Top 10 Emerging IT Audit Issues

Michael Juergens; Deloitte & Touche LLP, Principal
Compliance requirements and resource constraints have focused IT audit procedures on the bare essentials of IT controls. And yet, at the same time, technology and the current economic climate are introducing new IT risks that IT auditors should be aware of. In this presentation, we will cover the top 10 emerging IT issues that IT auditors should be aware of. In addition, we will cover the key risk areas for each issue, and provide practical recommendations for how IT auditors should deal with these risks.
Sep 29 2009
49 mins
Top 10 Emerging IT Audit Issues

Webinars and videos

  • Live and recorded (1009)
  • Upcoming (32)
  • Date
  • Rating
  • Views
  • In this session, we look at the issues with testing and audit. This is the base causes of why we fail to secure systems and how we can more effectively create methodologies that actually find flaws. Penetration tests and audit each have major failings, but when done correctly and with the right incentives, they can help make us more secure. When done poorly, we all suffer.
  • Zac Streelman, Manager, Information Technology at Leupold and Stevens was looking for a disaster recovery (DR) solution that would extend the flexibility of virtualization to his DR environment. The solution had to deliver enterprise-class support for his mission critical applications: Oracle, Microsoft SQL Server and SharePoint and various CAD programs. The board of directors was specifically asking what the current solution was and what service levels could the infrastructure deliver.
    Zerto Virtual Replication installed seamlessly into their existing infrastructure, did not require any data center updates and is fully integrated into VMware vCenter.

    With Zerto Virtual Replication he was able to:
    - Realize very aggressive service levels – recovery point objectives of seconds and recovery time objectives of minutes
    - Deliver a better ROI with a DR solution that is hardware agnostic
    - Increase team productivity with a very simple solution
    - Quickly cross-train additional staff on DR processes and procedures
    - Optimize flexibility as changes to the environment required changes to the DR strategy
    - Test and validate the DR failover process without taking primary production systems offline

    Join Zac Streelman, Manager, Information Technology at Leupold and Stevens and Jennifer Gill, Director of Product Marketing at Zerto, to hear from your peers and learn about Zerto Virtual Replication.
  • Zac Streelman, Manager, Information Technology at Leupold and Stevens was looking for a disaster recovery (DR) solution that would extend the flexibility of virtualization to his DR environment. The solution had to deliver enterprise-class support for his mission critical applications: Oracle, Microsoft SQL Server and SharePoint and various CAD programs. The board of directors was specifically asking what the current solution was and what service levels could the infrastructure deliver.
    Zerto Virtual Replication installed seamlessly into their existing infrastructure, did not require any data center updates and is fully integrated into VMware vCenter.

    With Zerto Virtual Replication he was able to:
    - Realize very aggressive service levels – recovery point objectives of seconds and recovery time objectives of minutes
    - Deliver a better ROI with a DR solution that is hardware agnostic
    - Increase team productivity with a very simple solution
    - Quickly cross-train additional staff on DR processes and procedures
    - Optimize flexibility as changes to the environment required changes to the DR strategy
    - Test and validate the DR failover process without taking primary production systems offline

    Join Zac Streelman, Manager, Information Technology at Leupold and Stevens and Jennifer Gill, Director of Product Marketing at Zerto, to hear from your peers and learn about Zerto Virtual Replication.
  • Join us as top security experts look at some of the latest security challenges and provide strategies for defense, including how to quickly implement a robust solution that provides the protection you need without impacting your network performance or reducing employee productivity. You will learn how to better protect your networks from the inside as well as the outside, with solutions that reduce work for IT and security teams.

    You will learn about:
    •The malware menace – latest stats and facts
    •Third party industry firewall comparison results: which firewall is best for you?
    •Best and easiest practices for securing end points
    •How a customer implemented a solution—step-by-step
    •And much more…
  • The data center is changing in an era of applications and automation, but how do you get there? OST, an expert in crafting automation for large-scale public clouds and developing new provisioning models for enterprise technology and in-application development, has experience in bringing data centers into the 21st century.

    Register for this webinar to learn:
    •How to develop core disciplines of application development and automation in the IT department
    •How to provide business-responsive services without compromising quality
    •How to prepare your data center for the future
  • Le taux d’équipement en périphériques mobiles (PC, tablettes, smarphones) dépassant maintenant celui des PCs fixes, il n’est pas surprenant que la tendance se poursuive en entreprises. Hors la mobilité va de pair avec le Cloud en tant que nouvelle plateforme de collaboration d’où un échange des informations bien au-delà du traditionnel périmètre.
    Lors de ce webcast, nous vous proposons de mieux comprendre comment protéger vos données stockées dans le Cloud, tout en garantissant une facilité d’expérience aux utilisateurs.
    Découvrez :
    -Comment développer, gérer et mettre en œuvre des politiques de sécurité renforcées dans le Cloud
    -Comment sécuriser les communications emails échangées entre terminaux mobiles
    -Comment Symantec peut vous aider à résoudre des problématiques de conformité grâce au DLP et au chiffrement
  • La convergence des infrastructures IT apporte un surcroit de complexité, de coûts et de risques dans la gestion, le stockage et la protection des informations dans les entreprises.
    Au cours de cette session, nous vous proposons de faire le point sur les enjeux actuels des infrastructures (virtualisation, croissance des données, stockage…) et vous présenterons une solution moderne de protection des données pour réduire la complexité et les coûts : l’appliance Symantec Backup Exec 3600.
  • Organizations outsourcing card data to the cloud face significant security risks. As soon as an organization adds other players to the offsite card-management mix, ensuring compliance with the PCI Data Security Standard becomes increasingly challenging. Cloud users and cloud service providers need to understand what their roles and responsibilities are when it comes to protecting this data. Storing, processing and transmitting cardholder data in the cloud brings the cloud environment into scope for PCI-DSS.

    Organizations need to know where their data is at all times. A lot of cloud clients have limited or no control over cardholder data storage. Organizations should be concerned about collecting and correlating access logs and other information from cloud vendors to ensure they are maintaining security compliance. Where's the data being stored? Is it stored in multiple locations? These are all things that you have to take into consideration when you're thinking about outsourcing to a cloud provider. Join this webcast as we address the compliance challanges in the cloud, and gain new insights on:

    - Emerging PCI security risks in the cloud
    - Understand the role of cloud entities
    - Processes for assessing risk when card data could potentially be stored in multiple locations
    - Structuring planning controls to deal with PCI DSS changes
    - Recommendations for achieving PCI compliance across virtual environments
  • Enterprise IT implementations and upgrades often come with business disruption, unexpected costs and lengthy delays. What if there were a way to avoid those risks?

    Please join us for an informative webinar spotlighting a unique alternative to traditional onsite technology integration. Take a look inside FusionStorm’s Integration Center and see how our expert configuration, staging and logistics services enable on-time, plug-and-play installation of multivendor solutions anywhere in the world.

    Detailed case study examples will show you how to cut deployment time and disruption for:
    •rollouts of customized technology solutions to multiple locations
    •repetitive deployments of standardized equipment

    Mark your calendar and join us for an inside look at the best practices and nimble processes that enable rapid turnaround of complex projects with less risk.
  • Channel
  • Channel profile
Up Down
  • Detecting File Execution: What Runs but Never Walks Jun 5 2013 5:00 pm UTC 45 mins
    In this webinar, I will begin with a brief discussion of the different types of attackers, and show how all threat actors are not equal. Then, I will discuss four main ways attackers execute code in a Windows environment. Reviewing real cases of recent attacks, I will show how to detect file execution using static, dynamic, and advanced analysis techniques. I will show how to use artifacts such as the Windows registry, logs, prefetch files, and network data to determine whether an attacker executed files. Finally, there will be a discussion of tools used for forensic analysis, including free tools such as the ShimCacheParser and MANDIANT Redline.
  • Full Security Visibility For Effective Incident Response Jun 5 2013 4:00 pm UTC 45 mins
    Despite significant time and effort deploying multiple security solutions, incident responders know more than anyone that existing signature-based, “set it and forget it” security technologies have not stopped the advanced persistent threat. Signature- and rule-based technologies are easily evaded with today’s advanced targeted attacks, morphing malware and zero-day threats. Tools like FireEye’s Malware Analysis System are effective in dealing with zero-day malware, but being able to detect this threat does not mean complete resolution.

    In addition, sophisticated attackers employ social engineering or take advantage of misconfigurations in security technologies to breach networks – without using any malware at all. Incident responders need full visibility of everything that is going through the network to understand the nature of how a threat originated, see what attackers actually did to take control over the network, and to answer the questions of what they did after they compromised systems. This session will provide an overview of Big Data Security Intelligence and Analytics and how full security visibility can answer the toughest post-breach questions so you can quickly determine the full source, scope and material impact of an incident.
  • Top 10 Mistakes Incident Response Teams Make Jun 5 2013 3:00 pm UTC 45 mins
    When it comes to organizations experiencing some form of cyber-attack, the adage still rings true: it’s not a question of if but when. Advanced malware, zero-day exploits, and targeted advanced persistent threats (APTs) have kept organizations on their heels and searching for ways to protect themselves. Incident Response teams are being forced to re-examine their existing IT security defenses and attempt to stay ahead of the attack curve. Surprisingly, many incident response teams aren’t doing themselves any favors with practices they have implemented.

    Attend this webinar to learn the top 10 mistakes that Incident Response teams make and what you can do to make sure you aren’t making them yourselves.
  • Don’t Ask, Don’t Tell: The (In)Security of Vendor-Supplied Software May 30 2013 4:00 pm UTC 45 mins
    What vulnerabilities threaten the integrity of your software supply chain and data? Can your enterprise really influence software vendors to meet your most important security policies and remediate insecure software?

    Action is needed, and urgently. An alarming 62 percent of all applications fail to reach compliance on their first submission, according to a study recently conducted by Veracode, Enterprise Testing of the Software Supply Chain. While few enterprises now have formal third-party testing programs, those that do find they dramatically improve vendor compliance while meeting industry standards.

    Join this webcast with Chris Eng, Veracode's Vice President of Research, and you will learn:

    •How leading enterprises now test their software supply chains.
    •Analytics drawn from code-level analyses of thousands of third-party applications that support global enterprises.
  • Today's Advanced Threats Require Next-Generation Protection May 22 2013 5:00 pm UTC 45 mins
    Are you using or considering a next-generation threat protection solution? Join this webcast and learn how you can multiply the value of your investment by integrating network and endpoint security.

    During this session you’ll learn best practices for protecting your network and your endpoints and servers from today's new breed of cyber attacks. You’ll also see firsthand how the integration of network and endpoint security solutions will help you:

    ・ Automatically confirm and prioritize alerts
    ・ Provide enterprise-wide visibility of infections to speed investigation
    ・ Drive remediation
    ・ Automatically analyze files from endpoints and servers
  • The Life Cycle of a Security Audit from Start to Finish Recorded: May 16 2013 49 mins
    The webinar will cover the life cycle of a security audit from start to finish. Several areas will be discussed to include auditing of software. There will be tips on how to reduce the number of audit findings from a security and privacy perspective from the start of the SDLC (Software development life cycle). This presentation will focus on FISMA audits, but the tips can be applied to all security and privacy audits.
  • Optimizing Disaster Recovery for the Software Defined Data Center Recorded: May 16 2013 34 mins
    Zac Streelman, Manager, Information Technology at Leupold and Stevens was looking for a disaster recovery (DR) solution that would extend the flexibility of virtualization to his DR environment. The solution had to deliver enterprise-class support for his mission critical applications: Oracle, Microsoft SQL Server and SharePoint and various CAD programs. The board of directors was specifically asking what the current solution was and what service levels could the infrastructure deliver.
    Zerto Virtual Replication installed seamlessly into their existing infrastructure, did not require any data center updates and is fully integrated into VMware vCenter.

    With Zerto Virtual Replication he was able to:
    - Realize very aggressive service levels – recovery point objectives of seconds and recovery time objectives of minutes
    - Deliver a better ROI with a DR solution that is hardware agnostic
    - Increase team productivity with a very simple solution
    - Quickly cross-train additional staff on DR processes and procedures
    - Optimize flexibility as changes to the environment required changes to the DR strategy
    - Test and validate the DR failover process without taking primary production systems offline

    Join Zac Streelman, Manager, Information Technology at Leupold and Stevens and Jennifer Gill, Director of Product Marketing at Zerto, to hear from your peers and learn about Zerto Virtual Replication.
  • Why Your Cloud Provider Security Logo Doesn’t Mean a Thing Recorded: May 16 2013 49 mins
    As more applications have moved to the cloud, the industry has seen a proliferation of application security issues. In 2012, several cloud service providers were breached as a direct result of application security vulnerabilities. Before you choose a cloud service provider, make sure that it answers the series of security questions created by the Cloud Security Alliance (CSA). CSA has created a checklist of industry-accepted ways to document what security controls exist in IaaS, PaaS, and SaaS offerings – creating more transparency for enterprises. The speakers will walk attendees through this blueprint, helping them to become more adept at identifying service provider security readiness. They'll also discuss some of the most common application vulnerabilities, including unencrypted passwords, SQL Injection, and those that impact poorly architected mobile apps.
  • Panel: In the Face of New Technology - Your Business and the Internal Audit Recorded: May 16 2013 59 mins
    New and disruptive technology is changing how we live and work. It is no longer just the infrastructure of our organization, providing tools and information with which to run our business, it has become integral to many of our products and services. The deployment of technology is the #1 way in which CEOs look to gain advantage and market share, and the CIO must be a visionary leader of the organization.

    The panel will discuss how this affects IT Governance. Is it still appropriate to focus on the enterprise governance of IT as a separate but important issue? Or, should the focus shift to governance of the enterprise as a whole and whether it is taking sufficient advantage of technology? Panelists will address the issue from the perspective of an IT Governance Evangelist, an advisor to boards and CFOs, and a leading internal auditor.
  • Panel: Securing Your Enterprise Cloud Recorded: May 16 2013 59 mins
    As the cloud model continues to disrupt and enhance the modern enterprise IT teams are facing new challenges retaining security and control in these new environments. This panel will explore a multifaceted approach to the cloud that looks at the importance of integrating the right tech solutions and deployments while negotiating and understanding your relationship with cloud providers.

    Panel:

    Bill Brenner, Managing Editor, CSO Magazine (moderator)
    Nataraj Nagaratnam, Ph.D., IBM Distinguished Engineer, IBM Master Inventor
    Chris Farrow, Information Security Specialist, Compassion International
    Jason Mendenhall, EVP Cloud, Switch
  • End Point to Perimeter: Network protection that’s inside out and outside in Recorded: May 16 2013 55 mins
    Join us as top security experts look at some of the latest security challenges and provide strategies for defense, including how to quickly implement a robust solution that provides the protection you need without impacting your network performance or reducing employee productivity. You will learn how to better protect your networks from the inside as well as the outside, with solutions that reduce work for IT and security teams.

    You will learn about:
    •The malware menace – latest stats and facts
    •Third party industry firewall comparison results: which firewall is best for you?
    •Best and easiest practices for securing end points
    •How a customer implemented a solution—step-by-step
    •And much more…
  • Active Defense: How to Think Outside the Box Recorded: May 16 2013 48 mins
    Synopsis:
    This webinar will define the concept of active defense or "hack back”. During his talk, David will explore the legal issues, reveal how it can be accomplished without breaching any laws, and show you how active defense will actually improve your security posture.

    About the speaker:
    David is a leading authority in cyber security and the law. He is a licensed attorney in NY, CT, and CO, and owner of Titan Info Security Group, a Risk Management and Cyber Security law firm. David is a retired Army JAG officer. During his 20 years in the Army he provided legal advice in computer network operations, information security and international law to the DoD and NSA and was the legal advisor for what is now CYBERCOM. He holds the CISSP & Security + certifications and has two LLM’s in International Law and in Intellectual Property law. He is a VP of his local ISSA chapter and a member of InfraGard.
  • Five Things Virtualization Has Changed In Your Disaster Recovery Plan Recorded: May 15 2013 36 mins
    Are you still rolling with the changes? Virtualization has made a huge impact on the way we deploy our computer workloads, and with that it has also changed the ways in which we protect them. The business continuity plans in place for IT even just five years ago look very different than what many companies have in place today. Keeping on top of these changes will help you understand your recovery capabilities, and your limitations as well. Join this session to make sure you're keeping your IT business continuity plans spicy and fresh!

    About the Presenter:
    Josh Mazgelis has been working in the storage and disaster recovery industries for close to two decades and brings a wide array of knowledge and insight to any technology conversation. He is currently working as a senior product marketing manager for Neverfail Group. Prior to joining Neverfail, Josh worked as a product manager and senior support engineer at Computer Associates. Before working at CA, he was a senior systems engineer at technology companies such as XOsoft, Netflix, and Quantum Corporation. Josh graduated from Plymouth State University with a bachelor’s degree in applied computer science and enjoys working with virtualization and disaster recovery.
  • Next Generation Access and Identity Management For a Multi-Perimeter World Recorded: May 15 2013 47 mins
    In today's open and interconnected enterprise, traditional perimeters are being extended to adopt mobile, cloud, social access and information interactions. To make matters worse, many organizations face the growing risk and burden of managing multiple identity and access controls without the required security intelligence to address those challenges. They need the ability to secure identity and access across the wide variety of enterprise and internet resources from any device, any service and any source. In this session, join IBM to review the emerging needs, the next generation access and identity management solutions available today to enable secure and rapid adoption of mobile, cloud, and social transformation.
  • Panel: Virtual World with Virtual Risks. Can it be Cloudy and Clearly Secure? Recorded: May 15 2013 64 mins
    As companies migrate to the virtual datacenter, executives must deal with security, audit, and visibility of their environment which has grown beyond their physical datacenter. Because of this, hesitancy remains and many questions are still being asked. What is a next-gen datacenter? What changes as businesses take steps toward a hybrid datacenter? When they move to a virtualized environment, how does their data remain secured and in their control? Will encrypting data in this environment achieve visibility and control of who is accessing it? Plus despite more knowledge on virtual risks, cloud services are still being purchased without authentication, adopting cloud first and then thinking about security second. So how can organisations win the struggle with authentication in the cloud?

    Join your fellow professionals for this lively and insightful discussion providing a complete vision on virtual risks in a virtual world. Then understand a way to manage risk, maintain compliance, accelerate and protect business from evolving security threats.
  • Stop Chasing Clouds: You Can Securely Adapt Recorded: May 15 2013 39 mins
    Enterprise is adapting to embrace new technologies and capture new opportunities. Cloud capabilities are attractive, but concerns for information security remain. In this webinar, Dr. Jeremy Ward will discuss how you can adapt and embrace change, while maintaining the security of your infrastructure and information. The key points discussed will include choosing a security service that helps you form better cloud security strategies that manage data risk, reduce complexity, identify vulnerabilities, and ease user access; resulting in improved security governance, enhanced visibility, increased cost control, and reduced risk exposure.
  • Attacking the Cloud with Social Engineering Recorded: May 15 2013 44 mins
    Synopsis:
    Cloud computing creates new opportunities for attackers who deploy social engineering as part of their strategy. End user organisations and cloud providers may be unprepared for these new attack vectors, which exploit some of the key elements of the cloud computing model. Pete will describe some real-world experiences with attacks that utilise multi-vector techniques and suggest how organisations can better defend against criminals and hackers alike.

    About the Speaker:
    Peter is a world-renowned security evangelist, speaking at conferences and seminars on ethical hacking and social engineering. He has appeared in documentaries for BBC television, provided commentary on security issues for TV and radio and written many articles on a variety of security topics.

    Peter has worked in the electronics and computer industries since 1969. He has extensive experience of communications and networking, with hands-on knowledge of many large-scale systems. He founded First Base Technologies in 1989, providing information security consultancy and security testing to commercial and government clients. Peter has hands-on technical involvement in the firm on a daily basis, working in penetration testing, social engineering and awareness.
  • Data Privacy in the Cloud – Enabling Business Agility by Managing Risk Recorded: May 15 2013 47 mins
    Synopsis: Organisations can’t avoid using the cloud. With surveys reporting that 90% of organisations achieve projected savings and 80% increase their competitive advantage, as one tech writer put it, “the cloud is coming to your business, like it or not”. But with cloud systems come inherent challenges. These are further complicated as data subject to privacy regulation inevitably moves into the cloud. This webinar explains why data privacy in the cloud is a business issue. It provides an overview of privacy as a concept, explains personally identifiable information (PII), along with the demands typically placed on organisations by privacy regulations and de-mystifies the complexity of cloud-based systems and their inherent risks. The webinar maps out how you can manage the risk of using cloud services for private data – whatever stage you are at – based on current efforts to formulate good practice at leading ISF Member organisations around the world. It offers independent guidance on simplifying the complexity of cloud-based systems and their inherent risks, providing insight into how organisations can develop the necessary privacy safeguards and good practice guidelines to achieve privacy compliance when using such systems.

    About the speaker:
    Steve Durbin is Global Vice President of the Information Security Forum (ISF). He is a regular speaker and chair at global events and is quoted in the Financial Times, Wall Street Journal, Forbes, Deutsche Presse, Süddeutsche Zeitlung, CIO Forum, ZD Net, and Information Week.
    Steve has considerable experience working in the technology and telecoms markets and was previously senior vice president at Gartner. He is also currently chairman of the Digiworld Institute senior executive forum in the UK, a think tank comprised of Telecoms, Media and IT leaders and regulators.
  • 2 Minutes on BrightTALK: Working with the Hacker Culture Recorded: Apr 30 2013 2 mins
    "It's a great situation when you have a hobby which becomes a job. And for a lot of hackers, we're doing something for fun, and somebody's going to pay us to do it." Jack Daniel, Technical Product Manager at Tenable and a well-known industry figure, comments on the transformations that many hackers encounter as they enter the world of productivity and management.
  • Trust-Based Application Control 101 Recorded: Apr 30 2013 55 mins
    Todays cyberthreats are becoming more targeted and sophisticated. Antivirus and other traditional security products are ineffective against stopping these attacks - like the ones that could be aimed at your organization.

    Learn how the visibility, detection, protection and forensic capabilities of a next generation security platform can help you protect your organization against advanced threats and malware by using trust-based application control.

    Attend this webinar to discover how you can:

    · Know what’s running on every server and endpoint—right now.
    · Deploy real-time detection of advanced threats and zero-day attacks.
    · Stop all untrusted software from executing.
    · Conduct a full audit trail that accelerates analysis and response.
    · How you can Integrate Endpoint/Server and Network Security
trends, developments, and technology
Increasing expectations for good governance, effective risk management and complex demands for legislative and regulatory compliance are presenting a growing challenge for organizations of all sizes. Tune in to live and recorded presentations by respected luminaries in the fields of governance, risk and compliance. Their thought leadership will provide you with practical advice on how to implement successful GRC strategies and processes for your organization.

Embed in website or blog

Successfully added emails: 0
Remove all
  • Title: Top 10 Emerging IT Audit Issues
  • Live at: Sep 29 2009 4:00 pm
  • Presented by: Michael Juergens; Deloitte & Touche LLP, Principal
  • From:
Your email has been sent.
or close
You must be logged in to email this