BEGIN:VCALENDAR
VERSION:2.0
PRODID:-//ISACA Greater Washington, D.C. Chapter - ECPv6.17.3.1//NONSGML v1.0//EN
CALSCALE:GREGORIAN
METHOD:PUBLISH
X-WR-CALNAME:ISACA Greater Washington, D.C. Chapter
X-ORIGINAL-URL:https://isaca-gwdc.org
X-WR-CALDESC:Events for ISACA Greater Washington, D.C. Chapter
REFRESH-INTERVAL;VALUE=DURATION:PT1H
X-Robots-Tag:noindex
X-PUBLISHED-TTL:PT1H
BEGIN:VTIMEZONE
TZID:America/New_York
BEGIN:DAYLIGHT
TZOFFSETFROM:-0500
TZOFFSETTO:-0400
TZNAME:EDT
DTSTART:20240310T070000
END:DAYLIGHT
BEGIN:STANDARD
TZOFFSETFROM:-0400
TZOFFSETTO:-0500
TZNAME:EST
DTSTART:20241103T060000
END:STANDARD
BEGIN:DAYLIGHT
TZOFFSETFROM:-0500
TZOFFSETTO:-0400
TZNAME:EDT
DTSTART:20250309T070000
END:DAYLIGHT
BEGIN:STANDARD
TZOFFSETFROM:-0400
TZOFFSETTO:-0500
TZNAME:EST
DTSTART:20251102T060000
END:STANDARD
BEGIN:DAYLIGHT
TZOFFSETFROM:-0500
TZOFFSETTO:-0400
TZNAME:EDT
DTSTART:20260308T070000
END:DAYLIGHT
BEGIN:STANDARD
TZOFFSETFROM:-0400
TZOFFSETTO:-0500
TZNAME:EST
DTSTART:20261101T060000
END:STANDARD
END:VTIMEZONE
BEGIN:VEVENT
DTSTART;TZID=America/New_York:20250925T083000
DTEND;TZID=America/New_York:20250925T123000
DTSTAMP:20250925T113911Z
CREATED:20250819T023957Z
LAST-MODIFIED:20250925T113911Z
UID:34219-1758789000-1758803400@isaca-gwdc.org
SUMMARY:Cloud Conference 2025
DESCRIPTION:  \n \n  \nSeptember 25\, 2025\nVirtual Event (Zoom)\nEarn up to 4 CPE\n$10 for GWDC Members\n$30 for Non-Members \n  \n  \n\n\n\nCloud Conference 2025 \nNext-Gen Cloud & Mobile Security: Mastering Compliance\, Addressing Emerging Risks\, API Protection\, and Cloud Trends \nIn a world where over 80% of organizational resources are now hosted in the cloud and more than 90% of internet traffic is API-based\, understanding and mitigating cybersecurity risks has never been more crucial. This virtual conference is tailored for cybersecurity professionals\, auditors\, and IT leaders who need to stay ahead of evolving threats and ensure robust security for their cloud environments. \nJoin us for an enlightening day of expert insights\, practical tips\, and actionable strategies that will empower you to enhance your cloud security posture. Our lineup of distinguished speakers will guide you through the complexities of continuous compliance\, API security\, and the latest cloud security trends. \nRegistration closes on September 24th @ 5PM. \nRegister Today! \n  \n\n\n\n  \nSponsorship Opportunities \nIf you are interested in sponsoring this event\, or sponsoring the chapter as an annual sponsor\, please visit our sponsorship page. \nSponsorship Info \n  \n\n\n\nEvent Details \n\nDate and Time \n\n\nThe conference will be held on September 25\, 2025 from 8:30 am to 12:30 pm. \nAdd this event to your calendar using the Add to Calendar link at the bottom of the page. \n  \n\n\nVirtual Event \n\n\nThe conference will be held using Zoom. \nPrior to the event\, participants must install the Zoom app on their respective devices. Participants using the web-based Zoom or calling via the phone may not be entitled to CPE credits. \n  \n\n\nPricing \n\n\nThe fee for GWDC Members is $10 for the conference.\nThe fee for all other registrants is $30 for the conference. \nTo become a member and take advantage of the member rate for our events\, among other benefits\, join ISACA and select the Greater Washington D.C. Chapter as your local chapter. \n  \n\n\nEvent Policies \n\n\nCancellation and refund for advance registrations is allowed if cancellations are submitted through the registration system by the date registration closes. Refunds vary depending on the date of cancellation and cost of the event. See ISACA GWDC Event Policies for details. \nThe GWDC welcomes your comments\, complaints\, suggestions\, questions\, and other feedback concerning our website information and services. \nAll complaints should be submitted through the Registration Contact Form. \n  \n\n  \n\n\n\n  \nInterested in Speaking at a Chapter Event \nIf you are interested in speaking at an upcoming conference\, please visit the Call for Speakers page and complete the form. \nCall for Speakers \n  \n\n\n\nConference Agenda \nConference agendas may change due to schedule conflicts and other unexpected situations. If a previously published agenda has changed\, the changes will be noted. \n  \n \n\n08:30 AM – 09:30 AM \n\n\nStopping Breaches Before They Start with AI-Powered Cloud Security \nPresenter: Carley Simon (Microsoft) \nThis session will explore how artificial intelligence and automation are transforming cloud security and what that means for cyber and IT auditors. We will dive into real-world breach scenarios\, such as privilege escalation and lateral movement in hybrid cloud environments\, and show how AI can be used to detect misconfigurations\, flag anomalous behavior\, and enforce compliance at scale. Attendees will walk away with a framework for auditing AI-augmented cloud environments\, including key questions to ask\, controls to validate\, and red flags to watch for in environments using tools like Microsoft Defender for Cloud\, Purview\, and Entra Permissions Management. \n\n \n\n09:30 AM – 10:30 AM \n\n\nAI-Powered Enterprise Security Risk Posture Management (ESRPM) in the Cloud: From Compliance to Continuous Digital Trust \nPresenter: Lalit Ahluwalia (DigitalXForce & XForce Galaxy) \nAs cloud adoption accelerates\, enterprises face unprecedented complexity in securing multi-cloud environments while meeting compliance demands. Traditional GRC tools are static and reactive\, leaving organizations vulnerable to evolving threats and regulatory gaps. This session will explore how AI-powered Enterprise Security Risk Posture Management (ESRPM) transforms cloud security and compliance into a real-time\, automated\, and outcome-driven discipline. \nAttendees will learn how to: \n\nContinuously map cloud assets to risks and controls\nAutomate compliance testing and evidence collection\nQuantify security posture in business terms\nEstablish digital trust through AI-driven risk intelligence/li>\n\nThis session is ideal for CISOs\, cloud security leaders\, and risk executives seeking to shift from compliance checklists to measurable cyber resilience. \n\n \n\n10:30 AM – 11:30 AM \n\n\nThe Cloud Changes Everything: Why Your Compliance Strategy Doesn’t \nPresenters: Terrence Williams (SANS) \nStop fighting the cloud with on-premises thinking. While your organization burns budget on third party tools and platforms designed for data centers\, AWS\, Azure\, and Google Cloud offer services that can be strategically automated for continuous compliance that costs fractions of traditional tools—yet most enterprises don’t know these capabilities exist. \nThis session explores the compliance revolution happening in plain sight: native cloud services that automatically enforce NIST controls\, AI that predicts violations before they occur\, and abstraction layers that eliminate vendor lock-in across multi-cloud environments. We’ll talk about whether continuous compliance automation can replace periodic audits and examine what happens when you treat compliance as code instead of paperwork. \nThe cloud isn’t just different infrastructure—it’s a fundamentally different approach to security and governance. While third-party vendors exploit knowledge gaps with expensive “cloud-washing” of legacy tools\, cloud providers deliver genuine innovation through services you’re already paying for. Join us as we explore what’s possible when you leverage the cloud’s native intelligence instead of fighting against it. \n\n \n\n11:30 AM – 12:30 PM \n\n\nAbove the Clouds: Navigating Audit & Compliance in Cloud Services \nPresenter: John Heath (KPMG) \nThe presentation will cover basics of cloud computing types\, service delivery models\, and how an auditor’s consideration of logical access controls\, program change management controls\, and other controls may be influenced by an entity’s use of a cloud service provider to host its systems. \n\n  \n\n\n\n  \nShare this Event \nIf you are interested\, planning to attend\, or attending this event\, please share with your colleagues across your social media networks. \n\n	\n		\n	\n			\n			\n								\n										\n													\n														\n												Share on X\n					\n					\n									\n			\n		\n			\n			\n								\n										\n													\n														\n												Share on Linkedin\n					\n					\n									\n			\n		\n			\n			\n								\n										\n													\n														\n												Share on Facebook\n					\n					\n									\n			\n		\n			\n			\n								\n										\n													\n														\n												Share on Print\n					\n					\n									\n			\n		\n			\n			\n								\n										\n													\n												Share on Email\n					\n					\n									\n			\n		\n		\n\n	\n\n\n  \n  \n\n\n\nPresenters \nAt times presenters for a session may change due to schedule conflicts and other unexpected situations. If a previously presenter has been substituted\, the changes will be noted. \n  \n \n\n \n\n\nCarley Simon\nSenior Data Security Solutions Engineer & Microsoft Federal \nCarley Salmon is a Senior Data Security Solutions Engineer at Microsoft Federal\, where she empowers Department of Defense customers to meet stringent data security and compliance requirements. With a deep understanding of regulatory frameworks and Microsoft’s security portfolio\, Carley delivers technical demonstrations and strategic guidance that help defense organizations navigate complex cybersecurity landscapes. Her work is grounded in real-world experience\, having served as a Team Chief and founding assessor at the Defense Industrial Base Cybersecurity Assessment Center (DIBCAC)\, where she led assessments aligned to DFARS Clause 252.204-7012 and NIST SP 800-171. \nAn Army veteran and former Blackhawk helicopter pilot\, Carley brings a unique dual perspective as both a warfighter and technologist. Her leadership in the USANG and her hands-on experience in cybersecurity assessments inform her mission-driven approach to securing sensitive information. Carley’s passion for data protection and her commitment to national defense make her a compelling voice in the federal cybersecurity community. \n  \n\n \n\n \n\n\nLalit Ahluwalia\nCEO & Founder DigitalXForce & XForce Galaxy \nLalit Ahluwalia is an award-winning cybersecurity executive\, and entrepreneur with over two decades of experience driving global security\, risk management\, and digital trust transformation. He is the CEO & Founder of “DigitalXForce” and “XForce Galaxy”\, his dream ventures committed to redefine the future of cybersecurity. \nLalit is an industry thought leader\, keynote speaker\, and pioneer in AI-powered Enterprise Security Risk Posture Management (ESRPM) and automated GRC solutions. He has led the North America Security practice for Accenture\, Global Cybersecurity practice at Wipro\, and diverse portfolio of security initiatives for Deloitte and PwC. \nLalit has been recognized at North Texas Top 500 Business Leaders by DCEO and awarded the 40 Under 40 by Business Journals and CIO-CTO – Excellence in Cyber Security award by Dallas Magazine for his contributions in the Cyber Security field. \n \n\n \n\n \n\n\nTerrence Williams\nCertified Instructor @ SANS \nWith a trident of expertise in Digital Forensics and Incident Response (DFIR)\, Computer Science\, and Cloud Environments\, Terrence approaches each class with the resounding belief that if individuals are not making those around them better\, then what are they doing? As an instructor\, Terrence’s commitment is to ensure that every encounter leaves individuals better equipped and empowered than before. This philosophy underscores his teaching approach\, emphasizing the transformative power of cybersecurity and the boundless possibilities that emerge with the right mindset. \nTerrence’s journey into cybersecurity wasn’t a deliberate choice; instead\, it was a path he navigated as a Marine. He found his roots and thrived in the ever-evolving game of chess that is cybersecurity. The constant challenge to stay ahead\, the perpetual growth\, and the desire to continuously learn are the driving forces behind Terrence’s commitment to this career. \nBeyond the technical realm\, Terrence’s interests and hobbies are as diverse as the winds that blow. Engaging in community efforts\, whether through international travel\, exploring new restaurants\, or discovering that hidden bourbon bar\, he finds joy in connecting with people from all walks of life. Coming from a background that limited his exposure to the world\, Terrence now embraces every opportunity to learn about it. \n \n\n \n\n \n\n\nJohn Heath\nDirector\, Audit\, Technology Assurance @ KPMG LLP \nJohn Heath is a Technology Assurance – Audit Director in KPMG’s Federal practice\, bringing over 20 years of expertise in audit and advisory services to the Federal Government\, commercial organizations\, and not-for-profit entities. His career has been predominantly centered on IT support for financial statement audits and System and Organization Control (SOC) examinations. From 2009 to 2011\, John expanded his global experience by delivering audit services for KPMG’s Swiss member firm in Geneva\, Switzerland. \nBeyond his client-facing responsibilities\, John supports various firm initiatives: \n\nNational Training Facilitator: Leading training initiatives to enhance team capabilities.\nRecruitment Support: Actively involved in recruiting top talent.\nTechnology Implementation Leader: Spearheading the rollout of Alteryx Designer for the Federal Technology Assurance – Audit practice.\nQuality Reviewer: Serving as a reviewer for the firm’s quality review program.\nCareer Advisory Leader: Previously Chaired the Career Advisory Board\, and recently joined the Executive Advisory Council for his alma mater’s business school.\n\nJohn holds a Bachelor of Science in Information Systems Management and International Business\, and a Bachelor of Arts in French from Salisbury University\, class of 2005. \n \n\n  \n\n\n\n  \nQuestions about this Event \n\n\nIf you have any registration questions about this event\, please contact us by completing the Registration Contact Form linked below. \nRegistration Questions \n  \n\n\n\n\nIf you have CPE questions after the event has concluded\, please contact us by completing the CPE contact form linked below. \nCPE Questions \n  \n\n\n  \n\n\n\nCPE Information \nEarn up to 4 Continuing Professional Education (CPE) credit in the area of Information Technology. The ISACA® Greater Washington\, D.C. Chapter is registered with the National Association of State Boards of Accountancy (NASBA) as a sponsor of continuing professional education on the National Registry of CPE Sponsors. State boards of accountancy have final authority on the acceptance of individual courses for CPE credit. Complaints regarding registered sponsors may be submitted to the National Registry of CPE Sponsors through its website: www.NASBARegistry.org \n  \n\nPoll Questions \n\n\nParticipants must respond to all the poll questions via the Zoom polling feature or chat log in order to receive NASBA CPE credits. The GWDC will not be responsible for the participant’s inability to respond to the polls. \n  \n\n\nCPE Distribution and Evaluation Survey \n\n\nCPEs will be distributed via e-mail along with the event evaluation survey after the completion of the event. Attendees must be present for the full event to receive full CPE credit. \n  \n\n\nLearning Objective \n\n\nAfter attending this event\, attendees will learn about current and future trends in the cloud security space. \n  \n\n\nCPE-Related Details \n\n\n\nPrerequisites: None\nAdvance Preparation: None\nProgram Knowledge Level: Basic\nDelivery Method:  Group Internet Based\nField of Study:  Information Technology – Technical
URL:https://isaca-gwdc.org/event/cloud-conference-2025/
LOCATION:Virtual Event
CATEGORIES:Conferences
ATTACH;FMTTYPE=image/png:https://isaca-gwdc.org/wp-content/uploads/2025/08/cloud_2025.png
ORGANIZER;CN="Avneet Sabharwal":MAILTO:programs@isaca-gwdc.org
END:VEVENT
END:VCALENDAR