The Password - September 2011

The Newsletter of ISACA - North Texas Chapter
September 2011
In This Issue:


Letter From the President
Marvin Reader

Welcome everyone to a new year of ISACA and our first newsletter of the season!   Your North Texas Board of Directors has been working behind the scenes since our last monthly meeting and have lots of great things in store for this year.
Our September meeting takes place next week and will feature two great speakers in the area of security and a post-lunch panel discussion that we believe you will find both interesting and informative.  In addition, we will be presenting our budget for the year. Please register ASAP if you have not already done so.

October will bring our joint meeting with the ACFE which will provide an emphasis on fraud.  Also, the last part of October along with the first three weekends in November should be kept open for those of you looking forward to our fall certification review sessions.

We already have a great fall seminar planned at the beginning of November that will feature one of your favorite instructors, Tanya Baccam.  JCPenney will again host the event so stay tuned as program and registration details will be coming soon.  You are always welcome to host such an event or volunteer your time toward making our seminars successful; just contact Greg Streder, VP of Education.

Let me also remind you that we can always use additional volunteers to make our chapter successful.  Although many of our board members have provided us with their talents for many years, I was simply a luncheon attendee for almost 10 years and only became involved with the board a couple of season ago!  If you indicated an interest in volunteering while completing the chapter survey, look forward to being contacted soon by a board member who will work with you to best use your talents. For those of you who did not already indicate your desire to volunteer, it's not too late. Contact any board member and let us know what you are interested in doing.

Stay tuned to our Chapter Website and your email box for all the North Texas Chapter ISACA News, and we'll see you at the monthly meeting!

Thanks and Take Care.

Marvin Reader, CISA
PricewaterhouseCoopers (PwC)
President - ISACA North Texas Chapter
President@isacantx.org


[Top]


September 8, 2011 - Luncheon Meeting Agenda

You have until noon on Wednesday, September 7th to register for this meeting. In the event you are unable to attend after you've registered, please contact reservations@isacantx.org for assistance with canceling your reservation. This will help us keep our event registration fees reasonably priced.

Pre-Luncheon Session - 10:30 AM - 11:30 AM
Managing Cyber Threats - Risk Management and Insurance Solutions
Doug Jones, Sr. VP & Principal-Roach, Howard, Smith & Barton

How can you apply practical risk management and insurance solutions to protect your company and insulate individuals from personal liability? This presentation will provide prevention and recovery risk management strategies that mitigate the financial impact of a cyber-threat. Additionally, it will provide an overview of the evolving insurance coverage available to protect companies from these emerging risks. Examples of specific claims experiences will be shared to help illustrate what should be implemented and what should be avoided.

Attendees will learn:

  • Practical loss prevention strategies to mitigate, eliminate to transfer cyber risk
  • Practical loss recovery steps after a cyber incident
  • Understanding of available cyber insurance
  • Benefits of cyber coverage and how it responds
  • How to work with your insurance broker and carrier to secure most favorable coverage

Pre-Luncheon registration begins at 10:00 AM.

Luncheon Session - 12:20 PM - 1:20 PM
A State of Dynamic Risk
Branden Williams, Director - RSA Security

The cyber world is heating up, from Cybercriminals and Hacktivists to Nation States and arms brokers in a world Advanced Persistent Threats (APTs). The hype and speculation and fear are high, but the answer lies in some old principles revisited. Manage the unmanageable, know the enemy and build the right structures to survive and even thrive in a new state of ³dynamic risk.² This is about a solid defense doctrine, operationalization and ultimately about familiar management principles applied in new ways.

Attendees will learn:

  • Provide education on this topic for security professionals
  • Frame the issues and the players through the introduction and opening remarks
  • Frame a 'modernized' defense doctrine and principles
  • Make recommendations
  • Seek actionable solutions that can be implemented today.

Lunch registration begins at 11:15 AM. Lunch is served at 11:45 AM.

Post Luncheon Session - 1:30 PM - 2:30 PM

Working with Law Enforcement in a Crisis
Panel of Law Enforcement Officers including Aaron Covey, Dallas FBI

It is important to work with law enforcement agencies during some security incident. The Chief Information Security Officer needs to know how to report an incident and to which enforcement agency. This panel will consist of members from several different agencies and will discuss how to work with different agencies.

Attendees will learn:

  • Fundamental responsibilities of different law enforcement agencies in handling cyber crime
  • What companies should capture and report to law enforcement
  • What to expect when reporting a cyber-crime incident

For complete details, including CPE information, and to register click the buttons below.

Event Details

Register

Copies of the presentations for this meeting will be made available at www.isacantx.org/index.cfm/Presentations,
before the meeting if possible.

Rick Nietubicz

Rick Nietubicz, MBA, CISA, CGEIT, PMP, ITIL, Six Sigma, ISO 20000
Research Now
VP of Programs - ISACA North Texas Chapter
Programs@isacantx.org


[Top]


ISACA North Texas Chapter Education Committee

Hello everyone! Another ISACA year is upon us and Neha Patel, Lisa Bartsch and I comprise your 2011-2012 Education Committee. 

Our Fall Seminar is Active Directory and Windows Security Audits Training presented by Tanya Baccam on November 1 - 3, 2011.  Stay tuned to our Chapter Website and your email box for details coming soon.

The committee has started planning our Spring Seminar and is interested in knowing what training topics you would like to see offered.  Additional committee members are always welcome!   Also, if your company is interested in hosting a future training event, please email us at Education@isacantx.org.

We look forward to seeing you at the September meeting!

Greg Streder

Greg Sreder, CISA, CISSP
VP of Education – ISACA North Texas Chapter
Education@isacantx.org


[Top]


ISACA North Texas Chapter University and Academic Relations Committee

In the coming months, the University and Academic Relations Committee will be focusing on student activities to help prepare them for professional IT Audit positions and to understand the value of ISACA. We plan to:

  
Ahmed Jessa

Ahmed Jessa, CISA, CISM
Ernst & Young, LLP
Director of Academic Relations – ISACA North Texas Chapter
academic_relations@isacantx.org


[Top]


ISACA North Texas Chapter Certification Committee

Hello, I'm Iddah Wangondu and I will be directing the Certification Committee this year. Over the next year we will:

Have your certification already? Why not take the review course again, it's a cost-effective way to earn additional CPEs.

Iddah Wangondu

Iddah Wangondu, CISA, CIA, GSNA, CISSP
Alliance Data
VP of Certification – ISACA North Texas Chapter
certification@isacantx.org


[Top]


Want To Get Published? We'd Like to Hear From You

In today's hectic and challenging business environment, where we are faced with so many different sources of information, e.g., websites, blogs, tweets, listservs, social networks, RSS feeds, etc, competing for our attention, it is increasingly challenging to create a meaningful and relevant newsletter that members have the time and inclination to read. Despite this, the feedback from the annual chapter survey tells us that the newsletter is generally still well received and wanted. However, we'd like to try an make it even better and that is where you come in.

When we compare ourselves to other award-winning chapter newsletters, one area where we have room for improvement is sharing the work experiences of our chapter members. With over a thousand members in a broad range of industries of varying sizes, we have a vast source of experience. Some of you work in best practice audit groups, others are in less mature organizations that are still developing. All of you have something you can share with other chapter members.

We'd like to hear from any member that is willing to write a brief article for the newsletter that would be of interest to fellow practitioners, e.g.:

These are just a few ideas and not meant to be all inclusive.

In addition, if you have any ideas for other content you'd like to see, let us know.

If you'd like to write an article or have ideas for the newsletter please send them to newsletter@isacantx.org.

Matthew C. Smith

Matthew C. Smith, CISA
Capital One
Newsletter Coordinator - ISACA North Texas Chapter
newsletter@isacantx.org


[Top]


Current Job Postings

The word is getting out - that firms and recruiters can post their available audit and security-based openings on our JOBS Board, without charge. Help bring jobs and job seekers together by promoting job postings. Your fellow ISACA members will appreciate it.

As of September 5, 2011, we have ten opportunities posted on the jobs board, as summarized below. See our website regularly for any updates and for complete details. Please note that positions may have been filled or new positions added prior to the newsletter publication, so always check the jobs board directly for the most current status.


Company: Blue Cross Blue Shield of Illinois
Position: Senior Risk & Compliance Specialist
Location: Chicago, IL
Salary: Based on experience

http://www.bcbsil.com/careers/index.html


Company: BrightLine CPAs & Associates, Inc.
Position: Senior Associate
Location: Dallas, TX

Salary: 100k+, including qua
Contact: Jeannie Reyno, 1-866-254-0000, reyno@brightline.com, http://brightline.com/careers/now-hiring?pmc=DI


Company: Brinker International
Position: Senior IT Auditor
Location: Dallas, TX

Salary: $70,000+
Contact: Dipesh Patel, 972-770-8895, Dipesh.patel@brinker.com, http://brinkerjobs.com/


Company: Federal Reserve Bank of Dallas
Position: Auditor
Location: Dallas, TX
Salary: $60,000+
Contact: Angela Gobert-Conway, Angela.gobert@dal.frb.org, http://www.dallasfed.org/careers/careers.cfm


Company: Federal Reserve Bank of Dallas
Position: IT Auditor
Location: Dallas, TX
Salary: $60,000+
Contact: Angela Gobert-Conway, Angela.gobert@dal.frb.org, http://www.dallasfed.org/careers/careers.cfm


Company: GM Financial
Position: IT Staff Auditor II
Location: Arlington, TX
Contact: Bryon Chesser, 817-524-4081, Bryon.Chesser@americredit.com, www.americredit.com


Company: Mary Kay Inc.
Position: Manager Finance Business Strategy – Europe
Location: Addison, TX
Contact: Martha Macias-Alexander, 972-687-4414, HRTempRecp@mkcorp.com, http://www.marykay.com/company/jobsatmarykay/default.aspx


Company: R J Byrd
Position: IT Auditor
Location: Dallas, TX
Contact: Chase Harrison, 214-647-1131, charrison@rjbyrd.com, www.rjbyrd.com


Company: Sumrall Consultants
Position: Sr. IT Auditor - Spanish Reqd.
Location: Dallas, TX
Salary: Based on experience
Contact: Virginia Sumrall, 972-386-4486, sumrall@airmail.net, www.virginiasumrall.com


Company: Sumrall Consultants
Position: Staff IT Auditor
Location: Plano, TX
Salary: Based on experience
Contact: Virginia Sumrall, 972-386-4486, sumrall@airmail.net, www.virginiasumrall.com

Additional details about these jobs and all current job postings are available at: ISACA North Texas Job Postings.


Now, let's get more jobs posted. This is a win-win for all concerned employers, recruiters, job candidates and our ISACA chapter.

To post an available position, just complete a Job Posting Template and e-mail it to jobs@isacantx.org. Each job posting will be displayed on our site for one month, but can be reposted again or removed at any time by request.

All posted job descriptions will also be included in this newsletter each month. Members can also examine the available positions on the ISACANTX.ORG job board at http://www.isacantx.org/index.cfm/Job_Postings.

Don't forget - Postings are FREE!

Vinay Gandhi

Joe McKernan, CISA, CISSP
IBM
Jobs Coordinator - ISACA North Texas Chapter
jobs@isacantx.org


Interested in positions outside the DFW area, even world-wide? ISACA International maintains a Career Center that hosts hundreds of available opportunities. Just select Career Center from the left-hand menu options at www.isaca.org.


[Top]


ISACA North Texas Linked-In Group

Did you know the North Texas Chapter has a group on Linked-In? It’s a great place to post questions and responses to some of those burning security, control and governance questions. After all, we learn from each other and grow from our shared experiences.

To access the group go to http://www.linkedin.com/groups?mostPopular=&gid=1360787

Get Linked-In!

Marvin Reader

Angel Jones, CISA
Fiserv
Marketing Coordinator - ISACA North Texas Chapter
marketing@isacantx.org


[Top]


June Luncheon Winners

Following each monthly luncheon meeting, we give away four $50 gift cards to popular merchants in the area, typically Home Depot, Lowe's, Macy's, Nordstrom and/or Best Buy.

June's winners are shown below. The next winner, at our September 2011 meeting, could be you!

May 2011 Winners

June 2011

Door Prize Winners - Mark Finck, Robert Nebel, Jonathan Young and Matthew Smith

To be eligible for the drawing, you must have checked in and paid at the registration table prior to the luncheon and be present at the time of the drawing. Walk-ins who have paid and registered are also included in the drawing. Our luncheon speaker typically draws the names from the basket to ensure objectivity, and the lucky winners are subsequently photographed for posterity.

Angel Jones

Brittany George Teare, CISA
Weaver
Hospitality Coordinator - ISACA North Texas Chapter
hospitality@isacantx.org


[Top]


News from ISACA International

Register Now for the December ISACA Certification Exams

Register now for the CISA, CISM, CGEIT and CRISC examinations on December 10,2011. Final registration deadline is October 5, 2011. For more details click here


Webinar: PCI: Compliance or Security - September 8, 2011

This 3-letter acronym has significantly impacted the security and IT industry over the last years. Some consider PCI as a daunting undertaking, a source of constraints, stress and restrictions. For them, PCI is at best a supplemental insurance hopefully preventing penalties. Others religiously believe that meeting PCI compliance requirements dramatically increases their overall security posture.

For more details and to register click here


eSymposium: Save the Date - September 27, 2011

Join us on Tuesday, September 27, 2011 to be a part of this important program! Earn 3 free CPE points.

For details and to register click here.


ISACA Training Week - 12-16 September 2011 - Minneapolis, Minnesota

Training week courses use a combination of lecture, class discussion, group exercises and case studies to explore aspects of IT assurance, audit, governance and security. Attendees will learn about proven strategies and techniques based upon best practices and lessons learned from the ISACA community. Participants can earn up to 38 CPE credits.

For details and to register click here


COBIT 5: Framework (public exposure through 18 September 2011)

The latest draft of the next version of ISACA’s governance of enterprise IT framework—the COBIT 5 Framework—is provided for your review and feedback.

This foundational COBIT volume introduces the following, which combine to provide a comprehensive, effective framework to support the governance and management of enterprise information and related technology:

The primary objective of this exposure is to obtain public input and comment regarding the completeness, quality and value of the development work undertaken. Please complete the short survey questionnaire to provide your feedback on the work completed to extend, improve and advance ISACA guidance in this area. This online questionnaire will remain open until 18 September 2011.

For details and to register click here


Information Security and Risk Management Conference - 19-21 September 2011, Las Vegas, Nevada

The Information Security and Risk Management Conference is an all-encompassing security event that merges network security, information security management and risk management. Designed to meet the exact needs of information security professionals, and those who have or plan to attain ISACA's Certified Information Security Manager (CISM) designation, this is an event you will not want to miss. Participants can earn up to 32 CPE credits.

For details and to register click here


Free CPE Using Your ISACA Membership

As a benefit of your ISACA membership, ISACA International is making free CPE available in four different formats. In fact, you can secure up to 72 hours of CPE per year, as follows:

As always, read the full details at http://www.isaca.org/Certification/Pages/How-to-Earn-CPE.aspx.


Doug Gorrie

Doug Gorrie, CISA, CISSP, CIA
INX, Inc.
VP of Communications - ISACA North Texas Chapter
communications@isacantx.org



Questions? Comments? Corrections? Please advise us at newsletter@isacantx.org

The Password is a free copyrighted publication of the North Texas Chapter of ISACA. It is published periodically from August through June. It is an objective of the North Texas Chapter of ISACA to be a forum of free expression and interchange of ideas. Statements of position or expressions of opinion appearing herein are those of the authors and not, by the fact of publication, necessarily those of ISACA or the North Texas Chapter. Likewise, the publication of any advertisement is not construed to be an endorsement of the product or service offered unless specifically stated.
Copyright 2011 ISACA North Texas Chapter - all rights reserved