BEGIN:VCALENDAR
VERSION:2.0
PRODID:-//ISACA Greater Washington, D.C. Chapter - ECPv6.17.3.1//NONSGML v1.0//EN
CALSCALE:GREGORIAN
METHOD:PUBLISH
X-ORIGINAL-URL:https://isaca-gwdc.org
X-WR-CALDESC:Events for ISACA Greater Washington, D.C. Chapter
REFRESH-INTERVAL;VALUE=DURATION:PT1H
X-Robots-Tag:noindex
X-PUBLISHED-TTL:PT1H
BEGIN:VTIMEZONE
TZID:America/New_York
BEGIN:DAYLIGHT
TZOFFSETFROM:-0500
TZOFFSETTO:-0400
TZNAME:EDT
DTSTART:20220313T070000
END:DAYLIGHT
BEGIN:STANDARD
TZOFFSETFROM:-0400
TZOFFSETTO:-0500
TZNAME:EST
DTSTART:20221106T060000
END:STANDARD
BEGIN:DAYLIGHT
TZOFFSETFROM:-0500
TZOFFSETTO:-0400
TZNAME:EDT
DTSTART:20230312T070000
END:DAYLIGHT
BEGIN:STANDARD
TZOFFSETFROM:-0400
TZOFFSETTO:-0500
TZNAME:EST
DTSTART:20231105T060000
END:STANDARD
BEGIN:DAYLIGHT
TZOFFSETFROM:-0500
TZOFFSETTO:-0400
TZNAME:EDT
DTSTART:20240310T070000
END:DAYLIGHT
BEGIN:STANDARD
TZOFFSETFROM:-0400
TZOFFSETTO:-0500
TZNAME:EST
DTSTART:20241103T060000
END:STANDARD
END:VTIMEZONE
BEGIN:VEVENT
DTSTART;TZID=America/New_York:20231207T083000
DTEND;TZID=America/New_York:20231207T123000
DTSTAMP:20231206T180223Z
CREATED:20231029T212110Z
LAST-MODIFIED:20231206T180223Z
UID:31252-1701937800-1701952200@isaca-gwdc.org
SUMMARY:Security and Risk Trends - Recap of 2023 with a Look ahead to 2024
DESCRIPTION:The ISACA Greater Washington DC (GWDC) proudly hosts the 2023 Security and Risk Trends conference. This seminar will recap cybersecurity and risk trends noted/experienced in 2023 and look ahead to what to expect in 2024. This virtual conference is part of our monthly conference series. \nBusiness leaders and managers\, executives\, technologists\, professionals\, and students\, interested in staying current in the field of cybersecurity and risk governance should attend this conference. \nRegistration closes on December 6\, 2023 @ 2pm.  \nRegister Today! \n  \nAgenda \n\n\n08:30 AM – 09:30 AM \n\n\n2023 Unlocked\, 2024 Unleashed \nPresenter: Sushila Nair (Capgemini) \nIn a world where cybersecurity threats are evolving rapidly\, understanding the landscape of the past and anticipating future challenges is crucial for organizational resilience. “2023 Unlocked\, 2024 Unleashed: Navigating the Future of Security and Risk” is a comprehensive presentation that delves into the significant security trends in 2023\, evaluates effective strategies for security budget allocation\, and forecasts the security and risk management landscape for 2024. \nThis presentation will recapitulate critical security incidents and technological advancements of 2023\, highlighting how they have reshaped the security domain. It will also delve into strategies for effective budget allocation in security spending\, providing insights into optimizing resources for maximum protection. The presentation will offer predictions for 2024\, focusing on anticipated threats\, emerging technologies\, and financial planning strategies. Attendees will leave with a holistic understanding of the security field and actionable strategies for the upcoming year. \nThis presentation aims to equip attendees with a thorough understanding of the current security environment and provide them with the tools and knowledge needed to prepare for the future effectively. \n\n\n\n09:30 AM – 10:30 AM \n\n\nSecuring Tomorrow’s Future in Education \nPresenter: VJ Rao (Fairfax County Public Schools) \n“Securing Tomorrow’s Future in Education” is a crucial exploration into the cybersecurity challenges and strategies within the K-12 education sector\, emphasizing the experiences of Fairfax County Public Schools. This presentation navigates the intricate digital ecosystem of today’s educational environment\, unraveling the complexities of maintaining a secure and resilient cyber infrastructure in a large and diverse school system. \nThe talk will discuss the state of K-12 cybersecurity and spotlight the recent trends and unique threats that schools face\, from protecting sensitive student data to ensuring safe digital learning spaces. It will also delve into the risks and vulnerabilities inherent in the educational sector’s technology use\, discussing how to safeguard effectively against breaches and cyber threats while prioritizing student privacy and safety. \n\n\n\n10:30 AM – 11:30 AM \n\n\nThe Digital Trust Gap: How Cyber Pros Break Silos to Advance Digital Trust \nPresenter: Pam Nigro (Medecision) \nDigital trust is sometimes misunderstood as a cybersecurity function; it’s really a part of an ecosystem that harnesses privacy\, quality\, assurance\, risk\, and governance to strengthen your enterprise and consumer trust. Learn how cyber professionals can communicate and collaborate with other IT functions in the digital trust ecosystem\, and gain access to a new digital trust ecosystem framework. \n\n\n\n11:30 AM – 12:30 PM \n\n\nPanel Discussion: Navigating the Shifting Cybersecurity Landscape: Insights from Top CISOs \nModerator: Ruchi Shewaramani \nPanelists: Lakshmi Hanspal\, Anne Saunders (Capgemini)\, and Zac Warren (TANIUM) \nCybersecurity is a critical pillar of organizational resilience and operational integrity in a rapidly evolving digital world. The panel discussion “Navigating the Shifting Cybersecurity Landscape: Insights from Top CISOs\,” part of the “Security and Risk Trends – Recap of 2023 with a Look Ahead to 2024” conference\, promises to offer unparalleled insights into the world of cybersecurity as seen through the eyes of experienced Chief Information Security Officers. \nThis 50-minute session will bring together a panel of distinguished CISOs and former CISOs from various industries to discuss and dissect the significant cybersecurity events and trends 2023. The panelists will share their firsthand experiences\, challenges\, and successful strategies implemented in their organizations. This retrospective look will provide valuable lessons learned and insights into the evolving nature of cyber threats and defense mechanisms. \n\n  \nPresenters \n\n\n \n\n\nSushila Nair\nVice President – North American Cybersecurity Practice @ Capgemini \nCISSP\, GIAC GSTRT\, CISA\, CISM\, CRISC\, CDPSE\, CCSK\, CCAK \nSushila Nair is Capgemini’s Vice President\, North American Cybersecurity practice. Capgemini is a global leader in providing secure digital transformation for our clients. Sushila has most recently served as the Vice President for cybersecurity offers at NTT Data Services and has held the role of a CISO for 10 years. Sushila has over 30 years of experience in computing infrastructure\, business and security risk analysis\, preventing credit card fraud\, and served as a legal expert witness. Sushila has been featured in global technical events including RSA\, Segurinfo and ISACA’s global conferences\, co-authored books and is regularly quoted in the press. She plays an active role in supporting best practices and skills development within the cybersecurity community through her work with ISACA and CSA. \nSushila is part of the ISACA global emerging trends working group. Sushila Nair was named by IT Security Guru as one of the Most Inspiring Women in Cyber 2022! Sushila is also the current Vice President of the ISACA Greater Washington D.C. Chapter. \n  \n\n\n\n \n\n\nVJ Rao\nDirector of Cybersecurity @ Fairfax County Public Schools \nVJ Rao currently oversees information security for Fairfax County Public Schools (FCPS). He is a widely respected cyber-security leader who joins the school division with over 20 years of experience. He also served as the Chief Information Security Officer for the 2016 and 2020 Presidential and Vice-Presidential Debates. \nBefore FCPS\, VJ worked at the Washington Metropolitan Area Transit Authority (WMATA) and served as Deputy Chief Technology Officer at the National Democratic Institute. As an industry expert on cyber risk\, VJ has conducted several security audits and risk assessments for organizations ranging from large banks to federal\, local\, and state governments. He regularly speaks on security matters\, and his efforts have been profiled in several technology articles. \n\n\n\n \n\n\nPam Nigro\nVice President of Security and Security Officer @ Medecision\nCRMA\, CISA\, CGEIT\, CRISC\, CDPSE \nPamela (Pam) Nigro\, CRMA\, CISA\, CGEIT\, CRISC\, CDPSE\, was recently named Security’s 2023 Top Cybersecurity Leaders by Security Magazine. Ms. Nigro serves on the Board of Directors for ISACA as Director\, where she was the Chair from 2022 2023. Presently\, Ms. Nigro is Vice President of Security at Medecision where she is responsible for all cyber security efforts that secure and protect information important to Medecision and its customers\, while ensuring the overall cyber resiliency of the company. Ms. Nigro is also an Adjunct Professor at Lewis University in Illinois where she teaches in the MSIS and MBA programs. Ms. Nigro has achieved her MBA from Illinois Institute of Technology. She has more than 25 years of experience in the healthcare industry and the information technology industry and holds numerous IT certifications. \n\n\n\n \n\n\nRuchi Shewaramani\nChief Information Security Officer at WA Health Benefit Exchange \nRuchi Shewaramani is a cyber security executive with 15+ years of experience in Information Technology Security\, Identity and Access Management (IAM)\, Governance\, Risk and Compliance (GRC) across Healthcare\, Education and Financial institutions. She holds a Masters in Software Engineering from Seattle U. In the last decade\, she has managed the security program for various Health and Human Services Agencies in the District of Columbia (DC) and Washington state and successfully cleared numerous federal audits. She specializes in leading HealthCare agencies to secure their data\, be compliant with state/federal partners and provide digital trust to the citizens they serve. She is currently serving as the Chief Information Security Officer for WA Health Benefit Exchange and as a Board member for ISACA Greater Washington DC Chapter. \n\n\n \n\n\nLakshmi Hanspal \nLakshmi Hanspal is the former Chief Information Security Officer of Amazon Devices and Services\, leading the Trust and Security team across multiple security and privacy domains\, including Cyber\, Customer\, Product\, Platform\, Risk and Assurance\, Compliance\, Data Protection\, and Finance. Lakshmi is a persuasive and recognized executive leader who provides transformational leadership for security strategies\, emphasizing cloud security\, risk\, and privacy management. She has a strong ability to engage with customers and senior-level executives across the organization and influence buy-in and consensus on key initiatives. Lakshmi is passionate about securing digital transformation\, IoT security\, and supporting socially conscious connected commerce. She actively engages and promotes Women in technical leadership roles and develops early talent for diversity within teams. Lakshmi is a catalyst and harbinger of change within her professional and volunteering circles. \nBefore joining Amazon\, Lakshmi was the Global CSO at Box\, where she protected a large dynamic cloud content platform with more than 100k+ customers. Lakshmi has also held leadership roles at SAP\, PayPal\, and Bank of America. Her career spans across 26+ years in Information Security and risk management\, with 16+ years in the financial and payment space. \nLakshmi is a graduate of Boston University with a Masters in Computer Science. She is an actively sought-after advisor and investor in Silicon Valley. She serves on the Advisory Boards and Board of Directors of innovative mission-based organizations and non-profits\, ready for growth and scale. She lives in California’s Bay Area with her family and is an active volunteer within the community in youth sports. \n\n\n \n\n\nAnne Saunders\nGlobal Director\, Cybersecurity Technology Partnerships @ Capgemini  \nAs a senior executive\, Anne’s career encompasses more than 15 years of cybersecurity experience working in various capacities including leadership\, solution design\, sales engineering and business development. Anne has worked to bring cybersecurity solutions to a variety of verticals including retail\, financial services\, manufacturing and technology. \nIn her current role for Capgemini\, (formerly Leidos Cyber)\, Saunders manages the global cybersecurity channel and technology portfolio. With a deep understanding of the entire cybersecurity life cycle\, she actively assists in bringing the right mix of technology\, value and solution design to help multimillion dollar enterprises with their cybersecurity roadmap and solution decision-making. Saunders also takes an active role in the cybersecurity community speaking at various conferences throughout the year\, including the RSA conference and Blackhat. \nPrior to\, and during her current role\, Saunders has sat on numerous advisory boards ranging from start-ups to regionally established security firms. Her knowledge of business operations and value-building\, coupled with her engineering and security operations background give her a unique ability to understand the business landscape to execute the correct cybersecurity strategies. \n\n\n \n\n\nZac Warren\nChief Information Security Advisor EMEA @ TANIUM \nZac Warren\, Chief Security Advisor in EMEA\, is a seasoned cybersecurity professional with a rich background in IT. Beginning as a senior security analyst at a leading security company\, Zac evolved into a cybersecurity architect and consultant for major system integrators. His career has been marked by transformative contributions\, assisting government agencies and Fortune 100 companies in restructuring security frameworks. Currently spearheading Tanium’s cybersecurity endeavors in EMEA\, Zac is dedicated to developing and supporting the company’s cybersecurity business as well as guiding organizations to stay ahead in the ever-evolving realm of cybersecurity. \n\n  \nVirtual Meeting Information \n\n	This event will be presented through Zoom.\n	Prior to the event\, participants must install the Zoom app on their respective devices or use the web-based Zoom. Calling via the phone may not be entitled to CPE credits.\n	Participants must respond to all the poll questions via the Zoom polling feature or chat log in order to receive NASBA CPE credits.\n	The ISACA Greater Washington\, D.C. Chapter will not be responsible for the participant’s inability to respond to the polls.\n\n  \nEvent Questions and Policies \nRegistration Questions \nIf you have any registration questions about this event\, please contact the chapter using the Registration Contact Form. \nIf you have CPE questions after the event has concluded\, please contact the chapter using the CPE Contact Form. \n  \nCancellation and Refund Policy \nCancellation and refund for advance registrations is allowed if cancellations are submitted through the registration system. Refunds vary depending on the date of cancellation. See ISACA GWDC Event Policies for details. \nIf ISACA GWDC cancels the event\, all registrants will be notified as soon as possible through email at the email address provided during registration. Full refunds will be provided. \n  \nComplaint Policy \nThe GWDC welcomes your comments\, complaints\, suggestions\, questions\, and other feedback concerning our website information and services. All complaints should be submitted through the Registration Contact Form. \n  \nCPE Information \nEarn up to 4 Continuing Professional Education (CPE) credit in the area of Information Technology. The ISACA® Greater Washington\, D.C. Chapter is registered with the National Association of State Boards of Accountancy (NASBA) as a sponsor of continuing professional education on the National Registry of CPE Sponsors. State boards of accountancy have final authority on the acceptance of individual courses for CPE credit. Complaints regarding registered sponsors may be submitted to the National Registry of CPE Sponsors through its website: www.NASBARegistry.org \n  \nCPE Distribution and Evaluation Survey \nCPEs will be distributed via e-mail along with the event evaluation survey after the completion of the event. Attendees must be present for the full event to receive full CPE credit. \n  \nLearning Objective \nAfter attending this event\, attendees will learn about recent topics in the cybersecurity and risk governance space. \n  \nCPE-Related Details \n\n	Prerequisites: None\n	Advance Preparation: None\n	Program Knowledge Level: Basic\n	Delivery Method:  Group Internet Based\n	Field of Study:  Information Technology – Technical
URL:https://isaca-gwdc.org/event/security-risk-trends-2023/
LOCATION:Virtual Event
CATEGORIES:Conferences
ATTACH;FMTTYPE=image/png:https://isaca-gwdc.org/wp-content/uploads/2023/10/conference-security-trends-2023.png
ORGANIZER;CN="Avneet Sabharwal":MAILTO:programs@isaca-gwdc.org
END:VEVENT
BEGIN:VEVENT
DTSTART;TZID=America/New_York:20231026T083000
DTEND;TZID=America/New_York:20231026T123000
DTSTAMP:20231029T161617Z
CREATED:20230917T140521Z
LAST-MODIFIED:20231029T161617Z
UID:30901-1698309000-1698323400@isaca-gwdc.org
SUMMARY:Cybersecurity 2023 Conference
DESCRIPTION:The GWDC is proud to host its annual cybersecurity conference. This virtual conference is part of our monthly conference series. \nBusiness leaders and managers\, executives\, technologists\, professionals\, and students\, interested in staying current in the field of cybersecurity should attend this conference. \nRegistration closes on October 25\, 2023 @ 12pm.  \nRegister Today! \n\nDate Change for this event! \nPlease note that this event is now scheduled to be held on October 26\, 2023. The event was previously advertised to occur on October 12th. \n\n  \nAgenda \n\n08:30 AM – 09:30 AM \n\n\nUsing Generative AI to Strengthen Cybersecurity – How IT professionals can balance its risks and rewards \nPresenter: Nirali Chawla (KPMG US) and Joseph Klimavicz (KPMG US) \nGenerative AI is a game-changing technology\, offering innovative ways to engage users and generate content with deeper insights. It is opening up entirely new avenues for improving experiences\, delivering new value streams and transforming business models. KPMG will discuss some opportunities for generative AI to enable cybersecurity to help business leaders harness the power of AI and associated risks to accelerate time-to-value in a trusted manner – from strategy and design through implementation and ongoing operations. \n\n\n09:30 AM – 10:30 AM \n\n\nViews from the Cloud: Cybersecurity and the Next Regulatory Frontier \nPresenter: Alexis Robinson (AWS) \nTopic description to be posted soon! \n\n\n10:30 AM – 11:30 PM \n\n\nSecurity Assessments – Pathway to Zero Trust \nPresenter: Albert E. Whale (Capgemini America) \nIn the presentation titled “Security Assessment – Pathway to Zero Trust\,” we delve into the evolving cybersecurity landscape\, emphasizing the insufficiencies of traditional Security Assessments and the necessity for a more robust approach\, the Zero Trust Model. Rooted in the principle “Never Trust\, Always Verify\,” Zero Trust demands no inherent trust\, advocating for micro segmentation and continuous monitoring. \nOur exploration underscores the role of security assessments in successfully transitioning to this model\, encompassing tasks like mapping current infrastructure\, pinpointing sensitive data\, reviewing policies\, designing segmented access\, and implementing real-time monitoring. By addressing challenges such as organizational resistance and technological integration\, and highlighting the overarching benefits of an enhanced security posture\, we aim to provide attendees with a comprehensive overview and a roadmap to begin their Zero Trust journey. \n\n\n11:30 AM – 12:30 PM \n\n\nWorking backwards with AWS Customer Compliance Guides to accelerate security assessments \nPresenter: Kevin Donohue (AWS) \nThe rapid increase in the number of innovative cloud service offerings has blurred the lines between traditional cloud service models like IaaS\, PaaS and SaaS. When looking at cloud services through the lens of compliance\, categorizing them becomes less important than applying the shared responsibility model to security control requirements. Establishing a clear understanding of security responsibilities based on the services in your workload is key to reducing compliance challenges. \nIn this presentation\, we’ll demonstrate how AWS Customer Compliance Guides make shared responsibility and compliance easier for customers interpret and integrate into their organization’s cloud strategy. We’ll demonstrate how the approach of working backwards from the security options you have for each service and mapping them to security standards can help accelerate your compliance initiatives. \n\n  \nPresenters \n\n \n\n\nNirali Chawla\nManaging Director\, Federal Advisory Services @ KMPG US\nCISSP\, CISA\, CRISC\, CAP\, ITIL\, and Six Sigma Green Belt \nNirali Shah Chawla is a Managing Director in KPMG’s Federal Advisory practice with more than 20 years of experience providing a wide range of services to private and public sector clients including financial and information technology audit readiness services\, information assurance and Cyber security services\, Governance\, Risk & Compliance implementations and programs\, Cloud Computing and transformation consulting services. Ms. Chawla currently leads some of the largest federal agencies at the brink of transformational change and growth\, leveraging her knowledge of existing and emerging technologies to uncover IT opportunities for business process and internal controls improvements. Ms. Chawla is the co-author of NIST Special Publication 800-137\, Information Security Continuous Monitoring (ISCM) for Federal Information Systems and Organizations\, and holds certifications such as the CISSP\, CISA\, CRISC\, CAP\, ITIL\, and Six Sigma Green Belt. Ms. Chawla is a recognized industry leader in the Information Technology Risk Management and transformation field\, speaking at industry conferences and instructing training seminars. \nMs. Chawla is the ISACA GWDC Director of Marketing\, AFCEA Scholarships Education Committee Chair\, Member of Cyber Council for INSA and on the Steering Committee for a non-profit organization\, Vicente Ferrer Foundation (VFF). She is also a member of the following organizations: ASMC\, NAASA and Women in Technology (WIT). \n\n\n \n\n\nJoseph Klimavicz\nManaging Director\, Federal Advisory Services @ KMPG US \nMr. Joseph Klimavicz joined KPMG LLP as a Managing Director in March 2020. In this position\, he leads the Federal Technology Advisory practice and helps government clients implement digital transformations and deal with rapidly changing technology\, growing complexities from budget constraints\, competing agendas\, and continuous attacks on their information infrastructure. \nMr. Klimavicz previously served as the Department of Justice (DOJ) Deputy Assistant Attorney General and CIO from May 2014 until March 2020. In this position\, he provided leadership and oversight of the Department’s information and technology programs and implemented large-scale and complex digital transformations. He also served as DOJ’s Chief Data Officer\, Senior Agency Official for Geospatial Information\, and executive responsible for both radio frequency spectrum and all technical standards. In addition\, he served as vice-chair of the Federal CIO Council. \nMr. Klimavicz’s 37-year career in the federal government began with the Central Intelligence Agency (CIA) as an imagery scientist. He subsequently served in line management positions within the CIA and the Department of Defense (DOD) leading information technology programs\, to include serving as the National Geospatial-Intelligence Agency Deputy CIO. Mr. Klimavicz also served as National Oceanic and Atmospheric Administration (NOAA) CIO and Director\, High Performance Computing and Communications from January 2007 until May 2014. \n\n\n \n\n\nAlexis Robinson\nSenior Manager\, Industry Specialist @ AWS\nCISA\, PMP\, MBA \nAlexis Robinson is a Senior Manager\, Industry Specialist for Amazon Web Services (AWS) Security Assurance in the Washington\, DC area. For the past 15 years\, she has served her clients\, buyers of the cloud\, and AWS Partners by enabling strategies based on security best practices\, collaborating for thought leadership\, solving problems\, and conducting cybersecurity and financial assessments. She graduated with double Bachelors of Science degrees in Accounting and Information Systems from the Robert H. Smith School of Business at University of Maryland\, College Park. She most recently graduated from Quantic with an Executive Masters in Business Administration. She has worked at several companies including CGI Federal and Ernst & Young before finding her way to Amazon. She is a Certified Information Systems Auditor (CISA) and a Project Management Professional (PMP). \nOn her free time\, she is playing video games\, watching “Bob’s Burgers”\, “Ted Lasso”\, “Demon Slayer”\, “Abbott Elementary” and “It’s Always Sunny in Philadelphia”. She lives with her husband and son in Maryland. \n\n\n \n\n\nAlbert E. Whale\nSenior Cloud Security / Zero Trust Architect @ Capgemini America\, Inc.\nCISSP\, CEH \nAlbert E. Whale is a Certified Global Coach at Napoleon Hill Institute\, where he support others in their personal development to live their dreams. With over 20 years of experience in cybersecurity\, IT security\, and entrepreneurship\, he has a unique perspective and skill set to help clients achieve their goals and overcome challenges. \nMr. Whale is also a #1 International Best Selling Author of the sequel book #HACKED2\, written with 12 esteemed cybersecurity professionals who offer their views and insights on how to protect personal and business information from cyber threats. He is passionate about sharing his knowledge and experience with others\, and regularly speak at events\, webinars\, podcasts\, and media outlets on topics related to cybersecurity\, personal development\, and entrepreneurship. \n\n\n \n\n\nKevin Donohue\nSecurity Partner Strategist\, Global Security & Compliance Acceleration team @ AWS \nCISSP \nKevin is a Sr. Security Partner Strategist on the AWS Global Security & Compliance Acceleration team\, specializing in shared responsibility and regulatory compliance support for AWS customers and partners. Kevin began his tenure with AWS in 2019 with the AWS FedRAMP program\, where he created Customer Compliance Guides to assist U.S. government customers with their assessment & authorization responsibilities. Prior to AWS\, Kevin worked at PwC in their commercial cybersecurity practice performing risk and compliance assessments across various security standards and industries. Kevin began is security career as a security control assessor at the U.S. Department of State. Kevin holds a B.A. in Political Science and Middle Eastern Studies from Rutgers University and M.S. Management of Security Information Systems from George Mason University. \nIn his spare time\, he enjoys taking advantage of everything to do in DC area from museums to biking with his wife Shannon and daughter Madeline. Originally from New Jersey\, Kevin has been in the DMV for 12 years and currently resides in Alexandria. \n\n  \nVirtual Meeting Information \n\n	This event will be presented through Zoom.\n	Prior to the event\, participants must install the Zoom app on their respective devices or use the web-based Zoom. Calling via the phone may not be entitled to CPE credits.\n	Participants must respond to all the poll questions via the Zoom polling feature or chat log in order to receive NASBA CPE credits.\n	The ISACA Greater Washington\, D.C. Chapter will not be responsible for the participant’s inability to respond to the polls.\n\n  \nEvent Questions and Policies \nRegistration Questions \nIf you have any registration questions about this event\, please contact the chapter using the Registration Contact Form. \nIf you have CPE questions after the event has concluded\, please contact the chapter using the CPE Contact Form. \n  \nCancellation and Refund Policy \nCancellation and refund for advance registrations is allowed if cancellations are submitted through the registration system. Refunds vary depending on the date of cancellation. See ISACA GWDC Event Policies for details. \nIf ISACA GWDC cancels the event\, all registrants will be notified as soon as possible through email at the email address provided during registration. Full refunds will be provided. \n  \nComplaint Policy \nThe GWDC welcomes your comments\, complaints\, suggestions\, questions\, and other feedback concerning our website information and services. All complaints should be submitted through the Registration Contact Form. \n  \nCPE Information \nEarn up to 4 Continuing Professional Education (CPE) credit in the area of Information Technology. The ISACA® Greater Washington\, D.C. Chapter is registered with the National Association of State Boards of Accountancy (NASBA) as a sponsor of continuing professional education on the National Registry of CPE Sponsors. State boards of accountancy have final authority on the acceptance of individual courses for CPE credit. Complaints regarding registered sponsors may be submitted to the National Registry of CPE Sponsors through its website: www.NASBARegistry.org \n  \nCPE Distribution and Evaluation Survey \nCPEs will be distributed via e-mail along with the event evaluation survey after the completion of the event. Attendees must be present for the full event to receive full CPE credit. \n  \nLearning Objective \nAfter attending this event\, attendees will learn about recent topics in the cybersecurity space. \n  \nCPE-Related Details \n\n	Prerequisites: None\n	Advance Preparation: None\n	Program Knowledge Level: Basic\n	Delivery Method:  Group Internet Based\n	Field of Study:  Information Technology – Technical
URL:https://isaca-gwdc.org/event/2023-cybersecurity-conference/
LOCATION:Virtual Event
CATEGORIES:Conferences
ATTACH;FMTTYPE=image/png:https://isaca-gwdc.org/wp-content/uploads/2023/09/cybersecurity_2023-1.png
ORGANIZER;CN="Avneet Sabharwal":MAILTO:programs@isaca-gwdc.org
END:VEVENT
BEGIN:VEVENT
DTSTART;TZID=America/New_York:20230928T083000
DTEND;TZID=America/New_York:20230928T123000
DTSTAMP:20230927T230806Z
CREATED:20230917T140643Z
LAST-MODIFIED:20230927T230806Z
UID:30895-1695889800-1695904200@isaca-gwdc.org
SUMMARY:Cloud Security 2023 Conference
DESCRIPTION:The GWDC is proud to partner with the DC Chapter of the Cloud Security Alliance to host its annual cloud conference\, Cloud Security 2023. This virtual conference is part of our monthly conference series. \nCloud security and enablement professionals\, IT advisory or audit professionals\, business executives\, cybersecurity professionals\, students or professionals interested in learning more about cloud security should attend this conference. \nRegistration closes on September 27\, 2023 @ 12pm.  \nRegister Today! \n  \nEvent Partner \nThe GWDC is proud to have the DC Chapter of the Cloud Security Alliance as a partner for this event.  For more information on the CSA DC Chapter\, please visit their website at https://cloudsecurityalliance-dc.org/home. \n \n  \nAgenda \n\n08:30 AM – 09:30 AM \n\n\nWho’s Vulnerable in YOUR IT Supply Chain? \nPresenter: David Barnscome (Microsoft) \n“Compromise one to compromise many.” More and more frequently\, nation-state attackers leverage the trusted relationships in an organization’s IT supply chain to achieve compromise of downstream targets. How can you take steps to protect against this type of activity? \nIn this discussion\, we’ll look at some interesting examples of how supply chain compromise has been achieved\, and what it eventually led to. More importantly\, we’ll talk about how you can assess your IT suppliers so that you can have confidence that they are taking the right steps to protect your organization’s data estate. \n\n\n09:30 AM – 10:30 AM \n\n\nThreat Intelligence Integration \nPresenter: George Alves (Defense Acquisition University) \nGeorge Alves discusses how being “threat informed” is critical in the execution of your Zero Trust capabilities and activities whether on-prem or in the cloud. From the Zero Trust Capability Roadmap: this capability requires integration of threat intelligence information and streams about identities\, motivations\, characteristics\, as well as tactics\, techniques\, and procedures (TTPs). This capability will assist Cyber Defenders be more proactive rather than reactive. \n\n\n10:30 AM – 11:30 PM \n\n\nCloud Adversarial Vectors\, Exploits\, and Threats (CAVEaT™): An Emerging Threat Matrix for Industry Collaboration \nPresenter: Dr. Mari J. Spina (CSA DC Chapter and MITRE) \nCloud security practitioners agree there’s a need for comprehensive threat-informed security guidance to address system assessment\, secure design\, cyber analytics\, and threat mitigation. Due to the rapid development of cloud technologies and service offerings\, it is also necessary to develop a forward-looking adversary perspective that identifies emerging cloud service risks along with detailed detections and mitigations for practitioners to implement. The Cloud Security Alliance (CSA) and the MITRE Corporation have established the Cloud Adversarial\, Vectors\, Exploits\, and Threats (CAVEaT™) collaboration to bring relevant content to the cloud security practitioner. This research explores today’s available frameworks with relevance to cloud systems and proposes a course of action to advance the state of the art in threat-informed security by collaborating with cloud service providers (CSPs)\, international security researchers\, and key subject matter experts. \n\n\n11:30 AM – 12:30 PM \n\n\nContinuous Compliance – Security Assessments the Cloud-Native Way \nPresenter: Michael Wasielewski (Capgemini) \nSecurity assessments for cloud environments have and continue to evolve at a dramatic rate. Just a few years ago security standards for cloud environments were difficult to understand and even more difficult to audit against. Since then\, cloud service providers and their partners have built tools to simplify auditability for their customers and auditors alike; but the pace of change in and of modern cloud environments still vexes many traditional assessment practices. In this talk\, we’ll cover how the next generation of audit tools are adopting a continuous compliance approach for evaluating cloud environments in near-real time\, and how to think differently about what artifacts can demonstrate real risk management as opposed to point in time theater. By the end of the session you’ll better understand how to approach security assessments for modern cloud environments. \n\n  \nPresenters \n\n    \n\n\nDavid Barnscome\nGlobal Partner Solutions Architect for Security\, Compliance\, and Identity @ Microsoft \nDavid is a Global Partner Solutions Architect for Security\, Compliance\, and Identity at Microsoft. In this role\, David is responsible for training and supporting Microsoft partners on the latest security compliance and identity solutions\, including Microsoft 365\, Azure and Windows. \n  \n\n\n \n\n\nGeorge Alves\nProfessor\, Enterprise Cybersecurity @ Defense Acquisition University (DAU)\nCISSP\, CEH \nGeorge Alves has over 35 years of DOD and Acquisition experience. Currently he is a Defense Acquisition University (DAU) Cybersecurity Professor. He holds a Master of Science in Cybersecurity along with various professional certifications such as CISSP and CEH. Before coming to DAU\, he served as the Information Systems Security Manager (ISSM) at the Office of the Comptroller of the Currency under Department of Treasury overseeing IT/Cyber acquisitions and compliance throughout several platforms to include public and private cloud environments. He is a former Navy Civilian of 10 years to include being the Deputy CIO for Cybersecurity at Naval Sea Systems Command HQ in Washington Navy Yard\, DC. There he oversaw the entire NAVSEA enterprise comprised of over 2000 operational\, developmental\, and RDT&E networks\, systems\, and applications both on-premise and in cloud environments. He had a team of almost 40 civilians and contractors to include the first NAVSEA Cyber Scientific & Technical Intelligence Liaison Officer (STILO) in a position he created to integrate intelligence within Cybersecurity. He also spent two years as an Army civilian supporting the Program Manager of DOD Biometrics as the Cybersecurity Lead under the Program Executive Office Intelligence Electronic Warfare and Sensors (PEO IEW&S). There he was involved in the early stages of acquisition supporting the designs\, engineers\, deployment\, and sustainment of enterprise biometric solutions in multiple operating environments enabling identity dominance on the battlefield and across the Department of Defense to include migrating tactical systems into the cloud. He is also a proud veteran retiring after 20 years of Navy active-duty service. Some of his assignments includes serving as the Automated Data Processing Division Officer onboard the USS NASSAU\, and as a Computer Network Defense Leading Chief Petty Officer within Joint Forces Command where he stood up a Global Command\, Control\, Communications\, Computers\, and Intelligence (C4I) Coordination Center after the 9/11 attack. \n\n\n \n\n\nDr. Mari J. Spina\nCloud Security Alliance-DC Chapter Research Committee Chair\nPrincipal Cybersecurity Engineer @ the MITRE Corp\nPMP\, CISSP\, ISSEP\, CCSP \nDr. Mari J. Spina is the Cloud Security Alliance-DC Chapter Reasearch Committee Chair. In this capacity\, she has been leading the charge to develop critical research to advance the state of practice in cloud security for highly regulated industries represented by the CSA-DC Chapter membership. Dr. Spina is also a Principal Cybersecurity Engineer at the MITRE Corp. supporting a multitude of MITRE Federal sponsors including DoD and the IC in the area of Cloud Security. At MITRE\, she leads the Cloud Security Capability Area\, and teaches Cloud Security for the MITRE Institute. She has taught many Information Technology courses for the George Washington University schools of engineering and business. Before joining MITRE\, she worked for government engineering firms including Hughes Aircraft\, SAIC\, ManTech\, NJVC\, and DMI since 1988 where she provided IT systems engineering to a variety of Federal agency missions including those of the Intelligence Community and the DoD. Mari holds a D.Sc. in Engineering Management from the George Washington University\, a MSEE from the University of Southern California\, and a BSME from California State University Northridge. She is also PMI PMP and ISC2 CISSP\, ISSEP\, CCSP certified. \n\n\n \n\n\nMichael Wasielewski\nCapgemini \nMoving from outside of Washington D.C. in the US\, Michael moved to Paris joining Capgemini in December of 2021. Responsible for global cloud security and next-gen secure architecture portfolio development\, Michael brings a robust background ranging from Network Operations and Engineering\, running global Information Security teams and modernizing enterprises through their cloud and workplace journeys\, and executing as a global Cloud Security specialist. When not playing video games with his two kids or struggling to learn French\, Michael wishes he could play more golf or do some more skydiving. \n\n  \nVirtual Meeting Information \n\n	This event will be presented through Zoom.\n	Prior to the event\, participants must install the Zoom app on their respective devices or use the web-based Zoom. Calling via the phone may not be entitled to CPE credits.\n	Participants must respond to all the poll questions via the Zoom polling feature or chat log in order to receive NASBA CPE credits.\n	The ISACA Greater Washington\, D.C. Chapter will not be responsible for the participant’s inability to respond to the polls.\n\n  \nEvent Questions and Policies \nRegistration Questions \nIf you have any registration questions about this event\, please contact the chapter using the Registration Contact Form. \nIf you have CPE questions after the event has concluded\, please contact the chapter using the CPE Contact Form. \n  \nCancellation and Refund Policy \nCancellation and refund for advance registrations is allowed if cancellations are submitted through the registration system. Refunds vary depending on the date of cancellation. See ISACA GWDC Event Policies for details. \nIf ISACA GWDC cancels the event\, all registrants will be notified as soon as possible through email at the email address provided during registration. Full refunds will be provided. \n  \nComplaint Policy \nThe GWDC welcomes your comments\, complaints\, suggestions\, questions\, and other feedback concerning our website information and services. All complaints should be submitted through the Registration Contact Form. \n  \nCPE Information \nEarn up to 4 Continuing Professional Education (CPE) credit in the area of Information Technology. The ISACA® Greater Washington\, D.C. Chapter is registered with the National Association of State Boards of Accountancy (NASBA) as a sponsor of continuing professional education on the National Registry of CPE Sponsors. State boards of accountancy have final authority on the acceptance of individual courses for CPE credit. Complaints regarding registered sponsors may be submitted to the National Registry of CPE Sponsors through its website: www.NASBARegistry.org \n  \nCPE Distribution and Evaluation Survey \nCPEs will be distributed via e-mail along with the event evaluation survey after the completion of the event. Attendees must be present for the full event to receive full CPE credit. \n  \nLearning Objective \nAfter attending this event\, attendees will learn about recent topics in the Cloud Security space. \n  \nCPE-Related Details \n\n	Prerequisites: None\n	Advance Preparation: None\n	Program Knowledge Level: Basic\n	Delivery Method:  Group Internet Based\n	Field of Study:  Information Technology – Technical
URL:https://isaca-gwdc.org/event/2023-cloud-security-conference/
LOCATION:Virtual Event
CATEGORIES:Conferences
ATTACH;FMTTYPE=image/png:https://isaca-gwdc.org/wp-content/uploads/2023/09/cloud_2023.png
ORGANIZER;CN="Avneet Sabharwal":MAILTO:programs@isaca-gwdc.org
END:VEVENT
BEGIN:VEVENT
DTSTART;TZID=America/New_York:20230831T083000
DTEND;TZID=America/New_York:20230831T123000
DTSTAMP:20230814T121341Z
CREATED:20230814T140007Z
LAST-MODIFIED:20230814T121341Z
UID:30741-1693470600-1693485000@isaca-gwdc.org
SUMMARY:2023 IT Fraud Virtual Conference with the ACFE
DESCRIPTION:Incidents of information technology being maliciously exploited reduce confidence and trust in the attacked organization’s security and operations. Cybersecurity Ventures estimates global cybercrime to cost $10.5 trillion annually by 2025. Join the Washington Metropolitan Chapter of the Association of Certified Fraud Examiners and ISACA Greater Washington DC chapter for their 2023 IT Fraud Virtual Conference.  Fraud and cybersecurity professionals\, IT advisory or audit professionals\, Business executives\, students or professionals interested in learning more about IT fraud should attend this event. \nTopics and presenters for this event are: \n\n	Cyber Risk and Financial Stability\nChris Wilson; Wilson Consulting\n	Framework for Managing Improper Payments in Emergency Assistance Programs\nSarah Garcia\, Johana Ayers\, and Daniel Flavin; United States Government Accountability Office\n	Anti Money Laundering Compliance Considerations in a Digital World\nGregory Schwarz; Guidehouse\n	Securities Fraud\nJames Park; UCLA School of Law\n\nAdvance registration is required. This event is free for GWDC members using the discount code that was provided via email.  If you did not receive the discount code\, please contact using the Registration Contact Form.  \nFor additional information\, including registration links\, please visit the ACFE website linked below.   \nRegister Today! \n  \nEvent Questions and Policies \nRegistration Questions \nIf you did not receive the email with the discount code for the event\, please contact us using the Registration Contact Form. \nAll other questions regarding the event\, registration\, and CPEs should be directed to the Washington Metropolitan Chapter of the ACFE. \n  \nCPEs  \nCPEs for this event will be issued by the Washington Metropolitan Chapter of the ACFE.
URL:https://isaca-gwdc.org/event/it-fraud-conference-with-acfe/
LOCATION:Virtual Event
CATEGORIES:Conferences
ORGANIZER;CN="Avneet Sabharwal":MAILTO:programs@isaca-gwdc.org
END:VEVENT
BEGIN:VEVENT
DTSTART;TZID=America/New_York:20230817T083000
DTEND;TZID=America/New_York:20230817T123000
DTSTAMP:20240911T155506Z
CREATED:20230715T153157Z
LAST-MODIFIED:20240911T155506Z
UID:30682-1692261000-1692275400@isaca-gwdc.org
SUMMARY:Summer Seminar - IT Modernization
DESCRIPTION:Join us for an exciting virtual summer seminar for an exciting event hosted by Guidehouse and the ISACA GWDC chapter focusing on the ever-relevant topic of IT modernization. This event brings together industry experts and government speakers to deliver insightful presentations on various aspects of IT modernization\, including its benefits\, challenges\, and risks as well as providing valuable insights to overcoming potential obstacles. \nAll information security program managers\, cybersecurity managers and professionals\, IT audit professionals\, business executives\, students and professionals interested in exploring the latest trends\, strategies\, and best practices in implementing and managing IT modernization initiatives should attend this event. \nRegistration closes on August 16\, 2023 @ 8pm.   This is a free virtual event. \nRegister Today! \n  \nEvent Sponsor \nThe GWDC is once again pleased to partner with our Platinum Sponsor Guidehouse on another series of summer seminars. \n \n  \nAgenda \n\n08:30 AM – 09:30 AM \n\n\nZero Knowledge Proofs in Blockchain \nPresenter: Remo Nyffenegger (University of Basel) \nA zero-knowledge proof is a cryptographic technique that enables one party (the prover) to demonstrate to another party (the verifier) that a certain statement is true without revealing any additional information about the statement itself. This concept has diverse applications\, particularly in fields like blockchain technology. Within blockchains\, zero-knowledge proofs address two critical dimensions: privacy and scalability. They empower confidential transaction verification by shielding sensitive data. Moreover\, these proofs enhance scalability through succinct verification\, allowing blockchains to process more transactions efficiently without compromising security. \nIn this presentation by Remo Nyffenegger\, we will discover how zero-knowledge proofs possess extensive applicability while providing utility in secure authentication\, upholding voting integrity\, and validating digital identities. \n\n\n09:30 AM – 10:30 AM \n\n\nTransformative Technologies: RPA\, Low-Code\, AI/ML \nPresenters: Ranyah Salous and Shelly Turner (Guidehouse) \nAs transformative technologies are reshaping the IT landscape\, they provide invaluable insights into harnessing their potential to streamline processes\, enhance efficiency\, and drive innovation. Join us for an engaging discussion that will unveil the cutting-edge technologies such Robotic Process Automation (RPA)\, Low-Code development\, Artificial Intelligence/Machine Learning (AI/ML) and other related technologies. \nIn this presentation by Shelly and Ranyah\, we will discover how these dynamic tools converge to empower organizations to achieve agility and modernization. \n\n\n10:30 AM – 11:30 PM \n\n\nAI-Guided Depression Management \nPresenter: Dr. Farrokh Alemi (George Mason University) \nMost patients with major depression do not benefit from their first treatment and have to go through repeated trials of medications to find a treatment that works for them. Over the years\, there have been multiple attempts to help clinicians provide a more optimal depression treatment. Neither the guidelines nor the decision aids have changed clinical practice by much or improved outcomes for patients. Our proposed generative AI system bridges this gap in service. The system has two components: patient-facing collection of medical history and a non-generative advice system. \nIn this presentation\, Dr. Farrokh Alemi will explain how this novel\, goal-based\, example-driven\, dialogue management system is likely to improve patient engagement; increase shared decision making between patient and their clinicians; and in the process lead to changes in prescription patterns and patient outcomes. \n\n\n11:30 AM – 12:30 PM \n\n\nProtecting Supply Chain Integrity and Data Privacy \nPresenter: Rodney Snyder (Guidehouse) \nAs the cyber warfare landscape continues to evolve\, IT modernization becomes the cornerstone of mitigating supply chain risks and reducing potential liabilities. The modern digital landscape has brought forth a cyber guerilla warfare that threatens the integrity of supply chains and data privacy across organizations. With ever more and increasingly sophisticated cyberattacks increasing the risk\, data compromise becomes a more frequent grim reality. Organizations must take proactive steps to implement robust cyber risk-mitigation and liability-reduction strategies within their supply chains. \nIn this presentation\, Rodney Snyder will touch on how IT modernization and supply chain risk management can help organizations navigate complexities and become resilient. \n\n  \nPresenters \n\n \n\n\nRemo Nyffenegger\nEconomist @ University of Basel  \nRemo Nyffenegger is an economist and researcher at the University of Basel in Switzerland. He conducts research on traditional economic topics as well as on blockchains and their underlying technology. In this role\, he investigates the utilization of zero-knowledge proofs within the realm of blockchains and other areas.  \nRecently\, he authored an article on this subject\, featured in the Federal Reserve Bank of St. Louis Review. \n\n\n \n\n\nRanyah Salous\nDirector @ Guidehouse  \nRanyah Salous is a Director at Guidehouse with the Advanced Analytics and Intelligent Automation team and has over 11 years of professional IT experience. In her time leading Advanced Analytics and Intelligent Automation initiatives\, she has worked with clients across segments around the globe to establish an enterprise approach to Intelligent Automation\, Data Analytics\, Data Visualization\, AI/ML\, and Low-code implementation including the establishment of strategic goals\, program governance\, change management\, and continuing the evolution of automation technology. Ms. Salous has provided value to organizations by leading efforts to automate manual tasks\, increase process efficiencies\, and free-up resources to work on higher-value initiatives. In addition to automation and application delivery\, Ms. Salous has worked with agencies and organizations to lead and establish the mission and vision for low-code solutions across the enterprise by standing up Robotic Process Automation and Data Analytics Centers of Excellence. \n\n\n \n\n\nShelly Turner\nDirector @ Guidehouse \nMs. Turner has 20 years’ experience with managing information technology projects\, including information system implementations. She has led projects to implement enterprise resource planning (ERP) systems\, low code/no code governance\, risk\, and compliance (GRC) solutions\, robotic process automation (RPA) solutions\, identity credential and access management (ICAM) solutions\, and data warehouse (DW) solutions. She also has experience with independent audits and assessments of information technology (IT) controls in connection with laws\, regulations\, and policies in both government and commercial sectors. She has led clients through all phases of technology implementations\, including solution selection\, business requirements capture\, gap analysis\, redesigning business processes\, designing customizations for gap-fit\, solution testing\, user training\, and post go-live support. She is a Certified Scrum Master (CSM) and has used both Agile and Waterfall implementation methodologies. \n\n\n \n\n\nDr. Farrokh Alemi\nProfessor & Researcher @ George Mason University  \nDr. Farrokh Alemi was trained as an operations researcher and industrial engineer and has worked in both academia and health industry. He maintains patents on (1) sentiment analysis\, (2) measurement of episodes of illness and (3) personalized medicine. He has more than 125 peer reviewed publications in journals such as Health Services Research\, Medical Care\, eClinicalMedicine and Palliative Medicine. His research focuses on causal analysis of massive data available in electronic health records. His publications have contributed to predictive medicine\, precision medicine\, comparative effectiveness of medications\, sentiment analysis\, natural language processing\, as well as other models and trajectories. \nAlemi maintains a decision aid for selection of antidepressants at http://MeAgainMeds.com. Alemi is the author of Multi-Morbidity index\, used in management of polypharmacy patients. In addition\, Alemi was a pioneer in online management of patients and has provided Congressional testimony on role of Internet in health delivery. He is the author of a book on decision analysis and another on policy systems and a third on application of process improvement to personal health. A fourth book\, on causal statistical analysis\, was published in 2020. \n\n\n \n\n\nRodney Snyder\nPartner @ Guidehouse \nRodney is a partner at Guidehouse within our Cyber Security Practice and leads our Supply Chain Risk Management (SCRM)\, Open Source Intelligence (OSINT)\, and Cyber Threats work. This includes leveraging the enormous and fast-growing universe of worldwide\, publicly available. information\, such as cyber\, corporate\, SCRM\, financial\, geolocational\, and open-source data to which data science and analytic tools can be applied. Before joining Guidehouse\, Rodney was a consultant with PwC Public Sector and\, prior to that\, served a full career in the US government\, including as a chief of station in the Middle East\, CIA chief of staff under two directors\, special assistant to the President at the White House\, and assistant commissioner at US Customs and Border Protection. He helped stand up the National Counterterrorism Center and began his career as a presidential management intern and an analyst. \n\n  \nEvent Questions and Policies \nRegistration Questions \nIf you have any registration questions about this event\, please contact the chapter using the Registration Contact Form. \nIf you have CPE questions after the event has concluded\, please contact the chapter using the CPE Contact Form. \n  \nCancellation and Refund Policy \nCancellation and refund for advance registrations is allowed if cancellations are submitted through the registration system. Refunds vary depending on the date of cancellation. See ISACA GWDC Event Policies for details. \nIf ISACA GWDC cancels the event\, all registrants will be notified as soon as possible through email at the email address provided during registration. Full refunds will be provided. \n  \nComplaint Policy \nThe GWDC welcomes your comments\, complaints\, suggestions\, questions\, and other feedback concerning our website information and services. All complaints should be submitted through the Registration Contact Form. \n  \nCPE Information \nEarn up to 4 Continuing Professional Education (CPE) credit in the area of Information Technology. The ISACA® Greater Washington\, D.C. Chapter is registered with the National Association of State Boards of Accountancy (NASBA) as a sponsor of continuing professional education on the National Registry of CPE Sponsors. State boards of accountancy have final authority on the acceptance of individual courses for CPE credit. Complaints regarding registered sponsors may be submitted to the National Registry of CPE Sponsors through its website: www.NASBARegistry.org \n  \nCPE Distribution and Evaluation Survey \nCPEs will be distributed via e-mail along with the event evaluation survey after the completion of the event. Attendees must be present for the full event to receive full CPE credit. \n  \nLearning Objective \nAfter attending this event\, attendees will learn about recent topics in the IT modernization space. \n  \nCPE-Related Details \n\n	Prerequisites: None\n	Advance Preparation: None\n	Program Knowledge Level: Basic\n	Delivery Method:  Group Internet Based\n	Field of Study:  Information Technology – Technical
URL:https://isaca-gwdc.org/event/summer-seminar-itmodernization/
LOCATION:Virtual Event
CATEGORIES:Conferences
ATTACH;FMTTYPE=image/png:https://isaca-gwdc.org/wp-content/uploads/2023/07/summer-seminar-itmodernization-2023.png
ORGANIZER;CN="Avneet Sabharwal":MAILTO:programs@isaca-gwdc.org
END:VEVENT
BEGIN:VEVENT
DTSTART;TZID=America/New_York:20230727T083000
DTEND;TZID=America/New_York:20230727T123000
DTSTAMP:20240911T155506Z
CREATED:20230715T152313Z
LAST-MODIFIED:20240911T155506Z
UID:30664-1690446600-1690461000@isaca-gwdc.org
SUMMARY:Summer Seminar - Cybersecurity
DESCRIPTION:Organizations face complex cybersecurity challenges and need to prepare in addressing current and future cybersecurity risks\, protection of operations and sensitive data\, and compliance with regulatory requirements. Join ISACA Greater Washington DC and Guidehouse for this summer seminar and don’t miss this opportunity to stay ahead of the curve and empower your organization to mitigate cybersecurity risks effectively. \nInformation security program managers\, cybersecurity managers and professionals\, IT audit professionals\, business executives\, students or professionals interested in learning about enhancing cybersecurity posture of organizations should attend this event. \nRegistration closes on July 26\, 2023 @ 8pm.   This is a free virtual event. \nRegister Today! \n  \nEvent Sponsor \nThe GWDC is once again pleased to partner with our Platinum Sponsor Guidehouse on another series of summer seminars. \n \n  \nAgenda \n\n8:30 AM – 9:30 AM \n\n\nAsset Intelligence and Understanding Cyber Risk \nPresenter: Amanda Kane (Guidehouse) \nThe proliferation of technology in today’s digital climate has led to an increase in digital assets\, creating more complexity and risks for organizations in securing networks and protecting data. Many organizations struggle with fragmented asset management and outdated legacy systems as the link between asset intelligence and cyber resilience is often underestimated due to the rapid pace of technological advancements. \nIn this presentation\, Amanda Kane will emphasize the need for an entity-wide shift in thinking\, sophisticated tools for identity and access management\, proactive asset management\, and the right combination of technology and processes to improve asset intelligence and increase resilience against cyber threats. \n\n\n9:30 AM – 10:30 AM \n\n\nNIST SP 800-216 – Federal Vulnerability Disclosure Guidelines \nPresenter: Dr. Kim Schaffer (NIST) \nBy establishing a vetted reporting structure\, federal agencies can focus on mitigating and remediating vulnerabilities in their systems. NIST SP 800-216\, Recommendations for Federal Vulnerability Disclosure Guidelines\, describes the policies and procedures for receiving vulnerability reports\, assessing them\, communicating with stakeholders\, and releasing advisories. The guidelines build upon ISO/IEC 30111 and ISO/IEC 29147 to cover the multitude of systems used by the Federal Government. In this presentation\, Kim Schaffer will highlight the requirements of the IOT Cybersecurity Improvement Act of 2020\, the process of adopting ISO/IEC standards for the Federal Government\, and the steps to take for implementation. \n\n\n10:30 AM – 11:30 AM \n\n\nCybersecurity: Challenges and Regulatory Trends in the Financial Services Industry \nPresenters: Prasun Howli (Guidehouse) and Tracy Angulo (Guidehouse) \nThe compliance requirements for the ever-changing cybersecurity landscape are increasing and becoming a focal point of interest in the cybersecurity world. As a counter measure to the rising cybersecurity regulations\, the adoption of best practices becomes crucial in developing a robust cybersecurity program\, and strategies for safeguarding your organizations’ critical assets. \nIn this presentation\, Prasun Howli and Alma Angotti will explore the latest trends and challenges in cybersecurity\, with a special focus on two crucial regulatory frameworks: the NYDFS (New York Department of Financial Services) cybersecurity regulations and the SEC (Securities and Exchange Commission) proposed rule. \n\n\n11:30 AM – 12:30 PM \n\n\nPrivileged Identity and Digital Risk Assessment Playbooks \nPresenter: Dr. Kenneth Myers (GSA) \nPrivileged users are unique user types that perform various security-related duties. As such\, privileged accounts are most likely to be targeted by cybercriminals or abused by malicious insiders. Unwanted behavior or compromised privileged accounts are responsible for the most high-profile federal and private security breaches. It is a critical Identity\, Credential\, and Access Management (ICAM) capability to secure privileged access. \nIn addition\, digital identity represents each individual engaged in an online transaction. However\, an individual’s real-life identity may not be known when used to access a digital service. Identity proofing helps establish that the individual is who they claim to be. Digital authentication provides reasonable risk based assurances that the individual accessing the application is the same individual who previously accessed the service. \nIn this presentation\, Dr. Kenneth Myers of the GSA will discuss the Privileged Identity Playbook and Digital Risk Assessment Playbook. \n  \n\n  \nPresenters \nAmanda Kane Partner\, Guidehouse \nAmanda Kane leads the Identity and Access Management (IAM) offering within the Advanced Solutions Cybersecurity Solutions Team at Guidehouse. Amanda works with clients so that the right people\, have the right access\, to the right resources\, for the right reasons. By taking an identity-centric approach\, Amanda works supports clients in establishing IAM strategies\, creating IAM solution roadmaps\, and implementing IAM technical solutions in the areas of: identity governance\, credentialing solutions\, privileged access management\, logical access control systems\, and physical access control systems. \nDr. Kim Schaffer\nNational Institute of Standards and Technology \nDr. Schaffer is a cybersecurity specialist in the Information Technology Laboratory at the National Institute of Standards and Technology. Formerly a Laboratory Director of a cryptographic security test lab\, Dr. Schaffer joined NIST in 2009 where he has been developing and integrating NIST and ISO/IEC cybersecurity standards. He has over 30 years of experience in cybersecurity\, is a Certified Information Systems Security Professional\, and holds a Doctor of Science in Information Assurance. \nPrasun K. Howli\nDirector\, Guidehouse \nPrasun K Howli is a Director within Banking\, Insurance & Capital Markets practice at Guidehouse. He has over 15 years of experience in advising and working with leading financial institutions. His experience has allowed him to manage some of the large and complex digital transformation\, data privacy\, cybersecurity\, credit reporting and third-party risk management engagements delivering strategic operational improvements. He is experienced in leading alliances with technology vendors and system integrators delivering complex strategic digital transformation engagements with cross functional teams. \nHe led several cybersecurity and technology risk engagements using various frameworks\, standards and regulatory requirements. He also led several data privacy engagements\, digital transformation\, payments and technology enablement engagements delivering strategic operational improvements. \nTracy Angulo\nDirector\, Guidehouse \nTracy Angulo is a Director in the Financial Crime\, Fraud\, & Investigative Services (“FFI”) practice at Guidehouse. She is an accomplished attorney\, Certified Fraud Examiner (“CFE”)\, and Certified Anti-Money Laundering Specialist (“CAMS”) with over 20+ years expertise in administrative law and investigations\, the last 15 in securities law and regulation\, financial crime compliance\, anti-money laundering (“AML”) compliance and financial fraud investigations. At Guidehouse\, Ms. Angulo has provided a wide compilation of financial crimes compliance and financial compliance services including projects for domestic and global financial institutions. \nPrior to joining the private sector\, Ms. Angulo served as a Principal Attorney Investigator in FINRA’s Enforcement Department for over six years and served as an Institutional Integrity Officer at the World Bank Group as a lead investigator in a variety of complex\, high-profile fraud and corruption investigations. \nDr. Kenneth Myers\nGeneral Services Administration  \nKenneth Myers is the Director of the Identity Assurance and Trusted Access Division with the General Services Administration Office of Government-wide Policy. He advises and coordinates government-wide cybersecurity policies and collaborates with federal executive branch agencies on implementation guidance. As an identity professional\, he has experience working with various public and private organizations on digital identity\, PKI\, security management\, and governance challenges. He is a former active duty Marine and received his Doctorate of Science in Cybersecurity from Marymount University. \n  \nEvent Questions and Policies \nRegistration Questions \nIf you have any registration questions about this event\, please contact the chapter using the Registration Contact Form. \nIf you have CPE questions after the event has concluded\, please contact the chapter using the CPE Contact Form. \n  \nCancellation and Refund Policy \nCancellation and refund for advance registrations is allowed if cancellations are submitted through the registration system. Refunds vary depending on the date of cancellation. See ISACA GWDC Event Policies for details. \nIf ISACA GWDC cancels the event\, all registrants will be notified as soon as possible through email at the email address provided during registration. Full refunds will be provided. \n  \nComplaint Policy \nThe GWDC welcomes your comments\, complaints\, suggestions\, questions\, and other feedback concerning our website information and services. All complaints should be submitted through the Registration Contact Form. \n  \nCPE Information \nEarn up to 4 Continuing Professional Education (CPE) credit in the area of Information Technology. The ISACA® Greater Washington\, D.C. Chapter is registered with the National Association of State Boards of Accountancy (NASBA) as a sponsor of continuing professional education on the National Registry of CPE Sponsors. State boards of accountancy have final authority on the acceptance of individual courses for CPE credit. Complaints regarding registered sponsors may be submitted to the National Registry of CPE Sponsors through its website: www.NASBARegistry.org \n  \nCPE Distribution and Evaluation Survey \nCPEs will be distributed via e-mail along with the event evaluation survey after the completion of the event. Attendees must be present for the full event to receive full CPE credit. \n  \nLearning Objective \nAfter attending this event\, attendees will learn about recent topics in the cybersecurity space. \n  \nCPE-Related Details \n\n	Prerequisites: None\n	Advance Preparation: None\n	Program Knowledge Level: Basic\n	Delivery Method:  Group Internet Based\n	Field of Study:  Information Technology – Technical
URL:https://isaca-gwdc.org/event/2023-summer-seminar-cybersecurity/
LOCATION:Virtual Event
CATEGORIES:Conferences
ATTACH;FMTTYPE=image/png:https://isaca-gwdc.org/wp-content/uploads/2023/07/summer-seminar-cybersecurity-2023.png
ORGANIZER;CN="Avneet Sabharwal":MAILTO:programs@isaca-gwdc.org
END:VEVENT
BEGIN:VEVENT
DTSTART;TZID=America/New_York:20230622T093000
DTEND;TZID=America/New_York:20230622T170000
DTSTAMP:20240912T105351Z
CREATED:20230503T004052Z
LAST-MODIFIED:20240912T105351Z
UID:30547-1687426200-1687453200@isaca-gwdc.org
SUMMARY:2023 Annual Meeting
DESCRIPTION:The ISACA® GWDC Annual Meeting is the Chapter’s premium event for the year. The AGM provides training and networking opportunities for all attendees and the opportunity for GWDC members to learn about the Chapter’s health\, achievements\, plans\, and other important matters. Presentations and panels focus on emerging technologies\, risk vectors\, mitigation strategies\, and governance trends. Topics are aimed equally at participants focused on the Government and Private sectors. All our sessions are designed to increase your understanding of current topics and hone your professional skills by learning directly from leading practitioner in their fields. \nThis is an in-person event that will be held at the Hilton McLean Tysons Corner.  IT executives\, management and operations staff\, risk management leaders and professionals\, IT auditors\, cybersecurity professionals\, students or anyone interested in learning more about this topic should attend this event. \nFor the convenience of all our members\, we will make the Chapter’s business session\, the Annual General Meeting (AGM) of the Membership\, available to them on-line. \nAfter the Annual Meeting there will be a networking event in the same venue.  A separate RSVP is required for this event.   \nRegistration closes on June 21\, 2023 @ 5 pm.  \nRegister Today! \n  \n\nEvent Sponsorship \nIf your organization is interested in being a sponsor for this event\, please contact Adnan Sijercic\, Outreach Director\, for details on sponsorship opportunities.  (Go to the Contact Us page select “Sponsorship” under “I have a question about”) \n\n  \nAgenda \n\n\n09:30 AM – 09:40 AM \n\n\nOpening Remarks \n  \n  \n\n\n09:40 AM – 10:30 AM \n\n\nIT System and Security Audit \nPresenter: Clemon Joseph (Deloitte) \nDefining an IT Auditor; Distinguishing the roles/responsibilities between government clients and private sector contractors; and Leveraging technology for Information Systems \n\n\n10:30 AM – 11:20 AM \n\n\nThe Power of Collaboration: ISACA Chapters Building the Industry Through Partnership \nPresenter: Virginia “Ginger” Spitzer (One In Tech) \nThrough a robust Scholarship Program\, ISACA’s Foundation One In Tech provides academic awards through a collaborative model offering US-Based Academic Scholarships and International Academic Scholarships. Within those categories\, we provide awards in partnership with ISACA Chapters\, corporations\, academic institutes\, and other non-profits. The Chapters are the most powerful in impacting their own cities and communities.  \nISACA has approximately 220 chapters around the world\, representing nearly 165 countries. ISACA chapters are uniquely positioned to build the workforce on a global scope. In addition\, corporations are also positioned to build the future workforce that will meet the increasing need for cyber professionals. Together with ISACA’s Foundation\, Chapters can have maximized impact through the Academic Scholarship Program. This presentation outlines the specifics of this powerful collaborative effort. \n\n\n11:20 AM – 12:10 PM \n\n\nThe Banking Crisis: A Failure of Risk Governance \nPresenter: Masood Aziz (BlockFi) \nThe banking crisis has unearthed deep structural shortcomings in both risk governance and lack of adequate regulatory supervision by the financial authorities. The impact\, influence and content of technological advances in banking makes it so that today’s banking is no longer your grandfather’s bank. Advanced payment systems\, the ubiquity of social media and new communication means\, and everyone having a smart phone in their pockets have all come to us so fast that regulators are having challenges keeping up. At the same time\, innovative bank executives\, left unchecked have found ways of increasing their own compensation at the expense of creating systemic risks and costing the public. Our systems of safety and soundness\, including the role of bank board of directors is in question once again. Who is in charge of looking after the interests of customers\, stakeholders\, the public at large\, and the community the organization operates within? Should we count on the CEO\, the Board\, the Internal Auditors\, the External Independent Auditors\, or the Regulatory Agencies? It turns out that all of these parties failed. How can effective Risk Governance be one such solution to help alleviate these failures in the future? \n\n\n12:10 PM – 12:40 PM \n\n\nLunch and Annual Membership Meeting \n(Zoom is only available to GWDC members who cannot attend the conference) \n\n\n12:40 PM – 01:30 PM \n\n\nRisk Management -> Painting the Bridge \nPresenter: Anthony Johnson (Delve Risk) \nDriving organizational change is hard but when you’re trying to change how a company thinks about risk…Well sometimes that’s a bridge too far. The bigger the organization\, the bigger the bridge that needs to be painted. In this discussion we’ll look at how risk management can be optimized and performed to maximize outcomes for even the largest of organizations. We’ll talk about what “painting the bridge” means\, and discuss suggestions for how to measure success when the bridge always seems to keep getting longer while you’re driving down it! \n\n\n01:30 PM – 02:20 PM \n\n\nRethinking Cybersecurity \nPresenter: Eugene H. Spafford (Purdue University) \nWe have been developing and practicing cybersecurity for over 60 years. However\, despite that history\, we still face massive failures and losses. Every year\, there seems to be dozens of new companies and products\, yet none really solve the problems\, which seem to multiply at a faster rate than the solutions available. Perhaps we have been making some incorrect assumptions about the nature of the problem — and the parties involved.  \nIn this talk\, I will discuss some insights gathered from 45 years in the field as both a practitioner and educator. In particular\, I will discuss some of the missteps and misconceptions that have contributed to our problems\, not least of which is the canard “The user is the weakest link.” With a shift in how we think about our goals and approaches we may be able to make more progress in defending our systems. \n\n\n02:20 PM – 02:30 PM \n\n\nCoffee Break \n  \n  \n\n\n02:30 PM – 03:20 PM \n\n\nAutomotive Cybersecurity & Data Management Platform for Connected Vehicles \nPresenter: Haim Kantor (Upstream Security) \nThe Automotive industry is rapidly expanding into a vast smart mobility ecosystem\, introducing new levels of cyber sophistication and attack vectors. \nHaim Kantor\, Upstream’s VP North America will discuss strategies to detect and mitigate critical automotive cyber security risks and vulnerabilities to help automotive and smart mobility stakeholders ensure trust and safety. \nKey topics and takeaways: \n\n	Gain insight into the latest automotive and smart mobility cybersecurity trends\n	Deep dive into the new threat actors\, motivations and impact\n	Learn about increases in API-related incidents and the rise in EV charging infrastructure cyber attacks\n	Get a glimpse into the threats lurking in the deep and dark web\n\n\n\n03:20 PM – 04:10 PM \n\n\nBuilding Value in a World of Change \nPresenter: Douglas W. Webster (TFC Consulting) \nEveryone will agree that we seek to deliver value in our work efforts\, but seldom do we explicitly define what we mean by “value”. This in turn leads to an inability to explicitly manage value delivery. This session will provide a universally valid and actionable definition of value\, explain how every attendee has a role in value delivery\, and discuss overcoming of impediments to the delivery of maximum value. \n\n\n04:10 PM – 05:00 PM \n\n\nHow to lead\, brand and network as an introverted cybersecurity pro: differentiate yourself\, make an impact and drive change without changing your personality \nPresenter: Prachee Kale (Think.Design.Cyber) \nThe presentation educates introverted techies and entrepreneurs to: \n\n	Understand why introverts are critical for advancing cybersecurity today and tomorrow. \n	Be seen\, heard\, and respected as an introvert. Learn how to transmute introversion from a limitation into a superpower. \n	Dispel myths and biases about introverts vs. extroverts and\, how it affects leadership\, driving change\, self-promotion\, branding\, and networking. \n	Develop connections and build relationships that serve you and others. \n	Overcome fears and blocks so you can lead diverse\, high performing teams and drive org change. \n	Learn how to invite and apply diverse perspectives to achieve outcomes\, even those you may disagree with. \n	Practical tips for different types of interactions – how to prepare (before and after). From 1:1s\, small group meetings (15-20 people)\, executive committees\, happy hours to formal events or conferences (15+ people).\n\n\n  \n  \nPresenters \n\n \n\n\nClemon Joseph\nProject Delivery Manager @ Deloitte\nCDFM \nMr. Clemon Joseph currently serves as a Project Delivery Manager at Deloitte with over 17 years of professional experience. He is an Information Technology (IT) and financial audit readiness leader with experience providing cross-functional support to both private and public sector clients. He serves as a technology consultant with the ability to lead teams to assess internal controls of business processes and to deliver training on emerging technologies that adds value to organizations. \n \n\n\n \n\n\nVirginia “Ginger” Spitzer\nExecutive Director @ One In Tech\, an ISACA Foundation \nVirginia “Ginger” Spitzer joined One In Tech\, an ISACA Foundation in November 2019 as the Foundation’s inaugural Executive Director. With a focus of building ISACA’s new Foundation\, One In Tech\, Ginger launched the start-up phase of the Foundation that engages members\, chapters\, organizations and other nonprofits\, corporations\, and the public in supporting the Foundation’s mission. As part of ISACA’s leadership team\, Ginger ensured the Foundation’s work aligned within the strong culture and community of ISACA and offers innovative\, relevant global programming. OIT works to building trust\, care\, confidence\, and career engagement in the digital space for students\, educators\, professionals\, and businesses.  \nGinger brings 25-plus years of non-profit leadership experience in fundraising; foundation start-ups; program development\, operational strategies\, and innovative collaborative models. Much of her extensive career experience has focused on missions working toward equity\, equality\, access\, and awareness within underserved communities. She has specialized in areas of youth development\, education\, and social justice and has led organizations with local\, national\, and global service.  \nBuilding ISACA’s Foundation One In Tech through ISACA chapter and membership engagement is the key focus for Ginger’s work in 2023 and beyond. \n \n\n\n \n\n\nMasood S. Aziz\nHead of Enterprise Risk Management (former) @ BlockFi Inc. \nMasood is a risk management leader\, adviser & guide to executives and board of directors. He has been a Chief Risk Officer\, and Head of Risk Management for PIMCO’s Investment Operations\, when Bill Gross (the “Kind of Bonds”) & Mohamed El-Erianthe managed over $1.9 billion aum and run the world’s largest fixed-income investment management firm. Head of Enterprise Risk Management at BlockFi\, the leading blockchain & Digital Asset fintech. Head of Operational Risk & Compliance at State Street\, the world’s largest custody bank. \nIn working with boards and the C-Suite\, Masood has been a leading expert in establishing the risk governance infrastructure\, including the board and executive level risk and audit committees. He has helped align and integrate risk management within organizational strategies\, and to assure execution\, and profitability. He has defined & established the risk appetite both at the corporate & operational levels\, created committee charters and led the implementation of policy & procedures\, and risk cultures firm-wide. \nMasood was head of service & solution delivery at the Big-4 KPMG & BearingPoint consulting firms\, and run his own consulting firm to support C-Suite & board risk management and operational effectiveness. He has led complex client initiatives\, and managed teams of experts to lead solutions helping clients optimize financial and operational information\, to create growth and profitability\, to manage risk capital\, and address regulatory challenges. \nMasood is an expert in creating and implementing risk systems and technology\, including along blockchain technology solutions. He has led projects to implement systems such as Chase Cooper\, Wolters Kluwer\, QRM\, BondEdge\, Kamakura Risk Manager (KRM). Masood has also created\, designed and implemented an in-house\, proprietary\, risk analytics\, simulation and reporting system. \nMasood is a member of the Directors and Chief Risk Officer Group (DCRO)\, and on the risk leadership group at the Professional Risk Managers’ International Association (PRMIA). He is a frequent speaker and lecturer\, including on TV & radio\, and has published articles and books. He has an MBA from Thunderbird School of Global Management\, a Bachelor of Science degree from Southern Illinois University and has obtained the French Baccalaureat from Paris\, France. \n \n\n\n \n\n\nAnthony Johnson\nManaging Partner @ Delve Risk \nAnthony Johnson is a Managing Partner at Delve Risk\, where he leads a practice focused on driving technology and risk management transformation on behalf of their clients. He brings extensive technical and executive leadership experience to the practice while also serving as a technology advisor to a number of software solution providers. Anthony is a graduate of Indiana University\, where he received a Masters of Business Administration (MBA) and of Regis University where he received a BS in Computer Information Systems.  \nThroughout his career\, Anthony has led some of the largest Cybersecurity programs in the world as the Chief Information Security Officer\, dealing with highly complex multi-national regulatory requirements and ever evolving sophisticated threats. He has driven dramatic program transformations across hundreds of people\, with budgets in the hundreds of millions of dollars; emphasizing the expansion of analytics\, secure from the start architecture\, incident response and cloud first security approaches to shatter expectations of what is possible with “classic corporate teams”. He leads with a people first mentality and is a coach to existing CISO’s around the world\, helping to translate complicated technology issues into actionable strategic plans that align with the corporate and Board objectives.  \nAnthony is a global speaker on the topic of cyber security and enterprise risk\, an active technology evangelist/advisor to emerging and startup companies and has multiple patents in progress related to both risk management and blockchain.  \nPrior to joining Delve Risk\, he served as the Global CISO and Managing Director for multiple Fortune 100 companies\, including Fannie Mae ($120bn) and the Corporate & Investment Bank (CIB) at J.P. Morgan Chase & Company ($35bn).  \nHis other passions include advancing the discussion on diversity and inclusion in the workforce and creating channels for disadvantaged youth to enter the technology field. He lives in the Washington D.C. metropolitan area with his wife and daughter. \n \n\n\n \n\n\nEugene H. Spafford\nProfessor of Computer Sciences @ Purdue University \n\nEugene H. Spafford is a professor of Computer Sciences at Purdue University. He is also the founder and Executive Director Emeritus of the Center for Education and Research in Information Assurance and Security. He has been working in computing as a student\, researcher\, consultant\, and professor for 45 years. Some of his work is at the foundation of current security practice\, including intrusion detection\, incident response\, firewalls\, integrity management\, and forensic investigation. His most recent work has been in cyber security policy\, forensics\, and future threats. He has also been a pioneer in education\, including starting and heading the oldest degree-granting cybersecurity program.\n\nDr. Spafford has been recognized with significant honors from various organizations. These include being elected as a Fellow of the American Academy of Arts and Sciences (AAA&S)\, and the Association for the Advancement of Science (AAAS); a Life Fellow of the ACM\, the IEEE\, and the (ISC)^2; a Life Distinguished Fellow of the ISSA; and a member of the Cyber Security Hall of Fame — the only person to ever hold all these distinctions. \nAmong many other activities\, he is vice-chair of ACM Publications Ethics & Plagiarism Committee\, is editor-in-chief of the journal Computers & Security\, serves on the Board of Directors of the Computing Research Association\, and as a member of the National Security Advisory Board for Sandia Laboratories. More information may be found at https://spaf.cerias.purdue.edu/narrate.html. \n \n\n\n \n\n\nHaim Kantor\nVice President\, North America @ Upstream Security \nHaim leads Upstream’s North America team and business. Haim is an executive Sales and Marketing professional with more than 20 years of experience\, with an unbroken record of success leading sales and marketing strategies to increase revenue. Prior to joining Upstream\, Haim led sales for companies such as Driivz\, Netcracker Technology\, Amdocs and Comverse. \n \n\n\n \n\n\nDouglas W. Webster\nPrincipal @ TFC Consulting\nCGEIT \nThe Honorable Doug Webster is a Principal with TFC Consulting. \nHe is a retired Air Force officer with a subsequent quarter century both working in and consulting to the federal government. He has served as Director of Risk Management at USAID and Deputy Director of the DoD Business Transformation Agency.  As a Senate-confirmed Presidential appointee\, he has served as CFO of both the Department of Labor and the Department of Education. \nHe is pioneer in Enterprise Risk Management in the federal government\, having introduced the topic to the White House in 2008\, established the first federal interest group in ERM that same year\, led the founding of the founding of the Association for Federal Enterprise Risk Management (AFERM) in 2011\, and developed and taught the inaugural ERM course for George Washington University. \nDr. Webster has co-authored or co-edited four books\, including Chasing Change: Building Organizational Capacity in a Turbulent Environment (2009)\, Managing Risk and Performance: A Guide for Government Decision Makers (2014)\, and Value Based Management in Government (2020).  He is an elected Fellow of the National Academy of Public Administration\, and holds the ISACA CGEIT certification. \n \n\n\n \n\n\nPrachee Kale\nCEO/Co-founder @ Think.Design.Cyber\nExecutive Fellow @ CyberTheory Institute  \nPrachee Kale helps introverted techies and entrepreneurs become high impact leaders by transforming their introversion into a superpower that drives change and creates networks that generate returns. Her unique service offerings bust the blocks\, myths and biases of branding\, leadership and networking as introverts vs. extroverts. She has combined her personal experiences and a successful 17-year corporate career in 1) business strategy\, 2) technology & cybersecurity\, 3) equity & inclusion and\, 4) executive coaching to develop her four-step method so her clients have a clear path to transform their fears\, blocks and limits into accelerants.  \nShe is the CEO/Co-founder of Think.Design.Cyber (https://www.thinkdesigncyber.com/)\, TDC LeadersHub (https://www.tdcleadershub.com/) and a Founding Executive Fellow at CyberTheory Institute. Prachee has a Masters Degree in Bioinformatics from George Washington University where she helped her introvert classmates defend their theses\, wrote distributed computing code\, experimented on HIV viruses\, and did PCR tests (yep\, those).  \nPrachee speaks on topics of empowering introverts\, cybersecurity and gender diversity at global conferences\, summits\, and podcasts. She makes meaningful connections with her audience and leaves them with a positive growth mindset\, actionable steps and impact they remember.  \nWhen she’s not working\, Prachee loves to solo travel\, sail\, host dinners. She is a total foodie and will surely whip up something delicious whenever you visit! \nFun facts: Prachee loves boats but is afraid of swimming in open waters\, she was once called a ‘pit-bull’ and ‘passionate’ woman during the same meeting! And\, her sister is a total introvert but a successful Bollywood movie director. \n \n\n  \nVenue Information \nHilton McLean Tysons Corner\n7920 Jones Branch Drive\nMcLean\, Virginia 22102\n \nHotel Website | Phone Number: (703) 847-5000 \nParking Information\nThe hotel offers complimentary parking (Ballroom Entrance / South Parking location). \nNearest Metro\nThe hotel offers free shuttle pick up service from Tysons Corner Metro Station.   To arrange a pickup\, call the hotel at 703-847-5000. \n  \nEvent Questions and Policies \nRegistration Questions \nIf you have any registration questions about this event\, please contact the chapter using the Registration Contact Form. \nIf you have CPE questions after the event has concluded\, please contact the chapter using the CPE Contact Form. \n  \nCancellation and Refund Policy \nCancellation and refund for advance registrations is allowed if cancellations are submitted through the registration system. Refunds vary depending on the date of cancellation. See ISACA GWDC Event Policies for details. \nIf ISACA GWDC cancels the event\, all registrants will be notified as soon as possible through email at the email address provided during registration. Full refunds will be provided. \n  \nComplaint Policy \nThe GWDC welcomes your comments\, complaints\, suggestions\, questions\, and other feedback concerning our website information and services. All complaints should be submitted through the Registration Contact Form. \n  \nCPE Information \nEarn up to 7 Continuing Professional Education (CPE) credit in the area of Information Technology. The ISACA® Greater Washington\, D.C. Chapter is registered with the National Association of State Boards of Accountancy (NASBA) as a sponsor of continuing professional education on the National Registry of CPE Sponsors. State boards of accountancy have final authority on the acceptance of individual courses for CPE credit. Complaints regarding registered sponsors may be submitted to the National Registry of CPE Sponsors through its website: www.NASBARegistry.org \n  \nCPE Distribution and Evaluation Survey \nCPEs will be distributed via e-mail along with the event evaluation survey after the completion of the event. Attendees must be present for the full event to receive full CPE credit. \n  \nCPE-Related Details \n\n	Learning Objective: After this event\, attendees will increase their understanding of current topics and honed their professional skills by learning directly from leading practitioner in their fields.\n	Prerequisites: None\n	Advance Preparation: None\n	Program Knowledge Level: Basic\n	Delivery Method: Live\, in-person\n	Field of Study: Information Technology – Technical
URL:https://isaca-gwdc.org/event/2023-annual-meeting/
LOCATION:Hilton McLean Tysons Corner\, 7920 Jones Branch Drive\, McLean\, VA\, 22102\, United States
CATEGORIES:Conferences
ATTACH;FMTTYPE=image/png:https://isaca-gwdc.org/wp-content/uploads/2023/04/annual_meeting_2023-e1682897030340.png
ORGANIZER;CN="Yehuda Schmidt (Annual Meeting Questions)":MAILTO:programs@isaca-gwdc.org
END:VEVENT
BEGIN:VEVENT
DTSTART;TZID=America/New_York:20230518T083000
DTEND;TZID=America/New_York:20230518T133000
DTSTAMP:20230517T174821Z
CREATED:20230510T011310Z
LAST-MODIFIED:20230517T174821Z
UID:30586-1684398600-1684416600@isaca-gwdc.org
SUMMARY:Risk Management and Governance
DESCRIPTION:The ISACA Greater Washington DC (GWDC) is proud to host our annual Risk Management and Governance conference. This conference is part of our monthly conference series. \nIT professionals\, IT advisory or audit professionals\, business executives\, students or professionals interested in learning more about IT Audit should attend this event. \nRegistration closes on May 17\, 2023 @ 12pm.  \nRegister Today! \n  \nAgenda \n\n08:30 AM – 09:30 AM \n\n\nA Cybersecurity Management Operating System (MOS) \nPresenter: Allan Alford (Allan Alford Consulting) \n\n\n09:30 AM – 10:30 AM \n\n\nCybersecurity Working with the C-Suite and the Tech Leadership to Bring About Results \nPresenter: Scott Rubin (KPMG) \nIn any business or government agency\, the leaders seek to achieve their mission objectives and not get caught up in technical details. Threats from malicious cyber actors and sometimes careless employees can disable or destroy entire electronic information and SCADA systems. While the inclination to learn more about cyber-based threats and environmental losses to availability are at perhaps an all-time high in C-Suites and with Federal Government agency directors\, there is precious little time to waste in enabling smart and useful cybersecurity programs in our workplaces. We can help these leaders by being the bridge between the technical underpinnings that support their mission objectives\, and the technical workforces that spend their time enabling and defending those systems. This topic is for managers and executives that find themselves either too technical or too aligned with the business operations to make all of the necessary connections that lead to effective cybersecurity outcomes. \n\n\n10:30 AM – 11:30 AM \n\n\nData Governance and IT Governance \nPresenter: David Cole \nKnowing your data and how it resides in IT systems assists in developing governance and monitoring of data. \n\n\n11:30 AM – 12:30 PM \n\n\nHow Security Teams Are Failing to Protect Users from 3rd Party Tracking and How to Stop It \nPresenter: Mike Landeck (NTT Data) \nWhile there is significant time and investments made by the CISO and Privacy offices to assure that user data is not leaked from the network\, users’ data- often their most sensitive- is being leaked to third-parties by the myriad of analytics tools that are added to web applications even after they have passed their security testing and privacy impact assessments\, thus creating a blind spot for those who are actually responsible for security and privacy. \nThis talk will provide information to privacy and security professionals on how to identify third-party tracking code that has been added to their applications\, how to assess the severity of the issue\, and how to articulate the problem to their leadership. \n\n\n12:30 PM – 01:30 PM \n\n\nCloud Computing System Implementations: Risk & Governance Audit Considerations \nPresenter: John Heath (KPMG) \nOrganizations are increasingly moving financial systems to cloud environments\, which raises potential risk and governance concerns\, particularly with respect to financial statement audits. During this session the speaker will provide a brief overview of cloud computing followed by risk considerations with respect to cloud migrations addressing areas of project governance\, user security\, data migration\, and control integration. \n\n  \nPresenters \n\n \n\n\nAllan Alford\nPresident & CISO\, Allan Alford Consulting \nWith twenty+ years in information security\, Allan has served as CISO five times in five industries\, with a strong history in technology\, manufacturing\, telecommunications\, litigation\, education\, cybersecurity and more – at companies ranging from 5 to 50\,000 employees. \nAllan parlayed an IT career into a product security career and then ultimately fused the two disciplines. This unique background means that Allan approaches the CISO role with a highly business-aligned focus and an understanding of an organization’s greater goals\, drivers\, methods\, and practices. Allan seeks at all turns to positively impact the top and bottom lines. \nAllan holds a Master of Information Systems & Security and a Bachelor of Liberal Arts with a focus on Leadership. \nAllan gives back to the security community via The Cyber Ranch Podcast\, by authoring articles\, speaking at conferences and teaching. \n\n\n \n\n\nScott Rubin\nDirector\, FED CIO Advisory @ KMPG \nScott Rubin is a Director at KPMG where he leads consulting programs that span the systems engineering spectrum from specific operational capabilities to the enterprise. Scott’s professional career began in the United States Air Force working with electronic cryptographic communication systems. After his military service\, Scott would serve on the staff at the Defense Advanced Research Projects Agency (DARPA) as their inaugural Chief of Information Security\, where he was responsible for the Agency’s operational cyber mission. His career progression spans from working inside of discreet-component TTL and CMOS systems up to designing and deploying large-scale interconnected information system environments in the cloud. \nScott is also an Adjunct Lecturer in Georgetown University’s School of Continuing Studies\, teaching graduate courses in Cybersecurity Risk Management and the Applied Intelligence program. Before Scott came to Georgetown\, he was an Adjunct Professor/Lecturer at George Washington University in the graduate Cybersecurity Policy and Compliance track. \nScott provides instruction across the Cybersecurity and Intelligence landscapes\, from policy and management concepts and practices as well as the complex technical aspects that exist in networked systems. Scott’s instructional coursework experience includes: \n\n	\n\n	Auditing\, Monitoring\, and Intrusion Detection for Information Security Managers\n	Management of Information and Systems Security\n	Managing the Protection of Information Assets and Systems\n	Cybercrime for Information Security Managers\n	Advanced Analytic Techniques in Intelligence\n	Cybersecurity Governance Frameworks\n\n\n\nScott brings over 30 years of professional experience into the classroom environment\, from the leading edges of the Department of Defense\, to federally funded research and development programs in the Intelligence Community\, and across the commercial consulting industry. Scott ties in real-world examples and modern technical and managerial challenges to broaden the course experience. \nWhen Scott is outside of the classroom or not consulting with clients\, he is an active father to his kids Cassandra\, Oliver\, and Miriam\, and doing all he can to keep up with his wife of twenty years\, Brigitta. A graduate from George Washington University with a Master of Engineering in Cybersecurity Policy and Compliance\, Scott keeps active in hobbies that helped launch his career\, including the restoration of classic arcade pinball machine and video games. \n  \n\n\n  \n\n\nDavid Cole\nOwner @ SysAudits.com\nCPA\, CISA\, CRISC \nMr. Cole has an extensive and diverse leadership and management experience covering IT security\, cyber assessments\, regulatory assessments\, IT audits\, and IT operations support. Mr. Cole is currently the owner of SysAudits.com. \nMr. Cole held numerous Director of IS Audit positions at: \n\n	U.S. House of Representatives Office of Inspector General\n	Department of Education\, Office of Inspector General\n	Smithsonian Office of Inspector General\n\nLeadership included: \n\n	Regulatory assessments (ITAR\, FISMA\, and HIPPA) of company and government IT operations\, contract compliance\, outsourced data centers\, and IAAS\, PAAS\, and SAAS cloud operations\n	Drafted national cybersecurity policy for the National Industrial Security Program (NISP) under the Director of National Intelligence\n	C-Suite presentations and Congressional testimony\n	Technical testing and training – pentesting\, disaster recovery\, and others\n	Forensic and technical support to Federal Agent cybercrimes investigations\n\nMr. Cole held numerous IT Operations positions: \n\n	Chief Information Officer\, Defense Security Service (DSS): Executive leadership and management oversight for all IT operations to include multiple datacenters\, systems engineering\, application development\, cybersecurity\, IT policy\, budget and resource planning. Responsible for a $100 million+ annual IT budget and 150+ technical staff supporting 70+ locations.\n	Director Designated Approving Authority\, DSS – CISO for cleared industry with responsibility for certification and accreditation under the NISP of 40\,000+ information systems at 14\,000+ locations.\n\n  \n\n\n  \n\n\nMike Landeck\nDirector of Security Consulting @ NTT Data \nMike Landeck led the security implementation and then operationalized two of the Country’s largest cloud-based healthcare IT projects. Mike has been responsible for the overall security of systems with financial transactions of over $4 billion per month\, as well security programs regulated by HIPAA\, SOX\, PCI\, FISMA (NIST 800-53) the IRS and FedRAMP. \nMike is a frequent conference speaker and workshop presenter focusing on such topics as software security testing and security program management. \n  \n\n\n \n\n\nJohn Heath\nDirector\, Audit\, Technology Assurance @ KPMG LLP \nJohn Heath is an IT director in KPMG’s Federal practice and has more than 17 years of experience providing audit and advisory services to the Federal Government\, commercial organizations\, and not-for-profit organizations. His career has mainly focused on IT support for financial statement audits and system and organization control (SOC) examinations. \n\n  \nVirtual Meeting Information \n\n	This event will be presented through Zoom.\n	Prior to the event\, participants must install the Zoom app on their respective devices or use the web-based Zoom. Calling via the phone may not be entitled to CPE credits.\n	Participants must respond to all the poll questions via the Zoom polling feature or chat log in order to receive NASBA CPE credits.\n	The ISACA Greater Washington\, D.C. Chapter will not be responsible for the participant’s inability to respond to the polls.\n\n  \nEvent Questions and Policies \nRegistration Questions \nIf you have any registration questions about this event\, please contact the chapter using the Registration Contact Form. \nIf you have CPE questions after the event has concluded\, please contact the chapter using the CPE Contact Form. \n  \nCancellation and Refund Policy \nCancellation and refund for advance registrations is allowed if cancellations are submitted through the registration system. Refunds vary depending on the date of cancellation. See ISACA GWDC Event Policies for details. \nIf ISACA GWDC cancels the event\, all registrants will be notified as soon as possible through email at the email address provided during registration. Full refunds will be provided. \n  \nComplaint Policy \nThe GWDC welcomes your comments\, complaints\, suggestions\, questions\, and other feedback concerning our website information and services. All complaints should be submitted through the Registration Contact Form. \n  \nCPE Information \nEarn up to 5 Continuing Professional Education (CPE) credit in the area of Information Technology. The ISACA® Greater Washington\, D.C. Chapter is registered with the National Association of State Boards of Accountancy (NASBA) as a sponsor of continuing professional education on the National Registry of CPE Sponsors. State boards of accountancy have final authority on the acceptance of individual courses for CPE credit. Complaints regarding registered sponsors may be submitted to the National Registry of CPE Sponsors through its website: www.NASBARegistry.org \n  \nCPE Distribution and Evaluation Survey \nCPEs will be distributed via e-mail along with the event evaluation survey after the completion of the event. Attendees must be present for the full event to receive full CPE credit. \n  \nCPE-Related Details \n\n	Learning Objective: After this conference\, attendees will have a better understanding of current trends and practices in risk management and governance.\n	Prerequisites: None\n	Advance Preparation: None\n	Program Knowledge Level: Basic\n	Delivery Method:  Group Internet Based\n	Field of Study:  Information Technology – Technical
URL:https://isaca-gwdc.org/event/risk-conference-2023/
LOCATION:Virtual Event
CATEGORIES:Conferences
ATTACH;FMTTYPE=image/png:https://isaca-gwdc.org/wp-content/uploads/2023/05/risk_conference_2023.png
ORGANIZER;CN="Avneet Sabharwal":MAILTO:programs@isaca-gwdc.org
END:VEVENT
BEGIN:VEVENT
DTSTART;TZID=America/New_York:20230329T100000
DTEND;TZID=America/New_York:20230329T170000
DTSTAMP:20230329T103407Z
CREATED:20230221T002151Z
LAST-MODIFIED:20230329T103407Z
UID:30350-1680084000-1680109200@isaca-gwdc.org
SUMMARY:Women in Technology and Leadership Conference 2023
DESCRIPTION:The ISACA GWDC Chapter is proud to host our 2023 Women in Technology and Leadership Conference. This conference is our premier annual event centered around the experience of women in technology and leadership positions. Our technology enrichment topics will focus on awareness and strategies around Cybersecurity\, Data Privacy\, and Technology Leadership.  Specific leadership focus areas include how to pursue IT and Cybersecurity roles in the organization\, discuss if the glass ceiling is too low\, and how women and advocates may support women’s career paths in technology. Our speakers are top leaders and experts in the technology field\, ready to share their experiences\, insights\, and tips for succeeding in a rapidly evolving industry. Attendees will have the opportunity to learn about the latest trends and challenges\, connect with like-minded professionals\, and engage in thought-provoking discussions. \nThis is an in-person event that will be held at the Hilton McLean Tysons Corner. IT executives\, management and operations staff\, risk management leaders and professionals\, IT auditors\, cybersecurity professionals\, students or anyone interested in learning more about this topic should attend this event. \nThere will be a free networking session after this event.   A separate RSVP is required to attend the networking session.  \nRegistration closes on March 28\, 2023 @ 5 pm.  \nRegister Today! \n  \n\nEvent Sponsorship \nIf your organization is interested in being a sponsor for this event\, please contact Bonita Patillo\, Special Events Director\, for details on sponsorship opportunities.  (Go to the Contact Us page select “Special Events” under “I have a question about”) \n\n  \nAgenda \n\n10:00 AM – 11:00 AM \n\n\nNever Trust\, Always Verify: The Zero Trust Approach to Cybersecurity \nPresenter: Sushila Nair (Capgemini) \nZero Trust is a cybersecurity model that assumes that all resources and services\, both internal and external\, are not inherently trustworthy\, and therefore require strict access control and continuous verification. It’s a departure from traditional perimeter-based security models\, which assume that everything inside the network is safe by default. \nThis presentation will cover the key principles of Zero Trust\, including the principle of never trusting\, always verifying\, the importance of strong identity and access management\, and the need for continuous monitoring and analysis of all network activity. We will also discuss the various components of a Zero Trust architecture and how it differs from traditional security models. \nAdditionally\, the presentation will provide an overview of the steps required to implement a Zero Trust architecture\, the benefits of Zero Trust\, and how Zero Trust can help organizations meet regulatory and compliance requirements. We will also discuss how auditors can assess the effectiveness of a Zero Trust architecture. \nBy the end of this presentation\, attendees will understand the importance of implementing a Zero Trust architecture and how it can help improve their organization’s cybersecurity posture. They will have a solid understanding of the key principles\, architecture\, and benefits of Zero Trust\, as well as how to implement it and how to assess its effectiveness. Overall\, the goal is to provide attendees with the knowledge and tools they need to take the first steps toward a Zero Trust architecture. \n\n\n11:00 AM – 12:00 PM \n\n\nTaking an Identity-centric Approach to Zero Trust \nPresenter: Christine Owen (Guidehouse) \n“Identity is the new perimeter” is being repeated over and over again\, because it’s true! A viable Zero Trust Architectures requires a mature\, enterprise-wide IAM program so an organization can understand who is accessing its resources. Christine will discuss the different IAM tools necessary\, and how they interact together to create the foundation of Zero Trust. \n\n\n12:00 PM – 01:00 PM \n\n\nLunch \n\n\n01:00 PM – 02:00 PM \n\n\nData Governance \nPresenter: Cortney Worthy (Zoom) and La-Nay Grant (Cisco) \nDuring this session\, Cortney will cover the following topics: \n\n	Understanding the difference between Data Governance\, Data Privacy and Data Security and why it matters to your organization.\n	Why a Data Governance Framework is Foundational to an Organization’s Data Security Strategy? And what Role does Identify Management play In Data Governance?\n\n\n\n\n02:00 PM – 03:00 PM \n\n\nResilience in an Era of Disruption \nPresenter: Terry Grafenstine (Citi) \nWe are living in a world where pandemics\, social unrest\, cyber-attacks\, and geo-political tensions are becoming the norm. To survive in this era of disruption\, organizations must shift from a traditional Business Continuity/Disaster Recovery (BCDR) model to Enterprise Resilience. In this session\, attendees will learn about: \n\n	Impacts of Disruption\n	Regulatory Focus on Resilience\n	The differences between BCDR and Enterprise Resilience\n	Key considerations in an Enterprise Resilience Model\n\n\n\n03:00 PM – 04:00 PM \n\n\nCrack the Cybersecurity Career Code – CISO’s guide to different career paths in cybersecurity \nPresenter: Ruchi Shewaramani (WA Health Benefit Exchange) \nDo you aspire to join cybersecurity? Already in cybersecurity and aiming to be a CISO? Did you know you do “not” have to be highly technical to excel in cybersecurity? \nIn this session\, Ruchi Shewaramani will present the various career paths to enter and excel in the highly sought after domain of cybersecurity. She will break some popular myths about cybersecurity. You will hear in depth on the various career opportunities across the fields of Application Security\, Identity & Access Management\, Cloud Security and Governance\, Risk and Compliance. \n\n\n04:00 PM – 05:00 PM \n\n\nPanel Discussion \nPanelists: Cortney Worthy (Zoom)\, Sarah Abedin (BreaktheTide)\, K. Casey Watkins (FTI Consulting\, Inc.)\, and Whitney Singletary \nDuring this session\, panelists will discuss the following questions: \n\n	Is the glass ceiling still too short?\n	How to better support and mentor women in technology.\n\n\n\n05:00 PM – 07:00 PM \n\n\nNetworking Social \nImmediately following this event\, the GWDC will host a networking event. A separate RSVP is required for the networking event. \n\n  \nPresenters \n\n \n\n\nSushila Nair\n Vice President – North American Cybersecurity Practice at Capgemini\nCISSP\, GIAC GSTRT\, CISA\, CISM\, CRISC\, CDPSE\, CCSK\, CCAK \nSushila Nair is Capgemini’s Vice President\, North American Cybersecurity practice. Capgemini is a global leader in providing secure digital transformation for our clients. Sushila has most recently served as the Vice President for cybersecurity offers at NTT Data Services and has held the role of a CISO for 10 years. Sushila has over 30 years of experience in computing infrastructure\, business and security risk analysis\, preventing credit card fraud\, and served as a legal expert witness. Sushila has been featured in global technical events including RSA\, Segurinfo and ISACA’s global conferences\, co-authored books and is regularly quoted in the press. She plays an active role in supporting best practices and skills development within the cybersecurity community through her work with ISACA and CSA. \nSushila is part of the ISACA global emerging trends working group and vice president of ISACA Greater Washington\, D.C. Chapter. Sushila Nair was named by IT Security Guru as one of the Most Inspiring Women in Cyber 2022! \n  \n\n\n \n\n\nChristine Owen\nDirector at Guidehouse \nChristine C. Owen is a recovering attorney who found solace as the Zero Trust Lead at Guidehouse. She is interested in securing people\, things\, applications\, devices\, and the cloud taking an identity-centric approach. Christine oversees and manages client engagements to provide enterprise IAM and Zero Trust solutions. \nChristine learned IAM principles while consulting for an IAM program that encompassed the entire Federal government. She then moved into a sandbox\, teaching First Responders how to secure their systems; her work resulted in the ICAM Educational Series\, published on the DHS S&T website. In her downtime\, Christine enjoys bourbon\, her grumpy Westie\, and chatting about IAM with anyone who will listen. \n \n\n\n \n\n\nCortney Worthy\nLeader of Data Governance & Compliance at Zoom Video Communications \nCortney Worthy is a passionate Data Governance & Management executive with 14+ years experience. A Mississippi native\, Cortney relocated to the DC Metro area after obtaining a degree in Finance from the University of Memphis and started a career in government consulting. She has successfully led the stand up of several Chief Data Offices across multiple government agencies to include the Department of Defense\, Department of State\, and United States Citizenship and Immigration Services. Cortney currently serves as the Leader of Data Governance & Compliance at Zoom Video Communications where she leads the maturation of data governance capabilities. Cortney’s self-proclaimed super power is her ability to “build relationships of influence to lead organizations to data driven insights with governance as a foundation”. When she’s not working tirelessly to ensure your data is safe and secure\, she serves as a Girl Scout Leader mentoring the next female generation of developers\, engineers\, data scientists\, and leaders. You can also find her making her way up the charts on the Peloton leader board! \n \n\n\n \n\n\nRuchi Shewaramani\nChief Information Security Officer at WA Health Benefit Exchange \nRuchi Shewaramani is a cyber security executive with 15+ years of experience in Information Technology Security\, Identity and Access Management (IAM)\, Governance\, Risk and Compliance (GRC) across Healthcare\, Education and Financial institutions. She holds a Masters in Software Engineering from Seattle U. In the last decade\, she has managed the security program for various Health and Human Services Agencies in the District of Columbia (DC) and Washington state and successfully cleared numerous federal audits. She specializes in leading HealthCare agencies to secure their data\, be compliant with state/federal partners and provide digital trust to the citizens they serve. She is currently serving as the Chief Information Security Officer for WA Health Benefit Exchange and as a Board member for ISACA Greater Washington DC Chapter. \n  \n\n\n \n\n\nTerry Grafenstine\nChief Auditor\, Technology and Business Services at Citi\nCPA\, CISSP\, CISA\, CIA\, CRISC\, CGEIT\, CGAP \nTerry Grafenstine was appointed as the Chief Auditor for Technology and Business Services in November 2020. She is responsible for leading the Internal Audit teams covering technology infrastructure\, cyber\, resilience\, platforms and applications within businesses and functions\, and global business services. Terry joined Citi in April 2019 as the Chief Auditor of Cyber\, Third Party Risk Management\, and Business Continuity. \nTerry has over 25 years of experience in the internal auditing and information technology profession. Before joining Citi\, Terry was a Managing Director in Deloitte’s Risk and Financial Advisory practice where she provided strategic advisory services to Chief Audit Executives across all commercial industries and IT audit\, risk\, and governance advisory services to first line executives in the defense and national security space. Prior to joining Deloitte\, Terry served for eight years as the appointed Inspector General of the U.S. House of Representatives\, where she designed\, managed\, and delivered audit and investigative services\, including the annual financial statement audit and a comprehensive cyber assurance program. \nTerry has held numerous leadership roles to support the auditing\, accounting\, and information technology profession\, including as ISACA’s Global Chair (2017-2018) and as a member of the AICPA board of directors. She currently serves on both the IIA’s North American and Global Boards of Directors. Terry speaks globally on a wide range of subjects\, including cyber security\, internal auditing\, accounting standards\, resilience\, leadership\, and risk. In 2019\, the Institute of Internal Auditors (IIA) recognized Terry as one of the “Top Ten Audit Thought Leaders of the Decade” and inducted Terry into their Hall of Distinguished Audit Practitioners\, the highest honor given by the IIA’s North American board for the accomplishments and contributions made by individuals to advance the internal audit profession. She has received numerous awards and accolades\, including FedScoop’s “Golden Gov Federal Executive of the Year\,” the Greater Washington DC Society of CPAs “Government CPA Leader of the Year”\, the NY Metropolitan ISACA Chapter’s “Joseph J Wasserman Cyber and Governance Leader of the Year\,” and ISACAs “Common Body of Knowledge” and “Best International Conference Speaker of the Year” awards. \nTerry holds a bachelor’s degree in Accounting from Saint Joseph’s University and is a Certified Public Accountant (CPA)\, Certified Information Systems Security Professional (CISSP)\, Certified Information Systems Auditor (CISA)\, Certified Internal Auditor (CIA)\, Certified In Risk and Information Systems Control (CRISC)\, Certified in the Governance of Enterprise IT (CGEIT)\, and Certified Government Auditing Professional (CGAP). Terry has been with Citi IA for 4 years\, has 29 years of auditor experience and 2 years of non-auditor experience. \n \n\n\n \n\n\nSarah Abedin\nFounder and CEO of BreaktheTide\nCISA\, CGEIT\, CRISC\, CDPSE \nSarah Ahmad Abedin is the Founder and CEO of BreaktheTide\, a 501c(3) nonprofit organization in the United States. BreaktheTide (www.breakthetide.org) provides a fundraising platform for nonprofit organizations to help raise funds for empowering women\, children and underprivileged communities. She is a Board member of Sambhali U.S.\, a nonprofit organization in the United States. Sambhali U.S. is a volunteer organization for Girls and Women Empowerment in Jodhpur\, India. Sarah is also a Board member of Gultaz Memorial School and College in Doulatpur\, Chattogram\, Bangladesh. \nSarah is an Information Technology and Cybersecurity expert by profession with extensive management and leadership experience on a broad range of complex\, fast-paced environments in public and private sectors. She started her career as an IT Auditor for the State of Michigan Office of the Auditor General and over the next 30 years she has worked in various capacities for global companies like KPMG\, Financial Industry Regulatory Authority (FINRA)\, NASDAQ Stock Market\, IBM and others. Sarah specialized in IT Security\, Cybersecurity\, Enterprise Governance\, Risk\, Compliance and Privacy in addition to her audit experience (internal and external). Her expertise is in the US Federal Law (NIST\, FISMA\, FedRAMP\, US Data Privacy law\, SOX\, HIPAA)\, COBIT with an emphasis on Strategy\, Governance\, Risk\, Compliance\, Security and Privacy. \nSarah has always been passionate to work in the developmental areas for empowering girls and women.  She has been a mentor and a founding Advisory Council Member of ISACA’s SheLeadsTech (2017-1018). She was also the first Bangladeshi American President (2013-2016) of the Greater Washington DC (GWDC) Chapter of ISACA\, the largest chapter in the world. She was a Member of Privacy Advisory Group of ISACA (2020-2021) and Governance Committee of ISACA (2019-2020). She was an Expert Reviewer of COBIT 2019 Framework (Introduction & Methodology; Governance & Management Objectives). She started the annual Women in Leadership & Technology conference for GWDC in 2016 and hosed this event every year since 2016 to present. \nSarah was an Adjunct professor at the University of Maryland Global Campus (Fall 2012) and an Advisory Board Member of University of Maryland Global Campus\, Graduate School of Management and Technology (Financial Management & Accounting). \nSarah obtained her BBA in Accounting Information Systems from Eastern Michigan University and MBA in Electronic Business from Carey Business School of Johns Hopkins University. \n \n\n\n \n\n\nLa-Nay Grant\nData Governance Leader\, CISCO \nLa-Nay is a leader within Data Governance and has 15+ years of experience. She began her career as a Congressional Intern then led advanced Data Analytics efforts as a Federal Government employee. She is an Ex-Big Senior Manager that now works for Cisco. In her current role she creates policy and initiatives that ensures her organization is compliant with local and international rules and regulations. As well as moving data operations forward by creating robust and innovative solutions that increase business value. She is a big believer in understanding how users see\, process\, and execute on data from various angles to best effect change. \nLa-Nay is a lifelong East of the River Washingtonian. She is a proud HBCU graduate and an active alumni member. She has created and launched mentoring programs focusing on HBCU students and STEM based extracurricular programs for middle school students. She holds a BS in Information Science and Systems from Morgan State University and a MA in Forensic Psychology from Marymount University. \n \n\n\n \n\n\nK. Casey Watkins\nHead of Global Cybersecurity & Privacy\, FTI Consulting\, Inc. \nFor more than 15 years Casey Watkins has served as FTI Consulting’s Head of the Global Cybersecurity & Privacy (GCP) Division based in the Mclean\, VA office. \nMr. Watkins is an information security\, privacy and risk management professional\, executive\, researcher and cybersecurity change agent with many years of information technology and business leadership experience. He is responsible for maintaining FTI’s security and privacy standards and keeping the firm’s security and privacy program up to date. He has over 30 years professional experience in Information Technology and Management with experiences in IT Management\, Project/Program Management\, Network Engineering\, Systems development design\, analysis and implementation; Information Security and IT Audit for complex multi-national organizations and the Department of Defense having spent a combined total of 24 years active and reserve as an Officer in the United States Army. \n \n\n  \nVenue Information \nHilton McLean Tysons Corner\n7920 Jones Branch Drive\nMcLean\, Virginia 22102\n \nHotel Website | Phone Number: (703) 847-5000 \nParking Information\nThe hotel offers complimentary parking (Ballroom Entrance / South Parking location). \nNearest Metro\nThe hotel offers free shuttle pick up service from Tysons Corner Metro Station.   To arrange a pickup\, call the hotel at 703-847-5000. \n  \nEvent Questions and Policies \nRegistration Questions \nIf you have any registration questions about this event\, please contact the chapter using the Registration Contact Form. \nIf you have CPE questions after the event has concluded\, please contact the chapter using the CPE Contact Form. \n  \nCancellation and Refund Policy \nCancellation and refund for advance registrations is allowed if cancellations are submitted through the registration system. Refunds vary depending on the date of cancellation. See ISACA GWDC Event Policies for details. \nIf ISACA GWDC cancels the event\, all registrants will be notified as soon as possible through email at the email address provided during registration. Full refunds will be provided. \n  \nComplaint Policy \nThe GWDC welcomes your comments\, complaints\, suggestions\, questions\, and other feedback concerning our website information and services. All complaints should be submitted through the Registration Contact Form. \n  \nCPE Information \nEarn up to 6 Continuing Professional Education (CPE) credit in the area of Information Technology. The ISACA® Greater Washington\, D.C. Chapter is registered with the National Association of State Boards of Accountancy (NASBA) as a sponsor of continuing professional education on the National Registry of CPE Sponsors. State boards of accountancy have final authority on the acceptance of individual courses for CPE credit. Complaints regarding registered sponsors may be submitted to the National Registry of CPE Sponsors through its website: www.NASBARegistry.org \n  \nCPE Distribution and Evaluation Survey \nCPEs will be distributed via e-mail along with the event evaluation survey after the completion of the event. Attendees must be present for the full event to receive full CPE credit. \n  \nCPE-Related Details \n\n	Learning Objective: After this event\, attendees will have a better understanding of Women in Technology and Leadership current trends and practices.\n	Prerequisites: None\n	Advance Preparation: None\n	Program Knowledge Level: Basic\n	Delivery Method: Live\, in-person\n	Field of Study: Information Technology – Technical
URL:https://isaca-gwdc.org/event/women-in-tech-conference-2023/
LOCATION:Hilton McLean Tysons Corner\, 7920 Jones Branch Drive\, McLean\, VA\, 22102\, United States
CATEGORIES:Conferences
ATTACH;FMTTYPE=image/png:https://isaca-gwdc.org/wp-content/uploads/2023/02/women_in_technology_and_leadership_conference_2023-e1677425207400.png
END:VEVENT
BEGIN:VEVENT
DTSTART;TZID=America/New_York:20230223T083000
DTEND;TZID=America/New_York:20230223T123000
DTSTAMP:20230225T125653Z
CREATED:20221220T153038Z
LAST-MODIFIED:20230225T125653Z
UID:29772-1677141000-1677155400@isaca-gwdc.org
SUMMARY:IT Audit Conference 2023
DESCRIPTION:The ISACA Greater Washington DC (GWDC) is proud to host our annual IT Audit conference. This conference is part of our monthly conference series. \nIT professionals\, IT advisory or audit professionals\, business executives\, students or professionals interested in learning more about IT Audit should attend this event. \nRegistration closes on February 22\, 2023 @ 12pm.  \nRegister Today! \n  \nAgenda \n\n8:30 – 9:30 AM \n\n\nCost Estimating and Scheduling practices for IT modernization Projects \nPresenter: Stephen Gilbride (Library of Congress OIG) \nThis presentation will provide a brief discussion on auditing technical projects for success. Mr. Gilbride will share federal guidance (GAO) and practical experience in the use of Cost Estimating and Scheduling practices for IT modernization projects and programs \n\n\n9:30 – 10:30 AM \n\n\nIT Audit in NASA Environment \nPresenters: Scott Riggenbach (NASA OIG)\, Chris Reeves (NASA OIG)\, and Linda Hargrove (NASA OIG) \nThis presentation will discuss the process of various IT audit performed in NASA environment\, including Cybersecurity Readiness\, Insider Threat and Software Asset Management. \n\n\n10:30 – 11:30 AM \n\n\nIT Audit in Cloud Environments \nPresenters: Shar Qureshi (Deloitte) and Twinkle Patel (Deloitte) \nIn this session\, you will learn about the different types of cloud services and deployment models\, understand the cloud shared responsibility model\, recognize key risks and controls based on the cloud service type\, how to evaluate a SOC report\, and additional considerations from an audit perspective. \n\n\n11:30 AM – 12:30 PM \n\n\nThe value of an IT auditor when integrating controls during a systems implementation or modernization effort. \nPresenter: Geoffery (Geoff) Weber (KPMG) \nGetting controls “right” during systems implementation or modernization efforts is commonly less expensive than designing them post-implementation. Integrators have a tendency to focus on functionality topics rather than controls – perhaps spending more time on users desired business process requirements and screen designs\, for example\, than on security issues. Increasing demands of new regulations for access and security controls provide an opportunity for organizations installing or upgrading ERP systems to design and implement good controls from the onset. This enables the controls to be better monitored and sustained throughout the life of the system. Not doing so has proved expensive: “Going live” before appropriate internal controls are in place negatively impacts business performance and creates unnecessary costs to retrofit controls into the new system. This situation may also cause the organization to report significant control deficiencies and/or material weaknesses. The end result could be adverse audit opinions on the adequacy of their internal controls and financial statements. A proper IT audit lens and methodology that focuses on key control areas helps reduce the risk of failed control environment associated with these systems efforts. \n\n  \nPresenters \nStephen Gilbride\nDirector IT Audits\, the Library of Congress Office of the Inspector General\nCIA\, CISA\, CRISC\, CGFM\, CEH \nMr. Gilbride has been the Director of IT Audits for over 6 years at the Library of Congress Office of the Inspector General. Prior to that he has worked for Accenture Federal Services as a Senior Manager of Internal Audit\, Information Technology. He has also worked for Kearney & Company in the DC area as a Senior Manager of Information Technology Audits for Federal clients. \nMr. Gilbride has a technology engineering background\, having spent twenty years with Nortel Networks in various roles and living in multiple countries designing\, delivering\, and providing sales support for network hardware and software products. \n  \nScott Riggenbach\nAssistant Director IT Audits\, NASA Office Inspector General \nScott Riggenbach has been a member of the NASA Office Inspector General team for the last 17 years based at the Kennedy Space Center in Florida. Prior to that he started his career doing IT audits at Arthur Andersen in Atlanta\, GA and a small startup auditing firm in the DC area. Mr. Riggenbach is an Assistant Director within NASA OIG’s Mission Support Directorate and is responsible for leading the majority of the IT audits for the organization. Scott graduated from Ohio University in Athens\, Ohio and currently resides in Viera\, FL with his wife and two children. \n  \nChris Reeves\nIT Specialist\, NASA Office Inspector General \nChris Reeves has worked for the NASA OIG since 2007. Prior to joining the NASA OIG team Chris spent 10 years serving as an IT specialist in the US Navy. While in the Navy he was responsible for shipboard communications\, information systems administration\, and cyber hygiene. He served at the Space and Naval Warfare Information Technology Center\, the Defense Information Systems Agency\, and the USS Crommelin\, a guided missile frigate based in Pearl Harbor. Chris has led and been involved in a wide range of information technology audits while with the NASA OIG. He has a bachelors in Information Technology Management\, lives in Galveston\, TX and has two young daughters\, Reagan and Avery. \n  \nLinda Hargrove\nIT Specialist\, NASA Office Inspector General \nWith more than three decades of experience in the IT ecosystem\, Linda Hargrove has managed\, led\, and supported complex IT projects for major aerospace programs. Her entire career has been working in data and computing systems at Kennedy Space Center\, FL. Linda is proud to be working at NASA OIG —providing impactful IT oversight by strengthening cybersecurity. Over the years\, her work has garnered various awards\, including NASA’s coveted Space Flight Awareness Launch Honoree Award. Linda holds bachelor and master’s degrees\, with honors\, from Rollins College in Winter Park\, Florida and has taught ‘Computer Systems Analysis & Design’ and ‘Communicating with Technology’ at the collegiate level. \n  \nShar Qureshi\nSenior Manager\, Digital Controls – Cloud Risk\, Deloitte \nShar is a Senior Manager in Deloitte’s Risk and Financial Advisory Digital Controls – Cloud Risk offering. He has been working in financial services and the tech industry for over 19 years. For the past 6 years\, he has been giving all his attention to controls advisory\, assurance and security engagements focusing primarily on AWS. \nHe is a technologist and brings a unique combination of audit/assurance and deep technical understanding of cloud. He has provided guidance to many organizations cross-industry on matters related to governance\, risk management\, compliance and security as organizations navigate their digital transformation. \nHe is an invited speaker and has had the pleasure to present at AWS Re:Inforce\, industry roundtables\, conferences and workshops. He has facilitated numerous cloud audit related courses through many of Deloitte’s partnerships and alliances. He is responsible for leading the upskilling\, cloud fluency\, learning and development initiatives for Deloitte assurance specialists. \n  \nTwinkle Patel\nAdvisory Manager\, Deloitte \nTwinkle Patel is a Manager within Deloitte’s Risk and Financial Advisory Digital Controls – Cloud Risk Offering with over 5 years of experience specializing in Technology Risk. For the past 3 years\, she has been giving all her attention to performing cloud assessments and audits to help companies navigate the cloud environments securely and quickly\, specifically for the Microsoft Azure (Azure) cloud platform. \nPreviously\, Twinkle has worked on Assurance projects\, supporting external financial statement audits\, SOC1 engagements\, and audits in the federal government that are aligned to NIST 800-53 and 800-37. Currently\, she is working on internal audits and projects with a focus on IT security and cloud computing related technologies in the consumer and retail industry. \nIn addition to supporting financial audits\, Twinkle has focused on leveraging her knowledge of IT controls and risk to help serve companies in an advisory capacity\, specializing in risk and control assessments\, pre and post implementation reviews. Twinkle is also currently serving as the project manager on an internal audit project for another publicly listed retail and healthcare company. \n  \nGeoffery (Geoff) Weber\nPrincipal\, KPMG – Federal Practice \nGeoff Weber is a Principal in KPMG’s Federal Practice. His experience spans more than 30 years leading information technology audits and advisory services in the Federal Industry. He currently leads teams assessing technology controls and risks for Federal Audit and Advisory clients. This includes topics such as IT controls\, IT transformation\, ERP/GRC system advisory services\, technology integration\, information security and privacy\, and IT audit and assurance. Geoff began his career in 1991 as a member of the civil service at the Department of Defense and joined KPMG’s Federal Practice in 1998. He earned a BS in Accounting and an MBA from George Mason University and holds CISA and CISM certifications. \n  \nVirtual Meeting Information \n\n	This event will be presented through Zoom.\n	Prior to the event\, participants must install the Zoom app on their respective devices or use the web-based Zoom. Calling via the phone may not be entitled to CPE credits.\n	Participants must respond to all the poll questions via the Zoom polling feature or chat log in order to receive NASBA CPE credits.\n	The ISACA Greater Washington\, D.C. Chapter will not be responsible for the participant’s inability to respond to the polls.\n\n  \nEvent Questions and Policies \nRegistration Questions \nIf you have any registration questions about this event\, please contact the chapter using the Registration Contact Form. \nIf you have CPE questions after the event has concluded\, please contact the chapter using the CPE Contact Form. \n  \nCancellation and Refund Policy \nCancellation and refund for advance registrations is allowed if cancellations are submitted through the registration system. Refunds vary depending on the date of cancellation. See ISACA GWDC Event Policies for details. \nIf ISACA GWDC cancels the event\, all registrants will be notified as soon as possible through email at the email address provided during registration. Full refunds will be provided. \n  \nComplaint Policy \nThe GWDC welcomes your comments\, complaints\, suggestions\, questions\, and other feedback concerning our website information and services. All complaints should be submitted through the Registration Contact Form. \n  \nCPE Information \nEarn up to 4 Continuing Professional Education (CPE) credit in the area of Information Technology. The ISACA® Greater Washington\, D.C. Chapter is registered with the National Association of State Boards of Accountancy (NASBA) as a sponsor of continuing professional education on the National Registry of CPE Sponsors. State boards of accountancy have final authority on the acceptance of individual courses for CPE credit. Complaints regarding registered sponsors may be submitted to the National Registry of CPE Sponsors through its website: www.NASBARegistry.org \n  \nCPE Distribution and Evaluation Survey \nCPEs will be distributed via e-mail along with the event evaluation survey after the completion of the event. Attendees must be present for the full event to receive full CPE credit. \n  \nCPE-Related Details \n\n	Learning Objective: After this conference\, attendees will have a better understanding of current trends and practices in IT Audit.\n	Prerequisites: None\n	Advance Preparation: None\n	Program Knowledge Level: Basic\n	Delivery Method:  Group Internet Based\n	Field of Study:  Information Technology – Technical
URL:https://isaca-gwdc.org/event/2023-it-audit-conference/
LOCATION:Virtual Event
CATEGORIES:Conferences
ATTACH;FMTTYPE=image/png:https://isaca-gwdc.org/wp-content/uploads/2022/12/it_audit_conference_2023-e1676940047519.png
ORGANIZER;CN="Avneet Sabharwal":MAILTO:programs@isaca-gwdc.org
END:VEVENT
BEGIN:VEVENT
DTSTART;TZID=America/New_York:20230119T083000
DTEND;TZID=America/New_York:20230119T123000
DTSTAMP:20230127T234223Z
CREATED:20221220T151918Z
LAST-MODIFIED:20230127T234223Z
UID:29769-1674117000-1674131400@isaca-gwdc.org
SUMMARY:2023 Emerging Technology Conference
DESCRIPTION:The ISACA Greater Washington DC (GWDC) is proud to host our annual Emerging Technology conference. This conference is part of our monthly conference series. \nIT professionals\, IT advisory or audit professionals\, business executives\, students or professionals interested in learning more about emerging technology should attend this event. \nRegistration closes on January 18\, 2023 @ 1pm.  \nRegister Today! \n  \nAgenda \n\n8:30 – 9:30 AM \n\n\nSecure Controls Framework (SCF): The Evolution of Integrated Controls Management (ICM) \nPresenters: Tom Cornelius (ComplianceForge) and David Driggers (HowToGRC) \nThe presentation will cover the past\, present and future of the SCF. This addresses the rise of the metaframework to address Integrated Controls Management (ICM) to address being both “secure and compliant” in an increasingly complex compliance environment. The presentation will also cover the SCF’s Conformity Assessment Program (CAP) that is going live in February to enable first and third-party assessments against tailored SCF control sets. \n\n\n9:30 – 10:30 AM \n\n\nBeyond the Hype of Mesh Architectures \nPresenter: Peter Illdefonso (Amazon Web Services) \nThe buzz of Mesh Architectures promises the zero-ETL\, native\, and seamless integrations for data systems. Cutting through the buzz\, companies are starting to launch services that will facilitate Mesh Architectures. Understanding the concepts of data\, networks\, and systems integrations will help companies build a strategy to maximize the value from these innovations. So far\, most Mesh concepts have been based on a significant amount of manual coding and tagging. Virtualized data catalogs\, zero-ETL connections\, and vendor managed networks will begin to remove the need for manual and error prone integrations. We will explore the constructs of Mesh and use examples from AWS to show how the concept of Mesh is becoming a reality. \n\n\n10:30 – 11:30 AM \n\n\nWarehouse Technology Transformation: A Case Study in Strategic Modernization \nPresenter: Robert Brian Marshal (KPMG) \nAs warehouses continue to transform at exponential rates regarding technology and data platforms\, implementation efforts can far exceed expectations when it comes to costs and results. By developing a strategy to modernize these platforms according to mission needs\, clients can set realistic expectations and procure appropriate systems and technology to realize potential results in the following areas: \n\n	Improved data integrity through enhanced capture techniques\n	Streamlined end-to-end business processes and warehouse operations with internal controls\n	System-based transactional accuracy for inventory balances and financial reporting purposes\n	Carbon-neutral initiatives to meet ESG objectives\n\nOver the past 5 years\, KPMG has helped the Marine Corps to implement technology initiatives at its Wilson Weapons Warehouse in Albany\, GA to establish a foundation on which to build on for future technology modernization and institute a commercial-level transformation in the Federal landscape. This case study will present the efforts to implement a modernization strategy to build that foundational element on which current 5G installation efforts are underway \n\n\n11:30 AM – 12:30 PM \n\n\nThe Modern Digital Workplace: Seven Trends that are Driving Change \nPresenter: Vishal Brown (NTT DATA) \nFactors like remote work\, the emergence of the gig workforce\, and the changing nature of work itself are forcing enterprises to rethink their employee experience. This is driving investment in systems and services that allow employees to stay connected to their business infrastructure and one another\, and support networks with greater resilience across more locations and devices. This talk will frame how we should think about the Modern Workplace and seven important trends shaping it\, and what that means to the design and delivery of workplace services that can lead to superior employee experiences. \n\n  \nPresenters \nTom Cornelius\nSenior Partner\, ComplianceForge \nTom Cornelius is the senior partner at ComplianceForge\, a firm that specializes in cybersecurity and privacy documentation. Tom is also the founder and contributor of the Secure Controls Framework (SCF). \n  \nDavid Driggers\nPartner\, HowToGRC \nDavid Driggers is a partner with HowToGRC\, an advisory firm specializing in implementation and operationalization of SCF-based Integrated Controls Management (ICM) solutions. In addition to being the President of the SCF Accreditation Body (SCF-AB)\, David is also the founder of CMMCplus and SCF Connect cybersecurity software products. \n  \nVishal Brown\nPortfolio Leader – Digital Workplace Services\, NTT DATA\, Inc. \nVishal is the Chief Evangelist and GTM Offering Leader for Digital Workplace Services at NTT DATA with over 20 years of industry experience. Focused on elevating the employee experience and their productivity\, I bring expertise of Modern Workplace technologies that leverage AI\, automation\, and machine learning to enable the Digital Workplace ecosystem. I have helped multiple Fortune 500 organizations design\, implement\, and manage human-centric digital workplace environments. \nHe has published several white papers\, articles\, and blogs and presented at executive industry forums and conferences\, including delivering keynote addresses for worldwide product launches. \n  \nRobert Brian Marshal\nDirector\, Federal Advisory Services\, KPMG \nRobert Brian Marshall is the Warehouse Modernization and Transformation Lead in KPMG’s Federal Advisory Services Practice. With a strong background in defense and commercial supply chain\, logistics\, and operations; his experience includes system design and implementation projects; distribution network strategy development and execution; and business process reengineering for commercial and federal clients. In addition\, he is an Air Force veteran with over 12 years’ experience directing large-scale operations in high-tempo environments. Brian can be found on LinkedIn and is a member of several veteran groups on the social platform. \n  \nPeter Illdefonso\nSolutions Architech\, Amazon Web Services \nPeter Ildefonso has been an Enterprise Solutions Architect for Amazon Web Services for 3 years. He is responsible for working across a large number of industries to identify business problems and working backwards to identify viable and scalable technical solutions. Peter has been helping customers plan and migrate critical workloads for more than 11 years with a recent focus on modern data systems prototyping to provide customers with the speed and scale needed for public facing solutions. He was previously a government cloud migration specialist\, developer\, and systems engineer and is a proud graduate of Clemson University. \n  \nVirtual Meeting Information \n\n	This event will be presented through Zoom.\n	Prior to the event\, participants must install the Zoom app on their respective devices. Participants using the web-based Zoom or calling via the phone may not be entitled to CPE credits.\n	Participants must respond to all the poll questions via the Zoom polling feature or chat log in order to receive NASBA CPE credits.\n	The ISACA Greater Washington\, D.C. Chapter will not be responsible for the participant’s inability to respond to the polls.\n\n  \nEvent Questions and Policies \nRegistration Questions \nIf you have any registration questions about this event\, please contact the chapter using the Registration Contact Form. \nIf you have CPE questions after the event has concluded\, please contact the chapter using the CPE Contact Form. \n  \nCancellation and Refund Policy \nCancellation and refund for advance registrations is allowed if cancellations are submitted through the registration system. Refunds vary depending on the date of cancellation. See ISACA GWDC Event Policies for details. \nIf ISACA GWDC cancels the event\, all registrants will be notified as soon as possible through email at the email address provided during registration. Full refunds will be provided. \n  \nComplaint Policy \nThe GWDC welcomes your comments\, complaints\, suggestions\, questions\, and other feedback concerning our website information and services. All complaints should be submitted through the Registration Contact Form. \n  \nCPE Information \nEarn up to 4 Continuing Professional Education (CPE) credit in the area of Information Technology. The ISACA® Greater Washington\, D.C. Chapter is registered with the National Association of State Boards of Accountancy (NASBA) as a sponsor of continuing professional education on the National Registry of CPE Sponsors. State boards of accountancy have final authority on the acceptance of individual courses for CPE credit. Complaints regarding registered sponsors may be submitted to the National Registry of CPE Sponsors through its website: www.NASBARegistry.org \n  \nCPE Distribution and Evaluation Survey \nCPEs will be distributed via e-mail along with the event evaluation survey after the completion of the event. Attendees must be present for the full event to receive full CPE credit. \n  \nCPE-Related Details \n\n	Learning Objective: After this conference\, attendees will have a better understanding of current trends and practices in emerging technology.\n	Prerequisites: None\n	Advance Preparation: None\n	Program Knowledge Level: Basic\n	Delivery Method:  Group Internet Based\n	Field of Study:  Information Technology – Technical
URL:https://isaca-gwdc.org/event/2023-emerging-tech-conference/
LOCATION:Virtual Event
CATEGORIES:Conferences
ORGANIZER;CN="Avneet Sabharwal":MAILTO:programs@isaca-gwdc.org
END:VEVENT
END:VCALENDAR