200 likes | 362 Views
Is IT Compliance A Profession? A Workshop on Refining Our Common Body of Knowledge, Skills and Ethics. Peter T. Davis Principal Peter Davis+Associates. The Need. Is compliance a profession or a job? Is there a need for a certification? Should the ITCi offer the certification?
E N D
Is IT Compliance A Profession? A Workshop on Refining Our Common Body of Knowledge, Skills and Ethics Peter T. Davis PrincipalPeter Davis+Associates
The Need • Is compliance a profession or a job? • Is there a need for a certification? • Should the ITCi offer the certification? • Or should they partner with someone else? IT COMPLIANCE CONFERENCE 2007 | Your Presentation Title Goes Here—To edit, go to View>Header and Footer
Professional Requirements • Professions require • Code of Ethics • Body of Knowledge • Testing on the body of knowledge • Regulation IT COMPLIANCE CONFERENCE 2007 | Your Presentation Title Goes Here—To edit, go to View>Header and Footer
Qualifications • Experience • Years • Disciplines • Exam • Code of Ethics • Sponsor • Grandfathering? IT COMPLIANCE CONFERENCE 2007 | Your Presentation Title Goes Here—To edit, go to View>Header and Footer
COMPBOK • What is included in the Body of Knowledge? • What will we call it? • Do you think people would respond to a survey on job specifications? • Should ITCi go for ANSI certification? IT COMPLIANCE CONFERENCE 2007 | Your Presentation Title Goes Here—To edit, go to View>Header and Footer
Suggested Table of Contents • Management principles • IT Governance • Laws and regulations • Records management • Ethics • Security • Privacy • Risk management • Control self-assessment • Investigations • Performance management IT COMPLIANCE CONFERENCE 2007 | Your Presentation Title Goes Here—To edit, go to View>Header and Footer
Management Principles • Processes and Business process mapping • Controls and testing • PlanOrganizeStaffDirectControl and PDCA/PDSA and DMAIC/DMADV • Organizational and committee structure • Marketing; influence without authority • Budgeting • Awareness and training • Policy framework IT COMPLIANCE CONFERENCE 2007 | Your Presentation Title Goes Here—To edit, go to View>Header and Footer
IT Governance • COBIT • ITIL • ISO 27000 • M_o_R • CRAMM • MSP • PMBOK • PRINCE2 • CMMI • Six Sigma IT COMPLIANCE CONFERENCE 2007 | Your Presentation Title Goes Here—To edit, go to View>Header and Footer
Laws and Regulations • Legal concepts, e.g., evidence, eDiscovery • Which ones? • SOX/Bill 198 • HIPAA • GLBA • PCI DSS • Privacy • Electronic evidence; e.g., FRCP IT COMPLIANCE CONFERENCE 2007 | Your Presentation Title Goes Here—To edit, go to View>Header and Footer
Records Management • Legal requirements • Guidelines • Record retention policy • Retention schedules • Enabling technologies IT COMPLIANCE CONFERENCE 2007 | Your Presentation Title Goes Here—To edit, go to View>Header and Footer
Ethics • “Tone at the Top” • Legal and regulatory requirements • Ethics topics • Ethical fallacies and dilemmas • Code of Conduct • Ethics plan IT COMPLIANCE CONFERENCE 2007 | Your Presentation Title Goes Here—To edit, go to View>Header and Footer
Security • CIA • Compliance tools IT COMPLIANCE CONFERENCE 2007 | Your Presentation Title Goes Here—To edit, go to View>Header and Footer
Privacy • Concepts • Privacy enhancing technologies, i.e., PET IT COMPLIANCE CONFERENCE 2007 | Your Presentation Title Goes Here—To edit, go to View>Header and Footer
Risk Management • Concepts • Definitions • Process • Quantitative vs. qualitative IT COMPLIANCE CONFERENCE 2007 | Your Presentation Title Goes Here—To edit, go to View>Header and Footer
Control Self-Assessment • Concepts • Techniques • Surveys IT COMPLIANCE CONFERENCE 2007 | Your Presentation Title Goes Here—To edit, go to View>Header and Footer
Investigations • Organization • Incident handling • Forensics • Reporting IT COMPLIANCE CONFERENCE 2007 | Your Presentation Title Goes Here—To edit, go to View>Header and Footer
Performance Management • Process • Definitions • Metrics • Reporting • Maturity model? IT COMPLIANCE CONFERENCE 2007 | Your Presentation Title Goes Here—To edit, go to View>Header and Footer
Solicitation • Would you like to help? IT COMPLIANCE CONFERENCE 2007 | Your Presentation Title Goes Here—To edit, go to View>Header and Footer
Questions and Answers IT COMPLIANCE CONFERENCE 2007 | Your Presentation Title Goes Here—To edit, go to View>Header and Footer
Contact Information Peter T. Davis, Principal Peter Davis+Associates ptdavis@pdaconsulting.com 416-907-4041 Please Complete Your Session Evaluation