EVOLUTION OF THE CISO
|
|
|
- Austin Heath
- 10 years ago
- Views:
Transcription
1 EVOLUTION OF THE CISO And the Confluence of IT Security & Audit Thomas Borton, MBA, CISA, CISM, CRISC, CISSP Director, IT Security & Compliance 13 March 2014
2 AGENDA 1. Introduction 2. Evolution of the CISO: Past, Present & Future 3. Security & Audit: A Confluence 4. Wrap it up
3 WHO IS THIS GUY (BONA FIDES) Over three decades of physical, material, personnel and information security, Privacy (PII), business continuity and disaster recovery planning experience. United States Coast Guard, Chief Warrant Officer, Telecommunications (Retired) Since entering the Private sector, I ve worked in the Property and Casualty Insurance and Retail environments where I developed and implemented information security, Business Continuity/Disaster Recovery and Compliance programs. I wrote, maintain and exercise the IT SOX controls for a $1 billion retailer. I received my undergraduate degree in business from St. Mary s College of California and my MBA from Dominican University of California. I hold the following professional certifications: CISA (Certified Information Systems Auditor) CISM (Certified Information Security Manager) CRISC (Certified in Risk and Information Systems Control) CISSP (Certified Information Systems Security Professional) I am also an instructor for UC Irvine Extended Ed currently teaching a 14-week CompTIA Security+ course
4 WHO IS THIS GUY (BONA FIDES) BUT WAIT THERE S MORE Affiliation with ISACA Member of ISACA since 2006 and have been actively involved with ISACA in a variety of senior strategic roles At the National level: Oversight board membership, Knowledge Board 2 years Charge: Ensure the coordination and prioritization of ISACA s professional guidance and knowledge development and dissemination initiatives in support of ISACA s strategy Committee co-chair, Knowledge Management and Education Committee 2 years Charge: Identify and support activities to facilitate the management and dissemination of ISACA s intellectual capital and other knowledge assets, inclusive of education opportunities, for ISACA constituents Chair, Co-Chair and member of NA CACS (Computer Audit, Control Security) and NA ISRM (Information Security Risk Management) conference task force 4 years Local Chapter level I serve on SF ISACA s board of directors in the role of research director, maintaining clear communications between ISACA national and international leadership and local chapter leadership
5 EVOLUTION OF THE CISO A LITTLE HISTORY Why security in the first place? Physical/personal security (historically, safety, both personal, family and community security in numbers (communities), weapons, walls, fences, doors, locks, MAD Personnel Security (background, bodyguards, trust) Material security (protect food, water, resources, wealth) Caveman Early cities & castles Information security (where the treasure or resources were kept)
6 EVOLUTION OF THE CISO SECURITY NOW OR IN THE NOT-TO-DISTANT FUTURE
7 EVOLUTION OF THE CISO LET S LEVEL-SET, WHAT S OUT ON THE WEB? There are many articles (and books) on this topic, just Google The Evolution of the CISO, to see the list: 211,000 results listed 2012 and 2013 were big years for opinions on this topic, from sources such as: IBM Infosecurity-magazine Conferences and seminars Computerweekly CSOonline Gartner Etc
8 EVOLUTION OF THE CISO MY STORY, MY EVOLUTION My evolution to my current CISO role (1976 through present) Old-school security through classroom and on the job training Seminars and conferences Exposure to business processes and requirements Undergraduate and graduate education Audit Military (Enlisted) Radioman classified and unclassified communication systems and data Top Secret clearance Cryptography was part of my day to day operations Classified Material Control Officer (CMCO) trained and operated a vault Watch officer ashore at a communications station and onboard a CG Law Enforcement cutter Assigned to attend college Duty under Instruction to study computer programming ugh! Out of college, I built LANs and WANS throughout California Transferred to sole CG mainframe in charge of computer security
9 EVOLUTION OF THE CISO MY STORY, MY EVOLUTION THERE S MORE My evolution to CISO role continued Military (Commissioned Officer) Chief Warrant officer, Telecommunications (CWO2 & CWO3) Area Information System Security Officer for: Florida, Georgia, South Carolina, Puerto Rico and the US Virgin Islands California, Oregon, Washington, Alaska, and Hawaii Member of Tiger team that assisted other information system security officers in setting up security and disaster recovery plans for their respective geographical areas Recruited by former Commanding Officer to start up IT Security position at Property Casualty insurance company Went back to college at night to complete my undergraduate degree in business 4$ billion privately held Property/Casualty Insurance company (4.5 years) Hired as non-management IT security expert Completed my undergraduate degree in business Began my Graduate degree (MBA) Worked as an international committee member to establish security program and policies for parent multi-national holding company based in Munich, Germany Left company after 4.5 years as Senior Director, IT Security & Disaster Recovery Staff of 17 Began studying for CISA
10 EVOLUTION OF THE CISO MY STORY, MY EVOLUTION IT WON T STOP HERE My evolution to CISO role almost done Retail (just about 10 years) Completed my CISA certification Completed my CISSP certification Completed my MBA, emphasis in Strategic Leadership just before I was hired Hired as IT Manager (matured the position into a IT Director level role) First task was to manage a project writing the IT SOX controls for the company Developed a portfolio of IT security standards, policies, and procedures Completed my CISM and CRISC certifications Established the company business continuity and IT disaster recovery plans and exercise them annually PCI compliance 3 years running (PCI DSS versions 1.2, 2.0 and eventually 3.0) Privacy compliance, both employee and customer data protection Staff of 1 My role as CISO will continue to grow & evolve as the business grows & evolves
11 EVOLUTION OF THE CISO OTHER ROADS Other common (or uncommon) roads to CISO role Begin in audit, gain experience, exposed to IT security Fresh out of college, audit or security interns, gain experience, jump into a business unit, back to security Tag, you re it There are many other paths, let s ask the audience
12 EVOLUTION OF THE CISO BEFORE THE CISO Before there were CISOs There were Security Conferences (MIS, NIST, ISACA, GARTNER, others) Physical security with specialization in information protection Then in 1995 in the wake of a highly published Russian malware incident, the CISO was invented Steve Katz is widely recognized as the first CISO, he joined Citicorp/Citigroup in 1995 as was appointed to the CISO role there. He later joined Merrill Lynch as their chief information security and privacy officer. "99% of becoming a CISO was Serendipity and being open to a new career opportunity where there wasn't a career." Steve Katz Then came security certifications: CISSP (Certified Information Systems Security Professional) CISM (Certified Information Security Manager) SANS (GIAC - Global Information Assurance Certification) GSLC - Global Security Leadership Certification GISP - Global Information Security Professional Other certs
13 EVOLUTION OF THE CISO NOW WE HAVE THE CERTIFIED CHIEF INFORMATION SECURITY OFFICER C/CISO Certification body: Electronic Commerce (EC)-Council, from their website; Description: C/CISO will provide your employers with the assurance that as a CISO certified executive leader, you possess the proven knowledge and experience to plan and oversee IS for the entire corporation. Domains: Governance (Policy, Legal & Compliance) IS Management Controls and Auditing Management Management Projects and Operations (Projects, Technology & Operations) Information Security Core Competencies Strategic Planning & Finance Global reach: over 60 countries, all 7 continents Wide range of job functions: CISO, CIO, CSO, CEO, Vice President, Chief Security Strategist, Senior IS Director, Chief Security Architect, Senior IT Risk & Compliance Manager And coming up next: Cybersecurity professionals (Professional development, sunrise to sunset track)
14 THE CONFLUENCE OF IT SECURITY AND AUDIT UNDERSTANDING THE PARTNERSHIP Security and Audit: A Confluence Historically there has been a tragedy and comedy relationship between audit and security an us versus them from IT we hear, "the auditors are coming, the auditors are coming" and from the auditors, "IT just doesn't understand our view of controls and the reasons/methods for testing them. Fortunately for security and audit alike, regulations such as GLBA, SOX, PCI, PII, HIPPA have driven IT Security and Audit towards the common goal of effective and sane controls. More importantly, I believe that these regulations and the requirements to address risk mitigation and relevant controls to company senior leadership and oversight committees have provided the drive to form successful audit/security relationships. Contentious relationships between auditors and security are not in the best interest of any business. Common goals, clear communication and business partnerships are key elements of success
15 THE CONFLUENCE OF IT SECURITY AND AUDIT UNDERSTANDING THE PARTNERSHIP Security and Audit: A Confluence My personal experience/my opinon: Successful CISOs are driven to completely understand all lines of business in their respective company. Understanding the strategy and contribution of each business unit to the overall success of that business is critical to establishing appropriate security standards, processes, and procedures and the appropriate audit controls. As a sole contributor, I find myself moving smoothly between developing, exercising and validating IT SOX controls throughout the year and simultaneously filling the position of CISO with no conflicts. By necessity I wear multiple hats for security, audit, BCP, disaster recovery, & privacy. Addressing the protection of data and systems from a multi-layered perspective has required me to better understand and assist my business partners. I ve heard the arguments of, Well Tom, you know that we can t totally accept your test results and will have test additional samples to show independence. Understood, I ve still reduced the scope of the external audit by providing solid controls that stand up to security and audit requirements and additional testing.
16 THE CONFLUENCE OF IT SECURITY AND AUDIT UNDERSTANDING THE PARTNERSHIP Security and Audit: A Confluence I did spend a fair amount of time up front explaining the evolution of the CISO and my own evolution in particular because I ve lived the confluence of IT security and audit. A few closing comments: On my journey I ve had a few aha moments concerning business that I will share: CIO capital cost/ongoing expense versus paying the penalty, and The two sides of the coin, the two different views of the same control: security and audit The real customer, our business partners Business continuity is a great tool to improve your ability to function as an interpreter & advocate between business, IT and audit (up, down lateral all directions) My professional success has relied in large part on my understanding of audit and security and that the business is the driver and beneficiary of both disciplines.
17 EVOLUTION OF THE CISO AND THE CONFLUENCE OF IT SECURITY AND AUDIT AND NOW A WORD (OR WORDS) FROM OUR AUDIENCE Questions/comments from the audience Your personal experience/opinon s will be of great value to the other attendees,. So please speak up (or I will be forced to come down among you armed with a microphone)
18 EVOLUTION OF THE CISO THANK YOU! Thank you!
Certification and Training
Certification and Training CSE 4471: Information Security Instructor: Adam C. Champion Autumn Semester 2013 Based on slides by a former student (CSE 551) Outline Organizational information security personnel
Cybercrime & Cybersecurity: the Ongoing Battle International Hellenic University
Cybercrime & Cybersecurity: the Ongoing Battle International Hellenic University Andreas Athanasoulias, CISM, CISSP Information Security Officer & Security Consultant Brief introduction My career path
State of South Carolina InfoSec and Privacy Career Path Model
State of South Carolina InfoSec and Privacy Career Path Model Start Introduction This Career Path Model for the State of South Carolina (State) is designed to help define the various career options available
Executive Management of Information Security
WHITE PAPER Executive Management of Information Security _experience the commitment Entire contents 2004, 2010 by CGI Group Inc. All rights reserved. Reproduction of this publication in any form without
Director, IT Security District Office Kern Community College District JOB DESCRIPTION
Director, IT Security District Office Kern Community College District JOB DESCRIPTION Definition Reporting to the Chief Information Officer, the Director of IT Security develops and implements procedures,
Kevin Savoy, CPA, CISA, CISSP Director of Information Technology Audits Brian Daniels, CISA, GCFA Senior IT Auditor
IT Audit/Security Certifications Kevin Savoy, CPA, CISA, CISSP Director of Information Technology Audits Brian Daniels, CISA, GCFA Senior IT Auditor Certs Anyone? There are many certifications out there
Security Transcends Technology
INTERNATIONAL INFORMATION SYSTEMS SECURITY CERTIFICATION CONSORTIUM, INC. Career Enhancement and Support Strategies for Information Security Professionals Paul Wang, MSc, CISA, CISSP [email protected]
North Texas ISSA CISO Roundtable
North Texas ISSA CISO Roundtable Roundtable Topic Threat Against Our Well Being The Most Effective Methods in Combating and Responding to the Cyber Attack Event Sponsor Moderator and Panelists David Stanton
CLASSIFICATION SPECIFICATION FORM
www.mpi.mb.ca CLASSIFICATION SPECIFICATION FORM Human Resources CLASSIFICATION TITLE: POSITION TITLE: (If different from above) DEPARTMENT: DIVISION: LOCATION: Executive Director Executive Director, Information
Profil stručnjaka za informacijsku sigurnost - certificirati se ili ne? Biljana Cerin, CISA, CISM, CGEIT, CBCP, PMP www.ostendogroup.
Profil stručnjaka za informacijsku sigurnost - certificirati se ili ne? Biljana Cerin, CISA, CISM, CGEIT, CBCP, PMP www.ostendogroup.com DA! (by Global knowledge & TechRepublic) Top certifications by salary:
ADMINISTRATIVE POLICY # 32 8 2 (2014) Information Security Roles and Responsibilities
Policy Title: Information Security Roles Policy Type: Administrative Policy Number: ADMINISTRATIVE POLICY # 32 8 2 (2014) Information Security Roles Approval Date: 05/28/2014 Revised Responsible Office:
Career Analysis into Cyber Security: New & Evolving Occupations
Alderbridge Specialists in Info Security Specialist Recruitment Knowledge for e-skills UK s Cyber Security Learning Pathways Programme Career Analysis into Cyber Security: New & Evolving Occupations e-skills
Stepping Through the Info Security Program. Jennifer Bayuk, CISA, CISM
Stepping Through the Info Security Program Jennifer Bayuk, CISA, CISM Infosec Program How to: compose an InfoSec Program cement a relationship between InfoSec program and IT Governance design roles and
Over 20 years experience in Information Security Management, Risk Management, Third Party Oversight and IT Audit.
CYBERSECURITY: ISSUES AND ISACA S RESPONSE June 2014 BILL S BIO Over 20 years experience in Information Security Management, Risk Management, Third Party Oversight and IT Audit. Vice President Controls
Feature. Developing an Information Security and Risk Management Strategy
Feature Developing an Information Security and Risk Management Strategy John P. Pironti, CISA, CISM, CGEIT, CISSP, ISSAP, ISSMP, is the president of IP Architects LLC. He has designed and implemented enterprisewide
Big 4 Information Security Forum
San Francisco ISACA Chapter Proudly Presents: Big 4 Information Security Forum A Day-Long, Multi-Session Event, being held in San Francisco @ the Sir Francis Drake Hotel! *** PLEASE NOTE THIS EVENT WILL
Re: Experience with the Framework for Improving Critical Infrastructure Cybersecurity ( Framework )
10 October 2014 Ms. Diane Honeycutt National Institute of Standards and Technology 100 Bureau Drive, Stop 8930 Gaithersburg, MD 20899 Re: Experience with the Framework for Improving Critical Infrastructure
So Why on Earth Would You WANT To be a CISO?
So Why on Earth Would You WANT To be a CISO? SESSION ID: PROF-M05A Todd Fitzgerald CISSP, CISA, CISM, CRISC, CGEIT, PMP, ISO27000, CIPP, CIPP/US, ITILV3f Global Director of Information Security Grant Thornton
Don t Get Left in the Dust: How to Evolve from CISO to CIRO
SESSION ID: CXO-W04 Don t Get Left in the Dust: How to Evolve from CISO to CIRO JC-JC James Christiansen VP Information Risk Management Accuvant [email protected] Bradley J. Schaufenbuel, CISSP
All about CPEs. David Gittens CISA CISM CISSP CRISC HISP
All about CPEs David Gittens CISA CISM CISSP CRISC HISP The Designer David Gittens ISSA Barbados Past President Certified in ethical hacking and computer forensics Certified in security management and
Getting In-Control - Combining CobiT and ITIL for IT Governance and Process Excellence. Executive Summary: What is the business problem?
Getting In-Control - Combining CobiT and ITIL for IT Governance and Process Excellence Executive Summary: Nearly all of us who are running an IT shop feel the need to gain or increase control, predictability,
Chief Information Officer
Security manager Job description Job title Security manager Location Wellington Group Organisation Development Business unit / team IT Solutions Grade and salary range Pay Group 1, Pay Band 6 Reports to
Information Security Management System (ISMS) Overview. Arhnel Klyde S. Terroza
Information Security Management System (ISMS) Overview Arhnel Klyde S. Terroza May 12, 2015 1 Arhnel Klyde S. Terroza CPA, CISA, CISM, CRISC, ISO 27001 Provisional Auditor Internal Auditor at Clarien Bank
ISACA Tools Help Develop Cybersecurity Expertise
Volume 21, 8 October 2014 ISACA Tools Help Develop Cybersecurity Expertise Nominate Qualified Candidates for the ISACA Board of Directors Tips for Solving Data Classification Challenges Earn CPE at Professional
Information Security Policy and Handbook Overview. ITSS Information Security June 2015
Information Security Policy and Handbook Overview ITSS Information Security June 2015 Information Security Policy Control Hierarchy System and Campus Information Security Policies UNT System Information
SPSP Phase III Recruiting, Selecting, and Developing Secure Power Systems Professionals: Job Profiles
PNNL-24138 SPSP Phase III Recruiting, Selecting, and Developing Secure Power Systems Professionals: Job Profiles March 2015 LR O Neil TJ Conway DH Tobey FL Greitzer AC Dalton PK Pusey Prepared for the
How To Become A Security Professional
Journal Online Jason Andress, Ph.D., CISM, CISSP, GPEN, ISSAP, is a seasoned security professional with experience in the academic and business worlds. In his present and previous roles, he has provided
Plenary: Compliance and Legal Trends Tuesday, May 24 4:15 p.m. 5:15 p.m.
Plenary: Compliance and Legal Trends Tuesday, May 24 4:15 p.m. 5:15 p.m. Join us for a special session with senior leaders as they discuss key issues affecting the regulatory landscape. Panelists will
2014 Montana Government IT Conference. Securing Data Networks and People
Presenter: Matt Bennett, Genetec Leveraging the Cloud for Hybrid Video Surveillance Matt is based in Seattle, WA and is the Western North America pre-sales engineer for Genetec (the world s leader in unified
The Emergence of the ISO in Community Banking Patrick H. Whelan CISA IT Security & Compliance Consultant
THE MARKET LEADER IN IT, SECURITY AND COMPLIANCE SERVICES FOR COMMUNITY FINANCIAL INSTITUTIONS The Emergence of the ISO in Community Banking Patrick H. Whelan CISA IT Security & Compliance Consultant Agenda
A Contrarian Risk Management Perspective. Nicole Keaton SVP Identity & Access Management CGEIT CISA CISM
A Contrarian Risk Management Perspective Nicole Keaton SVP Identity & Access Management CGEIT CISA CISM Introduction Nicole is a Senior Vice President of SunTrust Bank where she has spent six years of
ISACA S CYBERSECURITY NEXUS (CSX) October 2015
ISACA S CYBERSECURITY NEXUS (CSX) October 2015 DO2 EXECUTIVE OVERVIEW Will you be a Cyber defender? ISACA launched the Cybersecurity Nexus (CSX) program earlier this year. CSX, developed in collaboration
SECURITY CONSIDERATIONS FOR LAW FIRMS
SECURITY CONSIDERATIONS FOR LAW FIRMS Enterprise Risk Management Professional consulting firm that specializes in cyber security Founded in 1998 in Miami, Florida Serves more than 150 clients, locally,
INFORMATION SECURITY STRATEGIC PLAN
INFORMATION SECURITY STRATEGIC PLAN UNIVERSITY OF CONNECTICUT INFORMATION SECURITY OFFICE 4/20/10 University of Connecticut / Jason Pufahl, CISSP, CISM 1 1 MISSION STATEMENT The mission of the Information
Introduction Auditing Internal Controls in an IT Environment SOx and the COSO Internal Controls Framework Roles and Responsibilities of IT Auditors
Introduction Auditing Internal Controls in an IT Environment SOx and the COSO Internal Controls Framework Roles and Responsibilities of IT Auditors Importance of Effective Internal Controls and COSO COSO
Tom VAN DEN EYNDE CISSP, CISA, CISM
Tom VAN DEN EYNDE CISSP, CISA, CISM Personal information First Name Tom Last Name Van den Eynde E-mail: [email protected] Phone: +32 - (0)495 91 20 62 Address: Meerminnenstraat 34, 2800 Birthday: May
Designing & Building an Information Security Program. To protect our critical assets
Designing & Building an Information Security Program To protect our critical assets Larry Wilson Version 1.0 March, 2014 Instructor Biography Larry Wilson is responsible for developing, implementing and
SECURING PAYMENTS IN THE CYBER WORLD
The Central Bank of Kuwait Presents An Information Security Forum on SECURING PAYMENTS IN THE CYBER WORLD 16th NOVEMBER 2014 JUMEIRAH MESSILAH BEACH HOTEL, KUWAIT WELCOME In the last few years, the usages
TOPSECRETPROTECTION.COM (TSP)
TOPSECRETPROTECTION.COM (TSP) OVERVIEW OF CYBER SECURITY-INFORMATION SYSTEMS SECURITY PROGRAM MANAGEMENT TRAINING COURSE CYBER SECURITY-ISSPM PROFESSIONAL CERTIFICATION Introduction To TSP TSP has over
Governance Simplified
Information Security Governance Simplified From the Boardroom to the Keyboard TODD FITZGERALD, cissp; cisa, cism Foreword by Tom Peltier CRC Press Taylor & Francis Croup Boca Raton London NewYork CRC Press
KEY TRENDS AND DRIVERS OF SECURITY
CYBERSECURITY: ISSUES AND ISACA S RESPONSE Speaker: Renato Burazer, CISA,CISM,CRISC,CGEIT,CISSP KEY TRENDS AND DRIVERS OF SECURITY Consumerization Emerging Trends Continual Regulatory and Compliance Pressures
Independent Security Operations Oversight and Assessment. Captain Timothy Holland PM NGEN
Independent Security Operations Oversight and Assessment Captain Timothy Holland PM NGEN 23 June 2010 Independent Security Operations Oversight and Assessment Will Jordan NGEN Cyber Security 23 June 2010
Achieving Security through Compliance
Achieving Security through Compliance Policies, plans, and procedures Table of Contents This white paper was written by: McAfee Foundstone Professional Services Overview...3 The Rock Foundation...3 Governance...3
Information Security Principles and Practices
Information Security Principles and Practices by Mark Merkow and Jim Breithaupt Chapter 3: Certification Programs and the Common Body of Knowledge Certification & Information Security Industry standards,
Payment Card Industry Data Security Standard (PCI DSS) v1.2
Payment Card Industry Data Security Standard (PCI DSS) v1.2 Joint LA-ISACA and SFV-IIA Meeting February 19, 2009 Presented by Mike O. Villegas, CISA, CISSP 2009-1- Agenda Introduction to PCI DSS Overview
Cyber ROI. A practical approach to quantifying the financial benefits of cybersecurity
Cyber ROI A practical approach to quantifying the financial benefits of cybersecurity Cyber Investment Challenges In 2015, global cybersecurity spending is expected to reach an all-time high of $76.9
Information Security Workforce Development Matrix Initiative. FISSEA 23 rd Annual Conference March 23, 2010
Information Security Workforce Development Matrix Initiative FISSEA 23 rd Annual Conference March 23, 2010 Professionalization of the Workforce The CIO Council s IT Workforce Committee partnered with Booz
ERIC M. WRIGHT, cpa, citp
ERIC M. WRIGHT, cpa, citp ERIC M. WRIGHT, CPA, CITP Eric has been involved with Information Technology with Schneider Downs since 1983. He specializes in and oversees the design, setup, installation and
Exam Name: Certified Information Security Manager
Vendor: Isaca Exam Code: CISM Exam Name: Certified Information Security Manager Version: DEMO QUESTION 1 Senior management commitment and support for information security will BEST be attained by an information
THE DIGITAL AGE THE DEFINITIVE CYBERSECURITY GUIDE FOR DIRECTORS AND OFFICERS
THE DIGITAL AGE THE DEFINITIVE CYBERSECURITY GUIDE FOR DIRECTORS AND OFFICERS Download the entire guide and follow the conversation at SecurityRoundtable.org Collaboration and communication between technical
Athens, 2 December 2011 Hellenic American Union Conference Center
Athens, 2 December 2011 Hellenic American Union Conference Center ISACA Athens Chapter and the Hellenic American Union are organizing the 1 st ISACA Athens Chapter Conference on December 2 nd, 2011. The
Compliance, Security and Risk Management Relationship Advice. Andrew Hicks, Director Coalfire
Compliance, Security and Risk Management Relationship Advice Andrew Hicks, Director Coalfire Housekeeping You may submit questions throughout the webinar using the question area in the control panel on
Cybersecurity Audit Why are we still Vulnerable? November 30, 2015
Cybersecurity Audit Why are we still Vulnerable? November 30, 2015 John R. Robles, CISA, CISM, CRISC www.johnrrobles.com [email protected] 787-647-3961 John R. Robles- 787-647-3961 1 9/11-2001 The event
Job Market Intelligence: Cybersecurity Jobs, 2015. 2015 Burning Glass Technologies
Job Market Intelligence: Cybersecurity Jobs, 2015 Introduction: Cybersecurity and the Job Market American employers have realized the vital importance of cybersecurity but that realization has created
CFPB Readiness Series: Compliant Vendor Management Overview
CFPB Readiness Series: Compliant Vendor Management Overview Legal Disclaimer This information is not intended to be legal advice and may not be used as legal advice. Legal advice must be tailored to the
COBIT 5 For Cyber Security Governance and Management. Nasser El-Hout Managing Director Service Management Centre of Excellence (SMCE)
COBIT 5 For Cyber Security Governance and Management Nasser El-Hout Managing Director Service Management Centre of Excellence (SMCE) Cybersecurity Governance using COBIT5 Cyber Defence Summit Riyadh, KSA
THE CYBER SECURITY PLAYBOOK WHAT EVERY BOARD OF DIRECTORS SHOULD KNOW BEFORE, DURING, AND AFTER AN ATTACK SECURITY REIMAGINED
THE CYBER SECURITY PLAYBOOK WHAT EVERY BOARD OF DIRECTORS SHOULD KNOW BEFORE, DURING, AND AFTER AN ATTACK SECURITY REIMAGINED THE CYBER SECURITY PLAYBOOK 2 03 Introduction 04 Changing Roles, Changing Threat
CORPORATE GOVERNANCE GUIDELINES SYNACOR, INC. BOARD OF DIRECTORS GUIDELINES ON SIGNIFICANT CORPORATE GOVERNANCE ISSUES
CORPORATE GOVERNANCE GUIDELINES SYNACOR, INC. BOARD OF DIRECTORS GUIDELINES ON SIGNIFICANT CORPORATE GOVERNANCE ISSUES A. BOARD COMPOSITION 1. Selection of Chairman and CEO It is the policy of the Board
This article describes how these seven enablers have contributed towards better information security management at HDFC Bank.
Information Security Management at HDFC Bank: Contribution of Seven Enablers By Vishal Salvi, CISM, and Avinash W. Kadam, CISA, CISM, CGEIT, CRISC, CBCP, CISSP, CSSLP HDFC Bank was incorporated in August
NGA Paper. Act and Adjust: A Call to Action for Governors. for cybersecurity;
NGA Paper Act and Adjust: A Call to Action for Governors for Cybersecurity challenges facing the nation. Although implementing policies and practices that will make state systems and data more secure will
2015 CEO & Board University Cybersecurity on the Rise. Matthew J. Putvinski, CPA, CISA, CISSP
2015 CEO & Board University Cybersecurity on the Rise Matthew J. Putvinski, CPA, CISA, CISSP MEMBER OF PKF NORTH AMERICA, AN ASSOCIATION OF LEGALLY INDEPENDENT FIRMS 2011 Wolf & Company, P.C. About Wolf
CYBERSECURITY NEXUS ROBERT E STROUD INTERNATIONAL PRESIDENT, ISACA RAMSÉS GALLEGO INTERNATIONAL VICE PRESIDENT, ISACA
CYBERSECURITY NEXUS ROBERT E STROUD INTERNATIONAL PRESIDENT, ISACA RAMSÉS GALLEGO INTERNATIONAL VICE PRESIDENT, ISACA Robert Stroud International President, ISACA VP Strategy & Innovation, CA Technologies
Information Security Specialist Training on the Basis of ISO/IEC 27002
Information Security Specialist Training on the Basis of ISO/IEC 27002 Natalia Miloslavskaya, Alexander Tolstoy Moscow Engineering Physics Institute (State University), Russia, {milmur, ait}@mephi.edu
FedVTE Training Catalog SPRING 2015. advance. Free cybersecurity training for government personnel. fedvte.usalearning.gov
FedVTE Training Catalog SPRING 2015 advance. Free cybersecurity training for government personnel. fedvte.usalearning.gov If you need any assistance please contact the FedVTE Help Desk here or email the
Guild Mortgage Depth and Breadth of Skills, Experience Define the Management Team
FOR IMMEDIATE RELEASE October 17, 2012 Guild Mortgage Depth and Breadth of Skills, Experience Define the Management Team Leadership Team Backgrounder Guild Mortgage s leadership team sets the tone for
CYBERSECURITY: ISSUES AND ISACA S RESPONSE
CYBERSECURITY: ISSUES AND ISACA S RESPONSE June 2014 KEY TRENDS AND DRIVERS OF SECURITY Consumerization Emerging Trends Continual Regulatory and Compliance Pressures Mobile devices Social media Cloud services
Ed McMurray, CISA, CISSP, CTGA CoNetrix
Ed McMurray, CISA, CISSP, CTGA CoNetrix AGENDA Introduction Cybersecurity Recent News Regulatory Statements NIST Cybersecurity Framework FFIEC Cybersecurity Assessment Questions Information Security Stats
Strategy, COBIT and Vision: HOW DO THEY RELATE? Ken Vander Wal, CISA, CPA, Past President, ISACA [email protected] 11.16.2013
Strategy, COBIT and Vision: HOW DO THEY RELATE? Ken Vander Wal, CISA, CPA, Past President, ISACA [email protected] 11.16.2013 AGENDA IT s Changing Landscape ISACA s Response Vision and Mission COBIT 5
Social Media Security Training and Certifications. Stay Ahead. Get Certified. Ultimate Knowledge Institute. ultimateknowledge.com
Ultimate Knowledge Institute ultimateknowledge.com Social Media Security Training and Certifications Social Media Security Professional (SMSP) Social Media Engineering & Forensics Professional (SMEFP)
CISM (Certified Information Security Manager) Document version: 6.28.11
CISM (Certified Information Security Manager) Document version: 6.28.11 Important Note About CISM PDF techexams CISM PDF is a comprehensive compilation of questions and answers that have been developed
Database Security and Auditing
Database Security and Auditing COURSE DESCRIPTION: This seminar aims to provide the Database Administrators, System Administrators, Auditors and IT Security Officers an overview on how to secure and audit
What Directors need to know about Cybersecurity?
What Directors need to know about Cybersecurity? W HAT I S C YBERSECURITY? PRESENTED BY: UTAH BANKERS ASSOCIATION AND JON WALDMAN PARTNER, SENIOR IS CONSULTANT - SBS 1 Contact Information Jon Waldman Partner,
INTEGRATING THE TWO WORLDS OF PHYSICAL AND LOGICAL SECURITY
A White Paper Author: Guy Huntington, President, Huntington Ventures Ltd. Date: February 20, 2009 1 Integrating the Two Worlds of Physical and Logical Security Guy Huntington, Huntington Ventures Ltd.
Department of Homeland Security Cyber Resilience Review (Case Study) Matthew Butkovic Technical Manager - Cybersecurity Assurance, CERT Division
Department of Homeland Security Cyber Resilience Review (Case Study) Matthew Butkovic Technical Manager - Cybersecurity Assurance, CERT Division Matthew Butkovic is a Technical Manager Cybersecurity Assurance
COMPENSATION REPORT FOR FINANCIAL PROFESSIONS WITH CANDIDATE RECRUITMENT INSIGHTS
2016 COMPENSATION REPORT FOR FINCIAL PROFESSIONS WITH CANDIDATE RECRUITMENT INSIGHTS TABLE OF CONTENTS 3 4 8 12 16 24 26 30 Letter from the CEO Using the Report High-Demand Professionals & Qualifications
Trends in Managed Services in Tax Administration
Experience the commitment issue PAPeR Trends in Managed Services in Tax Administration This issue paper reviews the findings of a joint survey by CGI and the Federation of Tax Administrators asking senior
National Railroad Passenger Corp. (AMTRAK) Session 1 Threats and Constraints. Continuous. - Continuous Monitoring. - Continuous Assessment
0 National Railroad Passenger Corp. (AMTRAK) Session 1 Threats and Constraints Continuous - Continuous Monitoring - Continuous Assessment - Continuous Education 1 Amtrak Information Security Challenges
12/4/2013. Regulatory Updates. Eric M. Wright, CPA, CITP. Schneider Downs & Co., Inc. December 5, 2013
Regulatory Updates Eric M. Wright, CPA, CITP Schneider Downs & Co., Inc. December 5, 2013 Eric M. Wright, CPA, CITP Eric has been involved with Information Technology with Schneider Downs since 1983. He
Bridging the Cybersecurity Talent Gap Cybersecurity Employment and Opportunities for Engagement
Bridging the Cybersecurity Talent Gap Cybersecurity Employment and Opportunities for Engagement 2015 Burning Glass Technologies Cybersecurity has a Big Problem Attacks are rising Cyber incidents jumped
Cyberprivacy and Cybersecurity for Health Data
Experience the commitment Cyberprivacy and Cybersecurity for Health Data Building confidence in health systems Providing better health care quality at lower cost will be the key aim of all health economies
Certified Information Systems Auditor (CISA)
Certified Information Systems Auditor (CISA) Course Introduction Course Introduction Module 01 - The Process of Auditing Information Systems Lesson 1: Management of the Audit Function Organization of the
Val-EdTM. Valiant Technologies Education & Training Services. 2-day Workshop on Business Continuity & Disaster Recovery Planning
Val-EdTM Valiant Technologies Education & Training Services 2-day Workshop on Business Continuity & Disaster Recovery Planning All Trademarks and Copyrights recognized Page 1 of 8 Welcome to Valiant Technologies.
January IIA / ISACA Joint Meeting Pre-meeting. Cybersecurity Update for Internal Auditors. Matt Wilson, PwC Risk Assurance Director
January IIA / ISACA Joint Meeting Pre-meeting Cybersecurity Update for Internal Auditors Matt Wilson, Risk Assurance Director Introduction and agenda Themes from The Global State of Information Security
Experienced professionals may apply for the Certified Risk Management Professional (CRMP) certification under the grandfathering provision.
Application for CRMP Certification (part 1) GRCSI is now offering the Certified Risk Management Professional (CRMP) certification to support and recognize professionals who have skills and experience in
