March 26-27, 2012
OR a 3-day workshop running concurrently with the Conference
Session times and titles are correct at time of posting, and are subject to change.
DAY ONE |
MONDAY, MARCH 26, 2012 |
||||||||||
|---|---|---|---|---|---|---|---|---|---|---|---|
| 7:30 - 8:30 a.m. | Registration and Continental Breakfast / Visit Exhibitors |
||||||||||
| 8:30 - 9:30 a.m. |
Keynote Address:
| ||||||||||
| 9:30 - 11:00 a.m. | Understanding the Shifting Paradigm of Security in the Cyber AgeSalim Hasham, PwC LLPOverview Paradigm shifts in how we leverage new business strategies, such as cloud computing, digital transformation and mobility have forced us to rethink how we manage risk in a world of expanding electronic boundaries, increasing customer expectations, fluid supplier/partner relationships, rigorous compliance demand, sophisticated threats, organized crime, cyber crime, disclosure, theft and scarcity of critical resource. This session will help you understand the current and emerging threats and security risks from this shifting paradigm. 11:00 - 11:15 a.m. |
Networking Break / Visit Exhibitors11:15 - 12:15 p.m.
| CHOOSE ONE OF TWO CONCURRENT SESSIONS |
Business Managed Technology - How to Balance End User Flexibility with Risk Management and GovernanceLouie Velocci, KPMG LLPOverview In today's corporate IT environment, IT and business leaders need to strike a fine balance between meeting business needs and managing technology risks. Business leaders may not necessarily understand all the security risks that come along with the flexibility of end user solutions. IT leaders may not necessarily understand the business realities linked with limiting business units' flexibility to address current business needs. This session will cover the risk and control considerations from both sides. | OR | Cloud Computing - Understanding the Value, Risks and Related Audit IssuesFelix Isada and Strahan McCarten, BCEOverview Cloud computing is an emerging IT service delivery model that enables convenient, on-demand network access to a shared pool of configurable computing resources that can be rapidly provisioned with minimal effort or service provider interaction. Leading Canadian information and communication technology service providers are developing and launching their Cloud products to capture a share of the Canadian Cloud market that is projected to reach $1 billion in 2012. This session will discuss the business advantages of cloud computing, related risks and audit implications from a service provider's perspective. | |||||
| 12:15 - 1:30 p.m. |
LUNCH | ||||||||||
| 1:30 - 2:30 p.m CHOOSE ONE OF THREE CONCURRENT SESSIONS |
Managing an IT Outsourcing Relationship
|
||||||||||
| OR | Auditing IT ProjectsRon Foster, City of Oshawa and Paul Wallis, Peel RegionOverview This session will examine the value of auditing projects against best practice project management and system development lifecycle methodologies. In this presentation you will learn what it takes to plan and develop value-added and effective audit plans for IT projects throughout their lifecycle. |
||||||||||
| OR | Data Governance and IntegrityGord Kilarski, DeloitteOverview Data Governance is a hot topic at the executive table as organizations try to deal with the exponential growth of data and ever increasing regulatory and legal implications. Implementing a successful data governance program, however, can be significantly challenging. In this session you will be introduced to leading practice design and implementation of data governance organizational competencies. These are the building blocks to unlock the hidden value of data, mitigate data risks and break down the cultural and technical barriers that have been preventing success. |
||||||||||
| 2:30 - 2:45 p.m. | Networking Break / Visit Exhibitors |
||||||||||
| 2:45 – 3:45 p.m CHOOSE ONE OF THREE CONCURRENT SESSIONS |
Managing an IT Outsourcing Relationship -
| ||||||||||
| OR | Into the Cloud, Out of the FogCloud Security Subject Matter Expert, Ernst & Young, LLPOverview Turning over control of IT infrastructure and data (to a cloud provider) is an inherently uncomfortable situation for senior corporate managers - and it goes against the culture of many large corporate organizations. It's no surprise therefore that a research survey of North American and European businesses found that 50% of respondents cited their chief reason for not moving to cloud computing was security concerns. In a separate global study of IT risk, 77% of respondents said adopting cloud computing makes privacy more difficult. This cloud computing session will explore: key trends that have a significant impact on the role and importance of information security; key information security implications and potential business impact; and considerations for developing an information security framework. OR |
Getting Started with Audit Analytics Darren James, Deloitte
| |||||||||
| 3:45 - 4:00 p.m. | Networking Break / Visit Exhibitors |
||||||||||
| 4:00 - 5:00 p.m. | Is Your Board Dealing with IT Governance?Gary S. Baker, Independent Consultant
| ||||||||||
| 5:00 - 6:00 p.m. | Networking Reception / Visit Exhibitors |
Day 2 |
TUESDAY, MARCH 27, 2012 |
|---|---|
| 7:30 - 8:30 a.m. | Continental Breakfast / Visit Exhibitors |
| 8:30 - 9:30 a.m. | BYOD - How Do You Manage the Security Issues?Nitin Bedi, Telus Security SolutionsOverview Given the proliferation of smart phone and tablet based technology, organizations will either "adopt" or "tolerate" policies for "Bring Your Own Device" (BYOD). This leaves the IT organization with less control over the devices and related supporting services. Organizations need to seek new secure methods to allow personal devices to connect to the corporate infrastructure. During this session we will discuss: challenges and risks presented by allowing employee-owned devices in the enterprise; Mobile Device Management and what does this mean for my organization; strategies for addressing the risks associated with BYOD; and maintaining regulatory compliance. |
| 9:30 - 10:45 a.m. | Going Mobile - Get Ready and Be Careful! - Panel DiscussionModerator: Chris Anderson, Grant Thornton LLPOverview The panel will discuss: What opportunities and risks do mobile payment technologies present to businesses that do not adapt timely and carefully? What happens next - will mobile payments be a tipping point which will open up the Pandora's Box of mobile devices being the 'source documents' for everything? What are the risks, and the corresponding trust, security, control and assurance requirements? What roles can and should the banks, telcos, card brands and regulators play? |
| 10:45 - 11:00 a.m. | Networking Break / Visit Exhibitors |
| 11:00 - 12:00 p.m. CHOOSE ONE OF THREE CONCURRENT SESSIONS |
Continuous Auditing and Monitoring of IT - An Essential Part of an Auditor's Toolkit to Help Keep Pace with Ever-Changing IT EnvironmentsGary Margolis, Gary Margolis ConsultingOverview The pace of change in Information Technology continues to accelerate. With the global marketplace and technological dependencies, how do we ensure the audit approach and audit technologies are appropriate and keeping pace? In this session, participants will be presented with an understanding of Continuous Auditing and Monitoring of IT and the effectiveness of using automated tools. |
| OR | Cloud Computing - Are You Up in the Cloud on Governance Issues?Overview Cloud computing offers the advantage of flexibility, scalability and the ability to quickly roll out new functionalities to support business units. However, it also increases governance risk issues related to security, privacy, availability, continuity, and public confidence. In this session, we will review governance practices to deal with management oversight concerns for data reliability, transaction integrity and data security. |
| OR | Planning Successful Offshore AuditsMike Bentley, Hewlett PackardOverview Increasingly, corporations are required to plan and execute portions of their audits offshore with their IT service providers in order to provide assurance on controls. This session will focus on the recipient of the audit illustrating how to ensure that the audit is an effective one. The session will also provide an overview of how to plan these types of audits from the auditors' perspective. |
| 12:00 – 1:00 p.m. | LUNCH |
| 1:00 - 2:15 p.m. CHOOSE ONE OF THREE CONCURRENT SESSIONS |
Business Continuity and Pandemic Awareness in an Interconnected WorldShanda Chronowich, MNP LLPOverview Global crises appear to be happening more frequently. With our global market place and technological dependencies how do we ensure the impacts have limited interruptions to our local business? In this session participants will be presented with practical actions that they can take to ensure the appropriateness of their business continuity programs regardless of their global footprint. |
| OR | The Potential Costs of Low Tech HackingDavid Florio, Grant Thornton LLPOverview In this session you will learn about how low tech hackers could exploit vulnerabilities at your organization and obtain sensitive information. Some techniques that will be discussed include: social engineering; physical security weaknesses; surveillance; wireless and non user computer IP's. The presentation will provide you with information related to the risks and vulnerabilities of low tech hacking, and countermeasures you can take to protect yourself against them. |
| OR | Is Your IT Audit Plan Risk Based?Bruce Muir, Independent ConsultantOverview During these tough economic times, every department in an organization is forced to show that it is providing value to the organization, including IT internal audit departments. IT auditors are reviewing their audit scope to ensure that the key risks facing the organization are being addressed. Various methods and techniques are used to determine enterprise risks, and the IT scope is derived from those enterprise risks. This session explores how you ensure that your annual IT audit plan has good coverage and that it is risk-based. |
| 2:15 - 2:30 p.m. | Networking Break / Visit Exhibitors |
| 2:30 - 3:45 p.m. CHOOSE ONE OF THREE CONCURRENT SESSIONS |
Audit Tools - Commonly Used Software Tips to Help You Become a More Effective Analytical AuditorTony Stanco, Toronto Hydro CorporationOverview Commonly available software products have a wealth of creative features and functionality available that can help auditors analyze data and trends, identify key areas of risk and controls, improve business efficiencies, verify process effectiveness and report results in an efficient and effective manner. This session will review some of the neat tools available in commonly used software that can add the "WOW" factor to your engagement and improve your audit engagement results. |
| OR | Best Practices for Maximizing IT Value and EffectivenessCharan Bommireddipalli, Collins Barrow, LLPOverview The global economic environment is tough today and when the going gets tough only the tough get going. Building a value-add IT function is critical to the success of today's organizations. Having IT as a business enabler and strategic advantage requires an efficient and effective IT that maximizes its value by aligning its resources and activities to support strategic organizational goals and objectives. How can IT Governance help? This session will explore: how Boards can successfully support IT's role and mandate as an enabler through effective governance; how IT projects and initiatives can contribute to successful corporate goals, objectives, and strategies; and how to measure and monitor IT's performance in terms of those measures that matter most to the Board |
OR | IT Security Audit - Real World Lessons from the Field - Panel Discussion Moderator: Ann Marie Yamamoto, PwC
|
| 3:45 - 4:00 p.m. | Change Break |
| 4:00 - 5:00 p.m. | Recent and Emerging Technologies plus Future Trends - What are the Risks?Neil Bhattacharya, Accenture Mobilility ServicesOverview The consumerization of technology is blurring the lines of traditional enterprise and consumer technology. Social Networking, Apps, Unified Communications, Mobile Payments, Presence Awareness are some of the IT offerings that are combining enterprise and personal profiles to offer targeted enterprise services to employees and clients. This session will provide an overview of emerging technology trends, the benefits, expected evolution over 3-5 years and risk mitigation strategies to reduce the exposure for enterprises. |
DAY 3 |
WEDNESDAY, MARCH 28, 2012 |
|---|---|
| 8:00 - 9:00 a.m. | Registration and Continental Breakfast |
| 9:00 - 4:00 p.m. |
Wireless & Mobile Technologies - IT Audit and Security PerspectiveWorkshop Leader: Barry D. Lewis, Cerberus ISC Inc.Overview This one-day workshop focusses on the specific risks and controls involved when using Mobile technology. From access controls and inventory to automated tools, we analyze best practices and effective implementations. Finally, we review how you might perform an effective review of your mobile security, ensuring that all key areas are effectively and appropriately managed and controlled. After completing this workshop, participants will be able to:
Workshop Outline:
About Barry Lewis Barry Lewis is President of Cerberus, a firm specializing in the delivery of information security training and consulting. He has over 40 years of experience in the computer field, and has spent the last 30 years specializing in Information Security. He began work in the consulting field in 1987 and worked for two major audit firms before starting his own company in 1991 and joining Cerberus in 1993. He has provided seminars for ISACA for many years around the world. He is co-author of several books, including Computer Security for Dummies, Teach Yourself NT Server in 21 Days and Teach Yourself Windows 2000 Server in 21 Days and Wireless Networks for Dummies. His books have been translated into more than a half-dozen languages around the world. Barry lectures and consults world-wide on numerous security topics, including Windows, governance, wireless networking and security best practices. |
Optional Concurrent 3 Day Workshop |
MARCH 26 -28, 2012 |
|---|---|
| 8:30 - 4:30 p.m. |
Fundamentals of IT AuditWorkshop Leader: Craig McGuffin, C.R. McGuffin Consulting ServicesOverview This three-day workshop is designed to provide new IT assurance and control professionals with the core skills needed by all Information Technology Auditors. You will review and understand key audit and control principles, as well as many practical techniques, which are all necessary to complete a wide range of IT audit assignments within today's complex computing environments. Topics covered include overall IT audit planning and objectives, as well as audit risk assessment. We'll also examine the wide range of controls needed for managing the IT function, system development / acquisition and implementation, IT operations, logical and physical security, and business resumption / disaster recovery. Included are the vital business process controls found within specific financial tracking and reporting systems. In addition, we will consider important technology components that IT auditors must be able to understand, use, and evaluate. Key topics include:
Your understanding will be facilitated by demonstrations and discussions of current technology and audit techniques to help reinforce the key concepts. After completing the workshop, you will be able to take part in many types of IT audit assignments, and have a solid foundation on which to continue to build your audit expertise. Detailed Agenda Part 1 - The IT Audit Process Discuss control objectives and categorizations (e.g. general vs. business process, preventive vs. detective). Introduces the control benchmark we'll be using during subsequent sections. Discuss the impact of controls on audit strategy and testing.
Part 3 - Controls Over IT Management
Part 4 - Controls Over SDLC
Part 5 - Controls Over IT Operations
Part 6 - Controls Over IT Security
Part 7 - Controls Over BCP / DRP
Part 8 - Controls Over Business Processes
Part 9 - Testing IT Controls
Part 10 - Communicating Audit Findings About Craig McGuffin Workshop Leader Craig McGuffin, CA, CISA, CISM, CGEIT, CRISC, Principal of C.R. McGuffin Consulting Services, has more than 25 years of experience in the field of computer and network controls and security. He has a background in computer science and has worked as an information systems auditor, security consultant and security manager, obtaining experience in all major computing and networking environments. He also is the co-author of two books on networking technology. Craig is an award-winning and extremely popular speaker on the use of computer technology, controls and security, delivering core knowledge and practices through university courses, training seminars and conferences on six continents. He frequently presents on behalf of ISACA, IIA, and CICA.
|