(ISC)² Names 2016 Harold F. Tipton Memorial Scholarship Recipient

Erwin Karincic of Virginia Commonwealth University selected to carry on Tipton’s legacy in information security 

Clearwater, FL – January 5, 2017 –(ISC)²® today announced that Erwin Karincic, undergraduate student at Virginia Commonwealth University (VCU), is the recipient of its 2016 Harold F. Tipton Memorial Scholarship. The Tipton Scholar is selected annually from among the   previous years’ recipients of the (ISC)² Undergraduate Scholarships.

The (ISC)² Harold F. Tipton Memorial Scholarship, administered by the Center for Cyber Safety and Education™, was introduced in 2012 to provide enthusiastic and aspiring university students pursuing cyber, information, software and infrastructure security degrees, with a pathway into the profession. The scholarship was named after the late information security industry pioneer and (ISC)² co-founder Harold F. Tipton, and was established through the support of (ISC)² members, and CRC Press and their Taylor & Francis Group. Often referred to as “the grandfather” of the Certified Information Systems Security Professional (CISSP®), Hal’s work with (ISC)² as its past president, chief instructor and ambassador was integral to the formation of (ISC)² and the information security profession.

In 2016, the Center awarded scholarships to 44 students worldwide. The undergraduate recipients were invited to apply for the Harold F. Tipton Memorial Scholarship.

“It is a great honor for me to be named the Harold F. Tipton Scholar for 2016,” said Erwin Karincic. “This award is the most prestigious in the cybersecurity profession, and I am really proud to be the recipient. I will be sure that it is used to its full potential throughout my studies and my career.”

Mr. Karincic’s passion for technology started when he was only seven years old, growing up in Bosnia. His computer broke and without anyone to fix it, Karincic bought a hard drive and operating system, then figured out how to fix it himself. Immigrating to the United States in 2014, he learned English and began excelling academically, enrolling in college-level courses as a high school student. He is currently studying computer engineering at VCU and plans to pursue a career in cybersecurity.

“It’s quite impressive that Mr. Karincic is a 4.0+ student, has already earned more than nine professional IT certifications, and has competed in several cybersecurity competitions,” said Patrick Craven, director of the Center for Cyber Safety and Education. “He aspires to earn the CISSP and to help mentor other students, which demonstrates his motivation to excel as a leader in the industry. We’re pleased to honor him with this memorial scholarship to help carry on the late Hal Tipton’s legacy.”

Undergraduate, graduate and post-graduate students all have the opportunity to build careers in the field of information security through the (ISC)² Information Security Scholarship Program. The scholarship application period for 2017 opened on January 1st with the Women’s Scholarships. The application period for Undergraduate Scholarships opens on February 15th, and on February 28th for Graduate Scholarships.

For more information and to apply, please visit www.Iamcybersafe.org/scholarships.

###

About (ISC)²

(ISC)² is an international nonprofit membership association focused on inspiring a safe and secure cyber world. Best known for the acclaimed Certified Information Systems Security Professional (CISSP) certification, (ISC)² offers a portfolio of credentials that are part of a holistic, programmatic approach to security. Our membership, over 123,000 strong, is made up of certified cyber, information, software and infrastructure security professionals who are making a difference and helping to advance the industry. Our vision is supported by our commitment to educate and reach the public through our charitable foundation– The Center for Cyber Safety and Education.  For more information on (ISC)², visit www.isc2.org, follow us on Twitter or connect with us on Facebook.

###

© 2017, (ISC)² Inc., (ISC)², CISSP, SSCP, CCSP, CAP, CSSLP, HCISPP, CCFP, CISSP-ISSAP, CISSP-ISSEP, CISSP-ISSMP and CBK are registered marks of (ISC)², Inc.

About the Center for Cyber Safety and Education 

The Center for Cyber Safety and Education (the Center), formerly the (ISC)² Foundation, is a nonprofit charitable trust committed to making the cyber world a safer place for everyone. The Center works to ensure that people across the globe have a positive and safe experience online through their educational programs, scholarships and research. Visit www.iamcybersafe.org.

Media Contact

Maria Forrest
Senior Manager of Corporate Communications
mforrest@isc2.org
727-201-5759

[(ISC)² Press Release]

2016 Accomplishments Poised to Drive 2017 Growth

We hope 2017 finds you ready for another year of challenges, opportunities and achievements—much like the year we all have just enjoyed.

In 2016, ISACA moved forward as an organization with the support of its 215 chapters around the world working to increase our visibility, influence and impact, locally and globally.  Perhaps most encouraging is the progress we are making as a valued professional community, which has occurred amidst rapid changes and increasing complexity in and around our key fields of interest—audit/assurance, information and cyber security, governance and risk. Highlights from 2016 included:

  • The growth of our community to 159,000 constituents worldwide;
  • A very inspirational and successful Global Leadership Summit (GLS) that brought together over 400 ISACA chapter, member and staff leaders in April, and has resulted in ongoing input on both ISACA’s current efforts and how best to shape the future of our organization;
  • Regional expansion of ISACA events: Our first Africa CACS conference was held in Nairobi, Kenya, in August. Two new cyber security conferences took place in November: CSX Asia Pacific in Singapore and CSX Europe in London;
  • Completion of the development work required to support the 2017 transition from paper-based to computer-based testing for ISACA’s core certifications (CISA, CISM, CRISC, CGEIT);
  • ISACA’s acquisition of CMMI, with plans to accelerate ISACA’s reach in fast-growing economies, including China and India, and to better engage and deliver solutions to enterprises, while highlighting the value members of our professional community deliver;
  • ISACA’s significantly increased engagement with government, including the EU, US, India, Israel, Jordan, China, Kenya and Singapore, with many others expressing interest or initiating a dialogue;
  • The launch of ISACA’s Connecting Women Leaders in Technology program, which has been well-received across our professional community, and offers opportunities to extend its impact going forward into 2017 and beyond;
  • Established business development initiatives to grow relationships with organizations that employ professionals in our community worldwide;
  • The recent deployment of the ISACA Member and Customer Experience Center which, in its first two months of operation, has already significantly improved response time and overall service levels, including reducing certification application processing time from eight weeks to three weeks, and responding to email inquiries in less than 72 hours.

The above is a small subset of all that has happened over the past year. These highlights, along with many other contributions and accomplishments, have helped lay the foundations for a very promising year ahead. In 2017, we will again expand our education and training programs; increase our research efforts and publications output; grow our collaboration with government, industry, and other strategic partners; launch a new digital presence; enhance member and customer service levels; and begin planning our 50th anniversary, with an aim of using this 2019 milestone as a means to further increase the visibility of our professions and to build our workforce of the future.

While our anticipated growth in 2017 will occur in a world that remains unsettled, we believe ISACA’s professional community is ready to meet the challenges that will ensue, and turn these challenges into opportunities in the spirit of ISACA’s purpose to help enterprises and people realize the positive potential of technology. We thank all of you for your support and efforts to date, and as we begin 2017, we wish you all a safe, healthy, productive and prosperous year ahead.

Christos K. Dimitriadis, Ph.D., CISA, CISM, CRISC, chair of ISACA’s Board of Directors and group director of Information Security for INTRALOT, and Matt Loeb, CGEIT, FASAE, CAE, Director and CEO, ISACA

[ISACA Now Blog]

Setting the Record Straight: Convincing Management of COBIT’s Value in Risk Management

Although COBIT remains an extremely valuable tool for IT risk management, many Latin American companies still find themselves slightly confused when trying to understand what it takes to carry out a complete or partial COBIT implementation. In fact, organizations still struggle with how to achieve long-term business and IT goals through proper use of the framework’s tools, and advice from experienced or well-informed practitioners is not sought because top management often considers any external consultancy as an expenditure with little or no return on investment. In addition, due to multiple mergers and acquisitions currently taking place, there is a growing interest in the region in implementing COBIT as an IT risk management framework and even as a way to comply with globally accepted regulations, particularly the US Sarbanes-Oxley Act 2002 (SOX).
In those terms, the main challenge that must be addressed by COBIT practitioners is encouraging top management to actively participate in the transformation process for integrating and standardizing IT management practices. Also, the COBIT practitioner must be focused on helping the involved stakeholders understand that “IT guys” are friends interested in taking the company to the next level and providing solutions, not foes who should be pointed to when looking for scapegoats. Some of the elements to be considered when implementing COBIT as a reference for risk management practices are:

  • According to the COBIT goals cascade, every endeavor regarding the enterprise enablers must be driven by IT-related goals, which are also leveraged by the enterprise goals and the stakeholder needs, which includes risk optimization.
  • Going along with this definition, the concept and scope of governance of enterprise IT (GEIT) must be clarified and communicated within the organization to enable the achieving of the goals in which IT has participation and accountability. Once GEIT has been established, the cornerstone for the IT internal control model is established.
  • In addition, a business case must be generated to create an interface between the stakeholders’ expectations and IT plans as referenced in the publication COBIT 5 for Business Benefits Realization. The definitions included in the aforementioned business case will be the confirmation that the GEIT goal is to generate potential benefits for the organization as a whole, considering the pervasive nature of IT.
  • According to the white paper Getting Started With Governance of Enterprise IT (GEIT) and in this author’s experience, GEIT ensures greater alignment of IT functionality with business needs. However, commitment from the enterprise leadership at the highest levels (e.g., C-suite, board of directors) is fundamental to ensuring a successful implementation and a sustainable model.

Based on the aforementioned facts and on each organization’s background—determined by factors such as industry, rate of automation of its processes, and applicable regulation (e.g., SOX, anti-money laundering, fraud prevention) it is also important for the COBIT practitioner to set the record straight with the organization’s top management about the culture and practices that must be embraced when adopting the framework into their organizations:

  • Definition of governance and risk management structures required for the implementation of COBIT practices is not a one-time effort.
  • The effectiveness of the framework’s risk management practices depends on the management fomenting and fostering COBIT’s enablers as a primary commitment.
  • Although IT must actively participate in defining practices, COBIT maintenance and periodic review must be sponsored by core business and controlling dependencies.
  • Management must be aware that there is not a standard timeline for implementing COBIT. Therefore, COBIT practitioners must set realistic expectations with management when defining and analyzing which COBIT enablers will be implemented and how many resources (e.g., time, money, people) will be required to use COBIT practices and ensure their sustainability through early life support and other management review and follow-up activities. In some cases, it could even take years to get to the maturity level agreed on by the enterprise!

So, what should COBIT practitioners do to fight against these misconceptions? What actions will generate more COBIT supporters, based on the framework’s applicability, and counteract any perception that COBIT is an excuse invented by consultants to sell high-end products and obtain a constant income on a periodic basis? In this case, the experts’ experience, vision and judgment are fundamental, not only to set a solid cornerstone for IT risk management, but also to ensure the business processes will be optimized thanks to COBIT’s benefits, due to the relevance assigned by the standard to the management’s goals. The presentation prepared by the COBIT implementer and the individuals to whom it is presented will also affect the outcome, since the same presentation should not be used for top management, business areas, IT staff and support dependencies. Nonetheless, the main message must remain consistent: The entire organization is responsible for COBIT’s success and proper operation, with periodic consultations from external experts.
Another important factor is to assign proper accountability to ensure the defined practices are properly implemented and operate consistently over time. Robust activities and processes with no accountability are practically useless. The stakeholder accountable for each process must be defined according to business goals and requirements, and that person must act as a translator of the general strategic plan and as a mediator when change is to be implemented. The accountable stakeholder must be also aware of the process’s maturity level, what it is required to achieve the next level (assuming the enterprise has agreed that a higher level is optimal for the business) and what should be changed after a review is performed. Phrases such as “I do not have to change it since we have not have any outages” or “I have always done things this way and I have been with the organization for more than 20 years” pose a huge challenge for the accountable stakeholder, suggesting his/her role must also consider skills for dealing with change and transforming it into an opportunity to understand the importance and impact that each factor has for an organization.
With that being said, when initiating a COBIT implementation, practitioners should instruct the project’s stakeholders with these messages:

  • COBIT maintenance requires resources and infrastructure, but, in the end, it will greatly improve an organization’s stance regarding risk management.
  • COBIT promotes the importance of leadership and teamwork because, without proper guidance, commitment, and assignment of roles and accountability, the policies, procedures and rules that come along with COBIT fall into the perception that IT is an expenditure.

Conclusion

COBIT is a very powerful tool with numerous features that can be adapted to different circumstances, but it also takes a great deal of commitment to ensure it operates as expected. If management understands that everything is capable of being improved, nothing eternally remains in the same state and expert judgement is required on a periodic basis, the mystery of how to properly use COBIT to achieve business, compliance and operational goals could finally be solved.

Julian Marquez, CISA, CRISC, COBIT Foundation, ISO 27001 LA, ITIL Foundation
Is an experienced risk management professional. He has worked with Deloitte on IT auditing and consulting services for projects in Colombia, Chile and Canada. He has worked on initiatives to use COBIT as a reference framework for different retail, manufacturing, financial services, and energy and resources companies. He has also participated as a trainer on internal and external COBIT-related training.

[ISACA COBIT Focus]

The Decision to Adopt Machine Learning for Telemedicine

Telemedicine is fast-growing as a mobile health care information system (HIS) in most parts of the world. Fast Internet, smart phones and increased comfort of physicians in using electronic communication are also helping telemedicine become more widely adopted. Telemedicine consultation can contribute to reducing cost, lessening the stress of patients and improving accessibility to specialized consultations. However, it is difficult to schedule correct telemedicine sessions without a deep understanding of the health care needs of the region. The use of machine learning for decision making and better treatment has been a highly researched topic. Machine learning is also used to monitor patients remotely. However, this technique is not currently used to monitor telemedicine session broadcasting. In our recent Journal article, we present the case of an Indian health care organization that broadcasts telemedicine sessions to associated hospitals in remote locations. For the purpose of telemedicine governance, we suggest the following steps while using machine learning techniques through the department-session-organization (DSO) model proposed in our article:

  • Understand the specific IT governance problem using organization mission and vision to determine the purpose of the prediction model.
  • Past data collection, data cleaning to remove incomplete data and analysis of the data is required.
  • Perform data transformation for simplification and improved decision making if needed. For example, we simplified our model by clustering hospitals based on regions and identified teaching and nonteaching hospitals for better distinction and prediction.
  • Based on the data set, the organization needs to determine the kind of machine learning technique suitable for its decision making. In our study, as the variables were categorical and best suited for a classification model, we tested multiple classification techniques. Based on the results, we observed that a classification tree provided us the best prediction accuracy.

It is also important to balance the cost of information retrieval and resulting profit out of the prediction technique. While determining the return on the additional investment, we accounted for the risk associated with misclassification by the telemedicine decision support system (TDSS). A clear understanding of the risk and return on investment will help the hospital to understand the pros and cons of going forward with such a prediction technique.

Read Shounak Pal and Arunabha Mukhopadhyay’s recent Journal article:
A Machine Learning Approach for Telemedicine Governance,” ISACA Journal, volume 1, 2017.

Shounak Pal and Arunabha Mukhopadhyay, Ph.D.

[ISACA Journal Author Blog]

How to Keep IT Employees Fully Engaged

In my last article, I wrote about the importance of training, and how I believe it is the missing ingredient to IT success. This is something I feel rather strongly about and will discuss with anyone who listens.

But as I mentioned, the word training comes with some negative connotations – at least for myself. I associate it with being a student in a structured classroom setting where I’m supposed to follow the teacher’s instructions. Unfortunately, I’m afraid that many of my peers feel the same way.

But this is just one surface-level symptom of a larger issue. The fact of the matter is that many organizations don’t understand how to fully engage their IT departments. As a result, continuing education suffers, employees begin to lose focus, and productivity wanes.

This is why I’m a major proponent of finding better ways to engage IT employees and make them feel like what they’re doing is important and appreciated. In doing so, the entire organization benefits.

Ideas for Keeping Employees Engaged
How do we engage our IT employees? That’s a question that organizations need to consider as we move forward. And while there are some IT-specific strategies, a larger organizational perspective is critically important. Committing to engaging the company as a whole will lead to benefits for the IT department.

The first idea is to pull back on mindless restrictions that aim to establish pointless uniformity in the organization. This is something Zappos, the online shoe retailer, is adamant about.

“Zappos has a casual work environment where employees can be their most authentic selves,” according to an article in U.S. News & World Report. “The dress code is relaxed so they can feel comfortable. As long as their outfits are respectable and work-appropriate, employees have the freedom to express their individual style.”

When employees feel like themselves, they’re more engaged. It tears down the imaginary barrier between work and personal life and starts to feel more natural.

The second thing I recommend is for companies to invest in regular departmental team-building outings. Your IT employees would do well to get out of their comfort zones and try something they’ve never done before. I would recommend an activity like whitewater rafting. I did this while working for a previous employer, and we all left feeling like we knew each other better.

The goal of a team-building outing is to force employees to rely on one another. This increases trust and allows each individual to better understand the strengths and weaknesses of his or her co-workers. Upon returning to a work setting, everyone feels like they have a better picture of what they’re doing.

The third key is to be clear with your company’s vision and the IT department’s goals.

“People want to understand the vision that senior leadership has for the organization, and the goals that leaders or departmental heads have for the division, unit, or team,” according to Dan Crim, an expert in organizational behavior. “Success in life and organizations is, to a great extent, determined by how clear individuals are about their goals and what they really want to achieve.”

Make the Investment in Engagement
I’ve worked in a number of organizations and can tell you that there’s a huge difference between companies that focus on employee engagement and those that ignore it.

Become a company that prioritizes engagement, and your IT employees will appreciate your investment.

Larry Alton, Writer, LarryAlton.Com

[ISACA Now Blog]

English
Exit mobile version