Presentations from Securosis analysts at conferences and events.
Our discussion of the PCI Council’s Tokenization Information Supplement.

Tokenization Guidance (PDF)
From the AppSec US 2010 OWASP conference.
This is a reference page for database events commonly captured in the Audit Logs for major relational database platforms.
This presentation provides and executive summary of XML security issues: XML_SecurityOverview.pdf
Our presentation on Building A Web Application Security Program. This was presented as supplementary material to the white paper of the same name.
This is a quick presentation Rich gave at an ISSA/ISACA meeting in June, 2009.
Our presentation on Building A Web Application Security Program. This was presented as supplementary material to the white paper of the same name.
Presentation on Data Breaches and Encryption.
Our presentation on Information Centric Data Security and the Data Centric Security Lifecycle.
This Presentation, called Data Security Lifecycle and Standards, and sometimes Data Security in the Enterprise, covers basic data security considerations for all aspects of data as it is used across the enterprise. This is an overview presentation.
Understanding and Selecting a Database Activity Monitoring Solution. This presentation is a companion to the white paper of the same name.
Integrating Penetration Testing into a Web Application Security Program.
This is a presentation specific to things you can do to improve Oracle Database Security when budgets are tight.
Presentation on Securing Mobile Data and mobile media.
This presentation covers SIM, SEM, and Log Management solutions and how they aid in compliance efforts.
This presentation, Understanding and Selecting a Data Loss Prevention Solution, is a companion to the white paper on the same subject.
This presentation provides an overview of how to attack the data security problem, with a focus on practical techniques.
This is a presentation to complement the Business Justification for Data Security whitepaper.