role at Motorola. His career includes work with many external government agencies, including the FBI, Scotland Yard, Wiltshire Computer Crime and Wiltshire Child Protection. He has directly contributed to successful criminal prosecutions. Simmonds has a prior background in IT systems implementation and consulting during which he wrote and implemented one of the UK's first web sites in 1992. He is a founding member of the Jericho Forum, a group of large multinational organizations working together to define the common security issues from "de-perimeterisation". Simmonds has a degree in Electronic Engineering.

Andreas Wuchner \ Head of Global IT Security, Novartis

Andreas Wuchner, CISO, CISSP, is Head of Global IT Security at Novartis Pharmaceuticals where he leads IT Security and Security Emergency Response globally across the corporation. In this role he and his team are responsible for the planning and supervision of Novartis' worldwide computer and network information security systems, defining the company's IT security policies & standards and enhancing the security of Novartis IT services and global infrastructure.

He has more than 12 years of experience managing all aspects of information technology management, with deep expertise in rapidly changing, highly demanding large-scale environments. Prior to joining Novartis Pharmaceuticals, Andreas worked for Ciba Geigy and IBM on various IT projects covering all aspects of information technology.

Andreas is a regular speaker on numerous aspects of information risk management and IT security practices from a pharmaceutical business viewpoint. Recent speaking engagements include security seminars in Europe, Asia and USA.

He represents Novartis on strategic executive advisory boards of several leading security industry companies including Symantec Corporation, Microsoft and Qualys. Andreas holds a bachelor degree in Electronics and Computer Science from the University of Applied Sciences in Offenburg in Germany.