Thomas R. Peltier CISSP
Wyandotte, MI 48192
Career Summary
I am in my fifth decade of computer technology. During this time I
have shared my experiences with fellow professionals and because of
this work I have been awarded the 1993 Computer Security Institute's
(CSI) Lifetime Achievement Award. In 1999 the Information Systems
Security Association (ISSA) bestowed its Individual Contribution to
the Profession Award and in 2001 I was inducted into the ISSA Hall of
Fame. I was also awarded the CSI Lifetime Emeritus Membership Award.
Currently I am the President of Thomas R. Peltier Associates, LLC
information security training and consulting firm. Prior to this I
was Director of Policies and Administration for the Netigy
Corporation's Global Security Practice. I was the National Director
for Consulting Services for CyberSafe Corporation, the Corporate
Information Protection Coordinator for Detroit Edison. The security
program at Detroit Edison was recognized for excellence in the field
of computer and information security by winning the Computer Security
Institute's Information Security Program of the Year for 1996. I
previously was the Information Security Specialist for General Motors
Corporation where I wrote the Information Protection Policies and
Practices (IPP&P) manual and created the accompanying worldwide
awareness program.
Thomas R. Peltier Associates, LLC, President
Thomas R. Peltier Associates, LLC is an information security training
and consulting firm. We conduct training on topics of risk
management, policies, standards, procedures, network vulnerability
assessments, fundamentals of information security and CISSP prep
courses. These courses have been conducted throughout the United
States and Canada as well as four other continents. We also provide
consulting services for the ten information security domains.
Netigy Corporation, Director, Global Security Practice
I helped integrate security services and solutions into the Netigy
Corporation suite of offerings. I implemented training processes for
employee, consultant and sales personnel. These educational processes
ensured that consultants were adequately trained in services prior to
deployment at client sites. Sales personnel were familiarized with
the products and services and educated in terminology and in assessing
client needs. I refined the techniques for policy and procedure
development and the Facilitated Risk Analysis and Assessment Process
(FRAAP) became based on the ISO 17799. I managed the Total Information
Protection Strategies (TIPS) team, consisting of seven senior subject
matter experts. I helped establish a consultant training program to
prepare personnel to sit for the Certified Information Systems
Security Professional (CISSP) exam.
CyberSafe Corporation, National Director for Consulting Services
I developed consulting services for CyberSafe. The consulting
services included conducting network security assessments using a top-
down, bottom-up approach. Other services that were offered included
reviewing and critiquing enterprise information/computer security
programs and working with clients to develop their information
security policies, standards, guidelines and procedures. A key
security process that I developed and implemented was the Facilitated
Risk Analysis Process (FRAP). The FRAP is a qualitative process that
allows organizations to identify risk and threats, prioritize those
concerns and then identify cost-effective safeguards to mitigate those
risks.
Detroit Edison, Supervisor, Information Protection (Corporate
Information Protection Coordinator and Corporate Emergency Management
Coordinator)
I implemented the development of a Corporate Information Protection
Program including the examination of control requirements during the
applications development life cycle (Facilitated Business Impact
Analysis, Facilitated Risk Analysis Process), the enhancement of the
business continuity planning function to encompass all corporate
business units, the formation and maintenance of an incident response
team to manage virus and security exposure control, and the definition
of non-disclosure agreements and contract personnel controls to ensure
the protection of Detroit Edison proprietary assets. This program was
recognized for excellence by winning the Computer Security Institute's
Information Security Program of the Year for 1996.
Blaier & Associates, President
Provided specialized consulting services in the development of
information and computer security awareness programs. Primary clients
included the Department of Justice, Computer Security Society of
Mexico, and Computer Security Institute.
General Motors, Senior Staff Analyst (Corporate Information Security
Specialist)
I developed the information security program for General Motors
Corporation that included the development, implementation and
maintenance of information protection policies, training of local
information security liaisons and a corporate employee awareness
program.
Chevrolet-Pontiac-Canada Group, Information Security Officer
Developed and implemented an information security program to function
in conjunction with out-sourced data processing activities. I
established a control environment in association with Electronic Data
Systems (EDS) to ensure the protection of corporate information within
the Chevrolet-Pontiac-Canada Group. This program affected over
200,000 employees in the United States, Canada and Mexico.
Chevrolet Engineering Center (CEC), Computer Operator, Programmer,
Systems Analyst, Information Systems Security Officer
In addition to responsibilities suggested by listed job titles, I
developed an information security program for approximately 4500
employees within CEC. This program included the implementation of
policies, procedures, and employee awareness training.
Affiliations / Accomplishments
Former Chairman, Computer Security Institute (CSI) Advisory Council
Chairman, 18th Annual CSI Conference
Published The Complete Manual of Policies and Procedures for Data Security
Auerbach Publications published Information Security Policies and
Procedures: a Professional Reference in 1999 Information Security Risk
Analysis in 2001 the Second Edition in 2005 and the Third Edition in 2010.
Information Security Policies, Standards and Procedures in 2002 and the
Second Edition in 2004. How to Manage a Network Vulnerability Assessment
in 2002 and Information Security Fundamentals in 2004 and How to Complete a
Risk Assessment in 5 Days or Less in 2008.
Co-author of the 2007 Complete Guide to CISM Certification.
Working on Information Security Fundamentals, Second Edition (due out in
2010).
Contributing author and editor of the 2002 The Total CISSP Exam Prep Book;
and contributing author to the Computer Security Handbook, Third and Fifth
Editions and Data Security Management.
Conduct numerous presentations and seminars on various security topics for
CSI, American Institute of Banking (AIB), the American Institute of
Certified Public Accountants (AICPA), Institute of Internal Auditors (IIA),
EDP Auditors Association (EDPAA), MIS Training Institute, Sungard Planning
Solutions and AKA Associates (UK).
Developed and conducted extensive training seminars and workshops
including:
Practical Methods for Risk Analysis
Social Engineering: Low Tech Hacking
Identity Theft: How to Combat it and Include it in Your
Security Program
Information Assurance
Rapid Deployment of an Asset Classification Program
Developing Computer Security Policies and Procedures
e-mail Security
Computer Crime and Industrial Espionage
Introduction to Computer Security
Information Security Concepts
Conducting a Vulnerability Assessment
Building an Information Security Awareness Program
Business Continuity / Disaster Recovery
Technical Advisor to Commonwealth Films, Boston, MA in production of
nationally distributed films including "Locking the Door", "Virus:
Prevention, Detection, Recovery", "Back in Business" and other security
awareness and training films.
Founder, Southeast Michigan Computer Security Special Interest Group, at
the time one of the largest information security professional organizations
in the U.S.
Worked at Fraser High School 1985 - 1995 as assistant director for drama
Taught the Information Security curriculum for a Master's Certificate at
Eastern Michigan University
Currently an Adjunct Professor at Norwich University in the Information
Assurance masters program.