2004 San Francisco ISACA Fall Conference

SESSION TITLE

CONFERENCE SPEAKERS

· Keynote Speaker (Monday, 10/04/04)

· Victor Nichols, CIO, Wells Fargo

· Luncheon Speaker (Tuesday, 10/05/04) Sarbanes-Oxley

· Steve Wilkins, PricewaterhouseCoopers

· Luncheon Speaker (Wednesday, 10/06/04) OWASP

· Mark Curphey, Foundstone

· C11— Introduction to General Computer Controls

· Ed Byers, Deloitte

· Muna Shiekh, Deloitte

· C12— Auditing Application Systems

· Monica O’Reilly, Deloitte

· Maria Shaw, Deloitte

· C13— Introduction to Security Systems

· Carey Anne Carpenter, Deloitte

· Monica O’Reilly, Deloitte

· C21— Data Analysis—Leverage CAATs into Your Audits

· Sheryl Eberhardt, Deloitte

· Duy Nguyen, Deloitte

· C22— Business Continuity Management

· Neville Morcom, Deloitte

· C23— IT Architectural Reviews

· San Sri, Deloitte

· Shawn Mattar, Deloitte

· C24— Introduction to Project Risk Management / SDLS Reviews

· Greg Thomas, Deloitte

· Stephen Madler, Deloitte

· C31— Software Development Life Cycle

· Heather Stewart, Deloitte

· C32a — Oracle Application Security and Controls

· Ellen Chan, Oracle

· C32b— Oracle Database Security Auditing Basics

· Ellen Chan, Oracle

· Yogita Parulekar, Deloitte

· S11— Audit Risks and Issues for Radio Frequency Identification

· Lionel Yee, Ernst & Young

· Sagi Leizerov, Ernst & Young

· S12— Control Implications of Outsourcing

· Mark Lundin, KPMG

· S13— Streamlining Security Audits

· Douglas Barbin, Verisign

· S21— AICPA/CICA Enterprise Wide Privacy Framework

· Doron Rotman, KPMG

· S22— The Federal Perspective on Information Security Governance

· Mike Nelson, SecureNet Technologies

· S23— Use of COBIT As A Risk Management & Audit Framework For Access Compliance

· Lance Turcato, Schwab & Co.

· S31— Personal and Corporate Identity Theft

· Chris Pick, NetIQ

· S32— Web Services Risk, Controls, and Audit Implications

· Ayan Roy, E&Y

· S33— An Introduction to Security Event Management

· Matthew Klunder, PricewaterhouseCoopers

· E11— Internet’s Impact on Financial Crime

· Wilborne, US Secret Service

· E12— Sarbanes-Oxley and Identity Management

· Ehab Dawoud, PricewaterhouseCoopers

· E13— The Hacking Evolution:  New Trends in Exploits and Vulnerabilities

· Brian Christian, SPIDynamics

· E21— Intrusion Detection and Intrusion Prevention

· Eugene Shultz, Lawrence Berkeley Laboratory

· E22— Regulatory Compliance, Incident Response and the Technology Driving It

· Albert Barsocchini, Attorney

· E23— Security Development Lifecycle:  Applications and Infrastructure

· Himanshu Dwivedi, @Stake

· E31— Threats of Tomorrow

· Eric Levin, Qualys

· E32— Minimizing Operational Risks Associated with IT Security Breaches

· Arthur Coleman, Polivec

· E33— Web Site Gray Box Testing

· Bob Grill, Wells Fargo

· T1—Audit and Security of UNIX

· Rodney Kocot, Systems Control & Security, Inc.

· T2— Best Practice and Compliance:  What You Need to Know to Bridge the Gap and Meet Network Auditing Requirements

· Thomas Moore, Bindview

· T3— Auditing in a Windows Environment

· Nicholas Green, KPMG