The Password - Jan 2012 The Password - Feb 2012

ISACA - North Texas ChapterThePassword
The Newsletter of ISACA - North Texas Chapter
February 2012
In This Issue:


Letter From the President
Marvin Reader

Howdy everyone! 2012 is in full swing and hopefully those of you with a December year-end are starting to see the light at the end of the tunnel.

Our joint meeting with the IIA was a huge success (albeit a cozy one), and it was great to see our colleagues from the less technical side of the audit & controls arena.

Thanks to those of you who have renewed your membership - the North Texas Chapter is now nearly 1700 strong! If you haven't yet renewed, it's not too late, just go to www.isaca.org and sign up for another year.

Our February meeting is fast approaching and we hope you'll be on hand to provide a warm Texas welcome to our luncheon speaker, ISACA International President, Ken Vander Wal. Our bookend speakers will focus on COSO Updates (pre-lunch) and Intellectual Property Protection in an ERP environment (post-lunch). Please plan to join us on February 9th at the Brookhaven Country Club.

Future meetings include a focus on the following topics: March - Social Networking, April - Cloud Computing, and May - Board/Governance. Plans have also just been finalized for the next networking event (Feb 16th) and our two-day Spring Seminar (April 12-13). See details below.

Finally, registration has been opened for the spring CISA/CISM review courses. Keep an eye out for emails or check the Chapter Website for details.

See you at the monthly meeting!

Thanks and Take Care

Marvin Reader, CISA
PricewaterhouseCoopers (PwC)
President - ISACA North Texas Chapter
President@isacantx.org


[Top]


Meeting Agenda for our February 9, 2012 Luncheon Meeting

This month our meeting location is the Brookhaven Country Club in Farmers Branch, located NW of the Dallas North Tollway at I-635 LBJ (Click for Map).

You have until noon on Wednesday, February 8th to register online for this meeting. In the event you are unable to attend after you've registered, please contact reservations@isacantx.org for assistance with canceling your reservation. This will help us keep our event registration fees reasonably priced.

Pre-Luncheon Session - 10:30 AM - 11:30 AM
What's New With COSO?
Bill Schneider, AT&T Services

Bill is the AICPA representative on the COSO Advisory Committee on changes to Internal Control Integrated Framework. He will present changes to the COSO framework with benefits to organizations.

Attendees will:

  • Understand the changes to COSO
  • Understand the value of the COSO framework

Pre-Luncheon registration begins at 10:00 AM.

Luncheon Session - 12:20 PM - 1:20 PM
Trust in, and Value From, Information Systems: How ISACA Achieves its Vision
Ken Vander Wal, International President of ISACA

In his presentation, ISACA International President Ken Vander Wal will examine 2012 information technology and systems trends, as well as one priority that never changes - the critical need to ensure trust in, and value from, information systems. Ken will discuss what constitutes "value from information systems" and what it means to "trust in information systems." The last part of the presentation will discuss ISACA and its members' critical role relating to value and trust, the basis for trust and value being embedded in our tagline, and how ISACA can add value to both your career and your enterprise.

Attendees will:

  • Receive an overview of 2012 information technology and system trends as seen by ISACA's International President
  • Understand ISACA's tagline and how we are delivering on our vision
  • Understand how ISACA can add value to both your career and the enterprise

Lunch registration begins at 11:30 AM. Lunch is served no later than 11:45 AM.

Post Luncheon Session - 1:30 PM - 2:30 PM
Intellectual Property Protection in Enterprise Resource Planning Tools
Patrick Marcello, Ernst & Young

ERP systems (e.g., SAP and Oracle) store sensitive client information such as employee data, intellectual property, financial information, customer lists, product pricing, etc. The security around this information is dependent on controls within the ERP system such as user access controls, segregation of duties, and monitoring.

Authorized users can extract this information out of the ERP system for various business functions and reporting purposes, but since these extracts can be in multiple formats (e.g., xls, txt, pdf, etc.) and with different data in each extract, it is impossible for security tools outside of the ERP environment to track this information.

For example, an HR analyst can run a report with every employee's name and salary for analysis purpose from SAP. They can then save this report onto their laptop and email it to their Gmail account to view it from home. Security tools would not know this information left SAP and, most likely, would not be able to identify or stop it.

Attendees will identify:

  • What controls are required for an ERP system
  • Security tools that can help control an ERP system

For complete details, including CPE information and to register, click the buttons below.

Event Details

Register

Copies of the presentations for this meeting will be made available at www.isacantx.org/index.cfm/Presentations,
before the meeting if possible.

Rick Nietubicz

Rick Nietubicz, MBA, CISA, CGEIT, PMP, ITIL, Six Sigma, ISO 20000
Research Now
VP of Programs - ISACA North Texas Chapter
Programs@isacantx.org


[Top]


Spring 2012 Seminar - Securing and Auditing Virtualized Environments - April 12-13 - Save the Date

This two day seminar will cover virtualization basics, hardware virtualization considerations, and examine best practices for securing VMWare servers. Case studies using a combination of live demonstrations and exercises will reinforce important virtualization concepts and associated audit points addressed in real audit projects.

The seminar will take place on April 12-13 at Weaver LLP's offices in North Dallas. Details will be posted on our website shortly. For now, save the date.

Laurie Flandrau

Greg Streder, CISA, CISSP
JC Penney Company, Inc
VP Education - ISACA North Texas Chapter
education@isacantx.org


[Top]


2012 Spring Review Courses - Early Registration Discount Available

Are you planning to sit for the CISA exam this coming June 2012?

Are you certified and looking for an opportunity to earn additional CPE?

Checkout our ISACA NTX Chapter Website now for a cost effective resource to pass the exam and obtain CPE, as well as an opportunity to interact with other IT Audit and Security professionals!!

Register Online by March 31st, 2012 to get the Discount Price!!!!!

Registration: CISA Review Course or CISM Review Course

Both review courses take place as follows:

Location:

UT Dallas Campus - School of Management
2601 N. Floyd Road
Richardson TX 75080

Cost:

$250 - Early Online Registration (Members Only)
$300 - Members (after March 31st, 2012)
$400 - Non-Members

Times:

9:00 AM - 5:00 PM (lunch, snacks and drinks are provided)
CISA Logo

Saturday Dates:

  • April 28
  • May 5
  • May 12
  • May 19

CPE Hours: 32

Review Course Registration Deadline: April 20, 2012!

CISM Logo

Saturday Dates:

  • May 5
  • May 12
  • May 19

CPE Hours: 24

Review Course Registration Deadline: April 28, 2012!

Questions? We'll be glad to help -- just e-mail certifications@isacantx.org.

Iddah Wangondu

Iddah Wangondu, CISA, CIA, GSNA, CISSP
Alliance Data
VP of Certification – ISACA North Texas Chapter
certification@isacantx.org


[Top]


Spring Networking Event, February 16th, 2012
Blue Mesa Grill, Dallas

Come mingle with your fellow ISACA members at an event sponsored by your North Texas chapter! Don't miss this fun evening of food, drinks and networking - and don't forget thedoor prizes, so bring those business cards! This is a free event, but please register for planning purposes (check out the ISACA NTX website for more information).

Date: Thursday, February 16, 2012, 6:00-8:00pm

Location: Blue Mesa Grill, 7700 W. Northwest Highway Dallas, TX 75225 (Click for map)

Brittany George Teare

Brittany George Teare, CISA
Weaver
Hospitality Coordinator - ISACA North Texas Chapter
hospitality@isacantx.org


[Top]


Welcome To Our New and Returning Members

We want to welcome our new and returning members - those that have joined/rejoined ISACA and our North Texas Chapter in the last 30 days. We hope to see each of you at our monthly meetings.

By the way, the North Texas Chapter now has grown to 1,675 members (1/30/2012).

Name
Company
Name
Company
Amin Mohammad H. Abjani Mark Nagiel, CISA,CISM (T) MetroPCS Communications Inc.
Sharmin Afshar, CISA,CISM (T) IBM Sundararajan Narayanaswamy, CRISC (T) Ernst & Young LLP
Richard M. Butler, CISA William Nelson
Daniel Alan Cohen Amerisafe Balaji Palanisamy, CISA
Curt Craig Hunt Consolidated, Inc. Monica Piaquadio XTO Energy
Chris Dunlap Birchwood Consulting Jason Poirot, CISM
Patrick Wayne Ellis, CISM (T) Locke Lord LLP Jonathan R. Prewitt
Brian Christopher Evans, CGEIT Lisa Ramos BNSF Railway
Amit Gandre, CISA (T) Deloitte & Touche LLP Ronnie D. Randle, CISA (T) General Casualty Insurance Company
Howard Habib Andrew Russell
Kurt Hagerman, CISA (T) Coalfire Systems Matthew T. Sawyer, CRISC
Michael Herb Thresholds Data Architecture Group LLC Barbara Schultz
Melody Herrin Karen Suzann St John
Marcia S. Jones, CISA Quincy V. Thomas, CISA
Satyan Kachroo Sunela Sarah Thomas, CISA (T) AT&T
Peter Maung Courtney Treadaway, CISA The Garland Group
Herman Michael McGarry, CISA,CRISC (T) KPMG, LLP Okonanwan E. Udoh
Christopher Don Mears Jennifer Wendel, CISA (T) Deloitte & Touche LLP
Tom Moore, CISA PricewaterhouseCoopers Christina Willis, CISA

(T) = Transfer from another ISACA chapter

Laurie Flandrau

Laurie Flandrau, CISA
GM Financial
VP of Membership - ISACA North Texas Chapter
membership@isacantx.org

Special thanks to Armanda Moore for compiling these details for the newsletter.


[Top]


Want To Get Published? We'd Like to Hear From You

In today's hectic and challenging business environment, where we are faced with so many different sources of information, e.g., websites, blogs, tweets, listservs, social networks, RSS feeds, etc, competing for our attention, it is increasingly challenging to create a meaningful and relevant newsletter that members have the time and inclination to read. Despite this, the feedback from the annual chapter survey tells us that the newsletter is generally still well received and wanted. However, we'd like to make it even better, and that is where you come in.

When we compare ourselves to other award-winning chapter newsletters, one area where we have room for improvement is sharing the work experiences of our chapter members. With over a thousand members in a broad range of industries of varying sizes, we have a vast source of experience. Some of you work in best practice audit groups, others are in less mature organizations that are still developing. All of you have something you can share with other chapter members.

We'd like to hear from any member that is willing to write a brief article for the newsletter that would be of interest to fellow practitioners, e.g.:

These are just a few ideas and not meant to be all inclusive.

In addition, if you have any ideas for other content you'd like to see, let us know.

If you'd like to write an article or have ideas for the newsletter, please send them to newsletter@isacantx.org.

Matthew C. Smith

Matthew C. Smith, CISA
Capital One
Newsletter Coordinator - ISACA North Texas Chapter
newsletter@isacantx.org


[Top]


Current Job Postings

The word is getting out - that firms and recruiters can post their available audit and security-based openings on our JOBS Board, without charge. Help bring jobs and job seekers together by promoting job postings. Your fellow ISACA members will appreciate it.

As of February 1, 2012, we have 6 opportunities posted on the jobs board, as summarized below. See our website regularly for any updates and for complete details. Please note that positions may have been filled or new positions added prior to the newsletter publication, so always check the jobs board directly for the most current status.


Company: Coalfire Systems
Position: Sr. NERC CIP Auditor
Location: Dallas,TX
Salary: DOE
Contact: Chuck Glovick , 206-352-6028 x7524 , cglovick@coalfire.com


Company: Energy Future Holdings
Position: IT Security Architect
Location: Irving, TX, USA
Salary: DOE
Contact: Kevin Dailey , 214-812-1453 , Kevin.dailey@energyfutureholdings.com , https://efhexperienced.ats.hrsmart.com/cgi-bin/a/highlightjob.cgi?jobid=3801


Company: Energy Future Holdings
Position: IT Security Manager
Location: Irving, TX, USA
Salary: DOE
Contact: Kevin Dailey , 214-812-1453 , Kevin.dailey@energyfutureholdings.com , https://efhexperienced.ats.hrsmart.com/cgi-bin/a/highlightjob.cgi?jobid=3800


Company: Novation
Position: Sr. Auditor
Location: Irving, TX, USA
Salary: $60-80K
Contact: Alicia Garriotte,972-830-8636 , agarriot@vha.com


Company: The Neiman Marcus Group
Position: Information Services Staff Auditor
Location: Dallas, TX, USA
Salary: $45 - $50k
Contact: Kyra Hillard , (214)573-5606 , Kyra_jyro@neimanmarcus.com


Company: YMCA of Metropolitan Dallas
Position: Staff Internal Audit
Location: Irving, TX, USA
Salary: DOE
Contact: Jennifer Hanks , 972-560-3847 , Jhanks@ymcadallas.org , https://ymcadallas.hua.hrsmart.com/ats/js_job_details.php?reqid=1761

Additional details about these jobs and all current job postings are available at: ISACA North Texas Job Postings.


To post an available position, just complete a Job Posting Template and e-mail it to jobs@isacantx.org. Each job posting will be displayed on our site for one month, but can be reposted again or removed at any time by request.

All posted job descriptions will also be included in this newsletter each month. Members can also examine the available positions on the ISACANTX.ORG job board at http://www.isacantx.org/index.cfm/Job_Postings.

Don't forget - Postings are FREE, and available for members and non-members alike.

Interested in positions outside the DFW area, even world-wide? ISACA International maintains a Career Center that hosts hundreds of available opportunities. Just select Career Center from the left-hand menu options at www.isaca.org.

Joe McKernan

Joe McKernan, CISA, CISSP
IBM
Jobs Coordinator - ISACA North Texas Chapter
jobs@isacantx.org

Special thanks to Ali Subhani for compiling these details for the newsletter.


[Top]


Monthly Luncheon Meeting Dates for 2012

Mark these dates on your calendars now to ensure you don't miss a meeting:

MonthDate Location Main Session
March March 8, 2012 Crowne Plaza Social Media Policies
April April 12, 2012 CityPlace Cloud Computing - Joint Meeting with Infragard
May May 10, 2012 Crowne Plaza Board/Governance
June June 14, 2012 CityPlace -- TBD --

Refer to the Current Events to view details of session topics as they are posted.

Rick Nietubicz

Rick Nietubicz, MBA, CISA, CGEIT, PMP, ITIL, Six Sigma, ISO 20000
Research Now
VP of Programs - ISACA North Texas Chapter
Programs@isacantx.org


[Top]


ISACA North Texas LinkedIn Group

Did you know the North Texas Chapter has a group on LinkedIn? Catch the latest news from the ISACA NTX chapter and your fellow chapter members. Get updates as they happen, get information about professional development and jobs in the area, post questions or comments about an IT audit, security, etc. topic, network with colleagues and give your feedback/input on existing discussions. We look forward to connecting with you on Linked-In!

To access the group go to http://www.linkedin.com/groups?mostPopular=&gid=1360787

Get Linked-In!

Angel Jones

Angel Jones, CISA
Fiserv
Marketing Coordinator - ISACA North Texas Chapter
marketing@isacantx.org


[Top]


7th Annual - University of Texas at Dallas Fraud Summit
March 29-30, 2012

Thursday, March 29, 2012 - Fraud Workshop (8 CPE Credits)

Choose from one of two workshops:

Friday, March 30, 2012 - Fraud Conference - Latest Trends and Techniques (7 CPE Credits)

For details, click here. To register, click here

Doug Gorrie

Doug Gorrie, CISA, CIA
Independent Consultant
VP of Communications - ISACA North Texas Chapter
communications@isacantx.org


[Top]


News from ISACA International

World Congress: INSIGHTS 2012 - Registration Now Open

ISACA's World Congress: INSIGHTS 2012, taking place 25-27 June 2012, is an event unlike any other. Designed for progressive IT and business leaders, the conference addresses topics at a strategic level, giving you the insights you need to develop strategies for effective integration of business and technology.

Registration is now open! Join us in San Francisco.

More information and program details will be posted regularly as the information becomes available, so check back often!

2012 North America CACS - May 6-10, 2012

Register today for ISACA's 2012 North America CACS! Be a part of the world-leading audit conference for IT audit, security, governance and risk professionals. This world-class event will be located in Orlando, Florida, May 6–10, 2012.

Earn up to 44 CPE hours!

Check the ISACA web site frequently as additions are being made often.

New Audit Assurance Program Available

New audit assurance program for Voice-over Internet Protocol (VOIP) Audit/Assurance Program now available.


Information Security Essentials for IT Auditors - March 12-15, 2012

Register today for ISACA's 4 day course that teaches the experienced auditor to recognize and address information security issues in the enterprise. Learn to identify and analyze the risk associated with security threats across network, operational and physical systems. This event will be located in San Francisco, California, March 12-15, 2012.

Earn up to 32 CPE hours!


Updated COSO Framework Available for Public Comment

ISACA is pleased to provide its constituents an opportunity to be aware and have access to the most current public exposure draft from COSO. Deadline for providing comments is 31 March 2012, please visit the COSO website for details.


BENEFIT of Your ISACA Membership

As a benefit of your ISACA membership, the following upcoming online learning opportunities will be available in the near future:


Free CPE Using Your ISACA Membership

As a benefit of your ISACA membership, ISACA International is making free CPE available in four different formats. In fact, you can secure up to 72 hours of CPE per year, as follows:

As always, read the full details at http://www.isaca.org/Certification/Pages/How-to-Earn-CPE.aspx.


Ali Sughani

Ali Subhani, CISA,CIA,GSNA
Univ. of Texas at Dallas
Newsletter Committee - ISACA North Texas Chapter
newsletter@isacantx.org


[Top]


Questions? Comments? Corrections? Please advise us at newsletter@isacantx.org

The Password is a free copyrighted publication of the North Texas Chapter of ISACA. It is published periodically from August through June. It is an objective of the North Texas Chapter of ISACA to be a forum of free expression and interchange of ideas. Statements of position or expressions of opinion appearing herein are those of the authors and not, by the fact of publication, necessarily those of ISACA or the North Texas Chapter. Likewise, the publication of any advertisement is not construed to be an endorsement of the product or service offered unless specifically stated.
Copyright 2012 ISACA North Texas Chapter - all rights reserved