Faces of ISACA: Maria Divina C. Gregorio, CISA, CRISC, PCI-ISA, PCIP, internal audit manager, VSP Global

Editor’s note: The ISACA Now series titled “Faces of ISACA” highlights the contributions of ISACA members to our global professional community, as well as providing a sense of their lives outside of work. Today, we spotlight Maria Divina C. Gregorio, CISA, CRISC, PCI-ISA, PCIP, internal audit manager, VSP Global, a US resident from the state of California.

ISACA Now: What motivated you to pursue a career in audit?
I chose a career in audit because it allows me to have a comprehensive understanding of and exposure to all facets of the business. I am able to use my knowledge, analytical techniques and people skills to effectively contribute to the betterment of the organization. I was also influenced by a mentor early in my career who encouraged me to explore opportunities in this field and introduced me to ISACA’s CISA certification.

ISACA Now: How do you see technological advancements having the greatest impact on audit in the next 3-5 years?
I believe that technological advancements have and will pave the way for more efficient, more effective and more economical audits.

ISACA Now: What are a few professional achievements of which you’ve been most proud?
I am proud to have achieved my CISA, CRISC, PCI ISA and PCIP certifications. They allowed me to lead highly impactful audits that resulted in major cost savings to the organization. I am very proud to have authored our cyber crisis management plan, and I am now leading the global business continuity initiative in my organization.

ISACA Now: How long have you been an ISACA member, and what has that added to your professional development?
I have been a member of ISACA since October 2005 – 12 years! I believe that the benefits derived from my ISACA and other professional association membership, certifications, active participation in my local chapter, passion toward my profession and continued quest to educate myself have been a great formula for my professional development.

ISACA Now: You’ve been active in Habitat for Humanity – what have you taken from that experience?
I’ve always been guided by a personal commitment to leave this place a little better than I found it. I believe that serving with Habitat is my small contribution to that commitment.

ISACA Now: What is the most fun aspect of living in California?
Do I feel like having authentic dim sum breakfast in San Francisco this morning, then heading to a Napa vineyard for lunch and some wine? Or how about some honest to goodness mole in the Mission, then heading to the beach and gazing at migrating whales in Bodega Bay? Or maybe picking up my skis and hitting the slopes at South Lake Tahoe, or lounging in a houseboat in Shasta Lake? As you can see, there is something for everyone in California. I feel very blessed to have these choices – all within hours from each other!

ISACA Now: What are some of your favorite things to do outside work?
I read, go on hikes with my dog; tend my organic garden; feed the ducks, peacocks (yes, we have them “wild” around my neighborhood) and turkeys; swim; work out; and have lunch dates with my mom.

[ISACA Now Blog]

H1-B Visas Critical to Address Cybersecurity Professional Shortfall

Based on the findings of the 2017 Global Information Security Workforce Study, the world will face a deficit of 1.8 million information security professionals by 2022. With headlines dominated by breaches and cyber threats, we at (ISC)² need to be a strong voice and advocate for the global cybersecurity workforce.

It is for this reason that I sent a letter to White House Chief of Staff, Reince Priebus, on behalf of the (ISC)² organization and our members across the globe, to provide feedback on President Trump’s Executive Order, which directed the Department of Homeland Security to review how it issues H1-B visas.

Even after giving U.S. citizens priority consideration for open cybersecurity positions, we will still face a substantial talent shortfall, which can be mitigated with an H-1B visa program that helps bring skilled and trained workers from other countries to fill these roles.

(ISC)² suggests our Certified Information Systems Security Professional (CISSP) certification as one way to verify cybersecurity professionals for H-1B visas. The CISSP was the first credential in the field of information security to meet the stringent requirements of ISO/IEC Standard 17024, and is also Department of Defense 8140/8570 approved. Professionals with the CISSP have proven their knowledge and experience in the field. Our members also must abide by a standard code of ethics, which includes the following canon: “protect society, the common good, necessary public trust and confidence and the infrastructure.”

We do not want to prevent talented cybersecurity professionals, such as our global members, from offering their expertise to benefit the U.S. economy.

I recently testified in a Subcommittee on Information Technology on ways that the United States can improve the federal IT workforce. We also provided recommendations to the Trump administration on how to improve the current status of the federal cybersecurity workforce. Utilizing the expertise and experience of our membership, these recommendations were created following our 2016 federal CISO forum, which included members of the (ISC)² U.S. Government Advisory Council (USGAC) and other federal CISOs and executives who participated in discussions surrounding these critical considerations.

(ISC)² hopes to establish a constructive dialogue with the Trump administration as they strengthen cybersecurity for our country.

Dan Waddell, CISSP, CAP, PMP
Regional Managing Director, North America Region, (ISC)²

[(ISC)² Blog]

Tracking Members’ Progress with GDPR: Europe’s New Data Protection Regulation

Download the 12 Areas of Activity and their key supporting tasks

The (ISC)² EMEA Advisory Council is turning to its professional membership to measure the readiness of organizations and security departments for the General Data Protection Regulation (GDPR) and highlight the challenges they are facing in the effort to become compliant by May 2018. We are doing this by bringing people who are actively working on implementation projects together either on monthly international calls and, as of this month, in face-to-face workshops hosted at (ISC)²’s new two-day Secure Summits, five of which are being held across the EMEA region this year. The first such workshop staged a series of round table discussions at our Secure Benelux Summit in Amsterdam gathering over 120 information and cybersecurity professionals from various industries. Another is set for Stockholm at the end of May, and we’ll be in Zurich for the end of June.

Through this effort, we are helping our members realize expectations and requirements that they hadn’t anticipated. In January, for example, we raised the alarm around the lack of engagement and support from the business units which hold the key to assessing how and why personal data is collected, how it is processed and used, and therefore how much effort should be made to ensure the company can continue to work with it. Lack of engagement continues to be a challenge with many of our Summit workshop participants reporting that they are still working to motivate the stakeholders needed across various functions. Unfortunately, the work continues to be the domain of a few as most employees and their managers have yet to understand that GDPR is a task for everybody.

Work is progressing on the development of policies—legal departments are active in the review of contract clauses, plans are being made to communicate privacy notices to individuals—but there remain many practical gaps and a level of detail that many in the room admitted they had not yet considered. An example included employee awareness and the need to manage their downloading of data on laptops. It was clear training would be required, but the scope of such training has yet to be defined. In considering the need for an inventory of the personal data held, some very basic questions are still being asked, such as: How can you know when the task is complete?

There are also numerous uncertainties arising as requirements are translated into the processes needed for implementation. Discussions covered whether companies could rely on consent gathered decades ago, should a record of it be found.  Participants were unclear as whether privacy notices would have to be given in local languages—or all EU languages. To challenge things further, the role of the Data Protection Officer and parameters to conducting Data Protection Impact Assessments have not yet been fully defined by the EU Committee (Article 29 Working Group) working with and providing guidance to member states. And, as is currently the case for security practice in general, companies will continue to be challenged to gain the control needed over legacy systems and shadow IT to assure compliance. This is expected to, for example, frustrate the effort to document a process and efficiently fulfill data subject access requests, a new individual right that will come into force.

Overall, with just over a year to go to the compliance deadline, organizations remain in discovery mode. Plans are being put in place, but we are still developing our understanding of the scope of the task ahead, and our engagement with the organization. To address this concern, the EAC GDPR Task Force has worked with members’ input to define 12 Areas of Activity and their key supporting tasks, as well as some of the tips they shared for implementation. They can be tackled simultaneously, are easy to understand, and importantly, communicate to the people that will be responsible for achieving them:

  1. Stakeholder support: board and business units
  2. Inventory of the personal information you hold
  3. Privacy notice and information
  4. Individuals’ rights
  5. Data subjects’ access requests
  6. Data Protection Impact Assessments
  7. Consent
  8. Children
  9. Personal Data Breaches
  10. Security of data processing and Data Protection by Design
  11. Data Protection Governance
  12. International Data Transfers

We will continue to share what we learn from the upcoming opportunities to learn more about members’ experience as we progress. Workshops will be held at all the (ISC)² Secure Summits in the EMEA region this year, and an overview will be shared within the Strategy Theatre at Infosecurity Europe June 8th. Join us if you can and let us know how you are getting along.

Yves Le Roux, Co-Chair (ISC)² EMEA Advisory Council (EAC) and Chair of its GDPR Task Force.

[(ISC)² Blog]

English
Exit mobile version