Computing and IT technologies have become pervasive. This same infrastructure is growing more complex as the underlying computational and communication resources grow in speed and capacity. Every vision of future technology includes predictions of ubiquitous computing and networking, including embedded, portable, and distributed systems in every aspect of our infrastructure. Computing will continue to change the way we do business, interact with government, entertain ourselves, communicate, keep records, control our infrastructures and services, execute law enforcement and national defense, and conduct research and education.

Coupled with these changes, we face threats of massive disruption and denial, loss of privacy, alteration of critical information, and new forms of undesirable IT-based activity. Threats from criminals, anarchists and extremists, random hackers, and cyberterrorists (among others) continue to grow even as we put more reliance on our computing infrastructure. Yet most of the money, attention, and energy in information security and information assurance has been focused on incremental patches and updates to existing systems rather than on seeking fundamental advances.

In 2002, the Computing Research Association sponsored its first "Grand Research Challenges in Computer Science and Engineering." This was the first in a series of highly non-traditional conferences where the goal is to define important questions rather than expose current research. Grand Challenges meetings seek "out-of-the-box" thinking to expose some of the exciting, deep challenges yet to be met in computing research. Because of the clear importance and pressing needs in information security and assurance, the Computing Research Association's second "Grand Research Challenges Conference" will be devoted to defining technical and social challenges in information security and assurance.

We are seeking scientists, educators, business people, futurists, and others who have some vision and understanding of the big challenges (and accompanying advances) that should shape the research agenda in this field over the next few decades. These meetings are not structured as traditional conferences with scheduled presentations, but rather as highly participatory meetings exposing important themes and ideas. As such, this is not a conference for security specialists alone: We seek to convene a diverse group from a variety of fields and at all career stages; we seek insight and vision wherever it may reside.

