David Mortman is the Chief Security Architect for enStratus and a former SearchSecurity.com contributor. Most recently he was the Director of Security and Operations for C3, LLC. Formerly the Chief Information Security Officer for Siebel Systems, Inc., David and his team were responsible for Siebel's worldwide IT security infrastructure, both internal and external. He also worked closely with Siebel's product groups and the company's physical security team and is leading up Siebel's product security and privacy efforts. Previously, Mr. Mortman was Manager of IT Security at Network Associates, where, in addition to managing data security, he deployed and tested all of NAI's security products before they were released to customers. Before that, Mortman was a Security Engineer for Swiss Bank. Mr. Mortman is a regular speaker at RSA, Blackhat, Defcon. In the past year, he has presented at RSA, SourceBoston, Secure360, Sector and BSides San Francisco. Mr. Mortman sits on a variety of advisory boards including Qualys, Lookout and Reflective amongst others. He holds a BS in Chemistry from the University of Chicago.
Contributions from David Mortman, Contributor
- How to use COBIT for compliance
- Security compliance predictions for 2010: New regulatio
- Compliance strategy: How to become an internal IT audit
- Disaster recovery and business continuity tabletop exercises
- Personally identifiable information guidelines for U.S. passport numbers
- How to encrypt data-at-rest to meet the HITECH act regulations
- Encryption of mobile devices under Massachusetts data protection law
- Benefits of ISO 27001 and ISO 27002 certification for y
- PCI DSS questions: Should full credit card numbers be on a receipt?
- FTC Red Flags Rules: How to create an identity theft pr
- Creating a HIPAA employee training program
- How to choose the best IT security certification for pen testing jobs
- How serious is (ISC)2 about its code of ethics?
- PCI DSS compliance requirements: Ensuring data integrit
- How to perform an enterprise risk analysis
- Information security management hype: Debunking best pr
- What is the best security training to advance a career in IT security?
- How to prepare for a FERPA audit
- Why doesn't the CISSP cover information assurance and DIACAP?
- Monitoring program data and internal controls for risk
Security Management Strategies for the CIO