Protecting Data Privacy: A Practical Guide to Managing Risk Protecting valuable information assets, including personal data about employees, students, customers, and medical patients, is an enterprise wide responsibility. Like all components of good corporate governance, it begins with senior leadership establishing a culture of awareness about the importance of safeguarding these assets, and extends through coordinated actions among all business units, divisions, and departments. When creating data privacy programs, organizations should align them with their strategic enterprise risk management objectives and follow a top-down approach to achieve the greatest benefit. This presentation will focus on a practical approach to data privacy, which seeks to understand the business needs for data and align a data privacy protection program to those needs. Effective programs prevent companies from ending up in the news, disclosing a data loss, by enabling its employees to stay vigilant for situations where data may be at risk. Topics to be discussed include: • The Goals of an Effective Data Privacy Program Jill Frisby, CISSP, CISA Manager, Crowe Horwath, Risk Consulting Practice with a specialty in the area of Information Security and Data Privacy She has been the keynote presenter on Information Security for several regulatory agencies, banking associations, and industry roundtables.Jill has become an industry thought leader in the area of the Data Privacy, developing Crowe Horwath’s full suite of services to help ensure initial and continuing protection and compliance. Jill is a member of the editorial board for the International Association of Privacy Professionals (IAPP) and has written articles on Privacy and Identity Theft for the Privacy Advisor and Privacy Tracker publications. She designed a web-based tool for the facilitation of Information Systems Risk Assessments, and has helped major companies and government organizations remedy significant deficiencies in safeguarding consumer information. In addition, Jill has been featured in 5 major newspapers and on three network evening television broadcasts related to her research in the area of Wireless LAN Security. These media publications were completed in conjunction with a Crowe Horwath research study, the goal of which was, upon investigation, to inform the public of the growing problems with Wireless LAN security and the ways to remedy these issues. Jill currently performs assessments in the areas of: Data Privacy and Protection
Jill is a Certified Information Privacy Professional, Certified Information Systems Auditor, Certified Information Systems Security Professional, Microsoft Certified Systems Administrator with a Specialization in Security, a Project Management Professional and a CompTia Certified Security Professional. She is a graduate of the University of Illinois, where she majored in General Engineering and minored in Technology Management. SECURITY TOPICS Identity Theft – Protecting Sensitive Information Many privacy issues are becoming increasingly complex and more integral factors in a company’s ability to do business well. While privacy in earlier years may have been considered more of a marketing hook, focused on meeting customer preferences, privacy today is associated with the potential for abuse − inappropriate access to or exposure of information resulting in identity theft and fraud. The prevalence of such issues has attached a keen sense of urgency to privacy, thereby moving it up the list of business concerns on a global scale. This talk will provide insight into how an organization can determine how vulnerable it may be to privacy breaches or issues of noncompliance and what actions it could take to meet these inevitable challenges. Emerging Technologies and Risks IT leaders must understand that ‘over the horizon’ technologies will have a significant impact on the organization, and should take action to address the implications that these key technology trends may have for enterprises. This talk will bring attention to key considerations including value, cost, traditional risks, transitional/ disruptive process or technology and emergent risks of delivering the technologies in IT, business processes, data, applications, and infrastructure. 2008 Ernst & Young Global Information Security Survey The 11th Annual Global Information Security Survey will be reviewed. Learn what 1,300 EY client executives in more than 50 countries had to say about what drives information security in their organizations. Learn their view of how improved information security affects overall business performance and what happens when information security is not closely connected to executive management and the strategic decision-making process. Incident Response & Forensics Investigations As an IT Executive and staff member, do you understand your responsibilities and obligations under the new Federal Rules of Civil Procedure? What typically was in the domain of the corporation's legal team now confers obligations on the technology team. A number of high profile court levied sanctions against major corporations have been made public, yet there are many corporations that either do not fully understand their obligations or have failed to adapt their legal response and incident handling processes to comply with the new rules. Through a mock deposition and discussion, this talk will highlight the major changes and provide tips and lessons learned to help corporations respond effectively. Brian Kelly Executive Director, Ernst & Young’s Information Technology Enablement Center With over 25 years of experience in technology and security operations including information security, command & control, intelligence, investigations, electronic evidence collection, space systems reconnaissance and airborne sensors. Brian has led Ernst & Young’s New York Forensics Technology Services and the Advanced Security Center providing forensic technology and security services for global clients. Brian has served in a number of senior leadership roles within the private and public sectors including Chief Executive Officer, Chief Operations Officer and Senior Staff Officer within the Department of Defense. He was selected for and served in a prestigious Washington D.C Fellowship. Brian provides an array of operational and practical perspectives on building and protecting an organization’s critical assets. Gary Babick, CISSP Manager, Ernst & Young Northeast Advisory Services Practice Gary is responsible for development and delivery of a Global Information Security assessment methodology based on the ISO/IEC 27001 and 27002 security standards. His experience includes performing reviews of Fortune 50 Information Security programs in the context of leading practices and overall maturity level, identifying and reporting on overlapping roles and responsibilities, initiatives, management gaps, and identifying any security initiatives that could improve operational security processes and organizational security management relative to leading practices. Previously, Gary served as an Information Protection Manager at CIGNA, an employee benefits company providing health care and related benefits offered through the workplace. He was responsible for assessing compliance to corporate information protection policies and technical standards to ensure the confidentiality, integrity and availability of Information assets while meeting the strategic, regulatory and customer requirements for several diverse business units. His experience includes 18 years in Information Technology and Information Security, covering health care, manufacturing, educational, government and legal sectors. His duties have included client, server, network and application support, business continuity planning, information security assessment and compliance activities, and technical leadership for large scale security product deployments. He has a Bachelor of Science in Business Administration from the University of Connecticut and a Master of Science in Information Systems from Drexel University. Brian DePersiis, CISA Senior, Ernst & Young Northeast Advisory Services Practice Brian serves as a senior within Ernst & Young’s Advisory Services practice. He has performed network and application information security reviews. He has analyzed the security risks related to both the general network architecture environment as well as significant applications used for processing business and operational tasks. These reviews typically consist of an evaluation of particular business assets, security policies, software import and virus protection procedures, processes for securing data integrity, risks related to social engineering as well as providing clients with a current and future state assessment of the their security staffing needs. Brian has executed several of these types of security programs in conjunction with building a solid security framework that can be utilized by clients according leading security standards (i.e. ISO). Bachelor of Science, Business Administration – Management Information Systems, University at Albany, NY. Member of the Information Systems Audit and Control Association (ISACA) Time and Location Date: Thursday, October 23, 2008 Time: 8:00 AM – 4:00 PM Dress: Business casual Registration& Cancellations REQUIRED! Please reserve your spot now since seating is limited to 50 people. Kindly let us know if you need to cancel. Please register via the IIA Chapter website: http://www.theiia.org/chapters/index.cfm/view.events/cid/230 For any questions or cancellations, please contact our Event Manager, Celebrations Event & Meeting Management via email: IIACNJ@celebrationsevent.com. Location: Directions: From North Jersey Via Route 31: From South Jersey & Philadelphia AreaFrom Philadelphia Area Train and Airport Travel
Top of Page
CPE/Seminar Information
Level of Knowledge: Basic/Intermediate Recommended CPE Credit(s): 8 Prerequisite & Advance Preparation: None Method of Presentation: Group Live Recommended Category Eligibility: Auditing
|
||||||||
|
All contents of this Web site, except where expressly stated, are the copyrighted property of this IIA affiliate.
|
||