Latest News and Resources

Latest News and Resources
Latest Resources to the GRC Community
Written by Robin Basham
Thursday, 01 December 2011 00:00
Print E-mail
User Rating: / 8
PoorBest 
Enterprise Architecture and Compliance News - RegWatch and Latest News
Article Index
Latest Resources to the GRC Community
Now Available - Cloud & Virtualization Essentials™ PLEASE SIGN UP
The Holistic Information Security Practitioner Institute (HISPI) now welcomes EnterpriseGRC Solutions
Please Join Us AT ISACA’s 2012 Global Events Highlight Solutions for IT, Business Professionals
HOLD ON, For a short time only you too
All Pages

Mobile Security Technical Conference

Thursday Nov 15th 2012

8:30 am PST till 4:30 PM PST

Biltmore Hotel @ 2151 Laurelwood Road  Santa Clara, CA 95054

Register Now

Registration: Early Bird Registration (ends Nov 5th, 2012)
Members: $100, Non-members $125, Students $75

Regular Registration (from Nov 6th, 2012)
Members: $125, Non-members $150, Students $100

Please join us on Nov 15th for one day Mobile Security Technical Conference. Learn from the industry leader’s experiences and help create a secure mobile working environment for your organization.

Session Schedule

Session Topics

Speaker's

8:00 AM – 8:30 AM

Registration

 

8:30 AM - 9:30 AM

Risk Assessment for Mobile Devices and Applications

Kartik Trivedi Co-Founder at Symosis

9:30 AM - 9:45 AM

Break

 

9:45 AM - 10:45 AM

MDM Solutions: Business and Technical Considerations

Bryan Wise Director of IT at Coherent

10:45 AM - 11:00 AM

Break

 

11:00 AM - 12:00 PM

Mobile Security Innovation: BYOS (Bring Your Own Security)

Ben Ayed Founder - CEO at Secure Access Technologies

12:00 PM - 1:00 PM

Break

 

1:00 PM - 2:00 PM

Mobile Commerce Security

Selim Aissi Chief Security Architect at Visa

2:00 PM - 2:15 PM

Break

 

2:15 PM – 3:15 PM

Lessons Learned: 2 Years into Mobile Security

Mark Mellis
Associate Information Security Officer at Stanford University

3:15 PM - 3:30 PM

Break

 

3:30 PM - 4:30 PM

Panel Discussion: Risk Management in Mobile Society

 

For details please contact This e-mail address is being protected from spambots. You need JavaScript enabled to view it or call on (650) 762-9478.

 


Announcement for FedRamp

As of 9am on Wednesday, June 6th, 2012, the Federal Risk and Authorization Management Program (FedRAMP) Program Management Office (PMO) achieved Initial Operating Capability. As a part of IOC, the FedRAMP PMO is now accepting applications for provisional authorization of cloud systems. The application is currently housed on fedramp.gov and can be accessed via the following URL:http://www.gsa.gov/portal/content/125991

FedRamp's communication encourages all cloud service providers and agencies with cloud services to apply for FedRAMP accreditation. All cloud service offerings used by the federal government are now required to meet the FedRAMP requirements. Should you have any questions or concerns, please don't hesitate to contact the FedRAMP PMO directly ( This e-mail address is being protected from spambots. You need JavaScript enabled to view it ).


 

http://thegrcbluebook.com The GRC Blue Book is the world's largest database of risk and compliance applications. TheGRCBlueBook is the "Angie's List" of GRC vendor applications.  Let's support our well respected colleague James Bone, who's done the homework for us but we must write the reviews!

James Bone President,

Global Compliance Associates, LLC
Risk Luminosity Seminars, LLC
TheGRCBlueBook, LLC
www.globalcomplianceassociates.com
www.riskluminosityseminars.com
www.thegrcbluebook.com

(Reminder to self, get listed in the BlueBook!)

http://www.informaglobalevents.com/event/Risk-Minds-Usa-Conference

  • June 4th - 8th in Boston, MA at Hyatt Regency Boston
  • Risk Minds USA: North America's Leading Risk Management Event With 300+ Delegates
  • TheGRCBlueBook is a media sponsor for this event.

http://www.complianceonline.com/ecommerce/control/seminar?product_id=80026SEM

  • June 18th - 20th in San Francisco, CA at the Grand Hyatt
  • "Thriving on Risk – Risk Management for 21st Century"
  • Sponsored by ComplianceOnline and Produced by Risk Luminosity Seminars
  • Key Note Speaker:  Dr. Sam Savage, author of "The Flaw of Averages", Sanford University
  • Mention Risk Luminosity Seminars to receive discounts for this conference!

If you are interested in what is going on in DC regarding cyber security legislation, here are two easy ways to check in:

National Public Radio’s “Morning Edition” airing about a 5 minute segment on the cyber bill on Tuesday, May 8th that will probably air at either 20 past the hour or 40 past the hour depending on when you receive the show in your area.  I was interviewed for the story.

I also recently sat for an extensive interview with Richard Schlesinger, correspondent for CBS Evening News and EMC, addressing the cyber bills in Congress and how and why regulation will not effectively address our cyber security problems.  That interview is available on the EMC website, just click on the link below.

http://www.emc.com/emc-plus/index.htm

Listen on playback.  Conversation was outstanding!

Cloud Security Summit
Live on May 23-24 and afterward on demand

The main concern preventing organizations from fully adopting cloud-based solutions is doubt about security. Join this two-day Cloud Security Summit to connect with industry thought leaders as they focus on top-of-mind topics for securing the cloud and aligning it with your business.

Global summit lineup includes:

Understanding Cloud Security: Finding the Boundaries
Neira Jones, Head of Payment Security, Barclaycard

Turn Any Cloud into a Trusted and Compliant Environment
Ryan Holland, Solution Architect, AWS & Imam Sheikh, Sr. Product Manager – Cloud and Compliance, SafeNet

Securing the Cloud with SIEM
Marc Blackmer, Senior Product Marketing Manager, Solutions at HP Enterprise Security

View the full program and register to attend here

This week's featured panel: The State of IT Security and GRC in 2012

Live today May 1st at 5 p.m. BST / 1 p.m. EDT / 10 a.m. PDT and afterward on demand

Bringing together the top minds in the industry, The State of IT Security and GRC panel will focus on the challenges and opportunities that make 2012 unique.

Join Ron Ross, Computer Scientist, NIST Fellow; Dr. Anton Chuvakin, Research Director, Gartner; Andrea Hoy, Director, ISSA International; Dr. Said Tabet, Chair of GRC-XML Project, OCEG, as they discuss the technologies and challenges that will define 2012 and beyond.

Attend now

Ron Ross, Andrea Hoy, Said Tabet and Anton Chuvakin


Sponsors of the Cloud Security Summit:

In association with:

The Virtualization & Cloud Computing Group

Association of Information Technology Professionals

About BrightTALK
BrightTALK provides webinars and videos for professionals and their communities. Every day thousands of thought leaders are actively sharing their insights, their ideas and their most up-to-date knowledge with professionals all over the globe through the webinar and video technologies that BrightTALK has created.

Connect with BrightTALK

LinkedIn

For more information, please visit us at www.brighttalk.com, BrightTALK™, 501 Folsom Street, 2nd Floor, San Francisco, CA 94105


 

AuditNet.org

AuditNet® has developed an Audit Utilization of Technology Optimization Scale (AUTOS) to measure the maturity level of the use of audit technology by auditors. How would you rate your department on the use of audit technology?

Here are some of the key findings from other surveys on technology and internal audit1:

According to a recent survey by the Institute of Internal Auditors data mining and analytics are one of the top five skills sought for new internal auditors.

The 2012 Internal Audit Capabilities and Needs Survey by Protiviti reported that CAATs, continuous auditing and continuous monitoring are skills areas that auditors need to improve as the profession moves toward these approaches and techniques.

According to the 2011 TeamMate User Survey it is imperative that all auditors understand the technology tools available and use them on all audits.

The options available to CAE emphasize either hiring auditors with the technology skills to jump start implementation of technology initiatives which helps shorten the learning curve. Additionally providing staff with training for audit technology tools is a must.

According to the Grant Thornton 2012 CAE Survey … most CAEs seem to recognize that their departments can better harness the power of technology. Half of respondents acknowledged their organizations do not effectively use  governance, risk and compliance (GRC)-specific technology. Data analytics and continuous auditing technologies are gaining wider acceptance, however. Still, given the power of today’s technology tools, internal audit can do more.

Also here is the link to the AuditNet® survey which will shed light on how auditors are using technology and how far they have to go to achieve the highest level of maturity.

2012 State of Technology Use by Auditors Survey http://svy.mk/JfsCMC

Also if you are looking for CPE then check out http://www.auditnet.org/ATI_ACLSO.htm

If you are an ISACA member then send an email to This e-mail address is being protected from spambots. You need JavaScript enabled to view it for special discounted pricing!

 

ISACA Registration Image

Visit the SANS TOP 20 Security Issues Poster


Working Effectively In Geographically Distributed Agile Project Teams

Geographically distributed agile is not an oxymoron. And, it sure isn’t easy.  Each organization has its own unique culture, so you’ll have to find what works best for you.  You need to start with the agile principles and values to derive your approach to distributed agile.

The good news is: You don’t have to do this alone!

Let Shane Hastie and Johanna Rothman guide you with the help of their two-day experiential workshop, Working Effectively In Geographically Distributed Agile Project Teams, April 17-18, 2012 . In the workshop, you will learn which kind of geographically distributed team you have, whether you are working on a project or a program, and which approaches might work best. You’ll experience planning and implementation on a distributed project, and we’ll examine how being human affects us all.

We’ll practice with iterations and kanban and see which—or both—might work best for you.

Come armed with your questions, we’ll make sure that we address the problems in the room. Want more information or  to join us? See more or sign up here, http://www.jrothman.com/2012/01/working-effectively-in-geographically-distributed-agile-project-teams/

 


 

In case you missed the Eva Maler and Symplified on Zero Trust Identity, and it was, hands DOWN, the best hour on identity this year!...

To see the video broadcast click here and register for the playback.  You won't be cookied or profiled, and you'll love what you hear

EnterprisGRC Solutions consistently applauds Symplipfied's company's committment to education in identity. Forrester provides the speaker  Eva Maler, who is a gem.


Got an issue or GRC event you want to promote?  Talk2me.  Chat back. Send me a tweet.

Chicks are cool2/23/2012

 

Please Join us on Facebook



Last Updated on Sunday, 21 October 2012 14:36
 
New Services
The GRC Buzz

 

Now Available - Cloud & Virtualization Essentials™

 

 

 

Push 2 Check

http://rymatech.com/

 

HISPIHolistic Information Security Practitioner Institute (HISPI) welcomes EnterpriseGRC Solutions as member of their HISP Certification Board/Committee Read More

GRC Solutions

ITpreneursITpreneurs is proud to name EnterpriseGRC Solutions as its newest certified partner. ITpreneurs and EnterpriseGRC Solutions will collaborate to increase Cloud and Virtualization concepts and controls, ISO 27001, COBIT and ITIL courses offered through EnterpriseGRC Solutions. “Every member of my organization has achieved at least one certification through ITpreneurs, and this is the second company that I’ve founded with that same promise. [...] It is a proud day, that we can be a part of ITpreneurs’ landmark efforts to bring forward CompTIA Cloud Essentials training and certification. - Robin Basham, Managing Partner.

ComplianceExchange A Blog We Love

Spontaneous Kudos - We've really been digging our digest from The Compliance Exchange

Review enterprisegrc.com on alexa.com

Have you read Value of a Conversation?

Please Join us on Facebook

Read More

Partners and Client Information
EnterpriseGRC Solutions is recently named as a member of the Cloud Credential Council. Holistic Information Security Practitioner Institute names CEO, Robin Basham, to their Education Advisory Board.

Ryma Technology Solutions names EnterpriseGRC Solutions as an Affiliate Partner.  More. Recent Wins: EnterpriseGRC Provides IS0 27001 Policy and SOA readiness for NetSuite Inc.  EnterpriseGRC Solutions Sponsor to ISACA ITGI.  Recent Partner Alignments include ITpreneurs, Control Solutions International

Request For Information? Please fill out our Wufoo form.

Wordle: EnterpriseGRC.com Blog
Cloud Credential Council
Read More

ISACA Silicon Valley LogoAre you attending "Enabling Trust: Business In the Cloud"? Learn more.