Summary

Peter H. Gregory

Peter H. Gregory, CISA, CISSP, DRCE, is a career technologist, published author, public speaker, and commentator in the fields of data security, business security, and business use of technology. He is an expert on a wide variety of business and technology issues including:

  • Protection of corporate assets, both physical and information-based
  • Compliance with U.S. laws including Sarbanes Oxley 404, CA SB 1386, and HIPAA
  • Compliance with international standards such as ISO17799, ISO27001, and PCI
  • Management of SAS70 service provider audits
  • Security policy, controls, education, and business process
  • Key business processes that support security, including change and configuration management, vulnerability management, identity management, access management, and the software development life cycle
  • Business continuity planning and disaster recovery planning, including pandemic contingency planning
  • Lead instructor, University of Washington certificate program on Information Security

He is currently employed as a security and risk manager in a U.S.-based financial services management organization.

 

Industry Certifications

  • CISSP (Certified Information Systems Security Professional), 2000
  • CISA (Certified Information Systems Auditor), 2002
  • DRCE (Disaster Recovery Certified Expert), 2008

 

Published Author

Mr. Gregory has published twenty books on security and technology, including:

  • IT Disaster Recovery Planning for Dummies
  • Solaris Security
  • Blocking Spam and Spyware for Dummies
  • Securing the Vista Environment
  • Computer Viruses for Dummies
  • Biometrics for Dummies
  • VoIP Security for Dummies
  • CISSP Guide to Security Essentials
  • CISA All-In-One Study Guide

 

Expert Witness

Mr. Gregory was an expert witness (Amicus Curiae) in a U.S. federal prosecution of a cybercriminal in 2006.

 

Published Articles

He has written over twenty articles in publications including:

  • Computerworld
  • BusinessWeek
  • SearchSecurity
  • Software Magazine
  • Dark Reading Daily, where his analysis of the TJX 10-K filing topped their “Best of the Web” listing

 

Interviews

Mr. Gregory is regularly interviewed for industry news articles. His comments have been quoted in:

  • Computerworld
  • CIO Magazine
  • Information Security Magazine
  • Tech Republic
  • C|Net News
  • Seattle Times
  • Direct Marketing Association

 

Event Speaker

He has also spoken at numerous security conferences throughout the United States, including:

  • RSA
  • SecureWorld Expo
  • West Coast Security Forum
  • Washington Technology Industry Association
  • InfraGard
  • Western Pension and Benefits Conference
  • Veritas Worldwide User Conference
  • International Gaming Business Exposition

As an event speaker, Mr. Gregory is effective and entertaining whether the audience is highly technical or highly non-technical.

 

Advisory Boards

Mr. Gregory is on several advisory boards, including:

  • InfraGard, the Evergreen State (Washington) Chapter
  • University of Washington certification program for Information Assurance and Cyber Security, one of the first such programs certified by the National Security Agency
  • University of Washington certificate program for Information Security
  • SecureWorld Expo Conference
  • SearchSecurity, a TechTarget property

 

Community Work

He is also involved in various community service efforts, including:

  • Founder and manager of several international online communities, some numbering over two thousand members
  • Co-founder and group manager for the Pacific CISO Forum
  • Proctor at CISSP certification exams (retired)
  • Developer of CISA and CISSP certification exam questions (retired)
  • Graduate of the FBI Citizens’ Academy
  • Member of the FBI Citizens’ Academy Alumni Association

 

Trade Association Memberships

Mr. Gregory is a member of the following trade associations, including:

  • Pacific CISO Forum
  • InfraGard
  • (ISC)² (International Information Systems Security Certification Consortium)
  • ISACA (Information Security Audit and Control Association)
  • CTIN (Computer Technology Investigators Network)
  • The Internet Society
  • Partnership for Regional Infrastructure Security
  • Puget Sound Alliance for Cyber Security
  • Worldwide Executive Council, CISO Forum