Personal Information Curriculum Vitæ Alessandro Colantonio July 23, 2013 Address.......... B via Silicella 23 int. C6, Roma (Italy); Phone........... H +39 349 1434081; E-mail........... k alessandro@bay31.com; Personal Home Page.... E ricerca.mat.uniroma3.it/users/colanton; Date and place of birth... July 21, 1976, Penne, Pescara (Italy); Nationality........ Italian; Marital status....... Married. Education Ph.D., 2011. Ph.D. in Mathematics at Roma Tre University, Rome, Italy. Thesis: Role Mining Techniques To Improve RBAC Administration. Advanced Studies, 2008. Italian 2 nd level Master in Information Security and Governance (1-year, post Master s Degree) at La Sapienza University, Rome, Italy. Thesis: A Cost- Driven Approach to Role Engineering. Master s Degree, 2001. Computer Engineer (Italian 5-years Laurea Magistrale in Ingegneria Informatica, equivalent to M.Eng./M.Sc.) at University of Pisa, Italy. Thesis: Design and Implementation of a Hard Real-Time, Small Memory Footprint, and Portable Operating System Kernel. Languages Italian. Native language. English. Fluent business and technical English. BULATS certificate C1/4, March 2011 (www.bulats.org/bulats/results.html) IT Security Experience June 2011 present, Founder and CTO at Bay31 AG (www.bay31.com). Development of products to oversee and optimize business processes, and manage the risk associ- 1
ated with user access. Unique application of new techniques for data-mining, pattern recognition and risk management to access governance. April 2006 May 2011, Chief Research & Development Officer at CrossIdeas (www. crossideas.com, formerly Engiweb Security). Design of novel techniques and methodologies for GRC in IAM systems. December 2002 March 2006, Consultant at Accenture, Rome office (www.accenture. com). Main IT security-related activities: Alitalia Servizi (www.alitalia.it). Coordination of Asset Inventory and Risk Assessment activities based on BS 7799 and ISO 17799 standards. Italian Ministry of Health (www.nsis.ministerosalute.it). Design of IT security policies and procedures for the NSIS Project. Ente Tabacchi Italiano (ETI, now BAT, www.bat.com). Asset Inventory and Risk Assessment activities based on BS 7799 and ISO 17799 standards. Research Interest Methodologies and models for GRC (Governace, Risk Management, and Compliance) in Role-Based IAM (Identity & Access Management) systems, focusing on Role Engineering. Data Mining algorithms. Data Compression algorithms. Real-Time Operating Systems mechanisms for Embedded Systems. Office Automation applications. Books [1] Alessandro Colantonio, Roberto Di Pietro, and Alberto Ocello. Role Mining in Business Taming Role-Based Access Control Administration. World Scientific Publishing Co. Inc, 2011. Journal Papers [1] Alessandro Colantonio, Roberto Di Pietro, and Nino Vincenzo Verde. A business-driven decomposition methodology for role mining. Computers & Security, 2012. To appear. [2] Alessandro Colantonio, Roberto Di Pietro, Alberto Ocello, and Nino Vincenzo Verde. Visual role mining: A picture is worth a thousand roles. IEEE Transactions on Knowledge and Data Engineering (TKDE), 2011. In press. [3] Alessandro Colantonio and Roberto Di Pietro. CONCISE: COmpressed N Composable Integer SEt. Information Processing Letters, 110:644 650, 2010. [4] Alessandro Colantonio, Roberto Di Pietro, Alberto Ocello, and Nino Vincenzo Verde. A new role mining framework to elicit business roles and to mitigate enterprise risk. Decision Support Systems, 50:715 731, 2011. Special Issue on Enterprise Risk and Security Management: Data, Text and Web Mining. 2
[5] Alessandro Colantonio, Roberto Di Pietro, Alberto Ocello, and Nino Vincenzo Verde. Taming role mining complexity in RBAC. Computers & Security, 29:548 564, 2010. Special Issue on Challenges for Security, Privacy & Trust. Conference and Workshop Papers [1] Nino Vincenzo Verde, Jaideep Vaidya, Vijayalakshmi Atluri, and Alessandro Colantonio. Role engineering: From theory to practice. In Proceedings of the 2 nd ACM Conference on Data and Application Security and Privacy, CODASPY 12, pages 181 192, 2012. [2] Alessandro Colantonio. Prioritizing role engineering objectives using the analytic hierarchy process. In Proceedings of the 8 th Conference of the Italian Chapter of AIS, itais 2011, pages 419 427, 2011. [3] Alessandro Colantonio, Roberto Di Pietro, Alberto Ocello, and Nino Vincenzo Verde. Mining business-relevant RBAC states through decomposition. In Proceedings of the IFIP TC 11 25 th International Information Security Conference, SEC 10, pages 19 30, 2010. [4] Alessandro Colantonio, Roberto Di Pietro, Alberto Ocello, and Nino Vincenzo Verde. Evaluating the risk of adopting RBAC roles. In Proceedings of the 24 th Annual IFIP WG 11.3 Working Conference on Data and Applications Security, DBSec 10, pages 303 310, 2010. [5] Alessandro Colantonio, Roberto Di Pietro, Alberto Ocello, and Nino Vincenzo Verde. ABBA: Adaptive bicluster-based approach to impute missing values in binary matrices. In Proceedings of the 25 th ACM Symposium on Applied Computing, SAC 10, pages 1027 1034, 2010. [6] Alessandro Colantonio, Roberto Di Pietro, Alberto Ocello, and Nino Vincenzo Verde. A formal framework to elicit roles with business meaning in RBAC systems. In Proceedings of the 14 th ACM Symposium on Access Control Models and Technologies, SACMAT 09, pages 85 94, 2009. [7] Alessandro Colantonio, Roberto Di Pietro, Alberto Ocello, and Nino Vincenzo Verde. Mining stable roles in RBAC. In Proceedings of the IFIP TC 11 24 th International Information Security Conference, SEC 09, pages 259 269, 2009. [8] Alessandro Colantonio, Roberto Di Pietro, Alberto Ocello, and Nino Vincenzo Verde. A probabilistic bound on the basic role mining problem and its applications. In Proceedings of the IFIP TC 11 24 th International Information Security Conference, SEC 09, pages 376 386, 2009. [9] Alessandro Colantonio, Roberto Di Pietro, and Alberto Ocello. Leveraging lattices to improve role mining. In Proceedings of the IFIP TC 11 23 rd International Information Security Conference, SEC 08, pages 333 347, 2008. [10] Alessandro Colantonio, Roberto Di Pietro, and Alberto Ocello. A cost-driven approach to role engineering. In Proceedings of the 23 rd ACM Symposium on Applied Computing, SAC 08, pages 2129 2136, 2008. 3
Trade Journal Articles [1] Alessandro Colantonio. Politiche di separazione dei compiti basate sulla modellazione del business. ICT Security, (69), November/December 2008. http://www.nstecna.com. [2] Alessandro Colantonio. Modelli matematici a supporto del role engineering. ICT Security, (65), June 2008. http://www.nstecna.com. [3] Alessandro Colantonio. Minimizzazione dei costi di controllo degli accessi attraverso metodologie di role engineering. ICT Security, (61), January/February 2008. http: //www.nstecna.com. [4] Alessandro Colantonio. Un approccio al role engineering basato sui costi. Computer Programming, (174), December 2007. http://www.infomedia.it. [5] Alessandro Colantonio. Metodologie di role engineering. ICT Security, (60), November/December 2007. http://www.nstecna.com. Teaching Experience Adjunct Professor (Italian professore a contratto ) of Computer Security for Mathematics course at Roma Tre University, Rome, Italy, a.y. 2010 2011 and 2011 2012. (Settore Scientifico-Disciplinare INF/01) Teaching Assistant of Computer Security for Mathematics course at Roma Tre University, Rome, a.y. 2009 2010. Teaching Assistant of Computer Science Fundamentals Mathematics Degree Course at Roma Tre University, Rome, a.y. 2007 2008 and 2008 2009. Invited talk on Data Mining for Access Control for Computer Science Dept., Escuela Politécnica Superior, Carlos III de Madrid University, April 25, 2012. Invited talk on Role Management for Mathematics course at Roma Tre University, Rome, November 10 11, 2007. Invited talk on Role Engineering for Information Technology course at La Sapienza University, Rome, January 14, 2009. Visiting student at University of Malaga, Computer Science Department, Campus de Teatinos, Malaga, Spain, June 2009. Reference: Prof. Javier Lopez. Full grant of Roma Tre University, Rome, Italy. Other Experience December 2002 March 2006, Consultant at Accenture, Rome office (www.accenture. com). Main experience: Alitalia Servizi (www.alitalia.it). Design of Enterprise Architecture Integration (EAI) and coordination of Interface Assessment activities. Italian Ministry of Health. NSIS Project (www.nsis.ministerosalute.it): Design and development of Office Automation tools for Minister s Office. Design and development of Document Management tools for Minister s Office. Design and development of software for Health Emergency Call Center. 4
Design of Data Warehouse Business Intelligence component (Data Marts and KPI) to monitor drugs supply chain within Italian distribution system. May 2002 December 2002, Consultant at Altran Italia, Rome office (www.altran. com). Middleware specification for Flight Data Processor (FDP) project, Alenia Marconi Systems (www.amsjv.com). October 2001 May 2002, Software Architect at Magneti Marelli Powertrain (www. magnetimarelli.com), Bologna office. Design and development of real-time operating system mechanisms for electronic engine controllers. In collaboration with ReTiS Lab (retis.sssup.it), Scuola Superiore Sant Anna of Pisa, and Cadence European Labs. Additional Information Attended an IRCA/RICEC certified course for Information Security Management System (ISMS) Lead Auditors, according to ISO/IEC 27001:2005 and BS 7799-2:2002 standards, Rome, Italy, March 2007. Member of IFIP WG11.3 and ACM SIGAPP. Reviewer for the following journals: Elsevier JSS, Springer KAIS, IEEE TDSC, IEEE TIFS, Elsevier COSE Part of the Technical Program Committee of the following conferences: ACM RACS 2011, 2012, 2013 Technical Skills Operating Systems: OS X, MS Windows, GNU/Linux, MS-DOS. Office Automation: Apple iwork, MS Office, L A TEX. DBMS/Content Management: Oracle, SQL Server, PostgreSQL, MS Access, EMC Documentum. Programming Languages: Java (J2EE), C/C++, PL/SQL, MS VBA, ARM Assembly; Development tools: Eclipse, MS Visual Studio, ARM Development Suite, GNU gcc. With reference to the Italian law on privacy, D. Lgs. 196/2003, Codice in materia di protezione dei dati personali, I hereby authorize the reader of this document to use my personal data for hiring purposes. Rome, July 23, 2013 Alessandro COLANTONIO 5