Phil Agcaoili

From Infogalactic: the planetary knowledge core
Jump to: navigation, search
Phil Agcaoili
Born Flag of the Philippines.svg Philippines
Residence Flag of the United States.svg U.S.
Citizenship Flag of the United States.svg American
Fields Information Technology
Hacker (computer security)
Institutions General Electric
Lockheed Martin
SecureIT
VeriSign
Internet Devices
Alcatel
Scientific-Atlanta
Cisco
Dell
Cox Communications
Elavon
U.S. Bancorp
Alma mater Virginia Tech
Rensselaer Polytechnic Institute
Georgia State University
Known for Leadership
Cybersecurity
Information Security
Privacy
Cloud Computing
Mixed Martial Arts

Phil Agcaoili (also known as philA[1]) is a leader, technologist, entrepreneur, and accomplished cyber security, information security, and privacy expert. He is the Chief Information Security Officer at Elavon,[2] a Senior Vice President at U.S. Bancorp,[3] chairman of the Ponemon Institute Fellows,[4] a Distinguished Fellow of the Ponemon Institute,[5] on the Board of Advisors for the Payment Card Industry (PCI) Security Standards Council (SSC),[6] a Founding Member of the Cloud Security Alliance,[7] co-inventor and co-author of the Cloud Security Alliance Cloud Controls Matrix (CCM),[8] a standards developer for the Electronic Discovery Reference Model (EDRM),[9] on the Board of Directors for Mobile Active Defense,[10][11] and was on the Advisory Boards of Qualys [12] and Rapid7.[13]

Education

Phil Agcaoili graduated from Columbia High School in East Greenbush, New York in 1989, studied aerospace engineering at Virginia Tech in Blacksburg, Virginia, received a Bachelor of Science in mechanical engineering from Rensselaer Polytechnic Institute in Troy, New York in 1993, and attended Georgia State University in Atlanta, Georgia for an MBA in computer information systems. He was inducted into the Mechanical Engineering Honor Society Pi Tau Sigma in 1991[14] at Rensselaer Polytechnic Institute[15] and was inducted into the East Greenbush Education Foundation Hall of Fame in 2011.[16]

Career

Agcaoili started his career at General Electric.

He co-founded and was the Chief Information Security Officer of SecureIT in 1996,[17] which was one of the first pure-play Internet security services providers that was acquired by Verisign in 1998 for $70M.[18] After the acquisition, he became VeriSign's first CISO.[19] He was an early foundation member at Internet Devices, which was acquired by Alcatel in 1999 for $180M.[20] He was the Chief Security Architect [21] at Scientific-Atlanta, which was acquired by Cisco in 2005 for $6.9B.[22]

He co-founded the Southern CISO Security Council in 2006.[23]

While at Dell in 2008, he set security standards for Cloud computing as a Founding Member and Steering Committee member of the Cloud Security Alliance.[24] He co-invented and co-authored the Cloud Controls Matrix (CCM) in 2009[25] (versions 1.0, 1.1, and 1.2), co-founded the GRC Stack in 2010,[26] and co-founded the Security, Trust & Assurance Registry (STAR) in 2011.[27]

Agcaoili was named the Chief Information Security Officer at Cox Communications in 2009.[28]

He has helped shape cyber security best practices for U.S. Telecoms as a committee co-chair for the Federal Communications Commission (FCC) Communications Security, Reliability and Interoperability Council (CSRIC) II [29] Work Group 2A (Cyber Security Best Practices) in 2010,[30] served on the NCTA Cyber Security Work Group as an inaugural member,[31][32] played an instrumental role in 2012[33] in the FCC CSRIC III [34] Work Group 11 (Consensus Cyber Security Controls),[35] served as a committee co-chair for cyber security on the Communications Sector Coordinating Council (CSCC),[36] was a member of the Communications Information Sharing and Analysis Center (Communications ISAC),[37] and was an industry representative on the National Coordinating Center for Communications (NCCC).[37]

He was inducted into the Ponemon Institute as a Distinguished Fellow in 2011[38] and then appointed the Chairman of the Ponemon Institute Distinguished Fellows in 2012.[39][40]

He has been instrumental in shaping United States cyber security efforts.[41][42][43][44][45][46][46][47][48][49][50][51][52] Throughout 2013 he helped the National Institute of Standards and Technology develop the first version of the U.S. Cybersecurity Framework released as the Framework for Improving Critical Infrastructure Cybersecurity on February 12, 2014.[53] In 2013, Agcaoili was appointed as a co-chair for the FCC CSRIC IV Working Group 4 – Cybersecurity Best Practices[54] in order to help operationalize the Framework into practice within the Communications sector by updating and aligning his previous effort co-chairing the FCC CSRIC II Work Group 2A (Cyber Security Best Practices) with the NIST CSF.

In 2013, through a partnership with the Cloud Security Alliance and the American Institute of Certified Public Accountants (AICPA), a team of industry experts and the founder of the Service Organization Control (SOC) released seminal guidance[55] that reshaped how companies demonstrate and attest for their security and privacy practices by incorporating additional subject matter such as the CSA Cloud Controls Matrix in the type 2 SOC2 attestation standard and assessed using the AT 101 proven auditing principles. This replaced the SAS 70 auditing standard and augmented the successor, SSAE 16 SOC 1, to attest for internal controls over financial reporting.

.[56][57]

Agcaoili was appointed the Vice President and Chief Information Security Officer of Elavon in 2014.[2] He serves on the FS-ISAC [58] and on the Payments Processing Information Sharing Council (PPISC).[59]

He was nominated to serve a two-year term on the Board of Advisors of the PCI Security Standards Council in 2015.[60][61]

He has served on the Editorial Advisory Board for TechTarget Security Media Group Information Security Magazine,[62] Advisory Board for CSO Magazine,[63] Advisory Board for CIO Magazine,[64] Governing Body Co-chair for Evanta CISO Leadership Network,[65] Founding Advisory Council for CISO Executive Network in Atlanta,[66] Founding Member and CISO Advisory Council for Wisegate,[67] Advisory Board for the RSA Executive Security Action Forum (ESAF),[68] and Advisory Board for SecureWorld Expo in Atlanta, Houston, and Dallas.[69] He has served 10 times as a judge for the Information Security Executive (ISE®) Awards [70][71][72][73][74][75] and was on the Advisory Board for the Worldwide Executive Council Goldman Sachs CISO Council and the Citibank CISO Council.[76]

Information Security and Cyber Security Industry Contributions

Recognition

References

  1. Lua error in package.lua at line 80: module 'strict' not found.
  2. 2.0 2.1 Lua error in package.lua at line 80: module 'strict' not found.
  3. Lua error in package.lua at line 80: module 'strict' not found.
  4. Lua error in package.lua at line 80: module 'strict' not found.
  5. Lua error in package.lua at line 80: module 'strict' not found.
  6. Lua error in package.lua at line 80: module 'strict' not found.
  7. Lua error in package.lua at line 80: module 'strict' not found.
  8. Lua error in package.lua at line 80: module 'strict' not found.
  9. Lua error in package.lua at line 80: module 'strict' not found.
  10. Board of Directors | Mobile Active Defense
  11. Lua error in package.lua at line 80: module 'strict' not found.
  12. Lua error in package.lua at line 80: module 'strict' not found.
  13. Lua error in package.lua at line 80: module 'strict' not found.
  14. Lua error in package.lua at line 80: module 'strict' not found.
  15. Lua error in package.lua at line 80: module 'strict' not found.
  16. Lua error in package.lua at line 80: module 'strict' not found.
  17. Lua error in package.lua at line 80: module 'strict' not found.
  18. Lua error in package.lua at line 80: module 'strict' not found.
  19. Lua error in package.lua at line 80: module 'strict' not found.
  20. Lua error in package.lua at line 80: module 'strict' not found.
  21. Lua error in package.lua at line 80: module 'strict' not found.
  22. Lua error in package.lua at line 80: module 'strict' not found.
  23. Lua error in package.lua at line 80: module 'strict' not found.
  24. Lua error in package.lua at line 80: module 'strict' not found.
  25. Lua error in package.lua at line 80: module 'strict' not found.
  26. Lua error in package.lua at line 80: module 'strict' not found.
  27. Lua error in package.lua at line 80: module 'strict' not found.
  28. Lua error in package.lua at line 80: module 'strict' not found.
  29. http://transition.fcc.gov/pshs/advisory/csric/wg-2a-members.pdf
  30. Lua error in package.lua at line 80: module 'strict' not found.
  31. http://www.ncta.com/PublicationType/Letter/Joint-Letter-on-Cybersecurity-Legislation.aspx
  32. http://www.ncta.com/PublicationType/MiscellaneousPublication/Suggested-framework-for-cybersecurity-legislation.aspx
  33. Lua error in package.lua at line 80: module 'strict' not found.
  34. Communications Security, Reliability and Interoperability Council III | FCC.gov
  35. http://transition.fcc.gov/bureaus/pshs/advisory/csric3/CSRIC_III_WG11_Report_March_%202013Final.pdf
  36. Lua error in package.lua at line 80: module 'strict' not found.
  37. 37.0 37.1 National Coordinating Center for Communications | Homeland Security
  38. Lua error in package.lua at line 80: module 'strict' not found.
  39. Lua error in package.lua at line 80: module 'strict' not found.
  40. Lua error in package.lua at line 80: module 'strict' not found.
  41. http://www.tripwire.com/state-of-security/regulatory-compliance/phil-agcaoili-nist-framework/
  42. http://csrc.nist.gov/cyberframework/framework_comments/20131125_phil_agcaoli_unaffiliated.pdf
  43. Cybersecurity Leader Offers Alternative Version to NIST Framework ~ DigitalCrazyTown
  44. Comments on NIST framework begin to emerge, echoing longstanding concerns
  45. A Look at NIST’s Preliminary Cybersecurity Framework - Secuilibrium, LLC
  46. 46.0 46.1 http://www.ten-inc.com/lib/2013_NIST_Town_Meeting.asp
  47. Uplogix Local Management Blog: NIST cybersecurity framework development continues
  48. New York Defense and Security Conference Features Session on Exploring the NIST Cybersecurity Framework and Implementation
  49. Protecting Critical Infrastructure: Input Data | Threatpost | The first stop for security news
  50. NIST's cyber framework moves toward implementation stage - FederalNewsRadio.com
  51. NIST concludes cybersecurity framework workshops as agency prepares for Feb. deadline | SmartBrief
  52. Establishing Stronger Standards for Data Breach Protection : Wednesday, October 08, 2014
  53. http://www.nist.gov/cyberframework/upload/cybersecurity-framework-021214-final.pdf
  54. Lua error in package.lua at line 80: module 'strict' not found.
  55. Lua error in package.lua at line 80: module 'strict' not found.
  56. Lua error in package.lua at line 80: module 'strict' not found.
  57. Lua error in package.lua at line 80: module 'strict' not found.
  58. FS-ISAC : Financial Services - Information Sharing and Analysis Center
  59. FS-ISAC - Payments Processing Information Sharing Council (PPISC)
  60. Lua error in package.lua at line 80: module 'strict' not found.
  61. Lua error in package.lua at line 80: module 'strict' not found.
  62. http://docs.media.bitpipe.com/io_12x/io_120388/item_1061312/ISM_Dec_final.pdf
  63. Lua error in package.lua at line 80: module 'strict' not found.
  64. Lua error in package.lua at line 80: module 'strict' not found.
  65. Lua error in package.lua at line 80: module 'strict' not found.
  66. Lua error in package.lua at line 80: module 'strict' not found.
  67. Wisegate's Information Security Pros Join Forces to Counter Escalating Hacker Attacks
  68. Lua error in package.lua at line 80: module 'strict' not found.
  69. Lua error in package.lua at line 80: module 'strict' not found.
  70. Lua error in package.lua at line 80: module 'strict' not found.
  71. Lua error in package.lua at line 80: module 'strict' not found.
  72. Lua error in package.lua at line 80: module 'strict' not found.
  73. Lua error in package.lua at line 80: module 'strict' not found.
  74. Lua error in package.lua at line 80: module 'strict' not found.
  75. T.E.N. - ISE® North America Judges, Speakers and Presenters 2011
  76. Lua error in package.lua at line 80: module 'strict' not found.
  77. http://www.nist.gov/cyberframework/
  78. cloud_computing_security_&_governance-isaca.pdf - File Shared from Box
  79. http://www.ietf.org/mail-archive/text/capwap/2005-05.mail
  80. http://www.ietf.org/html.charters/capwap-charter.html
  81. http://www.tifaware.com/code/update-nessusrc/update-nessusrc-2.10
  82. update-nessusrc
  83. T.E.N. - ISE® Central 2009