BEGIN:VCALENDAR
VERSION:2.0
PRODID:-//ISACA Greater Washington, D.C. Chapter - ECPv6.17.3.1//NONSGML v1.0//EN
CALSCALE:GREGORIAN
METHOD:PUBLISH
X-WR-CALNAME:ISACA Greater Washington, D.C. Chapter
X-ORIGINAL-URL:https://isaca-gwdc.org
X-WR-CALDESC:Events for ISACA Greater Washington, D.C. Chapter
REFRESH-INTERVAL;VALUE=DURATION:PT1H
X-Robots-Tag:noindex
X-PUBLISHED-TTL:PT1H
BEGIN:VTIMEZONE
TZID:America/New_York
BEGIN:DAYLIGHT
TZOFFSETFROM:-0500
TZOFFSETTO:-0400
TZNAME:EDT
DTSTART:20220313T070000
END:DAYLIGHT
BEGIN:STANDARD
TZOFFSETFROM:-0400
TZOFFSETTO:-0500
TZNAME:EST
DTSTART:20221106T060000
END:STANDARD
BEGIN:DAYLIGHT
TZOFFSETFROM:-0500
TZOFFSETTO:-0400
TZNAME:EDT
DTSTART:20230312T070000
END:DAYLIGHT
BEGIN:STANDARD
TZOFFSETFROM:-0400
TZOFFSETTO:-0500
TZNAME:EST
DTSTART:20231105T060000
END:STANDARD
BEGIN:DAYLIGHT
TZOFFSETFROM:-0500
TZOFFSETTO:-0400
TZNAME:EDT
DTSTART:20240310T070000
END:DAYLIGHT
BEGIN:STANDARD
TZOFFSETFROM:-0400
TZOFFSETTO:-0500
TZNAME:EST
DTSTART:20241103T060000
END:STANDARD
BEGIN:DAYLIGHT
TZOFFSETFROM:-0500
TZOFFSETTO:-0400
TZNAME:EDT
DTSTART:20250309T070000
END:DAYLIGHT
BEGIN:STANDARD
TZOFFSETFROM:-0400
TZOFFSETTO:-0500
TZNAME:EST
DTSTART:20251102T060000
END:STANDARD
BEGIN:DAYLIGHT
TZOFFSETFROM:-0500
TZOFFSETTO:-0400
TZNAME:EDT
DTSTART:20260308T070000
END:DAYLIGHT
BEGIN:STANDARD
TZOFFSETFROM:-0400
TZOFFSETTO:-0500
TZNAME:EST
DTSTART:20261101T060000
END:STANDARD
BEGIN:DAYLIGHT
TZOFFSETFROM:-0500
TZOFFSETTO:-0400
TZNAME:EDT
DTSTART:20270314T070000
END:DAYLIGHT
BEGIN:STANDARD
TZOFFSETFROM:-0400
TZOFFSETTO:-0500
TZNAME:EST
DTSTART:20271107T060000
END:STANDARD
END:VTIMEZONE
BEGIN:VEVENT
DTSTART;TZID=America/New_York:20260611T083000
DTEND;TZID=America/New_York:20260611T123000
DTSTAMP:20260530T123812Z
CREATED:20250824T011355Z
LAST-MODIFIED:20260530T123812Z
UID:34387-1781166600-1781181000@isaca-gwdc.org
SUMMARY:Risk Management Conference 2026
DESCRIPTION:  \n \n  \nJune 11\, 2026\nVirtual Event (Zoom)\nEarn up to 4 CPE\n$10 for GWDC Members\n$30 for Non-Members \n  \n  \n\n\n\nRisk Management Conference 2026 \nRisk management is the cornerstone of effective governance and cybersecurity in an era defined by rapid technological innovation. The Risk Management Conference is designed to equip professionals in IT audit\, cybersecurity\, and governance with the tools and insights necessary to navigate complex risk landscapes. \nThis conference explores cutting-edge approaches to risk management\, with a focus on the NIST Risk Management Framework (RMF) and other industry-leading frameworks that empower organizations to identify\, assess\, and mitigate risks effectively. Attendees will gain actionable knowledge on: \n\nImplementing and tailoring risk management frameworks to align with organizational goals and compliance requirements\nAddressing the unique risks posed by emerging technologies such as artificial intelligence and cloud computing\nStrengthening governance structures to drive accountability and resilience\nPractical case studies showcasing successful risk management strategies in real-world scenarios\n\nWhether you’re focused on AI risks\, securing cloud environments\, or enhancing your organization’s governance practices\, this conference offers the expertise\, practical guidance\, and collaborative opportunities to advance your risk management strategies. \nJoin us to gain the insights and frameworks you need to navigate today’s risks and prepare for tomorrow’s challenges. \nRegistration closes on June 10 @ 5PM. \nRegister Today! \n  \n\n\n\n  \nSponsorship Opportunities \nIf you are interested in sponsoring this event\, or sponsoring the chapter as an annual sponsor\, please visit our sponsorship page. \nSponsorship Info \n  \n\n\n\nEvent Details \n\nDate and Time \n\n\nThe conference will be held on June 11\, 2026 from 8:30 am to 12:30 pm. \nAdd this event to your calendar using the Add to Calendar link at the bottom of the page. \n  \n\n\nVirtual Event \n\n\nThe conference will be held using Zoom. \nPrior to the event\, participants must install the Zoom app on their respective devices. Participants using the web-based Zoom or calling via the phone may not be entitled to CPE credits. \n  \n\n\nPricing \n\n\nThe fee for GWDC Members is $10 for the conference.\nThe fee for all other registrants is $30 for the conference. \nTo become a member and take advantage of the member rate for our events\, among other benefits\, join ISACA and select the Greater Washington D.C. Chapter as your local chapter. \n  \n\n\nEvent Policies \n\n\nCancellation and refund for advance registrations is allowed if cancellations are submitted through the registration system by the date registration closes. Refunds vary depending on the date of cancellation and cost of the event. See ISACA GWDC Event Policies for details. \nThe GWDC welcomes your comments\, complaints\, suggestions\, questions\, and other feedback concerning our website information and services. \nAll complaints should be submitted through the Registration Contact Form. \n  \n\n  \n\n\n\n  \nInterested in Speaking at a Chapter Event \nIf you are interested in speaking at an upcoming conference\, please visit the Call for Speakers page and complete the form. \nCall for Speakers \n  \n\n\n\nConference Agenda \nConference agendas may change due to schedule conflicts and other unexpected situations. If a previously published agenda has changed\, the changes will be noted. \nThe conference agenda is being developed and updates will be posted when available. \n  \n \n\n08:30 AM – 09:30 AM \n\n\nOverexposed and Underdeveloped: Why Visibility Alone Has Not Fixed Vulnerability Management \nPresenter: Jonathon Risto (ZenzizenSec Inc. and SANS) \nOrganizations have more vulnerability data than ever before: scanners\, dashboards\, threat intelligence\, asset inventories\, cloud findings\, and exposure signals. Yet many programs still struggle to consistently reduce risk. This talk explores the gap between what security teams can see and what organizations can actually act on. It examines how visibility can outpace maturity\, creating overloaded teams\, unclear priorities\, weak governance\, and growing exposure debt. The session will show why effective vulnerability management is not just about finding more issues\, but about building the decision-making\, prioritization\, mobilization\, and communication capabilities needed to turn visibility into meaningful risk reduction. \n\n \n\n09:30 AM – 10:30 AM \n\n\n90 Days to AI Governance \nPresenter: John Rood (Proceptual) \nGRC and data professionals are increasingly being asked to lead AI governance efforts in 2026 — frequently without additional training or incremental staff. \nThis webinar explores the path to “minimum viable governance” — an effective starting point for a compliant\, long-term AI governance program.\n \n\n \n\n10:30 AM – 11:30 AM \n\n\nIntegrating Risk Management into CMMC Compliance: From Gap Analysis to Continuous Monitoring \nPresenter: Dr. Constance Blanson (Walden University) \nAs organizations across the Defense Industrial Base (DIB) prepare for Cybersecurity Maturity Model Certification (CMMC) Level 2\, risk management is no longer a theoretical exercise—it is a core operational requirement. This session explores how organizations can systematically integrate risk management practices into their CMMC compliance strategy\, aligning with NIST SP 800-171 requirements while building a sustainable\, audit-ready security posture. \nParticipants will gain practical insight into identifying\, assessing\, and prioritizing cybersecurity risks within scoped CUI environments and translating those risks into actionable remediation plans. The session will also examine common pitfalls in gap assessments\, the role of continuous monitoring\, and how leveraging Managed Service Providers (MSPs) or Managed Security Service Providers (MSSPs) can accelerate compliance maturity. Real-world examples and assessor-informed perspectives will be shared to help organizations move from reactive compliance to proactive risk governance. \n\n \n\n11:30 AM – 12:30 PM \n\n\nThe AI Risks You’re Not Ready to Admit You Have \nPresenter: Dr. Keith Morneau (ECPI University) \nMost security teams didn’t see AI coming. Not like this. The tools arrived quickly\, adoption followed\, and somewhere in the middle\, a new attack surface quietly opened.\nPrompt injection\, data poisoning\, model theft\, jailbreaking\, AI-generated phishing\, and deepfakes are just some of the AI risks your organization faces. These risks are emerging across enterprises\, and most organizations are underprepared. Not because you aren’t trying\, but because the frameworks you trust weren’t built for this. \nThis session is about where AI risk actually hides in your organization. Not in your policy documents\, but in your workflows\, vendor relationships\, and data pipelines. We’ll get into threat assessments\, which controls to consider\, and how to build a response posture that protects you. \nNo hype. No doom. Just a clearer picture of what you’re dealing with\, and a practical path forward.\n \n\n  \n\n\n\n  \nShare this Event \nIf you are interested\, planning to attend\, or attending this event\, please share with your colleagues across your social media networks. \n\n	\n		\n	\n			\n			\n								\n										\n													\n														\n												Share on X\n					\n					\n									\n			\n		\n			\n			\n								\n										\n													\n														\n												Share on Linkedin\n					\n					\n									\n			\n		\n			\n			\n								\n										\n													\n														\n												Share on Facebook\n					\n					\n									\n			\n		\n			\n			\n								\n										\n													\n														\n												Share on Print\n					\n					\n									\n			\n		\n			\n			\n								\n										\n													\n												Share on Email\n					\n					\n									\n			\n		\n		\n\n	\n\n\n  \n  \n\n\n\nPresenters \nAt times presenters for a session may change due to schedule conflicts and other unexpected situations. If a previously presenter has been substituted\, the changes will be noted. \n \n\n \n\n\nJonathon Risto\nFounder of ZenzizenSec Incorporated and a SANS Institute instructor \nJonathan Ristro is a cybersecurity leader with more than 25 years of experience in network engineering\, security architecture\, and cyber operations across government and industry. He currently serves as Technical Director for the Government of Canada’s Cyber Posture Management Program\, focused on vulnerability management and automated remediation. \nHe is the Founder of ZenzizenSec Incorporated\, a SANS Institute instructor for LDR516: Strategic Vulnerability and Threat Management\, and a faculty member at the SANS Technology Institute\, where he mentors graduate students in risk and vulnerability management. \nHe has led cybersecurity and incident response work across Bell Canada\, the Canadian International Development Agency\, and Defence Research and Development Canada. \nHe is also the creator of the Vulnerability Management Maturity Model and Continuous Threat Exposure Management Maturity Model\, helping organizations build structured\, risk-based security programs. \n\n \n\n \n\n\nJohn Rood\nFounder and CEO @ Proceptual \nJohn is a recognized expert in AI literacy\, governance\, and organizational implementation\, with extensive experience working specifically with privacy professionals. He’s passionate about helping professionals navigate the rapidly evolving AI landscape with confidence and strategic insight. \nJohn’s Background \n\nSpeaker at SHRM National Conference and multiple SHRM chapters\nSpeaker at Chicago ATD\nInstructor at Michigan State University and University of Chicago\, teaching AI governance\, safety\, and literacy\nHas trained hundreds of leaders on practical AI implementation\n\n\n \n\n \n\n\nConstance Blanson\nCore Faculty\, College of Faculty and Human Potential @ Walden University\nCISSP\, CC\, ITIL\, Sec+\, CMMC-PI\, CCP\n \nDr. Constance Blanson is a cybersecurity professional\, educator\, and consultant specializing in CMMC readiness\, NIST SP 800-171 compliance\, and risk-based cybersecurity strategies. With a PhD in Information Security and multiple industry certifications\, including Certified CMMC Professional (CCP)\, Certified CMMC Assessor (CCA)\, and CISSP\, Dr. Blanson brings both academic rigor and real-world application to cybersecurity program development. \nShe has extensive experience supporting organizations in the Defense Industrial Base with gap assessments\, mock audits\, enclave scoping\, and control implementation aligned to federal requirements. In addition to her consulting work\, Dr. Blanson serves as a doctoral mentor and faculty member\, guiding future leaders in aligning research with practical IT and cybersecurity challenges. Her work focuses on translating complex regulatory frameworks into actionable\, scalable solutions that strengthen organizational resilience and audit readiness.\n \n\n \n\n \n\n\nDr. Keith Morneu\nDean of Computer and Information Science @ ECPI University \nDr. Keith Morneau is the Dean of Computer and Information Science at ECPI University. He has spent more than 30 years at the intersection of technology\, education\, and cybersecurity. He’s been building programs\, closing workforce gaps\, and asking uncomfortable questions about how to close the education and workforce skills gap. His research and practice span education\, software development\, cybersecurity\, AI systems\, and the very human problem of turning technical knowledge into workforce readiness. \n\n  \n\n\n\n  \nQuestions about this Event \n\n\nIf you have any registration questions about this event\, please contact us by completing the Registration Contact Form linked below. \nRegistration Questions \n  \n\n\n\n\nIf you have CPE questions after the event has concluded\, please contact us by completing the CPE contact form linked below. \nCPE Questions \n  \n\n\n  \n\n\n\nCPE Information \nEarn up to 4 Continuing Professional Education (CPE) credit in the area of Information Technology. The ISACA® Greater Washington\, D.C. Chapter is registered with the National Association of State Boards of Accountancy (NASBA) as a sponsor of continuing professional education on the National Registry of CPE Sponsors. State boards of accountancy have final authority on the acceptance of individual courses for CPE credit. Complaints regarding registered sponsors may be submitted to the National Registry of CPE Sponsors through its website: www.NASBARegistry.org \n  \n\nPoll Questions \n\n\nParticipants must respond to all the poll questions via the Zoom polling feature or chat log in order to receive NASBA CPE credits. The GWDC will not be responsible for the participant’s inability to respond to the polls. \n  \n\n\nCPE Distribution and Evaluation Survey \n\n\nCPEs will be distributed via e-mail along with the event evaluation survey after the completion of the event. Attendees must be present for the full event to receive full CPE credit. \n  \n\n\nLearning Objective \n\n\nAfter attending this event\, attendees will learn about current and future trends in the risk management space. \n  \n\n\nCPE-Related Details \n\n\n\nPrerequisites: None\nAdvance Preparation: None\nProgram Knowledge Level: Basic\nDelivery Method:  Group Internet Based\nField of Study:  Information Technology – Technical
URL:https://isaca-gwdc.org/event/risk-management-conference-2026/
LOCATION:Virtual Event
CATEGORIES:Conferences
ATTACH;FMTTYPE=image/png:https://isaca-gwdc.org/wp-content/uploads/2025/08/risk_management.png
ORGANIZER;CN="Avneet Sabharwal":MAILTO:programs@isaca-gwdc.org
END:VEVENT
BEGIN:VEVENT
DTSTART;TZID=America/New_York:20260514T083000
DTEND;TZID=America/New_York:20260514T123000
DTSTAMP:20260513T221045Z
CREATED:20250824T010024Z
LAST-MODIFIED:20260513T221045Z
UID:34381-1778747400-1778761800@isaca-gwdc.org
SUMMARY:IT Audit and Compliance Conference 2026
DESCRIPTION:  \n \n  \nMay 14\, 2026\nVirtual Event (Zoom)\nEarn up to 4 CPE\n$10 for GWDC Members\n$30 for Non-Members \n  \n  \n\n\n\nIT Audit and Compliance Conference 2026 \nThe IT Audit and Compliance Conference 2026 is part of ISACA GWDC’s monthly conference series focused on professional development in IT audit\, governance\, risk\, and compliance. \nRegistration closes on May 13 @ 5PM. \nRegister Today! \n  \n\n\n\n  \nSponsorship Opportunities \nIf you are interested in sponsoring this event\, or sponsoring the chapter as an annual sponsor\, please visit our sponsorship page. \nSponsorship Info \n  \n\n\n\nEvent Details \n\nDate and Time \n\n\nThe conference will be held on May 14\, 2026 from 8:30 am to 12:30 pm. \nAdd this event to your calendar using the Add to Calendar link at the bottom of the page. \n  \n\n\nVirtual Event \n\n\nThe conference will be held using Zoom. \nPrior to the event\, participants must install the Zoom app on their respective devices. Participants using the web-based Zoom or calling via the phone may not be entitled to CPE credits. \n  \n\n\nPricing \n\n\nThe fee for GWDC Members is $10 for the conference.\nThe fee for all other registrants is $30 for the conference. \nTo become a member and take advantage of the member rate for our events\, among other benefits\, join ISACA and select the Greater Washington D.C. Chapter as your local chapter. \n  \n\n\nEvent Policies \n\n\nCancellation and refund for advance registrations is allowed if cancellations are submitted through the registration system by the date registration closes. Refunds vary depending on the date of cancellation and cost of the event. See ISACA GWDC Event Policies for details. \nThe GWDC welcomes your comments\, complaints\, suggestions\, questions\, and other feedback concerning our website information and services. \nAll complaints should be submitted through the Registration Contact Form. \n  \n\n  \n\n\n\n  \nInterested in Speaking at a Chapter Event \nIf you are interested in speaking at an upcoming conference\, please visit the Call for Speakers page and complete the form. \nCall for Speakers \n  \n\n\n\nConference Agenda \nConference agendas may change due to schedule conflicts and other unexpected situations. If a previously published agenda has changed\, the changes will be noted. \nThe conference agenda is being developed and updates will be posted when available. \n  \n \n\n08:30 AM – 09:30 AM \n\n\nFederal Cyber Risk in Practice: What FISMA and CMMC Mean for Leaders \nPresenter: Dr. Anthony Foreman (Foreleads Leadership Consulting\, LLC) \nFederal cybersecurity regulations are often approached as compliance exercises\, yet their real value lies in how they inform risk-based decision-making. This session examines FISMA and CMMC through a leadership lens\, focusing on how federal and defense organizations can translate regulatory requirements into practical\, operational cyber risk management. \nAttendees will gain insight into how leaders can align governance\, controls\, and organizational accountability to reduce risk\, strengthen resilience\, and support mission outcomes—without treating compliance as a checkbox activity. \n\n \n\n09:30 AM – 10:30 AM \n\n\nThe Future of Assurance \nPresenter: Mica Jimenez (KPMG) \nExplore the evolving landscape of SOC and third-party assurance reports\, with a deep dive into SOC 1s\, their role in internal controls\, and Artificial Intelligence’s (AI’s) impact on these audits. \n\n \n\n10:30 AM – 11:30 AM \n\n\nImplementing and Auditing the CIS Critical Security Controls – Real World Experience \nPresenter: Randy Marchany (Virginia Tech\, SANS) \nDetails on the topic will be posted soon. \n\n \n\n11:30 AM – 12:30 PM \n\n\nSafeguarding Privacy Across the AI Development Lifecycle \nPresenter: Dr. Kyle David (Dr. David\, LLC) \nAs organizations accelerate adoption of artificial intelligence\, protecting individual privacy must remain a central design principle throughout the AI system lifecycle. This presentation provides a practitioner-friendly walkthrough of the OECD’s AI System Lifecycle Framework\, which identifies seven key stages—plan and design; gather and collect data; build and/or adapt models; test\, evaluate\, verify\, and validate; deploy; operate and monitor; and retire/decommission. Each stage introduces distinct privacy threats and risk vectors\, from consent and lawful basis challenges during collection to prompt injection and membership inference attacks during operation. Using real-world examples\, this talk translates complex AI privacy risks into clear\, actionable concepts accessible to non-AI and non-privacy specialists. Attendees will learn how to apply proven mitigations—such as privacy-by-design principles\, differential privacy\, data governance frameworks\, and continuous monitoring—to ensure responsible AI development and deployment. Participants will leave with a structured understanding of how privacy safeguards can be embedded at every step of the AI lifecycle to strengthen trust\, compliance\, and accountability. \n\n  \n\n\n\n  \nShare this Event \nIf you are interested\, planning to attend\, or attending this event\, please share with your colleagues across your social media networks. \n\n	\n		\n	\n			\n			\n								\n										\n													\n														\n												Share on X\n					\n					\n									\n			\n		\n			\n			\n								\n										\n													\n														\n												Share on Linkedin\n					\n					\n									\n			\n		\n			\n			\n								\n										\n													\n														\n												Share on Facebook\n					\n					\n									\n			\n		\n			\n			\n								\n										\n													\n														\n												Share on Print\n					\n					\n									\n			\n		\n			\n			\n								\n										\n													\n												Share on Email\n					\n					\n									\n			\n		\n		\n\n	\n\n\n  \n  \n\n\n\nPresenters \nAt times presenters for a session may change due to schedule conflicts and other unexpected situations. If a previously presenter has been substituted\, the changes will be noted. \n \n\n \n\n\nDr. Anthony Foreman\nForeleads Leadership Consulting LLC\, Founder and Principal Consultant \nDr. Anthony T. Foreman is a senior IT executive and cybersecurity leader with more than 25 years of experience managing mission-critical infrastructure in some of the most secure and high-visibility federal environments in the United States. \nHe currently serves as Division Chief for Data Center Management at the Library of Congress\, where he provides executive oversight for enterprise infrastructure\, cybersecurity remediation\, network modernization\, and risk management initiatives supporting Congressional operations\, digital preservation\, and public access systems. \nDr. Foreman previously held senior leadership roles supporting the White House\, U.S. Marshals Service\, Securities and Exchange Commission\, and USAID\, where he led large-scale modernization efforts\, compliance initiatives\, and incident response operations across classified and unclassified environments. \nHe holds a Doctorate in Organizational Leadership with a concentration in Information Technology\, with research focused on cloud security limitations and risk mitigation. Dr. Foreman is also the Founder and Principal Consultant of Foreman Leadership Consulting\, where he advises organizations on cybersecurity leadership\, governance\, and risk-based decision-making. \n \n\n \n\n \n\n\nMica Jimenez\nManager in KPMG’s Federal Tech Assurance practice \nMicaela (“Mica”) Jimenez is currently a manager in KPMG’s Federal Tech Assurance practice and has more than 14 years of progressive experience performing information technology (IT) financial statement audits\, attestation examinations (i.e.\, SOC 1 Type 1 and 2)\, and performance audits for various Federal and Department of Defense (DoD) agencies. Additionally\, she has 7 years of progressive experience performing Chief Financial Officers Act of 1990 (CFO Act) audits\, IT financial statement audits\, and attestation examinations (i.e.\, SOC 1 Type 2 & FISMA) for the United States Department of the Army (Army)\, United States Department of Agriculture (USDA)\, Small Business Administration (SBA)\, Pension Benefit Guaranty Corporation (PBGC)\, and United States Department of Labor (DOL). Mica and her family relocated from San Diego\, California back in 2009 and currently live in Maryland. \n \n\n \n\n \n\n\nRandy Marchany\nChief Information Security Officer @ Virginia Tech\nSenior Instructor @ SANS \nRandy is the Chief Information Security Officer of Virginia Tech and the Director of Virginia Tech’s IT Security Laboratory and has 25 years experience as a systems administrator\, IT auditor\, and security specialist. He is a co-author of the original SANS Top 10 Internet Threats\, the SANS Top 20 Internet Threats\, the SANS Consensus Roadmap for Defeating DDoS Attacks\, and the SANS Incident Response: Step-by-Step guides. Randy is currently a senior instructor for the SANS Institute and has taught a wide variety of courses over the years. Currently\, he can be found teaching SEC566: Implementing and Auditing CIS Controls on a regular basis. \nRandy holds the unique position of being the longest running SANS Instructor on the planet. After one of his Solaris systems got hacked in 1991 (part of the attack described in the book @Large: The Strange Case of the World’s Biggest Internet Invasion)\, he submitted a proposal for a talk to a startup called the SANS Institute in 1992. Alan Paller invited him to work on some projects with them and he’s been doing cybersecurity work with SANS and in his professional career ever since. \n \n\n \n\n \n\n\nDr. Kyle David\nFounder @ Dr. David\, LLC\nCIPP/US/E\, CIPM\, AIGP\, FIP\, CISSP\, and AAISM \nDr. Kyle David is the Founder of Dr. David\, LLC\, where he has delivered privacy and AI governance training to more than 10\,000 learners across 125 countries. Previously a Presidential Management Fellow at the U.S. Department of Energy\, he led privacy workforce development\, created DOE’s AI literacy course\, and supported the launch of EnerGPT. He holds a Ph.D.\, five IAPP designations (CIPP/US/E\, CIPM\, AIGP\, FIP)\, CISSP\, and AAISM. \n \n\n  \n\n\n\n  \nQuestions about this Event \n\n\nIf you have any registration questions about this event\, please contact us by completing the Registration Contact Form linked below. \nRegistration Questions \n  \n\n\n\n\nIf you have CPE questions after the event has concluded\, please contact us by completing the CPE contact form linked below. \nCPE Questions \n  \n\n\n  \n\n\n\nCPE Information \nEarn up to 4 Continuing Professional Education (CPE) credit in the area of Information Technology. The ISACA® Greater Washington\, D.C. Chapter is registered with the National Association of State Boards of Accountancy (NASBA) as a sponsor of continuing professional education on the National Registry of CPE Sponsors. State boards of accountancy have final authority on the acceptance of individual courses for CPE credit. Complaints regarding registered sponsors may be submitted to the National Registry of CPE Sponsors through its website: www.NASBARegistry.org \n  \n\nPoll Questions \n\n\nParticipants must respond to all the poll questions via the Zoom polling feature or chat log in order to receive NASBA CPE credits. The GWDC will not be responsible for the participant’s inability to respond to the polls. \n  \n\n\nCPE Distribution and Evaluation Survey \n\n\nCPEs will be distributed via e-mail along with the event evaluation survey after the completion of the event. Attendees must be present for the full event to receive full CPE credit. \n  \n\n\nLearning Objective \n\n\nAfter attending this event\, attendees will learn about current and future trends in the IT audit and compliance space. \n  \n\n\nCPE-Related Details \n\n\n\nPrerequisites: None\nAdvance Preparation: None\nProgram Knowledge Level: Basic\nDelivery Method:  Group Internet Based\nField of Study:  Information Technology – Technical
URL:https://isaca-gwdc.org/event/it-audit-and-compliance-conference-2026/
LOCATION:Virtual Event
CATEGORIES:Conferences
ATTACH;FMTTYPE=image/png:https://isaca-gwdc.org/wp-content/uploads/2025/08/it_audit.png
ORGANIZER;CN="Avneet Sabharwal":MAILTO:programs@isaca-gwdc.org
END:VEVENT
BEGIN:VEVENT
DTSTART;TZID=America/New_York:20260423T144500
DTEND;TZID=America/New_York:20260423T170000
DTSTAMP:20260413T000536Z
CREATED:20260221T221823Z
LAST-MODIFIED:20260413T000536Z
UID:35545-1776955500-1776963600@isaca-gwdc.org
SUMMARY:Annual FISMA and Risk Management Conference
DESCRIPTION:  \n \n  \nApril 23\, 2026\nVirtual Event (Zoom)\nEarn up to 2 CPE\n5 for GWDC Members\n$15 for Non-Members \n  \n  \n\n\n\nAnnual FISMA and Risk Management Conference \nTo protect federal information and systems\, the Federal Information Security Modernization Act of 2014 (FISMA) requires federal agencies to develop\, document\, and implement information security programs. The 2026 Annual FISMA Conference provides a useful update to IT Auditors and the Federal IT community on the current landscape and efforts to comply with FISMA. Come hear perspectives from senior federal executives who play key roles in FISMA compliance efforts. During this session\, you will learn about recent changes to the FISMA metrics\, and the opportunities and challenges agencies face in complying with FISMA. \nWho should attend? IT advisory or IT audit professionals that serve or support the Public Sector\, CIOs\, and CISOs. \nRegistration closes on April 22 @ 5PM. \nRegister Today! \n  \n\n  \nEvent Sponsor \nWe are proud to have Sikich. as the sponsor for this event. \n  \n \nSikich has approximately 2\,000 team members and operates across North America\, EMEA and APAC. Our approach is strategically and thoughtfully designed to help our clients\, teams and communities accelerate success. Sikich draws on a diverse portfolio of technology solutions to deliver transformative digital strategies. From corporations and not-for-profits to state and local governments and federal agencies\, Sikich clients utilize a broad spectrum of services and products to help them improve performance and achieve long-term\, strategic goals. Our professionals have performed extensive IT\, cybersecurity\, and privacy engagements across\nFederal environments. As a full-service provider to Federal government agencies\, our professionals have performed financial management advisory and assurance services\, such as: \n\nAssisting the U.S. Defense Industrial Base (DIB) sector in enhancing its cybersecurity posture within the multi-tier supply chain to ensure compliance with Cybersecurity Maturity Model Certification (CMMC) requirements.\nConducting CFO Act engagements on behalf of more than three dozen federal CFOs and Offices of Inspectors General (OIGs) in the Executive and Legislative Branches.\nConducting FISMA audits\, IT and cybersecurity performance audits\, evaluations of access controls\, configuration and change management\, systems development life cycle including audits of Agile and Waterfall implementations\, disaster recovery and contingency planning\, and overall governance and security frameworks.\nSupporting agencies adhere to the processes outlined in the National Institute of Standards and Technology (NIST) Special Publication (SP) 800 series and conducting Security Assessment and Authorization (SA&A) activities.\n\n  \n\n\n\n  \nSponsorship Opportunities \nIf you are interested in sponsoring a GWDC event\, or sponsoring the chapter as an annual sponsor\, please visit our sponsorship page. \nSponsorship Info \n  \n\n\n\nEvent Details \n\nDate and Time \n\n\nThe conference will be held on April 23\, 2026 from 2:45 PM – 5:00 PM. \nAdd this event to your calendar using the Add to Calendar link at the bottom of the page. \n  \n\n\nVirtual Event \n\n\nThe conference will be held using Zoom. \nPrior to the event\, participants must install the Zoom app on their respective devices. Participants using the web-based Zoom or calling via the phone may not be entitled to CPE credits. \n  \n\n\nPricing \n\n\nThe fee for GWDC Members is $5 for the conference.\nThe fee for all other registrants is $15 for the conference. \nTo become a member and take advantage of the member rate for our events\, among other benefits\, join ISACA and select the Greater Washington D.C. Chapter as your local chapter. \n  \n\n\nEvent Policies \n\n\nCancellation and refund for advance registrations is allowed if cancellations are submitted through the registration system by the date registration closes. Refunds vary depending on the date of cancellation and cost of the event. See ISACA GWDC Event Policies for details. \nThe GWDC welcomes your comments\, complaints\, suggestions\, questions\, and other feedback concerning our website information and services. \nAll complaints should be submitted through the Registration Contact Form. \n  \n\n  \n\n\n\n  \nInterested in Speaking at a Chapter Event \nIf you are interested in speaking at an upcoming conference\, please visit the Call for Speakers page and complete the form. \nCall for Speakers \n  \n\n\n\nConference Agenda \n \n\n2:45 PM – 2:55 PM \n\n\nOpening Remarks and Housekeeping \nLogistics\, CPEs\, etc. \n  \n\n \n\n3:00 PM – 4:50 PM \n\n\nPanel Discussion: 2026 Annual FISMA and Risk Management Framework \nModerator:  \n\nYehuda Schmidt\, CISA\, GRISC\, CGEIT\, CPA\nDirector @ Sikich\n\nPanelists:  \n\nJennifer Franks\nDirector\, Center for Enhanced Cybersecurity\, Acting Director & Analytics Foundry @ US Government Accountability Office (GAO)\nVictoria Yan Pillitteri\, CISSP\nSupervisory Computer Scientist and Security Engineering and Risk Management Group Manager @ National Institute of Standards and Technology (NIST)\nPatrick Bevill\, CISSP\n Chief Information Security Officer @ Federal Retirement Thrift Investment Board (FRTIB)\nFormer Fellow @ the National Institute of Standards and Technology\n\n\n\n4:50 PM – 5:00 PM \n\n\nClosing Remarks \n\n  \n\n\n\n  \nShare this Event \nIf you are interested\, planning to attend\, or attending this event\, please share with your colleagues across your social media networks. \n\n	\n		\n	\n			\n			\n								\n										\n													\n														\n												Share on X\n					\n					\n									\n			\n		\n			\n			\n								\n										\n													\n														\n												Share on Linkedin\n					\n					\n									\n			\n		\n			\n			\n								\n										\n													\n														\n												Share on Facebook\n					\n					\n									\n			\n		\n			\n			\n								\n										\n													\n														\n												Share on Print\n					\n					\n									\n			\n		\n			\n			\n								\n										\n													\n												Share on Email\n					\n					\n									\n			\n		\n		\n\n	\n\n\n  \n  \n\n\n\nPresenters \nAt times presenters for a session may change due to schedule conflicts and other unexpected situations. If a previously presenter has been substituted\, the changes will be noted. \n  \n\n \n\n\nYehuda Schmidt\nDirector @ Sikich\nCISA\, CRISC\, CGEIT\, CPA\n \nYehuda Schmidt is a Director with Sikich with over 30 years’ experience in assisting federal government agencies with IT risk assessments\, assessing systems and applications security posture in accordance with NIST standards\, business process improvement\, and program management. He has extensive experience in managing reviews of internal controls over financial reporting\, operational controls\, and risk management in compliance with Office of Management and Budget (OMB) Circular A-123. Yehuda is leading clients’ IT risk assessments in compliance with NIST SP 800-37\, and IT assessment in compliance with NIST SP 800-53. \nYehuda holds an MBA in Finance and Entrepreneurship\, and B.Sc. in Accounting and Economics from the Hebrew University of Jerusalem\, Israel. He is a Certified Public Accountant (CPA)\, a Certified Information Systems Auditor (CISA)\, a Certified Risk and Information Systems (CRISC)\, and Certified Governance of Enterprise IT (CGEIT) \n \n\n\n \n\n\nJennifer Franks\nDirector\, Center for Enhanced Cybersecurity and Acting Director\, Analytics Foundry @ US Government Accountability Office \nJennifer Franks directs the Center for Enhanced Cybersecurity within GAO’s Information Technology and Cybersecurity team. She oversees reviews that primarily focus on emerging cybersecurity issues and assessing an agency’s ability to protect the confidentiality\, integrity\, and availability of its sensitive data and computing infrastructure. Her multi-disciplinary teams actively review agencies’ computer security vulnerabilities across their enterprise-wide computing environment by assessing program management compliance and technical controls recommended for the agencies to follow in accordance with federal guidance and leading practices. In addition\, she leads reviews in the areas of IT management and operations\, financial management\, healthcare and public health IT\, data protection\, and privacy. \nFurther\, Jennifer serves as the Acting Director of the Analytics Foundry; a dedicated cloud computing environment that manages GAO’s complex analytical functions. \nJennifer earned a master’s degree in information security policy and management from Carnegie Mellon University and earned a bachelor’s degree in computer information systems from Hampton University. \n \n\n\n \n\n\nVictoria Yan Pillitteri\nSupervisory Computer Scientist and Security Engineering and Risk Management Group Manager @ National Institute of Standards and Technology (NIST)\nCISSP \nVictoria Yan Pillitteri\, CISSP\, Supervisory Computer Scientist and Security Engineering and Risk Management Group Manager at the National Institute of Standards and Technology (NIST). \nVictoria Yan Pillitteri is a supervisory computer scientist and manager of the Security Engineering and Risk Management Group at the National Institute of Standards and Technology (NIST). The group conducts the research and development of the suite of risk management\, systems security engineering\, and cybersecurity risk analytics and measurement guidance used for managing cybersecurity risk. She is the co-author of multiple NIST publications that are foundational for cybersecurity risk management\, including the security and privacy controls\, control assessment procedures\, the Risk Management Framework\, and the CUI security requirements and assessment procedures (Special Publications (SP) 800-53\, SP 800-53A\, SP 800-53B\, 800-37\, 800-171\, and 800-171A). \nMs. Pillitteri holds a B.S. in Electrical Engineering from the University of Maryland\, a M.S. in Computer Science\, with a concentration in Information Assurance\, from the George Washington University\, completed the Key Executive Leadership Program at American University\, and is a Certified Information Systems Security Professional (CISSP).\n \n \n\n\n \n\n\nPatrick Bevill\nChief Information Security Officer @ Federal Retirement Thrift Investment Board (FRTIB)\nCISSP \nPatrick Bevill is the Chief Information Security Officer at the Federal Retirement Thrift Investment Board (FRTIB). His thirty-year cybersecurity and technology career includes public and private sector experience in a variety of leadership roles\, including as a Federal CISO\, cybersecurity engineer\, and C-level and VP-level positions in everything from Fortune 500 companies to Silicon Valley startups. Patrick’s Federal career has been focused on driving cybersecurity maturity and enabling agile IT Security Operations\, and on interagency advocacy for the cybersecurity needs of the smaller\, non-CFO Act agencies. \nHe has a Master of Science degree in computer information systems from Boston University and a CISSP certification. He is also a recipient of a Fed100 award and a Presidential Rank Award\, the highest of honors for Federal employees. \n \n\n  \n\n\n\n  \nQuestions about this Event \n\n\nIf you have any registration questions about this event\, please contact us by completing the Registration Contact Form linked below. \nRegistration Questions \n  \n\n\n\n\nIf you have CPE questions after the event has concluded\, please contact us by completing the CPE contact form linked below. \nCPE Questions \n  \n\n\n  \n\n\n\nCPE Information \nEarn up to 2 Continuing Professional Education (CPE) credit in the area of Information Technology. The ISACA® Greater Washington\, D.C. Chapter is registered with the National Association of State Boards of Accountancy (NASBA) as a sponsor of continuing professional education on the National Registry of CPE Sponsors. State boards of accountancy have final authority on the acceptance of individual courses for CPE credit. Complaints regarding registered sponsors may be submitted to the National Registry of CPE Sponsors through its website: www.NASBARegistry.org \n  \n\nPoll Questions \n\n\nParticipants must respond to all the poll questions via the Zoom polling feature or chat log in order to receive NASBA CPE credits. The GWDC will not be responsible for the participant’s inability to respond to the polls. \n  \n\n\nCPE Distribution and Evaluation Survey \n\n\nCPEs will be distributed via e-mail along with the event evaluation survey after the completion of the event. Attendees must be present for the full event to receive full CPE credit. \n  \n\n\nLearning Objective \n\n\nAfter attending this event\, attendees will learn about updates on the current FISMA landscape and efforts to comply with FISMA. \n  \n\n\nCPE-Related Details \n\n\n\nPrerequisites: None\nAdvance Preparation: None\nProgram Knowledge Level: Basic\nDelivery Method:  Group Internet Based\nField of Study:  Information Technology – Technical
URL:https://isaca-gwdc.org/event/2026-annual-fisma-and-risk-management-conference/
LOCATION:Virtual Event
CATEGORIES:Conferences
ATTACH;FMTTYPE=image/png:https://isaca-gwdc.org/wp-content/uploads/2026/02/fisma_rmf.png
ORGANIZER;CN="Avneet Sabharwal":MAILTO:programs@isaca-gwdc.org
END:VEVENT
BEGIN:VEVENT
DTSTART;TZID=America/New_York:20260416T083000
DTEND;TZID=America/New_York:20260416T170000
DTSTAMP:20260414T204422Z
CREATED:20251106T161948Z
LAST-MODIFIED:20260414T204422Z
UID:34087-1776328200-1776358800@isaca-gwdc.org
SUMMARY:Future Tech DC 2026
DESCRIPTION:  \n\n\n \n\n\nFuture Tech DC 2026\nApril 16\, 2026 from 8:30 AM to 5:00 PM\nGeorge Mason University\, Arlington VA Campus\n7 CPE\n$179 for Members and Partner Organizations\n$249 for All Other Registrants \n  \n\n\n\n\n\n  \nTrust\, Privacy\, and AI: Resilience and Agility in the Age of Digital Transformation \nJoin us in the heart of Washington\, D.C.\, where innovators\, industry leaders\, and technology enthusiasts converge to shape the future of the digital landscape. This event offers: \n\nInsightful Sessions: Prepare for current and emerging challenges by exploring the balance of innovative emerging technologies with security and privacy in the digital age. Sessions are designed to empower auditors and cybersecurity professionals with strategies to ensure data protection and trust at every level of digital transformation.\nTailored Tracks: Choose from General\, Government\, and Workshop sessions\, including hands-on workshops.\nNetworking & Professional Growth: Connect with peers\, earn 7 CPE credits\, and gain practical tools to secure your organization.\n\nWho Should Attend this Event: IT / Cybersecurity professionals\, cybersecurity students\, auditors\, CISOs\, or business or government leaders \n \nRegistration closes on April 15 @ 5pm.  There is no walk-up registration for this event. \nRegister Today! \n\n  \n \n\n\n  \nRegistration Bundles Available (through April 9) \nEarly-bird registration pricing is not available for bundles and only applies to individual registrations. \n\n\nProfessional Bundles are available for businesses and organizations to purchase bundles of 10 registrations at the member rate. After purchase\, a discount code will be emailed. \nPurchase Professional Bundle \n\n\nStudent Bundles are available for colleges and universities to purchase bundles of 10 registrations for students at discounted student pricing. After purchase\, a discount code will be emailed. \nPurchase Student Bundle \n\n\n\n\n \n\n \nFuture Tech DC 2026 Presenters \nThank you to all of our conference presenters \n\n\n \nTim Brown\nSolarWinds\nOpening Keynote \n\n\n \nGeorge Kamide\nThe CISO Society\nLunch Keynote \n\n\n \nLarry Whiteside Jr.\nCONFIDE\nLunch Keynote \n\n\n \nIra Winkler\nCYE Security\nLunch Keynote \n\n\n\n\n \nDr. Linda Kostic\nUMUC\nGeneral Track Presenter \n\n\n \nMatthew D. Kohel\nSAUL EWING LLP\nGeneral Track Presenter \n\n\n \nDr. Kyle David\nDr. David\, LLC\nGeneral Track Presenter \n\n\n \nDanny Izquierdo\nDemandbase\nGeneral Track Presenter \n\n\n\n\n \nPrabhmeet Kohli\nNovamorph\nGeneral Track Presenter \n\n\n \nLaTonya E. Clark\nGeneral Track Presenter \n\n\n \nMike Keeney\nFreddie Mac\nGeneral Track Presenter \n\n\n \nKelly Siu\nMeta\nGeneral Track Presenter \n\n\n\n\n \nThadi Murali\nGeneral Track Presenter \n\n\n \nAlexis Appollonia Robinson\nAmazon\nGeneral Track Presenter \n\n\n \nDr. Amy Soller\nAI Industry SME\nGeneral Track Presenter \n\n\n \nMèlika D Carroll\nCohere\nGeneral Track Presenter \n\n\n\n\n \nDiya Wynn\nAWS\nGeneral Track Presenter \n\n\n \nAndrew Cunje\nAppian\nGeneral Track Presenter \n\n\n \nJesse Whaley\nCorticle & Digital Cyber Forge\nGeneral Track Presenter \n\n\n \nNat Habtesion\nLumen Technologies\nGeneral Track Presenter \n\n\n\n\n \nFernando Puerto Mendoza\nInter-American Development Bank\nGeneral Track Presenter \n\n\n \nRuchi Shewaramani\nWashington Health Benefit Exchange\nGeneral Track Presenter \n\n\n \nChris Haigh\nGovernment Track Presenter \n\n\n \nJennifer Franks\nGAO\nGovernment Track Presenter \n\n\n\n\n \nPerry Keating\nProtiviti Government Services\nGovernment Track Presenter \n\n\n \nBranden Reber\nFortreum\nGovernment Track Presenter \n\n\n \nGuy Walsh\nNDIA\nGovernment Track Presenter \n\n\n \nJason Boyd\nFederal Retirement Thrift Investment Board\nGovernment Track Presenter \n\n\n\n\n \nSuzanne Yuter\nGuidehouse\nGovernment Track Presenter \n\n\n \nDr. Jeffrey Pullen\nU.S. DOJ\nGovernment Track Presenter \n\n\n \nJason Yovich\nFDIC OIG\nGovernment Track Presenter \n\n\n \nMark Priebe\nDOE OIG\nGovernment Track Presenter \n\n\n\n\n \nVictoria Yan Pillitteri\nNIST\nGovernment Track Presenter \n\n\n \nDr. Michaela Iorga\nNIST/ITL\nWorkshop Instructor \n\n\n \nSelena Xiao\nNIST\nWorkshop Instructor \n\n\n \nInno Eroraha\nNet Security\nWorkshop Instructor \n\n\n  \n\nSpeaker Showcase Videos \nSeveral of the Future Tech presenters have showcase videos for their topics. \nView Speaker Showcase Videos \n  \n\n\n  \n \nAgenda \nThe conference will be held on April 16\, 2026 from 8:30 am to 5:00 pm. Add this event to your calendar using the Add to Calendar link at the bottom of the page. \nTailor your conference experience by choosing sessions in one of the three tracks.  Please note\, no advance selection is required for the General and Government Tracks. Registrants can attend the General and Government sessions on a first come basis on the day of the conference.  Selections for the workshop track will be made during registration. \nClick the link below to view the conference agenda\, parking information\, and CPE requirements. \nView Agenda and Logistics PDF \n  \n\n  \n \nKeynote Presentations \nOpening Keynote \nThe Sunburst Journey – From breach to closure in 5 years \nJoin Tim Brown from SolarWinds as he walks you through the lessons learned through the 5-year process. Starting with the Nation state attack\, the recovery\, the legal actions and finally the SEC dismissal of the case. It has been a journey for Tim personally as well as the company and the industry. \n  \nLunch Keynote \nThe Expanding CISO Role: A Live Debate on Developing Leadership That Delivers \nSee a lively keynote debate of highly experienced CISOs who bring decade of real-world leadership experience to the stage to challenge assumptions and debate what it means to succeed in the role today and what will be required to succeed tomorrow. Drawing on decades of leadership across different organizations and operating models\, they will explore whether it is actually possible for a CISO to get the role right when the expectations themselves are constantly shifting. \nThis lunch keynote is moderated by George Kamide (The CISO Society) and joined by panelists Larry Whiteside Jr. (CONFIDE) and Ira Winkler (CYE Security). \n  \n\n  \n \n\n\nGeneral Track \nVisionary Leaders in AI\, Emerging Tech\, Cybersecurity\, and Privacy \nHear from globally recognized thought leaders who are driving change in artificial intelligence\, emerging technologies\, cybersecurity\, and privacy. These inspirational talks will provide insights into the future of tech and its role in building a safer\, more innovative world. \nView General Track \n\n\nGovernment Track \nGovernment Focus: Federal\, State\, and Local Perspectives \nDive into sessions tailored to the unique challenges and opportunities faced by government entities and contractors. Explore innovative strategies for securing critical infrastructure\, enhancing digital services\, and navigating regulatory landscapes throughout government. \nView Government Track \n\n\nWorkshop Track \nPractical Skills and Cutting-Edge Tools \nParticipate in hands-on\, interactive workshops and labs that bring theory to life. Workshops will have pre-requisites for attendance as well as limited capacity. There is a limit of one workshop per registrant. There are system requirements and prerequisites for each workshop. \nView Workshop Track \n\n\n\n  \n \nPost-Event Activities and Training \n\n\n \nImmediately After the Conference \n5:00PM – 5:15PM: A raffle will be held immediately after the conference ends \n5:15PM – 7:00PM: A networking social will be held. Registrants should indicate during registration if the plan to attend. \n  \n\n\n \nPost-Event Training \nOn April 17\, a workshop on NIST AI Risk Management Framework (AI RMF) will be held at Mason Square. The workshop will be taught by Jim Wiggins from 8:30AM to 4:00PM. \nView Workshop Details \n\n\n\n\n \n\n\n  \nBe a Sponsor of this Year’s Conference! \nEvent sponsorships of $1\,000 per organization are available for this year’s Future Tech DC. Visit the site below for sponsor benefits\, submitting sponsorship payments\, and contacting the sponsorship team. \nSponsorship Info and Payment \n  \n\n\n \n\nEvent Hosts \nFuture Tech DC is led by ISACA GWDC and Hosted by GMU College of Engineering and Computing: \n\n\n \n\n\n \n\n\n\n  \nEvent Sponsors \nThank you to the following companies for sponsoring Future Tech DC 2026: \n\n\n \n\n\n \n\n\n \n\n\n\n\n \n\n\n \n\n\n \n\n\n\n  \nPartner Organizations \nThis event is presented in partnership with the following organizations: \n\n\n \n\n\n \n\n\n \n\n\n\n\n \n\n\n \n\n\n \n\n\n\n\n \n\n\n \n\n\n \n\n\n\n\n \n\n\n \n\n\n \n\n\n\n  \nGWDC Sponsors \nThank you to our annual sponsors for supporting the GWDC and its members! \n\n\n \n\n\n \n\n\n \n\n\n\n\n \n\n\n \n\n\n \n\n\n\n\n\n  \nShare this Event \nIf you are interested\, planning to attend\, or attending this event\, please share with your colleagues across your social media networks. \n\n	\n		\n	\n			\n			\n								\n										\n													\n														\n												Share on X\n					\n					\n									\n			\n		\n			\n			\n								\n										\n													\n														\n												Share on Linkedin\n					\n					\n									\n			\n		\n			\n			\n								\n										\n													\n														\n												Share on Facebook\n					\n					\n									\n			\n		\n			\n			\n								\n										\n													\n														\n												Share on Print\n					\n					\n									\n			\n		\n			\n			\n								\n										\n													\n												Share on Email\n					\n					\n									\n			\n		\n		\n\n	\n\n\n  \n  \n\n\n\n\n  \nAdditional Event Details \nDate and Time \nThe conference will be held on April 16\, 2026 from 8:30 am to 5:00 pm. \nRegistration will open at 8:00 AM. \nAdd this event to your calendar using the Add to Calendar link at the bottom of the page. \n  \nVenue Location\, Parking\, and Metro \nGeorge Mason University (GMU) Arlington Campus (Mason Square)\n3351 Fairfax Drive\, Arlington\, VA 22201 \nParking: Visitor parking is available underneath the school in the Fuse building or Van Metre Hall. Entrance to both garages is from Founders Way.  Please view the Mason Square parking map for additional information. Parking garages use the Metropolis parking system. Scan the QR code in the garage. \nMetro: The nearest Metro station is the Virginia Square-GMU station. It is a 5-minute walk from the metro station to the GMU Campus \n  \nPricing \n\nEarly Bird Pricing (through 3/6/26)\n$139 for Member and Partner Organizations\n$209 for all other registrants \n\n\nRegular Pricing\n$179 for Member and Partner Organizations\n$249 for all other registrants \n\nWhat’s included in the pricing: Breakfast\, Lunch\, Evening Networking/Social Event \nTo become a member and take advantage of the member rate for our events\, among other benefits\, join ISACA and select the Greater Washington D.C. Chapter as your local chapter. \n  \nEvent Policies \nCancellation and refund for advance registrations is allowed if cancellations are submitted through the registration system by the date registration closes. Refunds vary depending on the date of cancellation and cost of the event. See ISACA GWDC Event Policies for details. \nThe GWDC welcomes your comments\, complaints\, suggestions\, questions\, and other feedback concerning our website information and services. \nAll complaints should be submitted through the Registration Contact Form. \n  \n\n\n\n  \nQuestions about this Event \n\n\nIf you have any registration questions about this event\, please contact us by completing the Registration Contact Form linked below. \nRegistration Questions \n  \n\n\n\n\nIf you have CPE questions after the event has concluded\, please contact us by completing the CPE contact form linked below. \nCPE Questions \n  \n\n\n  \n\n\n\nCPE Information \nEarn up to 7 Continuing Professional Education (CPE) credit in the area of Information Technology. The ISACA® Greater Washington\, D.C. Chapter is registered with the National Association of State Boards of Accountancy (NASBA) as a sponsor of continuing professional education on the National Registry of CPE Sponsors. State boards of accountancy have final authority on the acceptance of individual courses for CPE credit. Complaints regarding registered sponsors may be submitted to the National Registry of CPE Sponsors through its website: www.NASBARegistry.org \n  \nCheck-ins and Checkouts \nParticipants must check into and out of the event in order to receive CPE credit. Participants will scan their conference badge in the morning at the registration desk and again at the end of the conference. Participants must attend the full day to receive the full amount of CPE credits. \n  \nCPE Distribution and Evaluation Survey \nCPEs will be distributed via e-mail along with the event evaluation survey after the completion of the event. Attendees must be present for the full event to receive full CPE credit. \n  \nLearning Objective \nAfter completing the course\, students will have a greater understanding of current trends and practices in AI\, Cybersecurity and Trust. Learning objectives for each session are included in the session description. \n  \nAdditional CPE Details \n\nPrerequisites: None\nAdvance Preparation: None\nProgram Knowledge Level: Basic\nDelivery Method:  Live\, In-Person\nField of Study:  Information Technology – Technical\n\n  \n\n\n 
URL:https://isaca-gwdc.org/event/future-tech-dc-2026/
LOCATION:George Mason University – Arlington\, 3351 Fairfax Drive\, Arlington\, VA\, 22201\, United States
CATEGORIES:Conferences
ATTACH;FMTTYPE=image/jpeg:https://isaca-gwdc.org/wp-content/uploads/2025/11/Future-Tech-DC-Logo-2026-Draft1-1.jpg
END:VEVENT
BEGIN:VEVENT
DTSTART;TZID=America/New_York:20260329T153000
DTEND;TZID=America/New_York:20260329T180000
DTSTAMP:20260226T172947Z
CREATED:20260226T015211Z
LAST-MODIFIED:20260226T172947Z
UID:35683-1774798200-1774807200@isaca-gwdc.org
SUMMARY:Special Meeting of the Chapter Membership
DESCRIPTION:  \n \n  \nMarch 29\, 2026\nHybrid (Zoom and The Boardroom in Arlington VA)\nEarn up to 1 CPE\nFor GWDC Members only\nComplimentary – No Registration Fee \n  \n  \n\n\n\nSpecial Member Meeting \nBylaws Vote + 1 CPE Debate + Networking + Prizes \nJoin us for an engaging and high-energy afternoon of networking\, chapter governance\, and a live industry debate that qualifies for 1 CPE. \nThe revised 2026 Chapter Bylaws have been approved by ISACA Global and voted on by the Chapter Board. We now need the membership to vote to formally adopt them. \nThis is a special meeting — and we are making it worth your time. \nWhat’s Included: \n\nNetworking and community connection\nFood and light refreshments\nTwo drink tickets per attendee\nLive debate session qualifying for 1 CPE\nPrizes and raffle giveaways\n\nRegistration closes on March 28 @ 5PM. \nRegister Today! \n  \n\n\n\n  \nSponsorship Opportunities \nIf you are interested in sponsoring a chapter event\, or sponsoring the chapter as an annual sponsor\, please visit our sponsorship page. \nSponsorship Info \n  \n\n\n\nEvent Details \n\nDate and Time \n\n\nThe special meeting will be held on Sundary\, March 29\, 2026 from 3:30 pm to 5:15 pm. \nAdd this event to your calendar using the Add to Calendar link at the bottom of the page. \n  \n\n\nHybrid Event \n\n\nDuring registration you will be asked whether you plan to attend in person or virtually. Please select “in-person” only if you know you will be able to attend. \n  \n\n\nIn-Person Details \nThe Board Room (Clarendon)\n925 N. Garfield Street\nArlington\, VA 22201 \nParking Information\nThere is street parking near the restaurant.  Parking is also available at the nearby Colonial Parking garage. The GWDC will not be paying for parking for this event. \nNearest Metro\nThe restaurant is a short walk from Clarendon Metro Station (Orange and Silver lines). \n\n\nVirtual Details \nThe conference will be held using Zoom. Prior to the event\, participants must install the Zoom app on their respective devices. Participants using the web-based Zoom or calling via the phone may not be entitled to CPE credits. \n\n\n\n  \n\nPricing \n\n\nThis event is for current GWDC members only!\nThere is no registration fee for this event. \nTo become a member and take advantage of the member rate for our events\, among other benefits\, join ISACA and select the Greater Washington D.C. Chapter as your local chapter. \n  \n\n\nEvent Policies \n\n\nCancellation and refund for advance registrations is allowed if cancellations are submitted through the registration system by the date registration closes. Refunds vary depending on the date of cancellation and cost of the event. See ISACA GWDC Event Policies for details. \nThe GWDC welcomes your comments\, complaints\, suggestions\, questions\, and other feedback concerning our website information and services. \nAll complaints should be submitted through the Registration Contact Form. \n  \n\n  \n\n\n\n  \nShare this Event \nIf you are interested\, planning to attend\, or attending this event\, please share with your colleagues across your social media networks. \n\n	\n		\n	\n			\n			\n								\n										\n													\n														\n												Share on X\n					\n					\n									\n			\n		\n			\n			\n								\n										\n													\n														\n												Share on Linkedin\n					\n					\n									\n			\n		\n			\n			\n								\n										\n													\n														\n												Share on Facebook\n					\n					\n									\n			\n		\n			\n			\n								\n										\n													\n														\n												Share on Print\n					\n					\n									\n			\n		\n			\n			\n								\n										\n													\n												Share on Email\n					\n					\n									\n			\n		\n		\n\n	\n\n\n  \n  \n\n\n\nAgenda \n \n\n03:30 PM – 04:00 PM \n\n\nNetworking \nNetworking\, food\, and drinks (two drink tickets per person) \nIn-person attendees will be entered into a raffle draw for prizes. \n\n \n\n04:00 PM – 4:15 PM \n\n\nSpecial Member Meeting: Bylaws Vote \nBrief overview of the updates to the chapter bylaws and official member vote (in-person and on Zoom). \nMembers are encouraged to review the proposed bylaws and summary of changes prior the meeting. \nVoting will be conducted via Online Survey.  For in-person attendees\, a QR code will be provided to enable voting via mobile devices.  For zoom attendees\, a survey link will be provided. \n\n \n\n04:15 PM – 05:15 PM \n\n\nLive Debate on AI Regulation: Protecting Society or Slowing Progress? \nArtificial intelligence is reshaping industries\, economies\, and national security. Governments around the world are proposing and implementing new regulatory frameworks — but are these measures necessary safeguards\, or could they hinder innovation and competitiveness? \nJoin us for a lively\, thought-provoking debate exploring: \n\nThe case for regulation — risk management\, accountability\, transparency\, and societal protection\nThe case against heavy regulation — innovation\, agility\, global competitiveness\, and unintended consequences\nWhat AI governance means for auditors\, cybersecurity professionals\, and technology leaders\n\nAudience participation and Q&A included. \n\n \n\n5:15 PM – 6:00 PM \n\n\nRaffle drawings and Wrap-Up \nContinued networking\, raffle drawings\, and prize announcements. \n\n  \nWhy Your Attendance Matters \nOur bylaws are the foundation for how the chapter operates — governance\, leadership structure\, member engagement\, and long-term sustainability. Your vote ensures the chapter remains strong\, compliant\, and positioned for growth. \nWe have not historically had strong turnout for special meetings. This time\, we are combining governance\, learning\, and community in one meaningful event. \nYour voice. Your vote. Your chapter. \n  \n\n\n\n  \nQuestions about this Event \n\n\nIf you have any registration questions about this event\, please contact us by completing the Registration Contact Form linked below. \nRegistration Questions \n  \n\n\n\n\nIf you have CPE questions after the event has concluded\, please contact us by completing the CPE contact form linked below. \nCPE Questions \n  \n\n\n  \n\n\n\nCPE Information \nEarn up to 1 Continuing Professional Education (CPE) credit in the area of Information Technology. The ISACA® Greater Washington\, D.C. Chapter is registered with the National Association of State Boards of Accountancy (NASBA) as a sponsor of continuing professional education on the National Registry of CPE Sponsors. State boards of accountancy have final authority on the acceptance of individual courses for CPE credit. Complaints regarding registered sponsors may be submitted to the National Registry of CPE Sponsors through its website: www.NASBARegistry.org \n  \n\nVirtual Attendees \n\n\nParticipants must respond to all the poll questions via the Zoom polling feature or chat log in order to receive NASBA CPE credits. The GWDC will not be responsible for the participant’s inability to respond to the polls. \n  \n\n\nIn-Person Attendees \n\n\nParticipants must stay through the entire debate session to earn the 1 hour of CPE. \n  \n\n\nCPE Distribution and Evaluation Survey \n\n\nCPEs will be distributed via e-mail along with the event evaluation survey after the completion of the event. Attendees must be present for the full event to receive full CPE credit. \n  \n\n\nLearning Objective \n\n\nAfter attending this event\, attendees will learn about current and future trends AI regulation. \n  \n\n\nCPE-Related Details \n\n\n\nPrerequisites: None\nAdvance Preparation: None\nProgram Knowledge Level: Basic\nDelivery Method: Group Internet Based and Group-Live\nField of Study: Information Technology – Technical
URL:https://isaca-gwdc.org/event/special-meeting-of-the-chapter-membership/
LOCATION:The Board Room\, 925 N. Garfield Street\, Arlington\, VA\, 22201\, United States
CATEGORIES:Conferences,Social Events
ATTACH;FMTTYPE=image/png:https://isaca-gwdc.org/wp-content/uploads/2026/02/special_member_meeting.png
ORGANIZER;CN="Avneet Sabharwal":MAILTO:programs@isaca-gwdc.org
END:VEVENT
BEGIN:VEVENT
DTSTART;TZID=America/New_York:20260219T083000
DTEND;TZID=America/New_York:20260219T123000
DTSTAMP:20260219T021800Z
CREATED:20250824T003823Z
LAST-MODIFIED:20260219T021800Z
UID:34370-1771489800-1771504200@isaca-gwdc.org
SUMMARY:Emerging Technology Conference 2026
DESCRIPTION:  \n \n  \nFebruary 19\, 2026\nVirtual Event (Zoom)\nEarn up to 4 CPE\n$10 for GWDC Members\n$30 for Non-Members \n  \n  \n\n\n\nEmerging Technology Conference 2026 \nEmerging Technology\, Quantum Computing\, AI \nArtificial intelligence (AI) is reshaping the landscape of IT audit and cybersecurity\, offering unprecedented opportunities and challenges for professionals in the field. This conference brings together thought leaders\, innovators\, and practitioners to explore how AI is transforming the way organizations secure their systems\, manage risks\, and navigate regulatory requirements. Through engaging sessions\, interactive workshops\, and dynamic discussions\, attendees will gain insights into: \n\nPractical applications of AI in enhancing cybersecurity defenses and streamlining IT audits\nNavigating the legal\, regulatory\, and ethical challenges posed by AI adoption\nStrategies for designing and implementing AI-driven solutions in enterprise environments\nLeveraging frameworks and tools to ensure AI systems are secure\, transparent\, and resilient\n\nConference highlights include expert-led discussions on the practical implementation and real-world application of artificial intelligence within the federal landscape and defense industrial base. Sessions will also explore emerging guardrails for responsible AI-assisted coding\, as well as the evolving role of autonomous technologies in strengthening cybersecurity resilience\, specifically AI resilience. \nWhether you’re an IT auditor\, cybersecurity professional\, or business leader\, this conference equips you with the knowledge and tools to harness the power of AI while addressing its unique risks. Prepare to lead your organization into the future with confidence\, innovation\, and resilience. \nRegistration closes on Feburary 18 @ 5PM. \nRegister Today! \n  \n\n\n\n  \nSponsorship Opportunities \nIf you are interested in sponsoring this event\, or sponsoring the chapter as an annual sponsor\, please visit our sponsorship page. \nSponsorship Info \n  \n\n\n\nEvent Details \n\nDate and Time \n\n\nThe conference will be held on February 19\, 2026 from 8:30 am to 12:30 pm. \nAdd this event to your calendar using the Add to Calendar link at the bottom of the page. \n  \n\n\nVirtual Event \n\n\nThe conference will be held using Zoom. \nPrior to the event\, participants must install the Zoom app on their respective devices. Participants using the web-based Zoom or calling via the phone may not be entitled to CPE credits. \n  \n\n\nPricing \n\n\nThe fee for GWDC Members is $10 for the conference.\nThe fee for all other registrants is $30 for the conference. \nTo become a member and take advantage of the member rate for our events\, among other benefits\, join ISACA and select the Greater Washington D.C. Chapter as your local chapter. \n  \n\n\nEvent Policies \n\n\nCancellation and refund for advance registrations is allowed if cancellations are submitted through the registration system by the date registration closes. Refunds vary depending on the date of cancellation and cost of the event. See ISACA GWDC Event Policies for details. \nThe GWDC welcomes your comments\, complaints\, suggestions\, questions\, and other feedback concerning our website information and services. \nAll complaints should be submitted through the Registration Contact Form. \n  \n\n  \n\n\n\n  \nInterested in Speaking at a Chapter Event \nIf you are interested in speaking at an upcoming conference\, please visit the Call for Speakers page and complete the form. \nCall for Speakers \n  \n\n\n\nConference Agenda \nConference agendas may change due to schedule conflicts and other unexpected situations. If a previously published agenda has changed\, the changes will be noted. \nThe conference agenda is being developed and updates will be posted when available. \n  \n \n\n08:30 AM – 09:30 AM \n\n\nGuardrails for AI Coding \nPresenter: Jon Zeolla (Zenable and SANS Instructor) \nGenerative AI is quickly becoming a default part of the software development lifecycle. Faster delivery can also increase security risk\, operational fragility\, and decisions that are difficult to review or audit after the fact. This session focuses on AI coding guardrails: practical\, developer-friendly controls that help teams adopt coding assistants with confidence while maintaining strong security\, governance\, and assurance. \nWe will walk through three maturity levels for agentic coding controls. Level 1 uses built-in steering mechanisms in modern agentic IDEs\, including project context files\, rules\, and instruction layers. These establish consistent expectations for architecture\, security patterns\, data handling\, logging\, and “how we do things here\,” so teams reduce variability and improve repeatability. Level 2 adds context-injection agents that deliver guidance at the right time. They provide the relevant requirements\, approved patterns\, and constraints based on what is changing\, the type of work underway\, and where the developer is in the workflow. Level 3 adds deterministic\, policy-as-code guardrails in pull requests and CI/CD to enforce security\, quality\, and compliance requirements with measurable outcomes and audit-ready evidence. These guardrails also learn from code changes and review outcomes\, continuously improving the context used in Levels 1 and 2 to strengthen controls over time. \n\n \n\n09:30 AM – 10:30 AM \n\n\nAI\, Data Governance\, and Sensitive Data Handling in Government Environments \nPresenter: Larry Pitts \nThis session explores how artificial intelligence tools interact with sensitive data in regulated and government-adjacent environments. Drawing on over a decade of government contracting experience\, Larry Pitts examines governance considerations for AI-enabled platforms\, including how data is collected\, processed\, stored\, and retained across government and commercial cloud infrastructures.  \nThe presentation will highlight practical differences between public-sector and commercial data architectures\, common governance gaps organizations encounter when adopting AI tools\, and the importance of transparency\, policy alignment\, and ethical considerations in AI deployment. Attendees will gain a clearer understanding of how to evaluate AI solutions through a data governance and compliance lens without slowing innovation. \nKey Takeaways: \n\nHow AI-based tools handle sensitive and regulated data in government contexts\nKey governance considerations when adopting AI in regulated environments\nDifferences between government and commercial cloud and data infrastructures\nPractical questions GRC teams should ask vendors about AI data usage\nEthical and policy-driven considerations for responsible AI adoption\n\n\n \n\n10:30 AM – 11:30 AM \n\n\nAI integration\, and cybersecurity resilience across the Defense Industrial Base (DIB) \nPresenter: Allen Westley \nThis session provides a senior-leadership perspective on emerging technologies\, AI integration\, and cybersecurity resilience across the Defense Industrial Base (DIB). Drawing from experience leading cybersecurity programs supporting mission-critical and classified environments\, Allen Westley discusses how organizations can align AI adoption with enterprise risk governance\, compliance obligations\, and operational resilience. \nThe presentation bridges strategy and execution\, focusing on translating digital risk into actionable leadership decisions. Topics include AI governance in high-assurance environments\, classified and unclassified network considerations\, and the human dimension of cybersecurity\, including mind privacy and cognitive security. Attendees will leave with a clearer understanding of how to balance innovation\, compliance\, and mission priorities at scale \nKey Takeaways: \n\nLeadership considerations for AI adoption in classified and regulated environments\nAligning AI strategy with enterprise risk governance and compliance needs\nManaging cybersecurity risk across classified and unclassified domains\nUnderstanding the human and cognitive dimensions of emerging technology risk\nPractical insights for building resilient\, compliance-driven AI governance models\n\n\n \n\n11:30 AM – 12:30 AM \n\n\nAutonomous Cybersecurity \nPresenter: Dr. Jeffrey Duffany (Politechnic University of Puerto Rico) \nAutonomous cybersecurity refers to the use of artificial intelligence (AI)\, machine learning (ML)\, and automation to detect\, prevent and respond to cyber threats with minimal human intervention. It aims to enhance traditional cybersecurity by improving speed\, accuracy\, and adaptability to emerging threats. The main benefits are faster threat mitigation\, reduced reliance on human analysts\, improved accuracy in threat detection and scalability across large networks. Some of the major challenges include sophisticated adversarial attacks against AI models and ethical concerns around full automation. Autonomous cybersecurity systems leverage AI\, machine learning (ML) and automation to identify\, analyze\, and neutralize cyber threats in real time. This approach significantly enhances an organization’s ability to counter advanced cyberattacks. \n\n  \n\n\n\n  \nShare this Event \nIf you are interested\, planning to attend\, or attending this event\, please share with your colleagues across your social media networks. \n\n	\n		\n	\n			\n			\n								\n										\n													\n														\n												Share on X\n					\n					\n									\n			\n		\n			\n			\n								\n										\n													\n														\n												Share on Linkedin\n					\n					\n									\n			\n		\n			\n			\n								\n										\n													\n														\n												Share on Facebook\n					\n					\n									\n			\n		\n			\n			\n								\n										\n													\n														\n												Share on Print\n					\n					\n									\n			\n		\n			\n			\n								\n										\n													\n												Share on Email\n					\n					\n									\n			\n		\n		\n\n	\n\n\n  \n  \n\n\n\nPresenters \nAt times presenters for a session may change due to schedule conflicts and other unexpected situations. If a previously presenter has been substituted\, the changes will be noted. \n  \n \n\n \n\n\nJon Zeolla\nCEO @ Zenable; SANS Instructor\nGCSA\, GCWN\, GPEN\, GCUX\, GPPA\, CISSP \nJon Zeolla is a full-stack security engineer and the founder and CEO of Zenable\, working at the intersection of quality engineering\, automation\, and emerging tech. He focuses on helping teams move fast without breaking things or compromising security. As a SANS Certified Instructor\, Jon travels globally to train organizations on AI safety\, cloud-native security\, and compliance. He is also a CNCF Ambassador and an active contributor to the open-source community. Jon regularly builds and shares projects that embed Governance\, Risk Management\, and Compliance (GRC) directly into developer workflows—favoring guardrails over gates to reduce friction and accelerate innovation. \nFinally\, Jon is an organizer of BSides Pittsburgh (the city’s largest security conference)\, an IANS Faculty member\, and an AWS community builder. You can see more of his contributions and awards at jonzeolla.com. \nAs a SANS Certified instructor\, Jon feels it is his responsibility to encourage curiosity in his students\, helping them to understand more than just what a tool says it can do on its label\, but digging deeper and working to understand how it was developed\, learning its tradeoffs and alternative use cases. He encourages students to get creative with how to use tools\, but also to periodically develop their own\, if only just to learn or better appreciate a solution. Jon’s expertise allows him to explain things simply and thoroughly while incorporating real-life examples. \nFrom an early age\, Jon started learning about security due to his competitiveness in video gaming. After developing and improving on a series of hacks and glitches\, he turned his attention to the systems and networks around him\, eventually getting to the point where his high school hired him part time to remediate vulnerabilities that he identified and disclosed. Jon’s love of finding ways that things could have unintended consequences\, coupled with his desire for efficiency and naturally analytical mind\, made the DevOps and Security Automation work a natural progression for him out of college. He has been digging into code\, processes\, and assumptions ever since\, with the goal of identifying and fixing vulnerabilities through automation and the creation of low-friction systems. \nEarly in his career\, Jon identified his interest in solving difficult and unique business problems through technology. When he noticed a clear gap in local technical networking events\, he created Steel City InfoSec and has been creating hands-on labs\, giving and facilitating presentations\, and setting up networking sessions for its roughly 1\,000 members of practitioners over the decade since. Throughout his career working at an R1 research university\, a top 5 US-based bank\, and a retailer with over 1\,200 stores\, Jon has leveraged automation and large scale analysis of security data to perform automated\, active defense activities shown to detect and withstand regular APT activities. \nJon holds three undergraduate degrees\, including a bachelor’s degree in Cyber Forensics and Information Security\, and while in school he was the recipient of two notable awards: “CIS Outstanding Undergraduate Student Award” and “IT Outstanding Student Award”. In 2017 he was inducted into the National Technical Honor Society as an Honorary Member. He holds a number of industry certifications including GCSA\, GCWN\, GPEN\, GCUX\, GPPA and CISSP. He is also a faculty member of the SANS Technology Institute\, an NSA Center of Academic Excellence in Cyber Defense and multiple winner of the National Cyber League competition. Jon is an active contributor to the cybersecurity community in Pittsburgh and nationally through various affiliations. \nWhen not behind a computer screen\, Jon can be found mountain biking through the Appalachian hills\, in the gym weightlifting\, or playing chess with his son. \n \n\n \n\n \n\n\nLarry Pitts\nDirector of Customer Success | AI Enablement & Government Technology \nLarry Pitts is a government contracting professional with over a decade of experience supporting state and federal agencies. He specializes in AI enablement\, data governance in AI-driven tools\, and technology adoption within regulated government environments. Larry has worked across the procurement lifecycle and understands the operational and compliance considerations that shape technology decisions in the public sector. \nAn active voice in the technology community\, he has moderated and participated in panels advocating for ethical AI adoption and expanded small business participation in government contracting. His work focuses on balancing innovation with responsible data governance practices. \n \n\n \n\n \n\n\nAllen Westley\nSenior Cybersecurity Leader | Founder | AI & Classified Network Strategy \nAllen Westley is a senior cybersecurity leader in the Aerospace and Defense sector\, where he drives classified network optimization\, AI-integrated cyber defense strategies\, and enterprise risk governance across mission-critical environments. He has led cybersecurity programs protecting multi-billion-dollar defense contracts and managed teams across secure and unclassified domains. \nAllen builds AI governance frameworks designed for high-assurance\, compliance-driven organizations within the Defense Industrial Base. He is also the founder of Cyber Explorer LLC and serves as a CISO-level advisor. A frequent speaker at NIST FISSEA\, ISC2\, and ISACA forums\, he writes and speaks on AI governance\, cognitive security\, and the evolving human dimension of cyber risk. \n \n\n \n\n \n\n\nDr. Jeffrey Duffany\nProfessor @ Politechnic University of Puerto Ric \nDr. Jeffrey L. Duffany is a full professor at Politechnic University of Puerto Rico in the graduate school of computer science. Duffany has many academic achievements to his name\, including being both a visiting scientist and visiting faculty member at several government and military research labs working in the area of cyberdefense. His biography is listed in “Who’s Who in the World\,” and he is a recipient of the Albert N. Marquis Lifetime Achievement Award for teaching and research. Widely published\, Duffany’s articles have appeared in many engineering and technology journals\, and he was asked by the Springer-Verlag publishing company to write the introductory chapter for a new book on computer and network security essentials. Duffany holds a BS in Electrical Engineering from the University of Connecticut; an MS in electrical engineering from Columbia University; and a dual PhD in computer and information engineering from Stevens Institute. \n \n\n  \n\n\n\n  \nQuestions about this Event \n\n\nIf you have any registration questions about this event\, please contact us by completing the Registration Contact Form linked below. \nRegistration Questions \n  \n\n\n\n\nIf you have CPE questions after the event has concluded\, please contact us by completing the CPE contact form linked below. \nCPE Questions \n  \n\n\n  \n\n\n\nCPE Information \nEarn up to 4 Continuing Professional Education (CPE) credit in the area of Information Technology. The ISACA® Greater Washington\, D.C. Chapter is registered with the National Association of State Boards of Accountancy (NASBA) as a sponsor of continuing professional education on the National Registry of CPE Sponsors. State boards of accountancy have final authority on the acceptance of individual courses for CPE credit. Complaints regarding registered sponsors may be submitted to the National Registry of CPE Sponsors through its website: www.NASBARegistry.org \n  \n\nPoll Questions \n\n\nParticipants must respond to all the poll questions via the Zoom polling feature or chat log in order to receive NASBA CPE credits. The GWDC will not be responsible for the participant’s inability to respond to the polls. \n  \n\n\nCPE Distribution and Evaluation Survey \n\n\nCPEs will be distributed via e-mail along with the event evaluation survey after the completion of the event. Attendees must be present for the full event to receive full CPE credit. \n  \n\n\nLearning Objective \n\n\nAfter attending this event\, attendees will learn about current and future trends in the emerging technology space. \n  \n\n\nCPE-Related Details \n\n\n\nPrerequisites: None\nAdvance Preparation: None\nProgram Knowledge Level: Basic\nDelivery Method:  Group Internet Based\nField of Study:  Information Technology – Technical
URL:https://isaca-gwdc.org/event/emerging-technology-conference-2026/
LOCATION:Virtual Event
CATEGORIES:Conferences
ATTACH;FMTTYPE=image/png:https://isaca-gwdc.org/wp-content/uploads/2025/08/emerging_tech.png
ORGANIZER;CN="Avneet Sabharwal":MAILTO:programs@isaca-gwdc.org
END:VEVENT
BEGIN:VEVENT
DTSTART;TZID=America/New_York:20260122T083000
DTEND;TZID=America/New_York:20260122T123000
DTSTAMP:20260121T120516Z
CREATED:20250823T210159Z
LAST-MODIFIED:20260121T120516Z
UID:34354-1769070600-1769085000@isaca-gwdc.org
SUMMARY:Data Protection\, Privacy\, and Controls Conference
DESCRIPTION:  \n \n  \nJanuary 22\, 2026\nVirtual Event (Zoom)\nEarn up to 4 CPE\n$10 for GWDC Members\n$30 for Non-Members \n  \n  \n\n\n\nData Protection\, Privacy\, and Controls Conference \nIn an era where data is currency and breaches dominate headlines\, protecting sensitive information has never been more critical—or more complex. Join the ISACA Greater Washington\, D.C. Chapter for a cutting-edge virtual conference that brings together industry leaders\, privacy professionals\, and cybersecurity practitioners to explore today’s most pressing data security and privacy challenges. \nAs privacy becomes a board-level concern and new AI-driven technologies introduce fresh risks\, this conference offers essential insights to future-proof your data security and compliance strategies. \nSecure your seat\, sharpen your skills\, and stay ahead of the curve in protecting what matters most—your data. \nRegistration closes on January 21 @ 5PM. \nRegister Today! \n  \n\n\n\n  \nSponsorship Opportunities \nIf you are interested in sponsoring this event\, or sponsoring the chapter as an annual sponsor\, please visit our sponsorship page. \nSponsorship Info \n  \n\n\n\nEvent Details \n\nDate and Time \n\n\nThe conference will be held on January 22\, 2026 from 8:30 am to 12:30 pm. \nAdd this event to your calendar using the Add to Calendar link at the bottom of the page. \n  \n\n\nVirtual Event \n\n\nThe conference will be held using Zoom. \nPrior to the event\, participants must install the Zoom app on their respective devices. Participants using the web-based Zoom or calling via the phone may not be entitled to CPE credits. \n  \n\n\nPricing \n\n\nThe fee for GWDC Members is $10 for the conference.\nThe fee for all other registrants is $30 for the conference. \nTo become a member and take advantage of the member rate for our events\, among other benefits\, join ISACA and select the Greater Washington D.C. Chapter as your local chapter. \n  \n\n\nEvent Policies \n\n\nCancellation and refund for advance registrations is allowed if cancellations are submitted through the registration system by the date registration closes. Refunds vary depending on the date of cancellation and cost of the event. See ISACA GWDC Event Policies for details. \nThe GWDC welcomes your comments\, complaints\, suggestions\, questions\, and other feedback concerning our website information and services. \nAll complaints should be submitted through the Registration Contact Form. \n  \n\n  \n\n\n\n  \nInterested in Speaking at a Chapter Event \nIf you are interested in speaking at an upcoming conference\, please visit the Call for Speakers page and complete the form. \nCall for Speakers \n  \n\n\n\nConference Agenda \nConference agendas may change due to schedule conflicts and other unexpected situations. If a previously published agenda has changed\, the changes will be noted. \n  \n \n\n08:30 AM – 09:30 AM \n\n\nAI Trust – Quality\, Sensitivity\, and Governance \nPresenter: Dr. James Barker (BigEye) \nThe world is excited over the abilities of AI. But\, Agents\, Advisors\, and Assistants all need quality data that is trusted and classified in order to be shared. Privacy professionals battle for the attention\, budget\, and priority of leadership but with the explosion of AI a reset is needed. Teams across a firm need to work to bring together the needs of data quality\, data privacy\, and data security to certify the use of data for AI. \nIn this session\, the idea of AI Trust will be examined\, surfaced\, described\, and direction will be provided in a manner to help privacy professionals educate leadership and stakeholders to build the case for the time\, talent\, and treasure of their organizations. This session will help set the stage for investment for success by discussing the need for information privacy and considering the idea of data sensitivity as it relates to privacy for AI. In addition we will diagram the role of data quality\, and the role of data security and governance of data for AI or CAID (Certified AI Data). \nJoin us in this session to help establish the privacy and security stage for AI. \n\n \n\n09:30 AM – 10:30 AM \n\n\nManaging Data Privacy and Other Risks in AI Agents \nPresenter: Tanya Baccam (SANS) \nAI agents ‐ autonomous or semi-autonomous systems capable of initiating actions\, making decisions\, and interacting with enterprise data ‐ are rapidly transforming operational models across the private sector\, government agencies\, and higher-education institutions. Their capabilities can introduce substantial efficiency and analytical value\, but they also can generate complex privacy\, security\, and compliance risks that exceed those of traditional AI tools. As organizations accelerate adoption\, internal audit\, cybersecurity\, privacy\, and risk management functions must adapt their assurance approaches to ensure safe\, accountable deployment. This session equips auditors and governance leaders with methodologies to assess and manage AI agent risks in environments where sensitive\, regulated\, and mission-critical data is pervasive. Leveraging extensive real-world expertise in AI governance\, cybersecurity\, privacy engineering\, and assurance disciplines\, the session will address how to: \n\nEvaluate the privacy and security risks inherent to AI agents.\nAlign AI agent governance with established regulatory and assurance frameworks – such as NIST AI RMF\, NIST CSF 2.0 Governance Function\, COBIT\, ISO/IEC 27001\, FERPA\, HIPAA\, – to provide cohesive\, auditable control structures across industries.\nAssess AI agent integration within business\, government\, and university workflows.\nDesign actionable audit procedures for AI agents.\n\nParticipants will leave with repeatable approaches to governing and auditing AI agents\, enabling them to support secure and ethical AI adoption while meeting escalating expectations from regulators\, boards\, and executive leadership. \n\n \n\n10:30 AM – 11:30 AM \n\n\nYour Car’s Hidden Passengers: Companies\, Cops\, and Criminals. Retake Control \nPresenters: Mike Pedrick\, Merry Marwig (Privacy4Cars)\, and Justin Pollard \nNot your grandparents’ Oldsmobile ‐ from integration with our smartphones to voice assistants to autonomous driving functionality\, today’s automotive products are more connected to the world around us than ever. With added convenience comes some interesting challenges to consumer privacy. In this panel\, two and a half car enthusiasts\, two privacy professionals\, and three data nerds will unpack the world of Connected Cars\, including the state of technology\, the effect of increasing regulatory pressures\, and most importantly\, what YOU can do to manage risk in this ever-changing landscape. \n\n \n\n11:30 AM – 12:30 PM \n\n\nData Protection for the Future: Threat Focused Data Protection\, Data Handling Best Practices and Thoughts on Protecting Data in an Era of Growing AI and Quantum Computing Capabilities \nPresenter: Kevin Garvey (SANS) \nData is the currency of companies worldwide. Protecting data has always been a challenge to companies and the rise of AI and concerns about Quantum continue to be talked about in alignment to data security. Protecting data requires administrative and technical controls to provide a level of comfort to senior leaders that their companies’ data is being protected. In this talk\, thoughts about how to have a threat-based view will be discussed\, best practices on handling data in organization from an administrative and technical perspective\, and what all leaders should know about when thinking of new AI and Quantum cybersecurity risks against their data. \n\n  \n\n\n\n  \nShare this Event \nIf you are interested\, planning to attend\, or attending this event\, please share with your colleagues across your social media networks. \n\n	\n		\n	\n			\n			\n								\n										\n													\n														\n												Share on X\n					\n					\n									\n			\n		\n			\n			\n								\n										\n													\n														\n												Share on Linkedin\n					\n					\n									\n			\n		\n			\n			\n								\n										\n													\n														\n												Share on Facebook\n					\n					\n									\n			\n		\n			\n			\n								\n										\n													\n														\n												Share on Print\n					\n					\n									\n			\n		\n			\n			\n								\n										\n													\n												Share on Email\n					\n					\n									\n			\n		\n		\n\n	\n\n\n  \n  \n\n\n\nPresenters \nAt times presenters for a session may change due to schedule conflicts and other unexpected situations. If a previously presenter has been substituted\, the changes will be noted. \n  \n \n\n \n\n\nDr. James Barker\nDirector of Professional Services @ BigEye \nDr. James M Barker has over three decades of experience in AI and Data. Jim currently serves as the Director of Professional Services at Bigeye\, where he leads professional services and champions data literacy\, governance\, and operational efficiency powered by AI. Collaborating with cross-functional teams\, Jim helps businesses adopt robust DataOps frameworks to drive measurable outcomes\, leveraging proven methodologies and innovative approaches to data management. He is singularly focused on introducing and expanding Data Trust in all aspects of data including AI\, Analytics\, Operations Management\, Data Quality\, Data Privacy\, Data Security\, Compliance\, and DataOps. \nDr. Barker’s career spans consulting\, data strategy\, and digital transformation across a wide variety of industries including health care\, manufacturing\, finance\, and oil & gas. His experiences at Best Buy originated the system use of Gamification and Market Basket Analysis. At Thomson Legal & Regulatory (Thomson-Reuters) his team was one of the first to put Big Data into practice. The professional Services team at Informatica expanded the use of Data Quality and built the Velocity Data Migration Methodology which was further enhanced with data governance at Honeywell. The Honeywell data and data governance council originated the ‘House of Data’ to include aspects of data quality\, data privacy\, data security\, and standards for operational efficiency. \nAt Bigeye\, he focuses on empowering organizations to treat data as a strategic asset\, fostering data enablement and literacy at scale. His mission is to improve data quality and governance processes while advancing industry-wide adoption of cutting-edge solutions in data observability and AI-driven insights. \n  \n\n \n\n \n\n\nTanya Baccam\nSenior Instructor & Faculty Research Advisor @ SANS\nCPA\, GIAC GPPA\, GIAC GCIH\, CISSP\, CISM\, CISA\, CITP\, and OCP DBA \nTanya is an experienced information security and audit consultant and long-time instructor for SANS. She has consulted with a variety of clients about their cybersecurity and audit controls. She regularly conducts IT audits\, cybersecurity assessments\, web application penetration testing and issues SOC 2 reports. She regularly consults in areas such as system audits\, web server security\, web application security\, risk assessments\, penetration testing\, database security\, and network infrastructure design. She has played an integral role in developing multiple business applications in roles ranging from the Director of Assurance Services for a security services consulting firm\, the Manager of Infrastructure Security for a healthcare organization\, and as a Manager at Deloitte in the Security Services practice. Tanya is also a faculty member of the SANS Technology Institute\, an NSA Center of Academic Excellence in Cyber Defense and multiple winner of the National Cyber League competition. She currently holds CPA\, GIAC GPPA\, GIAC GCIH\, CISSP\, CISM\, CISA\, CITP\, and OCP DBA certifications. \n \n\n \n\n \n\n\nMike Pedrick \nMike Pedrick has been on both sides of the IT\, IS\, and GRC consulting/client table for more than 20 years. A doggedly client-focused program leadership advisor\, mentor\, and trainer for organizations including ISACA\, as well as a Chapter Board member for the same\, Mike has been building consulting programs and helping clients of all sizes across several industries navigate the troubled waters of risk management\, cybersecurity\, and business enablement. \n \n\n \n\n \n\n\nMerry Marwig\nPrivacy4Cars\nFIP\, CIPP/US\, CIPM \nMerry Marwig is a pro-consumer\, pro-business privacy advocate who is optimistic about what data privacy rights mean for everyday people’and for the companies they do business with. At Privacy4Cars ‘ the world’s leading authority on vehicle privacy and data security ‐ she helps protect driver and passengers’ personal data while creating business opportunities for automotive companies. Merry holds three IAPP certifications (FIP\, CIPP/US\, CIPM)\, is certified in Logical AI Governance\, and earned a master’s degree from the University of Illinois at Urbana-Champaign. \n  \n\n \n\n \n\n\nJustin Pollard \nJustin Pollard has been a leader in data and analytics for more than 15 years. An advocate for leveraging data with purpose\, his consumer-first approach to solving complex business problems has consistently proven that driving value and respecting consumer privacy are not mutually exclusive. Justin has enabled companies in industries including healthcare\, hospitality\, media\, and more to build data programs where decisions and value come together. \n  \n\n \n\n \n\n\nKevin Garvey\nCertified Instructor @ SANS \nKevin Garvey is a certified SANS Instructor and teaches about data protection\, privacy and controls worldwide as part of the SANS LDR (Leadership) 512 course. Previously\, Kevin was the Director of Governance\, Risk and Compliance at CLS Bank\, an international bank responsible for FX settlement based in New York City. Additionally\, Kevin previously headed Security Operations for CLS with responsibility for overseeing incident response\, vulnerability management\, cyber threat intelligence\, and the security operations center (SOC). Previously\, Kevin was the manager of Threat Management and Incident Response at WarnerMedia. Previous cybersecurity experience included his time at New York Power Authority and JP Morgan. Kevin has always had a passion to hunt down the adversary and has loved tackling the risk and threat challenges his responsibilities have thrown at him. Kevin teaches SANSLDR512: Security Leadership Essentials for Managers \n  \n\n  \n\n\n\n  \nQuestions about this Event \n\n\nIf you have any registration questions about this event\, please contact us by completing the Registration Contact Form linked below. \nRegistration Questions \n  \n\n\n\n\nIf you have CPE questions after the event has concluded\, please contact us by completing the CPE contact form linked below. \nCPE Questions \n  \n\n\n  \n\n\n\nCPE Information \nEarn up to 4 Continuing Professional Education (CPE) credit in the area of Information Technology. The ISACA® Greater Washington\, D.C. Chapter is registered with the National Association of State Boards of Accountancy (NASBA) as a sponsor of continuing professional education on the National Registry of CPE Sponsors. State boards of accountancy have final authority on the acceptance of individual courses for CPE credit. Complaints regarding registered sponsors may be submitted to the National Registry of CPE Sponsors through its website: www.NASBARegistry.org \n  \n\nPoll Questions \n\n\nParticipants must respond to all the poll questions via the Zoom polling feature or chat log in order to receive NASBA CPE credits. The GWDC will not be responsible for the participant’s inability to respond to the polls. \n  \n\n\nCPE Distribution and Evaluation Survey \n\n\nCPEs will be distributed via e-mail along with the event evaluation survey after the completion of the event. Attendees must be present for the full event to receive full CPE credit. \n  \n\n\nLearning Objective \n\n\nAfter attending this event\, attendees will learn about current and future trends in the data security and privacy space. \n  \n\n\nCPE-Related Details \n\n\n\nPrerequisites: None\nAdvance Preparation: None\nProgram Knowledge Level: Basic\nDelivery Method:  Group Internet Based\nField of Study:  Information Technology – Technical
URL:https://isaca-gwdc.org/event/data-security-privacy-conference-2026/
LOCATION:Virtual Event
CATEGORIES:Conferences
ATTACH;FMTTYPE=image/png:https://isaca-gwdc.org/wp-content/uploads/2026/01/data_privacy_controls.png
ORGANIZER;CN="Avneet Sabharwal":MAILTO:programs@isaca-gwdc.org
END:VEVENT
BEGIN:VEVENT
DTSTART;TZID=America/New_York:20251218T083000
DTEND;TZID=America/New_York:20251218T123000
DTSTAMP:20251215T014217Z
CREATED:20250823T203556Z
LAST-MODIFIED:20251215T014217Z
UID:34339-1766046600-1766061000@isaca-gwdc.org
SUMMARY:Security and Risks Insights Conference 2025
DESCRIPTION:  \n \n  \nDecember 18\, 2025\nVirtual Event (Zoom)\nEarn up to 4 CPE\n$10 for GWDC Members\n$30 for Non-Members \n  \n  \n\n\n\nSecurity and Risks Insights Conference 2025 \nNavigating the Future: A CISO’s Perspective on 2025 Security and Risk Priorities \nThe ISACA Greater Washington D.C. Chapter (GWDC) invites you to our Annual Security and Risk Insight Conference—a must-attend event for cybersecurity professionals and business leaders. This year’s seminar offers a comprehensive review of the most critical cybersecurity and risk trends from 2025 and provides actionable insights on where to focus your budget and training efforts for 2026. Whether you’re a CISO\, IT manager\, or business executive\, this conference equips you with the knowledge you need to prepare for the year ahead. \nThis conference provides in-depth analysis of 2025 Trends to understand the key developments that shaped the cybersecurity landscape in 2026. Attendees will gain actionable insights that you can apply immediately to strengthen your organization’s security posture. \nRegistration closes on December 17 @ 5PM. \nRegister Today! \n  \n\n\n\n  \nSponsorship Opportunities \nIf you are interested in sponsoring this event\, or sponsoring the chapter as an annual sponsor\, please visit our sponsorship page. \nSponsorship Info \n  \n\n\n\nEvent Details \n\nDate and Time \n\n\nThe conference will be held on December 18\, 2025 from 8:30 am to 12:30 pm. \nAdd this event to your calendar using the Add to Calendar link at the bottom of the page. \n  \n\n\nVirtual Event \n\n\nThe conference will be held using Zoom. \nPrior to the event\, participants must install the Zoom app on their respective devices. Participants using the web-based Zoom or calling via the phone may not be entitled to CPE credits. \n  \n\n\nPricing \n\n\nThe fee for GWDC Members is $10 for the conference.\nThe fee for all other registrants is $30 for the conference. \nTo become a member and take advantage of the member rate for our events\, among other benefits\, join ISACA and select the Greater Washington D.C. Chapter as your local chapter. \n  \n\n\nEvent Policies \n\n\nCancellation and refund for advance registrations is allowed if cancellations are submitted through the registration system by the date registration closes. Refunds vary depending on the date of cancellation and cost of the event. See ISACA GWDC Event Policies for details. \nThe GWDC welcomes your comments\, complaints\, suggestions\, questions\, and other feedback concerning our website information and services. \nAll complaints should be submitted through the Registration Contact Form. \n  \n\n  \n\n\n\n  \nInterested in Speaking at a Chapter Event \nIf you are interested in speaking at an upcoming conference\, please visit the Call for Speakers page and complete the form. \nCall for Speakers \n  \n\n\n\nConference Agenda \nConference agendas may change due to schedule conflicts and other unexpected situations. If a previously published agenda has changed\, the changes will be noted. \n  \n \n\n08:30 AM – 09:30 AM \n\n\nUnpopular Opinions in Cybersecurity: What CISOs Must Know and Do Differently in 2025 \nPresenter: Joshua Copeland (Crescendo) \nJoshua’s signature candid style tackling myths\, best practices\, and actionable insights for CISOs to lead effectively in a rapidly changing cyber landscape. \n\n \n\n09:30 AM – 10:30 AM \n\n\nA Pragmatic Approach to Security Leadership – From Vision to Investment \nPresenter: Charu Bansal (ING Bank) \nWith the rapidly evolving threat landscape\, rise in emerging technologies and increasing regulatory oversight\, the role of a security leader is to enable the business and manage risk while continuously investing in proactive defense. \nIn this talk\, I will share the fundamental pillars of our security roadmap\, highlighting key initiatives and risk management priorities that shape our approach. I’ll share how we view the “business of security” in a pragmatic way and the metrics used to measure impact and success. By bridging vision and investment\, this session will shed a light on how we foster a culture of security\, enable sustainable growth and build trust. \n\n \n\n10:30 AM – 11:30 AM \n\n\nIt’s the end of the world as we know it (and I feel fine) \nPresenter: Mike Coogan (Brinks Home) \nEvery year for the past 30 years\, security folks have talked about how next year will change the game. And for the most part\, we have been right. Threats increase\, adversaries get smarter\, and losses mount. Looking back on 2025\, we have seen a big increase in the threat landscape\, and there is no reason to believe that 2026 will get easier. That said\, rather than complaining about it and stirring up angst and fear\, perhaps we should look to the future with anticipation and hope. We get better every year as well and as long as we make attacks more costly for our adversaries\, we make progress in the war. \n\n \n\n11:30 AM – 12:30 PM \n\n\nStrategic Compliance Investment & ROI Optimization for Federal Contractors \nPresenter: Derrich Phillips (Aspire Cyber) \nCMMC 2.0 isn’t just a compliance hurdle it’s a strategic opportunity disguised as a requirement. Derrich Phillips dismantles the “checkbox mentality” plaguing CMMC implementations\, revealing how smart CISOs transform mandatory compliance into competitive advantage. Drawing from his military cyber operations background and federal contractor expertise\, this session provides a battlefield-tested approach to CMMC budgeting that strengthens security posture while maximizing business value. \nWhat Participants Will Achieve: \n\nMaster Strategic Budgeting: Develop comprehensive cost models covering assessments\, technology upgrades\, training\, and ongoing maintenance for sustainable CMMC compliance\nBuild Executive Buy-In: Learn proven techniques to present CMMC investments as business enablers that unlock federal contract opportunities and enhance market positioning\nOptimize Resource Allocation: Prioritize CMMC spending across 17 domains using risk-based frameworks that deliver maximum security impact per dollar invested\nCreate Implementation Roadmaps: Walk away with actionable 2026 planning templates that integrate CMMC milestones with broader cybersecurity and business objectives\nLeverage Compliance for Growth: Transform CMMC readiness into a competitive differentiator that accelerates federal contracting opportunities and client trust\n\nTarget Audience: CISOs\, Security Directors\, and Finance Leaders at organizations pursuing or maintaining federal contracts\, particularly those planning CMMC compliance strategies for 2026 and beyond. \n\n  \n\n\n\n  \nShare this Event \nIf you are interested\, planning to attend\, or attending this event\, please share with your colleagues across your social media networks. \n\n	\n		\n	\n			\n			\n								\n										\n													\n														\n												Share on X\n					\n					\n									\n			\n		\n			\n			\n								\n										\n													\n														\n												Share on Linkedin\n					\n					\n									\n			\n		\n			\n			\n								\n										\n													\n														\n												Share on Facebook\n					\n					\n									\n			\n		\n			\n			\n								\n										\n													\n														\n												Share on Print\n					\n					\n									\n			\n		\n			\n			\n								\n										\n													\n												Share on Email\n					\n					\n									\n			\n		\n		\n\n	\n\n\n  \n  \n\n\n\nPresenters \nAt times presenters for a session may change due to schedule conflicts and other unexpected situations. If a previously presenter has been substituted\, the changes will be noted. \n  \n \n\n \n\n\nJoshua Copeland\nDirector of Cybersecurity @ Crescendo \nJoshua Copeland is a seasoned cybersecurity leader and engineer with 25 years of experience focused on cloud and on-prem security. He specializes in building and operating security stacks\, SOC operations\, and cybersecurity governance\, risk\, and compliance (GRC) processes. Joshua excels at assembling diverse teams that translate technical details into actionable business capabilities. He has managed cybersecurity teams ranging from 1 to over 100 members and led security and compliance programs across physical\, personnel\, and cyber domains. Since 2021\, he has been known as the “Unpopular Opinion Guy” (UOG) on LinkedIn\, sharing candid perspectives on hiring\, mentoring\, and cybersecurity topics. Joshua serves as Adjunct Faculty at Tulane University and is a member of the Louisiana State Guard. He holds expertise across cybersecurity\, risk management\, VPN\, SIEM tools like McAfee ESM and Devo\, social engineering\, pen testing\, DISA STIGs\, and more. He previously held TS/SCI\, Public Trust\, and CJIS clearances. \n \n\n \n\n \n\n\nCharu Bansal\nInformation Security Lead\, Global Infrastructure @ ING Bank \nCharu is an accomplished information security leader with over 15 years of experience spanning a variety of industries – Media and Entertainment\, Technology\, and most recently Financial Services. Having lived and worked in Asia\, North America and Europe\, she has a global mindset and is known for her strategic foresight and ability to drive organizational transformation. She has successfully implemented enterprise-wide security programs\, strengthened organizational resilience against emerging cyber threats\, and fostered a culture of security awareness. In her current role\, she oversees the security for Global Infrastructure including cloud environments at ING bank and is based in the Netherlands. \n \n\n \n\n \n\n\nMike Coogan\nVice President\, IT Services & Chief Information Security Officer (CISO) @ Brinks Home \nMike Coogan is a Texas cybersecurity executive and the Vice President\, IT Services & Chief Information Security Officer (CISO) at Brinks Home. He joined the company in 2024\, bringing more than 25 years of broad IT experience across multiple industry sectors including financial services\, logistics and education. At Brinks Home\, Mike Coogan oversees global network\, infrastructure\, cloud\, database\, and security operations\, driving risk management\, production resilience\, technology innovation\, and budget optimization in partnership with business and IT leaders. \nA recognized community leader\, Mike has served in various roles with ISSA\, ISACA\, Infragard\, WiCyS\, Gartner/Evanta\, and HMG Strategy’s Houston Advisory Board\, shaping the regional and national executive dialogue on security\, risk\, and digital transformation. \n \n\n \n\n \n\n\nDerrich Phillips\nPresident and Founder @ Aspire Cyber \nDerrich Phillips is the President and Founder of Aspire Cyber\, a consultancy dedicated to guiding organizations through complex cybersecurity compliance frameworks like CMMC\, HIPAA\, and ISO 27001. A U.S. Army veteran and former Cyber Network Defender\, Derrich managed Top Secret communications in combat zones\, bringing military-grade discipline and precision to every mission. His post-service career spans top firms including Lockheed Martin and Bank of America\, where he recognized a critical need for cybersecurity support among small businesses and federal contractors. Today\, through Aspire Cyber\, Derrich empowers clients with clear\, actionable strategies and tools\, rooted in integrity\, service\, and leadership. \n \n\n  \n\n\n\n  \nQuestions about this Event \n\n\nIf you have any registration questions about this event\, please contact us by completing the Registration Contact Form linked below. \nRegistration Questions \n  \n\n\n\n\nIf you have CPE questions after the event has concluded\, please contact us by completing the CPE contact form linked below. \nCPE Questions \n  \n\n\n  \n\n\n\nCPE Information \nEarn up to 4 Continuing Professional Education (CPE) credit in the area of Information Technology. The ISACA® Greater Washington\, D.C. Chapter is registered with the National Association of State Boards of Accountancy (NASBA) as a sponsor of continuing professional education on the National Registry of CPE Sponsors. State boards of accountancy have final authority on the acceptance of individual courses for CPE credit. Complaints regarding registered sponsors may be submitted to the National Registry of CPE Sponsors through its website: www.NASBARegistry.org \n  \n\nPoll Questions \n\n\nParticipants must respond to all the poll questions via the Zoom polling feature or chat log in order to receive NASBA CPE credits. The GWDC will not be responsible for the participant’s inability to respond to the polls. \n  \n\n\nCPE Distribution and Evaluation Survey \n\n\nCPEs will be distributed via e-mail along with the event evaluation survey after the completion of the event. Attendees must be present for the full event to receive full CPE credit. \n  \n\n\nLearning Objective \n\n\nAfter attending this event\, attendees will learn about current and future trends in the cybersecurity and risk space. \n  \n\n\nCPE-Related Details \n\n\n\nPrerequisites: None\nAdvance Preparation: None\nProgram Knowledge Level: Basic\nDelivery Method:  Group Internet Based\nField of Study:  Information Technology – Technical
URL:https://isaca-gwdc.org/event/security-and-risks-insights-conference-2025/
LOCATION:Virtual Event
CATEGORIES:Conferences
ATTACH;FMTTYPE=image/png:https://isaca-gwdc.org/wp-content/uploads/2025/08/security_risk.png
ORGANIZER;CN="Avneet Sabharwal":MAILTO:programs@isaca-gwdc.org
END:VEVENT
BEGIN:VEVENT
DTSTART;TZID=America/New_York:20251113T080000
DTEND;TZID=America/New_York:20251113T140000
DTSTAMP:20251106T141756Z
CREATED:20250824T152624Z
LAST-MODIFIED:20251106T141756Z
UID:34440-1763020800-1763042400@isaca-gwdc.org
SUMMARY:Leading Tech Conference
DESCRIPTION:  \n \n  \nNovember 13\, 2025\nGeorge Mason University (Arlington VA)\nEarn up to 4 CPE\nGWDC Member Fee is $125\nNon-Member Fee is $165 \n  \n  \n\n\n\n \nLeading Tech\, a SheLeadsTech Event \nTransforming the Future of Cybersecurity & IT Audit through Innovation \nWelcome to Leading Tech: Transforming the Future of Cybersecurity & IT Audit through Innovation\, a SheLeadsTech event. This premier Washington\, D.C. conference showcases how innovation is redefining the future of cybersecurity and IT audit. Join us in person for dynamic sessions led by an exceptional lineup of female speakers\, connect with industry leaders\, innovators\, and technology enthusiasts to strengthen your professional community\, and walk away with practical insights to help shape the digital landscape of tomorrow. This event offers: \nDynamic Sessions: Dive into forward-thinking strategies and innovative solutions tackling today’s most urgent cybersecurity and technology challenges—while equipping yourself for tomorrow’s risks. Led by an exceptional roster of female experts\, these sessions are designed to spark critical thinking\, inspire challenging questions\, and bridge visionary ideas with real-world execution. \nIn-Person Networking: Forge valuable connections and engage in meaningful conversations with IT and cybersecurity leaders\, practitioners\, students\, and allies. Build relationships that strengthen professional networks and foster a true sense of community. \nProfessional Development: Leave with actionable insights\, practical skills you can implement immediately\, and the opportunity to earn 4 CPE credits—advancing both your expertise and your career. \nIT/Cybersecurity professionals\, cybersecurity students\, auditors\, CISOs\, or business and government leaders should attend this event. \nRegistration closes on November 12 @ 5PM. \nRegister Today! \n  \n\n\n\n  \nShare this Event \nIf you are interested\, planning to attend\, or attending this event\, please share with your colleagues across your social media networks. \n\n	\n		\n	\n			\n			\n								\n										\n													\n														\n												Share on X\n					\n					\n									\n			\n		\n			\n			\n								\n										\n													\n														\n												Share on Linkedin\n					\n					\n									\n			\n		\n			\n			\n								\n										\n													\n														\n												Share on Facebook\n					\n					\n									\n			\n		\n			\n			\n								\n										\n													\n														\n												Share on Print\n					\n					\n									\n			\n		\n			\n			\n								\n										\n													\n												Share on Email\n					\n					\n									\n			\n		\n		\n\n	\n\n\n  \n  \n\n\n\nConference Agenda \nConference agendas may change due to schedule conflicts and other unexpected situations. If a previously published agenda has changed\, the changes will be noted. \n \n\n08:00 AM – 08:30 AM \n\n\nRegistration Check-in\, Networking\, and Complimentary Breakfast \n  \n\n \n\n08:30 AM – 09:45 AM \n\n\nKeynote Address: All Risks\, One Battlefield: Cybersecurity in the AI Era \nKeynote Presenter: Camille Stewart Gloster (CAS Strategies) \nThe boundaries between risks—cyber\, physical\, operational\, reputational—are collapsing. Artificial intelligence accelerates this shift\, allowing attackers to scale\, blend\, and disguise threats across domains. The battlefield is no longer segmented; it is unified\, dynamic\, and relentless. \nThis keynote explores how leaders and teams must adapt to an “all risks\, one battlefield” reality. It highlights how AI amplifies both the threat landscape and the defensive toolkit\, demanding more collaboration across disciplines\, sectors\, and geographies. Drawing on Camille Stewart Gloster’s work with companies from startups to global enterprises\, as well as her experience shaping national strategies at the highest levels of government\, the talk will deliver a vision of what’s next and practical steps to act now. \nLearning Objectives: \n\nRecognizing and responding to the collapse of traditional boundaries\,\nHarnessing AI’s potential for resilience as well as risk\, and\nBuilding collaborative\, innovative defenses that resonate from the boardroom to the SOC floor.\n\nThe future of cybersecurity will be defined not by technology alone\, but by leaders who embrace this unified battlefield with clarity\, creativity\, and courage. \n  \n\n \n\n10:00 AM – 10:55 AM \n\n\nFrom FOMO to Focus: A Strategic Approach to Cybersecurity Innovation \nPresenters: Stacey Champagne (Hacker in Heels) and Anna Wheeler (SSAW\, LLC) \nIn a field driven by constant change\, the pressure to adopt the latest technologies can overshadow the strategic thinking that makes innovation meaningful. In this dynamic fireside chat\, leaders will examine how organizations can build cybersecurity programs that are intentional\, not reactive—where innovation is guided by clear threat models\, realistic resource assessments\, and defined business outcomes rather than industry hype. Together\, we’ll explore the hidden costs of tool-first thinking and uncover practical frameworks for evaluating new technologies through a strategic lens. Attendees will gain insights on how to cultivate organizational discipline around innovation decisions\, calculate true ROI beyond vendor promises\, and create cybersecurity strategies that remain resilient to hype cycles while staying agile enough to capitalize on genuine breakthroughs that align with their mission. \nLearning Objectives: \n\nUnderstand how to evaluate emerging technologies against your organization’s actual threat landscape\, risk tolerance\, and resource capacity.\nLearn practical approaches to building organizational discipline around innovation decisions\, even when facing pressure from leadership or market trends.\nDiscover methods for calculating the true costs and ROI of cybersecurity innovations beyond initial implementation\, including hidden operational and cultural impacts.\n\n  \n\n \n\n11:05 AM – 12:00 PM \n\n\nRed & Blue Team Perspectives: Navigating the Evolving Threat Landscape \nModerator: Toni Benson (Peraton) \nPanelists: Kelly McCracken (Salesforce)\, Lara Meadows (ThreatConnect)\, and Krissy Safi (Protiviti) \nThe threat landscape is evolving faster than ever\, challenging security teams to stay ahead of sophisticated adversaries. Attackers are using AI to move faster\, scale their operations\, and outmaneuver traditional defenses. At the same time\, defenders are innovating with automated detection and response and new approaches to resilience. \nIn this session\, red and blue team perspectives come together to reveal how these shifting threats impact day-to-day operations and strategic decision-making. You’ll leave with both a strategic understanding of emerging risks and practical steps to strengthen your defenses and adapt your security program. \nLearning Objectives: \n\nAnticipate emerging threats and trends across the evolving cybersecurity landscape.\nApply defensive innovations\, including detection\, monitoring\, and automated response strategies.\nIntegrate red and blue team insights to improve controls\, incident response\, and proactive defense measures.\n\n  \n\n \n\n12:00 PM – 12:30 PM \n\n\nLunch (provided) and Networking \n  \n\n \n\n12:30 PM – 01:30 PM \n\n\nFriend\, Foe\, or Force Multiplier? A Debate on Cybersecurity and IT Audit in Action \nModerator: Chaitra Devaraysamudram Krishna (Fannie Mae) \nPanelists: Xin (Cindy) Tu and Kelly Volz (LPL Financial) \nWhen it comes to protecting organizations\, the first line of defense (cybersecurity) and the third line (IT audit) often find themselves in tension. Are they natural allies\, necessary challengers\, or something in between? In this dynamic debate session\, leaders from both functions will tackle real-world business scenarios — from responding to audit findings to prioritizing risk to navigating the intersection of advisory agreements and formal audits — to explore how these roles should (or shouldn’t) collaborate. The audience will gain an unfiltered look at the friction\, the opportunities\, and the innovative paths forward when two critical functions come together. Expect lively discussion\, spirited exchanges\, and fresh insights on how collaboration — or healthy tension — can transform the future of cybersecurity. \nLearning Objectives: \n\nExamine real-world scenarios that highlight both the friction and the opportunity between cybersecurity and IT audit.\nDifferentiate when collaboration drives progress versus when pushback or healthy tension strengthens outcomes.\nDiscover how to transform the audit–cybersecurity relationship into a catalyst for innovation\, trust\, and long-term resilience.\n\n  \n\n \n\n01:30 PM – 02:00 PM \n\n\nConference Conclusion and Networking \n  \n\nThe Vendor Hall will be open throughout the conference. \n  \nSpeaker Showcase \n\n \nLeading Tech Speaker Showcase – Toni Benson \nThis video provides an introduction to Toni Benson\, who is the moderator for the session “Red & Blue Team Perspectives: Navigating the Evolving Threat Landscape” at the ISACA-GWDC Leading Tech Conference\, a SheLeadsTech event\, on November 13th\, 2025. \n \n  \n\n  \n\n \nLeading Tech Speaker Showcase – Lara Meadows \nThis video provides an introduction to Lara Meadows\, who is a panelist for the session “Red & Blue Team Perspectives: Navigating the Evolving Threat Landscape” at the ISACA-GWDC Leading Tech Conference\, a SheLeadsTech event\, on November 13th\, 2025. \n \n  \n\n  \n\n\n\n  \nInterested in Joining ISACA and the GWDC? \nIf you are interested\, planning to attend\, or attending this event\, please share with your colleagues across your social media networks. \nTo become a member and take advantage of the member rate for our events\, among other benefits\, join ISACA and select the Greater Washington D.C. Chapter as your local chapter. \nJoin ISACA today!More about Membership Benefits \n  \n  \n\n\n\nAdditional Event Details \n\nDate and Time \n\n\nThe conference will be held on November 13\, 2025 from 8:00 am to 2:00 pm. \nAdd this event to your calendar using the Add to Calendar link at the bottom of the page. \n  \n\n\nIn-Person Event \n\n\nGeorge Mason University (GMU) Arlington Campus (Mason Square)\n3351 Fairfax Drive\, Arlington\, VA 22201 \nParking: Visitor parking is available in the Van Metre Hall (formerly Founders) Garage\, located directly beneath the school. To access the garage\, use the entrance located off of Kirkwood Drive\, in between Fairfax Drive and Washington Boulevard.  Please view the Mason Square parking map for additional information. \nMetro: The nearest Metro station is the Virginia Square-GMU station. It is a 5-minute walk from the metro station to the GMU Campus \n  \n\n\nPricing \n\n\nThe per-person fee for GWDC and Partner Organization Members is $99 for the conference until October 17\, afterward the fee is $125. \nThe per-person fee for Non-Members is $139 for the conference until October 17\, afterward the fee is $165. \n  \n\n\nEvent Policies \n\n\nCancellation and refund for advance registrations is allowed if cancellations are submitted through the registration system by the date registration closes. Refunds vary depending on the date of cancellation and cost of the event. See ISACA GWDC Event Policies for details. \nThe GWDC welcomes your comments\, complaints\, suggestions\, questions\, and other feedback concerning our website information and services. \nAll complaints should be submitted through the Registration Contact Form. \n  \n\n  \n\n\n\n  \nSponsorship Opportunities \nIf you are interested in sponsoring this event or sponsoring the chapter as an annual sponsor\, please visit our sponsorship page. \nSponsorship Info \n  \n\n\n\nConference Sponsors \n\n \n\n\n  \nPartner Organizations \nThis event is presented in partnership with: \n\n \n\n\n \n\n  \n\n \n\n\n \n\n  \n\n\n\n  \nInterested in Speaking at a Chapter Event \nIf you are interested in speaking at this conference\, please visit the Call for Speakers page and complete the form. \nCall for Speakers \n  \n\n\n\nPresenters \nAt times presenters for a session may change due to schedule conflicts and other unexpected situations. If a previously presenter has been substituted\, the changes will be noted. \n  \n \n\n \n\n\nCamille Stewart Gloster\nDCEO and Principal @ CAS Strategies\nCISSP\, PMP \nCamille Stewart Gloster is a strategist\, attorney\, and executive recognized for her expertise at the intersection of technology\, cybersecurity\, national security\, and foreign policy. She is the CEO and Principal of CAS Strategies\, a strategic advisory firm helping governments\, companies\, and nonprofits navigate converging risks across AI\, cybersecurity\, and digital governance. \nThroughout her career\, Camille has operated at the leading edge of emerging technologies and their impact on systems\, institutions\, and society. Her work spans technical\, policy\, and operational leadership across sectors. Early in her career\, she worked at Cyveillance\, focusing on internet governance\, cyber defense\, and digital safety. At the Department of Homeland Security\, she advanced democratic resilience and privacy as Senior Policy Advisor for Cyber. At Google\, she led product security strategy for Alphabet and built the Security Policy and Election Integrity teams for Google Play and Android. \nAs Deputy National Cyber Director for Technology & Ecosystem Security at the White House (2022–2024)\, Camille advised the President and led national efforts on AI security\, quantum readiness\, and tech workforce development. She played key roles in the 2023 National Cybersecurity Strategy\, the AI Executive Order\, and the 2024 Data Security Executive Order. \nCamille is also a researcher\, speaker\, and the co-founder of #ShareTheMicInCyber. Her work has earned recognition from Business Insider (AI 100)\, Microsoft (Security Changemaker)\, and Washingtonian (500 Most Influential). She holds a J.D. from American University\, a CISO certificate from Carnegie Mellon\, and CISSP and PMP certifications. \n \n\n \n\n \n\n\nStacey Champagne\nFounder & CEO of Hacker @ Heels \nStacey Champagne is the Founder & CEO of Hacker in Heels\, a company on a mission to elevate women into positions of power within the cybersecurity industry. With over a decade of hands-on experience\, she has built cybersecurity programs at Fortune 500 companies\, startups\, and the federal government\, and continues to lead from the front lines as a Senior Principal Consultant specializing in insider risk management\, cybersecurity strategy\, and incident response. She holds two master’s degrees\, one in Security and Resilience Studies\, Cybersecurity Policy from Northeastern University\, and the second in Criminal Justice\, Cybercrime Investigation and Cybersecurity from Boston University\, as well as multiple industry certifications including CISSP\, GSLC\, GSOM\, and ITPM. For her efforts in coaching and championing women in cybersecurity\, Stacey was recognized as a 2024 Top 20 Cybersecurity Woman of the World by United Cybersecurity Alliance\, and 2023 Cybersecurity Advocate of the Year by Women’s Society of Cyberjutsu. \n \n\n\n \n\n\nAnna Wheeler\nChief Executive Officer @ SSAW\, LLC \nAnna Wheeler is a seasoned cybersecurity strategist with over 20 years of experience bridging the gap between emerging technology\, government\, and commercial sectors. As a dynamic leader and technologist\, she has played a pivotal role in shaping national security initiatives and driving innovative solutions across critical infrastructure. \nWhile serving as a Strategic Initiatives Lead at Leidos\, Anna was ]instrumental in penetrating the Department of Homeland Security’s Cybersecurity and Infrastructure Security Agency (DHS CISA)\, transforming a strategic growth area into a $6 billion pipeline with $2.5 billion in awarded contracts. Her ability to identify and mitigate challenges years in advance resulted in over $900 million in cost savings while managing a portfolio valued at $15.5 billion. \nAnna’s expertise spans public sector leadership roles at Giant Oak\, Qualys\, Akamai\, and Symantec\, where she developed and executed high-impact strategies\, advised federal agencies\, and built coalitions to enhance cybersecurity resilience. Her deep understanding of risk management\, compliance\, and technology integration has enabled government agencies to stay ahead of evolving threats. \nA U.S. Army veteran\, Anna served as a Blackhawk helicopter crew chief and door gunner\, an experience that shaped her leadership\, adaptability\, and mission-first mindset. She is a sought-after speaker on cybersecurity\, AI\, and national security\, having engaged audiences at Cyber Women on Capitol Hill\, the Offset Symposium\, and AI for Good. \nBeyond her professional roles\, Anna serves on advisory boards for emerging technology companies\, guiding innovation in cybersecurity and risk management. She holds an active Top Secret clearance and continues to drive forward-thinking solutions that safeguard the nation’s digital and physical security. \n \n\n \n\n \n\n\nToni Benson\nDirector @ Peraton\nPMP\, CISSP \nToni S. Benson is a senior cybersecurity and strategy leader with more than 20 years of experience spanning the U.S. Air Force\, federal government\, and private sector. She is recognized nationally for her leadership in building cybersecurity workforce initiatives\, advising C-suite leaders\, and developing technology-driven strategies that empower diverse Teams. \nShe currently serves as a Director at Peraton where she is the Program Manager who leads strategic optimization initiatives across Department of State programs\, supporting innovation\, operations\, and threat intelligence. \nAs a federal government civilian she served in many roles the supported the Cybersecurity and Infrastructure Security Agency (CISA)\, in cyber threat intelligence\, workforce development\, and stakeholder engagement. Toni directed over $42M in federal grants expanding cyber education across the nation\, developed shared curricula for workforce growth\, and advised at White House-level forums. Toni is a Harvard Executive Leadership Fellow\, PMP\, and CISSP whose dynamic presence and storytelling connect strategy to action\, helping audiences see the human side of cybersecurity and leadership. \n \n\n\n \n\n\nKelly McCracken\nSenior Vice President\, Detection and Response @ Salesforce \nKelly McCracken is a highly accomplished executive with over 20 years of experience in the cybersecurity and technology industry\, specializing in establishing and standardizing incident response programs and Security Operations Centers (SOCs). Her expertise includes developing and leading national-level cybersecurity initiatives for the federal government\, notably co-authoring the National Institute of Standards and Technology (NIST) Standard Publication (SP) 800-61\, Computer Security Incident Handling Guide\, rev. 1\, which stands as the national standard for incident response. Ms. McCracken has successfully applied this deep experience to assist Fortune 100 companies in building world-class incident response programs capable of detecting and responding to advanced threats. \nSince joining Salesforce in 2015\, Ms. McCracken has significantly advanced and matured the company’s detection and incident response capabilities. Under her leadership\, she matured the global incident response organization into the Cyber Security Operations Center (CSOC)\, overseeing all of detection and response for Salesforce to maintain Salesforce’s position as the world’s most trusted customer relationship management platform. She oversees a global team of incident handlers\, security event analysts\, security engineers\, threat intelligence analysts\, data scientists\, and communications specialists. \nMs. McCracken holds a Bachelor of Business Administration in Computer Information Systems from James Madison University\, a Master of Science in Information & Telecommunication Systems from Johns Hopkins University\, and a Master of Business Administration from the Kenan-Flagler School of Business\, University of North Carolina Chapel Hill. \n \n\n\n \n\n\nLara Meadows\nGlobal Vice President of Security Architects @ ThreatConnect\nCISSP\, CISM \nLara Meadows is the Global Vice President of Security Architects at ThreatConnect\, a Threat and Risk-Informed Defense Platform. With more than 20 years of experience\, she began her career as a security systems engineer at Trusted Information Systems (TIS)\, the pioneer of the first firewall\, and went on to hold technical leadership roles at Symantec\, Cisco\, HP ArcSight/Micro Focus and Recorded Future. She has built and led global security engineering teams\, helped start-ups grow into Gartner-recognized leaders\, and guided Fortune 500 companies and U.S. federal agencies in strengthening their cybersecurity strategies. A passionate advocate for advancing women in technology\, Lara mentors through organizations like WiCyS\, #GirlsClub\, WiT\, and the PreSales Collective. She holds CISSP\, CISM\, and GIAC certifications. \n \n\n\n \n\n\nKrissy Safi\nManaging Director @ Safi \nI am a creator\, builder and leader of global businesses and highly effective teams\, with over 2 decades of Information Security experience across all domains of security in support of Fortune 500 companies and government agencies\, working throughout numerous international locations. [Ethical] Hacker turned business leader = creative thinker with an entrepreneurial spirit driving the development of multi-million dollar security practices for both private and public sector. \nI serve as Managing Director at Protiviti\, where I lead our Global Offensive Security Services practice. For over five years\, I’ve driven business growth\, nurtured high-performing teams\, and spearheaded initiatives that advance innovation and integrate AI into our solutions. My focus extends beyond operational excellence to shaping strategies that deliver impact both internally and across the industry. \nIn addition to my professional pursuits\, I am deeply committed to fostering Diversity\, Equity & Inclusion within the industry through initiatives such as Women in Cyber and Tech\, P-TECH\, Cyber Patriots\, and Cyber Day for Kids among others. I firmly believe that empowering diverse voices not only enriches our community but also ignites creativity and innovation. \nI serve on the board of the Innovation Center for the St. Vrain Valley School District in Colorado\, where I help shape the future of education. By bringing real-world industry insights into the classroom\, I aim to inspire bold ideas\, empower educators\, and prepare students to thrive in a world driven by innovation and possibility. \n \n\n \n\n \n\n\nChaitra Devaraysamudram Krishna\n IT Internal Audit Director @ Fannie Mae \nChaitra has 18 years of experience in the Technology Audit field\, where she started out as an intern in Fannie Mae’s IT Audit team back in 2006. Chaitra currently serves as a director within the same team. In her role\, she is responsible for overseeing technology infrastructure\, data\, and cybersecurity audits. She regularly collaborates with Infosec and technology infrastructure organizations as part of audits\, issue follow-up\, and continuous monitoring – focused on delivering Internal Audit’s point of view on top risks. She is also involved in problem-solve and team engagement efforts to improve the efficiency and effectiveness of audit processes. \nChaitra’s recent experience includes access management\, vulnerability management\, security configurations\, threat management and incident response\, third-party security\, AWS\, data governance\, including assessment of emerging risks such as GenAI and quantum computing – serving as a trusted partner for technology leadership. She regularly provides thought leadership in the validation of closure of high-risk and regulatory findings. Additionally\, she has participated in several leadership\, career development and cybersecurity panels to inspire and encourage other members of the field. \nChaitra holds a master’s degree in computer science from Louisiana State University. She is also a Certified Internal Auditor\, Certified Information Systems Auditor\, and Certified Information Systems Security Professional. Chaitra enjoys developing team members by helping them build competencies to achieve their career goals. \n \n\n\n \n\n\nXin (Cindy) Tu\nAudit Executive in AI\, Data and IT\, Financial Services \nXin “Cindy” Tu is an Audit Executive in the Financial Services industry with over 18 years of experience. Cindy has spent the last 10 years designing and improving IT and Data Audit Frameworks for Financial Services Companies. Additionally\, Cindy specialized in Data Governance and AI Governance Framework. \nIn her spare time\, Cindy participates actively in industry groups. She serves on the editorial board of CDO Magazine and AI Advisory Board of HotTopics and contributes to Data Governance and AI Governance Framework development by participating in CDMC Working Group and AI\, Data & Analytics Capabilities Working Group at EDM Council and American Bankers Association. \n \n\n\n \n\n\nKelly Volz\nSVP\, Governance Risk and Controls @ LPL Financial\nCISSP \nKelly Volz is the Senior Vice President leading Technology Governance Risk and Controls under the Chief information Security Officer for LPL Financial. She is responsible for policies\, program and third-party assessments\, issues and risk management\, regulatory readiness\, and the business office and works closely with stakeholders across business\, technology\, cybersecurity\, data\, finance\, legal\, risk\, and internal audit. Kelly is living out her passion by operating strategically across the business and making an impact in an innovative company going through transformation. \nKelly joined LPL from EY\, where she was a Managing Director and Regional Leader in the Cybersecurity Practice for the Financial Services Sector. She was the executive sponsor for EY’s relationships with Financial Services Information Sharing and Analysis Center (FS-ISAC)\, Cyber Risk Institute (CRI)\, and was the group diversity champion. While at EY\, Kelly was instrumental in uplifting cybersecurity program governance and maturity\, measuring and reducing risks\, gaining executive buy-in and investment\, leading major initiatives and closing regulatory findings\, and uniting teams across the enterprise towards joint outcomes. \nKelly is a Certified Information Systems Security Professional (CISSP)\, a member of the Association of Certified Fraud Examiners (ACFE)\, and has achieved certificates in Forensic Accounting\, Georgetown University CCPE and Insider Threat Program Manager\, Carnegie Mellon University SEI. Kelly recently spoke at the Executive Women’s Forum (EWF) Annual Conference and FAIR Institute Annual Conference and is the current executive sponsor for Women in Cybersecurity (WiCys) at LPL. \n \n\n  \n\n\n\n  \nQuestions about this Event \n\n\nIf you have any registration questions about this event\, please contact us by completing the Registration Contact Form linked below. \nRegistration Questions \n  \n\n\n\n\nIf you have CPE questions after the event has concluded\, please contact us by completing the CPE contact form linked below. \nCPE Questions \n  \n\n\n  \n\n\n\nCPE Information \nEarn up to 4 Continuing Professional Education (CPE) credit in the area of Information Technology. The ISACA® Greater Washington\, D.C. Chapter is registered with the National Association of State Boards of Accountancy (NASBA) as a sponsor of continuing professional education on the National Registry of CPE Sponsors. State boards of accountancy have final authority on the acceptance of individual courses for CPE credit. Complaints regarding registered sponsors may be submitted to the National Registry of CPE Sponsors through its website: www.NASBARegistry.org \n  \n\nPoll Questions \n\n\nParticipants must respond to all the poll questions via the Zoom polling feature or chat log in order to receive NASBA CPE credits. The GWDC will not be responsible for the participant’s inability to respond to the polls. \n  \n\n\nCPE Distribution and Evaluation Survey \n\n\nCPEs will be distributed via e-mail along with the event evaluation survey after the completion of the event. Attendees must be present for the full event to receive full CPE credit. \n  \n\n\nLearning Objective \n\n\nAfter attending this event\, attendees will learn about current and future trends in the technology space. \n  \n\n\nCPE-Related Details \n\n\n\nPrerequisites: None\nAdvance Preparation: None\nProgram Knowledge Level: Basic\nDelivery Method:  Group Live\nField of Study:  Information Technology – Technical
URL:https://isaca-gwdc.org/event/leading-tech-conference/
LOCATION:George Mason University – Arlington\, 3351 Fairfax Drive\, Arlington\, VA\, 22201\, United States
CATEGORIES:Conferences
ATTACH;FMTTYPE=image/png:https://isaca-gwdc.org/wp-content/uploads/2025/08/leading_tech.png
ORGANIZER;CN="Avneet Sabharwal":MAILTO:programs@isaca-gwdc.org
END:VEVENT
BEGIN:VEVENT
DTSTART;TZID=America/New_York:20251030T083000
DTEND;TZID=America/New_York:20251030T123000
DTSTAMP:20251028T194944Z
CREATED:20250820T005937Z
LAST-MODIFIED:20251028T194944Z
UID:34243-1761813000-1761827400@isaca-gwdc.org
SUMMARY:Cybersecurity Conference 2025
DESCRIPTION:  \n \n  \nOctober 30\, 2025\nVirtual Event (Zoom)\nEarn up to 4 CPE\n$10 for GWDC Members\n$30 for Non-Members \n  \n  \n\n\n\nCybersecurity Conference 2025 \nSecuring the Digital Frontline – From Algorithms to Adversaries \nIn today’s rapidly evolving cyber landscape\, small incidents can have outsized consequences. This year’s Cybersecurity Conference explores how every vulnerability — no matter how minor — has the potential to disrupt critical systems\, compromise national security\, and erode public trust. \nThrough expert-led sessions\, the conference will delve into advanced penetration testing techniques\, the future of encryption in a post-quantum world\, and the interconnected nature of today’s threat environment. Attendees will gain a deeper understanding of how adversaries exploit gaps in technology and human behavior — and what organizations must do to stay resilient. \nWhether you’re in the public or private sector\, this conference will equip you with the knowledge to anticipate emerging threats and build robust\, forward-looking defenses. \nRegistration closes on October 29th @ 5PM. \nRegister Today! \n  \n\n\n\n  \nSponsorship Opportunities \nIf you are interested in sponsoring this event\, or sponsoring the chapter as an annual sponsor\, please visit our sponsorship page. \nSponsorship Info \n  \n\n\n\nEvent Details \n\nDate and Time \n\n\nThe conference will be held on October 30\, 2025 from 8:30 am to 12:30 pm. \nAdd this event to your calendar using the Add to Calendar link at the bottom of the page. \n  \n\n\nVirtual Event \n\n\nThe conference will be held using Zoom. \nPrior to the event\, participants must install the Zoom app on their respective devices. Participants using the web-based Zoom or calling via the phone may not be entitled to CPE credits. \n  \n\n\nPricing \n\n\nThe fee for GWDC Members is $10 for the conference.\nThe fee for all other registrants is $30 for the conference. \nTo become a member and take advantage of the member rate for our events\, among other benefits\, join ISACA and select the Greater Washington D.C. Chapter as your local chapter. \n  \n\n\nEvent Policies \n\n\nCancellation and refund for advance registrations is allowed if cancellations are submitted through the registration system by the date registration closes. Refunds vary depending on the date of cancellation and cost of the event. See ISACA GWDC Event Policies for details. \nThe GWDC welcomes your comments\, complaints\, suggestions\, questions\, and other feedback concerning our website information and services. \nAll complaints should be submitted through the Registration Contact Form. \n  \n\n  \n\n\n\n  \nInterested in Speaking at a Chapter Event \nIf you are interested in speaking at an upcoming conference\, please visit the Call for Speakers page and complete the form. \nCall for Speakers \n  \n\n\n\nConference Agenda \nConference agendas may change due to schedule conflicts and other unexpected situations. \n  \n \n\n08:30 AM – 09:30 AM \n\n\nThe Digital Butterfly Effect: From the Dry Cleaners to the D.I.B. \nPresenter: Kurtis Minder (GroupSense) \nA poignant and tangible look at why every cyber incident is meaningful. This talk provides a detailed examination of how cyber attacks are carried out and how even seemingly benign incidents can have a negative impact on national security. \n\n \n\n09:30 AM – 10:30 AM \n\n\nPost-Quantum Cryptography: Fuel for Cryptographic Posture Management (Panel Discussion) \nHost: Dorin Munteanu (InfoSec Global); Panelists: Dr. Vladimir Soukharev (InfoSec Global) and Ted Shorter (Keyfactor) \nCryptography is at the heart of digital trust and\, therefore\, at the heart of digital business. Organizations must recognize that cryptography is now critical infrastructure – infrastructure that must be measured and managed by multifaceted physical and virtual teams. Modern organizations need to identify their cryptographic assets and evaluate whether they are cryptographically secure\, compliant\, adhere to best practices\, and are appropriately used. \nJoin us to explore how a cryptographic inventory serves as both an immediate security enhancement and a strategic foundation for quantum-resistant infrastructure. \n\n \n\n10:30 AM – 11:30 AM \n\n\nSecuring Gen AI RAG Data using Azure AI Search \nPresenter: Eric Johnson (Puma Security\, SANS) \nLarge Language Models (LLMs) and Generative AI have inherent limitations\, such as outdated knowledge\, lack of private data access\, and the potential for hallucinations. In this session\, we will introduce a strategy for overcoming these challenges: Retrieval-Augmented Generation (RAG). Attendees will see how a GenAI RAG application can provide access to real-time\, private data stored in an external knowledge base without needing to fine-tune the base LLM model. \nWith an understanding of the GenAI RAG application\, we will explore an example cloud infrastructure hosting the application using Azure AI Search\, Azure Storage\, and Azure Container Apps. The cloud architecture review will uncover new attack vectors and cloud security misconfigurations that can unintentionally leak RAG data to an attacker. Attendees will see how these vulnerabilities can be used to gain unauthorized access to AI data. Then\, we will look at the cloud security controls needed to authorize access to the RAG data. Attendees will walk away with an understanding of GenAI RAG applications\, the underlying cloud infrastructure powering these AI systems\, and the security controls needed to protect sensitive RAG data. \nLearning Objectives: \n\nReview GenAI RAG application architecture\nIdentify misconfigurations in GenAI RAG cloud infrastructure\nLearn GenAI RAG cloud security controls\n\nThis webcast supports content and knowledge from SEC510: Cloud Security Engineering and Controls. \n\n \n\n11:30 AM – 12:30 PM \n\n\nYour AI is vulnerable & you don’t even know it – Red Team Testing AI \nPresenter: Tyler Wrightson (Leet Cyber Security) \nHackers aren’t just exploiting code anymore\, they’re weaponizing the very AI systems designed to help your organization. The exploits are beyond easy\, even absurd at times\, and available to even non-technical adversaries. In this eye-opening session\, discover how attackers are exploiting AI chatbots and AI Systems and get a better grasp on what organizations should be doing to secure their systems. \n\n  \n\n\n\n  \nShare this Event \nIf you are interested\, planning to attend\, or attending this event\, please share with your colleagues across your social media networks. \n\n	\n		\n	\n			\n			\n								\n										\n													\n														\n												Share on X\n					\n					\n									\n			\n		\n			\n			\n								\n										\n													\n														\n												Share on Linkedin\n					\n					\n									\n			\n		\n			\n			\n								\n										\n													\n														\n												Share on Facebook\n					\n					\n									\n			\n		\n			\n			\n								\n										\n													\n														\n												Share on Print\n					\n					\n									\n			\n		\n			\n			\n								\n										\n													\n												Share on Email\n					\n					\n									\n			\n		\n		\n\n	\n\n\n  \n  \n\n\n\nPresenters \nAt times presenters for a session may change due to schedule conflicts and other unexpected situations. If a previously presenter has been substituted\, the changes will be noted. \n  \n \n\n \n\n\nKurtis Minder\nCEO and Co-Founder @ GroupSense \nKurtis Minder is the CEO and co-founder of GroupSense\, a leading provider of digital risk solutions. He built a robust cyber reconnaissance operation that protects some of the world’s largest enterprises and government organizations. \nKurtis is a recognized expert in ransomware negotiation\, having served as the lead negotiator in some of the largest ransomware\, breach\, and data extortion cases globally. His experiences and insights are captured in his book\, Cyber Recon\, which explores the high-stakes world of cyber threat actor engagement and ransomware response. \nHe holds a FEMA certification in Critical Infrastructure Protection and actively contributes to public good projects. He is a key contributor to RAPIDS\, a regional initiative based in Grand Junction\, Colorado\, focused on measuring and managing the health of the Colorado River through innovative technology and data collaboration. Kurtis’ book “Cyber Recon: My Live in Cyber Espionage and Ransomware Negotiation” (Wiley 2025) is an expose’ on the private cyber espionage industry and the economic impact of cyber attacks to the US economy. \nKurtis’s work has been featured in major media outlets including The New Yorker\, Fortune\, VICE\, WIRED\, CNN\, Good Morning America\, and many others. \n \n\n \n\n \n\n\nDorin Munteanu\nStrategic Advisor @ InfoSec Global (a Keyfactor Company) \nDorin Munteanu serves as Strategic Advisor to InfoSec Global\, a Keyfactor company and Fellow at the Future Government Institute. \nHe is co-founder of the Robotic Process Automation (RPA) Initiative\, Community Director of the Virginia Academic RPA Community of Practice and senior advisor at the Center for Business Civic Engagement at the George Mason University\, in Arlington\, VA. \nDorin also serves as the President of the Romanian-American Chamber of Commerce\, in Washington\, D.C.\, where he founded and is co-chairing the DC Cyber Task Force between the U.S. and Romania. \nDorin is an Advisory Council member at the Krach Institute for Tech Diplomacy at Purdue University. He is an Advisory Board Member to the US-Bulgarian Chamber in America and to the AlphaTech Group\, an initiative designed to engage with promising CEOs of emerging growth companies within the cybersecurity\, big data and analytics industries. Additionally\, Dorin is a member of the Black Sea Working Group (BSWG) at the Center for European Policy Analysis (CEPA). \nHe previously served as a Managing Partner at uRADMonitor network\, an automated Internet of Things (IoT) and Big Data solution. \nBefore\, Dorin has been a Research Associate and Assistant Program Coordinator of the U.S.-Romania Initiative at The Center for European Policy Analysis (CEPA) and Researcher at TD International\, both organizations based in Washington\, D.C.. Dorin holds degrees from Babeș-Bolyai University of Cluj-Napoca\, Romania\, and the School of International Service at American University. He is fluent in Romanian\, Spanish\, Italian\, and Hungarian\, and proficient in French. \n \n\n \n\n \n\n\nDr. Vladimir Soukharev\nVP of Cryptographic R&D @ InfoSec Global (a Keyfactor Company) \nDr. Vladimir Soukharev is VP of Cryptographic R&D at InfoSec Global. He is focused on cryptographic research and development and is inspired by continuous innovation. Vladimir obtained his Ph.D. from the University of Waterloo’s David R. Cheriton School of Computer Science\, specializing in cryptography\, security and privacy under the supervision of David Jao. He was part of the Centre for Applied Cryptographic Research\, CryptoWorks21 and has contributed and published works at world-renowned conferences and in journals\, such as PQCrypto\, Financial Cryptography and the Journal of Mathematical Cryptology. Since completing his formal studies in 2016\, he has dedicated his work life to advancing the knowledge and application of cutting-edge cryptography and cyber security technologies to protect vital information and communications in complex\, highly regulated environments. Vladimir is leading and managing the cryptographic R&D at InfoSec Global\, with main focus on Post-Quantum Cryptography\, Cryptographic Agility\, and Cryptographic Discovery & Analytics. He is also contributing to and is part of government initiatives and standards related to PQC and cryptographic migration\, which include NCCoE\, NIST\, and Quantum-Safe Canada. \n \n\n \n\n \n\n\nTed Shorter\nChief Technology Officer and Co-Founder @ Keyfactor\nCISSP \nTed Shorter is the Chief Technology Officer and co-founder at Keyfactor. Responsible for Keyfactor’s Intellectual Property development efforts\, Ted helps align Keyfactor’s focus with the changing security landscape\, ensuring our clients understand the importance of crypto-agility. \nTed has worked in the security arena for over 30 years\, in the fields of cryptography\, Public Key Infrastructure\, authentication and authorization\, and software vulnerability analysis. His past experience includes 10 years at the National Security Agency\, a master’s degree in computer science from The Johns Hopkins University\, and an active CISSP certification. \n \n\n \n\n \n\n\nEric Johnson\nCo-Founder and Principal Security Engineer @ Puma Security\nFellow @ the SANS Institute \nEric is a Co-Founder and Principal Security Engineer at Puma Security and a fellow at the SANS Institute. His experience includes cloud security assessments\, public cloud architecture\, Kubernetes and cloud native hardening\, cloud infrastructure automation\, static source code analysis\, web and mobile application penetration testing\, secure development lifecycle consulting\, and secure code review assessments. Additionally\, Eric is a member of the IANS Faculty and an AWS Community Builder. Eric is the lead author and an instructor for SEC540: Cloud Native Security and DevSecOps Automation and a co-author and instructor for both SEC549: Cloud Security Architecture\, and SEC510: Cloud Security Engineering and Controls. \n \n\n \n\n \n\n\nTyler Wrightson\nFounder @ Leet Cyber Security \nTyler Wrightson is the author of two books published by McGraw Hill; Advanced Persistent Threat Hacking\, The Art and Science of Hacking Any Organization (2014); Wireless Network Security: A Beginner’s Guide (2012). \nTyler is the founder of Leet Cyber Security\, which exists to fundamentally change the way organizations build their cyber security programs based on three principles: Threat Centric Wisdom\, Pragmatism and The Context of their business. \nLeet focuses on offensive security services such as Penetration Testing and Red Teaming to secure organizations against real world attackers. Tyler has over twenty years of experience in the cybersecurity field across many industries including healthcare and financial services with extensive experience in many areas of technical security including networking\, systems architecture\, offensive security and penetration testing. Tyler holds industry certifications such CISSP\, CCSP\, CCNA\, CCDA\, and MCSE. Tyler has also taught classes for CCNA certification\, hacking and penetration testing\, wireless security\, and network security. Tyler is the founder of ANYCon\, Albany New York’s Annual Hacker conference. He has been a frequent speaker at industry conferences including NY Bankers Association (NYBA)\, NYS CyberSecurity Conference\, Derbycon\, BSides\, Rochester Security Summit\, ISACA\, ISSA\, and others. Follow his security blog at blog.leetsys.com. \n \n\n  \n\n\n\n  \nQuestions about this Event \n\n\nIf you have any registration questions about this event\, please contact us by completing the Registration Contact Form linked below. \nRegistration Questions \n  \n\n\n\n\nIf you have CPE questions after the event has concluded\, please contact us by completing the CPE contact form linked below. \nCPE Questions \n  \n\n\n  \n\n\n\nCPE Information \nEarn up to 4 Continuing Professional Education (CPE) credit in the area of Information Technology. The ISACA® Greater Washington\, D.C. Chapter is registered with the National Association of State Boards of Accountancy (NASBA) as a sponsor of continuing professional education on the National Registry of CPE Sponsors. State boards of accountancy have final authority on the acceptance of individual courses for CPE credit. Complaints regarding registered sponsors may be submitted to the National Registry of CPE Sponsors through its website: www.NASBARegistry.org \n  \n\nPoll Questions \n\n\nParticipants must respond to all the poll questions via the Zoom polling feature or chat log in order to receive NASBA CPE credits. The GWDC will not be responsible for the participant’s inability to respond to the polls. \n  \n\n\nCPE Distribution and Evaluation Survey \n\n\nCPEs will be distributed via e-mail along with the event evaluation survey after the completion of the event. Attendees must be present for the full event to receive full CPE credit. \n  \n\n\nLearning Objective \n\n\nAfter attending this event\, attendees will learn about current and future trends in the cybersecurity space. \n  \n\n\nCPE-Related Details \n\n\n\nPrerequisites: None\nAdvance Preparation: None\nProgram Knowledge Level: Basic\nDelivery Method:  Group Internet Based\nField of Study:  Information Technology – Technical
URL:https://isaca-gwdc.org/event/cybersecurity-conference-2025/
LOCATION:Virtual Event
CATEGORIES:Conferences
ATTACH;FMTTYPE=image/png:https://isaca-gwdc.org/wp-content/uploads/2025/08/cybersecurity_2025.png
ORGANIZER;CN="Avneet Sabharwal":MAILTO:programs@isaca-gwdc.org
END:VEVENT
BEGIN:VEVENT
DTSTART;TZID=America/New_York:20250925T083000
DTEND;TZID=America/New_York:20250925T123000
DTSTAMP:20250925T113911Z
CREATED:20250819T023957Z
LAST-MODIFIED:20250925T113911Z
UID:34219-1758789000-1758803400@isaca-gwdc.org
SUMMARY:Cloud Conference 2025
DESCRIPTION:  \n \n  \nSeptember 25\, 2025\nVirtual Event (Zoom)\nEarn up to 4 CPE\n$10 for GWDC Members\n$30 for Non-Members \n  \n  \n\n\n\nCloud Conference 2025 \nNext-Gen Cloud & Mobile Security: Mastering Compliance\, Addressing Emerging Risks\, API Protection\, and Cloud Trends \nIn a world where over 80% of organizational resources are now hosted in the cloud and more than 90% of internet traffic is API-based\, understanding and mitigating cybersecurity risks has never been more crucial. This virtual conference is tailored for cybersecurity professionals\, auditors\, and IT leaders who need to stay ahead of evolving threats and ensure robust security for their cloud environments. \nJoin us for an enlightening day of expert insights\, practical tips\, and actionable strategies that will empower you to enhance your cloud security posture. Our lineup of distinguished speakers will guide you through the complexities of continuous compliance\, API security\, and the latest cloud security trends. \nRegistration closes on September 24th @ 5PM. \nRegister Today! \n  \n\n\n\n  \nSponsorship Opportunities \nIf you are interested in sponsoring this event\, or sponsoring the chapter as an annual sponsor\, please visit our sponsorship page. \nSponsorship Info \n  \n\n\n\nEvent Details \n\nDate and Time \n\n\nThe conference will be held on September 25\, 2025 from 8:30 am to 12:30 pm. \nAdd this event to your calendar using the Add to Calendar link at the bottom of the page. \n  \n\n\nVirtual Event \n\n\nThe conference will be held using Zoom. \nPrior to the event\, participants must install the Zoom app on their respective devices. Participants using the web-based Zoom or calling via the phone may not be entitled to CPE credits. \n  \n\n\nPricing \n\n\nThe fee for GWDC Members is $10 for the conference.\nThe fee for all other registrants is $30 for the conference. \nTo become a member and take advantage of the member rate for our events\, among other benefits\, join ISACA and select the Greater Washington D.C. Chapter as your local chapter. \n  \n\n\nEvent Policies \n\n\nCancellation and refund for advance registrations is allowed if cancellations are submitted through the registration system by the date registration closes. Refunds vary depending on the date of cancellation and cost of the event. See ISACA GWDC Event Policies for details. \nThe GWDC welcomes your comments\, complaints\, suggestions\, questions\, and other feedback concerning our website information and services. \nAll complaints should be submitted through the Registration Contact Form. \n  \n\n  \n\n\n\n  \nInterested in Speaking at a Chapter Event \nIf you are interested in speaking at an upcoming conference\, please visit the Call for Speakers page and complete the form. \nCall for Speakers \n  \n\n\n\nConference Agenda \nConference agendas may change due to schedule conflicts and other unexpected situations. If a previously published agenda has changed\, the changes will be noted. \n  \n \n\n08:30 AM – 09:30 AM \n\n\nStopping Breaches Before They Start with AI-Powered Cloud Security \nPresenter: Carley Simon (Microsoft) \nThis session will explore how artificial intelligence and automation are transforming cloud security and what that means for cyber and IT auditors. We will dive into real-world breach scenarios\, such as privilege escalation and lateral movement in hybrid cloud environments\, and show how AI can be used to detect misconfigurations\, flag anomalous behavior\, and enforce compliance at scale. Attendees will walk away with a framework for auditing AI-augmented cloud environments\, including key questions to ask\, controls to validate\, and red flags to watch for in environments using tools like Microsoft Defender for Cloud\, Purview\, and Entra Permissions Management. \n\n \n\n09:30 AM – 10:30 AM \n\n\nAI-Powered Enterprise Security Risk Posture Management (ESRPM) in the Cloud: From Compliance to Continuous Digital Trust \nPresenter: Lalit Ahluwalia (DigitalXForce & XForce Galaxy) \nAs cloud adoption accelerates\, enterprises face unprecedented complexity in securing multi-cloud environments while meeting compliance demands. Traditional GRC tools are static and reactive\, leaving organizations vulnerable to evolving threats and regulatory gaps. This session will explore how AI-powered Enterprise Security Risk Posture Management (ESRPM) transforms cloud security and compliance into a real-time\, automated\, and outcome-driven discipline. \nAttendees will learn how to: \n\nContinuously map cloud assets to risks and controls\nAutomate compliance testing and evidence collection\nQuantify security posture in business terms\nEstablish digital trust through AI-driven risk intelligence/li>\n\nThis session is ideal for CISOs\, cloud security leaders\, and risk executives seeking to shift from compliance checklists to measurable cyber resilience. \n\n \n\n10:30 AM – 11:30 AM \n\n\nThe Cloud Changes Everything: Why Your Compliance Strategy Doesn’t \nPresenters: Terrence Williams (SANS) \nStop fighting the cloud with on-premises thinking. While your organization burns budget on third party tools and platforms designed for data centers\, AWS\, Azure\, and Google Cloud offer services that can be strategically automated for continuous compliance that costs fractions of traditional tools—yet most enterprises don’t know these capabilities exist. \nThis session explores the compliance revolution happening in plain sight: native cloud services that automatically enforce NIST controls\, AI that predicts violations before they occur\, and abstraction layers that eliminate vendor lock-in across multi-cloud environments. We’ll talk about whether continuous compliance automation can replace periodic audits and examine what happens when you treat compliance as code instead of paperwork. \nThe cloud isn’t just different infrastructure—it’s a fundamentally different approach to security and governance. While third-party vendors exploit knowledge gaps with expensive “cloud-washing” of legacy tools\, cloud providers deliver genuine innovation through services you’re already paying for. Join us as we explore what’s possible when you leverage the cloud’s native intelligence instead of fighting against it. \n\n \n\n11:30 AM – 12:30 PM \n\n\nAbove the Clouds: Navigating Audit & Compliance in Cloud Services \nPresenter: John Heath (KPMG) \nThe presentation will cover basics of cloud computing types\, service delivery models\, and how an auditor’s consideration of logical access controls\, program change management controls\, and other controls may be influenced by an entity’s use of a cloud service provider to host its systems. \n\n  \n\n\n\n  \nShare this Event \nIf you are interested\, planning to attend\, or attending this event\, please share with your colleagues across your social media networks. \n\n	\n		\n	\n			\n			\n								\n										\n													\n														\n												Share on X\n					\n					\n									\n			\n		\n			\n			\n								\n										\n													\n														\n												Share on Linkedin\n					\n					\n									\n			\n		\n			\n			\n								\n										\n													\n														\n												Share on Facebook\n					\n					\n									\n			\n		\n			\n			\n								\n										\n													\n														\n												Share on Print\n					\n					\n									\n			\n		\n			\n			\n								\n										\n													\n												Share on Email\n					\n					\n									\n			\n		\n		\n\n	\n\n\n  \n  \n\n\n\nPresenters \nAt times presenters for a session may change due to schedule conflicts and other unexpected situations. If a previously presenter has been substituted\, the changes will be noted. \n  \n \n\n \n\n\nCarley Simon\nSenior Data Security Solutions Engineer & Microsoft Federal \nCarley Salmon is a Senior Data Security Solutions Engineer at Microsoft Federal\, where she empowers Department of Defense customers to meet stringent data security and compliance requirements. With a deep understanding of regulatory frameworks and Microsoft’s security portfolio\, Carley delivers technical demonstrations and strategic guidance that help defense organizations navigate complex cybersecurity landscapes. Her work is grounded in real-world experience\, having served as a Team Chief and founding assessor at the Defense Industrial Base Cybersecurity Assessment Center (DIBCAC)\, where she led assessments aligned to DFARS Clause 252.204-7012 and NIST SP 800-171. \nAn Army veteran and former Blackhawk helicopter pilot\, Carley brings a unique dual perspective as both a warfighter and technologist. Her leadership in the USANG and her hands-on experience in cybersecurity assessments inform her mission-driven approach to securing sensitive information. Carley’s passion for data protection and her commitment to national defense make her a compelling voice in the federal cybersecurity community. \n  \n\n \n\n \n\n\nLalit Ahluwalia\nCEO & Founder DigitalXForce & XForce Galaxy \nLalit Ahluwalia is an award-winning cybersecurity executive\, and entrepreneur with over two decades of experience driving global security\, risk management\, and digital trust transformation. He is the CEO & Founder of “DigitalXForce” and “XForce Galaxy”\, his dream ventures committed to redefine the future of cybersecurity. \nLalit is an industry thought leader\, keynote speaker\, and pioneer in AI-powered Enterprise Security Risk Posture Management (ESRPM) and automated GRC solutions. He has led the North America Security practice for Accenture\, Global Cybersecurity practice at Wipro\, and diverse portfolio of security initiatives for Deloitte and PwC. \nLalit has been recognized at North Texas Top 500 Business Leaders by DCEO and awarded the 40 Under 40 by Business Journals and CIO-CTO – Excellence in Cyber Security award by Dallas Magazine for his contributions in the Cyber Security field. \n \n\n \n\n \n\n\nTerrence Williams\nCertified Instructor @ SANS \nWith a trident of expertise in Digital Forensics and Incident Response (DFIR)\, Computer Science\, and Cloud Environments\, Terrence approaches each class with the resounding belief that if individuals are not making those around them better\, then what are they doing? As an instructor\, Terrence’s commitment is to ensure that every encounter leaves individuals better equipped and empowered than before. This philosophy underscores his teaching approach\, emphasizing the transformative power of cybersecurity and the boundless possibilities that emerge with the right mindset. \nTerrence’s journey into cybersecurity wasn’t a deliberate choice; instead\, it was a path he navigated as a Marine. He found his roots and thrived in the ever-evolving game of chess that is cybersecurity. The constant challenge to stay ahead\, the perpetual growth\, and the desire to continuously learn are the driving forces behind Terrence’s commitment to this career. \nBeyond the technical realm\, Terrence’s interests and hobbies are as diverse as the winds that blow. Engaging in community efforts\, whether through international travel\, exploring new restaurants\, or discovering that hidden bourbon bar\, he finds joy in connecting with people from all walks of life. Coming from a background that limited his exposure to the world\, Terrence now embraces every opportunity to learn about it. \n \n\n \n\n \n\n\nJohn Heath\nDirector\, Audit\, Technology Assurance @ KPMG LLP \nJohn Heath is a Technology Assurance – Audit Director in KPMG’s Federal practice\, bringing over 20 years of expertise in audit and advisory services to the Federal Government\, commercial organizations\, and not-for-profit entities. His career has been predominantly centered on IT support for financial statement audits and System and Organization Control (SOC) examinations. From 2009 to 2011\, John expanded his global experience by delivering audit services for KPMG’s Swiss member firm in Geneva\, Switzerland. \nBeyond his client-facing responsibilities\, John supports various firm initiatives: \n\nNational Training Facilitator: Leading training initiatives to enhance team capabilities.\nRecruitment Support: Actively involved in recruiting top talent.\nTechnology Implementation Leader: Spearheading the rollout of Alteryx Designer for the Federal Technology Assurance – Audit practice.\nQuality Reviewer: Serving as a reviewer for the firm’s quality review program.\nCareer Advisory Leader: Previously Chaired the Career Advisory Board\, and recently joined the Executive Advisory Council for his alma mater’s business school.\n\nJohn holds a Bachelor of Science in Information Systems Management and International Business\, and a Bachelor of Arts in French from Salisbury University\, class of 2005. \n \n\n  \n\n\n\n  \nQuestions about this Event \n\n\nIf you have any registration questions about this event\, please contact us by completing the Registration Contact Form linked below. \nRegistration Questions \n  \n\n\n\n\nIf you have CPE questions after the event has concluded\, please contact us by completing the CPE contact form linked below. \nCPE Questions \n  \n\n\n  \n\n\n\nCPE Information \nEarn up to 4 Continuing Professional Education (CPE) credit in the area of Information Technology. The ISACA® Greater Washington\, D.C. Chapter is registered with the National Association of State Boards of Accountancy (NASBA) as a sponsor of continuing professional education on the National Registry of CPE Sponsors. State boards of accountancy have final authority on the acceptance of individual courses for CPE credit. Complaints regarding registered sponsors may be submitted to the National Registry of CPE Sponsors through its website: www.NASBARegistry.org \n  \n\nPoll Questions \n\n\nParticipants must respond to all the poll questions via the Zoom polling feature or chat log in order to receive NASBA CPE credits. The GWDC will not be responsible for the participant’s inability to respond to the polls. \n  \n\n\nCPE Distribution and Evaluation Survey \n\n\nCPEs will be distributed via e-mail along with the event evaluation survey after the completion of the event. Attendees must be present for the full event to receive full CPE credit. \n  \n\n\nLearning Objective \n\n\nAfter attending this event\, attendees will learn about current and future trends in the cloud security space. \n  \n\n\nCPE-Related Details \n\n\n\nPrerequisites: None\nAdvance Preparation: None\nProgram Knowledge Level: Basic\nDelivery Method:  Group Internet Based\nField of Study:  Information Technology – Technical
URL:https://isaca-gwdc.org/event/cloud-conference-2025/
LOCATION:Virtual Event
CATEGORIES:Conferences
ATTACH;FMTTYPE=image/png:https://isaca-gwdc.org/wp-content/uploads/2025/08/cloud_2025.png
ORGANIZER;CN="Avneet Sabharwal":MAILTO:programs@isaca-gwdc.org
END:VEVENT
BEGIN:VEVENT
DTSTART;TZID=America/New_York:20250626T083000
DTEND;TZID=America/New_York:20250626T123000
DTSTAMP:20250625T181216Z
CREATED:20241231T184338Z
LAST-MODIFIED:20250625T181216Z
UID:33380-1750926600-1750941000@isaca-gwdc.org
SUMMARY:Risk Management Conference
DESCRIPTION:Risk management is the cornerstone of effective governance and cybersecurity in an era defined by rapid technological innovation. The Risk Management Conference 2025 is designed to equip professionals in IT audit\, cybersecurity\, and governance with the tools and insights necessary to navigate complex risk landscapes. \nThis conference explores cutting-edge approaches to risk management\, with a focus on the NIST Risk Management Framework (RMF) and other industry-leading frameworks that empower organizations to identify\, assess\, and mitigate risks effectively. Attendees will gain actionable knowledge on: \n\nImplementing and tailoring risk management frameworks to align with organizational goals and compliance requirements\nAddressing the unique risks posed by emerging technologies such as artificial intelligence and cloud computing\nStrengthening governance structures to drive accountability and resilience\nPractical case studies showcasing successful risk management strategies in real-world scenarios\n\nWhether you’re focused on AI risks\, securing cloud environments\, or enhancing your organization’s governance practices\, this conference offers the expertise\, practical guidance\, and collaborative opportunities to advance your risk management strategies. Join us to gain the insights and frameworks you need to navigate today’s risks and prepare for tomorrow’s challenges. \nRegistration closes on June 25th @ 3pm. \nRegister Today! \n  \nConference Overview \n\nJune 26 \nThe conference will be held on June 26\, 2025 from \n8:30 am to 12:30 pm. \nAdd this event to your calendar using the Add to Calendar link at the bottom of the page. \n  \nVirtual Event \nThe workshop will be held using Zoom. \nPrior to the event\, participants must install the Zoom app on their respective devices. Participants using the web-based Zoom or calling via the phone may not be entitled to CPE credits. \n\n\nGWDC Member Fee – $10 \nThe fee for GWDC Members is $10 for the conference.\nThe fee for all other registrants is $30 for the conference. \nTo become a member and take advantage of the member rate for our events\, among other benefits\, join ISACA and select the Greater Washington D.C. Chapter as your local chapter. \n  \nEarn up to 4 CPEs \nAttendees can earn up to 4 CPEs for this event. \nParticipants must respond to all the poll questions via the Zoom polling feature or chat log in order to receive NASBA CPE credits. The GWDC will not be responsible for the participant’s inability to respond to the polls. \n\nShare this Event in Your Network \n\n	\n		\n	\n			\n			\n								\n										\n													\n														\n												Share on X\n					\n					\n									\n			\n		\n			\n			\n								\n										\n													\n														\n												Share on Linkedin\n					\n					\n									\n			\n		\n			\n			\n								\n										\n													\n														\n												Share on Facebook\n					\n					\n									\n			\n		\n			\n			\n								\n										\n													\n														\n												Share on Print\n					\n					\n									\n			\n		\n			\n			\n								\n										\n													\n												Share on Email\n					\n					\n									\n			\n		\n		\n\n	\n\n\n  \nAgenda \n \n\n08:30 AM – 09:30 AM \n\n\nCyber Risk Management in Practice: A Strategic Playbook for CISOs \nPresenter: Russell Eubanks (Cyverity\, SANS Institute) \nBalancing risk reduction with business enablement isn’t just a theory—it’s a challenge cybersecurity leaders face daily. Cyber Risk Management in Practice: A Strategic Playbook for CISOs is a presentation designed for CISOs\, cybersecurity executives\, and program managers who need more than frameworks—they need guidance they can act on. \nIn this session\, Russell Eubanks\, Principal Instructor at the SANS Institute and Managing Partner at Cyverity\, will discuss the practical elements of an effective cybersecurity risk management program. He’ll explain how to evaluate your current cybersecurity posture\, prioritize safeguard investments using a “good\, better\, best” model\, and close the gap between today’s risk realities and tomorrow’s security goals. \nAttendees will be introduced to a structured approach from the Cybersecurity Risk Foundation’s Governance and Risk Model (CRF-GRM)\, a proven methodology for turning cybersecurity strategy into repeatable action. You’ll leave with concrete steps to build a risk-informed roadmap\, embed cybersecurity into business decision-making\, and create a continuous improvement cycle. \nWhether strengthening your existing risk management program or building one from the ground up\, this webcast offers real-world techniques and strategic insight to help you make smarter\, more defensible decisions. \n\n \n\n09:30 AM – 10:30 AM \n\n\nBuilding Strong Governance for Accountability and Resilience \nPresenter: Elizabeth Dunsmoor (Shared Assessments) \nLearn how to strengthen governance structures to drive accountability and organizational resilience. The session will cover: \n\nGovernance Models – Overview of effective governance models and their key components\nAccountability Mechanisms – Strategies for establishing clear accountability and oversight\nResilience Building – Enhancing organizational resilience through robust governance practices\n\n\n \n\n10:30 AM – 11:30 AM \n\n\nA Fireside chat on “AI in the Crosshairs: Legal\, Risk and Cybersecurity Challenges in the Age of Generative AI” \nPresenters: Nick Lockett (ADL Solicitors) and Sushila Nair (Cybernetic LLC) \nArtificial Intelligence\, particularly Generative AI (GenAI)\, is reshaping industries with its innovative capabilities\, from content creation to complex decision-making. However\, with these advancements come significant cybersecurity and legal challenges. In this one-hour fireside chat\, a cybersecurity expert and a legal professional will dive into the complex interplay between AI technology and its risks. \nThe discussion will explore how GenAI is both a tool and a target in cybersecurity\, examining its role in threat detection as well as its misuse for creating deep fakes and automating cyberattacks. From a legal standpoint\, the conversation will delve into data privacy concerns\, intellectual property issues\, regulatory implications\, and ethical considerations surrounding AI use and development\, considering EU\,UK and US AI laws and Codes of Practice and how this impacts on competition in the AI field. Together\, the speakers will offer practical insights into securing AI-driven systems and ensuring compliance with emerging legal frameworks. \nThis engaging dialogue aims to provide actionable strategies for managing AI’s risks while embracing its potential\, catering to professionals navigating this transformative. \n\n \n\n11:30 AM – 12:30 AM \n\n\nRisk and Compliance: A Digital Transformation Journey – Day 0 to Day 5 \nPresenter: Bhargav Trivedi (Capital One) \nThis five-day journey guides organizations through a focused digital transformation of the risk and compliance functions. Starting with Day 0 alignment on vision and priorities\, the process quickly progresses to designing future-state models\, identifying digital enablers\, and integrating data-driven strategies. By Day 5\, organizations emerge with a clear roadmap and executive buy-in to implement agile\, tech-enabled risk and compliance capabilities. \n\n  \nPresenters \n\n \n\n\nRussell Eubanks\nManaging Partner @ Cyverity\nPrincipal Instructor at the SANS Institute \nRussell is a Principal Instructor at the SANS Institute and Managing Partner at Cyverity\, an information security consulting firm specializing in governance and fractional CISO. He is the former CIO and CISO of the Federal Reserve Bank of Atlanta. Russell has developed cybersecurity programs from the ground up and also led extensive cybersecurity teams. Russell actively seeks opportunities to add value to organizations and measurably increase their overall security posture. \n \n\n  \n \n\n \n\n\nElizabeth Dunsmoor\nThird-Party Risk Management (TPRM) Principal @ Shared Assessments \nElizabeth Dunsmoor is a Third-Party Risk Management (TPRM) Principal at Shared Assessments. With over 15 years of experience in the TPRM field\, Elizabeth has designed holistic TPRM programs and assessed risks across various sectors\, such as cybersecurity\, financial services\, manufacturing\, and healthcare. Elizabeth excels at transforming risk strategies into actionable frameworks\, partnering with procurement and corporate teams to strengthen risk resilience. She is also committed to developing cross-functional leadership within the risk management space. In her current role\, Elizabeth trains business leaders on third-party risk program requirements\, third-party capabilities\, and performance expectations. \nAbout Shared Assessments: In our global economy where third-party services are essential\, Shared Assessments is at the forefront of providing thought leadership\, standards\, and education to drive third-party risk assurance. \n \n\n \n\n \n\n\nNick Lockett\nFounding partner @ ADL Solicitors (London) \nNick Lockett\, founding partner of ADL Solicitors in London\, is a barrister and solicitor-advocate with over 30 years of experience in IT law\, including leading roles in top law firms\, Sidley & Austin (London) and McDermott Will\, Emery & Stanbrook (Brussels). Currently within Nick’s Advanced Technology practice\, Nick focuses on the legal and ethical implications of AI and founder of the Centre for Assessment of AI Risk & Opportunity (CAAIRO) and has a forthcoming book\, “Techsistential Risk: AI Law and Ethics\,” (due late 2025). Nick’s extensive experience allows him to navigate the complexities of AI governance\, ensuring compliance with evolving legal frameworks\, and addressing ethical considerations in technology deployment. \n \n\n\n \n\n\nSushila Nair\nCEO @ Cybernetic LLC\nCISSP\, GIAC GSTRT\, GSNA GDSA\, CISA\, CISM\, CRISC\, CDPSE\, CCSK\, CCAK \nSushila Nair is the CEO of Cybernetic LLC and former Vice President of Capgemini’s North American Cybersecurity practice\, where she played a crucial role in driving secure digital transformation on a global scale. With over 30 years of experience in computing infrastructure\, business\, and security risk analysis\, Sushila has established herself as a leading authority in the cybersecurity domain. Her career highlights include serving as Vice President responsible for global security offers at NTT DATA Services\, a decade of leading her own IT and cybersecurity company across major UK cities\, and serving as a Chief Information Security Officer (CISO) and trusted advisor to boards\, where she honed her expertise in protecting organizations from evolving digital threats. Recognized through the top cybersecurity leader award by Security Magazine\, Sushila’s influence in the industry is undeniable. \nAn esteemed thought leader\, Sushila has shared her insights on prestigious platforms such as public radio\, RSA Conference and ISACA’s global events. Her active participation in ISACA’s global emerging trends working group and her leadership as President of ISACA’s Greater Washington\, D.C. Chapter underscore her dedication to advancing the field of cybersecurity. In 2024\, her commitment to nurturing the next generation of cybersecurity professionals and promoting diversity in the industry was honored with the prestigious ISACA Technology for Humanity Award and Security Magazine’s Top Cybersecurity leader. \n \n\n \n\n \n\n\nBhargav Trivedi\nSenior Director of Software Engineering @ Capital One \nBhargav leads the Enterprise and Operational Risk Management Technology teams within Risk Tech. Over the past 6 years\, he has played a pivotal role in architecting and delivering technology solutions that support Capital One’s risk identification\, assessment\, control monitoring\, and issue management processes. Prior to this\, he spent 5 years in Commercial Bank Technology\, focusing on resilient\, scalable platforms. Bhargav is passionate about the intersection of risk and technology\, particularly in using AI\, automation\, and data analytics to strengthen risk posture\, enable proactive risk management\, and improve control effectiveness. He is a champion of building secure\, transparent systems that empower first and second-line risk teams to make timely\, risk-informed decisions. Bhargav is based in Richmond\, VA. Before joining Capital One\, he was a software architect at American Express\, supporting critical capabilities in the Business Travel division. His early career included roles at GE Commercial Finance and PNC Bank\, where he gained foundational experience in financial risk\, credit systems\, and data governance frameworks. Outside the office\, Bhargav enjoys playing chess\, spending time with his two young boys\, and keeping up with the latest in tech innovation through podcasts. His mission is not only to build software—but to lead the transformation of risk management through technology. \n \n\n  \nEvent Questions and Policies \n\n\nRegistration Questions \nIf you have any registration questions about this event\, please contact us by completing the Registration Contact Form linked below. \nRegistration Questions \n  \n\n\n\n\nCPE Questions \nIf you have CPE questions after the event has concluded\, please contact us by completing the CPE contact form linked below. \nCPE Questions \n  \n\n\n\n\nCancellation and Refunds \nCancellation and refund for advance registrations is allowed if cancellations are submitted through the registration system by the date registration closes. Refunds vary depending on the date of cancellation and cost of the event. See ISACA GWDC Event Policies for details. \n\n\n\n\nComplaints \nThe GWDC welcomes your comments\, complaints\, suggestions\, questions\, and other feedback concerning our website information and services. \nAll complaints should be submitted through the Registration Contact Form. \n\n\n  \n  \nCPE Information \nEarn up to 4 Continuing Professional Education (CPE) credit in the area of Information Technology. The ISACA® Greater Washington\, D.C. Chapter is registered with the National Association of State Boards of Accountancy (NASBA) as a sponsor of continuing professional education on the National Registry of CPE Sponsors. State boards of accountancy have final authority on the acceptance of individual courses for CPE credit. Complaints regarding registered sponsors may be submitted to the National Registry of CPE Sponsors through its website: www.NASBARegistry.org \n  \nCPE Distribution and Evaluation Survey \nCPEs will be distributed via e-mail along with the event evaluation survey after the completion of the event. Attendees must be present for the full event to receive full CPE credit. \n  \nLearning Objective \nAfter attending this event\, attendees will learn about current and future trends in the IT Audit space. \n  \nCPE-Related Details \n\nPrerequisites: None\nAdvance Preparation: None\nProgram Knowledge Level: Basic\nDelivery Method:  Group Internet Based\nField of Study:  Information Technology – Technical
URL:https://isaca-gwdc.org/event/risk-management-conference-2025/
LOCATION:Virtual Event
CATEGORIES:Conferences
ATTACH;FMTTYPE=image/png:https://isaca-gwdc.org/wp-content/uploads/2024/12/conference-risk-management.png
ORGANIZER;CN="Avneet Sabharwal":MAILTO:programs@isaca-gwdc.org
END:VEVENT
BEGIN:VEVENT
DTSTART;TZID=America/New_York:20250519T084500
DTEND;TZID=America/New_York:20250519T170000
DTSTAMP:20250517T013723Z
CREATED:20250106T021103Z
LAST-MODIFIED:20250517T013723Z
UID:33542-1747644300-1747674000@isaca-gwdc.org
SUMMARY:Future Tech DC
DESCRIPTION:<< Return to GWDC Events \n  \n \nFuture Tech DC\nMay 19\, 2025 from 8:45 AM to 5:00 PM\nGeorge Mason University\, Arlington VA Campus\n8 CPE\n$175 for Members of Partner Organizations\n$250 for All Other Registrants \n  \n  \n\n\n\nWelcome to Future Tech DC: AI\, Cybersecurity\, and Trust\nThe premier conference that explores the intersection of artificial intelligence\, cybersecurity\, and IT audit. \nJoin us in the heart of Washington\, D.C.\, where innovators\, industry leaders\, and technology enthusiasts converge to shape the future of the digital landscape. This event offers: \n\nInsightful Sessions: Prepare for the challenges of tomorrow\, by delving into the evolving cybersecurity threat landscape\, gaining insights into emerging technologies such as AI\, and discovering strategies for IT audit and cybersecurity professionals to build trust in a digital world.\nTailored Tracks: Choose from General\, Government\, and Workshop sessions\, including hands-on SANS demonstrations.\nNetworking & Professional Growth: Connect with peers\, earn 8 CPE credits\, and gain practical tools to secure your organization.\n\nWhat’s included with the registration fee in addition to conference attendance: Breakfast\, lunch\, parking at GMU Arlington campus \nWho Should Attend this Event?  IT / Cybersecurity professional\, cybersecurity student\, auditor\, CISO\, or business or government leader \nRegistration closed on May 16 @ 6pm.  There is no walk-up registration for this event. \nRegister Today! \n  \n\n\n\n  \nRegistration Bundles Available \n\nProfessional Bundles are available for businesses and organizations to purchase bundles of 10 registrations at the member rate. After purchase\, a discount code will be emailed. \nPurchase Professional Bundle \n\n\nStudent Bundles are available for colleges and universities to purchase bundles of 10 registrations for students at discounted student pricing. After purchase\, a discount code will be emailed. \nPurchase Student Bundle \n\n  \n\n\n\nPartner Organizations \nThis event wouldn’t be possible with the time and dedication of the following partner organizations present this event. These organizations are presented below in no order of significance: \n\n\n\n\n\n\n\n\n\n\n\n\n\nWorkshops Powered By: \n \n\n\nHosted By: \n \n\n  \nAgenda \nTailor your conference experience by choosing sessions in one of the three tracks.  Please note\, no advance selection is required for the General and Government Tracks. Registrants can attend the General and Government sessions on a first come basis on the day of the conference.  SANS Workshops will be selected during registration \nGovernment Track – Government Focus: Federal\, State\, and Local Perspectives\nDive into sessions tailored to the unique challenges and opportunities faced by government entities. Explore innovative strategies for securing critical infrastructure\, enhancing digital services\, and navigating regulatory landscapes at every level of government. \nGeneral Track – Visionary Leaders in AI\, Emerging Tech\, and Cybersecurity\nHear from globally recognized thought leaders who are driving change in artificial intelligence\, emerging technologies\, and cybersecurity. These inspirational talks will provide insights into the future of tech and its role in building a safer\, more innovative world. \nSANS Workshop Track – Practical Skills and Cutting-Edge Tools\nParticipate in interactive workshops and labs that bring theory to life. From building a machine learning network to detect anomalies\, to reverse engineering malware\, and identifying cloud misconfigurations\, these sessions offer practical\, real-world applications for staying ahead in an ever-evolving digital landscape.  Please note\, SANS workshops have a limited capacity. Sign up early to secure your spot before sessions reach capacity.  There is a limit of one SANS workshop per registrant. \n  \n\n\n\n Time\nGeneral Track\nGovernment Track\nSANS Workshop Track\nSpecial Activities\n\n\n08:00 AM – 08:45 AM\nBreakfast and Networking\n\n\n08:45 AM – 09:00 AM\nConference Introduction\n\n\n09:00 AM – 10:00 AM\nKeynote Speaker: Dave Hoelzer\, SANS Fellow\nReal World Hype-Free AI in the Cybersecurity Enterprise\n\n\n10:00 AM – 11:00 AM\nAsk Questions\nTerry Grafenstine (IIA and PenFed)\nCybersecurity for Artificial Intelligence\nJeffrey Eyink (DoD)\nPresented by SANS – Avoiding Data Disasters: Techniques to Identify and Address Cloud Storage Misconfigurations\nShaun McCullough (SANS and GitHub)\n\nCapture the Flag \nCheck-in \n10:00-10:30 \nAM  \nCompetition \n10:30 AM – \n2:30 PM  \nWinners \nAnnounced \n2:30 – 3:00 PM \n\n\n\n11:00 AM – 12:00 PM\nAdapt or Be Breached: Why Outdated Third-Party Risk Models are Failing SaaS\nVishal Chawla (BluOcean Cyber)\nThe NIST Risk Management Framework: More Than Just Compliance and an ATO\nVictoria Yan Pillitteri (NIST)\n\n\n12:00 PM – 01:00 PM\nLunch Keynote Speaker:  Sounil Yu (Knostic)\nWhat to Expect When You’re Expecting Your GenAI Baby\n\n\n01:00 PM – 02:00 PM\nExploring the Intersection of Cybersecurity and Artificial Intelligence\nDr. Kellep Charles (Capitol Technology University)\nEmerging Threats in Space\nFireside Chat with Renee Wynn (Former NASA CIO\, Axonius) and Dr. Diane Janosek (Janos LLC)\nPresented by SANS – Reverse Engineering Malware: A Hands-On Introduction\nAnuj Soni (Johns Hopkins University APL and SANS)\n\n\n02:00 PM – 03:00 PM\nMITRE ATLAS: Community Driven Tools for AI Security & Assurance\nDr. Christina Liaghati (MITRE)\nSecuring the Machine Mind: AI Risk Management in the Federal Enterprise\nDavid Branscome (Microsoft)\n\n\n03:00 PM – 04:00 PM\nIn the age of AI\, getting to the “who” is your biggest threat advantage\nRyan LaSalle (Nisos®)\nShifting Left Security Automation with Open Security Controls Assessment Language (OSCAL)\nDr. Michaela Iorga (NIST/ITL)\nPresented by SANS – Build a Machine Learning Neural Network for Anomaly Detection on Logs\nChristopher Crowley (SANS)\nIndustry Exchange\n\n\n04:00 PM – 05:00 PM\nAccelerating Innovation with AI Security & Responsibility\nAlexis Appollonia Robinson (Amazon)\nFireside Chat – Securing the Future: NIST NCCoE\, AI\, and Emerging Tech\nModerator: Jim Wiggins (Securible and FITSI)\nPanelists: Cherilyn Pascoe (NIST)\n\n\n05:00 PM – 06:00 PM\nConference Wrap-Up\n\n\n\n  \nClick the link below to view the agenda in a PDF along with the room numbers and floor Maps of GMU’s Van Metre Hall in the Mason Square Building. \nView Agenda PDF \n  \nKeynote Address \n\n09:00 AM – 10:00 AM \n\n\nReal World Hype-Free AI in the Cybersecurity Enterprise \nPresenter: Dave Hoelzer (SANS) \nEnterprises today are fixated on adopting AI solutions\, yet few have clearly defined the business problems they hope that AI will solve. What’s the reality of the applicability of AI to cybersecurity? What knowledge should someone with a GRC focus have to understand what vendors are selling and how this aligns with an enterprise’s controls? How can AI be leveraged to enhance a SOC or expand the threat-hunting capabilities of a security organization? David Hoelzer\, COO of a managed security provider and SANS fellow will answer these questions\, in addition to showing how his enterprise and his customers are leveraging machine learning and AI to identify previously unknown zero-day malware\, find compromised hosts at scale\, identify anomalous log entries without writing rules\, and more. These demonstrations will include clear explanations of how these solutions work that anyone with Python and TensorFlow or PyTorch knowledge can implement! \nView Dave’s Speaker Showcase video for this session \nLearning Objectives: \n\nHow AI and ML can be defined in a way that benefits the vendor\, not the enterprise\, and how to know what they’re saying.\nUnderstand how to articulate the role of AI/ML in a security operation/threat hunting operation in a way that is aligned with objectives.\nHave a better understanding of precisely what types of problems in security benefit from the application of AI/ML techniques.\n\n\n  \nKeynote Presenter \n\n \n\n\nDave Hoelzer\nSANS Fellow \nDavid Hoelzer\, a SANS Fellow and author of more than twenty days of SANS courseware\, is an expert in a variety of information security fields\, having served in most major roles in the IT and security industries over the past twenty-five years. Currently\, David serves as the principal examiner and director of research for Enclave Forensics\, a New York/Las Vegas based incident response and forensics company. He also serves as the chief information security officer for Cyber-Defense\, an open-source security software solution provider. David is the author of SANS SEC495: Leveraging LLMs: Building & Securing RAG\, Contextual RAG\, and Agentic RAG\, SANS SEC595: Applied Data Science and AI/Machine Learning for Cybersecurity Professionals\, and a seasoned instructor and author for myriad other SANS courses. \n \n\n  \nLunch Keynote Address \n\n12:00 PM – 01:00 PM \n\n\nWhat to Expect When You’re Expecting Your GenAI Baby \nPresenter: Sounil Yu (Knostic) \nMany of us are scrambling to leverage GenAI\, but it’s hard to anticipate the risks\, challenges\, and controls. Using various mental models\, we can get a clearer understanding of what to expect in the next stages of the AI revolution and start building governance processes and security capabilities to get ahead of potential challenges. \nLearning Objectives: \n\nLearn about tools for thinking about AI-related problems\nApply these tools towards specific AI-related problems\nAnticipate future needs using these thinking tools\n\n\n  \nLunch Keynote Presenter \n\n \n\n\nSounil Yu\nCo-Founder and Chief AI Security Officer @ Knostic \nSounil Yu is the author and creator of the Cyber Defense Matrix and the DIE Triad\, which are reshaping approaches to cybersecurity. He’s a Board Member of the FAIR Institute; fellow at GMU Scalia Law School’s National Security Institute; guest lecturer at Carnegie Mellon; and advisor to many startups. Sounil is the co-founder and Chief AI Safety Officer at Knostic and previously served as the CISO at JupiterOne\, CISO-in-Residence at YL Ventures\, and Chief Security Scientist at Bank of America. Before BofA\, he helped improve information security at several Fortune 100 companies and Federal Government agencies. Sounil has over 20 granted patents and was recognized as one of the most influential people in security by Security Magazine\, Influencer of the Year by SC Awards\, and a Top 10 CISO by Black Unicorn Awards. He is a recipient of the SANS Lifetime Achievement Award and was inducted into the Cybersecurity Hall of Fame. He has an MS in Electrical Engineering from Virginia Tech and a BS in Electrical Engineering and a BA in Economics from Duke University. \n \n\n  \nGeneral Track Sessions \n\n10:00 AM – 11:00 AM \n\n\nAsk Questions \nPresenter: Terry Grafenstine (IIA and PenFed) \nJoin Terry Grafenstine\, Chair of the Global Board of Directors\, 2024-2025\, for an inspiring session centered on her IIA Global Board Chair theme: “Ask Questions.” To provide strategic insights\, Internal Audit must help their organizations prepare for disruption. Disruption can be an opportunity\, like Artificial Intelligence\, or a threat\, such as Covid or cyber. While many disruptive technologies and events will push Internal Auditors out of their traditional comfort zones\, to avoid auditing these topics is to miss some of the greatest threat (and opportunities) our organizations face. Instead\, internal auditors should rely on an area where they are experts and ask questions about controls. She will explore how fostering a culture of curiosity can support organizational innovation while also creating a stronger control environment and building enterprise resilience. \nView Terry’s Speaker Showcase video for this session \nLearning Objectives: \n\nExplore how Internal Audit teams can help their organizations prepare for disruptions\, including disruptive technologies.\nUnderstand how relying on your expertise and asking questions can help prepare you for assessing controls in unfamiliar areas.\nLearn how being “curious” is critical for supporting innovation\, resilience\, and strengthening controls.\n\n\n\n11:00 AM – 12:00 PM \n\n\nAdapt or Be Breached: Why Outdated Third-Party Risk Models Are Failing SaaS Security \nPresenter: Vishal Chawla (BluOcean Cyber) \nYour annual third-party risk management (TPRM) checklist is a hacker’s favorite loophole. While you audit once\, attackers exploit SaaS misconfigurations daily. Legacy TPRM frameworks can’t track live configuration drifts\, data sprawl\, data exfiltration\, shadow APIs\, or “Snowflake-style” breaches. We’ll dissect how TPRM models fail—and equip you with continuous monitoring\, zero-trust SaaS governance\, and proactive threat defenses. Evolve or be breached. Your move. \nView Vishal’s Speaker Showcase video for this session \nLearning Objectives: \n\n“97% of Third-Party SaaS Breaches Start Where Vendor Audits End” Why paper-based vendor reviews fail—and how continuous SaaS threat detection closes the gap.\n“Snowflake’s 243-Day Breach Window: Why Compliance ≠ Security” Unpacking the preventable Snowflake breach and how real-time SaaS monitoring slashes detection time by 90%.\n“90 Days to Modern TPRM: From Annual Audits to Always-On SaaS Defense” A proven roadmap to harden critical third-party SaaS apps\, automate controls\, and turn compliance into an advantage.\n\n\n\n01:00 PM – 02:00 PM \n\n\nExploring the Intersection of Cybersecurity and Artificial Intelligence \nPresenter: Dr. Kellep Charles (Capitol Technology University) \nDominated by technological advancements\, Artificial Intelligence (AI) with cybersecurity stands out as a key component for the future of our digital defense. This talk will discuss the impact of AI on cybersecurity\, by examining the challenges\, opportunities\, and the role it plays in safeguarding our digital world. \nThe session will briefly discuss the historical roots of AI\, to its projected surge to $135 billion by 2030. The session will also discuss the relationship between AI and cybersecurity\, first by explaining how AI benefits the defense against cyber threats as well as examine the dark side of this technological alliance in cybersecurity. The presentation concludes by providing practical insights for staying secure in the AI-driven landscape. A call to action is issued to review and update cybersecurity practices\, incorporating best practices in password management\, data privacy\, and personal cybersecurity. In conclusion\, the presentation portrays the intersection of cybersecurity and AI as a dynamic and evolving landscape\, urging cybersecurity leaders to embrace AI’s potential\, understand its risks\, and adapt to ensure a secure and resilient digital world. \nLearning Objectives: \n\nExplore the challenges and opportunities of AI as it relates to safeguarding the digital world.\nUnderstand the impact of AI on cybersecurity including the benefits and the dark side.\nLearn practical insights for cybersecurity in the AI era.\n\n\n\n02:00 PM – 03:00 PM \n\n\nMITRE ATLAS: Community Driven Tools for AI Security & Assurance \nPresenter: Dr. Christina Liaghati (MITRE) \nMITRE ATLAS (atlas.mitre.org) is a public knowledge base of adversary tactics and techniques based on real-world attack observations and realistic demonstrations from artificial intelligence (AI) red teams and security groups. There are a growing number of vulnerabilities in AI-enabled systems as the incorporation of AI increases the attack surfaces of existing systems beyond those of traditional cyberattacks. We developed ATLAS to raise community awareness and readiness for these unique threats\, vulnerabilities\, and risks in the broader AI assurance landscape. \nChristina will speak to the latest MITRE ATLAS community efforts focused on capturing and sharing cross community data on real world AI incidents\, expanding the community’s data on vulnerabilities that can arise when using open-source AI models or data\, especially for vulnerabilities that fall outside of the scope of CVE/CWE\, and developing mitigations to defend against these AI security threats and vulnerabilities. \nView Christina’s Speaker Showcase video for this session \nLearning Objectives: \n\nLearn about the unique threats\, vulnerabilities\, and risks that AI poses.\nHear how the MITRE ATLAS community is engaging to provide real world data on the impact of AI on cybersecurity.\nExplore mitigations to defend against AI security threats and vulnerabilities.\n\n\n\n03:00 PM – 04:00 PM \n\n\nIn the age of AI\, getting to the “who” is your biggest threat advantage \nPresenter: Ryan LaSalle (Nisos®) \nAI is making the landscape less human. Yet people are both a significant enterprise vulnerability\, and the key to protecting your organization. And cyber’s remit is getting larger\, not smaller. As companies take on greater digital risk\, cybersecurity accountability extends to include protecting executives from physical harm\, keeping insider threats out\, and surfacing signs of employment fraud. It’s your job to stay a step ahead by detecting emerging threats online and to action quickly. Beyond the day to day compliance and cyber defense\, security teams need to grow with the business and tackle the emerging challenges to people presented by the innovative attacks powered by AI\, the fomenting discord targeting your people and brand\, and the new vulnerabilities and exploits to hiring and ways of working. Getting to the “who” behind these threats empowers you to take real-world action to move upstream from the techniques employed and address the people at the root of the campaign or attack. \nView Ryan’s Speaker Showcase video for this session \nLearning Objectives: \n\nBetter understand human risk threats and TTPs for executive protection\, employment fraud\, and insider threat.\nDevelop strategies on how getting to the “who” behind human risk threats can drive real-world consequences\, including shutting down the threat.\nLearn about practical ways you and your teams can detect and prevent human risk threats.\n\n\n\n04:00 PM – 05:00 PM \n\n\nAccelerating Innovation with AI Security & Responsibility \nPresenters: Alexis Appollonia Robinson (Amazon) \nFor innovation to thrive\, teams need the freedom to operate quickly. Yet many organizations slow development for governance with restrictive controls. In this session\, learn how to implement 100 controls that empower teams to ship rapidly without compromising reliability\, security\, or compliance. Additionally\, learn from AWS experts as we breakdown AWS’s Responsible AI Strategy and AWS Audit Manager’s generative AI framework. In this session\, explore how to incorporate controls as we build AI with AWS. \nLearning Objectives: \n\nUnderstand how to accelerate innovation by embedding security controls and responsible AI guardrails from day one.\nConsider AWS’s Responsible AI Strategy as a way to build trust while maintaining development velocity.\nImplement AWS Audit Manager’s Generative AI Framework to automate compliance and strengthen governance.\n\n\n  \nGeneral Track Presenters \n\n \n\n\nTerry Grafenstine\n2024–25 Chair of the Global Board of Directors of The Institute of Internal Auditors (IIA) and Chief Audit Executive with Pentagon Federal Credit Union (PenFed)\nCIA\, CPA\, CISSP\, CISA\, CRISC\, CGEIT\, CGAP \nTerry Grafenstine is the 2024–25 Chair of the Global Board of Directors of The Institute of Internal Auditors (IIA) and Chief Audit Executive with Pentagon Federal Credit Union (PenFed). She was recognized by The IIA as one of the “Top Ten Audit Thought Leaders of the Decade” and inducted into The IIA’s Hall of Distinguished Audit Practitioners. She has served on both the IIA’s North American and Global Boards of Directors. \nTerry has over 25 years of experience in the internal auditing and information technology profession. As CAE at PenFed\, Terry is responsible for leading internal audit teams covering all aspects of operations at the second largest federal credit union in the U.S. Prior to joining PenFed in May 2023\, Terry was the global chief auditor for Operations & Technology at Citi where she led audits covering technology\, cyber\, business continuity\, enterprise resilience\, and third party risk management across the 155 countries in which Citi operated. \nBefore joining Citi\, Terry was a Managing Director in Deloitte’s Risk and Financial Advisory practice\, where she provided strategic advisory services to Chief Audit Executives across all commercial industries and IT audit\, risk\, and governance advisory services to first line executives in the defense and national security space. Prior to joining Deloitte\, Terry served for eight years as the bi-partisan appointed Inspector General of the U.S. House of Representatives\, where she designed\, managed\, and delivered audit and investigative services\, including the annual financial statement audit and a comprehensive cyber assurance program. \nTerry has held numerous leadership roles to support the auditing\, accounting\, and information technology profession\, including serving as ISACA’s Global Chair (2017-2018) and a member of the AICPA board of directors (2014 – 2018). Terry speaks globally on a wide range of subjects\, including cyber security\, internal auditing\, accounting standards\, resilience\, leadership\, and risk. \nTerry earned a Bachelor’s degree in Accounting from Saint Joseph’s University. She is a Certified Internal Auditor (CIA)\, Certified Public Accountant (CPA)\, Certified Information Systems Security Professional (CISSP)\, Certified Information Systems Auditor (CISA)\, Certified In Risk and Information Systems Control (CRISC)\, Certified in the Governance of Enterprise IT (CGEIT)\, and Certified Government Auditing Professional (CGAP). \n \n\n\n \n\n\nVishal Chawla\nFounder & CEO BluOcean Cyber \nVishal brings 30 years of cybersecurity expertise\, combining his Big 4 experience as global cybersecurity leader and senior partner serving global fortune 100 clients in the financial services and healthcare industry. \nHe is now the founder and CEO of BluOcean Cyber (located in Northern Virginia)\, where he created RiskGPS\, a Cyber Risk Governance platform that helps companies dominate their competition by redefining cybersecurity as a critical strategic business asset. The groundbreaking approach revolutionizes cybersecurity for mid-sized companies by bridging the gap between technical cybersecurity measures and business mission-based objectives. By connecting specific actions to threats and business processes\, RiskGPS protects\, sustains\, and amplifies critical outcomes with verifiable ROI. Vishal’s work has been published in The Wall Street Journal\, NACD Directors\, RMA\, MIT Review\, and many other publications. \n \n\n\n \n\n\nDr. Kellep Charles\nDepartment Chair of Cybersecurity programs and Professor of Computer Science @ Capitol Technology University \nDr. Kellep Charles serves as Department Chair of Cybersecurity programs and Professor of Computer Science at Capitol Technology University. Dr. Charles’ research areas encompasses Digital Forensics\, Threat Detection\, OSINT\, Machine Learning and Malware Analysis. He completed his Doctorate in Cybersecurity at Capitol Technology University. He also holds a Master of Science in Telecommunication Management from the University of Maryland University College and a Bachelor of Science in Computer Science from North Carolina Agricultural and Technical State University. \nDr. Charles also worked as a government contractor in the Washington\, DC area as an information security analyst for over 25 years in the areas of incident response\, computer forensics\, security assessments\, malware analysis\, and security operations. \n \n\n\n \n\n\nDr. Christina Liaghati\nTrustworthy & Secure AI Department Manager and MITRE ATLAS Lead @ MITRE \nWorking across a collaborative global community of industry\, government\, and academia\, Dr. Liaghati leads MITRE’s Trustworthy & Secure AI Department and MITRE ATLAS\, where she passionately drives research and developments in trustworthy and secure AI for everyone working to leverage AI-enabled systems. Leading her department of 50+ scientist and engineers and serving the community with the not-for-profit\, objective\, MITRE perspective\, she is dedicated to working together to create and openly share actionable tools\, capabilities\, data\, and frameworks for trustworthy and secure AI like ATLAS\, an ATT&CK-style framework of the threats and vulnerabilities of AI-enabled systems. \nAs Dr. Liaghati has worked across the community to improve the common understanding of AI security concerns\, her work quickly started overlapping with broader AI assurance concerns\, which includes AI equitability\, interpretability\, reliability\, robustness\, safety\, and needs for privacy enhancement. As a result of this expansion beyond AI security into more of these elements of trustworthy AI and AI assurance\, her current focus under ATLAS and across the international community is to build a protected mechanism for increased knowledge and incident sharing across government and industry in both AI security and the broader areas of AI assurance. \nDr. Liaghati also chairs the NATO Science and Technology Organization Research Task Group on the AI Assurance and Security\, focused on fostering an enduring collaborative community of NATO organizations and industry partners\, leveraging the Science and Technology Organization to shape future interoperable capability developments in AI security and assurance. \n \n\n\n \n\n\nRyan LaSalle\nChief Executive Officer @ Nisos® \nRyan LaSalle is the Chief Executive Officer of Nisos®\, the Managed Intelligence Company®. For over 25 years\, Ryan has been a trusted advisor to business leaders and their boards within Fortune 500 and National Security organizations. His expertise has helped drive business growth\, secure and protect critical infrastructure\, and allow organizations to overcome unique business and technology challenges. Prior to joining Nisos\, Ryan was a senior executive and serial intrapreneur at Accenture\, leading one of the largest cybersecurity organizations in North America. During his tenure he spearheaded global enterprise through reinvention\, facilitated new revenue sources\, managed acquisitions\, and developed patented solutions spanning cybersecurity\, information management\, and analytics. Ryan has run high-growth cyber services organizations and led over 1\,600 people. He balances business acumen with technical expertise\, enabling Fortune 500 companies to articulate and implement action in the face of disruptive competition\, technologies\, and cyber risk. Ryan holds patents in human resource management\, knowledge discovery\, and establishing trust between entities online. He frequently speaks at international security conferences and has authored numerous articles on cybersecurity. \n \n\n\n \n\n\nAlexis Appollonia Robinson\nPrincipal Program Manager @ Amazon\nCISA\, PMP \nAlexis Appollonia Robinson is a Principal Program Manager for Amazon in the Washington\, DC area. For the past 15 years\, she has served buyers of the cloud\, retail sellers\, policy makers\, compliance organizations\, engineering leaders\, and security teams by developing and implementing security strategies\, collaborating for thought leadership\, solving problems\, building products\, and conducting cybersecurity\, engineering\, and financial assessments. She graduated with double Bachelors of Science degrees in Accounting and Information Systems from the Robert H. Smith School of Business at University of Maryland\, College Park and an Executive Masters of Business Administration (MBA) from the Quantic Program. She has worked at several companies including CGI Federal and Ernst & Young before finding her way to Amazon. She is a Certified Information Systems Auditor (CISA) and a Project Management Professional (PMP). \nAlexis is the former Co-Chair of EY’s Black Professional Network of Greater Washington\, an affinity group that hosts several networking events\, career development workshops\, partner and executive director relationship breakfasts and dinners\, and community service outreach programs within the Washington D.C. metropolitan area for over 150 members in the community. Through this effort\, she served on the Americas BPN Steering Committee as the Northeast Representative and Communications Lead. To continue her diversity initiatives at Amazon\, Alexis is currently on the Inclusiveness\, Diversity & Equity Counsel of AWS Security and involved with IDE Inclusive Recruiting. \nOn her free time\, she is playing video games\, watching “Only Murders in the Building”\, “Real Housewives of “\, “Demon Slayer”\, and “Abbott Elementary”. She lives with her husband and son in Maryland. \n \n\n  \nGovernment Track Sessions \n\n10:00 AM – 11:00 PM \n\n\nCybersecurity for Artificial Intelligence \nPresenter: Jeffrey Eyink (DoD) \nThis session offers attendees key insights into the converging worlds of AI and cybersecurity\, focusing on the unique challenges and opportunities presented by AI within the Department of Defense. The session promises a deep dive into the critical issues facing organizations deploying AI systems. \nAttendees will gain a clear understanding of the specific cybersecurity risks inherent in DoD’s AI systems. The presentation will unpack the complexities of authorizing these systems\, outlining the appropriate assessment approaches and explaining how to communicate these risks and mitigation strategies effectively to authorizing officials. This is crucial for ensuring that AI systems are deployed securely and responsibly. \nBeyond risk assessment\, the presentation will explore the development of tailored cybersecurity guidance for AI. This will address the specific security requirements for both the underlying infrastructure and the AI models themselves\, equipping attendees with the knowledge to navigate the evolving landscape of AI security. The session will also delve into the potential of leveraging AI to enhance cybersecurity practices. This includes exploring how AI can automate anomaly detection\, provide real-time threat intelligence\, and enable adaptive response mechanisms\, ultimately reducing human error and accelerating response times. \nFinally\, the presentation will shed light on the DoD’s ongoing efforts to modernize its assessment and authorization processes for AI systems. This includes collaborative initiatives between the offices of the DoD Chief Information Officer and the Chief Digital and AI Officer\, ensuring a unified and effective approach to AI cybersecurity. Attendees will also learn about planned updates to key DoD guidance\, such as M-24-10\, which addresses governance\, innovation\, and risk management for AI. This provides valuable insight into the future direction of AI cybersecurity within the DoD. In short\, this presentation offers a comprehensive overview of the challenges and opportunities at the intersection of AI and cybersecurity\, providing attendees with actionable insights and a glimpse into the future of secure AI implementation. \nLearning objectives: \n\nGain an understanding of the specific cybersecurity risks inherent in DoD’s AI systems.\nExplore cybersecurity guidance specific to AI and how AI can enhance cybersecurity practices.\nLearn about the DoD’s efforts to modernize its assessment and authorization processes for AI systems.\n\n\n\n11:00 AM – 12:00 PM \n\n\nThe NIST Risk Management Framework: More Than Just Compliance and an ATO \nPresenter: Victoria Yan Pillitteri (NIST) \nDid you know the NIST Risk Management Framework (RMF) goes far beyond meeting compliance requirements and getting an ATO for your system? The NIST RMF provides a repeatable\, flexible and customizable approach to managing risk supported by a portfolio of technical implementation guidance and can be used by any size and type of organization. \nIn this session\, we’ll dispel common misnomers as you learn more about the NIST RMF and its supporting resources\, how it is designed to identify\, understand\, and manage cybersecurity\, privacy and cybersecurity supply chain risks and support organizational resilience\, and the path forward for NIST’s work in risk management. \nView Victoria’s Speaker Showcase video for this session \nLearning objectives: \n\nGain a deeper understanding of the NIST Risk Management Framework (RMF).\nLearn how the NIST RMF can be used by your organization manage risk.\nGain insights into what’s upcoming for risk management from NIST.\n\n\n\n01:00 PM – 02:00 PM \n\n\nEmerging Threats in Space \nPresenters: Fireside Chat with Renee Wynn (Former NASA CIO\, Axonius) and Dr. Diane Janosek (Janos LLC) \nWe rely on space every day! Emerging threats in space pose significant challenges to global security and technological infrastructure. These include the development of anti-satellite weapons (ASATs) that can disable critical satellites used for communication\, navigation\, and defense. Space debris from past missions and collisions increases the risk of damaging active satellites\, creating a cascade of potential disruptions. Additionally\, cyberattacks targeting satellite systems and ground control networks highlight the vulnerability of space-based assets to digital threats. As space becomes increasingly crowded and contested\, international cooperation and policy frameworks will be essential to mitigate risks and ensure the sustainable use of this vital domain. \nView Renee’s Speaker Showcase video for this session \nLearning objectives: \n\nLearn how space impacts your daily life\nLearn about the emerging threats in space and the impact that these risks can have on security and technology infrastructure\nExplore what’s needed to mitigate risk in space\n\n\n\n02:00 PM – 03:00 PM \n\n\nSecuring the Machine Mind: AI Risk Management in the Federal Enterprise \nPresenter: David Branscome (Microsoft) \nAI presents immense opportunity—and unprecedented risk. From data leakage and model drift to adversarial manipulation and opaque decision-making\, federal agencies must rethink how they apply traditional security and compliance principles to intelligent systems. This session delves into the evolving risk landscape of AI through a federal lens\, offering actionable insights into threat modeling\, continuous assurance\, and auditability. Learn how Microsoft is helping agencies implement AI securely by design\, leveraging tools like Azure OpenAI\, Purview\, and Security Copilot within a Zero Trust architecture. \nLearning objectives: \n\nApply a federal lens to the evolving risk landscape of AI.\nLearn actionable insights for threat modeling\, continuous assurance\, and auditability of AI.\nExplore how Microsoft can assist federal agencies with implementing AI securely by design.\n\n\n\n03:00 PM – 04:00 PM \n\n\nShifting Left Security Automation with Open Security Controls Assessment Language (OSCAL) \nPresenter: Dr. Michaela Iorga (NIST/ITL) \nThe exponential increase in the complexity of information systems has been a challenging task to date\, compelling organizations to leverage risk management strategies that are tightly coupled with the dynamic nature of their systems. In an era of multiple competing regulatory frameworks which often trigger conflicting priorities\, opinions\, and claims\, security and privacy practitioners could miss vital actions while performing labor-intensive\, paper-based compliance work. NIST developed Open Security Controls Assessment Language (OSCAL) – a standard of standards that provides a normalized expression of security requirements across standards\, and a machine-readable representation of security information from controls to system implementation and security assessment. This bridges the gap between antiquated approaches to IT compliance and innovative technology solutions. Imagine a future where security documentation builds itself\, and security management tools from different vendors integrate seamlessly. Security practitioners will spend less time on security documentation\, assessments\, and adjudication\, yet the results of those activities will be more accurate and more easily monitored. OSCAL enables this and more. \nLearning objectives: \n\nUnderstand the driving factors behind the creation of OSCAL\, a machine-readable representation of security control implementations and assessment.\nLearn how OSCAL can be used to modernize the approach to compliance to reduce manual processes and increase accuracy of compliance results.\nExplore how OSCAL can enable reciprocity among frameworks.\n\n\n\n04:00 PM – 05:00 PM \n\n\nFireside Chat – Securing the Future: NIST NCCoE\, AI\, and Emerging Tech \nModerator: Jim Wiggins (Securible and FITSI)\nPanelists: Cherilyn Pascoe (NIST) \nThe NIST National Cybersecurity Center of Excellence (NCCoE) is a collaborative hub where industry\, government\, and academic experts work together to tackle the nation’s most urgent cybersecurity issues of today and tomorrow. In this keynote\, NIST NCCoE Director Cherilyn Pascoe will delve into the center’s collaborative strategies and initiatives to solve security and privacy challenges associated with emerging technologies such as AI\, post-quantum cryptography\, and more. Join us for this engaging presentation to learn how organizations can leverage NIST guidance to effectively mitigate and manage risk\, discover future project considerations\, and explore areas for collaboration. \nLearning objectives: \n\nLearn how the NIST National Cybersecurity Center of Excellence (NCCoE) is developing collaborative strategies to solve the most pressing security and privacy challenges.\nExplore how organizations can leverage NIST guidance to mitigate and manage risk.\nDiscover NIST NCCoE focus areas going forward and potential collaboration opportunities.\n\n\n  \nGovernment Track Presenters \n\n \n\n\nJeffrey Eyink\nChief\, Cybersecurity Implementation Division Department of Defense Chief Information Officer\nPMP\, CISM \nJeffrey Eyink is a seasoned cybersecurity professional with extensive expertise in managing and implementing risk management framework\, cybersecurity policies\, and secure cloud adoption strategies within the Department of Defense (DoD). As the Chief of the Cybersecurity Implementation Division under the DoD Chief Information Officer\, he plays a pivotal role in safeguarding national security through robust cybersecurity measures. \nIn his current position\, Mr. Eyink chairs the Risk Management Framework Technical Advisory Group (RMF TAG)\, offering strategic guidance on risk management policies and framework. He serves as a Subject Matter Expert for the Authorizing Official Council\, Defense Security/Cybersecurity Authorization Working Group\, and the Information Security Risk Management Committee\, contributing critical insights into authorization processes\, security controls\, and risk assessments. Additionally\, as a technical representative for DoD to the Joint Authorization Board of FedRAMP\, he evaluates the security postures of cloud service providers\, enabling secure cloud adoption across the DoD. \nPrior to his current role\, Mr. Eyink served in several high-profile positions\, including Chief of Cybersecurity at the Program Executive Office\, Defense Healthcare Management Systems\, and Chief of the Assessment and Authorization Branch at the Defense Health Agency. In these roles\, he developed innovative strategies to streamline authorization processes\, implemented automation to enhance efficiency\, and led cross-agency teams to integrate cybersecurity requirements within complex systems. \nMr. Eyink holds a Master of Business Administration from William Carey College and a Bachelor of Arts in Business Administration from Saint Leo College. He has also earned advanced certifications in cybersecurity and IT project management from the National Defense University and Villanova University. A member of professional organizations such as the Project Management Institute (PMI) and ISACA\, he has achieved certifications including Project Management Professional (PMP) and Certified Information Security Manager (CISM). \n\n\n \n\n\nVictoria Yan Pillitteri\nSupervisory Computer Scientist and Security Engineering and Risk Management Group Manager @ the National Institute of Standards and Technology (NIST)\nCISSP \nVictoria Yan Pillitteri is a supervisory computer scientist and manager of the Security Engineering and Risk Management Group at the National Institute of Standards and Technology (NIST). The group conducts the research and development of the suite of risk management\, systems security engineering\, and cybersecurity risk analytics and measurement guidance used for managing cybersecurity risk. She is the co-author of multiple NIST publications that are foundational for cybersecurity risk management\, including the security and privacy controls\, control assessment procedures\, the Risk Management Framework\, and the CUI security requirements and assessment procedures (Special Publications (SP) 800-53\, SP 800-53A\, SP 800-53B\, 800-37\, 800-171\, and 800-171A). \nMs. Pillitteri holds a B.S. in Electrical Engineering from the University of Maryland\, a M.S. in Computer Science\, with a concentration in Information Assurance\, from the George Washington University\, completed the Key Executive Leadership Program at American University\, and is a Certified Information Systems Security Professional (CISSP). \n \n\n\n \n\n\nRenee Wynn\nFormer NASA Chief Information Officer and Board Member for Axonius \nRenee Wynn is a leader with over 30 years of experience in environmental policy\, global information technology and cybersecurity operations\, supply chain risk management\, and ESG. She led programs at the Environmental Protection Agency (EPA) and served as the CIO at an iconic agency\, National Aeronautics and Space Administration (NASA). \nRenee currently serves as an independent board member for Axonius\, a cybersecurity company\, and she is seeking additional Board roles. She serves on the Board of Advisors at MITRE\, Interos\, Dataminr\, Adobe\, and Level6 Cybersecurity. She serves as a Strategic Advisor at Attain Capital to their portfolio companies. \nTo continue a lifetime in service to others\, Renee serves on the Board at The Women’s Center\, a Virginia and Washington\, DC-based non-profit organization dedicated to improving the community’s mental health and well-being through counseling\, education\, support\, and advocacy. She also serves on the Board of the Virginia Tech – Applied Research Corporation (VT-ARC). Renee earned a bachelor’s degree in economics from DePauw University. \n \n\n\n \n\n\nDr. Diane Janosek\nCEO of Janos LLC \nDiane M. Janosek is the CEO of Janos LLC. Leveraging her law degree and PhD\, she focuses on the intersection of law\, policy\, and technology to provide advisory services on data policy\, cybersecurity law\, compliance\, governance\, leadership\, and privacy. Previously served as Defense Intelligence Senior Executive Service (SES) for 12 years\, to include leadership roles at the National Security Agency\, to include Commandant National Cryptologic University\, Deputy Director Compliance and Chief Information Security Officer. She also served as Chief Legal Officer for the Privacy and Civil Liberties Oversight Board\, and as Legal Counsel at both the White House and the Pentagon. \nDr. Janosek has published dozens of articles and is a multiple international award-winner. In addition to having a Juris Doctorate\, she has a Master’s in Strategic Intelligence\, a PhD in Cyber Leadership\, is admitted to the United States Supreme Court and is certified in information and network security (CISSP) and ethics and compliance (LPEC). She has been inducted into the Hall of Fame by the Information Systems Security Assoc Inter’l. Dr. Janosek is passionate about giving back and advocating for the global cyber community. \nLearn more at dianejanosek.com \n \n\n\n \n\n\nDavid Branscome\nGlobal Partner Solutions Architect for Security\, Compliance and Identity @ Microsoft \nDavid has been with Microsoft for 17 years in a variety of roles\, from Microsoft Consulting Services to Premier Field Engineer and most recently\, supporting the Microsoft partner organization. He has worked with dozens of state\, local and federal customers\, including supporting some of the largest Microsoft implementations in the federal space. \n \n\n\n \n\n\nDr. Michaela Iorga\nSupervisory Computer Scientist at the National Institute of Standards and Technology (NIST/ITL) \nDr. Michaela Iorga is a supervisory computer scientist at the National Institute of Standards and Technology (NIST/ITL). She serves as the Strategic Outreach Director for the Open Security Controls Assessment Language (OSCAL) program\, and as the senior security technical lead for cloud computing\, chairing the NIST Cloud Security and Forensics Working Groups. \nDr. Iorga\, a subject matter expert in cybersecurity\, risk assessment\, and information assurance\, collaborates with industry\, academia\, and other government stakeholders on developing and disseminating high-level\, vendor-neutral cybersecurity and forensics guidelines that meet national priorities and promote American innovation and industrial competitiveness. Dr. Iorga received her Ph.D. from the Duke University/ Pratt School of Engineering\, in North Carolina\, USA. \n \n\n\n \n\n\nJim Wiggins\nCISSP\, ISSEP\, CISM\, CISA\, CRISC\, CDPSE\, CGRC\, CySA+\, SCNA\, SCNP\, IAM\, IEM\, SSCP\, CEH\, ECSA\, CHFI\, LPT\, TICSA\, CIWSA\, Security+\, and MCSE: Security and FITSP-M \nJim has over 28 years of direct experience in the design\, operation\, management\, and auditing of information technology systems\, with the past 23 years focused on information systems security. He has an extensive background in technical education and specializes in security certification courses aimed at federal and government contracting clients. \nToday\, Jim is the Founder and Principal of Securible\, LLC. Securible is an information security service provider offering cyber training programs to organizations of all sizes. At Securible\, Jim has taught IT security certification courses such as CISSP\, CISM\, CISA\, Ethical Hacking\, RMF\, Security+\, and other courses requested by Securible’s clients. Currently\, he provides education and training support for the National Risk Management Center (NRMC) at the Cybersecurity and Infrastructure Security Agency (CISA) within the Department of Homeland Security (DHS). More information on Securible can be found at: http://www.securible.com. \nJim is also the Founder and Chief Executive Officer (CEO) of the Federal IT Security Institute (FITSI). FITSI is a 501(c)(6) non-profit certification body accredited by the ANSI National Accreditation Board (ANAB) under ISO 17024:2012. FITSI offers a role-based IT security certification program targeted at the federal workforce. More information on FITSI can be found at: http://www.fitsi.org. \nAdditionally\, Jim is the Founder and Executive Director of the FITSI Foundation. The FITSI Foundation is a 501(c)(3) public charity that focuses on cyber education and serves as the philanthropic sister organization of the Federal IT Security Institute. The FITSI Foundation operates the Wounded Warrior Cyber Combat Academy (W2CCA). More information on the FITSI Foundation can be found at: https://www.fitsifoundation.org. \nIn 2020\, Jim launched a TV show on cybersecurity called “Cybersecurity Today\,” which can be viewed in the Washington\, DC area. Episodes can also be streamed online at the following website: http://www.cybersecuritytoday.org. \nIn 2019\, FCW named Jim to the “Federal 100” for his tireless efforts to promote cybersecurity education across all branches of the federal government. \nIn 2011\, the Federal Information Systems Security Educators’ Association (FISSEA) named him “Educator of the Year” for the impact he continues to make on the federal workforce. \nJim holds the following IA/IT security certifications: CISSP\, ISSEP\, CISM\, CISA\, CRISC\, CDPSE\, CGRC\, CySA+\, SCNA\, SCNP\, IAM\, IEM\, SSCP\, CEH\, ECSA\, CHFI\, LPT\, TICSA\, CIWSA\, Security+\, and MCSE: Security and FITSP-M. \n \n\n\n \n\n\nCherilyn Pascoe\nDirector\, NIST NCCoE \nCherilyn Pascoe is the Director of the NIST National Cybersecurity Center of Excellence (NCCoE). She provides strategic direction and technical leadership for the NCCoE\, aligns the NCCoE’s work with the industry\, government\, and NIST priorities\, and builds relationships with key stakeholders. Prior to her role as Director of the NCCoE she served as the Senior Technology Policy Advisor\, advising NIST leadership on technology policy and strategy\, including cybersecurity\, privacy\, and artificial intelligence. She also led the NIST Cybersecurity Framework program and was a team member of the NIST AI Risk Management Framework. Prior to joining NIST in 2021\, she served more than a decade in staff leadership roles on the US Senate Committee on Commerce\, Science\, and Transportation. Most recently\, she served as Deputy Policy Director managing the Committee’s Space and Science Subcommittee\, which has jurisdiction over science\, technology\, standards\, and civil space policy. \n \n\n  \nSANS Workshop Track Sessions \n\n10:00 AM – 12:00 PM \n\n\nPresented by SANS – Avoiding Data Disasters: Techniques to Identify and Address Cloud Storage Misconfigurations \nPresenter: Shaun McCullough (SANS and GitHub) \nIt appears that every few months\, there’s news of yet another cloud breach stemming from a carelessly configured cloud storage solution. While this isn’t the default for most cloud vendors\, some users still manage to make their cloud data publicly accessible by going out of their way – sometimes to a significant extent. Whether it’s out of ignorance or convenience\, it doesn’t matter – this practice must come to an end. \nTo address this issue\, we’ve developed a workshop that equips attendees with various techniques and methods to identify and rectify cloud storage misconfigurations in their own cloud accounts. We’ll even demonstrate some ways to prevent these misconfigurations from happening in the first place. Although the chosen vendor for this workshop is AWS\, due to its Simple Storage Service (S3) being the one making headlines\, misconfigurations could occur in any cloud environment. Hence\, the techniques discussed in this workshop will be applicable to all cloud vendor environments\, including Azure\, Google Cloud Platform\, and Oracle. \nLearning objectives for this session: \n\nDiscover all-too-common cloud storage security deficiencies present as either insecure vendor defaults or careless mistakes\nCorrect these issues using a variety of means (e.g.\, cloud management console\, command line tools\, and Infrastructure-as-Code)\nLearn how to leverage command-line tools to deploy\, assess\, and secure cloud solutions\n\nSystem Requirements \nParticipants should bring a computer with the following requirements to participate in the workshop. It is critical that you back-up your system ahead of time. It is also strongly advised that you do not bring a system storing any sensitive data. Your system should meet these requirements: \n\nLaptop with a modern web browser\nAWS account with root access or an IAM user with Administrator Access permissions\nIf you need an AWS account\, you can create a free tier account with root access at https://aws.amazon.com/free/. The cost will be minimal (pennies) to complete the workshop\n\n\n\n01:00 PM – 03:00 PM \n\n\nPresented by SANS – Reverse Engineering Malware: A Hands-On Introduction \nPresenter: Anuj Soni (Johns Hopkins University APL and SANS) \nIn this interactive\, hands-on workshop\, participants will be introduced to the fundamentals of Windows executable malware analysis\, learning key techniques for dissecting and understanding malicious code. Through guided demonstrations and exercises\, attendees will explore static and dynamic analysis methods\, identify suspicious indicators\, and recognize common malware behaviors. \nWhether you’re new to reverse engineering or looking to sharpen your skills\, this practical workshop will equip you with the foundational tools needed to triage and analyze Windows malware with confidence. \nLearning Objectives: \n\nUnderstand the Malware Analysis Process\nAnalyze the PE File Structure (EXEs and DLLs)\nPerform Basic Static and Dynamic Analysis\n\nParticipants should bring a computer with the following requirements to participate in the workshop with the following requirements: \nSystem Requirements: \nBack up your system before class. Better yet\, use a system without any sensitive/critical data. \nMANDATORY SYSTEM HARDWARE REQUIREMENTS: \n\nCPU: 64-bit Intel i5/i7 (8th generation or newer)\, or AMD equivalent. A x64 bit\, 2.0+ GHz or newer processor is mandatory for this class.\nCRITICAL: Apple Silicon devices cannot perform the necessary virtualization and therefore cannot in any way be used for this course.\nBIOS settings must be set to enable virtualization technology\, such as “Intel-VTx” or “AMD-V” extensions. Be absolutely certain you can access your BIOS if it is password protected\, in case changes are necessary.\n16GB of RAM or more is required.\n200GB of free storage space or more is required.\nAt least one available USB 3.0 Type-A port. A Type-C to Type-A adapter may be necessary for newer laptops. Some endpoint protection software prevents the use of USB devices\, so test your system with a USB drive before class.\nWireless networking (802.11 standard) is required. There is no wired Internet access in the classroom.\n\nMANDATORY HOST CONFIGURATION AND SOFTWARE REQUIREMENTS \n\nYour host operating system must be the latest version of Windows 10\, Windows 11\, or macOS 10.15.x or newer.\nFully update your host operating system prior to the class to ensure you have the right drivers and patches installed.\nLinux hosts are not supported in the classroom due to their numerous variations. If you choose to use Linux as your host\, you are solely responsible for configuring it to work with the course materials and/or VMs.\nLocal Administrator Access is required. (Yes\, this is absolutely required. Don’t let your IT team tell you otherwise.) If your company will not permit this access for the duration of the course\, then you should make arrangements to bring a different laptop.\nYou should ensure that antivirus or endpoint protection software is disabled\, fully removed\, or that you have the administrative privileges to do so. Many of our courses require full administrative access to the operating system and these products can prevent you from accomplishing the labs.\nAny filtering of egress traffic may prevent accomplishing the labs in your course. Firewalls should be disabled or you must have the administrative privileges to disable it.\nDownload VMware Workstation Pro 17.5.X+ for Windows hosts or VMWare Fusion Pro 13.5.X+ for macOS hosts prior to class beginning. If you do not own a licensed copy of VMware Workstation Pro or VMware Fusion Pro\, you can download a free 30-day trial copy from VMware.\nVMware will send you a time-limited serial number if you register for the trial at their website. This course requires a “Pro” version of VMware software. The “Player” versions are not sufficient.\nOn Windows hosts\, VMware products might not coexist with the Hyper-V hypervisor. For the best experience\, ensure VMware can boot a virtual machine. This may require disabling Hyper-V. Instructions for disabling Hyper-V\, Device Guard\, and Credential Guard are contained in the setup documentation that accompanies your course materials.\nDownload and install 7-Zip (for Windows Hosts) or Keka (for macOS hosts). These tools are also included in your downloaded course materials.\n\n\n\n03:00 PM – 05:00 PM \n\n\nPresented by SANS – Build a Machine Learning Neural Network for Anomaly Detection on Logs \nPresenter: Christopher Crowley (SANS) \nGPTs (Generative Pretrained Transformers) based on Large Language Models are great for a lot of challenges. But they’re not trained to find outliers within your log data. \nIn this brief\, informative\, and useful session\, Christopher Crowley will discuss the concept of a variational autoencoder\, then show how you could implement this to train an autoencoder based on your logs. \nAfter training on your log information\, you would then implement the concept to look for outliers within your log data\, to surface weird things to analysts for review. The session will include theory\, a practical demonstration using a jupyter lab notebook\, python\, and tensorflow; and the material to enable you to build the neural network. Even if you’re not a programmer\, this session will enable understanding what’s possible in building your own machine learning neural network. \nView Christopher’s Speaker Showcase video for this session \nLearning Objectives: \n\nFundamental concepts associated with use of tensorflow\, a machine learning development library\nConcepts associated with deep learning and variational autoencoder\nObserve the data cleaning (extract\, transform\, load) and training of a deep learning neural network\n\nSystem Requirements \nParticipants should bring a computer with the following requirements to participate in the workshop. It is critical that you back-up your system ahead of time. It is also strongly advised that you do not bring a system storing any sensitive data. Your system should meet these requirements: \n\nModern 64-bit processor (ARM/AMD/Intel) running Linux (Ubuntu or similar recommended\, Linux kernel version 6 or higher)\, Windows 10 or later\, or MacOS 11.x or later\nA minimum of 16 GB RAM\n10 GB Free Hard Drive Space\nYour account must have the necessary rights to install Anaconda or Anaconda must be preinstalled.\n\n\n  \nSANS Workshop Presenters \n\n \n\n\nShaun McCullough\nCloud Security Engineer @ GitHub and SANS Instructor \nShaun spent 20+ years at the National Security Agency working in all aspects of cyber operations. A software engineer\, manager\, researcher\, and operations lead\, including as the technical director of the Blue\, Red\, and Hunt teams. Today\, Shaun is a staff level Cloud Security Engineer at GitHub focusing on cloud infrastructure. Shaun is also the lead author of SANS SEC541: Cloud Security Threat Detection\, which focuses on how attackers target cloud infrastructure and what security analysts\, SOC operators\, and detection engineers can do to protect their organizations. \n \n\n\n \n\n\nAnuj Soni\nReverse Engineer @ the Johns Hopkins University Applied Physics Laboratory (APL) and SANS Certified Instructor \nAnuj is a Reverse Engineer at the Johns Hopkins University Applied Physics Laboratory (APL)\, where he specializes in malware research and reverse engineering. He is a SANS Certified Instructor\, the author of FOR710: Advanced Code Analysis\, and co-author of FOR610: Malware Analysis Tools and Techniques. He also creates educational malware analysis content on YouTube to inspire others to dive into the field. When Anuj is away from his computer\, you’ll find him at the local gym\, or with his kids – which is also a workout. \n \n\n\n \n\n\nChristopher Crowley\nSANS Senior Instructor @ SANS Institute \nChristopher Crowley\, a SANS Senior Instructor\, has 25 years of industry experience managing and securing networks. He has authored numerous courses and is considered a leading expert in building an effective SOC. He currently works as an independent consultant in the Washington\, DC area focusing on effective computer network defense. His work experience includes penetration testing\, security operations\, incident response\, and forensic analysis. \n \n\n  \nSpecial Activities \n\n10:00 AM – 03:00 PM \n\n\nCapture the Flag (CTF) \nHosted By: Capitol Technology University \nCheckin: 10:00 AM – 10:30 PM \nActivity Overview: Test your cybersecurity skills and compete against fellow conference attendees in a live Capture the Flag (CTF) competition. The CTF will follow a Jeopardy-style format\, where individuals solve security challenges in cryptography\, web exploitation\, reverse engineering\, forensics\, and binary exploitation to name a few. If you think you’re up for the challenge\, we look forward to you joining us! \nNo advance registration required. \nSession Requirements: \n\nLaptop with a full operating system (Windows\, Mac\, Linux). Tablets\, chromebooks\, and kindles are not recommended.\n\n\n\n03:00 PM – 06:00 PM \n\n\nIndustry Exchange \nActivity Overview: Meet representatives from DC area companies. Use this time to network\, network\, network! \n\n  \nHost Organization \nThe Department of Information Sciences and Technology (IST) at George Mason University\, within the College of Engineering and Computing\, is dedicated to advancing knowledge and innovation in the fields of Artificial intelligence (AI)\, data science\, cybersecurity\, and application development. With a focus on hands-on learning\, cutting-edge research\, and interdisciplinary collaboration\, the department prepares students to tackle real-world challenges and lead in the rapidly evolving tech industry. As a host and co-sponsor of this conference\, IST supports the exchange of ideas and the development of the next generation of technology leaders. \n  \nVenue\, Parking\, and Transportation Information \n\n \n\n\nVenue Location \nGeorge Mason University (GMU) Arlington Campus \nThe event is in Van Metre Hall in the Mason Square Building\n3351 Fairfax Drive\, \nArlington\, VA 22201 \n  \n\n  \n\n \n\n\nParking \nVisitor parking is available in the Van Metre Hall (formerly Founders) Garage\, located directly beneath the school. To access the garage\, use the entrance located off of Kirkwood Drive\, in between Fairfax Drive and Washington Boulevard.  Please view the Mason Square parking map for additional information. \nParking is included in the registration fee for the event. \n\n  \n\n \n\n\nMetro \nThe nearest Metro station is the Ballston-MU station. \nIt is a 14-minute walk from the metro station to the GMU Campus \n  \n\n  \nSponsors \nThe GWDC thanks our sponsors and their support of the chapter and its members. \n \nConference Sponsor \n\n \nPlatinum Sponsor \n\n\n \nGold Sponsor \n\n\n \nGold Sponsor \n\n \nSilver Sponsor \n\n  \nEvent Questions and Policies \n\n\nRegistration Questions \nIf you have any registration questions about this event\, please contact us by completing the Registration Contact Form linked below. \nRegistration Questions \n  \n\n\n\nCPE Questions \nIf you have CPE questions after the event has concluded\, please contact us by completing the CPE contact form linked below. \nCPE Questions \n  \n\n\n\n\nCancellation and Refunds \nCancellation and refund for advance registrations is allowed if cancellations are submitted through the registration system by the date registration closes. Refunds vary depending on the date of cancellation and cost of the event. See ISACA GWDC Event Policies for details. \n\n\n\n\nComplaints \nThe GWDC welcomes your comments\, complaints\, suggestions\, questions\, and other feedback concerning our website information and services. \nAll complaints should be submitted through the Registration Contact Form. \n\n\n  \nCPE Information \nEarn up to 8 Continuing Professional Education (CPE) credit in the area of Information Technology. The ISACA® Greater Washington\, D.C. Chapter is registered with the National Association of State Boards of Accountancy (NASBA) as a sponsor of continuing professional education on the National Registry of CPE Sponsors. State boards of accountancy have final authority on the acceptance of individual courses for CPE credit. Complaints regarding registered sponsors may be submitted to the National Registry of CPE Sponsors through its website: www.NASBARegistry.org. \n  \nCPE Distribution and Evaluation Survey \nCPEs will be distributed via e-mail along with the event evaluation survey after the completion of the event. Attendees must be present for the full event to receive full CPE credit. \n  \nCPE-Related Details \n\nLearning Objective: After completing the course\, students will have a greater understanding of current trends and practices in AI\, Cybersecurity and Trust.\nPrerequisites and Advance Preparation: None\nProgram Knowledge Level: Basic\nDelivery Method:  Live\, In-Person\nField of Study:  Information Technology – Technical
URL:https://isaca-gwdc.org/event/future-tech-dc/
LOCATION:George Mason University – Arlington\, 3351 Fairfax Drive\, Arlington\, VA\, 22201\, United States
CATEGORIES:Conferences
ATTACH;FMTTYPE=image/png:https://isaca-gwdc.org/wp-content/uploads/2025/01/Future-Tech-DC_600.png
ORGANIZER;CN="Avneet Sabharwal":MAILTO:programs@isaca-gwdc.org
END:VEVENT
BEGIN:VEVENT
DTSTART;TZID=America/New_York:20250320T083000
DTEND;TZID=America/New_York:20250320T123000
DTSTAMP:20250319T125528Z
CREATED:20241231T183229Z
LAST-MODIFIED:20250319T125528Z
UID:33353-1742459400-1742473800@isaca-gwdc.org
SUMMARY:SheLeadsTech - Celebrating Women in Technology
DESCRIPTION:In celebration of Women’s Month this March\, this SheLeadsTech Conference brings together IT audit and cybersecurity professionals to celebrate the contributions of women leaders in the field while fostering inclusivity and collaboration for all. This unique event is designed for both men and women\, offering sessions that highlight innovation\, leadership\, and strategies to excel in the rapidly evolving tech landscape. \nFeaturing an all-female lineup of inspiring speakers\, this conference provides an opportunity to: \n\nGain actionable insights from industry leaders driving change in IT audit and cybersecurity\nExplore cutting-edge solutions and strategies to address today’s most pressing challenges\nBuild connections in an inclusive environment that champions diversity and collaboration\nCelebrate the achievements of women while engaging in meaningful discussions about empowering the next generation of leaders\n\nWhether you’re an IT auditor\, IT/Cyber professional\, or business leader\, join us for a day of inspiration\, education\, and connection as we celebrate Women’s Month and explore how diverse perspectives strengthen the future of technology and leadership. Together\, we can lead\, innovate\, and thrive. \nRegistration closes on March 19th @ 2pm. \nRegister Today! \n  \nConference Overview \n\nMarch 20 \nThe conference will be held on March 20\, 2025 from \n8:30 am to 12:30 pm. \nAdd this event to your calendar using the Add to Calendar link at the bottom of the page. \n  \nVirtual Event \nThe conference will be held using Zoom. \nPrior to the event\, participants must install the Zoom app on their respective devices. Participants using the web-based Zoom or calling via the phone may not be entitled to CPE credits. \n\n\nGWDC Member Fee – $10 \nThe fee for GWDC Members is $10 for the conference.\nThe fee for all other registrants is $30 for the conference. \nTo become a member and take advantage of the member rate for our events\, among other benefits\, join ISACA and select the Greater Washington D.C. Chapter as your local chapter. \n  \nEarn up to 4 CPEs \nAttendees can earn up to 4 CPEs for this event. \nParticipants must respond to all the poll questions via the Zoom polling feature or chat log in order to receive NASBA CPE credits. The GWDC will not be responsible for the participant’s inability to respond to the polls. \n\nShare this Event in Your Network \n\n	\n		\n	\n			\n			\n								\n										\n													\n														\n												Share on X\n					\n					\n									\n			\n		\n			\n			\n								\n										\n													\n														\n												Share on Linkedin\n					\n					\n									\n			\n		\n			\n			\n								\n										\n													\n														\n												Share on Facebook\n					\n					\n									\n			\n		\n			\n			\n								\n										\n													\n														\n												Share on Print\n					\n					\n									\n			\n		\n			\n			\n								\n										\n													\n												Share on Email\n					\n					\n									\n			\n		\n		\n\n	\n\n\n  \nSpeaker Insights Showcase \nThe GWDC Media Relations team works with Conference speakers to share insights into their IT journey as well as their topic for the conference in the “Speaker Insights Showcase” series. Below are the videos for three of this month’s speakers. \nYou can view the full Speaker Insights Showcase series on our YouTube channel. \n﻿﻿ \n  \n\n﻿ \n  \n\nAgenda \n \n\n08:30 AM – 09:30 AM \n\n\nAccelerate Your Tech Mastery: Leveraging Generative AI to Empower Women in STEM \nPresenter: Sujatha Dantuluri (AWS) \nIn the rapidly evolving technology industry\, the pace of change and the emergence of transformative innovations\, such as generative AI\, have created a pressing need for continuous upskilling and reskilling. This is especially true for women in STEM fields\, who often face unique challenges in accessing the resources and support necessary to keep their skills sharp and stay ahead of the curve. \nThis session will explore how women in tech can leverage the capabilities of Amazon Bedrock\, a comprehensive generative AI platform\, to accelerate their technical upskilling and drive innovation. Through interactive demonstrations and real-world case studies\, attendees will learn how to leverage Bedrock’s advanced language models\, multimodal capabilities\, and customization features to tackle complex challenges\, automate repetitive tasks\, and unlock new levels of creativity and problem-solving. \n\n \n\n09:30 AM – 10:30 AM \n\n\nThe Power of Partnerships \nPresenter: Marcelle Lee (Equinix) \nIn my role as lead for cyber threat research at Equinix\, I am responsible for intelligence sharing partnerships. In this talk\, I will discuss how to establish\, maintain\, and grow these crucial relationships. I will also share practical tips on starting an intelligence sharing program and highlight some success stories that demonstrate the value of collaboration in enhancing cybersecurity. \n\n \n\n10:30 AM – 11:30 AM \n\n\nFireside Chat – Leadership & Talent Development: Breaking Barriers and Building Future-Ready Skills \nPresenters: Emily Lewis Pinnell (Tential Solutions) and Sushila Nair (Cybernetic) and Avneet Sabharwal (GWDC Programs Director) \nJoin us for an engaging fireside chat as part of the ISACA Greater Washington DC SheLeadsTech initiative\, where we will explore the evolving landscape of leadership and talent development. In an era of rapid technological advancements\, organizations are seeking professionals who can blend technical expertise with strategic leadership\, risk management\, and business acumen. \nThis conversation will delve into the most in-demand skills in cybersecurity and IT governance\, from cloud security and AI risk management to regulatory compliance and zero-trust architectures. We’ll discuss practical strategies for upskilling\, career progression\, and overcoming the ‘pink ceiling’—the invisible barriers that often hinder women from reaching leadership roles. \nThrough real-world insights and success stories\, our speakers will address mentorship\, executive presence\, and building influence. Whether you are an emerging leader or an experienced professional looking to advance\, this session will provide actionable strategies to help you future-proof your career\, navigate workplace challenges\, and step into leadership with confidence. \nDon’t miss this opportunity to gain industry insights\, and be part of the conversation shaping the future of leadership in IT audit and cybersecurity. \n\n \n\n11:30 AM – 12:30 AM \n\n\nPioneering Change Through Bold Innovation \nPresenter: Gurmeet Kaur (Agilious) \nThe United Nations finds that in 2022\, only 17% of inventors holding international patents were women\, while 83% were men. To achieve innovation and progress\, it’s necessary to challenge the status quo\, think outside the box\, and break established rules. \nJoin our speaker\, Gurmeet Kaur\, as she walks us through how to navigate barriers\, believe in your idea even when facing challenges\, and persevere against the bias that holds us back. \n\n  \nPresenters \n \n\n  \n  \n  \n\n\nSujatha Dantuluri\nSenior Solutions Architect on the US Federal Civilian team @ AWS \nSujatha Dantuluri is a Senior Solutions Architect on the US Federal Civilian team at AWS. With over 20 years of experience supporting both commercial and government customers\, she is a trusted advisor in building and architecting mission-critical solutions. An active public speaker\, Sujatha also contributes to IEEE standards. Additionally\, she serves as a mentor for women in within and outside the AWS. Sujatha is an active participant in initiatives that enable and empower women in the industry. \n \n\n \n\n \n\n\nMarcelle Lee\nPrincipal Information Security Engineer | Team Lead\, Cyber Threat Research @ Equinix \nMarcelle is a principal information security engineer at Equinix\, the world’s largest digital infrastructure company\, where she oversees the cyber threat research team. She has more than ten years of experience in cybersecurity\, specializing in cyber threat analysis\, research\, and reporting\, identification of tactics\, techniques and procedures (TTPs)\, campaign tracking\, threat hunting\, network traffic analysis\, intrusion analysis\, digital forensics\, malware analysis\, and technical writing. Before embarking on her cyber career\, Marcelle had years of experience leading operations and projects for a variety of organizations. \nMarcelle is also a passionate educator and a published author\, teaching digital forensics and cybersecurity courses at University of Maryland. She is a recognized community leader\, presenting technical talks and training\, providing mentoring\, and volunteering on numerous boards and committees. She is driven by the mission of advancing and empowering people in the field of cybersecurity. \nIf you are looking for a key for a CTF challenge it is “diversity.” \n \n\n \n\n \n\n\nEmily Lewis Pinnell\nSenior Vice President\, Professional Services @ Tential Solutions \nI have worked with hundreds of customers in managing Data\, Cloud and AI initiatives. In building innovative professional services teams\, I focus on the pairing technical expertise with a focus on the impact to people and process. \nI love building and making a tangible impact. With a focus on strategic growth\, I’ve achieved significant success in delivering compelling and tangible results. I am demonstrably committed to optimizing organizational systems\, performance—and the bottom line. \nI effectively lead and empower top-performing global teams. With excellent communication and interpersonal skills\, I easily build productive relationships with diverse groups of key stakeholders\, shareholders\, clients\, and colleagues at all levels. \n \n\n\n \n\n\nSushila Nair\nCEO of Cybernetic LLC\nCISSP\, GIAC GSTRT\, GSNA GDSA\, CISA\, CISM\, CRISC\, CDPSE\, CCSK\, CCAK \nSushila Nair is the CEO of Cybernetic LLC and former Vice President of Capgemini’s North American Cybersecurity practice\, where she played a crucial role in driving secure digital transformation on a global scale. With over 30 years of experience in computing infrastructure\, business\, and security risk analysis\, Sushila has established herself as a leading authority in the cybersecurity domain. Her career highlights include serving as Vice President responsible for global security offers at NTT DATA Services\, a decade of leading her own IT and cybersecurity company across major UK cities\, and serving as a Chief Information Security Officer (CISO) and trusted advisor to boards\, where she honed her expertise in protecting organizations from evolving digital threats. Recognized through the top cybersecurity leader award by Security Magazine\, Sushila’s influence in the industry is undeniable. \nAn esteemed thought leader\, Sushila has shared her insights on prestigious platforms such as RSA Conference and ISACA’s global events. Her active participation in ISACA’s global emerging trends working group and her leadership as President of ISACA’s Greater Washington\, D.C. Chapter underscore her dedication to advancing the field of cybersecurity. In 2024\, her commitment to nurturing the next generation of cybersecurity professionals and promoting diversity in the industry was honored with the prestigious ISACA Technology for Humanity Award. \n  \n\n\n \n\n\nAvneet Sabharwal\nIT Audit Manager and GWDC Programs Director\nCISA\, CMMC-AB Registered Practioner \nAvneet Sabharwal is an experienced IT Auditor with nearly a decade of expertise across various industries\, including consulting\, finance\, and telecommunications. She has worked extensively on SOX\, SOC 1\, and FSA audits. In her current role\, Avneet is an Internal Audit Manager at a financial planning firm\, focusing on information systems and data analytics. \nAvneet holds a Master’s degree in Information Systems and Technology and an MBA from the George Washington School of Business. She is also certified as a CISA and a CMMC-AB Registered Practitioner. \nIn addition to her professional role\, Avneet serves as the Director of Virtual Conferences on the ISACA GWDC chapter Board\, where she is responsible for planning\, organizing\, and hosting monthly conferences. \nIn her free time\, Avneet enjoys traveling and exploring new places with her family\, reading thriller novels\, and\, recently\, delving into the art of prompting. \n \n\n \n\n \n\n\nGurmeet Kaur\nChief Product & Experience Officer @ Agilious \nGurmeet is a product and design leader with passion for designing and delivering extraordinary user experiences. Gurmeet’s expertise is in driving user engagement by planning\, designing and delivering digital products that meet end user needs. She brings 25+ years of experience leading successful transformations across the private and non-profit sectors. Gurmeet is building Agilous’s strategy and design practices to ensure all applications and products we build are based on customer data and deliver clear value to the enterprise (private or public sector) and their end users. \nGurmeet joined Agilious from Capital One\, where she built a Developer Experience team from the ground up and delivered the long term vision for Capital One Developer Experience. Gurmeet has led the product transformation at AARP’s for-profit sector and doubled member engagement on the benefits’ app. In her tenure at Marriott she served as the digital lead for all acquisitions\, successfully integrating multiple brands into the digital Marriott platforms\, including The Ritz-Carlton\, Starwood\, Gaylord\, MOXY\, Atlantis\, Protea\, and AC hotels. \nGurmeet is a Gallup certified coach with deep expertise in building high-performing teams by leveraging collective skills\, diverse perspectives\, and complementary expertise. She is also the published author of Empathy & Arrogance: The Paradox of Digital Products\, a compilation of lessons learned over two decades of building digital products. \n \n\n  \nEvent Questions and Policies \n\n\nRegistration Questions \nIf you have any registration questions about this event\, please contact us by completing the Registration Contact Form linked below. \nRegistration Questions \n  \n\n\n\n\nCPE Questions \nIf you have CPE questions after the event has concluded\, please contact us by completing the CPE contact form linked below. \nCPE Questions \n  \n\n\n\n\nCancellation and Refunds \nCancellation and refund for advance registrations is allowed if cancellations are submitted through the registration system by the date registration closes. Refunds vary depending on the date of cancellation and cost of the event. See ISACA GWDC Event Policies for details. \n\n\n\n\nComplaints \nThe GWDC welcomes your comments\, complaints\, suggestions\, questions\, and other feedback concerning our website information and services. \nAll complaints should be submitted through the Registration Contact Form. \n\n\n  \n  \nCPE Information \nEarn up to 4 Continuing Professional Education (CPE) credit in the area of Information Technology. The ISACA® Greater Washington\, D.C. Chapter is registered with the National Association of State Boards of Accountancy (NASBA) as a sponsor of continuing professional education on the National Registry of CPE Sponsors. State boards of accountancy have final authority on the acceptance of individual courses for CPE credit. Complaints regarding registered sponsors may be submitted to the National Registry of CPE Sponsors through its website: www.NASBARegistry.org \n  \nCPE Distribution and Evaluation Survey \nCPEs will be distributed via e-mail along with the event evaluation survey after the completion of the event. Attendees must be present for the full event to receive full CPE credit. \n  \nLearning Objective \nAfter attending this event\, attendees will learn about current and future trends in emerging technology. \n  \nCPE-Related Details \n\nPrerequisites: None\nAdvance Preparation: None\nProgram Knowledge Level: Basic\nDelivery Method:  Group Internet Based\nField of Study:  Information Technology – Technical
URL:https://isaca-gwdc.org/event/emerging-technology-conference-2025/
LOCATION:Virtual Event
CATEGORIES:Conferences
ATTACH;FMTTYPE=image/png:https://isaca-gwdc.org/wp-content/uploads/2024/12/conference-emergingtech-sheleadstech.png
ORGANIZER;CN="Avneet Sabharwal":MAILTO:programs@isaca-gwdc.org
END:VEVENT
BEGIN:VEVENT
DTSTART;TZID=America/New_York:20250220T083000
DTEND;TZID=America/New_York:20250220T123000
DTSTAMP:20250222T191604Z
CREATED:20241231T173905Z
LAST-MODIFIED:20250222T191604Z
UID:33349-1740040200-1740054600@isaca-gwdc.org
SUMMARY:Artificial Intelligence Conference
DESCRIPTION:Artificial intelligence (AI) is reshaping the landscape of IT audit and cybersecurity\, offering unprecedented opportunities and challenges for professionals in the field. This conference brings together thought leaders\, innovators\, and practitioners to explore how AI is transforming the way organizations secure their systems\, manage risks\, and navigate regulatory requirements. \nWhether you’re an IT auditor\, cybersecurity professional\, or business leader\, this conference equips you with the knowledge and tools to harness the power of AI while addressing its unique risks. Prepare to lead your organization into the future with confidence\, innovation\, and resilience. \nRegistration closes on February 19th @ 8pm. \nRegister Today! \n  \nConference Overview \n\nFebruary 20 \nThe conference will be held on February 20\, 2025 from \n8:30 am to 12:30 pm. \nAdd this event to your calendar using the Add to Calendar link at the bottom of the page. \n  \nVirtual Event \nThe conference will be held using Zoom. \nPrior to the event\, participants must install the Zoom app on their respective devices. Participants using the web-based Zoom or calling via the phone may not be entitled to CPE credits. \n\n\nGWDC Member Fee – $10 \nThe fee for GWDC Members is $10 for the conference.\nThe fee for all other registrants is $30 for the conference. \nTo become a member and take advantage of the member rate for our events\, among other benefits\, join ISACA and select the Greater Washington D.C. Chapter as your local chapter. \n  \nEarn up to 4 CPEs \nAttendees can earn up to 4 CPEs for this event. \nParticipants must respond to all the poll questions via the Zoom polling feature or chat log in order to receive NASBA CPE credits. The GWDC will not be responsible for the participant’s inability to respond to the polls. \n\nShare this Event in Your Network \n\n	\n		\n	\n			\n			\n								\n										\n													\n														\n												Share on X\n					\n					\n									\n			\n		\n			\n			\n								\n										\n													\n														\n												Share on Linkedin\n					\n					\n									\n			\n		\n			\n			\n								\n										\n													\n														\n												Share on Facebook\n					\n					\n									\n			\n		\n			\n			\n								\n										\n													\n														\n												Share on Print\n					\n					\n									\n			\n		\n			\n			\n								\n										\n													\n												Share on Email\n					\n					\n									\n			\n		\n		\n\n	\n\n\n  \nSpeaker Insights Showcase \nThe GWDC Media Relations team works with Conference speakers to share insights into their IT journey as well as their topic for the conference in the “Speaker Insights Showcase” series. Below are the videos for three of this month’s speakers. \nYou can view the full Speaker Insights Showcase series on our YouTube channel. \n \n  \n\n \n  \n\nAgenda \n \n\n08:30 AM – 09:30 AM \n\n\nMITRE ATLAS: Actionable Tools for AI Security & Assurance \nPresenter: Dr. Christina Liaghati (MITRE) \nMITRE ATLAS (atlas.mitre.org) is a public knowledge base of adversary tactics and techniques based on real-world attack observations and realistic demonstrations from artificial intelligence (AI) red teams and security groups. \nThis capabilities overview will include the latest MITRE ATLAS community driven and open sourced efforts focused on capturing and sharing cross community data on real world AI incidents\, expanding the community’s data on vulnerabilities that can arise when using open-source AI models or data\, especially for vulnerabilities that fall outside of the scope of CVE/CWE\, and developing mitigations to defend against these AI security threats and vulnerabilities. \n\n \n\n09:30 AM – 10:30 AM \n\n\nEthics of Artifical Intelligence \nPresenter: Diana Burley (American University) \nAI and other emerging technologies both empower innovation and expose societal vulnerabilities. The policies that guide their deployment and use determine\, to a large extent\, the role that these innovations play in society. As such\, the policies\, and the policymakers who shape them\, are powerful arbiters of future human welfare. How then\, do we extend the “responsible” principles we promote with the technology developers to the policies and policymakers who shape societal standards? \n\n \n\n10:30 AM – 11:30 AM \n\n\nAI Trends and Deploying Systems Securely at Scale \nPresenter: Henrik Balle (AWS) \nThis presentation explores the latest generative AI trends and cloud-native approaches to deploying enterprise-ready generative AI solutions at scale\, highlighting advances in and the advantages of managed services alongside comprehensive security controls. We examine how modern cloud infrastructure enables organizations to build innovative generative AI solutions while maintaining security\, data privacy and regulatory compliance. Key focus areas include flexible model deployment options\, knowledge bases\, AI agents\, integrated governance tools\, and scalable architecture that helps enterprises minimize risks while maximizing AI innovation. \n\n \n\n11:30 AM – 12:30 AM \n\n\nUnpacking Generative AI Applications: Navigating Security Risks \nPresenter: Ahmed Abugharbia (SANS) \nGenerative AI (GenAI) is no longer a future possibility—it’s a present reality transforming industries at an unprecedented pace. As organizations embrace GenAI to drive innovation and gain competitive advantages\, they must also navigate the significant risks it introduces. In this talk\, we will demystify the core components of GenAI applications and examine the critical security challenges they pose. \n\n  \nPresenters \n \n\n \n\n\nDr. Christina Liaghati\nTrustworthy & Secure AI Department Manager and MITRE ATLAS Lead @ MITRE \nWorking across a collaborative global community of industry\, government\, and academia\, Dr. Liaghati leads MITRE’s Trustworthy & Secure AI Department and MITRE ATLAS\, where she passionately drives research and developments in trustworthy and secure AI for everyone working to leverage AI-enabled systems. Leading her department of 50+ scientist and engineers and serving the community with the not-for-profit\, objective\, MITRE perspective\, she is dedicated to working together to create and openly share actionable tools\, capabilities\, data\, and frameworks for trustworthy and secure AI like ATLAS\, an ATT&CK-style framework of the threats and vulnerabilities of AI-enabled systems. \nAs Dr. Liaghati has worked across the community to improve the common understanding of AI security concerns\, her work quickly started overlapping with broader AI assurance concerns\, which includes AI equitability\, interpretability\, reliability\, robustness\, safety\, and needs for privacy enhancement. As a result of this expansion beyond AI security into more of these elements of trustworthy AI and AI assurance\, her current focus under ATLAS and across the international community is to build a protected mechanism for increased knowledge and incident sharing across government and industry in both AI security and the broader areas of AI assurance. \nDr. Liaghati also chairs the NATO Science and Technology Organization Research Task Group on the AI Assurance and Security\, focused on fostering an enduring collaborative community of NATO organizations and industry partners\, leveraging the Science and Technology Organization to shape future interoperable capability developments in AI security and assurance. \n \n\n \n\n \n\n\nDr. Diana Burley\nVice Provost for Research and Innovation @ American University \nDr. Diana L. Burley is a global cybersecurity expert with more than 30 years of experience driving digital transformation\, implementing cybersecurity workforce initiatives\, and promoting an equitable global technology community. Diana is currently Vice Provost for Research and Innovation at American University where she also leads the Khan Cyber & Economic Security Institute and serves as a member of the faculty. As both the university’s chief research officer and chief innovation officer\, Diana oversees the university-wide R&D portfolio\, research partnerships\, and strategic initiatives to catalyze discovery. She advises government officials and regularly offers thought leadership at executive forums. Her board service includes the Cyber Future Foundation and the Global Cyber Security Advisory Group\, and she has been honored by GET Cities\, Executive Women’s Forum\, SC Magazine\, ACM\, and others for her leadership in building the global cybersecurity workforce. She earned her Ph.D. from Carnegie Mellon University. \n \n\n \n\n \n\n\nHenrik Balle\nPrincipal Solutions Architect @ AWS \nHenrik Balle is a Principal Solutions Architect at AWS supporting federal civilian customers\, and he helps them achieve their mission through architecting and implementing innovative solutions at scale. He works closely with customers on a range of topics from AI/ML to security and governance at scale\, and he holds both AWS Security and Machine Learning Specialty certifications. In his spare time\, he loves road biking\, motorcycling\, or you might find him working on yet another home improvement project. \n \n\n\n \n\n\nAhmed Abugharbia\nSANS Certified Instructor and Founder of Cyberdojo\nGIAC GSEC and GPEN\, AWS Certified DevOps Engineer Professional\, AWS Certified Solutions Architect Associate\, CEH\, JNCIS-FWV\, JNCIA-IDP\, and CCNA \nAhmed Abugharbia is a SANS Certified Instructor and founder of Cyberdojo\, focusing on GenAI and Cloud Security. With over 17 years of experience in security\, Ahmed has worked and led projects in cloud security\, network and application security\, as well as incident handling. He is the author of SEC545: GenAI and LLM Application Security™ and an instructor for SEC540: Cloud Security and DevSecOps Automation™ \nFor over a decade Ahmed has been providing training in various capacities. Starting with mentoring new team members at work to providing training to clients on various security topics\, teaching them about hacking concepts and the possible effects on their infrastructure. His first interaction with SANS was in 2013 when he took both SEC401: SANS Security Essentials and SEC560: Network Penetration Testing and Ethical Hacking\, earning both the GSEC and GPEN certificates. By that point at his career\, he had taken many classes\, exams\, and attended many seminars but felt none of which came close to how practical and comprehensive the SANS courses were. A few years later\, after realizing he wanted teaching to be an integral part of his career\, SANS was his first choice. He is also a faculty member of the SANS Technology Institute\, an NSA Center of Academic Excellence in Cyber Defense and multiple winner of the National Cyber League competition. \nAhmed holds a bachelor’s degree in Computer Science along with a myriad of professional certifications including: GIAC GSEC and GPEN\, AWS Certified DevOps Engineer Professional\, AWS Certified Solutions Architect Associate\, CEH\, JNCIS-FWV\, JNCIA-IDP\, and CCNA. He’s fluent in both English and Arabic and when not in front of a computer screen\, he is practicing Brazilian Jiu Jitsu\, which he describes as a form of martial arts that is all about solving technical problems. \n \n\n  \nEvent Questions and Policies \n\n\nRegistration Questions \nIf you have any registration questions about this event\, please contact us by completing the Registration Contact Form linked below. \nRegistration Questions \n  \n\n\n\n\nCPE Questions \nIf you have CPE questions after the event has concluded\, please contact us by completing the CPE contact form linked below. \nCPE Questions \n  \n\n\n\n\nCancellation and Refunds \nCancellation and refund for advance registrations is allowed if cancellations are submitted through the registration system by the date registration closes. Refunds vary depending on the date of cancellation and cost of the event. See ISACA GWDC Event Policies for details. \n\n\n\n\nComplaints \nThe GWDC welcomes your comments\, complaints\, suggestions\, questions\, and other feedback concerning our website information and services. \nAll complaints should be submitted through the Registration Contact Form. \n\n\n  \n  \nCPE Information \nEarn up to 4 Continuing Professional Education (CPE) credit in the area of Information Technology. The ISACA® Greater Washington\, D.C. Chapter is registered with the National Association of State Boards of Accountancy (NASBA) as a sponsor of continuing professional education on the National Registry of CPE Sponsors. State boards of accountancy have final authority on the acceptance of individual courses for CPE credit. Complaints regarding registered sponsors may be submitted to the National Registry of CPE Sponsors through its website: www.NASBARegistry.org \n  \nCPE Distribution and Evaluation Survey \nCPEs will be distributed via e-mail along with the event evaluation survey after the completion of the event. Attendees must be present for the full event to receive full CPE credit. \n  \nLearning Objective \nAfter attending this event\, attendees will learn about current and future trends in the IT Audit space. \n  \nCPE-Related Details \n\nPrerequisites: None\nAdvance Preparation: None\nProgram Knowledge Level: Basic\nDelivery Method:  Group Internet Based\nField of Study:  Information Technology – Technical
URL:https://isaca-gwdc.org/event/artificial-intelligence-conference/
LOCATION:Virtual Event
CATEGORIES:Conferences
ATTACH;FMTTYPE=image/png:https://isaca-gwdc.org/wp-content/uploads/2024/12/conference-ai-2025.png
ORGANIZER;CN="Avneet Sabharwal":MAILTO:programs@isaca-gwdc.org
END:VEVENT
BEGIN:VEVENT
DTSTART;TZID=America/New_York:20250116T083000
DTEND;TZID=America/New_York:20250116T123000
DTSTAMP:20250109T164216Z
CREATED:20241119T015248Z
LAST-MODIFIED:20250109T164216Z
UID:33210-1737016200-1737030600@isaca-gwdc.org
SUMMARY:IT Audit Conference
DESCRIPTION:The GWDC’s Annual IT Audit Conference is a must-attend virtual event for IT Auditor\, IT professionals\, and cybersecurity enthusiasts. Scheduled for January 16\, 2025\, from 8:30 am to 12:30 pm EST\, this highly anticipated conference provides a platform to explore cutting-edge topics in IT auditing and cybersecurity. Key sessions include strategies for preventing cloud incidents from escalating into breaches\, implementing robust security controls\, and addressing cloud misconfigurations. Attendees will gain valuable insights from industry experts\, ensuring they stay ahead in the rapidly evolving IT landscape. With the opportunity to earn up to 4 Continuing Professional Education (CPE) credits\, this event is an excellent investment in professional growth and expertise. \nWhether you are a seasoned IT auditor or new to the field\, this conference is tailored to meet diverse professional needs. Registration is affordably priced at $10 for GWDC members and $30 for non-members\, making it accessible to a wide audience. The convenience of a virtual format allows participants from across the globe to join without travel constraints. Don’t miss the chance to network with like-minded professionals\, engage with thought leaders\, and enhance your skill set. Registration closes on January 15\, 2025\, at 2:00 pm\, so secure your spot today and take a significant step toward advancing your IT audit capabilities. \nRegistration closes on January 15th @ 2pm. \nRegister Today! \n  \nConference Overview \n\nJanuary 16 \nThe conference will be held on January 16\, 2025 from \n8:30 am to 12:30 pm. \nAdd this event to your calendar using the Add to Calendar link at the bottom of the page. \n  \nVirtual Event \nThe workshop will be held using Zoom. \nPrior to the event\, participants must install the Zoom app on their respective devices. Participants using the web-based Zoom or calling via the phone may not be entitled to CPE credits. \n\n\nGWDC Member Fee – $10 \nThe fee for GWDC Members is $10 for the conference.\nThe fee for all other registrants is $30 for the conference. \nTo become a member and take advantage of the member rate for our events\, among other benefits\, join ISACA and select the Greater Washington D.C. Chapter as your local chapter. \n  \nEarn up to 4 CPEs \nAttendees can earn up to 4 CPEs for this event. \nParticipants must respond to all the poll questions via the Zoom polling feature or chat log in order to receive NASBA CPE credits. The GWDC will not be responsible for the participant’s inability to respond to the polls. \n\nShare this Event in Your Network \n\n	\n		\n	\n			\n			\n								\n										\n													\n														\n												Share on X\n					\n					\n									\n			\n		\n			\n			\n								\n										\n													\n														\n												Share on Linkedin\n					\n					\n									\n			\n		\n			\n			\n								\n										\n													\n														\n												Share on Facebook\n					\n					\n									\n			\n		\n			\n			\n								\n										\n													\n														\n												Share on Print\n					\n					\n									\n			\n		\n			\n			\n								\n										\n													\n												Share on Email\n					\n					\n									\n			\n		\n		\n\n	\n\n\n  \nSpeaker Insights Showcase \nThe GWDC Media Relations team works with Conference speakers to share insights into their IT journey as well as their topic for the conference in the “Speaker Insights Showcase” series. Below are the videos for three of this month’s speakers. \nYou can view the full Speaker Insights Showcase series on our YouTube channel. \n \n  \n\n \n  \n\n \n  \n\n\n\n  \n  \nAgenda \n \n\n08:30 AM – 09:30 AM \n\n\nPrevent Cloud Incidents from Becoming Cloud Breaches \nPresenter: Brandon Evans (On-Brand Technologies LLC) \nThe number of cloud security breaches in the headlines have been staggering lately. It seems like a week cannot go by without a massive amount of sensitive data being leaked from either AWS\, Azure\, or Google Cloud. \nOne example that would be funny if it were not so sad is the September 2023 incident where the Microsoft AI team leaked 38TB of sensitive data\, including employee workstation backups and 30\,000 internal Teams messages\, due to a misconfigured storage configuration. How is the industry failing to use the clouds properly\, let alone Microsoft\, the extremely mature company who created Azure in the first place? \nJoin Brandon as he shares his analysis on this trend. He will discuss the unique challenges of protecting the cloud\, why the cloud providers are unable to solve these problems alone\, why multicloud makes matters even more difficult\, and how your organization can take practical measures to mitigate the impact of cloud incidents. The presentation will include case studies of real breaches that were made much worse due to a lack of defense-in-depth. Learn how to prevent real attacks with controls that matter. \n\n \n\n09:30 AM – 10:30 AM \n\n\nMaking Controls Work for You \nPresenter: Valecia Stocchetti (Center for Internet Security) \nHave you ever been in the position of implementing and/or auditing against a set of controls? For one framework or multiple frameworks? It can become exhausting chasing down people for evidence\, fulfilling hundreds of evidence requests\, or worse\, falling behind and not being able to keep up with challenging deadlines. And that’s the key word in all of this…CONTROL. However\, in this talk\, we are going to discuss the context of not just any control\, but the CIS Critical Security Controls\, a set of prescriptive\, prioritized\, and simplified best practices that you can use to strengthen your cybersecurity posture. Through implementation of the Controls\, an organization is able to demonstrate a commitment to strengthening their cybersecurity posture\, but also working their way toward aligning with other frameworks in the world of security and compliance – frameworks such as NIST 800-53\, ISO 27001\, PCI DSS\, HIPAA\, and more. \nThere are two sets of challenges this talk will address and one has to do with frameworks. Any given organization may need to comply with one or more frameworks\, depending on the industry they are in. There’s no one “golden” approach to take when implementing these controls. One thing is for certain though\, less is more in this scenario. Most frameworks have overlap and therefore\, controls can be “mapped” from one framework to another to alleviate the pressure of assessing against each individual framework\, which can quickly add up to hundreds and hundreds of controls. To go one step further\, CIS helps alleviate this mapping process by providing users with mappings to over 25 security and compliance frameworks\, along with the tools that help to streamline the mapping process. \nThe second challenge has to do with tooling. During an assessment\, organizations may face challenges keeping information straight. This includes evidence\, the implementation status of a control\, who is responsible for a control\, and so on. Even with an external audit team\, internal tools are still needed for the work that is involved before the external audit. Additionally\, an organization may want to adopt a continuous compliance methodology\, where audits don’t just happen once a year\, but at various points throughout the year. A tool is needed to keep this information in one space. CIS has tools and resources available to help alleviate this burden\, through their CIS Controls Self-Assessment Tool (CSAT)\, which helps them track and prioritize their implementation of the CIS Controls. \nJoin us for this invigorating talk that will not just highlight the challenges\, but also offer solutions! \n\n \n\n10:30 AM – 11:30 AM \n\n\nUsing Cloud Security Posture Management (CSPM) Solutions to Mitigate Cloud Misconfigurations \nPresenter: Michael Ratemo (Cyber Security Simplified) \nThe rapid adoption of cloud technology by organizations has led to a shift towards both single and multi-cloud environments. Unfortunately\, this shift has also resulted in cloud misconfigurations\, which are one of the top risks associated in the cloud. Cloud misconfiguration refers to any errors or gaps in the security measures of a cloud environment. \nWe will begin by discussing the root causes of cloud misconfigurations. The primary cause is human error followed by poor governance. Additionally\, the lack of knowledge and skills in cloud technology is a key factor resulting in misconfigurations. Another challenge is system complexity\, as there are numerous cloud services with distinct implementations and nuances. \nWe will then review case studies of organizations that have suffered data breaches due to cloud misconfigurations\, such as Capital One in 2019\, eBay in 2014\, and World Wrestling Entertainment (WWE) in 2017. These case studies will emphasize the importance of proper cloud security controls and measures. \nWe will then walk through built-in tools provided by AWS\, Microsoft Azure\, and Google Cloud\, that cyber professionals can leverage to mitigate security risks in the cloud. These tools are also known as Cloud Security Posture Management (CSPM) solutions. \nCloud Security Posture Management tools are automated solutions designed to identify misconfiguration issues and compliance risks in the cloud so that they can be remediated\, reducing the risk of successful breaches. We will explore AWS Security Hub\, Microsoft Defender for Cloud\, and Google Security Command Center\, and review how each tool can be used to gain visibility into the current security posture of each respective cloud. Furthermore\, we will emphasize how these tools can be applied to determine alignment with relevant regulatory compliance standards and industry-standard benchmarks\, as well as identify threats and potential security weaknesses. \nThe Key Takeaways from this session are: \n\nMost cloud breaches are due to misconfigurations or human errors.\nDo not rely on your Cloud Service Provider to secure your data (Understand the Shared Responsibility model).\nYou cannot protect what you do not have visibility into (CSPM solutions can help).\nCloud security should begin with implementation of Cloud Governance.\n\n\n \n\n11:30 AM – 12:30 AM \n\n\n“I ran a data science livestream every day for 100 days. Here’s what I learned about the future of data science in your organization” \nPresenter: Dennis Salguerna (Data Science With Dennis) \nI have been fortunate to build a global community of data science enthusiasts and have more than 15\,000 followers on social media. I also run what I believe to be the world’s first daily data science stream. In this presentation\, I want to discuss the meta-themes that have emerged during this period. There are fundamental risks that exist in how data science is currently executed; people understand the How (development tools\, processing power\, etc.) but not the Why or When (methodology). There is also an emerging risk in the level of creativity that will be required in future data science development work. Finally\, I will present a framework that your organization can use to address these risks and be better prepared for the changing landscape of data science. \n\n  \nPresenters \n \n\n \n\n\nBrandon Evans\nOwner and InfoSec Consultant @ On-Brand Technologies LLC \nBrandon is the owner and an InfoSec Consultant at On-Brand Technologies LLC\, a consultancy helping organizations secure their applications and other workloads in multi cloud environments\, specializing in AWS\, Azure\, and Google Cloud. Prior to starting his consultancy\, Brandon led the secure development training program at Zoom Video Communications. He began his career as a Software Engineer\, where he worked on both the core product of a startup\, later acquired by a Fortune 500 organization\, and on various products spanning a multi-billion dollar enterprise. \nBrandon is lead author for SANS Institute course SEC510: Cloud Security Controls and Mitigations a contributor to SEC540: Cloud Security and DevSecOps Automation\, host of Cloud Ace podcast\, Season 1\, an analyst for the SANS Multicloud Survey\, a multi-year RSA Conference presenter\, and participates in bug bounties\, such as when he found a critical vulnerability in Microsoft Defender for Cloud. \n \n\n \n\n \n\n\nValecia Stocchetti\nSenior Cybersecurity Engineer @ the Center for Internet Security\, Inc. (CIS®)\nGCFE\, GCFA\, GSEC \nValecia Stocchetti is a Senior Cybersecurity Engineer at the Center for Internet Security\, Inc. (CIS®). As a member of the CIS Critical Security Controls team\, she has led multiple projects including: the CIS Cost of Cyber Defense for IG1\, CIS Community Defense Model (CDM) v2.0\, CIS Risk Assessment Method (CIS RAM) v2.1\, as well as multiple Living off the Land (LotL) guides. Stocchetti was also one of the principal authors of the Blueprint for Ransomware Defense. \nPrior to joining the CIS Controls team\, she led the Cyber Incident Response Team (CIRT) at the Multi-State and Elections Infrastructure Information Sharing and Analysis Centers (MS-ISAC® and EI-ISAC®). While managing CIRT\, Stocchetti spearheaded multiple forensic investigations and incident response engagements for the MS-ISAC and EI-ISAC’s state\, local\, tribal\, and territorial (SLTT) community. Stocchetti was also the Information Security Audit Manager at CIS where she evaluated and managed the control implementation within CIS and measured compliance to various standards and best practices. Stocchetti came to CIS from the eCommerce field where she worked complex financial fraud cases. She holds multiple certifications\, including GIAC Certified Forensic Examiner (GCFE)\, GIAC Certified Forensic Analyst (GCFA)\, and GIAC Security Essentials Certification (GSEC). \nWhile she enjoys all things InfoSec\, Stocchetti particularly finds the cybercrime and espionage fields fascinating\, which is what prompted her career choice. Stocchetti earned her Bachelor of Science degree in Digital Forensics from the University at Albany\, State University of New York\, as well as her Master of Science degree in Information Security at Champlain College. \n \n\n \n\n \n\n\nMichael Ratemo \nMichael Ratemo is a Principal Security Consultant at Cyber Security Simplified\, a boutique security firm that provides Cloud Security and Cyber Security solutions. He speaks security in a language businesses can understand and has built a career advising organizations on effective security strategies. \nMichael is a thought leader in the field of Cyber Security\, and the author of the LinkedIn Learning Courses; “Cloud Security and Audit Foundations in AWS\, Microsoft Azure\, and Google Cloud\,” and “Building and Auditing a Cyber Security Program.” In addition\, Michael is the co-author of the “Cloud Auditing Best Practices” book. \nFinally\, Michael is a speaker and trainer at major industry events including RSA Conference\, Cloud Security Alliance\, and Stronger Conference. \nMichael gives back to the community by providing mentorship and guidance to future security practitioners. \n \n\n \n\n \n\n\nDennis Salguero \nPrincipal @ Data Science With Dennis \nDennis Salguero has been a technology professional for more than 20 years. He has worked for companies such as Citi\, IBM\, Ticketmaster\, and Caesars Entertainment. He is also a Top Data Science Voice on LinkedIn and has more than 15\,000 followers on social media. \nIn his free time\, he enjoys playing poker\, golf\, and traveling the world. He has visited 6 continents and only Antarctica remains as the final continent to visit. \n \n\n  \nEvent Questions and Policies \n\n\nRegistration Questions \nIf you have any registration questions about this event\, please contact us by completing the Registration Contact Form linked below. \nRegistration Questions \n  \n\n\n\n\nCPE Questions \nIf you have CPE questions after the event has concluded\, please contact us by completing the CPE contact form linked below. \nCPE Questions \n  \n\n\n\n\nCancellation and Refunds \nCancellation and refund for advance registrations is allowed if cancellations are submitted through the registration system by the date registration closes. Refunds vary depending on the date of cancellation and cost of the event. See ISACA GWDC Event Policies for details. \n\n\n\n\nComplaints \nThe GWDC welcomes your comments\, complaints\, suggestions\, questions\, and other feedback concerning our website information and services. \nAll complaints should be submitted through the Registration Contact Form. \n\n\n  \n  \nCPE Information \nEarn up to 4 Continuing Professional Education (CPE) credit in the area of Information Technology. The ISACA® Greater Washington\, D.C. Chapter is registered with the National Association of State Boards of Accountancy (NASBA) as a sponsor of continuing professional education on the National Registry of CPE Sponsors. State boards of accountancy have final authority on the acceptance of individual courses for CPE credit. Complaints regarding registered sponsors may be submitted to the National Registry of CPE Sponsors through its website: www.NASBARegistry.org \n  \nCPE Distribution and Evaluation Survey \nCPEs will be distributed via e-mail along with the event evaluation survey after the completion of the event. Attendees must be present for the full event to receive full CPE credit. \n  \nLearning Objective \nAfter attending this event\, attendees will learn about current and future trends in the IT Audit space. \n  \nCPE-Related Details \n\nPrerequisites: None\nAdvance Preparation: None\nProgram Knowledge Level: Basic\nDelivery Method:  Group Internet Based\nField of Study:  Information Technology – Technical
URL:https://isaca-gwdc.org/event/it-audit-conference-2025/
LOCATION:Virtual Event
CATEGORIES:Conferences
ATTACH;FMTTYPE=image/png:https://isaca-gwdc.org/wp-content/uploads/2024/11/conference_itaudit.png
ORGANIZER;CN="Avneet Sabharwal":MAILTO:programs@isaca-gwdc.org
END:VEVENT
BEGIN:VEVENT
DTSTART;TZID=America/New_York:20241205T083000
DTEND;TZID=America/New_York:20241205T123000
DTSTAMP:20241204T184000Z
CREATED:20240817T194849Z
LAST-MODIFIED:20241204T184000Z
UID:32663-1733387400-1733401800@isaca-gwdc.org
SUMMARY:Security and Risk Insights Conference
DESCRIPTION:Share on X\n					\n					\n									\n			\n		\n			\n			\n								\n										\n													\n														\n												Share on Linkedin\n					\n					\n									\n			\n		\n			\n			\n								\n										\n													\n														\n												Share on Facebook\n					\n					\n									\n			\n		\n			\n			\n								\n										\n													\n														\n												Share on Print\n					\n					\n									\n			\n		\n			\n			\n								\n										\n													\n												Share on Email\n					\n					\n									\n			\n		\n		\n\n	\n\n\nNavigating the Future: A CISO’s Perspective on 2024 Security and Risk Priorities \nThe ISACA Greater Washington D.C. Chapter (GWDC) invites you to our Annual Security and Risk Insights Conference—a must-attend event for cybersecurity professionals and business leaders. This year’s seminar offers a comprehensive review of the most critical cybersecurity and risk trends from 2024 and provides actionable insights on where to focus your budget and training efforts for 2025. Whether you’re a CISO\, IT manager\, or business executive\, this conference equips you with the knowledge you need to prepare for the year ahead. \nWhy Attend? \n\n	In-Depth Analysis of 2024 Trends: Understand the key developments that shaped the cybersecurity landscape in 2024.\n	Future-Focused Strategies: Learn about emerging risks and opportunities in 2025\, helping you make informed decisions about budget allocations and training priorities.\n	Expert Guidance: Hear from industry leaders like Ira Winkler\, Greg Carpenter\, and Gary Hayslip on how to navigate the evolving security environment.\n	Practical Takeaways: Gain actionable insights that you can apply immediately to strengthen your organization’s security posture.\n\n \nRegistration closes on December 4\, 2024 @ 2pm. \nRegister Today! \n  \nAgenda \n\n\n08:30 AM – 09:30 AM \n\n\nYour Budget is a Horse’s A$$ \nPresenter: Ira Winkler (CYE Security) \nExplore the historical influence of horse-drawn carts on railcar dimensions and how it relates to rigid cybersecurity budgeting. Join this session to learn how to apply machine learning and other mathematical concepts to justify budget allocation\, optimize risk\, and design effective cybersecurity programs for limited resources. \n\n\n\n09:30 AM – 10:30 AM \n\n\nTeaching Information Warfare: Current and Future Adversarial Philosophy and Strategy by Greg Carpenter \nPresenter: Greg Carpenter (KnowledgeBridge) \nThis presentation provides a concise overview of the philosophy and teaching strategies employed in academic and government institutions to educate adversaries on information warfare techniques and procedures. The information has been collected from various sources\, including the Russian Ministry of Defense and the Peoples Liberation Army National Defense University. Most information has been collected from sources which are not publicly available. Participants will have a better understanding of what our adversaries’ strategic goals are and how to best identify and defend against them. \n\n\n\n10:30 AM – 11:30 AM \n\n\nGenAI & Security – Championing the use of GenAI within the Security Program \nPresenter: Gary Hayslip (SoftBank Investment Advisers) \nAs GenAI use becomes the norm\, what approach should CISOs take to effectively deploy these technologies and build resilient security programs? \n\n\n\n11:30 AM – 12:30 AM \n\n\nThe Growing Threat of Supply Chain Attacks \nPresenter: Erika Carrara (The Greenbrier Companies) \nSuccess: No longer accepting the unacceptable risks we inherit from our 3rd parties. Implementing stricter vendor risk management practices and improved software supply chain security\, reducing vulnerabilities introduced through third-party software. Challenging assumptions embedded in long accepted best practices. \nChallenge: Sophisticated supply chain attacks\, like SolarWinds and the CrowdStrike debacle\, exposed the fragility of software supply chains and the potential for widespread damage. These incidents underscored the challenge of securing complex systems\, where a single compromised component can infiltrate numerous others. The CrowdStrike incident prompted a reevaluation of allowing blanketed automated security updates\, revealing potential vulnerabilities introduced through this practice. These events highlight the need for a multi-layered security approach\, including rigorous vendor risk management\, continuous monitoring\, and robust incident response plans. \nView Erika’s Speaker Showcase for this Conference on the GWDC YouTube channel \n\n  \nPresenters \n\n\n \n\n\nIra Winkler\nField CISO @ CYE Security\nCISSP \nIra Winkler\, CISSP is the Field CISO for CYE Security\, former Chief Security Architect at Walmart\, and author of You Can Stop Stupid\, Security Awareness for Dummies\, and Advanced Persistent Security. He is considered one of the world’s most influential security professionals\, and has been named a “Modern Day James Bond” by the media. He did this by performing espionage simulations\, where he physically and technically “broke into” some of the largest companies in the World and investigating crimes against them\, and telling them how to cost effectively protect their information and computer infrastructure. He continues to perform these espionage simulations\, as well as assisting organizations in developing cost effective security programs. Ira also won the Hall of Fame award from the Information Systems Security Association\, as well as several other prestigious industry awards. CSO Magazine named Ira a CSO Compass Award winner as The Awareness Crusader. He was named 2021 Top Cybersecurity Leader by Security Magazine\, and most recently 2022 Cybersecurity Champion of the Year by the Cybersecurity Association of Maryland. \nIra is also author of the riveting\, entertaining\, and educational books\, Advanced Persistent Security\, Spies Among Us and Zen and the Art of Information Security. He also writes for a variety of online sites\, including RSA Conference\, DarkReading and ComputerWorld\, and for several other industry publications. \nMr. Winkler has been a keynote speaker at almost every major information security related event\, on 6 continents\, and has keynoted events in many diverse industries. He is frequently ranked among\, if not the\, top speakers at the events. \nMr. Winkler began his career at the National Security Agency\, where he served as an Intelligence and Computer Systems Analyst. He moved onto support other US and overseas government military and intelligence agencies. After leaving government service\, he went on to serve as President of the Internet Security Advisors Group\, Chief Security Strategist at HP Consulting\, and Director of Technology of the National Computer Security Association. He was also on the Graduate and Undergraduate faculties of the Johns Hopkins University and the University of Maryland. Mr. Winkler was previously elected the International President of the Information Systems Security Association\, which is a 10\,000+ member professional association. \nMr. Winkler has also written the book Corporate Espionage\, which has been described as the bible of the Information Security field\, and the bestselling Through the Eyes of the Enemy. Both books address the threats that companies face protecting their information. He has also written hundreds of professional and trade articles. He has been featured and frequently appears on TV on every continent. He has also been featured in magazines and newspapers including Forbes\, USA Today\, Wall Street Journal\, San Francisco Chronicle\, Washington Post\, Planet Internet\, and Business 2.0. \n \n\n\n\n \n\n\nGreg Carpenter\nChief Security Officer @ KnowledgeBridge International\nCISM\, Lean Six-Sigma Black Belt\, and ISO-9000 lead auditor \nDr. Gregory Carpenter serves as the Chief Security Officer at KnowledgeBridge International\, holds the title of Fellow of the Royal Society for the Arts in London\, and was named the National Security Agency’s Operations Officer of the Year. He is on the Board of Directors for ATNA Systems\, an advisor for RedSeer Security\, a Senior Advisor for ARIC\, Inc.\, and a Special Operations Medical Association member. Previously\, Dr. Carpenter has served on the International Board of Advisors for the Mackenzie Institute and as an advisor for EC-Council University\, Prior to his current role\, Dr. Carpenter held various senior military and civilian positions\, including Vice President for Cyber Operations\, Chief of Security Testing\, Chief Operations Officer\, Counterintelligence Division Chief\, Chief of Special Space Operations\, and Functional Team Lead for Electronic Warfare. \nDr. Carpenter is a co-author of Reverse Deception: Organized Cyber Threat Counterexploitation\, he is an international keynote speaker on adversarial psychology\, techniques\, and deception. He has worked projects with the UN\, INTERPOL\, and several domestic and international law enforcement and intelligence agencies. \nHe is a retired U.S. Army officer who served 27 years. He holds a Bachelor of Science\, a Master of Science\, and a Doctorate in Public Health. His professional qualifications include Certified Information Security Manager\, Lean Six-Sigma Black Belt\, and ISO-9000 lead auditor. \n \n\n\n\n \n\n\nGary Hayslip\nGlobal CISO @ Softbank Investment Advisors \nWith over 20 years of IT\, cybersecurity\, and risk management experience\, Gary Hayslip has established a reputation as a skilled communicator\, author\, board director\, and keynote speaker. Currently\, as Global CISO\, he advises Softbank Investment Advisers (SBIA) executive leadership on protecting critical information resources and overseeing enterprise cybersecurity strategy. Hayslip co-authored the CISO Desk Reference Guide: A Practical Guide for CISOs\, volumes 1 and 2\, which enable CISOs to expand their business and leadership expertise. Hayslip’s previous executive roles include multiple CISO\, CIO\, Deputy Director of IT and Chief Privacy Officer for the US Navy (active duty)\, the US Navy (Civil Service)\, the City of San Diego\, California\, and Webroot Software. \n \n\n\n\n  \n\n\nErika Carrara\nVP\, Chief Technology & Security Officer @ The Greenbrier Companies \nErika Carrara is a highly strategic and visible executive at Greenbrier Companies\, serving as the Chief Technology & Security Officer. With a career focus on being a security-minded technologist\, Erika is a business enabler who thrives on innovation and solving complex problems. Her deep understanding of both security and infrastructure\, coupled with her alignment with the SRE methodology\, allows her to create a more reliable\, secure\, and efficient IT environment. \nErika’s leadership philosophy centers on the power of thought\, emphasizing that we become what we think about. She believes in continuous learning\, serving others\, and embracing individuality. Her foundational principles include defining one’s desires\, setting clear goals\, and viewing failure as a learning opportunity. As a leader\, Erika is committed to empowering her team\, fostering collaboration\, and inspiring growth. She expects her team to embrace challenges\, think critically\, communicate openly\, and strive for excellence. \n \n\n  \nEvent Questions and Policies \nRegistration Questions \nIf you have any registration questions about this event\, please contact the chapter using the Registration Contact Form. \nIf you have CPE questions after the event has concluded\, please contact the chapter using the CPE Contact Form. \n  \nCancellation and Refund Policy \nCancellation and refund for advance registrations is allowed if cancellations are submitted through the registration system. Refunds vary depending on the date of cancellation. See ISACA GWDC Event Policies for details. \nIf ISACA GWDC cancels the event\, all registrants will be notified as soon as possible through email at the email address provided during registration. Full refunds will be provided. \n  \nComplaint Policy \nThe GWDC welcomes your comments\, complaints\, suggestions\, questions\, and other feedback concerning our website information and services. All complaints should be submitted through the Registration Contact Form. \n  \nCPE Information \nEarn up to 4 Continuing Professional Education (CPE) credit in the area of Information Technology. The ISACA® Greater Washington\, D.C. Chapter is registered with the National Association of State Boards of Accountancy (NASBA) as a sponsor of continuing professional education on the National Registry of CPE Sponsors. State boards of accountancy have final authority on the acceptance of individual courses for CPE credit. Complaints regarding registered sponsors may be submitted to the National Registry of CPE Sponsors through its website: www.NASBARegistry.org \n  \nCPE Distribution and Evaluation Survey \nCPEs will be distributed via e-mail along with the event evaluation survey after the completion of the event. Attendees must be present for the full event to receive full CPE credit. \n  \nLearning Objective \nAfter attending this event\, attendees will learn about current and future trends in the cybersecurity and risk governance space. \n  \nCPE-Related Details \n\n	Prerequisites: None\n	Advance Preparation: None\n	Program Knowledge Level: Basic\n	Delivery Method:  Group Internet Based\n	Field of Study:  Information Technology – Technical
URL:https://isaca-gwdc.org/event/security-and-risk-insights-conference-2024/
LOCATION:Virtual Event
CATEGORIES:Conferences
ATTACH;FMTTYPE=image/png:https://isaca-gwdc.org/wp-content/uploads/2024/08/conference-security-insights-2024.png
ORGANIZER;CN="Avneet Sabharwal":MAILTO:programs@isaca-gwdc.org
END:VEVENT
BEGIN:VEVENT
DTSTART;TZID=America/New_York:20241024T083000
DTEND;TZID=America/New_York:20241024T123000
DTSTAMP:20240918T195947Z
CREATED:20240817T190739Z
LAST-MODIFIED:20240918T195947Z
UID:32655-1729758600-1729773000@isaca-gwdc.org
SUMMARY:Cybersecurity Conference
DESCRIPTION:Share on X\n					\n					\n									\n			\n		\n			\n			\n								\n										\n													\n														\n												Share on Linkedin\n					\n					\n									\n			\n		\n			\n			\n								\n										\n													\n														\n												Share on Facebook\n					\n					\n									\n			\n		\n			\n			\n								\n										\n													\n														\n												Share on Print\n					\n					\n									\n			\n		\n			\n			\n								\n										\n													\n												Share on Email\n					\n					\n									\n			\n		\n		\n\n	\n\n\nThe GWDC is proud to host its annual cybersecurity conference. This virtual conference is part of our monthly conference series. \nBusiness leaders and managers\, executives\, technologists\, professionals\, and students\, interested in staying current in the field of cybersecurity should attend this conference. \n \nRegistration closes on October 23\, 2024 @ 2pm. \nRegister Today! \n  \nAgenda \n\n\n08:30 AM – 09:30 AM \n\n\nSecuring the Road Ahead: NIST Cybersecurity Framework 2.0 \nPresenter: Cherilyn Pascoe (NIST) \nBack in February\, the National Institute of Standards and Technology (NIST) published the Cybersecurity Framework (CSF) 2.0—the first major update to its landmark cybersecurity guidance since 2014. Join NIST’s National Cybersecurity Center of Excellence (NCCoE) Director and CSF Lead Cherilyn Pascoe for this presentation to learn about the key updates to CSF 2.0\, including a new suite of implementation tools and resources to address specific organizational needs\, and how you can engage with NIST. \n\n\n\n09:30 AM – 10:30 AM \n\n\nIgnore Cybersecurity in Your Third-Party Ecosystem at Your Own Peril \nPresenter: Jeffrey Wheatman (Black Kite) \nHistorically\, and even as recently as less than a decade ago\, third-party risk management was about this: if legal and finance said OK\, we were good to go. But no more! What would happen to your organization if a critical partner got slammed with the latest ransomware and were down for a week\, a month\, or forever. What would be the impact on your company? Real time\, continuous visibility into cybersecurity posture within your ecosystem is no longer a “nice to have”. In this presentation we will explore: \n\n	Are questionnaires enough? (SPOILER ALERT: No)\n	How can we shift focus to resilience in our full ecosystem\n	Best practices in integrating cybersecurity risk into the process of managing your partners\n\n\n\n\n10:30 AM – 11:30 AM \n\n\nBack to Basics: The Indispensable Role of Cybersecurity Fundamentals in a Complex World \nPresenter: Rich Greene (SANS Institute) \nIn today’s fast-paced digital landscape\, it’s easy to be swept up in the allure of cutting-edge technologies and advanced security measures. However\, amidst the rush towards innovation\, the core principles of cybersecurity—the fundamentals—often get overlooked. In this engaging 45-minute talk\, Rich Greene\, will explore why these foundational elements are more critical than ever. Drawing on real-world examples and personal experiences\, Rich will illustrate how neglecting the basics can lead to significant vulnerabilities and how a solid grasp of these principles can fortify an organization’s defense strategy. Attendees will leave with a renewed appreciation for the essential building blocks of cybersecurity and practical insights on how to integrate these fundamentals into their security practices. \n\n\n\n11:30 AM – 12:30 AM \n\n\nNavigating the Cyber Frontier: 2025 Threats and Strategies Protect Your Workforce\, Assets & IP \nPresenter: Juman Doleh-Alomary (BorgWarner) \nIn an era where cyber threats are evolving at an unprecedented pace\, organizations must stay ahead of the curve to safeguard their workforce\, assets\, and intellectual property (IP). This presentation delves into the anticipated cyber threats of 2025\, offering a comprehensive overview of emerging risks and the strategies necessary to mitigate them. \nKey topics include: \n\n	Emerging Cyber Threats: An analysis of the latest trends in cyber-attacks\, including advanced persistent threats (APTs)\, ransomware\, and insider threats.\n	Protecting Your Workforce: Strategies to enhance employee awareness and training\, ensuring that your first line of defense is well-prepared.\n	Safeguarding Assets and IP: Best practices for securing critical assets and intellectual property\, from robust encryption methods to advanced access controls.\n	Innovative Defense Mechanisms: Exploration of cutting-edge technologies and methodologies\, such as AI-driven security solutions and zero-trust architectures.\n	Case Studies and Lessons Learned: Real-world examples of cyber incidents and the lessons they offer for future preparedness.\n\nJoin us to gain valuable insights and actionable strategies to navigate the complex cyber landscape of 2025\, ensuring your organization remains resilient against the ever-evolving threats. \n\n  \nPresenters \n\n\n \n\n\nCherilyn Pascoe\nDirector\, National Cybersecurity Center of Excellence (NCCoE) @ NIST \nCherilyn Pascoe is the Director of the NIST National Cybersecurity Center of Excellence (NCCoE). She provides strategic direction and technical leadership for the NCCoE\, aligns the NCCoE’s work with the industry\, government\, and NIST priorities\, and builds relationships with key stakeholders. Prior to her role as Director of the NCCoE she served as the Senior Technology Policy Advisor\, advising NIST leadership on technology policy and strategy\, including cybersecurity\, privacy\, and artificial intelligence. She also led the NIST Cybersecurity Framework program and was a team member of the NIST AI Risk Management Framework. Prior to joining NIST in 2021\, she served more than a decade in staff leadership roles on the US Senate Committee on Commerce\, Science\, and Transportation. Most recently\, she served as Deputy Policy Director managing the Committee’s Space and Science Subcommittee\, which has jurisdiction over science\, technology\, standards\, and civil space policy. \n \n\n\n\n \n\n\nJeffrey Wheatman\nSVP\, Cyber Risk Strategist @ Black Kite \nA strategic thought leader with extensive expertise in security and cyber risk management\, Jeffrey Wheatman is regarded as a foremost expert in guiding public sector clients and Fortune 500 companies in connection with their cybersecurity and risk management programs. Jeffrey’s history of working with clients to plan\, grow\, and transform their cyber risk management programs has been instrumental in ensuring organizations’ continued viability and health as they define short- and long-term expansion plans. Under Jeffrey’s guidance\, board and C-level leaders are fortified with the best practice solutions to realize exceptional performance outcomes. \nIn his current capacity as SVP\, Cyber Risk Strategist at Black Kite\, Jeffrey has been tasked with raising awareness of the enterprise-wide risk impacts of third party Cyber risk\, both in the digital and traditional supply chain and supporting the strategic vision of the executive leadership team and investors. \nPrior to joining Black Kite\, Jeffrey acted as a VP\, Advisor with Gartner\, the global strategic advisory firm\, where he worked with clients to build and improve their security programs\, assess risk\, focus on reporting on program status\, metrics\, performance management\, stakeholder engagement\, executive communication\, and bridging the connection between technology and security risk. Jeffrey guided leaders in selecting frameworks to run cyber programs in compliance with regulatory requirements and expectations of auditors and partners. \n \n\n\n\n \n\n\nRich Greene\nSenior Solutions Engineer @ SANS Institute\nGFACT\, GISF\, GSEC\, GCIA\, GCIH\, GPYC\, GWAPT\, GMOB\, GPEN\, GSTRT\, SSAP\, GDSA\, GICSP\, GRID\, CISSP \nPresently\, Rich wears many hats\, serving as a Senior Solutions Engineer at the prestigious SANS Institute while also steering the ship at SITH2\, LLC\, where he is the owner and operator. At SANS\, he harnesses his extensive 20-year background in cybersecurity\, intelligence\, and special operations to craft tailored solutions and deliver comprehensive training to clients spanning diverse industries and sectors. Rich’s expertise is underscored by an impressive arsenal of certifications\, boasting 14 GIAC certifications alongside a CISSP credential. His proficiency spans a wide spectrum of cybersecurity domains\, including incident response\, mobile device security\, information security fundamentals\, and penetration testing. \nBeyond his professional endeavors\, Rich is a passionate advocate for mentorship and collaboration\, steadfastly committed to imparting his knowledge and skills through captivating presentations\, interactive workshops\, and insightful reports. His commitment to excellence is evident in his track record of consistently exceeding target goals and client expectations\, consistently delivering exceptional results. \nDriven by an unwavering dedication to staying ahead of the curve in the face of evolving cyber threats\, Rich is perpetually engaged in the pursuit of knowledge\, embracing new technologies\, tools\, and methodologies with fervor. His impressive array of certifications which include active GFACT\, GISF\, GSEC\, GCIA\, GCIH\, GPYC\, GWAPT\, GMOB\, GPEN\, GSTRT\, SSAP\, GDSA\, GICSP\, GRID and CISSP–further solidifies his standing as a preeminent cybersecurity expert\, revered within the field for his unparalleled expertise and unwavering commitment to excellence. \n \n\n\n\n \n\n\nJuman Doleh-Alomary\nChief Information Security Officer @ BorgWarner\nCISA\, CISM\, CRISC\, CDPSE\, ISO 27001 \nJuman Doleh-Alomary is BorgWarner’s Chief Information Security Officer and an active volunteer board member of the ISACA Detroit Chapter.  With over 15 years of experience in security\, audit\, investigation\, compliance\, and privacy policy/standards\, Juman most recently held the position of Director of Cybersecurity GRC at Little Caesar’s Enterprises serving the Ilitch holdings portfolio of companies. Her prior positions include Director of IT Audit at Wayne State University and a significant tenure in IT and Risk Management at Ford Motor Company. A leader within the ISACA community\, Juman has held various roles\, including past president and\, notably\, chair of the IIA/ISACA Spring Conference\, which achieved a record attendance. She is active volunteer with Michigan Council of Women in Technology (MCWT)\, Women Security Alliance (WomSA)\, and Women in Cyber (WiCys) Michigan.  An alumnus of the University of Michigan\, she holds both a bachelor’s and a master’s degree\, complemented by an impressive suite of certifications: CISA\, CISM\, CRISC\, CDPSE\, and ISO 27001. \n \n\n  \nVirtual Meeting Information \n\n	This event will be presented through Zoom.\n	Prior to the event\, participants must install the Zoom app on their respective devices or use the web-based Zoom. Calling via the phone may not be entitled to CPE credits.\n	Participants must respond to all the poll questions via the Zoom polling feature or chat log in order to receive NASBA CPE credits.\n	The ISACA Greater Washington\, D.C. Chapter will not be responsible for the participant’s inability to respond to the polls.\n\n  \nEvent Questions and Policies \nRegistration Questions \nIf you have any registration questions about this event\, please contact the chapter using the Registration Contact Form. \nIf you have CPE questions after the event has concluded\, please contact the chapter using the CPE Contact Form. \n  \nCancellation and Refund Policy \nCancellation and refund for advance registrations is allowed if cancellations are submitted through the registration system. Refunds vary depending on the date of cancellation. See ISACA GWDC Event Policies for details. \nIf ISACA GWDC cancels the event\, all registrants will be notified as soon as possible through email at the email address provided during registration. Full refunds will be provided. \n  \nComplaint Policy \nThe GWDC welcomes your comments\, complaints\, suggestions\, questions\, and other feedback concerning our website information and services. All complaints should be submitted through the Registration Contact Form. \n  \nCPE Information \nEarn up to 4 Continuing Professional Education (CPE) credit in the area of Information Technology. The ISACA® Greater Washington\, D.C. Chapter is registered with the National Association of State Boards of Accountancy (NASBA) as a sponsor of continuing professional education on the National Registry of CPE Sponsors. State boards of accountancy have final authority on the acceptance of individual courses for CPE credit. Complaints regarding registered sponsors may be submitted to the National Registry of CPE Sponsors through its website: www.NASBARegistry.org \n  \nCPE Distribution and Evaluation Survey \nCPEs will be distributed via e-mail along with the event evaluation survey after the completion of the event. Attendees must be present for the full event to receive full CPE credit. \n  \nLearning Objective \nAfter attending this event\, attendees will learn about recent topics in the cybersecurity space. \n  \nCPE-Related Details \n\n	Prerequisites: None\n	Advance Preparation: None\n	Program Knowledge Level: Basic\n	Delivery Method:  Group Internet Based\n	Field of Study:  Information Technology – Technical
URL:https://isaca-gwdc.org/event/cybersecurity-conference-2024/
LOCATION:Virtual Event
CATEGORIES:Conferences
ATTACH;FMTTYPE=image/png:https://isaca-gwdc.org/wp-content/uploads/2024/08/conference_cybersecurity.png
ORGANIZER;CN="Avneet Sabharwal":MAILTO:programs@isaca-gwdc.org
END:VEVENT
BEGIN:VEVENT
DTSTART;TZID=America/New_York:20240926T083000
DTEND;TZID=America/New_York:20240926T123000
DTSTAMP:20240918T194444Z
CREATED:20240814T162056Z
LAST-MODIFIED:20240918T194444Z
UID:32598-1727339400-1727353800@isaca-gwdc.org
SUMMARY:Cloud Security Conference
DESCRIPTION:Share on X\n					\n					\n									\n			\n		\n			\n			\n								\n										\n													\n														\n												Share on Linkedin\n					\n					\n									\n			\n		\n			\n			\n								\n										\n													\n														\n												Share on Facebook\n					\n					\n									\n			\n		\n			\n			\n								\n										\n													\n														\n												Share on Print\n					\n					\n									\n			\n		\n			\n			\n								\n										\n													\n												Share on Email\n					\n					\n									\n			\n		\n		\n\n	\n\n\nIn a world where over 80% of organizational resources are now hosted in the cloud and more than 90% of internet traffic is API-based\, understanding and mitigating cybersecurity risks has never been more crucial. This virtual conference is tailored for cybersecurity professionals\, auditors\, and IT leaders who need to stay ahead of evolving threats and ensure robust security for their cloud environments. \nJoin us for an enlightening day of expert insights\, practical tips\, and actionable strategies that will empower you to enhance your cloud security posture. Our lineup of distinguished speakers will guide you through the complexities of continuous compliance\, API security\, and the latest cloud security trends. \nIT professionals\, IT advisory or audit professionals\, business executives\, students or professionals interested in learning more about cloud security should attend this event. \n \nRegistration closes on September 25\, 2024 @ 2 pm.  \nRegister Today! \n  \nAgenda \n\n\n08:30 AM – 09:30 AM \n\n\nFire Side Chat: Clear the Clouds: Threats and Risk Mitigation on Cloud Computing \nPresenters: Jose Torres (ACFE DC\, Guidehouse)\, Prem Mishra\, and David Hinchman (GAO) \nLearning Objectives for this session: \n\n	Recognize challenges organizations face in implementing cloud security practices and recommendations to remediate their risks \n	Understand leading practices and standards for effective and efficient cloud security. \n	Learn the importance of people\, process\, and technology in having a secure cloud environment.\n\n\n\n\n09:30 AM – 10:30 AM \n\n\nContinuous Compliance (cATO) with ML and OSCAL \nPresenter: Valinder Mangat (DRTConfidence) \nAchieving continuous compliance (cATO) requires integration with development teams\, security teams\, security tools\, authorizing officials\, and DevOps platforms. A ‘common data fabric’ is necessary to enable standardized information exchange and automate analysis. OSCAL is the data fabric that allows for standardized data exchange across all security operations and sets the foundation for achieving a continuous compliance posture. Learn how security teams can transition to a robust cATO compliance framework. \n\n\n\n10:30 AM – 11:30 AM \n\n\nProtecting Your Apps: API Security from Development to Deployment \nPresenter: Dan Barahona (APIsec University) \nAPIs are critical in modern applications but are increasingly targeted by cyberattacks. We will explore the key vulnerabilities\, including authorization\, authentication\, data exposure and business logic flaws – providing practical techniques to mitigate these risks. Attendees will learn the importance and approaches to shift-left API security with continuous\, comprehensive and automated testing. \nThrough real-world case studies\, the session highlights the impact of API breaches and offers preventive measures. We will discuss secure deployment strategies\, continuous monitoring\, and ensuring compliance with regulations like GDPR and PCI DSS. This presentation delivers actionable insights for developers to fortify their APIs against evolving threats\, ensuring robust security from development to deployment. \n\n\n\n11:30 AM – 12:30 AM \n\n\nFive Key Cloud Security Trends and Tips \nPresenter: Frank Kim (SANS) \nLearn about the top five trends that are shaping cloud security adoption: identity\, architecture\, automation\, assessment\, and detection. Hear about high profile cloud security breaches and walk away with tips and techniques for responding to these trends including free and open source tools as well as cloud provider specific services you can use to build your security capabilities. \n\n  \nPresenters \n  \n\n\n  \n\n\nJose Torres\nPresident @ Washington Metro Association of Certified Fraud Examiners\nAssociate Director @ Guidehouse’s Financial Services practice \nJose Torres is the President of the Washington Metro Association of Certified Fraud Examiners and an Associate Director at Guidehouse’s Financial Services practice. He serves organizations in optimizing their governance\, information security strategy\, risk management\, internal control programs\, and financial reporting and compliance. Jose is a Certified Public Accountant\, Certified Fraud Examiner\, and Certified Information Systems Auditor. \n\n\n\n  \n\n\nPrem Mishra \nExperienced technology and security audit leader with more than 20 years of professional experience providing technology and security assurance services in the financial and telecom industries. Extensive experience in risk management and governance\, IT auditing\, cybersecurity\, emerging technology\, including cloud and AI governance\, and policy development. Possesses a proven track record of successfully leading large\, diverse teams that deliver high value-added audit results for senior management and the Board. \n\n\n\n \n\n\nDavid Hinchman\nDirector\, Information Technology and Cybersecurity @ GAO \nDave is a Director in GAO’s Information Technology and Cybersecurity team. He oversees audits on critical infrastructure protection\, the IT and cybersecurity workforce\, cloud computing\, and the IRS’s IT modernization efforts. \nDave joined GAO in July 2002. He has led numerous reviews of federal data center optimization and cloud computing\, and was responsible for GAO’s work on the High-Risk area of Improving the Management of IT Acquisitions and Operations. Prior to joining GAO\, Dave worked as a business consultant for several private sector firms (including PricewaterhouseCoopers)\, and served as a Surface Warfare Officer in the United States Navy. \nDave earned a master’s degree in business administration from the University of Arizona. Dave earned a bachelor’s degree in anthropology from Vassar College. \nDave works in GAO’s Dallas Field Office. \n \n\n\n\n \n\n\nValinder Mangat\nChief Innovation Officer @ DRTConfidence \nValinder Mangat is the Chief Innovation Officer (CIO) at DRTConfidence Inc.\, a contributor to the Open Security Controls Assessment Language (OSCAL) standard\, and an avid technologist. As a 30-year Information Technology veteran for various Government Agencies and Fortune 100 clients\, Valinder brings diverse experience in implementing complex enterprise systems and shares a unique perspective in preparing organizations for OSCAL adoption. \n \n\n\n\n \n\n\nDan Barahona\nCo-founder @ APIsec University  \nDan is the co-founder of APIsec Universtiy\, a free API security training site that quickly gained over 50\,000 students. He’s also the Head of Growth at APIsec\, an API security testing company\, and was formerly CMO and EVP Sales at Qualys\, CMO at Anomali\, and VP Business Development at ArcSight/MicroFocus. Dan was born and raised in Washington\, DC started his career in the automotive industry as a Crashworthiness Engineer before pivoting to cybersecurity for the last 20 years. \n \n\n\n\n \n\n\nFrank Kim\nFellow @ SANS Institute \nFrank Kim is a SANS Fellow where he leads the Cloud Security and Cybersecurity Leadership curricula to help shape and develop the next generation of security leaders. Previously\, he served as the organization’s CISO where he led the information risk function for the most trusted source of cybersecurity training and certification in the world. \nHe was also the CISO-in-Residence at YL Ventures where he supported cybersecurity entrepreneurs with ideation and market research\, conducted due diligence for potential investments\, and engaged in go-to-market activities of the firm’s portfolio companies. \nFrank continues to serve as an advisor to numerous security startups and authors and teaches courses on CISO leadership\, strategic planning\, DevSecOps\, and cloud security. Frank is the author and instructor of LDR512: Security Leadership Essentials for Managers\, LDR514: Security Strategic Planning\, Policy\, and Leadership\, and co-author of SEC540: Cloud Security and DevSecOps Automation. \n \n\n  \nVirtual Meeting Information \n\n	This event will be presented through Zoom.\n	Prior to the event\, participants must install the Zoom app on their respective devices or use the web-based Zoom. Calling via the phone may not be entitled to CPE credits.\n	Participants must respond to all the poll questions via the Zoom polling feature or chat log in order to receive NASBA CPE credits.\n	The ISACA Greater Washington\, D.C. Chapter will not be responsible for the participant’s inability to respond to the polls.\n\n  \nEvent Questions and Policies \nRegistration Questions \nIf you have any registration questions about this event\, please contact the chapter using the Registration Contact Form. \nIf you have CPE questions after the event has concluded\, please contact the chapter using the CPE Contact Form. \n  \nCancellation and Refund Policy \nCancellation and refund for advance registrations is allowed if cancellations are submitted through the registration system. Refunds vary depending on the date of cancellation. See ISACA GWDC Event Policies for details. \nIf ISACA GWDC cancels the event\, all registrants will be notified as soon as possible through email at the email address provided during registration. Full refunds will be provided. \n  \nComplaint Policy \nThe GWDC welcomes your comments\, complaints\, suggestions\, questions\, and other feedback concerning our website information and services. All complaints should be submitted through the Registration Contact Form. \n  \nCPE Information \nEarn up to 4 Continuing Professional Education (CPE) credit in the area of Information Technology. The ISACA® Greater Washington\, D.C. Chapter is registered with the National Association of State Boards of Accountancy (NASBA) as a sponsor of continuing professional education on the National Registry of CPE Sponsors. State boards of accountancy have final authority on the acceptance of individual courses for CPE credit. Complaints regarding registered sponsors may be submitted to the National Registry of CPE Sponsors through its website: www.NASBARegistry.org \n  \nCPE Distribution and Evaluation Survey \nCPEs will be distributed via e-mail along with the event evaluation survey after the completion of the event. Attendees must be present for the full event to receive full CPE credit. \n  \nLearning Objective \nAfter attending this event\, attendees will learn about recent topics in the cloud security space. \n  \nCPE-Related Details \n\n	Prerequisites: None\n	Advance Preparation: None\n	Program Knowledge Level: Basic\n	Delivery Method:  Group Internet Based\n	Field of Study:  Information Technology – Technical
URL:https://isaca-gwdc.org/event/cloud-security-conference-2024/
LOCATION:Virtual Event
CATEGORIES:Conferences
ATTACH;FMTTYPE=image/png:https://isaca-gwdc.org/wp-content/uploads/2024/08/cloud_security_conference.png
ORGANIZER;CN="Avneet Sabharwal":MAILTO:programs@isaca-gwdc.org
END:VEVENT
BEGIN:VEVENT
DTSTART;TZID=America/New_York:20240815T083000
DTEND;TZID=America/New_York:20240815T123000
DTSTAMP:20240911T155507Z
CREATED:20240805T221256Z
LAST-MODIFIED:20240911T155507Z
UID:32563-1723710600-1723725000@isaca-gwdc.org
SUMMARY:Summer Seminar on Cryptocurrency\, Blockchain\, and Security
DESCRIPTION:Join us for an exciting virtual summer seminar event hosted by Guidehouse and the ISACA GWDC chapter. This year’s topic focuses on one of the most relevant topics of the time\, Blockchain\, Cryptocurrency\, and Security. This event brings together a lawyer\, industry experts\, and academic researchers to deliver insightful presentations on various aspects of distributed ledgers\, including its benefits\, challenges\, risks\, and legal issues. \nAll are welcome to join this free information session and bring questions for the expert speakers. If you are interested in exploring the latest trends\, strategies\, and best practices in the fundamentals of Cryptocurrency and Blockchain\, this event is for you. \nRegistration closes on August 14 @ 5 pm.  Please note\, CPE credits will not be issued for this event. \nRegister Today! \n  \nEvent Sponsor \nThe GWDC is once again pleased to partner with our Gold Sponsor Guidehouse on this summer seminar. \n \n  \n  \nAgenda \n\n\n08:30 AM – 09:30 AM \n\n\nShifts in the Concept of Trustworthy Information Systems Induced by Permissionless Blockchain \nPresenter: Shin’ichiro Matsuo (Georgetown University\, CS Department) \nBlockchain technology\, invented by Satoshi Nakamoto in 2008 through a paper without peer review\, was designed with the aim of eliminating single points of failure in ledger systems based on cryptographic timestamping technology. The objective of removing single points of failure is a critically important concept in the context of information system security. However\, even after sixteen years\, numerous security incidents\, including private key leaks and vulnerabilities in smart contracts\, have occurred\, suggesting that the original technical goals have not yet been fully achieved. This presentation will revisit the fundamental technical objectives of blockchain technology and discuss how contemporary blockchain systems have altered the structure of trust points within systems. Additionally\, it will address the new requirements needed to ensure the security and auditing of systems utilizing blockchain in the future. \n\n\n\n09:30 AM – 10:30 AM \n\n\nDigital Assets: Central Bank Digital Currency and AML Risks \nPresenter: Alma Angotti (Guidehouse) \nIn the modern financial landscape\, understanding the Central Bank issued Digital Currency and the inherent and residual Anti-Money Laundering risks and control environment is a challenge all practitioners face. In this presentation\, learn how these standards are changing globally and why Digital Assets\, and the associated risks are of great importance to the United States. \n\n\n\n10:30 AM – 11:30 AM \n\n\nThe Changing Regulatory Environment for Blockchain\, Crypto and NFTs \nPresenter: James Gatto (Sheppard Mullin) \nThis presentation will address the recent changes in the regulatory environment for Blockchain\, Crypto and NFTs and why these changes may drive greater activity in this space. Specific topics to be covered: \n\n	An overview of the Blockchain\, Crypto and NFT industry and technology\n	An overview of the historical regulatory environment\n	The power struggle between the CFTC and SEC and how that is likely to be resolved\n	How the market has turned the tables on the SEC and overview of some of the significant legal battles\n	The potential impact of the upcoming election on the regulatory environment\n\n\n\n\n11:30 AM – 12:30 PM \n\n\nA Collision Course: Classical Finance and Cryptocurrency \nPresenter: Jonathan Shiery (Guidehouse) \nAs financial technology continues to evolve the traditional banking and payment domains\, cryptocurrency and blockchains come to the forefront to replace classical financial methods. Cryptocurrency and blockchain continue to gain prominence with investors and financial institutions as a device for financial activities; cryptocurrencies promote anonymity and blockchains provide transparency. This presentation will dive into the benefits of crypto and blockchain in building faster payment systems and securing legitimate banking activities while analyzing the associated regulatory\, volatility\, and cyber risks. \n\n  \nPresenters \n\n\n \n\n\nShin’Ichiro Matsuo\nResearch Professor @ Georgetown \nDr. Shin’ichiro Matsuo is a research professor specializing in cryptography and information security at Virginia Tech and Georgetown University. At Georgetown University\, he co-directs CyberSMART research center\, a National Science Foundation (NSF) Industry-University Collaborative Research Center (IUCRC)\, and leads blockchain technology and ecosystem design. He is an acting co-chair of Blockchain Governance Initiative Network (BGIN). He also co-founded the BSafe.network\, a global and neutral research test network for Blockchain technology. Previously\, he served as the head of the Japanese national body of ISO/IEC JTC1 SC27/WG2. He’s led the security standardization project of Blockchain (ISO TC307). He was a member of OECD Blockchain Expert Policy Advisory Board (BEPAB). \n \n\n\n\n \n\n\nAlma Angotti\nPartner @ Guidehouse  \nAlma Angotti is a Partner\, Financial Crime\, Fraud and Investigation Services practice at Guidehouse. Ms. Angotti is a recognized expert in financial crime and economic sanctions compliance. With over 25 years of experience in regulation and enforcement\, Ms. Angotti has held senior enforcement positions at the U.S. Securities and Exchange Commission (SEC)\, U.S. Department of the Treasury’s Financial Crimes Enforcement Network (FinCEN) and FINRA (Financial Industry Regulatory Authority). In these positions\, she was responsible for investigations and enforcement of the Bank Secrecy Act\, the federal securities laws\, and FINRA rules. \nShe leads the firm’s FinTech and digital assets compliance projects\, which includes risk assessments\, compliance program builds\, independent tests\, stable coin reviews\, and oversight of BAU compliance implementation\, and fiat and on-chain look-backs. Her clients include some of the largest cryptocurrency exchanges of all types and she is on the advisory board of the Global Digital Assets and Crypto Currency Association and the Digital Dollar Project. \n \n\n\n\n \n\n\nJames Gatto\nLawyer @ Sheppard Mullin \nJames Gatto has been a leading lawyer for 35 years providing business-focused\, legal advice on all aspects of intellectual property strategy\, technology transactions\, technology-related regulatory issues\, and litigation\, especially ones driven by new business models and/or disruptive technology. For over 20 years he has focused on Artificial intelligence legal issues (e.g.\, training\, policies\, IP\, regulatory issues). He is an Adjunct Professor at Ole Miss Law School where he teaches “Legal Issues with AI.” He is a frequent author and speaker on AI. Some of his recent talks include: \n\n	Invited Speaker\, Korean Copyright Office “AI and Open Source” \n	Speaker\, US Copyright Office Listening Session on AI Authorship \n	Speaker\, USPTO Listening Session on AI Inventorship Issues \n\nHe is an industry leader\, with prominent roles in a number of top tier legal organizations\, including:  \n\n	Appointed member\, ABA-IPL AI/Machine Learning Task Force \n	Co-Chair\, AI Subcommittee\, AIPLA \n	Member\, Artificial Intelligence Committee\, International Technology Law Association\n\n \n\n\n \n\n\nJonathan Shiery\nPartner @ Guidehouse \nJonathan Shiery is a Partner within the Financial Services segment at Guidehouse and leads Guidehouse’s Payment Services where he advises complex financial institutions on how to accelerate their payment modernization investment returns\, reduce costs through payment operations outsourcing\, and control and mitigate operational risk throughout the payments value chain. Jonathan is currently on the Board Advisory Group of the U.S. Faster Payments Council and held a leadership role in the Federal Reserve’s Faster Payments Taskforce and as the first Regulatory Workstream Chair for the U.S. Faster Payments Council. \nMr. Shiery has two decades of experience managing transformational engagements for some of the largest global financial institutions and corporations as well mid-market and regional institutions in response to shareholder\, board\, and C-level objectives. He has advised and led engagements on over $25 billion of M&A\, Operations and Technology Modernization\, Data Management and Analytics\, Payments\, and Governance\, Risk\, and Compliance investments. \n \n\n  \nVirtual Meeting Information \n\n	This event will be presented online through Zoom.  \n	The zoom link will be emailed to you when you register. \n\n  \nEvent Questions and Policies \nRegistration Questions \nIf you have any registration questions about this event\, please contact the chapter using the Registration Contact Form. \nIf you have CPE questions after the event has concluded\, please contact the chapter using the CPE Contact Form. \n  \nCancellation and Refund Policy \nCancellation and refund for advance registrations is allowed if cancellations are submitted through the registration system. Refunds vary depending on the date of cancellation. See ISACA GWDC Event Policies for details. \nIf ISACA GWDC cancels the event\, all registrants will be notified as soon as possible through email at the email address provided during registration. Full refunds will be provided. \n  \nComplaint Policy \nThe GWDC welcomes your comments\, complaints\, suggestions\, questions\, and other feedback concerning our website information and services. All complaints should be submitted through the Registration Contact Form. \n  \nCPE Information \nNo CPEs will be awarded for this event. \n 
URL:https://isaca-gwdc.org/event/summer-seminar-on-crypto-blockchain-security/
LOCATION:Virtual Event
CATEGORIES:Conferences
ATTACH;FMTTYPE=image/png:https://isaca-gwdc.org/wp-content/uploads/2024/08/summer-seminar-crypto-2024.png
ORGANIZER;CN="Avneet Sabharwal":MAILTO:programs@isaca-gwdc.org
END:VEVENT
BEGIN:VEVENT
DTSTART;TZID=America/New_York:20240718T083000
DTEND;TZID=America/New_York:20240718T123000
DTSTAMP:20240911T155507Z
CREATED:20240630T151003Z
LAST-MODIFIED:20240911T155507Z
UID:32429-1721291400-1721305800@isaca-gwdc.org
SUMMARY:Summer Seminar on Artificial Intelligence (AI) and Generative AI
DESCRIPTION:Join us for an exciting virtual summer seminar event hosted by Guidehouse and the ISACA GWDC chapter. This year’s topic focuses on one of the most relevant topics of the time\, Artificial Intelligence (AI) and Generative AI. This event brings together a lawyer\, industry experts\, and government speakers to deliver insightful presentations on various aspects of AI\, including its benefits\, challenges\, risks\, and legal issues. \nAll are welcome to join this free information session and bring questions for the expert speakers. If you are interested in exploring the latest trends\, strategies\, and best practices in implementing and managing AI this is the event to attend. \nIT professionals\, managers\, auditors\, consultants\, or anyone else interested in learning more about artificial intelligence and machine learning should attend this event. \nRegistration closes on July 17 @ 5 pm.  Note\, CPE credits will not be issued for this event. \nRegister Today! \n  \nEvent Sponsor \nThe GWDC is once again pleased to partner with our Gold Sponsor Guidehouse on this summer seminar. \n \n  \n  \nAgenda \n\n\n08:30 AM – 09:30 AM \n\n\nUnderstanding and Managing Legal Risks with AI \nPresenter: James Gatto (Sheppard Mullin) \nThe benefits of AI are clear\, but the legal risks are a bit murky and rapidly evolving. Employees are using AI without understanding the potential legal ramifications of certain uses. Join us for a timely discussion on the key legal issues with AI and what companies need to do to manage the legal risks while leveraging AI. \nIn this presentation\, Jim Gatto (who has 20+ years of legal experience with AI) will clarify the key legal issues with AI\, explain business risks if not properly managed\, provide insights on likely future legal developments and provide specific recommendations on what companies must do now to manage the legal risks with company use of AI. \n\n\n\n09:30 AM – 10:30 AM \n\n\nHarnessing the Power of Generative AI in Financial Auditing \nPresenter: Bob Dunmyer (Guidehouse) \nIn the rapidly evolving financial landscape\, organizations face increasing complexity in regulatory compliance\, financial reporting\, IT risk management\, predictive analytics\, and fraud detection. Join us to learn how Generative AI can significantly streamline these organizational audit processes. \nIn this presentation\, Bob Dunmyer\, the leader of Guidehouse’s Data and AI Division\, will break down the use case of GenAI in financial auditing processes\, describe the process of implementing this robust technology\, and provide insights on how GenAI can cause a paradigm shift for financial institutions. \n\n\n\n10:30 AM – 11:30 AM \n\n\nAI’s Impact on Cybersecurity – Today\, Tomorrow\, and Beyond \nPresenter: Geoff Grogan (Guidehouse) \nAI technology is quickly evolving and becoming more and more ubiquitous in our daily lives. With it comes many benefits\, but also many risks. Learn how AI is affecting today’s cybersecurity landscape and how organizations can tackle this challenge today\, while laying a robust foundation of cyber resilience in the future. \n\n\n\n11:30 AM – 12:30 AM \n\n\nAI\, Deep Fakes\, Natural Hazard Modeling \nPresenters: Brian Bothwell (GAO) and Kevin Walsh (GAO) \nI and associated technologies are changing how we interact with the world. In this seminar\, Brian and Kevin will discuss how AI is changing forecasting\, deep fakes\, and interactions between the government and citizens. Join us as we explore the peril and the potential of AI. \n\n  \nPresenters \n\n\n \n\n\nJames Gatto\nLawyer @ Sheppard Mullin \nJames Gatto has been a leading lawyer for 35 years providing business-focused\, legal advice on all aspects of intellectual property strategy\, technology transactions\, technology-related regulatory issues\, and litigation\, especially ones driven by new business models and/or disruptive technology. For over 20 years he has focused on Artificial intelligence legal issues (e.g.\, training\, policies\, IP\, regulatory issues). He is an Adjunct Professor at Ole Miss Law School where he teaches “Legal Issues with AI.” He is a frequent author and speaker on AI. Some of his recent talks include: \n\n	Invited Speaker\, Korean Copyright Office “AI and Open Source” \n	Speaker\, US Copyright Office Listening Session on AI Authorship \n	Speaker\, USPTO Listening Session on AI Inventorship Issues \n\nHe is an industry leader\, with prominent roles in a number of top tier legal organizations\, including:  \n\n	Appointed member\, ABA-IPL AI/Machine Learning Task Force \n	Co-Chair\, AI Subcommittee\, AIPLA \n	Member\, Artificial Intelligence Committee\, International Technology Law Association\n\n \n\n\n\n \n\n\nBob Dunmyer\nPartner @ Guidehouse \nBob Dunmyer serves as a Partner in the Digital Solutions sector at Guidehouse\, where he spearheads the Data & AI division. His leadership is pivotal in guiding clients through their Digital Transformation journey\, leveraging GenAI and Intelligent Automation. Bob’s rapidly expanding team\, comprising data management pros\, data scientists\, and bot developers\, is dedicated to harnessing artificial intelligence and automation to tackle intricate challenges. He navigates clients through the dynamic landscape of artificial intelligence\, making certain they stay at the forefront of digital innovation. Bob’s leadership ethos is centered around creating synergies between technology and strategy\, delivering tailored solutions that catalyze significant transformations in both the Commercial and Public Sectors. \n \n\n\n\n \n\n\nGeoff Grogan\nDirector @ Guidehouse  \nExperienced cybersecurity business leader with more than 15 years of professional experience providing consulting\, program management\, and risk management expertise to Department of Defense and Federal Government clients. Extensive experience in cybersecurity strategy\, governance\, and policy development\, including expertise in supply chain risk management (SCRM)\, and non-traditional IT (i.e. weapons systems\, industrial control systems). Possesses a proven track record successfully leading large\, diverse teams that deliver at a high level to senior clients in a variety of high-paced\, dynamic environments. \n \n\n\n\n \n\n\nBrian Bothwell\nDirector of Science\, Technology Assessment\, and Analytics @ U.S. Government Accountability Office (GAO) \nBrian Bothwell is a Director in GAO’s Science\, Technology Assessment\, and Analytics (STAA) team. He oversees a team of engineers and scientists who analyze engineering and technology issues. He also directs a team whose work includes assessing federal efforts to acquire and operate weapons\, satellites\, and other major technological systems on time and on budget. \nBrian joined GAO in December 2013 as a member of the Applied Research and Methods team\, where he assessed cost estimates\, schedules\, cost management systems\, and technology readiness of several federal programs. Additionally\, Brian contributed to the development of several GAO best practice guides and led the update to the “Cost Estimating and Assessment Guide.” In 2021\, he became a Director in GAO’s STAA team. Prior to joining GAO\, Brian enjoyed a 20-year career in the United States Navy and worked as a cost estimator in the private sector. \nBrian earned a master’s degree in operations research from the Naval Postgraduate School and a bachelor’s degree in chemical engineering from the University of Notre Dame. \n \n\n\n\n \n\n\nKevin Walsh\nDirector of Information Technology and Cybersecurity @ U.S. Government Accountability Office (GAO) \nKevin Walsh is a Director in GAO’s Information Technology and Cybersecurity team. He oversees work related to AI\, Census\, CIO authorities\, legacy modernizations\, and satellite and space systems. He has led reviews covering topics related to the authorities of federal Chief Information Officers\, management of legacy IT systems\, coordination of IT contracts\, and assessments of IT-related risk. \nKevin joined GAO in June 2006\, and led projects related to FITARA and GAO’s High-Risk area on Improving the Management of IT Acquisitions and Operations. \nKevin earned a master’s degree in business administration from Virginia Tech. Kevin earned a bachelor’s degree in economics from the University of Maryland\, College Park. \n \n\n  \nVirtual Meeting Information \n\n	This event will be presented online through Zoom.  \n	The zoom link will be emailed to you when you register. \n\n  \nEvent Questions and Policies \nRegistration Questions \nIf you have any registration questions about this event\, please contact the chapter using the Registration Contact Form. \nIf you have CPE questions after the event has concluded\, please contact the chapter using the CPE Contact Form. \n  \nCancellation and Refund Policy \nCancellation and refund for advance registrations is allowed if cancellations are submitted through the registration system. Refunds vary depending on the date of cancellation. See ISACA GWDC Event Policies for details. \nIf ISACA GWDC cancels the event\, all registrants will be notified as soon as possible through email at the email address provided during registration. Full refunds will be provided. \n  \nComplaint Policy \nThe GWDC welcomes your comments\, complaints\, suggestions\, questions\, and other feedback concerning our website information and services. All complaints should be submitted through the Registration Contact Form. \n  \nCPE Information \nNo CPEs will be awarded for this event. \n 
URL:https://isaca-gwdc.org/event/summer-seminar-ai-generative-ai/
LOCATION:Virtual Event
CATEGORIES:Conferences
ATTACH;FMTTYPE=image/png:https://isaca-gwdc.org/wp-content/uploads/2024/06/summer-seminar-ai-2024_v2.png
ORGANIZER;CN="Avneet Sabharwal":MAILTO:programs@isaca-gwdc.org
END:VEVENT
BEGIN:VEVENT
DTSTART;TZID=America/New_York:20240612T090000
DTEND;TZID=America/New_York:20240612T160000
DTSTAMP:20240610T005948Z
CREATED:20240519T134331Z
LAST-MODIFIED:20240610T005948Z
UID:32220-1718182800-1718208000@isaca-gwdc.org
SUMMARY:2024 Annual Meeting Conference
DESCRIPTION:The ISACA® GWDC annual conference is the Chapter’s premium event for the year. This year the Annual Meeting coincide with the chapter’s 50th anniversary. \nThis year the Annual Meeting Conference is a virtual event.  Presentations will focus on emerging technologies\, risk vectors\, mitigation strategies\, and governance trends. Topics are aimed equally at participants focused on the Government and Private sectors. All sessions are designed to increase your understanding of current topics and hone your professional skills by learning directly from leading practitioners in their fields.  IT professionals\, IT advisory or audit professionals\, business executives\, students or professionals interested in learning more about IT risk management and governance should attend this event. \nFor the convenience of all our members\, we will make the Chapter’s business session – the Annual General Membership Meeting – available to them on-line. \nRegistration closes on June 11\, 2024 @ 12pm.  \nRegister Today! \n  \nAgenda \n\n\n09:00 AM – 09:10 AM \n\n\nOpening Remarks \nIntroduction to the conference and discussion of logistics\, including CPEs and polling questions. \n\n\n\n09:10 AM – 10:00 AM \n\n\nBridging the Divide: Technology’s Role in Shaping Policy for a Sustainable Future \nPresenter: Dr. Gina Guillaume-Joseph (Eztera Digital Solutions) \nGiven the dynamic nature of technology and its profound impact on society\, the topic will resonate with the audience in Washington DC\, considering both the political and technological significance. I’ll explore how technology not only drives innovation but also serves as a critical bridge between diverse sectors\, including government\, private industry\, and the public. I will delve into AI\, cybersecurity\, and the policies for tech governance. \n\n\n\n10:00 AM – 10:50 AM \n\n\nWhat are the intersections of Privacy and AI? \nPresenter: Deborah Adleman (Adleman Consulting Services LLC) \nEvery month there seem to be new examples of artificial intelligence (AI) technology such as Generative AI and accompanying privacy regulations. At the same time\, the complexity of these privacy requirements is also increasing. There is a heightened clamor for governments\, businesses\, and individuals to approach AI ethically while not derailing innovation. Amidst this environment\, what are the overlaps between Privacy and AI that can help us mitigate risk and govern emerging technologies consistent with our business mission? How do we protect privacy while allowing AI to increase business efficiency and simplify our lives without stifling innovation? \nLearn from Deborah Adleman of Adleman Consulting Services LLC who has spent her career as a US and Global Risk and Privacy Leader who will help us tackle these answers and leave us with a roadmap to take back to our organizations. \n\n\n\n10:50 AM – 11:00 AM \n\n\nMorning Break \n\n\n\n11:00 AM – 11:50 AM \n\n\nNavigating the Cybersecurity Frontier: Emerging Threats and Defense Strategies in 2024 \nPresenter: Sushila Nair (Cybernetic LLC) \nThis dynamic presentation delves into the evolving landscape of cybersecurity\, focusing on emerging technologies\, threats\, and defense strategies crucial for today’s digital world. \nThe session begins by exploring the realms of cyberwar and cybercrime. Recent state-sponsored cyberattacks targeting critical infrastructures are highlighted\, emphasizing the need for robust national cybersecurity strategies and international cooperation. The rise of sophisticated ransomware\, phishing schemes\, and AI-enhanced fraudulent activities are examined\, drawing insights from recent high-profile incidents. The importance of cybersecurity awareness\, advanced threat detection\, and response strategies are underscored as vital defensive measures. \nNext\, the transformative role of Artificial Intelligence (AI) and machine learning in cybersecurity is investigated. These technologies are revolutionizing threat detection and response\, though they also introduce risks such as adversarial AI and ethical concerns. \nA significant focus is placed on Zero Trust Architecture\, a critical shift in cybersecurity paradigms. The principles of zero trust are explained\, emphasizing the importance of continuously verifying users\, devices\, and applications. Practical steps for implementing zero trust within organizations are provided\, highlighting the approach’s effectiveness in mitigating modern cyber threats. \nIdentity security is covered as a cornerstone of effective cybersecurity. Strategies for robust identity and access management (IAM)\, including multi-factor authentication (MFA) and identity governance\, are discussed to reduce attack surfaces and protect sensitive data. \nThe presentation further explores emerging attack vectors\, such as supply chain attacks and zero-day exploits\, offering real-world examples and mitigation strategies. Advanced defensive measures\, including threat intelligence and sharing\, are examined\, stressing the value of collaboration and effective threat intelligence platforms. \nConcluding with a summary and a Q&A session\, this presentation aims to equip attendees with a comprehensive understanding of current cybersecurity challenges and the advanced defenses necessary to counter them. \n\n\n\n11:50 AM – 12:20 PM \n\n\nLunch Break \n\n\n\n12:20 PM – 01:10 PM \n\n\nStreamlining AI Governance: Tools for Tomorrow’s Challenges \nPresenter: Meghan Maneval (RiskOptics) \nIn an era where artificial intelligence is rapidly transforming industries\, the need for proactive and robust AI governance has never been more pressing. In this session\, “Streamlining AI Governance: Tools for Tomorrow’s Challenges\,” I’ll provide a strategic roadmap for organizations looking to establish a solid governance framework that not only meets today’s requirements but also anticipates future regulatory landscapes. During this session\, we will explore the practical steps necessary to lay the foundational groundwork for AI governance. Leveraging a real-world AI use case\, the focus will be on equipping your organization with the necessary strategies to establish AI Controls\, align with AI Regulations\, track AI Risk\, and monitor AI in your supply chain. \nYou’ll learn how to implement a governance structure that adapts to new challenges\, ensuring your AI initiatives are both innovative and within regulatory bounds. \nParticipants will explore: \n\n	Aligning organization controls with AI specific regulations\, automating evidence collection\, and correcting non-conformities.\n	Tracking AI projects and managing the associated assets\, threats\, vulnerabilities\, and risks.\n	Monitoring your supply chain’s compliance with AI usage standards and risk reduction activities.\n\n\n\n\n01:10 PM – 02:00 PM \n\n\nWhat is going on in the ransomware cybercrime business ecosystem? \nPresenter: Dr. Ferhat Dikbiyik (Black Kite) \nRansomware groups now operate like agile tech startups\, not traditional crime cartels. They combine advanced tech skills with psychological manipulation and a business mindset. Their sophisticated tactics challenge standard cybersecurity defenses\, requiring a new approach to understanding and combating these threats. This session explores their operations and mindset through business and social psychology principles\, particularly those by Elliot Aronson. \nWe’ll discuss why technical defenses aren’t enough. Ransomware groups carefully choose targets based on vulnerability\, strategic value\, and psychological impact. Despite law enforcement’s progress against groups like Lockbit and Black Cat\, these syndicates adapt and evolve\, highlighting the need for a dynamic risk assessment model that considers both technical and psychological factors. \nWe’ll examine how some professionalized ransomware groups use business tactics and moral justifications\, posing as pentesters\, hacktivists\, or reluctant actors. By analyzing their PR moves\, apologies\, and rationalizations\, we’ll gain insights into their behavior. Case studies will reveal their strategies in operations\, negotiations\, and public relations. \n\n\n\n02:00 PM – 02:10 PM \n\n\nAfternoon Break \n\n\n\n02:10 PM – 03:00 PM \n\n\nBuilding an Effective Insider Risk Mitigation Program \nPresenter: Randall Trzeciak (Security Engineering Institute @ Carnegie Mellon University) \nThe National Insider Threat Center in the CERT Division of the Software Engineering institute at Carnegie Mellon University has been researching Insider Threats since 2001 and has analyzed over 3500 incidents where insiders have maliciously or non- maliciously harmed organizations. The research has resulted in the development of models describing how these incidents tend to evolve over time\, including the identification of both the technical and behavioral potential risk indicators. This presentation will provide a brief overview of the insider incident types; best practices for the mitigation of insider threats; provide an insider threat program development roadmap; and recommend resources for the evaluation of an insider threat program. \n\n\n\n03:00 PM – 03:50 PM \n\n\nHealthcare Under Siege: Decoding Cybersecurity and Privacy Challenges to Navigate the Surge in Ransomware Attacks \nPresenters: Tina Curtis (Office of the Attorney General for the District of Columbia) and Ruchi Shewaramani (Washington Health Benefit Exchange) \nTopic description to be posted soon \n\n\n\n03:50 PM – 04:00 PM \n\n\nClosing Remarks \n\n\n\n04:00 PM – 05:00 PM \n\n\nAnnual General Meeting (AGM) of the Chapter Membership \nThe member portion of the meeting will be held on a separate zoom and is open to all current chapter members. Members can register for this session on the AGM event page. \n\n  \nPresenters \n\n\n \n\n\nDr. Gina Guillaume-Joseph\nChief Innovation Officer (CIO) @ Eztera Digital Solutions \nGina Guillaume-Joseph\, PhD is a published author and technologist with executive experience and thought leadership within the Federal and Commercial Sector. \nGina is the Chief Innovation Officer (CIO) at Eztera Digital Solutions. Gina will leverage her technology implementation experience and vast network to support the Federal Government’s Technology Transformation Strategy. Her accomplishments and successes are based on strong program performance\, leadership discipline\, a commitment to developing relevant\, innovative and adaptive solutions\, and a vigilant focus on best value solutions for her clients. \nGina spent 16 years supporting our Federal Government as a contractor with Booz Allen Hamilton\, L-3 Communications and The MITRE Corporation. As a Systems Engineer she was responsible for implementing key strategic frameworks\, solutions and technology platforms to assist agencies such as the DoD\, IRS\, FDIC\, DHS\, VA\, and SSA overcome technology gaps in delivering capabilities and value to our United States Taxpayers. \nGina is the former Chief Technology Officer – Government at Workday and former Director of Technology at Capital One. Gina supported the HR and People Technology team as a strategic technical advisor. At Capital One\, she matured their Scaled Agile practices by hiring agilists\, training the team\, and fully implementing the framework to scale resulting in improved product value delivery across the organization. Workday was a key product implemented to Capital One’s more than 43\,000 employees. \n \n\n\n\n \n\n\nDeborah Adleman\nAdleman Consulting Services LLC\nCCEP\, SCCE\, IDP\, GCRP\, CIPP/US\, CIPM\, and FEP \nDeborah is a strategy-driven and practical\, results oriented leader recognized for enabling future focused enterprise-wide data protection risk management\, AI governance and ethics & compliance programs. Deborah’s evolved experience in leadership at a Big Four firm combined with a successful consulting career brings a global\, IT engineering\, and business process outcomes mindset to data governance\, process improvement and teamwork. Deborah was the US & Americas Data Protection Risk Management Leader for Ernst & Young for over a decade and a successful consultant within EY before that. While at EY\, Deborah led EY’s US and Americas’ data protection risk\, ethics and compliance program strategy and implementation across 50\,000 employees while collaborating with other EY global leaders. Deborah was accountable for assessing\, implementing\, and monitoring the effectiveness of the enterprise data protection program and its maturity. Deborah accomplished this by fusing ethical and responsible data protection leading practices into the core business processes and then establishing accountability grounded in metrics. Since leaving EY\, Deborah has started her own single person consultancy serving a wide range of companies\, continuing her tradition of helping companies leverage risk to empower their teams to perform accountably\, with integrity in the midst of uncertainty. \nDeborah has her Bachelor of Arts from the University of Pennsylvania\, and has various governance\, ethics and privacy certifications including the Certified Compliance and Ethics Professional (CCEP) through the Society for Corporate Compliance and Ethics (SCCE)\, the Integrated Data Privacy (IDP) and the Governance\, Risk & Compliance Professional (GCRP) from the Open Compliance and Ethics Group (OCEG)\, and the CIPP/US\, CIPM and FEP through the IAPP. \nDeborah is the author of “How to Operationalize Privacy and Data Governance for AI” (InformationWeek)\, and “A Data Privacy Compliance Program Primer” (SCCE) and is a regularly sought after speaker who recently provided subject matter expertise for the IAPP’s new Artificial Intelligence Governance Professional (AIGP) certification. \n \n  \n\n\n\n \n\n\nSushila Nair\nVice President\, Head of Cybersecurity Services\, CEO @ Cybernetic LLC\nCISSP\, GIAC GSTRT\, CISA\, CISM\, CRISC\, CDPSE\, CCSK\, CCAK \nSushila Nair is the CEO of Cybernetic LLC and former Vice President of Capgemini’s North American Cybersecurity practice. Sushila Nair is a pivotal figure in driving secure digital transformation globally. With over 30 years of experience spanning computing infrastructure\, business\, and security risk analysis\, Sushila has carved a niche in the cybersecurity domain. Her journey includes a decade-long leadership of her own IT and Cybersecurity company across major UK cities and serving as a Chief Information Security Officer (CISO)\, where she mastered the art of safeguarding against evolving digital threats. \nAn esteemed thought leader\, Sushila’s insights have graced global platforms like RSA and ISACA’s conferences. Her role in the ISACA global emerging trends working group and as Vice President of ISACA’s Greater Washington\, D.C. Chapter showcases her commitment to advancing the field. Her efforts\, especially in championing the next generation of cybersecurity talent and promoting diversity\, earned her the prestigious ISACA Technology for Humanity Award in 2024. \n \n\n\n\n \n\n\nMeghan Maneval\nVice President of Product Strategy and Evangelism @ RiskOptics\nCISM\, CRISC \nMeghan Maneval is a distinguished figure in the cybersecurity and governance\, risk management\, and compliance (GRC) sectors\, renowned for her innovative approach and commitment to enhancing diversity in the tech industry. With nearly 20 years of experience\, she has consistently demonstrated her ability to simplify the complexities of cybersecurity for organizations around the world. \nAs the Vice President of Product Strategy and Evangelism at RiskOptics\, Maneval leverages her unique insights to drive significant advancements in GRC tools. Her direct involvement in the development of RiskOptics ROAR\, a trailblazing GRC solution that automates risk management and compliance\, underscores her role as a key innovator in the industry. \nManeval’s influence extends beyond RiskOptics- advocating for risk-centric strategies that adapt to the evolving landscape of cybersecurity. Her pioneering work in AI governance\, including the design of a continuous monitoring process and the development of an AI Governance course for ISACA\, showcases her dedication to responsible and secure AI usage. These achievements awarded her the SC Media Women in Cybersecurity Award. \nBeyond her technical achievements\, Maneval is passionate about fostering an inclusive work environment. She founded the Women in Leadership Program at RiskOptics\, aiming to empower female employees and equip them with the skills necessary for leadership roles. Her efforts reflect a deep commitment to breaking down barriers and creating opportunities for women in technology. \nAdditionally\, Maneval is an active mentor\, particularly within the Girl Scouts\, where she inspires young women to pursue careers in STEM. Her involvement with the Cyber Guild’s Diverse Minds Movement and her doctoral research on the impact of AI on neuroinclusion further illustrate her commitment to building a more diverse and inclusive tech community. \nMeghan Maneval’s comprehensive contributions to cybersecurity\, her innovative solutions\, and her dedication to mentorship and diversity mark her as a transformative leader in the field. \n \n\n\n\n \n\n\nDr. Ferhat Dikbiyik\nChief Research & Intelligence Officer @ Black Kite \nDr. Ferhat Dikbiyik\, as the Chief Research & Intelligence Officer\, stands at the vanguard of redefining cybersecurity’s frontiers\, particularly in the realm of ransomware. Under his leadership\, his team delves into the sophisticated world of cyber threats\, blending cutting-edge data analysis and machine learning to elevate the Black Kite platform’s capabilities. His unique approach uncovers not just the how of ransomware operations but the why\, illuminating the psychological underpinnings and business-like efficiency of these cybercriminals. \nWith a storied 15-year journey traversing from academia to the pulsating heart of startup innovation\, Dr. Dikbiyik’s transition shines a light on his versatility. Holding a Ph.D. in Electrical and Computer Engineering from the University of California\, Davis\, he initially focused on enhancing the resilience of telecom networks against disasters. This foundation set the stage for his later work\, where he explores the nexus between technology\, psychology\, and strategy within the cyber risk domain. \nDr. Dikbiyik has contributed to national and international projects on disaster risk\, including cyber risk. His prolific output\, featuring over 40 scientific papers with more than 1\,000 citations\, evidences his significant impact on the field. He is a co-inventor of two patents granted on cyber risk assessment\, one related to ransomware susceptibility measurement. \nIn recent years\, Dr. Dikbiyik has become a sought-after voice on the global stage\, elucidating the complexities of cyber risk management and the intricacies of ransomware groups. His work—bridging the gap between academic research and practical\, startup-driven solutions—resonates with a broad spectrum of cybersecurity professionals and businesses alike. \n \n\n\n\n \n\n\nRandall Trzeciak\nDirector of The Insider Threat Center at CERT\nAdjunct Faculty\, MSISPM Program Director @ Software Engineering Institute @ Carnegie Mellon University\n \nRandy Trzeciak currently holds a dual appointment between Heinz College and the CERT Program of the Software Engineering Institute at Carnegie Mellon University. In support of the Heinz College\, Randy occupies the role of Director of the Master of Science Information Security Policy & Management (MSISPM) Program as well as an adjunct professor for the graduate School of Information Systems and Management. \nIn support of the Software Engineering Institute\, Randy is the Technical Manager of CERT’s Enterprise Threat and Vulnerability Management Team and the CERT Insider Threat Center. The team’s mission is to assist organizations in improving their security posture and incident response capability by researching technical threat areas; developing and conducting information security assessments; and providing information\, solutions and training for preventing\, detecting\, and responding to illicit activity. Team members are domain experts in insider threat and incident response. Team capabilities include threat analysis and modeling; building and evaluating insider threat programs; development of insider threat controls\, workshops\, and exercises. \nPrior to his current role in the CERT Program\, Mr. Trzeciak managed the Management Information Systems (MIS) team in the Information Technology Department at the SEI. Under his direction\, the MIS team developed and supported numerous mission-critical\, large-scale\, relational database management systems. \nPrior to his time working at the SEI\, Mr. Trzeciak was a software engineer for the Information Technology Development Center of the Carnegie Mellon Research Institute (CMRI)\, responsible for a variety of information networking projects. These projects included the design and development of large-scale databases and Internet-based systems that adhered to data privacy and security requirements; the design and implementation of multi-organizational portals for preparation and response to weapons of mass destruction; and collaboration among public health department epidemiologists. \nPrior to his career at Carnegie Mellon\, Mr. Trzeciak worked for Software Technology\, Incorporated (STI) in Alexandria\, Virginia. For nine years\, Mr. Trzeciak was a consultant to the Naval Research Laboratory (NRL) working on numerous projects designing\, building\, and supporting large-scale relational database management systems. During his employment with STI\, Mr. Trzeciak also filled the role of Information Systems Business Manager. \n \n\n\n\n \n\n\nTina Curtis\nAssistant Attorney General\, District-wide Privacy and Security Official/ Director of the Office of Privacy and Confidentiality @ Office of the Attorney General for the District of Columbia\nCIPP\, CCSA \nTina Curtis serves as Assistant Attorney General\, and District-wide Privacy and Security Official/ Director of the Office of Privacy and Confidentiality\, within the Office of the Attorney General for the District of Columbia. With a focus on health and human services data\, she leads the government’s corporate compliance efforts for 20 agencies\, spanning Human Services\, Public Safety and Education clusters. She also provides ad hoc advice across all governmental business types. This includes overseeing privacy and security matters involving the operation of agency offices\, data sharing design\, policy development\, audits\, contracts oversight\, policy development\, technology reviews and training. \nShe also serves as Secretary for the Institute of Electrical and Electronics Engineers’ (IEEE) Privacy PAR Working Group. The PAR is completing the development of a global privacy standard for consumer mobile devices. \nHer background also includes serving as Assistant General Counsel for the DC Department of Insurance Securities and Banking\, and as the Chair of the Minority Business Opportunities Commission for Prince George’s County\, Maryland. \nMs. Curtis is a graduate of the University of Maryland\, College Park and the Howard University School of Law. She holds Certified Information Privacy Professional (CIPP) and Certified Cyber Security Architect (CCSA) certifications. \n \n\n\n \n\n\nRuchi Shewaramani\nChief Information Security Officer @ Washington Health Benefit Exchange \nRuchi Shewaramani is a cyber security executive with 18+ years of experience in Information Technology Security\, Identity and Access Management (IAM)\, Governance\, Risk and Compliance (GRC) across healthcare\, education and financial sector. She is currently serving as the Chief Information Security Officer for Washington Health Benefit Exchange and as a Board member for ISACA Greater Washington DC Chapter. \nIn the last decade\, she has led the security program for various healthcare agencies in District of Columbia (DC) prior to joining Washington state exchange. She specializes in establishing and transforming cyber security program for healthcare agencies to attain compliance with state and federal partners\, safeguard customer data and build digital trust for the citizens served. \n \n\n  \nVirtual Meeting Information \n\n	This event will be presented through Zoom.\n	Prior to the event\, participants must install the Zoom app on their respective devices or use the web-based Zoom. Calling via the phone may not be entitled to CPE credits.\n	Participants must respond to all the poll questions via the Zoom polling feature or chat log in order to receive NASBA CPE credits.\n	The ISACA Greater Washington\, D.C. Chapter will not be responsible for the participant’s inability to respond to the polls.\n\n  \nEvent Questions and Policies \nRegistration Questions \nIf you have any registration questions about this event\, please contact the chapter using the Registration Contact Form. \nIf you have CPE questions after the event has concluded\, please contact the chapter using the CPE Contact Form. \n  \nCancellation and Refund Policy \nCancellation and refund for advance registrations is allowed if cancellations are submitted through the registration system. Refunds vary depending on the date of cancellation. See ISACA GWDC Event Policies for details. \nIf ISACA GWDC cancels the event\, all registrants will be notified as soon as possible through email at the email address provided during registration. Full refunds will be provided. \n  \nComplaint Policy \nThe GWDC welcomes your comments\, complaints\, suggestions\, questions\, and other feedback concerning our website information and services. All complaints should be submitted through the Registration Contact Form. \n  \nCPE Information \nEarn up to 7 Continuing Professional Education (CPE) credit in the area of Information Technology. The ISACA® Greater Washington\, D.C. Chapter is registered with the National Association of State Boards of Accountancy (NASBA) as a sponsor of continuing professional education on the National Registry of CPE Sponsors. State boards of accountancy have final authority on the acceptance of individual courses for CPE credit. Complaints regarding registered sponsors may be submitted to the National Registry of CPE Sponsors through its website: www.NASBARegistry.org \n  \nCPE Distribution and Evaluation Survey \nCPEs will be distributed via e-mail along with the event evaluation survey after the completion of the event. Attendees must be present for the full event to receive full CPE credit. \n  \nLearning Objective \nAfter attending this event\, attendees will learn about recent topics in the information technology. \n  \nCPE-Related Details \n\n	Prerequisites: None\n	Advance Preparation: None\n	Program Knowledge Level: Basic\n	Delivery Method:  Group Internet Based\n	Field of Study:  Information Technology – Technical
URL:https://isaca-gwdc.org/event/annual-meeting-2024/
LOCATION:Virtual Event
CATEGORIES:Conferences
ATTACH;FMTTYPE=image/png:https://isaca-gwdc.org/wp-content/uploads/2024/05/annual_meeting_2024.png
ORGANIZER;CN="Yehuda Schmidt (Annual Meeting Questions)":MAILTO:programs@isaca-gwdc.org
END:VEVENT
BEGIN:VEVENT
DTSTART;TZID=America/New_York:20240523T083000
DTEND;TZID=America/New_York:20240523T123000
DTSTAMP:20240521T012938Z
CREATED:20231030T234536Z
LAST-MODIFIED:20240521T012938Z
UID:31265-1716453000-1716467400@isaca-gwdc.org
SUMMARY:Risk Management and Governance Conference 2024
DESCRIPTION:The ISACA Greater Washington DC (GWDC) is proud to host our annual Risk Management and Governance conference. This conference is part of our monthly conference series. \nIT professionals\, IT advisory or audit professionals\, business executives\, students or professionals interested in learning more about IT risk management and governance should attend this event. \nRegistration closes on May 22\, 2024 @ 12pm.  \nRegister Today! \nThe agenda for this event is being developed.  Details for this event will be posted when available. \n  \nAgenda \n\n\n08:30 AM – 09:30 AM \n\n\nWhere Is AI Taking Us? Cyber influence Operations and Synthetic Media \nPresenter: David Branscome (Microsoft) \nTools like ChatGPT\, OpenAI and DALL-E have burst onto the scene with a usability and simplicity that makes the use of AI seem to be easy enough for a child to use. \nBut is that good or bad? The answer may depend on who you ask. \nIn this discussion\, we’ll look at how nation-states are using AI tools to shape public opinion to achieve their political and strategic goals. We’ll look at the cyberinfluence campaigns surrounding COVID-19 and the ongoing war in Ukraine\, as well as the use of AI to digitally manipulate media for political gain. We’ll also investigate the tools being developed to counter these trends and help ensure the information we consume can be trusted. \n\n\n\n09:30 AM – 10:30 AM \n\n\nAI Risk Assessment: Where to Start\, What to Ask\, and Things to do About the Risk \nPresenter: Joe Veroneau (Conveyor) \nAs AI advancements revolutionize business decision-making\, understanding how to evaluate and mitigate AI-associated risk is top of mind for all companies. In this session\, participants will learn practical ways to scope and prioritize where to start when including AI risk in their wider risk assessment methodology. Participants will learn to evaluate if AI risk is present critically\, assess the potential impact and navigate the potential risks of AI-powered companies and processes. \n\n\n\n10:30 AM – 11:30 AM \n\n\nBleeding Edge of Cybersecurity Risk \nPresenters: Ramona Ratiu (Zurich Insurance and DePaul University) and Alex Islamov (MorganFranklin Consulting) \nThe presentation on the bleeding edge of cybersecurity risks offers a comprehensive exploration of the ever-evolving landscape of digital threats and vulnerabilities. We will delve into the intricacies of emerging technologies like artificial intelligence\, quantum computing\, the Internet of Things (IoT)\, and Information and Communication Technologies (ICT)\, which are being harnessed by sophisticated threat actors to launch unprecedented cyberattacks. You will gain insights into the growing menace of ransomware\, supply chain attacks\, and state-sponsored cyber espionage\, along with the escalating challenges these pose to organizations worldwide. By highlighting the need for proactive adaptation\, robust threat intelligence\, and innovative cybersecurity strategies\, this presentation will equip you with the knowledge and tools to navigate the cutting-edge risks in today’s digital world effectively. \n\n\n\n11:30 AM – 12:30 AM \n\n\nInformation Risk Management \nPresenter: Jay Ranade (Risk Management Professionals) \nInformation is the life blood of the organization\, because information risk is primarily to the business processes. Without information (data)\, there is no business. Protecting data from confidentiality\, integrity\, availability\, and privacy perspective is of paramount importance. Even from the enterprise risk management perspective\, all OTHER enterprise risks depend upon information. Information risk management revolves around identifying risks\, measuring risk\, treating risk\, and monitoring risk. One of the most complex tasks in information risks is designing KRIs and KCIs\, where most of the organizations make mistakes. \n\n  \nPresenters \n\n\n \n\n\nDavid Branscome\nGlobal Partner Solutions Architect for Security\, Compliance and Identity @ Microsoft\nCISSP\, GCWN\, GCED\, GCDA\, GMOB\, GCIH\, GISP\, GSEC\, GSOC\, GCFA\, GDAT\, GCPN\, GCFR \nDavid is a Global Partner Solutions Architect for Security\, Compliance and Identity at Microsoft. In this role\, David is responsible for training and supporting Microsoft partners on the latest security compliance and identity solutions\, including Microsoft 365\, Azure and Windows. \n \n\n\n\n \n\n\nJoe Veroneau\nDirector\, Trust & Security @ Conveyor Inc. \nRisk management professional with wide experience across GRC domains in an operational and advisory capacity. Currently specializing in cloud security compliance. \n \n  \n\n\n\n \n\n\nRamona Ratiu\nGlobal Head of Cyber Tabletop Exercises- Cybersecurity – Zurich Insurance\nAdjunct Professor – IT Risk Management – DePaul University\nBoard Strategic Advisor/Past President – ISACA Chicago Chapter\nSheLeadsTech Ambassador\nMS\, CISA\, CISM\, GSTRT \nRamona Ratiu’s current role at Zurich Insurance Group focuses on effective risk planning strategies as the core for strengthening\, improving\, and maturing the cybersecurity program. She successfully leads transformational cybersecurity projects through her strong planning and organizational skills. Ms. Ratiu’s experience in information security\, governance\, audit\, risk management\, and compliance helped her develop and implement technical and procedural solutions\, enabling stakeholders to achieve and sustain compliance efficiently across multiple standards. \nMs. Ratiu holds a bachelor’s degree in finance and earned the Master of Science in Information Security and Compliance from DePaul University. In addition\, she holds these certifications: Certified Information Systems Auditor (CISA)\, Certified Information Systems Manager (CISM)\, COBIT5 Foundations\, ITIL Foundations Certificate and GIAC Strategic Planning\, Policy and Leadership (GSTRT). \n \n\n\n \n\n\nAlex Islamov\nDirector\, Cybersecurity Strategy and GRC @ MorganFranklin Consulting\nCredentials \nAlex Islamov is the Director of Cybersecurity Strategy and Risk\, and a leader of the MorganFranklin Consulting Cyber Financial Services pillar with over 18 years of experience helping companies navigate complex compliance and regulatory environments while providing comprehensive operational\, information technology\, and information security risk management solutions. Alex offers extensive experience in software and technology\, healthcare\, manufacturing and distribution\, and financial services industries with significant subject matter expertise in IT Audit\, IT SOX\, IT/IS Governance\, Regulatory Compliance\, Data Privacy and Protection\, Information Security and Cybersecurity\, Enterprise Risk Management\, Third-Party Risk Management\, and Finance & Accounting. In addition\, Alex possesses deep knowledge and understanding of the regulatory standards and frameworks such as COSO\, SOX\, NIST (800-53 and CSF)\, HIPAA\, CSA CCM\, FISMA\, FedRAMP\, CIS CSC\, PCI-DSS\, HITRUST\, ISO\, and SOC 1/2/3. Prior to joining MorganFranklin Cyber\, Alex spent over 15 years in management/leadership positions at leading accounting firms\, financial institutions\, and software companies. \n \n\n\n\n \n\n\nJay Ranade\nSenior Trainer @ Risk Management Professionals\nCIA\, CISA\, CISM\, CISSP\, ISSAP\, CGEIT\, CRISC\, HCISPP\, CRMA\, and CBCP \nJay Ranade\, a certified CIA\, CISA\, CISM\, CISSP\, ISSAP\, CGEIT\, CRISC\, HCISPP\, CRMA\, and CBCP is an internationally renowned expert on computers\, IT Risk management\, disaster recovery\, IT Security\, cyber security and IT controls. He has written and published more than 37 IT-related books on various subjects ranging from networks\, security\, mainframe/distributed operating systems\, and computer programming languages. He also has an imprint with McGraw-Hill with more than 300 books called the “Jay Ranade Series” with more than 7 million copies in print. His books have been translated in German\, Portuguese\, Spanish\, Japanese\, Chinese\, and Korean. The New York Times critically acclaimed his book called the “Best of Byte” with endorsements from Bill Gates and Steve Wozniak. \nJay has consulted and worked for Global and Fortune 500 companies in the US and abroad including AIG\, Merrill Lynch\, Dreyfus/Mellon Bank\, Johnson and Johnson\, Unisys\, McGraw-Hill\, Mobiltel Bulgaria\, Central Bank of Armenia\, and Credit Suisse. His classes and lectures have been attended by employees of almost every Fortune 500 company globally. \nHe teaches graduate-level classes on Information Security Management and Ethical Risk Management at New York University. Jay is also an adjunct professor at St John’s University and teaches graduate-level classes on Accounting Information Systems\, IT Auditing\, Internal Auditing\, Security/Forensics\, and Operational Risk Management. Jay is senior faculty member for Wharton Executive Education program for U of Penn. \nJay teaches ISACA credentialing courses (CISA\, CISM\, CRISC\, CGEIT\, CSX-F) and non-credentialing classes for ISACA NY Metropolitan chapter\, London\, Singapore\, Armenia\, Bangkok\, Bermuda\, Cayman Islands\, US Navy\, and US Army. \nJay was awarded President’s “Outstanding Educator Award” by ISACA NY Metropolitan Chapter in June 2013. \n \n\n  \nVirtual Meeting Information \n\n	This event will be presented through Zoom.\n	Prior to the event\, participants must install the Zoom app on their respective devices or use the web-based Zoom. Calling via the phone may not be entitled to CPE credits.\n	Participants must respond to all the poll questions via the Zoom polling feature or chat log in order to receive NASBA CPE credits.\n	The ISACA Greater Washington\, D.C. Chapter will not be responsible for the participant’s inability to respond to the polls.\n\n  \nEvent Questions and Policies \nRegistration Questions \nIf you have any registration questions about this event\, please contact the chapter using the Registration Contact Form. \nIf you have CPE questions after the event has concluded\, please contact the chapter using the CPE Contact Form. \n  \nCancellation and Refund Policy \nCancellation and refund for advance registrations is allowed if cancellations are submitted through the registration system. Refunds vary depending on the date of cancellation. See ISACA GWDC Event Policies for details. \nIf ISACA GWDC cancels the event\, all registrants will be notified as soon as possible through email at the email address provided during registration. Full refunds will be provided. \n  \nComplaint Policy \nThe GWDC welcomes your comments\, complaints\, suggestions\, questions\, and other feedback concerning our website information and services. All complaints should be submitted through the Registration Contact Form. \n  \nCPE Information \nEarn up to 4 Continuing Professional Education (CPE) credit in the area of Information Technology. The ISACA® Greater Washington\, D.C. Chapter is registered with the National Association of State Boards of Accountancy (NASBA) as a sponsor of continuing professional education on the National Registry of CPE Sponsors. State boards of accountancy have final authority on the acceptance of individual courses for CPE credit. Complaints regarding registered sponsors may be submitted to the National Registry of CPE Sponsors through its website: www.NASBARegistry.org \n  \nCPE Distribution and Evaluation Survey \nCPEs will be distributed via e-mail along with the event evaluation survey after the completion of the event. Attendees must be present for the full event to receive full CPE credit. \n  \nLearning Objective \nAfter attending this event\, attendees will learn about recent topics in the IT risk management and governance space. \n  \nCPE-Related Details \n\n	Prerequisites: None\n	Advance Preparation: None\n	Program Knowledge Level: Basic\n	Delivery Method:  Group Internet Based\n	Field of Study:  Information Technology – Technical
URL:https://isaca-gwdc.org/event/risk-management-conference-2024/
LOCATION:Virtual Event
CATEGORIES:Conferences
ATTACH;FMTTYPE=image/png:https://isaca-gwdc.org/wp-content/uploads/2023/10/conference-risk-2024.png
ORGANIZER;CN="Avneet Sabharwal":MAILTO:programs@isaca-gwdc.org
END:VEVENT
BEGIN:VEVENT
DTSTART;TZID=America/New_York:20240222T083000
DTEND;TZID=America/New_York:20240222T123000
DTSTAMP:20240221T152229Z
CREATED:20231029T214309Z
LAST-MODIFIED:20240221T152229Z
UID:31262-1708590600-1708605000@isaca-gwdc.org
SUMMARY:Emerging Technology Conference 2024
DESCRIPTION:The ISACA Greater Washington DC (GWDC) is proud to host our annual Emerging Technology conference. This conference is part of our monthly events. \nFraud and cybersecurity professionals\, IT advisory or audit professionals\, business executives\, students or professionals interested in learning more about new and emerging technologies should attend this event. \nRegistration closes on February 21\, 2024 @ 5pm.  \nRegister Today! \n  \nAgenda \n \n\n08:30 AM – 09:30 AM \n\n\nThe Impact of Emerging Technologies on Teams of the Future \nPresenter:  Michael Wasielewski (Capgemini) \nCyber security professionals have evolved over the decades and today’s emerging technologies have put us at another inflection point\, where the skills that serve us well now are not necessarily the same skills that we will need in the future. Frameworks and technologies like Zero Trust\, Automation with AI\, and now Generative AI are creating new opportunities for us to be more efficient and deliver better results\, but only if we know how to use them. This discussion will center around how these technologies impact the people and teams expected to use and secure them\, and how you can upskill yourself and your teams as these technologies support\, not replace\, all of us. \n\n \n\n\n09:30 AM – 10:30 AM \n\n\nZero Trust Application Framework\, Building Security without a Perimeter \nPresenter:  Nat Bongiovanni (NTT DATA Federal Services) \nZero-Trust is everywhere\, but how do you implement it in your applications with the flexibility and agility you need for complex authorization changes? In this presentation\, I’ll discuss how to do this by building cloud-ready Zero Trust Architecture (ZTA) applications. We will discuss the three components of Zero Trust that enable ZTA as well as the concepts and implementation of policy decision and enforcement points with examples\, covering NIST SP 800-204 a\, b\, and c. \n\n \n\n\n10:30 AM – 11:30 AM \n\n\nAI-Driven Cybersecurity: Empowering CIOs and CISOs for Enhanced Risk Management and Governance \nPresenter: Oki Mek (Microsoft) \nThe discussion will be the advent of emerging technologies\, big data\, and a diverse array of teams has amplified the complexities of cybersecurity. We will discuss how AI can empower CIOs and CISOs to do more with less by facilitating connections between people\, processes\, and technologies. AI can bridge the various entities that constitute a cybersecurity program\, such as governance\, compliance\, risk management\, change management\, incident management\, analysis\, dashboarding and reporting. Ultimately\, this session will elucidate how AI enables cybersecurity programs to manage risks in real-time and prioritize security activities. \n\n \n\n\n11:30 AM – 12:30 PM \n\n\nGenerative AI in Cybersecurity \nPresenter: Jim Wiggins (Federal IT Security Institute – FITSI) \nThis comprehensive presentation dives into the dynamic intersection of Generative AI and cybersecurity\, showcasing its transformative influence in modern digital defense strategies. It highlights how Generative AI is redefining threat detection\, streamlining policy frameworks\, and enhancing training approaches in cybersecurity. The session will also illuminate the complex ethical questions and privacy challenges posed by advanced AI technologies. Attendees will explore how these intelligent systems can be leveraged responsibly\, ensuring robust cyber defenses while maintaining ethical integrity. The discussion will include real-world applications\, demonstrating the practical impact of Generative AI in cybersecurity. This insightful exploration is designed to provide a deeper understanding of AI’s role in shaping future cybersecurity landscapes. \n\n  \nPresenters \n\n\n \n\n\nMichael Wasielewski\nHead of Cloud Security and Next-Gen Secure Architectures @ Capgemini \nMoving from outside of Washington D.C. in the US\, Michael moved to Paris joining Capgemini in December of 2021. Responsible for global cloud security and next-gen secure architecture portfolio development\, Michael brings a robust background ranging from Network Operations and Engineering\, running global Information Security teams and modernizing enterprises through their cloud and workplace journeys\, and executing as a global Cloud Security specialist. When not playing video games with his two kids or struggling to learn French\, Michael wishes he could play more golf or do some more skydiving. \n\n\n\n \n\n\nNat Bongiovanni\nCTO and CIO @ NTT DATA Federal Services\, Inc \nNat Bongiovanni is the CTO and CIO at NTT DATA Federal Services\, Inc. He is a veteran of the United States Navy with nearly 40 years of experience in the public and private sectors. Mr. Bongiovanni thrives on technical challenges and\, over the course of his extensive career\, has lent his considerable expertise to solving the most difficult challenges facing the government. \nMr. Bongiovani’s vast and varied technical acumen uniquely suits him to lead diverse teams across highly secure and regulated government environments. His thoughtful\, pragmatic nature combines with an encyclopedic knowledge of information technology to facilitate strategic growth in his current role. Under Nat’s leadership\, NTT DATA Federal Services\, the secure arm of a $1B public sector IT organization\, had grown exponentially while remaining compliant with the rules and regulations of a FOCI-mitigated organization. \nWhile it is impossible to list the many government clients impacted by Nat’s impeccable critical thinking skills and proven knowledge\, Nat and his teams have delivered successful programs at such notable government agencies as the Federal Bureau of Investigation\, Department of Homeland Security\, Defense Intelligence Agency\, Department of Interior\, and many others. Early in his career\, Mr. Bongiovanni held leadership positions at Blue Cross Blue Shield and Enterprise Rent-A-Car. \n\n\n\n \n\n\nOki Mek\nCISO @ Microsoft Federal Civilian Sector \nOki Mek recently joined Microsoft as Chief Information Security Officer for the Federal Civilian Sector. His civil servant career spans nearly 20 years inside the federal government. Oki is also a veteran of the Army National Guard\, who believes in service to others as a personal mission and purpose. Oki previously served as the Chief Information Security Officer (CISO) for Equideum Health. In his U.S Department of Health and Human Services (HHS) roles\, he served as the first appointed Chief Artificial Intelligence Officer (CAIO)\, Acting Chief Information Officer (CIO) for Office of the Secretary\, Senior Advisor to the HHS CIO\, Chief Technology Officer\, Chief Product Officer\, and Senior Information Security Manager. \n\n\n\n \n\n\nJim Wiggins\n Founder and Chief Executive Officer (CEO) @ the Federal IT Security Institute (FITSI)\nCISSP\, ISSEP\, CISM\, CISA\, CRISC\, CySA+\, SCNA\, SCNP\, CAP\, IAM\, IEM\, SSCP\, CEH\, ECSA\, CHFI\, LPT\, TICSA\, CIWSA\, Security+\, MCSE: Security\, FITSP-M \nJim has over 26 years of direct experience in the design\, operation\, management\, and auditing of information technology systems\, with the past 21 years focused on information systems security. He has an extensive background in technical education and specializes in security certification courses targeted at federal and government contracting clients. \nToday\, Jim is the Founder and Chief Executive Officer (CEO) of the Federal IT Security Institute (FITSI). FITSI is a 501(c)(6) non-profit certification body accredited by the ANSI National Accreditation Board (ANAB) under ISO 17024:2012. FITSI provides a role-based IT security certification program targeted at the federal workforce. More information on FITSI can be found at https://www.fitsi.org. \nJim is also the Founder and Executive Director of the FITSI Foundation. The FITSI Foundation is a 501(c)(3) public charity that focuses on cyber education and serves as the philanthropic sister organization of the Federal IT Security Institute. The FITSI Foundation operates the Wounded Warrior Cyber Combat Academy (W2CCA). More information on FITSI can be found at https://www.fitsi.org. \nAdditionally\, Jim is the Founder and Principal at Securible\, LLC. Securible is an information security service provider offering cyber training programs to organizations of all sizes. At Securible\, Jim has taught IT security certification courses such as CISSP\, CISM\, CISA\, Ethical Hacking\, RMF\, Security+\, and other courses requested by Securible’s clients. Currently\, Jim provides education and training support for the National Risk Management Center (NRMC) at the Cybersecurity and Infrastructure Security Agency (CISA) within the Department of Homeland Security (DHS). More information on Securible can be found at: https://www.securible.com. \nIn 2020\, Jim launched a TV show about cybersecurity called “Cybersecurity Today\,” which can be viewed in the Washington\, DC area. Episodes can also be streamed online at the following website: https://www.cybersecuritytoday.org. \nIn 2019\, FCW named Jim to the “Federal 100” for his tireless efforts to promote cybersecurity education across all branches of the federal government. \nIn 2011\, the Federal Information Systems Security Educators’ Association (FISSEA) named him “Educator of the Year” for the ongoing impact he has made in the federal workforce. \nJim holds the following IA/IT security certifications: CISSP\, ISSEP\, CISM\, CISA\, CRISC\, CySA+\, SCNA\, SCNP\, CAP\, IAM\, IEM\, SSCP\, CEH\, ECSA\, CHFI\, LPT\, TICSA\, CIWSA\, Security+\, and MCSE: Security and FITSP-M. \n\n  \nVirtual Meeting Information \n\n	This event will be presented through Zoom.\n	Prior to the event\, participants must install the Zoom app on their respective devices or use the web-based Zoom. Calling via the phone may not be entitled to CPE credits.\n	Participants must respond to all the poll questions via the Zoom polling feature or chat log in order to receive NASBA CPE credits.\n	The ISACA Greater Washington\, D.C. Chapter will not be responsible for the participant’s inability to respond to the polls.\n\n  \nEvent Questions and Policies \nRegistration Questions \nIf you have any registration questions about this event\, please contact the chapter using the Registration Contact Form. \nIf you have CPE questions after the event has concluded\, please contact the chapter using the CPE Contact Form. \n  \nCancellation and Refund Policy \nCancellation and refund for advance registrations is allowed if cancellations are submitted through the registration system. Refunds vary depending on the date of cancellation. See ISACA GWDC Event Policies for details. \nIf ISACA GWDC cancels the event\, all registrants will be notified as soon as possible through email at the email address provided during registration. Full refunds will be provided. \n  \nComplaint Policy \nThe GWDC welcomes your comments\, complaints\, suggestions\, questions\, and other feedback concerning our website information and services. All complaints should be submitted through the Registration Contact Form. \n  \nCPE Information \nEarn up to 4 Continuing Professional Education (CPE) credit in the area of Information Technology. The ISACA® Greater Washington\, D.C. Chapter is registered with the National Association of State Boards of Accountancy (NASBA) as a sponsor of continuing professional education on the National Registry of CPE Sponsors. State boards of accountancy have final authority on the acceptance of individual courses for CPE credit. Complaints regarding registered sponsors may be submitted to the National Registry of CPE Sponsors through its website: www.NASBARegistry.org \n  \nCPE Distribution and Evaluation Survey \nCPEs will be distributed via e-mail along with the event evaluation survey after the completion of the event. Attendees must be present for the full event to receive full CPE credit. \n  \nLearning Objective \nAfter attending this event\, attendees will learn about recent topics in the emerging technologies space. \n  \nCPE-Related Details \n\n	Prerequisites: None\n	Advance Preparation: None\n	Program Knowledge Level: Basic\n	Delivery Method:  Group Internet Based\n	Field of Study:  Information Technology – Technical
URL:https://isaca-gwdc.org/event/emerging-technology-conference-2024/
LOCATION:Virtual Event
CATEGORIES:Conferences
ATTACH;FMTTYPE=image/png:https://isaca-gwdc.org/wp-content/uploads/2023/10/emerging-technology-2024.png
ORGANIZER;CN="Avneet Sabharwal":MAILTO:programs@isaca-gwdc.org
END:VEVENT
BEGIN:VEVENT
DTSTART;TZID=America/New_York:20240118T083000
DTEND;TZID=America/New_York:20240118T123000
DTSTAMP:20240118T140553Z
CREATED:20231029T213337Z
LAST-MODIFIED:20240118T140553Z
UID:31256-1705566600-1705581000@isaca-gwdc.org
SUMMARY:IT Audit Conference 2024
DESCRIPTION:The ISACA Greater Washington DC (GWDC) is proud to host our annual IT Audit conference. This conference is part of our monthly conference series. \nIT professionals\, IT advisory or audit professionals\, business executives\, students or professionals interested in learning more about IT Audit should attend this event. \nRegistration closes on January 17\, 2024 @ 8pm.  \nRegister Today! \n  \nAgenda \n\n\n08:30 AM – 09:30 AM \n\n\nBuilding an API Audit Program \nPresenter: Baljeet Malhotra (TeejLab) \nAPIs benefit organizations immensely through accelerated innovations\, newer business models\, and competitive differentiation. However\, the growing API usage also means increased cybersecurity risks for enterprises. Given the importance of APIs in digital transformation at enterprises\, it is imperative for Audit Professionals to understand better various API risks that pose various challenges to their organizations. In this session\, we’ll first identify various risks that originate from within the enterprise API ecosystems. This session will then provide an overview of an API Auditing framework to manage API Risks effectively. Dr. Malhotra will also highlight best industry practices and hands-on examples for API Risk Management. \n\n\n\n09:30 AM – 10:30 AM \n\n\nUse of Agile Methodology in IT Audit \nPresenter: Jack Doyle (Kearney & Company) \nWhile Agile delivery approaches are normative in software development\, auditor and consultant usage is a mixed bag. This presentation is meant to inform assessors considering a change in project management style by describing agile\, reviewing key tenets of implementation\, and discussing experience using agile for assessments. The presentation should answer questions such as: \n\n	What is the value of changing from the existing approach?\n	How is this different from any other corporate project management vocabulary?\n	How and why does your team discuss project status?\n	What project management activities result in changes to delivery?\n	What are the use cases where this approach is best suited and how do you implement them?\n\n\n\n\n10:30 AM – 11:30 AM \n\n\nPrioritizing Enterprise Risks Using Data Normalization with Ken Squires \nPresenter: Ken Squires (Sikich) \nMany organizations have competing risk assessment remediation priorities with business objectives and regulatory requirements that are difficult to compare. Normalization techniques can collect and aggregate numerical risk values into comparable data to ensure the organization’s IT resources\, legal team\, C-Level executives\, and key stockholders can jointly prioritize the implementation of controls needed to mitigate risk to a reasonable level. \nAttendees will learn: \n\n	Define acceptable risk criteria that can be utilized as a data normalization technique\n	View a sample risk register populated with results from different assessments that have gone through the risk data normalization process.\n\n\n\n\n11:30 AM – 12:30 AM \n\n\nAdaptive Cybersecurity Risk Assessments \nPresenter: Gideon Rasmussen (Cybersecurity Management Consultant) \nThis session provides practical cybersecurity assessment advice. It details the end-to-end process\, including scoping\, 9 steps to develop work papers\, scheduling\, on-site assessment\, report preparation\, and presentation. \nThe first assessment example leverages the NIST Cybersecurity Framework to ensure coverage across security domains. Sample scoping questions will be provided\, along with tips and examples to add controls based on business processes\, insider threat\, privacy\, and fraud. \nThis session also addresses follow-on assessments. Attendees are encouraged to evaluate lines of business and to take deep dives into critical functions. Tips and examples are provided to leverage best practices\, creating specific testing procedures. \nRather than repeating the same assessment year-over-year\, the scoping methodology is risk opportunistic. There is a focus on areas that have not been evaluated recently and areas that may require enhanced controls due to the presence of valuable data. Albert Einstein’s quote applies here: “The definition of insanity is doing something over and over again and expecting different results”. \nThe session will briefly walk through the assessment report framework\, providing tips along the way. \nThe assessment presentation phase includes a slide deck framework covering: the threat landscape\, assessment methodology\, high and moderate-high findings\, a Strengths\, Weaknesses\, Opportunities and Threats (SWOT) slide and next steps. \n\n  \nPresenters \n  \n\n\n \n\n\nDr. Baljeet Malhotra\nFounder & CEO of TeejLab  \nDr. Baljeet Malhotra is an award-winning researcher and a global tech leader known for his work in Open Source and API Risk Management. He founded TeejLab in 2019 and steered the team to build API Discovery and Security™\, world’s first end-to-end API Risk Management platform. Prior to TeejLab\, he established the R&D unit of Black Duck Software in 2016 (acquired by Synopsys). He also served as Research Director at SAP and Senior Software Engineer at MahindraTech. He received a PhD in Computing Science from the University of Alberta and won several awards including NSERC (Canada) scholar and Global Young Scientist (Singapore). He concurrently holds Adjunct Professor positions at the University of British Columbia\, University of Victoria and University of Northern BC. He has given numerous talks globally that were organized by ISACA\, ISSA\, IIA\, ISC2\, OWASP and other organizations. \n \n\n  \n\n\n \n\n\nJack Doyle\nPrincipal @ Kearney & Company\nCPA\, CGFM\, CISA\, CISSP \nJack Doyle has 12 years of experience across financial statements\, IT controls audit\, GRC consulting\, and GRC software implementation. Jack is a Principal at Kearney & Company\, where he currently supports OCIO GRC clients at the National Institute of Health\, following experience in the HHS\, DHS\, DoD\, and Intel communities. \nJack is a proud graduate of Virginia Tech\, where he majored in accounting and philosophy. Jack grew up in northern Virginia but is loyal to his Massachusetts family roots for all things sports\, especially the Boston Celtics. Jack holds the following certifications: CPA\, CGFM\, CISA\, and CISSP. \n  \n\n\n\n \n\n\nKen Squires\nPartner of Governance\, Risk & Compliance @ Sikich\nCDPSE\, CISA\, CISSP\, CRISC\, HCISPP\, NSA IAM \nKen Squires is a Partner of Governance\, Risk\, and Compliance (GRC) at Sikich\, a leading professional services firm that helps clients achieve their goals in the digital age. With more than 26 years of risk management experience and multiple credentials\, such as CISSP\, HCISPP\, and CRISC\, he offers unparalleled strategic guidance to clients as they work to complete organizational cybersecurity objectives and navigate complex compliance requirements. \nAs a virtual Chief Information Security Officer (vCISO) for several companies\, he has managed multiple information security management systems based on ISO 27001\, NIST\, HITRUST\, HIPAA\, and PCI standards. He has also led internal and external vendor due diligence assessments\, presented findings and remediation projects to C-level sponsors and executive leadership teams\, and designed and implemented security policies and incident response plans. He has contributed intellectual capital to Sikich’s Professional Services Framework\, including reporting\, checklists\, templates\, testing methods and techniques\, and research. Ken’s mission is to help clients protect their data\, assets\, and reputation from cyber threats and regulatory risks. \n \n\n  \n\n\n \n\n\nGideon Rasmussen\nCybersecurity Management Consultant\nCISSP\, CRISC\, CISA\, CISM\, CIPP \nGideon Rasmussen is a Cybersecurity Management Consultant with over 20 years of experience in corporate and military organizations. Gideon has designed and led programs including Information Security (as a CISO)\, PCI – Payment Card Security\, Third Party Risk Management\, Application Security and Information Risk Management. Has diverse industry experience within banking\, insurance\, pharmaceuticals\, DoD/USAF\, state government\, advertising and talent management. \nGideon has authored over 30 information security articles. He is a veteran of the United States Air Force\, a graduate of the FBI Citizens Academy and a recipient of the Microsoft Most Valuable Professional award. Gideon has also completed the Bataan Memorial Death March (4 occurrences). \n \n\n  \nVirtual Meeting Information \n\n	This event will be presented through Zoom.\n	Prior to the event\, participants must install the Zoom app on their respective devices or use the web-based Zoom. Calling via the phone may not be entitled to CPE credits.\n	Participants must respond to all the poll questions via the Zoom polling feature or chat log in order to receive NASBA CPE credits.\n	The ISACA Greater Washington\, D.C. Chapter will not be responsible for the participant’s inability to respond to the polls.\n\n  \nEvent Questions and Policies \nRegistration Questions \nIf you have any registration questions about this event\, please contact the chapter using the Registration Contact Form. \nIf you have CPE questions after the event has concluded\, please contact the chapter using the CPE Contact Form. \n  \nCancellation and Refund Policy \nCancellation and refund for advance registrations is allowed if cancellations are submitted through the registration system. Refunds vary depending on the date of cancellation. See ISACA GWDC Event Policies for details. \nIf ISACA GWDC cancels the event\, all registrants will be notified as soon as possible through email at the email address provided during registration. Full refunds will be provided. \n  \nComplaint Policy \nThe GWDC welcomes your comments\, complaints\, suggestions\, questions\, and other feedback concerning our website information and services. All complaints should be submitted through the Registration Contact Form. \n  \nCPE Information \nEarn up to 4 Continuing Professional Education (CPE) credit in the area of Information Technology. The ISACA® Greater Washington\, D.C. Chapter is registered with the National Association of State Boards of Accountancy (NASBA) as a sponsor of continuing professional education on the National Registry of CPE Sponsors. State boards of accountancy have final authority on the acceptance of individual courses for CPE credit. Complaints regarding registered sponsors may be submitted to the National Registry of CPE Sponsors through its website: www.NASBARegistry.org \n  \nCPE Distribution and Evaluation Survey \nCPEs will be distributed via e-mail along with the event evaluation survey after the completion of the event. Attendees must be present for the full event to receive full CPE credit. \n  \nLearning Objective \nAfter attending this event\, attendees will learn about recent topics in the IT Audit space. \n  \nCPE-Related Details \n\n	Prerequisites: None\n	Advance Preparation: None\n	Program Knowledge Level: Basic\n	Delivery Method:  Group Internet Based\n	Field of Study:  Information Technology – Technical
URL:https://isaca-gwdc.org/event/it-audit-conference-2024/
LOCATION:Virtual Event
CATEGORIES:Conferences
ATTACH;FMTTYPE=image/png:https://isaca-gwdc.org/wp-content/uploads/2023/10/conference_itaudit_2024.png
ORGANIZER;CN="Avneet Sabharwal":MAILTO:programs@isaca-gwdc.org
END:VEVENT
BEGIN:VEVENT
DTSTART;TZID=America/New_York:20231207T083000
DTEND;TZID=America/New_York:20231207T123000
DTSTAMP:20231206T180223Z
CREATED:20231029T212110Z
LAST-MODIFIED:20231206T180223Z
UID:31252-1701937800-1701952200@isaca-gwdc.org
SUMMARY:Security and Risk Trends - Recap of 2023 with a Look ahead to 2024
DESCRIPTION:The ISACA Greater Washington DC (GWDC) proudly hosts the 2023 Security and Risk Trends conference. This seminar will recap cybersecurity and risk trends noted/experienced in 2023 and look ahead to what to expect in 2024. This virtual conference is part of our monthly conference series. \nBusiness leaders and managers\, executives\, technologists\, professionals\, and students\, interested in staying current in the field of cybersecurity and risk governance should attend this conference. \nRegistration closes on December 6\, 2023 @ 2pm.  \nRegister Today! \n  \nAgenda \n\n\n08:30 AM – 09:30 AM \n\n\n2023 Unlocked\, 2024 Unleashed \nPresenter: Sushila Nair (Capgemini) \nIn a world where cybersecurity threats are evolving rapidly\, understanding the landscape of the past and anticipating future challenges is crucial for organizational resilience. “2023 Unlocked\, 2024 Unleashed: Navigating the Future of Security and Risk” is a comprehensive presentation that delves into the significant security trends in 2023\, evaluates effective strategies for security budget allocation\, and forecasts the security and risk management landscape for 2024. \nThis presentation will recapitulate critical security incidents and technological advancements of 2023\, highlighting how they have reshaped the security domain. It will also delve into strategies for effective budget allocation in security spending\, providing insights into optimizing resources for maximum protection. The presentation will offer predictions for 2024\, focusing on anticipated threats\, emerging technologies\, and financial planning strategies. Attendees will leave with a holistic understanding of the security field and actionable strategies for the upcoming year. \nThis presentation aims to equip attendees with a thorough understanding of the current security environment and provide them with the tools and knowledge needed to prepare for the future effectively. \n\n\n\n09:30 AM – 10:30 AM \n\n\nSecuring Tomorrow’s Future in Education \nPresenter: VJ Rao (Fairfax County Public Schools) \n“Securing Tomorrow’s Future in Education” is a crucial exploration into the cybersecurity challenges and strategies within the K-12 education sector\, emphasizing the experiences of Fairfax County Public Schools. This presentation navigates the intricate digital ecosystem of today’s educational environment\, unraveling the complexities of maintaining a secure and resilient cyber infrastructure in a large and diverse school system. \nThe talk will discuss the state of K-12 cybersecurity and spotlight the recent trends and unique threats that schools face\, from protecting sensitive student data to ensuring safe digital learning spaces. It will also delve into the risks and vulnerabilities inherent in the educational sector’s technology use\, discussing how to safeguard effectively against breaches and cyber threats while prioritizing student privacy and safety. \n\n\n\n10:30 AM – 11:30 AM \n\n\nThe Digital Trust Gap: How Cyber Pros Break Silos to Advance Digital Trust \nPresenter: Pam Nigro (Medecision) \nDigital trust is sometimes misunderstood as a cybersecurity function; it’s really a part of an ecosystem that harnesses privacy\, quality\, assurance\, risk\, and governance to strengthen your enterprise and consumer trust. Learn how cyber professionals can communicate and collaborate with other IT functions in the digital trust ecosystem\, and gain access to a new digital trust ecosystem framework. \n\n\n\n11:30 AM – 12:30 PM \n\n\nPanel Discussion: Navigating the Shifting Cybersecurity Landscape: Insights from Top CISOs \nModerator: Ruchi Shewaramani \nPanelists: Lakshmi Hanspal\, Anne Saunders (Capgemini)\, and Zac Warren (TANIUM) \nCybersecurity is a critical pillar of organizational resilience and operational integrity in a rapidly evolving digital world. The panel discussion “Navigating the Shifting Cybersecurity Landscape: Insights from Top CISOs\,” part of the “Security and Risk Trends – Recap of 2023 with a Look Ahead to 2024” conference\, promises to offer unparalleled insights into the world of cybersecurity as seen through the eyes of experienced Chief Information Security Officers. \nThis 50-minute session will bring together a panel of distinguished CISOs and former CISOs from various industries to discuss and dissect the significant cybersecurity events and trends 2023. The panelists will share their firsthand experiences\, challenges\, and successful strategies implemented in their organizations. This retrospective look will provide valuable lessons learned and insights into the evolving nature of cyber threats and defense mechanisms. \n\n  \nPresenters \n\n\n \n\n\nSushila Nair\nVice President – North American Cybersecurity Practice @ Capgemini \nCISSP\, GIAC GSTRT\, CISA\, CISM\, CRISC\, CDPSE\, CCSK\, CCAK \nSushila Nair is Capgemini’s Vice President\, North American Cybersecurity practice. Capgemini is a global leader in providing secure digital transformation for our clients. Sushila has most recently served as the Vice President for cybersecurity offers at NTT Data Services and has held the role of a CISO for 10 years. Sushila has over 30 years of experience in computing infrastructure\, business and security risk analysis\, preventing credit card fraud\, and served as a legal expert witness. Sushila has been featured in global technical events including RSA\, Segurinfo and ISACA’s global conferences\, co-authored books and is regularly quoted in the press. She plays an active role in supporting best practices and skills development within the cybersecurity community through her work with ISACA and CSA. \nSushila is part of the ISACA global emerging trends working group. Sushila Nair was named by IT Security Guru as one of the Most Inspiring Women in Cyber 2022! Sushila is also the current Vice President of the ISACA Greater Washington D.C. Chapter. \n  \n\n\n\n \n\n\nVJ Rao\nDirector of Cybersecurity @ Fairfax County Public Schools \nVJ Rao currently oversees information security for Fairfax County Public Schools (FCPS). He is a widely respected cyber-security leader who joins the school division with over 20 years of experience. He also served as the Chief Information Security Officer for the 2016 and 2020 Presidential and Vice-Presidential Debates. \nBefore FCPS\, VJ worked at the Washington Metropolitan Area Transit Authority (WMATA) and served as Deputy Chief Technology Officer at the National Democratic Institute. As an industry expert on cyber risk\, VJ has conducted several security audits and risk assessments for organizations ranging from large banks to federal\, local\, and state governments. He regularly speaks on security matters\, and his efforts have been profiled in several technology articles. \n\n\n\n \n\n\nPam Nigro\nVice President of Security and Security Officer @ Medecision\nCRMA\, CISA\, CGEIT\, CRISC\, CDPSE \nPamela (Pam) Nigro\, CRMA\, CISA\, CGEIT\, CRISC\, CDPSE\, was recently named Security’s 2023 Top Cybersecurity Leaders by Security Magazine. Ms. Nigro serves on the Board of Directors for ISACA as Director\, where she was the Chair from 2022 2023. Presently\, Ms. Nigro is Vice President of Security at Medecision where she is responsible for all cyber security efforts that secure and protect information important to Medecision and its customers\, while ensuring the overall cyber resiliency of the company. Ms. Nigro is also an Adjunct Professor at Lewis University in Illinois where she teaches in the MSIS and MBA programs. Ms. Nigro has achieved her MBA from Illinois Institute of Technology. She has more than 25 years of experience in the healthcare industry and the information technology industry and holds numerous IT certifications. \n\n\n\n \n\n\nRuchi Shewaramani\nChief Information Security Officer at WA Health Benefit Exchange \nRuchi Shewaramani is a cyber security executive with 15+ years of experience in Information Technology Security\, Identity and Access Management (IAM)\, Governance\, Risk and Compliance (GRC) across Healthcare\, Education and Financial institutions. She holds a Masters in Software Engineering from Seattle U. In the last decade\, she has managed the security program for various Health and Human Services Agencies in the District of Columbia (DC) and Washington state and successfully cleared numerous federal audits. She specializes in leading HealthCare agencies to secure their data\, be compliant with state/federal partners and provide digital trust to the citizens they serve. She is currently serving as the Chief Information Security Officer for WA Health Benefit Exchange and as a Board member for ISACA Greater Washington DC Chapter. \n\n\n \n\n\nLakshmi Hanspal \nLakshmi Hanspal is the former Chief Information Security Officer of Amazon Devices and Services\, leading the Trust and Security team across multiple security and privacy domains\, including Cyber\, Customer\, Product\, Platform\, Risk and Assurance\, Compliance\, Data Protection\, and Finance. Lakshmi is a persuasive and recognized executive leader who provides transformational leadership for security strategies\, emphasizing cloud security\, risk\, and privacy management. She has a strong ability to engage with customers and senior-level executives across the organization and influence buy-in and consensus on key initiatives. Lakshmi is passionate about securing digital transformation\, IoT security\, and supporting socially conscious connected commerce. She actively engages and promotes Women in technical leadership roles and develops early talent for diversity within teams. Lakshmi is a catalyst and harbinger of change within her professional and volunteering circles. \nBefore joining Amazon\, Lakshmi was the Global CSO at Box\, where she protected a large dynamic cloud content platform with more than 100k+ customers. Lakshmi has also held leadership roles at SAP\, PayPal\, and Bank of America. Her career spans across 26+ years in Information Security and risk management\, with 16+ years in the financial and payment space. \nLakshmi is a graduate of Boston University with a Masters in Computer Science. She is an actively sought-after advisor and investor in Silicon Valley. She serves on the Advisory Boards and Board of Directors of innovative mission-based organizations and non-profits\, ready for growth and scale. She lives in California’s Bay Area with her family and is an active volunteer within the community in youth sports. \n\n\n \n\n\nAnne Saunders\nGlobal Director\, Cybersecurity Technology Partnerships @ Capgemini  \nAs a senior executive\, Anne’s career encompasses more than 15 years of cybersecurity experience working in various capacities including leadership\, solution design\, sales engineering and business development. Anne has worked to bring cybersecurity solutions to a variety of verticals including retail\, financial services\, manufacturing and technology. \nIn her current role for Capgemini\, (formerly Leidos Cyber)\, Saunders manages the global cybersecurity channel and technology portfolio. With a deep understanding of the entire cybersecurity life cycle\, she actively assists in bringing the right mix of technology\, value and solution design to help multimillion dollar enterprises with their cybersecurity roadmap and solution decision-making. Saunders also takes an active role in the cybersecurity community speaking at various conferences throughout the year\, including the RSA conference and Blackhat. \nPrior to\, and during her current role\, Saunders has sat on numerous advisory boards ranging from start-ups to regionally established security firms. Her knowledge of business operations and value-building\, coupled with her engineering and security operations background give her a unique ability to understand the business landscape to execute the correct cybersecurity strategies. \n\n\n \n\n\nZac Warren\nChief Information Security Advisor EMEA @ TANIUM \nZac Warren\, Chief Security Advisor in EMEA\, is a seasoned cybersecurity professional with a rich background in IT. Beginning as a senior security analyst at a leading security company\, Zac evolved into a cybersecurity architect and consultant for major system integrators. His career has been marked by transformative contributions\, assisting government agencies and Fortune 100 companies in restructuring security frameworks. Currently spearheading Tanium’s cybersecurity endeavors in EMEA\, Zac is dedicated to developing and supporting the company’s cybersecurity business as well as guiding organizations to stay ahead in the ever-evolving realm of cybersecurity. \n\n  \nVirtual Meeting Information \n\n	This event will be presented through Zoom.\n	Prior to the event\, participants must install the Zoom app on their respective devices or use the web-based Zoom. Calling via the phone may not be entitled to CPE credits.\n	Participants must respond to all the poll questions via the Zoom polling feature or chat log in order to receive NASBA CPE credits.\n	The ISACA Greater Washington\, D.C. Chapter will not be responsible for the participant’s inability to respond to the polls.\n\n  \nEvent Questions and Policies \nRegistration Questions \nIf you have any registration questions about this event\, please contact the chapter using the Registration Contact Form. \nIf you have CPE questions after the event has concluded\, please contact the chapter using the CPE Contact Form. \n  \nCancellation and Refund Policy \nCancellation and refund for advance registrations is allowed if cancellations are submitted through the registration system. Refunds vary depending on the date of cancellation. See ISACA GWDC Event Policies for details. \nIf ISACA GWDC cancels the event\, all registrants will be notified as soon as possible through email at the email address provided during registration. Full refunds will be provided. \n  \nComplaint Policy \nThe GWDC welcomes your comments\, complaints\, suggestions\, questions\, and other feedback concerning our website information and services. All complaints should be submitted through the Registration Contact Form. \n  \nCPE Information \nEarn up to 4 Continuing Professional Education (CPE) credit in the area of Information Technology. The ISACA® Greater Washington\, D.C. Chapter is registered with the National Association of State Boards of Accountancy (NASBA) as a sponsor of continuing professional education on the National Registry of CPE Sponsors. State boards of accountancy have final authority on the acceptance of individual courses for CPE credit. Complaints regarding registered sponsors may be submitted to the National Registry of CPE Sponsors through its website: www.NASBARegistry.org \n  \nCPE Distribution and Evaluation Survey \nCPEs will be distributed via e-mail along with the event evaluation survey after the completion of the event. Attendees must be present for the full event to receive full CPE credit. \n  \nLearning Objective \nAfter attending this event\, attendees will learn about recent topics in the cybersecurity and risk governance space. \n  \nCPE-Related Details \n\n	Prerequisites: None\n	Advance Preparation: None\n	Program Knowledge Level: Basic\n	Delivery Method:  Group Internet Based\n	Field of Study:  Information Technology – Technical
URL:https://isaca-gwdc.org/event/security-risk-trends-2023/
LOCATION:Virtual Event
CATEGORIES:Conferences
ATTACH;FMTTYPE=image/png:https://isaca-gwdc.org/wp-content/uploads/2023/10/conference-security-trends-2023.png
ORGANIZER;CN="Avneet Sabharwal":MAILTO:programs@isaca-gwdc.org
END:VEVENT
BEGIN:VEVENT
DTSTART;TZID=America/New_York:20231026T083000
DTEND;TZID=America/New_York:20231026T123000
DTSTAMP:20231029T161617Z
CREATED:20230917T140521Z
LAST-MODIFIED:20231029T161617Z
UID:30901-1698309000-1698323400@isaca-gwdc.org
SUMMARY:Cybersecurity 2023 Conference
DESCRIPTION:The GWDC is proud to host its annual cybersecurity conference. This virtual conference is part of our monthly conference series. \nBusiness leaders and managers\, executives\, technologists\, professionals\, and students\, interested in staying current in the field of cybersecurity should attend this conference. \nRegistration closes on October 25\, 2023 @ 12pm.  \nRegister Today! \n\nDate Change for this event! \nPlease note that this event is now scheduled to be held on October 26\, 2023. The event was previously advertised to occur on October 12th. \n\n  \nAgenda \n\n08:30 AM – 09:30 AM \n\n\nUsing Generative AI to Strengthen Cybersecurity – How IT professionals can balance its risks and rewards \nPresenter: Nirali Chawla (KPMG US) and Joseph Klimavicz (KPMG US) \nGenerative AI is a game-changing technology\, offering innovative ways to engage users and generate content with deeper insights. It is opening up entirely new avenues for improving experiences\, delivering new value streams and transforming business models. KPMG will discuss some opportunities for generative AI to enable cybersecurity to help business leaders harness the power of AI and associated risks to accelerate time-to-value in a trusted manner – from strategy and design through implementation and ongoing operations. \n\n\n09:30 AM – 10:30 AM \n\n\nViews from the Cloud: Cybersecurity and the Next Regulatory Frontier \nPresenter: Alexis Robinson (AWS) \nTopic description to be posted soon! \n\n\n10:30 AM – 11:30 PM \n\n\nSecurity Assessments – Pathway to Zero Trust \nPresenter: Albert E. Whale (Capgemini America) \nIn the presentation titled “Security Assessment – Pathway to Zero Trust\,” we delve into the evolving cybersecurity landscape\, emphasizing the insufficiencies of traditional Security Assessments and the necessity for a more robust approach\, the Zero Trust Model. Rooted in the principle “Never Trust\, Always Verify\,” Zero Trust demands no inherent trust\, advocating for micro segmentation and continuous monitoring. \nOur exploration underscores the role of security assessments in successfully transitioning to this model\, encompassing tasks like mapping current infrastructure\, pinpointing sensitive data\, reviewing policies\, designing segmented access\, and implementing real-time monitoring. By addressing challenges such as organizational resistance and technological integration\, and highlighting the overarching benefits of an enhanced security posture\, we aim to provide attendees with a comprehensive overview and a roadmap to begin their Zero Trust journey. \n\n\n11:30 AM – 12:30 PM \n\n\nWorking backwards with AWS Customer Compliance Guides to accelerate security assessments \nPresenter: Kevin Donohue (AWS) \nThe rapid increase in the number of innovative cloud service offerings has blurred the lines between traditional cloud service models like IaaS\, PaaS and SaaS. When looking at cloud services through the lens of compliance\, categorizing them becomes less important than applying the shared responsibility model to security control requirements. Establishing a clear understanding of security responsibilities based on the services in your workload is key to reducing compliance challenges. \nIn this presentation\, we’ll demonstrate how AWS Customer Compliance Guides make shared responsibility and compliance easier for customers interpret and integrate into their organization’s cloud strategy. We’ll demonstrate how the approach of working backwards from the security options you have for each service and mapping them to security standards can help accelerate your compliance initiatives. \n\n  \nPresenters \n\n \n\n\nNirali Chawla\nManaging Director\, Federal Advisory Services @ KMPG US\nCISSP\, CISA\, CRISC\, CAP\, ITIL\, and Six Sigma Green Belt \nNirali Shah Chawla is a Managing Director in KPMG’s Federal Advisory practice with more than 20 years of experience providing a wide range of services to private and public sector clients including financial and information technology audit readiness services\, information assurance and Cyber security services\, Governance\, Risk & Compliance implementations and programs\, Cloud Computing and transformation consulting services. Ms. Chawla currently leads some of the largest federal agencies at the brink of transformational change and growth\, leveraging her knowledge of existing and emerging technologies to uncover IT opportunities for business process and internal controls improvements. Ms. Chawla is the co-author of NIST Special Publication 800-137\, Information Security Continuous Monitoring (ISCM) for Federal Information Systems and Organizations\, and holds certifications such as the CISSP\, CISA\, CRISC\, CAP\, ITIL\, and Six Sigma Green Belt. Ms. Chawla is a recognized industry leader in the Information Technology Risk Management and transformation field\, speaking at industry conferences and instructing training seminars. \nMs. Chawla is the ISACA GWDC Director of Marketing\, AFCEA Scholarships Education Committee Chair\, Member of Cyber Council for INSA and on the Steering Committee for a non-profit organization\, Vicente Ferrer Foundation (VFF). She is also a member of the following organizations: ASMC\, NAASA and Women in Technology (WIT). \n\n\n \n\n\nJoseph Klimavicz\nManaging Director\, Federal Advisory Services @ KMPG US \nMr. Joseph Klimavicz joined KPMG LLP as a Managing Director in March 2020. In this position\, he leads the Federal Technology Advisory practice and helps government clients implement digital transformations and deal with rapidly changing technology\, growing complexities from budget constraints\, competing agendas\, and continuous attacks on their information infrastructure. \nMr. Klimavicz previously served as the Department of Justice (DOJ) Deputy Assistant Attorney General and CIO from May 2014 until March 2020. In this position\, he provided leadership and oversight of the Department’s information and technology programs and implemented large-scale and complex digital transformations. He also served as DOJ’s Chief Data Officer\, Senior Agency Official for Geospatial Information\, and executive responsible for both radio frequency spectrum and all technical standards. In addition\, he served as vice-chair of the Federal CIO Council. \nMr. Klimavicz’s 37-year career in the federal government began with the Central Intelligence Agency (CIA) as an imagery scientist. He subsequently served in line management positions within the CIA and the Department of Defense (DOD) leading information technology programs\, to include serving as the National Geospatial-Intelligence Agency Deputy CIO. Mr. Klimavicz also served as National Oceanic and Atmospheric Administration (NOAA) CIO and Director\, High Performance Computing and Communications from January 2007 until May 2014. \n\n\n \n\n\nAlexis Robinson\nSenior Manager\, Industry Specialist @ AWS\nCISA\, PMP\, MBA \nAlexis Robinson is a Senior Manager\, Industry Specialist for Amazon Web Services (AWS) Security Assurance in the Washington\, DC area. For the past 15 years\, she has served her clients\, buyers of the cloud\, and AWS Partners by enabling strategies based on security best practices\, collaborating for thought leadership\, solving problems\, and conducting cybersecurity and financial assessments. She graduated with double Bachelors of Science degrees in Accounting and Information Systems from the Robert H. Smith School of Business at University of Maryland\, College Park. She most recently graduated from Quantic with an Executive Masters in Business Administration. She has worked at several companies including CGI Federal and Ernst & Young before finding her way to Amazon. She is a Certified Information Systems Auditor (CISA) and a Project Management Professional (PMP). \nOn her free time\, she is playing video games\, watching “Bob’s Burgers”\, “Ted Lasso”\, “Demon Slayer”\, “Abbott Elementary” and “It’s Always Sunny in Philadelphia”. She lives with her husband and son in Maryland. \n\n\n \n\n\nAlbert E. Whale\nSenior Cloud Security / Zero Trust Architect @ Capgemini America\, Inc.\nCISSP\, CEH \nAlbert E. Whale is a Certified Global Coach at Napoleon Hill Institute\, where he support others in their personal development to live their dreams. With over 20 years of experience in cybersecurity\, IT security\, and entrepreneurship\, he has a unique perspective and skill set to help clients achieve their goals and overcome challenges. \nMr. Whale is also a #1 International Best Selling Author of the sequel book #HACKED2\, written with 12 esteemed cybersecurity professionals who offer their views and insights on how to protect personal and business information from cyber threats. He is passionate about sharing his knowledge and experience with others\, and regularly speak at events\, webinars\, podcasts\, and media outlets on topics related to cybersecurity\, personal development\, and entrepreneurship. \n\n\n \n\n\nKevin Donohue\nSecurity Partner Strategist\, Global Security & Compliance Acceleration team @ AWS \nCISSP \nKevin is a Sr. Security Partner Strategist on the AWS Global Security & Compliance Acceleration team\, specializing in shared responsibility and regulatory compliance support for AWS customers and partners. Kevin began his tenure with AWS in 2019 with the AWS FedRAMP program\, where he created Customer Compliance Guides to assist U.S. government customers with their assessment & authorization responsibilities. Prior to AWS\, Kevin worked at PwC in their commercial cybersecurity practice performing risk and compliance assessments across various security standards and industries. Kevin began is security career as a security control assessor at the U.S. Department of State. Kevin holds a B.A. in Political Science and Middle Eastern Studies from Rutgers University and M.S. Management of Security Information Systems from George Mason University. \nIn his spare time\, he enjoys taking advantage of everything to do in DC area from museums to biking with his wife Shannon and daughter Madeline. Originally from New Jersey\, Kevin has been in the DMV for 12 years and currently resides in Alexandria. \n\n  \nVirtual Meeting Information \n\n	This event will be presented through Zoom.\n	Prior to the event\, participants must install the Zoom app on their respective devices or use the web-based Zoom. Calling via the phone may not be entitled to CPE credits.\n	Participants must respond to all the poll questions via the Zoom polling feature or chat log in order to receive NASBA CPE credits.\n	The ISACA Greater Washington\, D.C. Chapter will not be responsible for the participant’s inability to respond to the polls.\n\n  \nEvent Questions and Policies \nRegistration Questions \nIf you have any registration questions about this event\, please contact the chapter using the Registration Contact Form. \nIf you have CPE questions after the event has concluded\, please contact the chapter using the CPE Contact Form. \n  \nCancellation and Refund Policy \nCancellation and refund for advance registrations is allowed if cancellations are submitted through the registration system. Refunds vary depending on the date of cancellation. See ISACA GWDC Event Policies for details. \nIf ISACA GWDC cancels the event\, all registrants will be notified as soon as possible through email at the email address provided during registration. Full refunds will be provided. \n  \nComplaint Policy \nThe GWDC welcomes your comments\, complaints\, suggestions\, questions\, and other feedback concerning our website information and services. All complaints should be submitted through the Registration Contact Form. \n  \nCPE Information \nEarn up to 4 Continuing Professional Education (CPE) credit in the area of Information Technology. The ISACA® Greater Washington\, D.C. Chapter is registered with the National Association of State Boards of Accountancy (NASBA) as a sponsor of continuing professional education on the National Registry of CPE Sponsors. State boards of accountancy have final authority on the acceptance of individual courses for CPE credit. Complaints regarding registered sponsors may be submitted to the National Registry of CPE Sponsors through its website: www.NASBARegistry.org \n  \nCPE Distribution and Evaluation Survey \nCPEs will be distributed via e-mail along with the event evaluation survey after the completion of the event. Attendees must be present for the full event to receive full CPE credit. \n  \nLearning Objective \nAfter attending this event\, attendees will learn about recent topics in the cybersecurity space. \n  \nCPE-Related Details \n\n	Prerequisites: None\n	Advance Preparation: None\n	Program Knowledge Level: Basic\n	Delivery Method:  Group Internet Based\n	Field of Study:  Information Technology – Technical
URL:https://isaca-gwdc.org/event/2023-cybersecurity-conference/
LOCATION:Virtual Event
CATEGORIES:Conferences
ATTACH;FMTTYPE=image/png:https://isaca-gwdc.org/wp-content/uploads/2023/09/cybersecurity_2023-1.png
ORGANIZER;CN="Avneet Sabharwal":MAILTO:programs@isaca-gwdc.org
END:VEVENT
BEGIN:VEVENT
DTSTART;TZID=America/New_York:20230928T083000
DTEND;TZID=America/New_York:20230928T123000
DTSTAMP:20230927T230806Z
CREATED:20230917T140643Z
LAST-MODIFIED:20230927T230806Z
UID:30895-1695889800-1695904200@isaca-gwdc.org
SUMMARY:Cloud Security 2023 Conference
DESCRIPTION:The GWDC is proud to partner with the DC Chapter of the Cloud Security Alliance to host its annual cloud conference\, Cloud Security 2023. This virtual conference is part of our monthly conference series. \nCloud security and enablement professionals\, IT advisory or audit professionals\, business executives\, cybersecurity professionals\, students or professionals interested in learning more about cloud security should attend this conference. \nRegistration closes on September 27\, 2023 @ 12pm.  \nRegister Today! \n  \nEvent Partner \nThe GWDC is proud to have the DC Chapter of the Cloud Security Alliance as a partner for this event.  For more information on the CSA DC Chapter\, please visit their website at https://cloudsecurityalliance-dc.org/home. \n \n  \nAgenda \n\n08:30 AM – 09:30 AM \n\n\nWho’s Vulnerable in YOUR IT Supply Chain? \nPresenter: David Barnscome (Microsoft) \n“Compromise one to compromise many.” More and more frequently\, nation-state attackers leverage the trusted relationships in an organization’s IT supply chain to achieve compromise of downstream targets. How can you take steps to protect against this type of activity? \nIn this discussion\, we’ll look at some interesting examples of how supply chain compromise has been achieved\, and what it eventually led to. More importantly\, we’ll talk about how you can assess your IT suppliers so that you can have confidence that they are taking the right steps to protect your organization’s data estate. \n\n\n09:30 AM – 10:30 AM \n\n\nThreat Intelligence Integration \nPresenter: George Alves (Defense Acquisition University) \nGeorge Alves discusses how being “threat informed” is critical in the execution of your Zero Trust capabilities and activities whether on-prem or in the cloud. From the Zero Trust Capability Roadmap: this capability requires integration of threat intelligence information and streams about identities\, motivations\, characteristics\, as well as tactics\, techniques\, and procedures (TTPs). This capability will assist Cyber Defenders be more proactive rather than reactive. \n\n\n10:30 AM – 11:30 PM \n\n\nCloud Adversarial Vectors\, Exploits\, and Threats (CAVEaT™): An Emerging Threat Matrix for Industry Collaboration \nPresenter: Dr. Mari J. Spina (CSA DC Chapter and MITRE) \nCloud security practitioners agree there’s a need for comprehensive threat-informed security guidance to address system assessment\, secure design\, cyber analytics\, and threat mitigation. Due to the rapid development of cloud technologies and service offerings\, it is also necessary to develop a forward-looking adversary perspective that identifies emerging cloud service risks along with detailed detections and mitigations for practitioners to implement. The Cloud Security Alliance (CSA) and the MITRE Corporation have established the Cloud Adversarial\, Vectors\, Exploits\, and Threats (CAVEaT™) collaboration to bring relevant content to the cloud security practitioner. This research explores today’s available frameworks with relevance to cloud systems and proposes a course of action to advance the state of the art in threat-informed security by collaborating with cloud service providers (CSPs)\, international security researchers\, and key subject matter experts. \n\n\n11:30 AM – 12:30 PM \n\n\nContinuous Compliance – Security Assessments the Cloud-Native Way \nPresenter: Michael Wasielewski (Capgemini) \nSecurity assessments for cloud environments have and continue to evolve at a dramatic rate. Just a few years ago security standards for cloud environments were difficult to understand and even more difficult to audit against. Since then\, cloud service providers and their partners have built tools to simplify auditability for their customers and auditors alike; but the pace of change in and of modern cloud environments still vexes many traditional assessment practices. In this talk\, we’ll cover how the next generation of audit tools are adopting a continuous compliance approach for evaluating cloud environments in near-real time\, and how to think differently about what artifacts can demonstrate real risk management as opposed to point in time theater. By the end of the session you’ll better understand how to approach security assessments for modern cloud environments. \n\n  \nPresenters \n\n    \n\n\nDavid Barnscome\nGlobal Partner Solutions Architect for Security\, Compliance\, and Identity @ Microsoft \nDavid is a Global Partner Solutions Architect for Security\, Compliance\, and Identity at Microsoft. In this role\, David is responsible for training and supporting Microsoft partners on the latest security compliance and identity solutions\, including Microsoft 365\, Azure and Windows. \n  \n\n\n \n\n\nGeorge Alves\nProfessor\, Enterprise Cybersecurity @ Defense Acquisition University (DAU)\nCISSP\, CEH \nGeorge Alves has over 35 years of DOD and Acquisition experience. Currently he is a Defense Acquisition University (DAU) Cybersecurity Professor. He holds a Master of Science in Cybersecurity along with various professional certifications such as CISSP and CEH. Before coming to DAU\, he served as the Information Systems Security Manager (ISSM) at the Office of the Comptroller of the Currency under Department of Treasury overseeing IT/Cyber acquisitions and compliance throughout several platforms to include public and private cloud environments. He is a former Navy Civilian of 10 years to include being the Deputy CIO for Cybersecurity at Naval Sea Systems Command HQ in Washington Navy Yard\, DC. There he oversaw the entire NAVSEA enterprise comprised of over 2000 operational\, developmental\, and RDT&E networks\, systems\, and applications both on-premise and in cloud environments. He had a team of almost 40 civilians and contractors to include the first NAVSEA Cyber Scientific & Technical Intelligence Liaison Officer (STILO) in a position he created to integrate intelligence within Cybersecurity. He also spent two years as an Army civilian supporting the Program Manager of DOD Biometrics as the Cybersecurity Lead under the Program Executive Office Intelligence Electronic Warfare and Sensors (PEO IEW&S). There he was involved in the early stages of acquisition supporting the designs\, engineers\, deployment\, and sustainment of enterprise biometric solutions in multiple operating environments enabling identity dominance on the battlefield and across the Department of Defense to include migrating tactical systems into the cloud. He is also a proud veteran retiring after 20 years of Navy active-duty service. Some of his assignments includes serving as the Automated Data Processing Division Officer onboard the USS NASSAU\, and as a Computer Network Defense Leading Chief Petty Officer within Joint Forces Command where he stood up a Global Command\, Control\, Communications\, Computers\, and Intelligence (C4I) Coordination Center after the 9/11 attack. \n\n\n \n\n\nDr. Mari J. Spina\nCloud Security Alliance-DC Chapter Research Committee Chair\nPrincipal Cybersecurity Engineer @ the MITRE Corp\nPMP\, CISSP\, ISSEP\, CCSP \nDr. Mari J. Spina is the Cloud Security Alliance-DC Chapter Reasearch Committee Chair. In this capacity\, she has been leading the charge to develop critical research to advance the state of practice in cloud security for highly regulated industries represented by the CSA-DC Chapter membership. Dr. Spina is also a Principal Cybersecurity Engineer at the MITRE Corp. supporting a multitude of MITRE Federal sponsors including DoD and the IC in the area of Cloud Security. At MITRE\, she leads the Cloud Security Capability Area\, and teaches Cloud Security for the MITRE Institute. She has taught many Information Technology courses for the George Washington University schools of engineering and business. Before joining MITRE\, she worked for government engineering firms including Hughes Aircraft\, SAIC\, ManTech\, NJVC\, and DMI since 1988 where she provided IT systems engineering to a variety of Federal agency missions including those of the Intelligence Community and the DoD. Mari holds a D.Sc. in Engineering Management from the George Washington University\, a MSEE from the University of Southern California\, and a BSME from California State University Northridge. She is also PMI PMP and ISC2 CISSP\, ISSEP\, CCSP certified. \n\n\n \n\n\nMichael Wasielewski\nCapgemini \nMoving from outside of Washington D.C. in the US\, Michael moved to Paris joining Capgemini in December of 2021. Responsible for global cloud security and next-gen secure architecture portfolio development\, Michael brings a robust background ranging from Network Operations and Engineering\, running global Information Security teams and modernizing enterprises through their cloud and workplace journeys\, and executing as a global Cloud Security specialist. When not playing video games with his two kids or struggling to learn French\, Michael wishes he could play more golf or do some more skydiving. \n\n  \nVirtual Meeting Information \n\n	This event will be presented through Zoom.\n	Prior to the event\, participants must install the Zoom app on their respective devices or use the web-based Zoom. Calling via the phone may not be entitled to CPE credits.\n	Participants must respond to all the poll questions via the Zoom polling feature or chat log in order to receive NASBA CPE credits.\n	The ISACA Greater Washington\, D.C. Chapter will not be responsible for the participant’s inability to respond to the polls.\n\n  \nEvent Questions and Policies \nRegistration Questions \nIf you have any registration questions about this event\, please contact the chapter using the Registration Contact Form. \nIf you have CPE questions after the event has concluded\, please contact the chapter using the CPE Contact Form. \n  \nCancellation and Refund Policy \nCancellation and refund for advance registrations is allowed if cancellations are submitted through the registration system. Refunds vary depending on the date of cancellation. See ISACA GWDC Event Policies for details. \nIf ISACA GWDC cancels the event\, all registrants will be notified as soon as possible through email at the email address provided during registration. Full refunds will be provided. \n  \nComplaint Policy \nThe GWDC welcomes your comments\, complaints\, suggestions\, questions\, and other feedback concerning our website information and services. All complaints should be submitted through the Registration Contact Form. \n  \nCPE Information \nEarn up to 4 Continuing Professional Education (CPE) credit in the area of Information Technology. The ISACA® Greater Washington\, D.C. Chapter is registered with the National Association of State Boards of Accountancy (NASBA) as a sponsor of continuing professional education on the National Registry of CPE Sponsors. State boards of accountancy have final authority on the acceptance of individual courses for CPE credit. Complaints regarding registered sponsors may be submitted to the National Registry of CPE Sponsors through its website: www.NASBARegistry.org \n  \nCPE Distribution and Evaluation Survey \nCPEs will be distributed via e-mail along with the event evaluation survey after the completion of the event. Attendees must be present for the full event to receive full CPE credit. \n  \nLearning Objective \nAfter attending this event\, attendees will learn about recent topics in the Cloud Security space. \n  \nCPE-Related Details \n\n	Prerequisites: None\n	Advance Preparation: None\n	Program Knowledge Level: Basic\n	Delivery Method:  Group Internet Based\n	Field of Study:  Information Technology – Technical
URL:https://isaca-gwdc.org/event/2023-cloud-security-conference/
LOCATION:Virtual Event
CATEGORIES:Conferences
ATTACH;FMTTYPE=image/png:https://isaca-gwdc.org/wp-content/uploads/2023/09/cloud_2023.png
ORGANIZER;CN="Avneet Sabharwal":MAILTO:programs@isaca-gwdc.org
END:VEVENT
BEGIN:VEVENT
DTSTART;TZID=America/New_York:20230831T083000
DTEND;TZID=America/New_York:20230831T123000
DTSTAMP:20230814T121341Z
CREATED:20230814T140007Z
LAST-MODIFIED:20230814T121341Z
UID:30741-1693470600-1693485000@isaca-gwdc.org
SUMMARY:2023 IT Fraud Virtual Conference with the ACFE
DESCRIPTION:Incidents of information technology being maliciously exploited reduce confidence and trust in the attacked organization’s security and operations. Cybersecurity Ventures estimates global cybercrime to cost $10.5 trillion annually by 2025. Join the Washington Metropolitan Chapter of the Association of Certified Fraud Examiners and ISACA Greater Washington DC chapter for their 2023 IT Fraud Virtual Conference.  Fraud and cybersecurity professionals\, IT advisory or audit professionals\, Business executives\, students or professionals interested in learning more about IT fraud should attend this event. \nTopics and presenters for this event are: \n\n	Cyber Risk and Financial Stability\nChris Wilson; Wilson Consulting\n	Framework for Managing Improper Payments in Emergency Assistance Programs\nSarah Garcia\, Johana Ayers\, and Daniel Flavin; United States Government Accountability Office\n	Anti Money Laundering Compliance Considerations in a Digital World\nGregory Schwarz; Guidehouse\n	Securities Fraud\nJames Park; UCLA School of Law\n\nAdvance registration is required. This event is free for GWDC members using the discount code that was provided via email.  If you did not receive the discount code\, please contact using the Registration Contact Form.  \nFor additional information\, including registration links\, please visit the ACFE website linked below.   \nRegister Today! \n  \nEvent Questions and Policies \nRegistration Questions \nIf you did not receive the email with the discount code for the event\, please contact us using the Registration Contact Form. \nAll other questions regarding the event\, registration\, and CPEs should be directed to the Washington Metropolitan Chapter of the ACFE. \n  \nCPEs  \nCPEs for this event will be issued by the Washington Metropolitan Chapter of the ACFE.
URL:https://isaca-gwdc.org/event/it-fraud-conference-with-acfe/
LOCATION:Virtual Event
CATEGORIES:Conferences
ORGANIZER;CN="Avneet Sabharwal":MAILTO:programs@isaca-gwdc.org
END:VEVENT
BEGIN:VEVENT
DTSTART;TZID=America/New_York:20230817T083000
DTEND;TZID=America/New_York:20230817T123000
DTSTAMP:20240911T155506Z
CREATED:20230715T153157Z
LAST-MODIFIED:20240911T155506Z
UID:30682-1692261000-1692275400@isaca-gwdc.org
SUMMARY:Summer Seminar - IT Modernization
DESCRIPTION:Join us for an exciting virtual summer seminar for an exciting event hosted by Guidehouse and the ISACA GWDC chapter focusing on the ever-relevant topic of IT modernization. This event brings together industry experts and government speakers to deliver insightful presentations on various aspects of IT modernization\, including its benefits\, challenges\, and risks as well as providing valuable insights to overcoming potential obstacles. \nAll information security program managers\, cybersecurity managers and professionals\, IT audit professionals\, business executives\, students and professionals interested in exploring the latest trends\, strategies\, and best practices in implementing and managing IT modernization initiatives should attend this event. \nRegistration closes on August 16\, 2023 @ 8pm.   This is a free virtual event. \nRegister Today! \n  \nEvent Sponsor \nThe GWDC is once again pleased to partner with our Platinum Sponsor Guidehouse on another series of summer seminars. \n \n  \nAgenda \n\n08:30 AM – 09:30 AM \n\n\nZero Knowledge Proofs in Blockchain \nPresenter: Remo Nyffenegger (University of Basel) \nA zero-knowledge proof is a cryptographic technique that enables one party (the prover) to demonstrate to another party (the verifier) that a certain statement is true without revealing any additional information about the statement itself. This concept has diverse applications\, particularly in fields like blockchain technology. Within blockchains\, zero-knowledge proofs address two critical dimensions: privacy and scalability. They empower confidential transaction verification by shielding sensitive data. Moreover\, these proofs enhance scalability through succinct verification\, allowing blockchains to process more transactions efficiently without compromising security. \nIn this presentation by Remo Nyffenegger\, we will discover how zero-knowledge proofs possess extensive applicability while providing utility in secure authentication\, upholding voting integrity\, and validating digital identities. \n\n\n09:30 AM – 10:30 AM \n\n\nTransformative Technologies: RPA\, Low-Code\, AI/ML \nPresenters: Ranyah Salous and Shelly Turner (Guidehouse) \nAs transformative technologies are reshaping the IT landscape\, they provide invaluable insights into harnessing their potential to streamline processes\, enhance efficiency\, and drive innovation. Join us for an engaging discussion that will unveil the cutting-edge technologies such Robotic Process Automation (RPA)\, Low-Code development\, Artificial Intelligence/Machine Learning (AI/ML) and other related technologies. \nIn this presentation by Shelly and Ranyah\, we will discover how these dynamic tools converge to empower organizations to achieve agility and modernization. \n\n\n10:30 AM – 11:30 PM \n\n\nAI-Guided Depression Management \nPresenter: Dr. Farrokh Alemi (George Mason University) \nMost patients with major depression do not benefit from their first treatment and have to go through repeated trials of medications to find a treatment that works for them. Over the years\, there have been multiple attempts to help clinicians provide a more optimal depression treatment. Neither the guidelines nor the decision aids have changed clinical practice by much or improved outcomes for patients. Our proposed generative AI system bridges this gap in service. The system has two components: patient-facing collection of medical history and a non-generative advice system. \nIn this presentation\, Dr. Farrokh Alemi will explain how this novel\, goal-based\, example-driven\, dialogue management system is likely to improve patient engagement; increase shared decision making between patient and their clinicians; and in the process lead to changes in prescription patterns and patient outcomes. \n\n\n11:30 AM – 12:30 PM \n\n\nProtecting Supply Chain Integrity and Data Privacy \nPresenter: Rodney Snyder (Guidehouse) \nAs the cyber warfare landscape continues to evolve\, IT modernization becomes the cornerstone of mitigating supply chain risks and reducing potential liabilities. The modern digital landscape has brought forth a cyber guerilla warfare that threatens the integrity of supply chains and data privacy across organizations. With ever more and increasingly sophisticated cyberattacks increasing the risk\, data compromise becomes a more frequent grim reality. Organizations must take proactive steps to implement robust cyber risk-mitigation and liability-reduction strategies within their supply chains. \nIn this presentation\, Rodney Snyder will touch on how IT modernization and supply chain risk management can help organizations navigate complexities and become resilient. \n\n  \nPresenters \n\n \n\n\nRemo Nyffenegger\nEconomist @ University of Basel  \nRemo Nyffenegger is an economist and researcher at the University of Basel in Switzerland. He conducts research on traditional economic topics as well as on blockchains and their underlying technology. In this role\, he investigates the utilization of zero-knowledge proofs within the realm of blockchains and other areas.  \nRecently\, he authored an article on this subject\, featured in the Federal Reserve Bank of St. Louis Review. \n\n\n \n\n\nRanyah Salous\nDirector @ Guidehouse  \nRanyah Salous is a Director at Guidehouse with the Advanced Analytics and Intelligent Automation team and has over 11 years of professional IT experience. In her time leading Advanced Analytics and Intelligent Automation initiatives\, she has worked with clients across segments around the globe to establish an enterprise approach to Intelligent Automation\, Data Analytics\, Data Visualization\, AI/ML\, and Low-code implementation including the establishment of strategic goals\, program governance\, change management\, and continuing the evolution of automation technology. Ms. Salous has provided value to organizations by leading efforts to automate manual tasks\, increase process efficiencies\, and free-up resources to work on higher-value initiatives. In addition to automation and application delivery\, Ms. Salous has worked with agencies and organizations to lead and establish the mission and vision for low-code solutions across the enterprise by standing up Robotic Process Automation and Data Analytics Centers of Excellence. \n\n\n \n\n\nShelly Turner\nDirector @ Guidehouse \nMs. Turner has 20 years’ experience with managing information technology projects\, including information system implementations. She has led projects to implement enterprise resource planning (ERP) systems\, low code/no code governance\, risk\, and compliance (GRC) solutions\, robotic process automation (RPA) solutions\, identity credential and access management (ICAM) solutions\, and data warehouse (DW) solutions. She also has experience with independent audits and assessments of information technology (IT) controls in connection with laws\, regulations\, and policies in both government and commercial sectors. She has led clients through all phases of technology implementations\, including solution selection\, business requirements capture\, gap analysis\, redesigning business processes\, designing customizations for gap-fit\, solution testing\, user training\, and post go-live support. She is a Certified Scrum Master (CSM) and has used both Agile and Waterfall implementation methodologies. \n\n\n \n\n\nDr. Farrokh Alemi\nProfessor & Researcher @ George Mason University  \nDr. Farrokh Alemi was trained as an operations researcher and industrial engineer and has worked in both academia and health industry. He maintains patents on (1) sentiment analysis\, (2) measurement of episodes of illness and (3) personalized medicine. He has more than 125 peer reviewed publications in journals such as Health Services Research\, Medical Care\, eClinicalMedicine and Palliative Medicine. His research focuses on causal analysis of massive data available in electronic health records. His publications have contributed to predictive medicine\, precision medicine\, comparative effectiveness of medications\, sentiment analysis\, natural language processing\, as well as other models and trajectories. \nAlemi maintains a decision aid for selection of antidepressants at http://MeAgainMeds.com. Alemi is the author of Multi-Morbidity index\, used in management of polypharmacy patients. In addition\, Alemi was a pioneer in online management of patients and has provided Congressional testimony on role of Internet in health delivery. He is the author of a book on decision analysis and another on policy systems and a third on application of process improvement to personal health. A fourth book\, on causal statistical analysis\, was published in 2020. \n\n\n \n\n\nRodney Snyder\nPartner @ Guidehouse \nRodney is a partner at Guidehouse within our Cyber Security Practice and leads our Supply Chain Risk Management (SCRM)\, Open Source Intelligence (OSINT)\, and Cyber Threats work. This includes leveraging the enormous and fast-growing universe of worldwide\, publicly available. information\, such as cyber\, corporate\, SCRM\, financial\, geolocational\, and open-source data to which data science and analytic tools can be applied. Before joining Guidehouse\, Rodney was a consultant with PwC Public Sector and\, prior to that\, served a full career in the US government\, including as a chief of station in the Middle East\, CIA chief of staff under two directors\, special assistant to the President at the White House\, and assistant commissioner at US Customs and Border Protection. He helped stand up the National Counterterrorism Center and began his career as a presidential management intern and an analyst. \n\n  \nEvent Questions and Policies \nRegistration Questions \nIf you have any registration questions about this event\, please contact the chapter using the Registration Contact Form. \nIf you have CPE questions after the event has concluded\, please contact the chapter using the CPE Contact Form. \n  \nCancellation and Refund Policy \nCancellation and refund for advance registrations is allowed if cancellations are submitted through the registration system. Refunds vary depending on the date of cancellation. See ISACA GWDC Event Policies for details. \nIf ISACA GWDC cancels the event\, all registrants will be notified as soon as possible through email at the email address provided during registration. Full refunds will be provided. \n  \nComplaint Policy \nThe GWDC welcomes your comments\, complaints\, suggestions\, questions\, and other feedback concerning our website information and services. All complaints should be submitted through the Registration Contact Form. \n  \nCPE Information \nEarn up to 4 Continuing Professional Education (CPE) credit in the area of Information Technology. The ISACA® Greater Washington\, D.C. Chapter is registered with the National Association of State Boards of Accountancy (NASBA) as a sponsor of continuing professional education on the National Registry of CPE Sponsors. State boards of accountancy have final authority on the acceptance of individual courses for CPE credit. Complaints regarding registered sponsors may be submitted to the National Registry of CPE Sponsors through its website: www.NASBARegistry.org \n  \nCPE Distribution and Evaluation Survey \nCPEs will be distributed via e-mail along with the event evaluation survey after the completion of the event. Attendees must be present for the full event to receive full CPE credit. \n  \nLearning Objective \nAfter attending this event\, attendees will learn about recent topics in the IT modernization space. \n  \nCPE-Related Details \n\n	Prerequisites: None\n	Advance Preparation: None\n	Program Knowledge Level: Basic\n	Delivery Method:  Group Internet Based\n	Field of Study:  Information Technology – Technical
URL:https://isaca-gwdc.org/event/summer-seminar-itmodernization/
LOCATION:Virtual Event
CATEGORIES:Conferences
ATTACH;FMTTYPE=image/png:https://isaca-gwdc.org/wp-content/uploads/2023/07/summer-seminar-itmodernization-2023.png
ORGANIZER;CN="Avneet Sabharwal":MAILTO:programs@isaca-gwdc.org
END:VEVENT
END:VCALENDAR