All Upcoming Events

Seminars

Breakfast Meetings

CISM/CISA Reviews

Board Meetings

Past Events

 

Topic:
IT Controls Required to Enforce Data Privacy and Prevent Fraud 
Type:
Seminar
Date:
Tuesday April 06, 2010
Time:
8:30 AM - 5:00 PM
Price:
ISACA Member: $50
Non-member: $75
CPE's:
8
Registration Deadline:
April 2, 2010
Location:

Protiviti
101 Arch Street
Boston, MA

Description:

IT Controls Required to Enforce Data Privacy and Prevent Fraud

 

Regardless if your interests relate to the Government, Health Care, Retail or Financial industries, this seminar cuts across all of the data privacy and fraud detection/prevention legal requirements in order to establish implementation and audit validation requirements.

I.  Introduction to Data Privacy and Fraud Prevention

  • What is PHI, PII and private employee & customer information?
  • Data Privacy & Fraud Prevention Legal Requirements
    • How these legal requirements impact specific industries
  • Security and operation impacts of recent legislation (HITECH Act and others)
    • How companies are addressing these requirements

II.  Risk Assessment processes

 

III.  Establishing and Auditing a Privacy Impact Assessment

 

IV. Data Classification Standard

 

  • Alternative approaches used for developing a data classification standard
  • Implementation requirements
  • How to audit a data classification standard

V.  Detective Processes “red flags”

  • Alternative audit trails
  • Evaluating Detective Process “red flags” to reduce Fraud
  • Identifying inadequate data collection processes
  • Automating detective review processes

VI.  Third Party Relationship handling

 

  • Business partner data exchange
  • Handling third-party vendor access

VII.  Reassessment of Access Control Requirements

 

  • Upgrade requirements to logon security
  • Security design approaches which do not meet Data Privacy and Fraud Prevention requirements
  • Realistic measures for maintaining confidentiality of data in transit
  • Alternative approaches for securing data at rest

VIII.  PCI Compliance

 

  • An insiders view of how to become and maintain PCI compliance
  • Unpublished methods to resolve “show stopper” non-compliance issues

Speaker:

Mitchell H. Levine, CISA

 

Mitchell Levine is the founder of Audit Serve, Inc. which is an IT Audit & Systems consulting company.   For the last 20 years at Audit Serve, Mr. Levine has split his time between traditional IT & Integrated Audit Consulting projects, PCI Implementations, SOX Implementation/Testing Projects and the implementation of defect tracking, compliance and software management systems.  Mr. Levine spends 220+ days per year consulting which is the basis for the material which is included in the seminars.

 

Over the past five years Mr. Levine has presented over 35 seminars to thirteen different ISACA & IIA chapters.  Mr. Levine also was the primary writer and editor of the Audit Vision Magazine which was published from 1991 – 1998.  The magazine was transformed into the Audit Vision E-mail newsletter which is published monthly which has a subscription base of over 3,500 audit & security professionals.

 

Prior to establishing Audit Serve, Inc. in 1990, Mr. Levine was an IT Audit Manager at Citicorp where his duties included managing a team of IT Auditors who were responsible for auditing 25+ service bureaus and the corporate financial systems.

 

Directions:

1) For driving directions please go to Google Maps. 2) Using the MBTA take the Red or Orange Line to Downtown Crossing.

Questions?:
Send an email to evp@isacane.org

Return to Events

______________________________________________________________

Cancellation Policy

ISACANE will make every effort to hold events at the times, dates and locations specified. However, ISACANE holds the right to cancel and/or change ISACANE event times, dates and locations under certain conditions. These conditions usually include, but are not limited to, inclement weather, event venue cancellation or rescheduling, speaker cancellation or rescheduling, and insufficient number of participants for the event. ISACANE holds the right to cancel the event for any reason up to and including the day of the event. In the event that ISACANE must cancel the event, you will be refunded your money in full.

In the event of predicted inclement weather, a decision will be made by 5pm on the prior day. If the event is cancelled, the notice will be posted on the website and an email will be sent to all registered participants. ISACA ® New England will attempt to reschedule the program\seminar if space allows.

Refund Policy

All Registrants are required to pay for a session.    Full refunds will be given for a cancellation if a participant emails the Programs and Seminar committee of the cancellation two (2) weeks prior to the seminar date.  A refund transaction fee will be charged.  Canceled reservations after the deadline date will be billed.