Archived Virtual Conference: Enterprise Risk Management: Provide Security from Cyberthreats 

 

Participate in live, educational sessions presented by experts, ask questions and connect one-on-one with industry professionals, ISACA members and staff during this online, all-day event.

 


Register Now to View Archive

 

Already registered?

Access Archive

Use your user name and password that you created when you registered for the event. Do not use your ISACA login credentials.

The event archive will be available until 22 June 2012.

 


Presented by ISACA

Cyberrisk is a significant enterprise threat and proactive risk management means identifying the risk and implementing appropriate risk mitigation strategies. As the threat landscape changes – and it will, successful enterprises continuously monitor controls to minimize financial and reputational risk. Learn how to recognize your organization’s vulnerability to cyberattacks and understand the importance of having proper security measures on all devices.

Learn best practices and receive expert advice for tackling emerging issues and challenges. Ask questions and interact with speakers and vendors while you connect one-on-one with industry professionals.

Join us on 22 March 2012 from 9:00 to 16:00 CDT (UTC–5) to:

  • Gain knowledge of evolving risk and cyberchallenges
  • Connect with thousands of peers across the globe
  • Earn 5 FREE CPE hours without the cost of travel
  • Ask questions directly to industry experts and speakers
  • Interact with presenters and vendors
  • Enhance your professional knowledge

 


 

Education Sessions:

Session 1: Detecting the Stealthy Attacker: Who Can You trust?

Presented by: Matt Mosley, NetIQ

Matt MosleyMatt Mosley comes to NetIQ with over 15 years of experience in engineering, consulting and management positions with highly successful technology companies. Prior to joining NetIQ, Matt led product management and marketing for Brabeion Software, a leader in IT Governance, Risk and Compliance. As the Senior Product Manager for Security Products at NetIQ, he is responsible for aligning the product roadmap with current and future end user security and compliance objectives. Mr. Mosley has consulted for over two dozen Fortune 100 companies and is a founding member of the ISP Security Consortium, an organization dedicated to improving security amongst Internet providers through the sharing of information and experience. Matt is a frequent speaker at security conferences and holds the CISSP, CISM, and CISA designations.

Despite increasing awareness and implementation of security controls, large organizations are still suffering significant and often public security breaches. How do you detect a potential breach that results from a mistake by an authorized administrator? Are you able to distinguish between a trusted insider and a hacker who has used malware to infiltrate your organization? In this presentation, we will discuss new techniques for protecting sensitive data and mitigating risk and how these approaches differ from traditional solutions.

 

Session 2: Emerging Trends in Cybersecurity and Risk Management

Presented by: Dr. Ron Ross, Senior Computer Scientist and Fellow, National Institute of Standards and Technology (NIST), and the Honorable Theresa Grafenstine, Inspector General of the U.S. House of Representatives 

Dr. Ron RossDr. Ron Ross leads the Federal Information Security Management Act (FISMA) Implementation Project, which includes the development of key security standards and guidelines for the federal government, contractors and the U.S. critical infrastructure. Ross has authored numerous cybersecurity publications and is the principal architect of the NIST Risk Management Framework. He also leads the Joint Task Force Transformation Initiative Working Group, a partnership with NIST, the Department of Defense and the Intelligence Community, to develop a unified information security framework. He is a 3-time recipient of the Federal 100 award and has been inducted into the Information Systems Security Association Hall of Fame.

Theresa GrafenstineTheresa Grafenstine is the fourth person and first woman to be appointed as the Inspector General of the U.S. House of Representatives. She has been with the House OIG since 1998. During her time with the House OIG, Grafenstine led many ground-breaking audits, including the first-ever review of the House Complex fire and emergency response program, as well as numerous security and internal control assessments, including the deployment of Active Directory and the House payroll and financial management systems.

Join Dr. Ron Ross, Senior Computer Scientist and Fellow at the National Institute of Standards and Technology (NIST) and the Honorable Theresa Grafenstine, the Inspector General of the U.S. House of Representatives as they lead an informal discussion on the future direction of cybersecurity and risk management. Ms. Grafenstine will pose a series of probing questions to Dr. Ross on topics ranging from emerging threats in the realm of cybersecurity, the risks of cyberespionage—both in the corporate and government space, issues in cloud and mobile computing, insider threats, industrial control system security, the role of enterprise architecture in helping to secure organizations, and some of the cutting-edge standards and guidelines on the horizon that will help achieve increased levels of security and privacy in information systems.

 

Session 3: Understanding Cyberthreats in the ERM Ecosystem

Presented by: Ramses Gallego, CISM, CGEIT, ISACA Conference Task Force Member, Guidance and Practices Committee Menber, Topic Leader and White Paper Contributor

Ramses GallegoRamses Gallego is security strategist and evangelist at Quest Software, where he also oversees the deployment of services. With a background in business administration and law, Gallego has more than 15 years of security experience with expertise in risk management and governance. Before joining Quest Software, he worked at CA Technologies for 8 years, was regional manager for SurfControl in Spain and Portugal, and most recently was chief strategy officer of the security and risk management practice at Entelgy.

The world we live in is changing. This is a world with no frontiers, no barriers, no secrets. We must expand our vision of the world to include cyberspace as another business landscape, a territory where we have an identity and we do business. Enterprises need to understand the risk that cyberthreats present and incorporate this perspective into their enterprise risk management ecosystem. A blended vision is needed, one that combines physical threats as well as those that come from afar. Join Ramses Gallego as he discusses how to understand the changing face of risk and how cyberthreats must be treated as a security concern.

 

Session 4: How Vulnerable Are You to Cyberattacks?

Presented by: Marc Vael, CISA, CISM, CGEIT, Chief Audit Executive, Smals

Marc VaelMarc Vael is a director of ISACA and chief audit executive at Smals, a large Belgian IT organization with more than 1,800 people working for the Belgian federal government. He has more than 15 years of experience in evaluating, designing, implementing and monitoring solutions on risk and information security management, incident and business continuity management, data protection/privacy, and IT audit.

An ISACA member for more than 15 years, he is vice president of the ISACA Belgium Chapter, chair of ISACA’s Cloud Computing Task Force, chair of the Knowledge Board, member of the Strategic Advisory Council and past chair of the ISACA Communities Committee.

In the current global media, cyberthreats are increasingly identified as not just linked to IT nerds hacking into IT infrastructures, but now to other attackers threatening IT and physical infrastructures. During this presentation, hear 6 valuable lessons -- illustrated with real examples -- learned from cyberattacks. Then learn about 11 practical mitigation strategy solutions. Finally, see how the COBIT framework is used to help you with control objectives for proactively countering these cyberattacks.

 

Further Insight:  Participants may submit questions during the live Q&A sessions that follow each presentation.

Agenda

Live Show:  
Date: 22 March 2012
Title: Enterprise Risk Management: Provide Security from Cyberthreats
Show hours:  9:00–16:00 CDT (UTC-5)

Virtual Seminar Agenda

9:00 Doors open
9:1510:15 Session 1 and Live Q&A
10:1510:30 Booth Activity
10:3011:30 Session 2 and Live Q&A
11:3011:45 Booth Activity
11:4512:30 Networking Lounge
12:30–13:00 Spotlight Session 1
13:00–14:00 Session 3 and Live Q&A
14:00–14:15 Booth Activity
14:15–15:15 Session 4 and Live Q&A
15:15–15:45 Spotlight Session 2
15:45–16:00 Booth Activity & Prize Giveaway
16:00 Doors Close

 

Spotlight Session 1:  Building a Culture of Security

Presented by:  Jo Stewart-Rattray

Jo Stewart-RattrayJo Stewart-Rattray is director of information security at RSM Bird Cameron.

Stewart-Rattray is past president of the ISACA Adelaide Chapter, and is the chair of ISACA's Leadership Development Committee, and is a member of the COBIT Security Taskforce. She has been a member of ISACA's Board of Directors and the Security Management Committee.

Stewart-Rattray has 24 years experience in the IT field; some which were spent as CIO in the utilities space, and 15 in the information security arena. She specializes in consulting in information security issues, with a particular emphasis on governance in both the commercial and operational areas of businesses. She provides strategic advice to organizations across a number of industry sectors, including banking and finance, utilities, automotive manufacturing, tertiary education, retail and government.

This spotlight session is based on the work undertaken by the ISACA Security Culture Taskforce in creating the publication Creating a Culture of Security. Join Jo Stewart-Rattray, Security Culture Taskforce chair, as she defines and identifies culture and provides suggestions and benefits for building a security culture.

 

Spotlight Session 2:  COBIT Process Assessment Model

Presented by:  Greet Volders

Greet VoldersGreet Volders is a managing consultant with her consultancy, Voquals N.V. Volders is experienced in quality management for the IT department, IT governance using COBIT and the development and optimization of business processes.

Since 2002, Volders has been an active member in development teams for COBIT and was part of the team who created COBIT QuickStart. Volders is an accredited trainer for the COBIT Foundation Course and the IT Governance Implementation training, using COBIT. Volders has experience in the internal processes of conforming to SOX and CMMI.

The PAM combines COBIT 4.1 with ISO/IEC 15504-2, and provides the basis for a robust, dependable assessment approach. Join Greet Volders as she explains how the COBIT Assessment Programme is designed to provide consistency and reliability so business and IT leaders can have confidence in the assessment process and the quality of the results as they maximize the business value of their IT investments.

 

Why Attend?

Gain exposure to new thoughts and ideas to discover, implement and deliver results. The Virtual Conference provides a convenient and open forum where you can:

  • Participate in educational sessions presented by knowledgeable speakers and industry experts
  • Earn up to 5 CPE hours with no travel cost
  • Connect with peers around the world
  • Explore the exhibit hall in between sessions, and interact with sponsors, speakers, experts and peers

A resource center, complete with additional information and materials such as white papers, ISACA Journal articles and speaker materials, will also be available.

FAQs

FAQs and Tips for an Enriching, Educational Virtual Experience

  How to Earn CPE (156K)

Describe the virtual conference experience.
You (and several hundred of your peers) will enter a vibrant interface to experience expert informational sessions, peer interaction and the sharing of technology solution insights. Attend sessions with security and compliance experts, visit vendor booths for product information and speak with representatives to answer your questions, download background information on enterprise risk management best practices, and interact with your peers.

How will I be reminded of the seminar?
We don't want you to miss this live interactive broadcast. We will send you email reminders with a link to the environment the day before and the morning of the event, and an Outlook calendar invitation to block out the time on your schedule.

What will I get from this virtual seminar?
Walk away with proven techniques from top experts on managing enterprise risk for improved results. This is a great venue to network with hundreds of peers and leading information systems experts, as well as ISACA staff.

PC Requirements
Click Here to Run System Check

For Technical Support, please email support@inxpo.com

To attend this event you will need a Windows PC with Internet Explorer 6.0 (minimum), or Firefox 3.0 to 3.0.17 and 3.6. Mac users will need Firefox 3.0 to 3.0.17 and 3.6 or Safari 3.1 or higher. We support Windows XP, Windows Vista and Windows 7 on PCs;. Leopard, Tiger, and Snow Leopard on Macs. Linux Fedora Core 10 is also supported. Macromedia Flash Player 10 or higher is required. Access to the internet using high-speed access (Cable, DSL, Network) is highly recommended for the overall environment and required for all presentations. Pop-up blockers must be disabled; cookies and JavaScript must be enabled. On entering the seminar, a system check is run to identify computer requirements essential to interact with the virtual conference. It is recommended to view the environment with the display resolution of 1024 x 768.

The Virtual Conference Environment

  • Exhibit Hall—Stop by vendor booths to learn more about products and services important to you and your organization.
  • Resource Center—Browse content by subject in this digital library. Select content for immediate viewing or save it for future reference.
  • Conference Hall—Make yourself comfortable in a virtual auditorium where speakers and presentations take place.
  • Networking Lounge—Connect with attendees from across the globe. Start a discussion, meet new people or capture the latest information from your peers in this live, dynamic environment.