Showing posts with label compliance trainings. Show all posts
Showing posts with label compliance trainings. Show all posts

Thursday, May 29, 2014

Evaluating Your Compliance Training - Are You Providing Enough?

Overview

Financial institutions are required to be compliant with laws and regulations. Such compliance needs to be well documented and consistent to ensure financial institutions avoid violations and implications. However, financial institutions often rely on their training programs to provide knowledge and education to their personnel. This training needs to be sufficient and thorough enough to provide the necessary information for them to properly perform their roles and responsibilities while remaining compliant.

Why should you attend:

Although financial institutions have been managing their training program per the regulation requirements, determining if the training program is sufficient remains a challenge for financial institutions. Regulators look to the Bank for ensurance and evidence that not only are the training programs compliant with laws and regulations, but that they are thorough.

Areas Covered in the Session:

  • Assessing Training policies and procedures
  • Common Pitfalls in training
  • Determining effectiveness of training programs
  • Ensuring qualified oversight of training programs

Who Will Benefit:

  • Compliance Officers
  • Internal Auditors
  • Staff with roles and responsibilities in training
Speaker Profile : Gina Lowdermilk is a highly experienced and educated BSA/AML and Financial Regulatory Compliance professional with extensive policy and procedure development and implementation, training, internal audit, monitoring, risk management, and reporting experience. Her emphasis has been working with financial institutions that are experiencing regulatory concerns and resolutions, including enforcement actions such as memorandums of understanding and cease and desist orders.

Background to Industrial Regional Benefits in Canada - Webinar By Compliance4all.com

Overview

Industrial Technical Benefits- Canada's new approach to offsets for defence procurement: As part of the recently announced Defence Procurement Strategy, the Canadian Government has introduced a new industrial benefits policy that is designed to leverage purchases of defence equipment to create jobs and economic growth in Canada. Companies pursuing defence procurement opportunities in Canada will be required to submit value propositions, include key industrial capabilities (KIC) in their proposal and submit detailed industrial and technological benefits (ITB) plans with their proposals that will then be rated by the Government.
This webinar will provide the background to the Federal Government's new DPS, and discuss in detail value propositions, KIC's, and ITB plan requirements. The impact of this new approach on defence procurement will be assessed. Concluding remarks will include a brief discussion of some of the major procurement projects now underway in Canada. 

Why should you Attend:

Defence budgets are being cut throughout the world's advanced nations. While Canada is no exception, new defence policies have been introduced since 2008 that provide for predictable defence spending over a 20 year period. As part of those defence policies, the Canadian Government introduced the National Shipbuilding Procurement Strategy that envisaged spending more than $40B on ship replacement programs over the next 15 years.

With the exception of the USA, this is probably one of the largest military ship construction programs anywhere in the world today. Coupled to the NSPS is a recently announced Defence Procurement Strategy that reinforces the industrial benefits program required for all defence procurement; a program that in many ways is even more demanding than previous policies. If you are considering pursuing defence procurement opportunities in Canada, you will need to join this webinar to be up to date on the new Canadian policy


Areas Covered in the Session:

  • Background to Industrial Regional Benefits in Canada
  • Impact of IRB's on the defence industry in Canada
  • Policy changes over past three years
  • Why a new approach to defence procurement was required
  • New Defence Procurement Strategy
  • Industrial and Technological Benefits 101
  • National Shipbuilding Procurement Strategy
  • Impact of ITB's on shipbuilding requirements
  • Major Defence projects 2014-2020
  • Conclusions

Who Will Benefit:

  • CEO's
  • VP Business Development
  • VP Marketing
  • VP Technical and Engineering
  • Senior Government officials in State and Commerce
Speaker ProfileAnthony Goode After 30 years of commissioned service in the Canadian Navy, during which he commanded HMC Ships THUNDER, CHIGNECTO, SAGUENAY and ALGONQUIN, as well as Training Group Pacific, Fourth Destroyer Squadron and Royal Roads Military College, Tony Goode retired as the CF Naval Attache at the Canadian Embassy in Washington, DC in 1996 to join Litton Systems Canada (now L-3 Electronic Systems) as the Program Manager for the Tribal Class Update and Modernization Program (TRUMP). As that program wound down, Tony assumed responsibilities for program management of the CP 140 Mission Systems Avionics Engineering and In Service Support program and other related contracts. 

Wednesday, May 14, 2014

Moving to the 3rd IT Platform and Beyond - Challenges and Opportunities

Overview: According to IDC the 3rd IT Platform is comprised of Cloud, Mobile, Social, and Big Data. Mobile and Social originated in the consumer market and have been driven into enterprise IT by users, while Cloud and Big Data were typically driven by businesses looking to create a new computing paradigm and break the traditional bottlenecks in processing vast information. Forward looking IT organizations are now gearing up to utilize 3rd IT Platform technologies across most of their projects, and to move beyond, using new technologies such as Web APIs and BYOT (Bring Your Own Technology). 

This presentation will discuss the four pillars of the 3rd IT Platform and illustrate the challenges and opportunities to advance them for greater business value. 

Why should you attend:: Are you still deploying 2nd platform applications while your competition is moving full steam ahead onto the 3rd platform? The new technologies - cloud, mobile, social, big data - are compelling, but what is the best way to exploit them; how can you build the new generation of applications that appeals to your customers and connect them to the systems of record, without compromising the integrity of those systems?

Areas Covered in the Session:

  • The 3rd IT platform defined and redefined
  • How does IT consumerization impact the Enterprise?
  • Cloud 2.0: hybrid clouds, legacy migration, and a new application development paradigm
  • Moving Beyond BYOD - the impact of BYOT and the Internet of Things
  • How Web APIs enable the digital business
  • How can IT meet the challenges and stay relevant to the business
Speaker Profile: Max Dolgicer
is Senior Consultant at International System Group (ISG), Inc a leading consulting firm that specializes in IT Strategy, development and integration of large-scale applications, Service-Oriented Architecture, and Cloud Computing. For over 25 years Mr. Dolgicer has held many senior IT Management and Technical positions including engagements for companies like 3M, Carey International, United States Patent Office (USPTO), New York Stock Exchange (NYSE), Credit Suisse, Federal Reserve, Allstate Insurance, Financial Times Interactive, MetLife, Principal Financial Group, Cigna, Citi Group, Morgan Stanley, Delta Airlines, Goldman Sachs, McKenzie Financial Corporation. In addition to end-user companies, Mr. Dolgicer has worked closely for many established software vendors as well as various stage start-ups. Most of his work focused on product roadmap and strategy, competitive analysis as well as product positioning. 
Call our representative on 1800 447 9407 to have your seats confirmed.
Contact Information:

Event Coordinator
Toll free: 1800 447 9407
Fax: 302 288 6884
EITAGlobal
NetZealous LLC,
161| Mission Falls Lane| Suite 216, Fremont| CA 94539

Data Compression Methods and Compression Performance Metrics

Overview: The webinar covers the foundations of data compression in the context of the broader subject of information theory. The learner will gain valuable insight into how lossless compression works and why the techniques are robust and trustworthy. In the historical perspective, data compression concepts have arrived in a timely manner to aid the expanding data storage and wireless communication needs of the modern era. The measure of information is defined probabilistically, it is formally defined as entropy, a term that Claude Shannon borrowed from quantum mechanics. 

Why should you Attend:The information age continues to yield more and more data. The Internet, Big Data, Cloud Computing, and data storage requirements are measured in ever-increasing scales of Terabytes, Petabytes, Exabytes, and Zettabytes. Does data compression provide a solution to stem this ever-expanding flood? Can you trust data compression? Doesn't it put your data “at risk”? Are some types of data more compressible than other data? How do the methods of lossless data compression (covered) differ from lossy data compression? Take away from this session a meaningful understanding of lossless compression, its limitations, and the tradeoffs between storage reduction and increased processing required to compact and re-expand data. 

Areas Covered in the Session:
  • Entropy as the measure of information
  • Shannon's Source Coding Theorem
  • Huffman Trees and Huffman Coding
  • Arithmetic coding
  • Dictionary methods
  • Transform methods
  • Data deduplication
  • Implementation considerations, Open Source software, Hardware compression chips
  • Performance
Speaker Profile: Raymond Moberly
is a consulting subject matter expert in the field of Information Theory, knowledgeable about principles of error correction, cryptography, and data compression. He has worked extensively in the field of software defined radio. He has lead development efforts for embedded software and firmware on microcontrollers, digital signal processors, and field programmable gate arrays. He has extensive experience in the verification and validation of systems through all development phases including formal qualification testing. He enjoys profiling software in order to to analyze and better optimize code code performance. Raymond holds a bachelor's degree in engineering from Caltech, masters in applied mathematics from San Diego State University, and a doctorate in computational science from the Claremont Graduate University.
Call our representative on 1800 447 9407 to have your seats confirmed.
Contact Information:

Event Coordinator
Toll free: 1800 447 9407
Fax: 302 288 6884
EITAGlobal
NetZealous LLC,
161| Mission Falls Lane| Suite 216, Fremont| CA 94539

Best Practices for Securing Active Directory - Webinar By EITAGlobal

Why should you attend: This Webinar is helpful for Active Directory administrators. It teaches them how to properly secure the Active Directory Domain Controllers. A vast majority of servers in the world are running Microsoft Windows operating system. This makes them a favorite target of bad guys. In this Webinar you will learn some of the best practices for securing your Active Directory environment. 

Areas Covered in the Session:
  • 10 immutable laws of security
  • Minimizing known security threats to Active Directory
  • Identifying sources of threat
  • Securing various administrative accounts
  • Minimizing attacks on Domain Controllers from 16-bit apps
  • Deciding which services are necessary to run on Domain Controllers
  • Reducing Active Directory attack surface
  • Dealing with local administrator accounts
  • Understanding the protected accounts and groups in Active Directory
  • Group Policy settings for securing Active Directory
Speaker Profile: Zubair Alexander
is a Microsoft MVP, a Microsoft Certified Trainer, and the founder of SeattlePro Enterprises, LLC, an IT training and consulting company. He holds more than 25 industry certifications including MCT, MCSE, MCSA, MCDST, MCITP, MCTS, MCP+I, MCSA 2000/2003: Security, MCSE 2000/2003: Security, CNA, A+, Network+, Security+, CTT+ and CIW. His experience covers a wide range of spectrum: trainer, consultant, systems administrator, security architect, network engineer, author, technical editor, college instructor and public speaker. 
Call our representative on 1800 447 9407 to have your seats confirmed.
Contact Information:

Event Coordinator
Toll free: 1800 447 9407
Fax: 302 288 6884
EITAGlobal
NetZealous LLC,
161| Mission Falls Lane| Suite 216, Fremont| CA 94539


Disciplined Agile Offshoring: Making it Work for Both the Customer and the Service Provider

Overview: Offshoring software development projects suffer from two significant yet easily addressed problems. First, the customer's instincts for how to run an outsourced project are more likely to hurt rather than help them. Second, service providers (SPs) prove to be little more than order takers that don't have the courage to negotiate a winning strategy. 

Why should you attend:
  • What will happen with your intellectual property (IP)?
  • How do you know that an outsourced project is on track?
  • How do you recover a troubled outsourced project before it's too late?
  • How do you build a healthy relationship with your outsourcing partners?
  • How do you know that a service provider can deliver in an agile manner?

Areas Covered in the Session:
  • What the Disciplined Agile Delivery (DAD) framework is.
  • The risks associated with offshoring.
  • Disciplined agile offshoring from the point of view of the customer.
  • Disciplined agile offshoring from the point of view of the service provider.
  • What you need to do to succeed at disciplined agile offshoring.
  • Industry statistics regarding agile offshoring in practice
  • Criteria to determine if you're ready for offshoring IT delivery projects.

Speaker Profile: Scott Ambler

 is a Canadian software engineer, consultant and author, currently Senior Consulting Partner at Scott Ambler + Associates. He is a well-known author of numerous books focused on the Disciplined Agile Delivery process decision framework, the Unified process, Agile software development, the Unified Modeling Language, and CMM-based development. I spend much of my time exploring what works, what doesn't work, and why in software development. I regularly run surveys which explore such issues and work with organizations around the world to help them improve their software development approach. 

Thursday, April 3, 2014

2-day In-person Seminar: Security & Compliance by Objects using UML and SysML (PCI DSS, NERC,...) By Marc Andre Heroux


"The International Association of Privacy Professionals (IAPP) has approved "Security & Compliance by Objects using UML and SysML (PCI DSS, NERC,...)" seminar for 12 CPE credits"






Areas Covered in the Session:



  • Governance objects
  • Compliance by objects
  • Security Controls Definition and Implementation
  • UML/SysML - Object Management Group (OMG)
  • PCI DSS, NERC, etc.










Who Will Benefit:


  • Chief (CEO, CTO, CSO, etc.)
  • Senior Director
  • IT Manager
  • Project Control Officer (PCO)
  • Project Manager
  • Technological/Security Architect
  • Security Advisor
  • Auditor





















































































































































































































































































































































































































































  Why should you attend :


Many organizations have short delay to get their information system compliant to standards such as PCI DSS, NERC or any other standards.


This seminar will guide you in the application of a Compliance Object Model approach to evaluate the risk, determine gaps and implement security controls. 


This seminar will focus on how to apply Unified Modeling Language (UML) concepts from the Object Management Group (OMG) such as communication/collaboration diagrams and activity diagrams.
                                
                                 We will explore the SysML approach to elaborate system architectures and engineering model. During the seminar, we will design a Data Leak Prevention System using UML and SysML. The output diagram will present the functional and technical requirements (ex.: Diagram of the Security Controls for a Data Leak Prevention System). 

  Day 1 –Agenda

LectureAgenda Content
Lectur 1:
During the first day, we will explain the following:
  • What is UML?
  • What is SysML?
  • What are the relations between objects, compliances and security
  • We will enumerate the various elements and basics concepts to understand prior going forward with a real example
  • We will evaluate potential organizational data losses and the impact of loss
  • We will explain what are the requirements in order to apply the method: "Security & Compliance by Objects using UML and SysML"

 Day 2 –Agenda

LectureAgenda Content
Lecture 1:The second day, we will work with objects. We will evaluate the gaps between the current situation of an organization with the acceptable situation based on a "Risk Profile".
Lecture 2:We will design the security controls using UML and SysML. The final output will be the technological architecture to be implemented by the operational team.
Lecture 3:We will cover strategic aspects of the PCI DSS standard and NERC CIP to explain how we can quickly define tactical security controls and how we can collaborate the operational team regarding the implementation of each security control.
Lecture 4:After this seminar, you will be able to use the Compliance Object Model to quickly resolve security issues on a daily basis or apply the method for larger compliance project.
Lecture 5:Finally, you will be comfortable with many UML concepts of the Object Management Group (OMG) and will better armed to manage security and compliance in your organization.

About Speaker
speakerMarc Andre Heroux
Senior Security Advisor, GRCSI

Mr. Heroux cumulates over 16 years of experience in Governance, Risk Management, Compliance, Security & IT consulting.

Marc been involved in many Linux, Security & SaaS/Cloud Computing Projects. He has a solid technical background.

Since 2000, he especially acted as a security, compliance & risk management specialist. Marc leaded many critical security projects such as: AS2 certification with the AAFES (US Army and Air Force Exchange Service), compliance of Sears Canada and GE Commercial Finance transactions, ASC X12.58 encryption and architecture analysis for Banks, US Custom Border EDI integration and SOX compliance.

He also worked on compliance projects against ISO 27000, COBIT, ANSI, NIST standards, Basel II, SAS 70 (SSAE no. 16), PCI, CICA 5970, Article 17 Directive 95/46/EC & NERC.



Contact Information: 



Event Coordinator
Toll free: 1800 447 9407
Fax: 302 288 6884
EITAGlobal
NetZealous LLC,
161| Mission Falls Lane| Suite 216, Fremont| CA 94539