Upcoming Chapter Events

Below are upcoming chapter conferences, seminars, review courses, and other events.  Prior chapter events can also be viewed.

For information on our event policies, see https://isaca-gwdc.org/event-policies/.

Loading Events

« All Events

  • This event has passed.

Cloud Security Conference

September 26 @ 8:30 am - 12:30 pm EDT

GWDC Members $10, Non-GWDC Members $30

In a world where over 80% of organizational resources are now hosted in the cloud and more than 90% of internet traffic is API-based, understanding and mitigating cybersecurity risks has never been more crucial. This virtual conference is tailored for cybersecurity professionals, auditors, and IT leaders who need to stay ahead of evolving threats and ensure robust security for their cloud environments.

Join us for an enlightening day of expert insights, practical tips, and actionable strategies that will empower you to enhance your cloud security posture. Our lineup of distinguished speakers will guide you through the complexities of continuous compliance, API security, and the latest cloud security trends.

IT professionals, IT advisory or audit professionals, business executives, students or professionals interested in learning more about cloud security should attend this event.

Registration closes on September 25, 2024 @ 2 pm. 

Register Today!

 

Agenda

08:30 AM – 09:30 AM

Fire Side Chat: Clear the Clouds: Threats and Risk Mitigation on Cloud Computing

Presenters: Jose Torres (ACFE DC, Guidehouse), Prem Mishra, and David Hinchman (GAO)

Learning Objectives for this session:

  • Recognize challenges organizations face in implementing cloud security practices and recommendations to remediate their risks 
  • Understand leading practices and standards for effective and efficient cloud security. 
  • Learn the importance of people, process, and technology in having a secure cloud environment.

09:30 AM – 10:30 AM

Continuous Compliance (cATO) with ML and OSCAL

Presenter: Valinder Mangat (DRTConfidence)

Achieving continuous compliance (cATO) requires integration with development teams, security teams, security tools, authorizing officials, and DevOps platforms. A ‘common data fabric’ is necessary to enable standardized information exchange and automate analysis. OSCAL is the data fabric that allows for standardized data exchange across all security operations and sets the foundation for achieving a continuous compliance posture. Learn how security teams can transition to a robust cATO compliance framework.

10:30 AM – 11:30 AM

Protecting Your Apps: API Security from Development to Deployment

Presenter: Dan Barahona (APIsec University)

APIs are critical in modern applications but are increasingly targeted by cyberattacks. We will explore the key vulnerabilities, including authorization, authentication, data exposure and business logic flaws – providing practical techniques to mitigate these risks. Attendees will learn the importance and approaches to shift-left API security with continuous, comprehensive and automated testing.

Through real-world case studies, the session highlights the impact of API breaches and offers preventive measures. We will discuss secure deployment strategies, continuous monitoring, and ensuring compliance with regulations like GDPR and PCI DSS. This presentation delivers actionable insights for developers to fortify their APIs against evolving threats, ensuring robust security from development to deployment.

11:30 AM – 12:30 AM

Five Key Cloud Security Trends and Tips

Presenter: Frank Kim (SANS)

Learn about the top five trends that are shaping cloud security adoption: identity, architecture, automation, assessment, and detection. Hear about high profile cloud security breaches and walk away with tips and techniques for responding to these trends including free and open source tools as well as cloud provider specific services you can use to build your security capabilities.

 

Presenters

 

 

Jose Torres
President @ Washington Metro Association of Certified Fraud Examiners
Associate Director @ Guidehouse’s Financial Services practice

Jose Torres is the President of the Washington Metro Association of Certified Fraud Examiners and an Associate Director at Guidehouse’s Financial Services practice. He serves organizations in optimizing their governance, information security strategy, risk management, internal control programs, and financial reporting and compliance. Jose is a Certified Public Accountant, Certified Fraud Examiner, and Certified Information Systems Auditor.

 

Prem Mishra

Experienced technology and security audit leader with more than 20 years of professional experience providing technology and security assurance services in the financial and telecom industries. Extensive experience in risk management and governance, IT auditing, cybersecurity, emerging technology, including cloud and AI governance, and policy development. Possesses a proven track record of successfully leading large, diverse teams that deliver high value-added audit results for senior management and the Board.

David Hinchman
Director, Information Technology and Cybersecurity @ GAO

Dave is a Director in GAO’s Information Technology and Cybersecurity team. He oversees audits on critical infrastructure protection, the IT and cybersecurity workforce, cloud computing, and the IRS’s IT modernization efforts.

Dave joined GAO in July 2002. He has led numerous reviews of federal data center optimization and cloud computing, and was responsible for GAO’s work on the High-Risk area of Improving the Management of IT Acquisitions and Operations. Prior to joining GAO, Dave worked as a business consultant for several private sector firms (including PricewaterhouseCoopers), and served as a Surface Warfare Officer in the United States Navy.

Dave earned a master’s degree in business administration from the University of Arizona. Dave earned a bachelor’s degree in anthropology from Vassar College.

Dave works in GAO’s Dallas Field Office.

Valinder Mangat
Chief Innovation Officer @ DRTConfidence

Valinder Mangat is the Chief Innovation Officer (CIO) at DRTConfidence Inc., a contributor to the Open Security Controls Assessment Language (OSCAL) standard, and an avid technologist. As a 30-year Information Technology veteran for various Government Agencies and Fortune 100 clients, Valinder brings diverse experience in implementing complex enterprise systems and shares a unique perspective in preparing organizations for OSCAL adoption.

Dan Barahona
Co-founder @ APIsec University

Dan is the co-founder of APIsec Universtiy, a free API security training site that quickly gained over 50,000 students. He’s also the Head of Growth at APIsec, an API security testing company, and was formerly CMO and EVP Sales at Qualys, CMO at Anomali, and VP Business Development at ArcSight/MicroFocus. Dan was born and raised in Washington, DC started his career in the automotive industry as a Crashworthiness Engineer before pivoting to cybersecurity for the last 20 years.

Frank Kim
Fellow @ SANS Institute

Frank Kim is a SANS Fellow where he leads the Cloud Security and Cybersecurity Leadership curricula to help shape and develop the next generation of security leaders. Previously, he served as the organization’s CISO where he led the information risk function for the most trusted source of cybersecurity training and certification in the world.

He was also the CISO-in-Residence at YL Ventures where he supported cybersecurity entrepreneurs with ideation and market research, conducted due diligence for potential investments, and engaged in go-to-market activities of the firm’s portfolio companies.

Frank continues to serve as an advisor to numerous security startups and authors and teaches courses on CISO leadership, strategic planning, DevSecOps, and cloud security. Frank is the author and instructor of LDR512: Security Leadership Essentials for Managers, LDR514: Security Strategic Planning, Policy, and Leadership, and co-author of SEC540: Cloud Security and DevSecOps Automation.

 

Virtual Meeting Information

  • This event will be presented through Zoom.
  • Prior to the event, participants must install the Zoom app on their respective devices or use the web-based Zoom. Calling via the phone may not be entitled to CPE credits.
  • Participants must respond to all the poll questions via the Zoom polling feature or chat log in order to receive NASBA CPE credits.
  • The ISACA Greater Washington, D.C. Chapter will not be responsible for the participant’s inability to respond to the polls.

 

Event Questions and Policies

Registration Questions

If you have any registration questions about this event, please contact the chapter using the Registration Contact Form.

If you have CPE questions after the event has concluded, please contact the chapter using the CPE Contact Form.

 

Cancellation and Refund Policy

Cancellation and refund for advance registrations is allowed if cancellations are submitted through the registration system. Refunds vary depending on the date of cancellation. See ISACA GWDC Event Policies for details.

If ISACA GWDC cancels the event, all registrants will be notified as soon as possible through email at the email address provided during registration. Full refunds will be provided.

 

Complaint Policy

The GWDC welcomes your comments, complaints, suggestions, questions, and other feedback concerning our website information and services. All complaints should be submitted through the Registration Contact Form.

 

CPE Information

Earn up to 4 Continuing Professional Education (CPE) credit in the area of Information Technology. The ISACA® Greater Washington, D.C. Chapter is registered with the National Association of State Boards of Accountancy (NASBA) as a sponsor of continuing professional education on the National Registry of CPE Sponsors. State boards of accountancy have final authority on the acceptance of individual courses for CPE credit. Complaints regarding registered sponsors may be submitted to the National Registry of CPE Sponsors through its website: www.NASBARegistry.org

 

CPE Distribution and Evaluation Survey

CPEs will be distributed via e-mail along with the event evaluation survey after the completion of the event. Attendees must be present for the full event to receive full CPE credit.

 

Learning Objective

After attending this event, attendees will learn about recent topics in the cloud security space.

 

CPE-Related Details

  • Prerequisites: None
  • Advance Preparation: None
  • Program Knowledge Level: Basic
  • Delivery Method:  Group Internet Based
  • Field of Study:  Information Technology – Technical

Details

Date:
September 26
Time:
8:30 am - 12:30 pm EDT
Cost:
GWDC Members $10, Non-GWDC Members $30
Event Category:
Event Tags:
, ,
Website:
CLICK TO REGISTER »

Venue

Virtual Event

Organizer

Avneet Sabharwal
Email
programs@isaca-gwdc.org

ISACA GWDC