ISACA® Western New York Chapter - May 2010 Newsletter


 


Monthly Newsletter 

May 2010 

Vol.2 Issue 5

CHAPTER NEWS

ISACA-WNY was at this year’s White Hat Security Day earlier this month.  Attendee interest in membership and certification was positive.  The event drew record numbers and featured presentation by Chapter President Peter Spier on the HITRUST Common Security Framework.

In This Issue:

Chapter News
Member Spotlight
President's Message
Upcoming Events
ISACA Resources
Technology News
Featured Download
Trivia

MEMBER SPOTLIGHT

Patrick Helmes


Patrick Helmes is an IT auditor with PricewaterhouseCoopers. Helmes is scheduled to take his CISA certification exam and further plans on studying for the CISM certification. He also recently assumed the role of the chapter's webmaster.

Helmes has been working in the audit field for over three years, and has been a member of ISACA for the same amount of time. He learned of ISACA through his manager and is looking forward to this year's Rochester Security Summit. Further, he values the many reference materials that are made available as a part of his membership in addition to its many networking opportunities.

PRESIDENT'S MESSAGE

It appears that summer has finally arrived!  With the warm weather too comes many an IT initiative.  With this flurry of activity, as a reminder, please be certain to appropriately mitigate your risk.

Also, good luck to our certification exam registrants!  I know that our CISA Course Review attendees are well prepared. 


Peter Spier

Chapter President

UPCOMING EVENTS

PCI Risk Abounds: Practical Approaches to Achieving and Maintaining Compliance -

Be sure that your cardholder data environment is compliant and stays compliant.  Join us for this moderated panel event and stay for networking, refreshments, and hors d’oeuvres!  June 10th from 2:30pm-6:30pm at Max of Eastman Place, 25 Gibbs Street, Rochester. Please contact Chapter Secretary Alex Douds for further information.

ISSA Event: Computer Hacking and Intellectual Property Crime Seminar -

Includes an overview of Computer Crimes, Resources, and Trends.  Do YOU know when to contact law enforcement?  Find out more June 2nd from 9:00am-3:00pm at

RIT.  Please contact Kendell Jones for further information.

 

TRIVIA

Which of the following is the PRIMARY safeguard for securing software and data
within an information processing facility?


A. Security awareness
B. Reading the security policy
C. Security committee
D. Logical access controls


Submit your response through our Contact form. The first received, correct answer wins a $5 Amazon Gift Certificate!

 ISACA RESOURCES

The Certified in Risk and Information Systems Control™

The Certified in Risk and Information Systems Control™ certification (CRISC™, pronounced “see-risk”) is intended to recognize a wide range of professionals for their knowledge of enterprise risk and their ability to design, implement, monitor, and maintain IS controls to mitigate such risk. It is particularly designed for IT professionals who have hands-on experience with risk identification, assessment, and evaluation; risk response; risk monitoring; IS control design and implementation; and IS control monitoring and maintenance.

 




 

 

TECHNOLOGY NEWS

Ukranian TJX Hacking Suspect Arrested In India

By Dan Goodin
Source:The Register

A Ukrainian national accused of helping to hack into nine US retailers and making off with data for millions of credit cards has been arrested in India, IDG News has reported.

Sergey Valeryevich Storchark was arrested earlier this week in New Delhi as he deplaned from a flight from Goa, the news service said, citing a spokesman with India's Central Bureau of Investigation. He was in New Delhi on a layover before flying to Turkey.

The arrest is a major victory for US law enforcement agents, who are pressing for Storchark's extradition via diplomatic channels. It's often next to impossible to extradite suspected hackers from many eastern European countries. "His extradition and prosecution would have been very unlikely had he reached his final destination of Ukraine," Indian authorities said in a statement.

Storchark was one of 11 men charged in August 2008 with hacking the networks of TJX and other retailers. The ringleader of the operation, Albert Gonzalez, was sentenced to 20 years in prison in March after pleading guilty in three separate cases brought in Massachusetts, New Jersey, and New York.

FEATURED DOWNLOAD

The Business Case Guide: Using Val ITTM 2.0

The business case does not operate in a vacuum. It is an integral part—a fundamental building block—of the Val IT
framework, which is a comprehensive and pragmatic organising framework that enables the creation of business value from
IT-enabled investments.

Copyright © 2010 ISACA® Western New York Chapter. All rights reserved.
If you wish to cancel your subscription to this newsletter click here