ISACA Greater Washington, D.C. Chapter
Serving ISACA GWDC Members since 1974
Upcoming Chapter Events
Below are upcoming chapter conferences, seminars, review courses, and other events. Prior chapter events can also be viewed.
For information on our event policies, see https://isaca-gwdc.org/event-policies/.
In a world where over 80% of organizational resources are now hosted in the cloud and more than 90% of internet traffic is API-based, understanding and mitigating cybersecurity risks has never been more crucial. This virtual conference is tailored for cybersecurity professionals, auditors, and IT leaders who need to stay ahead of evolving threats and ensure robust security for their cloud environments.
Join us for an enlightening day of expert insights, practical tips, and actionable strategies that will empower you to enhance your cloud security posture. Our lineup of distinguished speakers will guide you through the complexities of continuous compliance, API security, and the latest cloud security trends.
IT professionals, IT advisory or audit professionals, business executives, students or professionals interested in learning more about cloud security should attend this event.
Registration closes on September 25, 2024 @ 2 pm.
Agenda
08:30 AM – 09:30 AM
Fire Side Chat: Clear the Clouds: Threats and Risk Mitigation on Cloud Computing
Presenters: Jose Torres (ACFE DC, Guidehouse), Prem Mishra, and David Hinchman (GAO)
Learning Objectives for this session:
09:30 AM – 10:30 AM
Continuous Compliance (cATO) with ML and OSCAL
Presenter: Valinder Mangat (DRTConfidence)
Achieving continuous compliance (cATO) requires integration with development teams, security teams, security tools, authorizing officials, and DevOps platforms. A ‘common data fabric’ is necessary to enable standardized information exchange and automate analysis. OSCAL is the data fabric that allows for standardized data exchange across all security operations and sets the foundation for achieving a continuous compliance posture. Learn how security teams can transition to a robust cATO compliance framework.
10:30 AM – 11:30 AM
Protecting Your Apps: API Security from Development to Deployment
Presenter: Dan Barahona (APIsec University)
APIs are critical in modern applications but are increasingly targeted by cyberattacks. We will explore the key vulnerabilities, including authorization, authentication, data exposure and business logic flaws – providing practical techniques to mitigate these risks. Attendees will learn the importance and approaches to shift-left API security with continuous, comprehensive and automated testing.
Through real-world case studies, the session highlights the impact of API breaches and offers preventive measures. We will discuss secure deployment strategies, continuous monitoring, and ensuring compliance with regulations like GDPR and PCI DSS. This presentation delivers actionable insights for developers to fortify their APIs against evolving threats, ensuring robust security from development to deployment.
11:30 AM – 12:30 AM
Five Key Cloud Security Trends and Tips
Presenter: Frank Kim (SANS)
Learn about the top five trends that are shaping cloud security adoption: identity, architecture, automation, assessment, and detection. Hear about high profile cloud security breaches and walk away with tips and techniques for responding to these trends including free and open source tools as well as cloud provider specific services you can use to build your security capabilities.
Presenters
Jose Torres
President @ Washington Metro Association of Certified Fraud Examiners
Associate Director @ Guidehouse’s Financial Services practice
Jose Torres is the President of the Washington Metro Association of Certified Fraud Examiners and an Associate Director at Guidehouse’s Financial Services practice. He serves organizations in optimizing their governance, information security strategy, risk management, internal control programs, and financial reporting and compliance. Jose is a Certified Public Accountant, Certified Fraud Examiner, and Certified Information Systems Auditor.
Experienced technology and security audit leader with more than 20 years of professional experience providing technology and security assurance services in the financial and telecom industries. Extensive experience in risk management and governance, IT auditing, cybersecurity, emerging technology, including cloud and AI governance, and policy development. Possesses a proven track record of successfully leading large, diverse teams that deliver high value-added audit results for senior management and the Board.
David Hinchman
Director, Information Technology and Cybersecurity @ GAO
Dave is a Director in GAO’s Information Technology and Cybersecurity team. He oversees audits on critical infrastructure protection, the IT and cybersecurity workforce, cloud computing, and the IRS’s IT modernization efforts.
Dave joined GAO in July 2002. He has led numerous reviews of federal data center optimization and cloud computing, and was responsible for GAO’s work on the High-Risk area of Improving the Management of IT Acquisitions and Operations. Prior to joining GAO, Dave worked as a business consultant for several private sector firms (including PricewaterhouseCoopers), and served as a Surface Warfare Officer in the United States Navy.
Dave earned a master’s degree in business administration from the University of Arizona. Dave earned a bachelor’s degree in anthropology from Vassar College.
Dave works in GAO’s Dallas Field Office.
Valinder Mangat
Chief Innovation Officer @ DRTConfidence
Valinder Mangat is the Chief Innovation Officer (CIO) at DRTConfidence Inc., a contributor to the Open Security Controls Assessment Language (OSCAL) standard, and an avid technologist. As a 30-year Information Technology veteran for various Government Agencies and Fortune 100 clients, Valinder brings diverse experience in implementing complex enterprise systems and shares a unique perspective in preparing organizations for OSCAL adoption.
Dan Barahona
Co-founder @ APIsec University
Dan is the co-founder of APIsec Universtiy, a free API security training site that quickly gained over 50,000 students. He’s also the Head of Growth at APIsec, an API security testing company, and was formerly CMO and EVP Sales at Qualys, CMO at Anomali, and VP Business Development at ArcSight/MicroFocus. Dan was born and raised in Washington, DC started his career in the automotive industry as a Crashworthiness Engineer before pivoting to cybersecurity for the last 20 years.
Frank Kim
Fellow @ SANS Institute
Frank Kim is a SANS Fellow where he leads the Cloud Security and Cybersecurity Leadership curricula to help shape and develop the next generation of security leaders. Previously, he served as the organization’s CISO where he led the information risk function for the most trusted source of cybersecurity training and certification in the world.
He was also the CISO-in-Residence at YL Ventures where he supported cybersecurity entrepreneurs with ideation and market research, conducted due diligence for potential investments, and engaged in go-to-market activities of the firm’s portfolio companies.
Frank continues to serve as an advisor to numerous security startups and authors and teaches courses on CISO leadership, strategic planning, DevSecOps, and cloud security. Frank is the author and instructor of LDR512: Security Leadership Essentials for Managers, LDR514: Security Strategic Planning, Policy, and Leadership, and co-author of SEC540: Cloud Security and DevSecOps Automation.
Virtual Meeting Information
Event Questions and Policies
Registration Questions
If you have any registration questions about this event, please contact the chapter using the Registration Contact Form.
If you have CPE questions after the event has concluded, please contact the chapter using the CPE Contact Form.
Cancellation and Refund Policy
Cancellation and refund for advance registrations is allowed if cancellations are submitted through the registration system. Refunds vary depending on the date of cancellation. See ISACA GWDC Event Policies for details.
If ISACA GWDC cancels the event, all registrants will be notified as soon as possible through email at the email address provided during registration. Full refunds will be provided.
Complaint Policy
The GWDC welcomes your comments, complaints, suggestions, questions, and other feedback concerning our website information and services. All complaints should be submitted through the Registration Contact Form.
CPE Information
Earn up to 4 Continuing Professional Education (CPE) credit in the area of Information Technology. The ISACA® Greater Washington, D.C. Chapter is registered with the National Association of State Boards of Accountancy (NASBA) as a sponsor of continuing professional education on the National Registry of CPE Sponsors. State boards of accountancy have final authority on the acceptance of individual courses for CPE credit. Complaints regarding registered sponsors may be submitted to the National Registry of CPE Sponsors through its website: www.NASBARegistry.org
CPE Distribution and Evaluation Survey
CPEs will be distributed via e-mail along with the event evaluation survey after the completion of the event. Attendees must be present for the full event to receive full CPE credit.
Learning Objective
After attending this event, attendees will learn about recent topics in the cloud security space.
CPE-Related Details
ISACA® Greater Washington, D.C. Chapter
P.O. Box 13993
Arlington, VA 22219
Terms of Use ■ Privacy Policy ■ Cookie Policy
Chapter Information
ISACA GWDC