The Password - March 2010

ISACA - North Texas ChapterThePassword

The Newsletter of ISACA - North Texas Chapter
March 2010
In This Issue:


Letter From the President
Sue Pagel

Hi to All! 

Welcome to our new mini-Newsletter format!  We want to keep you informed not only about our monthly meetings, but about all chapter, local and International activities. Look forward to seeing this on a monthly basis.

I hope it doesn't snow on our March 11th meeting day, as it did in January and February, because we have an exciting program lined up.  We start off with a GRC discussion, lunch over Network Security Considerations, and finish up the day with an Overview of Identity and Access Administration .  And don’t forget to sign up for our Spring Seminar on April 15th, Security and Compliance in Virtualized Environments.  All great educational opportunities.  

Your input is what keeps this organization going, so please feel free to let us know what’s on your mind.

See you at the meeting!

Sue Pagel, CISA, CSOX
Independent Contractor
President - ISACA North Texas Chapter
President@isacantx.org



March 11, 2010 - Meeting Agenda

You have until Noon on Wednesday, March 10th to register for this meeting. But in the event you find you are unable to attend after you've registered, please contact reservations@isacantx.org for assistance with canceling your reservation. This will help us keep our event registration fees reasonably priced.

 

Pre-Luncheon Session - 10:30 AM - 11:20 AM
Governance, Risk and Compliance (GRC)
Anil Markose CISA, CISSP, CIPP, Manager - Ernst & Young LLP

Many organizations have developed risk management activities in silos to meet regulatory and internal reporting requirements. This approach, taken over the years, has created a tremendous amount of overhead and fatigue within the organization when it comes to assessing and reporting on risks at a corporate level. The presentation will highlight the challenges that organizations are facing today around Governance, Risk and Compliance (GRC) with a focus on the concept of risk convergence. In addition, the presentation will discuss how to prepare for an implementation of GRC tools and technologies to enable the consolidated view of risk. After this presentation, attendees will be more aware of the developing GRC market and be in a better position to consider next steps for their own organizations.

A total of 1.0 CPE credits will be awarded.

Luncheon Session - 11:30 PM - 1:30 PM
Network Security Considerations in 2010
Brian J. Thomas CISA, CISSP, Partner Risk Advisory Services, Weaver

A focus on the evolution of network security and some key considerations for IT auditors in 2010. Factors such as our increased dependence on technology, continued development of exploits for security vulnerabilities and motivators such as geopolitical tension or the troubled economy continue to shape the security threats to our organizations. As threats continue to evolve, so do the processes and controls necessary to manage those threats. IT auditors should stay current with the trends in network security to make sure that risks are properly evaluated based on current practices. This presentation will discuss several evolving concepts relating to network security that IT auditors should consider in their 2010 audits.

A total of 1.0 CPE credits will be awarded.

Post Luncheon Session - 1:40 PM - 2:30 PM
Overview of Identity and Access Administration
Mark Wilcox, Principal Product Manager, Identity & Access Management, Oracle

This presentation will provide an introduction to the concepts involved with identity and access administration in particular how it relates to compliance. This includes area such as providing access to personal identity information, user provisioning, application authorization and single sign-on.

Attendees will learn about:

  •  What is Identity and Access Management
  •  Considerations for choosing when to implement an Identity & Access Management solution
  • Complying with various privacy and security rules

A total of 1.0 CPE credits will be awarded.

For details and to register, go to ISACA March 11, 2010 - Registration.


April 8, 2010 - Meeting Presentations

In April, we have yet another exciting and pertinent series of sessions. Be sure to join us then. Registration for the April meeting begins on Friday, March 12, 2010.

 

Topics planned for April are still being arranged, but we currently plan the following:

  • Systems Due Diligence
  • Third Party Service Providers, Updates to SAS70, and the new IAASB standard, ISAE 3402

More complete information will be available by March 12.

 
Marvin Reader

Marvin Reader, CISA
NTTA
VP of Programs - ISACA North Texas Chapter
Programs@isacantx.org



ISACA North Texas Chapter's Spring Seminar – April 15, 2010
     SECURITY AND COMPLIANCE IN A VIRTUALIZED ENVIRONMENT

Virtualization technologies have been aggressively adopted based on the promise of better utilization, increased efficiency, reduced cost and improved infrastructure agility. Organizations taking advantage of the benefits of virtualization will also have to demonstrate efforts to ensure these environments are fully integrated within a broader compliance program. Enterprises currently struggle with complex compliance requirements that include the impact of local data protection, global industry mandates as well as regulatory requirements. In addition, many organizations must navigate the complexities associated with internal polices and agreements with business partners and customers. Because of this, it is critical to have a complete view into how virtualization impacts an organizations’ compliance program.

The Seminar will cover the following topics:

Location: CityPlace Conference Center

Registration Fees: (Includes lunch and snacks)

After online registration ends, member walk-ins will be $225.00 at the door.

Full details and registration are available on our website.

Vinay Gandhi

Vinay Gandhi, CISA, CISM
Independent Consultant - Caris Life Sciences
VP of Education - ISACA North Texas Chapter
education@isacantx.org



CISA & CISM Review Courses

The North Texas Chapter of ISACA is pleased to announce our Spring Review Course schedules. Let us help you prepare for these exams!

The North Texas Chapter is offering a 4-day CISA Review Course and a 3-day CISM Review Course to assist individuals in preparing for the June 12, 2010 exams. These review courses will provide attendees with a presentation for each domain focusing on the key concepts.

When:  CISA - Saturday May 1st, 8th, 15th and 22nd - 9AM-5PM
               CISM - Saturday May 1st, 8th and 15th - 9AM-5PM

Where: UT Dallas Campus - School of Management, Richardson, TX

Cost:    $250 for ISACA members; $300 for non-members

The cost includes lunch and snacks.  Students need to purchase their own 2010 review manuals from the ISACA International bookstore at www.isaca.org.  We also strongly recommend purchasing the 2010 Practice Question Database on CD-ROM.

Students can earn up to 32 CPEs for attending the CISA course, and 24 CPEs for attending the CISM course.

Note: These are review classes and not teaching classes.  CISA attendees are expected to have basic knowledge of IT concepts and auditing skills. CISM attendees are expected to have basic knowledge of information security concepts.  All students are expected to have read their review manuals prior to attending the course.  If you do not prepare, you will not receive the maximum benefit from attending these classes.

Seats are limited, so please register early! The last day to register for these Review Courses is April 23, 2010.

To Register, access the CISA Review page, or the CISM Review page as appropriate.

Questions about our local review courses? Please contact us at certification@isacantx.org.

Greg Streder

Greg Streder CISA
JCPenney
VP of Certification - ISACA North Texas Chapter
certification@isacantx.org



February Luncheon Winners

Following each monthly luncheon meeting, we give away four $50 gift cards to popular merchants in the area, typically Home Depot, Lowe's, Macy's, Nordstrom and/or Best Buy.

To be eligible for the drawing, you must have checked in and paid at the registration table prior to the luncheon and be present at the time of the drawing. Walk-in's who have paid and registered are also included in the drawing. Our luncheon speaker typically draws the names from the basket to ensure objectivity, and the lucky winners are subsequently photographed for posterity.

February's winners are shown below. The next winner could be you!

Sept 2009 Drawing

February 2010
Robert Fadojutimi - Rae Kitchin - Richard Cole - Tony Aguilar


Tracy Durham

Tracy Durham, CISA, CSM, ASM
Raytheon
Hospitality Coordinator - ISACA North Texas Chapter
hospitality@isacantx.org



Surveys By Our Members - Can You Help?

Below are three surveys that our members have been asked to complete. The first is brand-new, received from an officer of ISACA's St. Louis Chapter. The remaining two are continued from our February newsletter, one from our own Hospitality Coordinator, Tracy Durham, and the other from the University of Houston's College of Business.

All three surveys are voluntary and anonymous, and should take only a few moments. Please participate if you can.


Karen Quagliata, an officer with the St. Louis, Missouri Chapter of ISACA, is a doctorial student at the University of Fairfax in Vienna, Virginia (USA). To quote Karen:

"As part of my research project, I have created and posted a survey entitled "Survey on Critical Components of Information Security"  located at http://www.surveymonkey.com/s/QDWSJV6.

"I am reaching out to you today to ask you to please send emails to your membership encouraging them to answer my survey.  The survey only takes approximately 10-15 minutes to complete, but by answering the survey know that you help the information security profession by adding to the body of research knowledge.

"The survey will be available from 03/01/10 until 03/30/10, and is open to all ISACA members in good standing.

"If you have any questions, please contact me at Karen.quagliata@students.ufairfax.org"


Raytheon IT Internal Audit is moving from a start-up IA function to one that is more mature. We wish to ensure we are exploring every avenue to add the most value in the IT Audit arena. To that end, we would like to leverage off what other IT IA functions are considering "value-add" activities. Your input is greatly appreciated.

Please use the following link to respond: http://www.zoomerang.com/Survey/?p=WEB22A7KWRF8HF.

If you have any questions, please contact: Tracy Durham (972) 344-6334 or tracy_durham@raytheon.com.


The link below is to a national survey of Information Systems (IS) professionals' beliefs and opinions about IS development projects. The survey is being conducted by the University of Houston - Downtown.  It is completely voluntary and anonymous.

http://www.isaca.org/Content/NavigationMenu/Students_and_Educators/Academic_Relations/Academic_Advocate/Determinants_of_Information_Systems_Development_Project_Escalation.htm

Increasing our knowledge in this area is vital to the future growth of our global economy. The survey contains 15-25 simple questions to determine your beliefs or opinions about IS development projects, and should take only five minutes of your time.



News from ISACA International

ISACA Training Week

ISACA "Training Week" is taking place in five U.S. locations during 2010. If you are a DFW-area resident, you might consider the event that occurs in Dallas March 22-26. Here is a great opportunity to get that much-needed training without incurring travel costs.

The event takes place at the InterContinental Dallas Hotel on Dallas Parkway, adjacent to the North Dallas Tollway. Attendees can earn up to 38 CPE credits by attending the three different courses being offered. The courses are:

For details, go to www.isaca.org/trainingweek.

Even better, our North Texas Chapter of ISACA will receive $50 for each registrant from our chapter, as part of the agreement of the Training Week local host chapter program. So here is a chance to get great training, earn CPE credits and help the chapter make money. What could be better!


June 12th Exam Date for CISA, CISM and CGEIT

Final registration for the June 12, 2010 CISA, CISM and CGEIT exams is April 7, 2010. To view details on the exams, please visit www.isaca.org/cisaboi, www.isaca.org/cismboi or www.isaca.org/cgeitboi. Registration is available at www.isaca.org/examreg.

Once you have registered for the exam, remember that our North Texas Chapter of ISACA provides Review Courses to help you pass the CISA and CISM exams. These courses occur over 3-4 consecutive Saturdays in May, and again in October for the December exams. Specific details are provided elsewhere in this newsletter.




Discounts Available to ISACA Members

Your membership in ISACA entitles you to frequent discounts for upcoming local and regional training. We would like you to be aware of the following:

Canaudit is providing a 50% discount to ISACA members for its Professional Development Week - May 3-6, 2010 in Austin, TX. Details are provided below:

Dates

Course

CPE Hours

Full Price / Chapter Price

May 3-6, 2010

Performing an IT Audit and Security Baseline  4-DAY / HANDS-ON

32

$2,395 / $1,197.50

May 3-4, 2010

IT Auditing: The First Step  2-DAY

16

$1,195 / $597.50

May 5-6, 2010

Preventing Electronic Fraud and Cyber Incidents  2-DAY

16

$1,195 / $597.50

 
Location Information:
Hilton Garden Inn Austin North
12400 North Interstate Highway 35
Austin, Texas  78753

Register and pay by March 26, 2010 and use code ISACANTX50% to receive this special pricing.
For more information and to register please visit www.canaudit.com or contact Brenna at 805-583-3723 or brenna@canaudit.com

Canaudit, Inc.   •   Tel: 805.583.3723   •  Fax: 805.582.2676   •  www.canaudit.com


 



Job Posting Opportunity, and It's Still FREE ...

Your local ISACA chapter is continuing to encourage firms and recruiters to post their available audit and security-based openings on our local website's JOBS board, without charge. Help bring jobs and job seekers together by promoting job postings - your fellow ISACA members will appreciate it.

All we ask is that you Get Those Jobs Posted. This is a win-win for all concerned employers, recruiters, job candidates and our ISACA chapter.

To post an available position, just complete a Job Posting Template and e-mail it to jobs@isacantx.org. Each job posting will be displayed on our site for one month, but can be reposted again or removed at any time by request.

All posted job descriptions will be included in this newsletter each month .Members can also examine the available positions on the ISACANTX.ORG job board at http://www.isacantx.org/index.cfm/Job_Postings.

Currently, we have three positions posted. See our website for complete details:

Company:   City of Garland
Position:   IT Auditor
Position Type:   Temp-to-Perm
Location:   Garland, Texas, USA

 

Company:   Neohapsis
Position:   Senior Security Consultant
Position Type:   Permanent
Location:   Dallas, Texas, USA

 

Company:   Sumrall Consultants, Inc.
Position:   Integrated Project Manager
Position Type:   Permanent
Location:   Dallas Texas, USA

Interested in positions outside the DFW area, even world-wide? ISACA International maintains a Career Centre that hosts hundreds of available opportunities. Just select Career Centre from the left-hand menu options at www.isaca.org.

Bryan Plantes

Bryan Plantes
Deloitte & Touche
Jobs Coordinator - ISACA North Texas Chapter
jobs@isacantx.org



Questions? Comments? Corrections? Please advise us at newsletter@isacantx.org