On Tuesday 7th February 2023 CSP sponsored the ‘ISACA Northern England Chapter’ event in Leeds, that was so popular, it sold out! The event presented a diverse range of topics from excellent expert speakers. The event consisted of:
The history behind ISACA (Information Systems Audit and Control Association):
“ISACA has served our professional community for more than 50 years. The association was incorporated as the EDP Auditors Association in 1969 by a small group of individuals who recognized a need for a centralised source of information and guidance in the new field of electronic data processing audit. Today, ISACA serves 150,000 professionals in 188 countries, who span several roles in assurance, governance, risk and information security.”
Statement from the ISACA website, which can be found here.
About the event
An excellent lunch was provided by CSP, which was obviously enjoyed by the attendees, as there was hardly anything left afterwards!
The event started with an excellent talk by Martin Smith MBE, about his life in Security. As chair and founder of the Security Awareness Special Interest Group, he is passionate about making users aware of the risks and sharing knowledge and experience across the profession through events, webinars and masterclasses.
Further information on SASIG is available at The SASIG | Security Awareness Special Interest Group | Events
The second speaker was Will Priestly from Varonis who spoke about the need for regular reviews of access to cloud based resources. The proliferation of data held within the cloud and the different methods used, has highlighted the need for detailed and frequent analysis of exactly who has access to what data, and both the ease and risk of getting that configuration wrong.
The final session was a panel session, with Chris Bell CTO and Head of Security Architecture, Stuart Frost Head of Enterprise Security Risk Management at DWP and Mark Ainsley Head of Supply Chain Assurance at DWP, facilitated by Kevin Else, Consulting Director at CSP, which CSP have held before on the difference between Security Assurance and Security Compliance.
Each panelist provided their own views on the differences and challenges of compliance over assurance, which led to some interesting and thought-provoking discussions with the audience. One of the main takeaways from the discussion, was the difficulty most of the participants have in raising awareness of the risks raised by assurance activities to the C-suite. It highlighted the issues with terminology between the audit/assurance and senior management, rather than a lack of commitment by the heads of the company.
(Catering provided by Slips Deli on Cardigan Road, Leeds, thank you!)
Kevin Else, Consulting Director at CSP, said this after the meeting:
“The opportunity to share knowledge and experiences is a key part of helping companies address information security issues and CSP is always happy to support organisations like ISACA in facilitating the sharing of this knowledge. Only by working together can we address the cyber security concerns of companies in this ever-interconnected ecosystem.”
Chris Bell, CTO, commented:
“The final session was very informative for me, it’s the first ISACA event I have attended and the comments from the audience proved that even as a group of security professionals, we can’t agree on a common vocabulary, which definitely struck a chord. Whether we are communicating with the business, using perspective through a Risk lens, Compliance lens or Assurance lens, the onus is on security professionals to ensure their message is clear and understood. As a profession we have a good track record of developing programmes for technical development of our members. Perhaps we should apply increased focus to softer skills?”
If you want to read more about the difference between Security Assurance and Security Compliance, read our article here.
Pictured below: Mark Ainsley (Left) Stuart Frost (Middle) and Chris Bell (right).
