BEGIN:VCALENDAR
VERSION:2.0
PRODID:-//ISACA Greater Washington, D.C. Chapter - ECPv6.17.1//NONSGML v1.0//EN
CALSCALE:GREGORIAN
METHOD:PUBLISH
X-WR-CALNAME:ISACA Greater Washington, D.C. Chapter
X-ORIGINAL-URL:https://isaca-gwdc.org
X-WR-CALDESC:Events for ISACA Greater Washington, D.C. Chapter
REFRESH-INTERVAL;VALUE=DURATION:PT1H
X-Robots-Tag:noindex
X-PUBLISHED-TTL:PT1H
BEGIN:VTIMEZONE
TZID:America/New_York
BEGIN:DAYLIGHT
TZOFFSETFROM:-0500
TZOFFSETTO:-0400
TZNAME:EDT
DTSTART:20250309T070000
END:DAYLIGHT
BEGIN:STANDARD
TZOFFSETFROM:-0400
TZOFFSETTO:-0500
TZNAME:EST
DTSTART:20251102T060000
END:STANDARD
BEGIN:DAYLIGHT
TZOFFSETFROM:-0500
TZOFFSETTO:-0400
TZNAME:EDT
DTSTART:20260308T070000
END:DAYLIGHT
BEGIN:STANDARD
TZOFFSETFROM:-0400
TZOFFSETTO:-0500
TZNAME:EST
DTSTART:20261101T060000
END:STANDARD
BEGIN:DAYLIGHT
TZOFFSETFROM:-0500
TZOFFSETTO:-0400
TZNAME:EDT
DTSTART:20270314T070000
END:DAYLIGHT
BEGIN:STANDARD
TZOFFSETFROM:-0400
TZOFFSETTO:-0500
TZNAME:EST
DTSTART:20271107T060000
END:STANDARD
END:VTIMEZONE
BEGIN:VEVENT
DTSTART;TZID=America/New_York:20260514T083000
DTEND;TZID=America/New_York:20260514T123000
DTSTAMP:20260513T221045Z
CREATED:20250824T010024Z
LAST-MODIFIED:20260513T221045Z
UID:34381-1778747400-1778761800@isaca-gwdc.org
SUMMARY:IT Audit and Compliance Conference 2026
DESCRIPTION:  \n \n  \nMay 14\, 2026\nVirtual Event (Zoom)\nEarn up to 4 CPE\n$10 for GWDC Members\n$30 for Non-Members \n  \n  \n\n\n\nIT Audit and Compliance Conference 2026 \nThe IT Audit and Compliance Conference 2026 is part of ISACA GWDC’s monthly conference series focused on professional development in IT audit\, governance\, risk\, and compliance. \nRegistration closes on May 13 @ 5PM. \nRegister Today! \n  \n\n\n\n  \nSponsorship Opportunities \nIf you are interested in sponsoring this event\, or sponsoring the chapter as an annual sponsor\, please visit our sponsorship page. \nSponsorship Info \n  \n\n\n\nEvent Details \n\nDate and Time \n\n\nThe conference will be held on May 14\, 2026 from 8:30 am to 12:30 pm. \nAdd this event to your calendar using the Add to Calendar link at the bottom of the page. \n  \n\n\nVirtual Event \n\n\nThe conference will be held using Zoom. \nPrior to the event\, participants must install the Zoom app on their respective devices. Participants using the web-based Zoom or calling via the phone may not be entitled to CPE credits. \n  \n\n\nPricing \n\n\nThe fee for GWDC Members is $10 for the conference.\nThe fee for all other registrants is $30 for the conference. \nTo become a member and take advantage of the member rate for our events\, among other benefits\, join ISACA and select the Greater Washington D.C. Chapter as your local chapter. \n  \n\n\nEvent Policies \n\n\nCancellation and refund for advance registrations is allowed if cancellations are submitted through the registration system by the date registration closes. Refunds vary depending on the date of cancellation and cost of the event. See ISACA GWDC Event Policies for details. \nThe GWDC welcomes your comments\, complaints\, suggestions\, questions\, and other feedback concerning our website information and services. \nAll complaints should be submitted through the Registration Contact Form. \n  \n\n  \n\n\n\n  \nInterested in Speaking at a Chapter Event \nIf you are interested in speaking at an upcoming conference\, please visit the Call for Speakers page and complete the form. \nCall for Speakers \n  \n\n\n\nConference Agenda \nConference agendas may change due to schedule conflicts and other unexpected situations. If a previously published agenda has changed\, the changes will be noted. \nThe conference agenda is being developed and updates will be posted when available. \n  \n \n\n08:30 AM – 09:30 AM \n\n\nFederal Cyber Risk in Practice: What FISMA and CMMC Mean for Leaders \nPresenter: Dr. Anthony Foreman (Foreleads Leadership Consulting\, LLC) \nFederal cybersecurity regulations are often approached as compliance exercises\, yet their real value lies in how they inform risk-based decision-making. This session examines FISMA and CMMC through a leadership lens\, focusing on how federal and defense organizations can translate regulatory requirements into practical\, operational cyber risk management. \nAttendees will gain insight into how leaders can align governance\, controls\, and organizational accountability to reduce risk\, strengthen resilience\, and support mission outcomes—without treating compliance as a checkbox activity. \n\n \n\n09:30 AM – 10:30 AM \n\n\nThe Future of Assurance \nPresenter: Mica Jimenez (KPMG) \nExplore the evolving landscape of SOC and third-party assurance reports\, with a deep dive into SOC 1s\, their role in internal controls\, and Artificial Intelligence’s (AI’s) impact on these audits. \n\n \n\n10:30 AM – 11:30 AM \n\n\nImplementing and Auditing the CIS Critical Security Controls – Real World Experience \nPresenter: Randy Marchany (Virginia Tech\, SANS) \nDetails on the topic will be posted soon. \n\n \n\n11:30 AM – 12:30 PM \n\n\nSafeguarding Privacy Across the AI Development Lifecycle \nPresenter: Dr. Kyle David (Dr. David\, LLC) \nAs organizations accelerate adoption of artificial intelligence\, protecting individual privacy must remain a central design principle throughout the AI system lifecycle. This presentation provides a practitioner-friendly walkthrough of the OECD’s AI System Lifecycle Framework\, which identifies seven key stages—plan and design; gather and collect data; build and/or adapt models; test\, evaluate\, verify\, and validate; deploy; operate and monitor; and retire/decommission. Each stage introduces distinct privacy threats and risk vectors\, from consent and lawful basis challenges during collection to prompt injection and membership inference attacks during operation. Using real-world examples\, this talk translates complex AI privacy risks into clear\, actionable concepts accessible to non-AI and non-privacy specialists. Attendees will learn how to apply proven mitigations—such as privacy-by-design principles\, differential privacy\, data governance frameworks\, and continuous monitoring—to ensure responsible AI development and deployment. Participants will leave with a structured understanding of how privacy safeguards can be embedded at every step of the AI lifecycle to strengthen trust\, compliance\, and accountability. \n\n  \n\n\n\n  \nShare this Event \nIf you are interested\, planning to attend\, or attending this event\, please share with your colleagues across your social media networks. \n\n	\n		\n	\n			\n			\n								\n										\n													\n														\n												Share on X\n					\n					\n									\n			\n		\n			\n			\n								\n										\n													\n														\n												Share on Linkedin\n					\n					\n									\n			\n		\n			\n			\n								\n										\n													\n														\n												Share on Facebook\n					\n					\n									\n			\n		\n			\n			\n								\n										\n													\n														\n												Share on Print\n					\n					\n									\n			\n		\n			\n			\n								\n										\n													\n												Share on Email\n					\n					\n									\n			\n		\n		\n\n	\n\n\n  \n  \n\n\n\nPresenters \nAt times presenters for a session may change due to schedule conflicts and other unexpected situations. If a previously presenter has been substituted\, the changes will be noted. \n \n\n \n\n\nDr. Anthony Foreman\nForeleads Leadership Consulting LLC\, Founder and Principal Consultant \nDr. Anthony T. Foreman is a senior IT executive and cybersecurity leader with more than 25 years of experience managing mission-critical infrastructure in some of the most secure and high-visibility federal environments in the United States. \nHe currently serves as Division Chief for Data Center Management at the Library of Congress\, where he provides executive oversight for enterprise infrastructure\, cybersecurity remediation\, network modernization\, and risk management initiatives supporting Congressional operations\, digital preservation\, and public access systems. \nDr. Foreman previously held senior leadership roles supporting the White House\, U.S. Marshals Service\, Securities and Exchange Commission\, and USAID\, where he led large-scale modernization efforts\, compliance initiatives\, and incident response operations across classified and unclassified environments. \nHe holds a Doctorate in Organizational Leadership with a concentration in Information Technology\, with research focused on cloud security limitations and risk mitigation. Dr. Foreman is also the Founder and Principal Consultant of Foreman Leadership Consulting\, where he advises organizations on cybersecurity leadership\, governance\, and risk-based decision-making. \n \n\n \n\n \n\n\nMica Jimenez\nManager in KPMG’s Federal Tech Assurance practice \nMicaela (“Mica”) Jimenez is currently a manager in KPMG’s Federal Tech Assurance practice and has more than 14 years of progressive experience performing information technology (IT) financial statement audits\, attestation examinations (i.e.\, SOC 1 Type 1 and 2)\, and performance audits for various Federal and Department of Defense (DoD) agencies. Additionally\, she has 7 years of progressive experience performing Chief Financial Officers Act of 1990 (CFO Act) audits\, IT financial statement audits\, and attestation examinations (i.e.\, SOC 1 Type 2 & FISMA) for the United States Department of the Army (Army)\, United States Department of Agriculture (USDA)\, Small Business Administration (SBA)\, Pension Benefit Guaranty Corporation (PBGC)\, and United States Department of Labor (DOL). Mica and her family relocated from San Diego\, California back in 2009 and currently live in Maryland. \n \n\n \n\n \n\n\nRandy Marchany\nChief Information Security Officer @ Virginia Tech\nSenior Instructor @ SANS \nRandy is the Chief Information Security Officer of Virginia Tech and the Director of Virginia Tech’s IT Security Laboratory and has 25 years experience as a systems administrator\, IT auditor\, and security specialist. He is a co-author of the original SANS Top 10 Internet Threats\, the SANS Top 20 Internet Threats\, the SANS Consensus Roadmap for Defeating DDoS Attacks\, and the SANS Incident Response: Step-by-Step guides. Randy is currently a senior instructor for the SANS Institute and has taught a wide variety of courses over the years. Currently\, he can be found teaching SEC566: Implementing and Auditing CIS Controls on a regular basis. \nRandy holds the unique position of being the longest running SANS Instructor on the planet. After one of his Solaris systems got hacked in 1991 (part of the attack described in the book @Large: The Strange Case of the World’s Biggest Internet Invasion)\, he submitted a proposal for a talk to a startup called the SANS Institute in 1992. Alan Paller invited him to work on some projects with them and he’s been doing cybersecurity work with SANS and in his professional career ever since. \n \n\n \n\n \n\n\nDr. Kyle David\nFounder @ Dr. David\, LLC\nCIPP/US/E\, CIPM\, AIGP\, FIP\, CISSP\, and AAISM \nDr. Kyle David is the Founder of Dr. David\, LLC\, where he has delivered privacy and AI governance training to more than 10\,000 learners across 125 countries. Previously a Presidential Management Fellow at the U.S. Department of Energy\, he led privacy workforce development\, created DOE’s AI literacy course\, and supported the launch of EnerGPT. He holds a Ph.D.\, five IAPP designations (CIPP/US/E\, CIPM\, AIGP\, FIP)\, CISSP\, and AAISM. \n \n\n  \n\n\n\n  \nQuestions about this Event \n\n\nIf you have any registration questions about this event\, please contact us by completing the Registration Contact Form linked below. \nRegistration Questions \n  \n\n\n\n\nIf you have CPE questions after the event has concluded\, please contact us by completing the CPE contact form linked below. \nCPE Questions \n  \n\n\n  \n\n\n\nCPE Information \nEarn up to 4 Continuing Professional Education (CPE) credit in the area of Information Technology. The ISACA® Greater Washington\, D.C. Chapter is registered with the National Association of State Boards of Accountancy (NASBA) as a sponsor of continuing professional education on the National Registry of CPE Sponsors. State boards of accountancy have final authority on the acceptance of individual courses for CPE credit. Complaints regarding registered sponsors may be submitted to the National Registry of CPE Sponsors through its website: www.NASBARegistry.org \n  \n\nPoll Questions \n\n\nParticipants must respond to all the poll questions via the Zoom polling feature or chat log in order to receive NASBA CPE credits. The GWDC will not be responsible for the participant’s inability to respond to the polls. \n  \n\n\nCPE Distribution and Evaluation Survey \n\n\nCPEs will be distributed via e-mail along with the event evaluation survey after the completion of the event. Attendees must be present for the full event to receive full CPE credit. \n  \n\n\nLearning Objective \n\n\nAfter attending this event\, attendees will learn about current and future trends in the IT audit and compliance space. \n  \n\n\nCPE-Related Details \n\n\n\nPrerequisites: None\nAdvance Preparation: None\nProgram Knowledge Level: Basic\nDelivery Method:  Group Internet Based\nField of Study:  Information Technology – Technical
URL:https://isaca-gwdc.org/event/it-audit-and-compliance-conference-2026/
LOCATION:Virtual Event
CATEGORIES:Conferences
ATTACH;FMTTYPE=image/png:https://isaca-gwdc.org/wp-content/uploads/2025/08/it_audit.png
ORGANIZER;CN="Avneet Sabharwal":MAILTO:programs@isaca-gwdc.org
END:VEVENT
END:VCALENDAR