<?xml version="1.0" encoding="UTF-8"?><!-- generator="podbean/5.5" -->
<rss version="2.0"
     xmlns:content="http://purl.org/rss/1.0/modules/content/"
     xmlns:wfw="http://wellformedweb.org/CommentAPI/"
     xmlns:dc="http://purl.org/dc/elements/1.1/"
     xmlns:atom="http://www.w3.org/2005/Atom"
     xmlns:itunes="http://www.itunes.com/dtds/podcast-1.0.dtd"
     xmlns:googleplay="http://www.google.com/schemas/play-podcasts/1.0"
     xmlns:spotify="http://www.spotify.com/ns/rss"
     xmlns:podcast="https://podcastindex.org/namespace/1.0"
    xmlns:media="http://search.yahoo.com/mrss/">

<channel>
    <title>ISACA Podcast</title>
    <atom:link href="https://feed.podbean.com/isacapodcast/feed.xml" rel="self" type="application/rss+xml"/>
    <link>https://isacapodcast.podbean.com</link>
    <description>The ISACA Podcast gives you insight into the latest regulations, trends and threats experienced by information systems auditors and governance and security professionals. Whether you are beginning your career or have decades of experience, the ISACA Podcast can help you be better equipped to address industry challenges and embrace opportunities.</description>
    <pubDate>Thu, 28 May 2026 05:00:00 +0000</pubDate>
    <generator>https://podbean.com/?v=5.5</generator>
    <language>en</language>
        <copyright>All rights reserved</copyright>
    <category>Technology</category>
    <ttl>1440</ttl>
    <itunes:type>episodic</itunes:type>
          <itunes:summary>The ISACA Podcast gives you insight into the latest regulations, trends and threats experienced by information systems auditors and governance and security professionals. The experts interviewed in the ISACA Podcast have valuable perspectives they have gained from their years of experience in the field. Whether you are beginning your career or have decades of experience, the ISACA Podcast can help you be better equipped to address industry challenges and embrace opportunities.</itunes:summary>
        <itunes:author>ISACA Podcast</itunes:author>
<itunes:category text="Technology" />
	<itunes:category text="News">
		<itunes:category text="Tech News" />
	</itunes:category>
<itunes:category text="Business" />
    <itunes:owner>
        <itunes:name>ISACA Podcast</itunes:name>
            </itunes:owner>
    	<itunes:block>No</itunes:block>
	<itunes:explicit>false</itunes:explicit>
    <itunes:image href="https://pbcdn1.podbean.com/imglogo/image-logo/6036265/ISACA_Podcast-cover-art_square.png" />
    <image>
        <url>https://pbcdn1.podbean.com/imglogo/image-logo/6036265/ISACA_Podcast-cover-art_square.png</url>
        <title>ISACA Podcast</title>
        <link>https://isacapodcast.podbean.com</link>
        <width>144</width>
        <height>144</height>
    </image>
    <item>
        <title>The Future of IT Audit: Key Changes in ITAF 5</title>
        <itunes:title>The Future of IT Audit: Key Changes in ITAF 5</itunes:title>
        <link>https://isacapodcast.podbean.com/e/the-future-of-it-audit-key-changes-in-itaf-5/</link>
                    <comments>https://isacapodcast.podbean.com/e/the-future-of-it-audit-key-changes-in-itaf-5/#comments</comments>        <pubDate>Thu, 28 May 2026 05:00:00 +0000</pubDate>
        <guid isPermaLink="false">isacapodcast.podbean.com/5ba88264-5340-3741-81d6-cd57d8a2fee5</guid>
                                    <description><![CDATA[<p>Technology is transforming how organizations operate — and IT audit and assurance must evolve alongside it. In this episode, Paul Phillips sits down with Mary Carmichael, contributor to the newly updated IT Audit and Assurance Framework (ITAF 5), to discuss how audit professionals can adapt to today’s increasingly complex digital enterprise.</p>
<p> </p>
<p>Together, they explore the major shifts shaping modern audit, including AI governance, digital ecosystems, automation, evolving risk landscapes, cloud environments, and the growing need for stronger data literacy within audit teams. Mary also shares practical guidance on how organizations can begin modernizing their audit approach without overhauling everything overnight.</p>
<p> </p>
<p>Key discussion topics include:</p>
<ul>
<li>The evolution from traditional control testing to outcome-based assurance</li>
<li>Why audit teams need stronger technology and data capabilities</li>
<li>AI governance, automation, and digital risk considerations</li>
<li>Building practical audit modernization strategies</li>
<li>How ITAF 5 supports governance, credibility, and audit relevance in modern enterprises</li>
</ul>
<p> </p>
<p>Whether you're an auditor, governance professional, cybersecurity leader, or risk practitioner, this conversation provides valuable insight into the future of audit and assurance in a technology-driven world.</p>
<p> </p>
<p>Related Resources &amp; Stay Connected</p>
<p>Download ITAF 5: <a href='https://www.isaca.org/resources/itaf-is-a-framework'>https://www.isaca.org/resources/itaf-is-a-framework</a></p>
<p> </p>
<p>Explore More ISACA Podcast Episodes: Dive deeper into cybersecurity, governance, risk, and emerging tech insights. <a href='https://www.isaca.org/resources/news-and-trends/isaca-podcast-library'>https://www.isaca.org/resources/news-and-trends/isaca-podcast-library</a></p>
<p> </p>
<p>▶️Subscribe to ISACA on YouTube: Stay ahead with expert interviews, industry analysis, and cybersecurity leadership insights. <a href='https://www.youtube.com/@IsacaHq'>https://www.youtube.com/@IsacaHq</a></p>
<p> </p>
<p>🔔 Don’t forget to like, comment, and subscribe for more conversations shaping the future of IT audit, governance, risk, and cybersecurity.</p>
<p> </p>
<p>#ITAudit #ITAF5 #AuditAndAssurance #Cybersecurity #Governance #RiskManagement #AI #ISACA #DigitalTransformation #InternalAudit</p>
]]></description>
                                                            <content:encoded><![CDATA[<p>Technology is transforming how organizations operate — and IT audit and assurance must evolve alongside it. In this episode, Paul Phillips sits down with Mary Carmichael, contributor to the newly updated IT Audit and Assurance Framework (ITAF 5), to discuss how audit professionals can adapt to today’s increasingly complex digital enterprise.</p>
<p> </p>
<p>Together, they explore the major shifts shaping modern audit, including AI governance, digital ecosystems, automation, evolving risk landscapes, cloud environments, and the growing need for stronger data literacy within audit teams. Mary also shares practical guidance on how organizations can begin modernizing their audit approach without overhauling everything overnight.</p>
<p> </p>
<p>Key discussion topics include:</p>
<ul>
<li>The evolution from traditional control testing to outcome-based assurance</li>
<li>Why audit teams need stronger technology and data capabilities</li>
<li>AI governance, automation, and digital risk considerations</li>
<li>Building practical audit modernization strategies</li>
<li>How ITAF 5 supports governance, credibility, and audit relevance in modern enterprises</li>
</ul>
<p> </p>
<p>Whether you're an auditor, governance professional, cybersecurity leader, or risk practitioner, this conversation provides valuable insight into the future of audit and assurance in a technology-driven world.</p>
<p> </p>
<p>Related Resources &amp; Stay Connected</p>
<p>Download ITAF 5: <a href='https://www.isaca.org/resources/itaf-is-a-framework'>https://www.isaca.org/resources/itaf-is-a-framework</a></p>
<p> </p>
<p>Explore More ISACA Podcast Episodes: Dive deeper into cybersecurity, governance, risk, and emerging tech insights. <a href='https://www.isaca.org/resources/news-and-trends/isaca-podcast-library'>https://www.isaca.org/resources/news-and-trends/isaca-podcast-library</a></p>
<p> </p>
<p>▶️Subscribe to ISACA on YouTube: Stay ahead with expert interviews, industry analysis, and cybersecurity leadership insights. <a href='https://www.youtube.com/@IsacaHq'>https://www.youtube.com/@IsacaHq</a></p>
<p> </p>
<p>🔔 Don’t forget to like, comment, and subscribe for more conversations shaping the future of IT audit, governance, risk, and cybersecurity.</p>
<p> </p>
<p>#ITAudit #ITAF5 #AuditAndAssurance #Cybersecurity #Governance #RiskManagement #AI #ISACA #DigitalTransformation #InternalAudit</p>
]]></content:encoded>
                                    
        <enclosure url="https://mcdn.podbean.com/mf/web/vfaqgg539n2fxcv6/26_031_ISACA_Podcast_ITAF_-_Mary_Carmichael_D180t5b.mp3" length="28842155" type="audio/mpeg"/>
        <itunes:summary><![CDATA[Technology is transforming how organizations operate — and IT audit and assurance must evolve alongside it. In this episode, Paul Phillips sits down with Mary Carmichael, contributor to the newly updated IT Audit and Assurance Framework (ITAF 5), to discuss how audit professionals can adapt to today’s increasingly complex digital enterprise.
 
Together, they explore the major shifts shaping modern audit, including AI governance, digital ecosystems, automation, evolving risk landscapes, cloud environments, and the growing need for stronger data literacy within audit teams. Mary also shares practical guidance on how organizations can begin modernizing their audit approach without overhauling everything overnight.
 
Key discussion topics include:

The evolution from traditional control testing to outcome-based assurance
Why audit teams need stronger technology and data capabilities
AI governance, automation, and digital risk considerations
Building practical audit modernization strategies
How ITAF 5 supports governance, credibility, and audit relevance in modern enterprises

 
Whether you're an auditor, governance professional, cybersecurity leader, or risk practitioner, this conversation provides valuable insight into the future of audit and assurance in a technology-driven world.
 
Related Resources &amp; Stay Connected
Download ITAF 5: https://www.isaca.org/resources/itaf-is-a-framework
 
Explore More ISACA Podcast Episodes: Dive deeper into cybersecurity, governance, risk, and emerging tech insights. https://www.isaca.org/resources/news-and-trends/isaca-podcast-library
 
▶️Subscribe to ISACA on YouTube: Stay ahead with expert interviews, industry analysis, and cybersecurity leadership insights. https://www.youtube.com/@IsacaHq
 
🔔 Don’t forget to like, comment, and subscribe for more conversations shaping the future of IT audit, governance, risk, and cybersecurity.
 
#ITAudit #ITAF5 #AuditAndAssurance #Cybersecurity #Governance #RiskManagement #AI #ISACA #DigitalTransformation #InternalAudit]]></itunes:summary>
        <itunes:author>ISACA Podcast</itunes:author>
        <itunes:explicit>false</itunes:explicit>
        <itunes:block>No</itunes:block>
        <itunes:duration>1792</itunes:duration>
                <itunes:episode>319</itunes:episode>
        <itunes:episodeType>full</itunes:episodeType>
            </item>
    <item>
        <title>​​Breaking the Compliance Mentality​</title>
        <itunes:title>​​Breaking the Compliance Mentality​</itunes:title>
        <link>https://isacapodcast.podbean.com/e/%e2%80%8b%e2%80%8bbreaking-the-compliance-mentality%e2%80%8b/</link>
                    <comments>https://isacapodcast.podbean.com/e/%e2%80%8b%e2%80%8bbreaking-the-compliance-mentality%e2%80%8b/#comments</comments>        <pubDate>Thu, 21 May 2026 05:00:00 +0000</pubDate>
        <guid isPermaLink="false">isacapodcast.podbean.com/1b8d2455-3237-33b5-8cee-c39f77758729</guid>
                                    <description><![CDATA[<p>In today’s evolving cybersecurity landscape, strong leadership is the foundation of an effective security posture. Yet many agencies struggle when a “compliance mentality” takes hold, where meeting minimum requirements overshadows proactive risk management.</p>
<p>In this ISACA Podcast episode, Lisa Cook, ISACA's Principal Research Analyst, sits down with Patrick Bevill, Chief Information Security Officer (CISO) at the Federal Retirement Thrift Investment Board, to explore how agency leaders can establish a strong tone at the top and foster a culture that prioritizes security resilience over check-the-box compliance.​</p>
<p>Related Resources &amp; Stay Connected </p>
<p>Learn more about Williams Adley: Discover how Williams Adley helps organizations navigate audit, assurance, cybersecurity, risk, and advisory services with a focus on integrity and innovation. <a href='https://www.williamsadley.com/'>https://www.williamsadley.com/</a></p>
<p>Explore More ISACA Podcast Episodes: Dive deeper into cybersecurity, governance, risk, and emerging tech insights. <a href='https://www.isaca.org/resources/news-and-trends/isaca-podcast-library'>https://www.isaca.org/resources/news-and-trends/isaca-podcast-library</a> </p>
<p>Subscribe to ISACA on YouTube: Stay ahead with expert interviews, industry analysis, and cybersecurity leadership insights. <a href='https://www.youtube.com/@IsacaHq'>https://www.youtube.com/@IsacaHq</a> </p>
<p> </p>
<p>Don’t forget to like, comment, and subscribe for more conversations shaping the future of IT and cybersecurity.</p>
]]></description>
                                                            <content:encoded><![CDATA[<p>In today’s evolving cybersecurity landscape, strong leadership is the foundation of an effective security posture. Yet many agencies struggle when a “compliance mentality” takes hold, where meeting minimum requirements overshadows proactive risk management.</p>
<p>In this ISACA Podcast episode, Lisa Cook, ISACA's Principal Research Analyst, sits down with Patrick Bevill, Chief Information Security Officer (CISO) at the Federal Retirement Thrift Investment Board, to explore how agency leaders can establish a strong tone at the top and foster a culture that prioritizes security resilience over check-the-box compliance.​</p>
<p>Related Resources &amp; Stay Connected </p>
<p>Learn more about Williams Adley: Discover how Williams Adley helps organizations navigate audit, assurance, cybersecurity, risk, and advisory services with a focus on integrity and innovation. <a href='https://www.williamsadley.com/'>https://www.williamsadley.com/</a></p>
<p>Explore More ISACA Podcast Episodes: Dive deeper into cybersecurity, governance, risk, and emerging tech insights. <a href='https://www.isaca.org/resources/news-and-trends/isaca-podcast-library'>https://www.isaca.org/resources/news-and-trends/isaca-podcast-library</a> </p>
<p>Subscribe to ISACA on YouTube: Stay ahead with expert interviews, industry analysis, and cybersecurity leadership insights. <a href='https://www.youtube.com/@IsacaHq'>https://www.youtube.com/@IsacaHq</a> </p>
<p> </p>
<p>Don’t forget to like, comment, and subscribe for more conversations shaping the future of IT and cybersecurity.</p>
]]></content:encoded>
                                    
        <enclosure url="https://mcdn.podbean.com/mf/web/k6gjjqst2bwtmpz7/26_014_ISACA_Podcast_-_Sponsored_by_Williams_Adley_D1b48c6.mp3" length="22989945" type="audio/mpeg"/>
        <itunes:summary><![CDATA[In today’s evolving cybersecurity landscape, strong leadership is the foundation of an effective security posture. Yet many agencies struggle when a “compliance mentality” takes hold, where meeting minimum requirements overshadows proactive risk management.
In this ISACA Podcast episode, Lisa Cook, ISACA's Principal Research Analyst, sits down with Patrick Bevill, Chief Information Security Officer (CISO) at the Federal Retirement Thrift Investment Board, to explore how agency leaders can establish a strong tone at the top and foster a culture that prioritizes security resilience over check-the-box compliance.​
Related Resources &amp; Stay Connected 
Learn more about Williams Adley: Discover how Williams Adley helps organizations navigate audit, assurance, cybersecurity, risk, and advisory services with a focus on integrity and innovation. https://www.williamsadley.com/
Explore More ISACA Podcast Episodes: Dive deeper into cybersecurity, governance, risk, and emerging tech insights. https://www.isaca.org/resources/news-and-trends/isaca-podcast-library 
Subscribe to ISACA on YouTube: Stay ahead with expert interviews, industry analysis, and cybersecurity leadership insights. https://www.youtube.com/@IsacaHq 
 
Don’t forget to like, comment, and subscribe for more conversations shaping the future of IT and cybersecurity.]]></itunes:summary>
        <itunes:author>ISACA Podcast</itunes:author>
        <itunes:explicit>false</itunes:explicit>
        <itunes:block>No</itunes:block>
        <itunes:duration>1426</itunes:duration>
                <itunes:episode>318</itunes:episode>
        <itunes:episodeType>full</itunes:episodeType>
            </item>
    <item>
        <title>Audit-Ready by Design: How AI Powers Smarter Identity Security</title>
        <itunes:title>Audit-Ready by Design: How AI Powers Smarter Identity Security</itunes:title>
        <link>https://isacapodcast.podbean.com/e/audit-ready-by-design-how-ai-powers-smarter-identity-security/</link>
                    <comments>https://isacapodcast.podbean.com/e/audit-ready-by-design-how-ai-powers-smarter-identity-security/#comments</comments>        <pubDate>Tue, 19 May 2026 05:00:00 +0000</pubDate>
        <guid isPermaLink="false">isacapodcast.podbean.com/dca5817c-c246-3c4b-a5a9-81e50a2a58c8</guid>
                                    <description><![CDATA[<p>Compliance does not have to be a stressful, last-minute scramble. In this episode, we explore how AI-driven control and automation transforms identity security from a costly headache into an audit-ready powerhouse. We break down the steps to simplify your regulatory processes, reduce operational costs, and enhance security by effectively managing human and non-human identities.</p>
<p>You will learn why gaining centralized visibility is your crucial first step, how to instantly spot and remediate risky orphan accounts, and the secret to running seamless, automated access certifications. Join our identity security experts as they share practical strategies to strengthen your defenses without draining your IT resources. Expect actionable tips that will help you build a sustainable, AI-powered compliance process tailored to your organization.</p>
<p class="isSelectedEnd">Related Resources &amp; Stay Connected</p>
<ul>
<li class="isSelectedEnd">Learn more about SailPoint:
Explore how SailPoint is helping organizations modernize identity security, strengthen governance, and simplify compliance in an AI-driven world.
<a href='https://www.sailpoint.com/'>https://www.sailpoint.com/</a></li>
<li class="isSelectedEnd">Explore More ISACA Podcast Episodes:
Dive deeper into cybersecurity, governance, risk, and emerging tech insights.
<a href='https://www.isaca.org/resources/news-and-trends/isaca-podcast-library'>https://www.isaca.org/resources/news-and-trends/isaca-podcast-library</a></li>
<li class="isSelectedEnd">Subscribe to ISACA on YouTube:
Stay ahead with expert interviews, industry analysis, and cybersecurity leadership insights.
<a href='https://www.youtube.com/@IsacaHq'>https://www.youtube.com/@IsacaHq</a></li>
</ul>
<p>Don’t forget to like, comment, and subscribe for more conversations shaping the future of IT and cybersecurity.</p>
]]></description>
                                                            <content:encoded><![CDATA[<p>Compliance does not have to be a stressful, last-minute scramble. In this episode, we explore how AI-driven control and automation transforms identity security from a costly headache into an audit-ready powerhouse. We break down the steps to simplify your regulatory processes, reduce operational costs, and enhance security by effectively managing human and non-human identities.</p>
<p>You will learn why gaining centralized visibility is your crucial first step, how to instantly spot and remediate risky orphan accounts, and the secret to running seamless, automated access certifications. Join our identity security experts as they share practical strategies to strengthen your defenses without draining your IT resources. Expect actionable tips that will help you build a sustainable, AI-powered compliance process tailored to your organization.</p>
<p class="isSelectedEnd">Related Resources &amp; Stay Connected</p>
<ul>
<li class="isSelectedEnd">Learn more about SailPoint:<br>
Explore how SailPoint is helping organizations modernize identity security, strengthen governance, and simplify compliance in an AI-driven world.<br>
<a href='https://www.sailpoint.com/'>https://www.sailpoint.com/</a></li>
<li class="isSelectedEnd">Explore More ISACA Podcast Episodes:<br>
Dive deeper into cybersecurity, governance, risk, and emerging tech insights.<br>
<a href='https://www.isaca.org/resources/news-and-trends/isaca-podcast-library'>https://www.isaca.org/resources/news-and-trends/isaca-podcast-library</a></li>
<li class="isSelectedEnd">Subscribe to ISACA on YouTube:<br>
Stay ahead with expert interviews, industry analysis, and cybersecurity leadership insights.<br>
<a href='https://www.youtube.com/@IsacaHq'>https://www.youtube.com/@IsacaHq</a></li>
</ul>
<p>Don’t forget to like, comment, and subscribe for more conversations shaping the future of IT and cybersecurity.</p>
]]></content:encoded>
                                    
        <enclosure url="https://mcdn.podbean.com/mf/web/kc538zvh4bikng4k/26_029_ISACA_Podcast_-_SailPoint_Sponsor_D2_WITH_AD9m87c.mp3" length="24999349" type="audio/mpeg"/>
        <itunes:summary><![CDATA[Compliance does not have to be a stressful, last-minute scramble. In this episode, we explore how AI-driven control and automation transforms identity security from a costly headache into an audit-ready powerhouse. We break down the steps to simplify your regulatory processes, reduce operational costs, and enhance security by effectively managing human and non-human identities.
You will learn why gaining centralized visibility is your crucial first step, how to instantly spot and remediate risky orphan accounts, and the secret to running seamless, automated access certifications. Join our identity security experts as they share practical strategies to strengthen your defenses without draining your IT resources. Expect actionable tips that will help you build a sustainable, AI-powered compliance process tailored to your organization.
Related Resources &amp; Stay Connected

Learn more about SailPoint:Explore how SailPoint is helping organizations modernize identity security, strengthen governance, and simplify compliance in an AI-driven world.https://www.sailpoint.com/
Explore More ISACA Podcast Episodes:Dive deeper into cybersecurity, governance, risk, and emerging tech insights.https://www.isaca.org/resources/news-and-trends/isaca-podcast-library
Subscribe to ISACA on YouTube:Stay ahead with expert interviews, industry analysis, and cybersecurity leadership insights.https://www.youtube.com/@IsacaHq

Don’t forget to like, comment, and subscribe for more conversations shaping the future of IT and cybersecurity.]]></itunes:summary>
        <itunes:author>ISACA Podcast</itunes:author>
        <itunes:explicit>false</itunes:explicit>
        <itunes:block>No</itunes:block>
        <itunes:duration>1551</itunes:duration>
                <itunes:episode>317</itunes:episode>
        <itunes:episodeType>full</itunes:episodeType>
            </item>
    <item>
        <title>SheLeadsTech Fireside Chat: Celebrating Women in Cybersecurity</title>
        <itunes:title>SheLeadsTech Fireside Chat: Celebrating Women in Cybersecurity</itunes:title>
        <link>https://isacapodcast.podbean.com/e/sheleadstech-fireside-chat-celebrating-women-in-cybersecurity/</link>
                    <comments>https://isacapodcast.podbean.com/e/sheleadstech-fireside-chat-celebrating-women-in-cybersecurity/#comments</comments>        <pubDate>Wed, 04 Mar 2026 13:30:58 +0000</pubDate>
        <guid isPermaLink="false">isacapodcast.podbean.com/dfaa66f8-51b9-3660-8811-363074875e62</guid>
                                    <description><![CDATA[<p>Women in cybersecurity leaders share their stories and career advice in this SheLeadsTech fireside chat celebrating International Women’s Day.</p>
<p>In celebration of International Women’s Day and Women’s History Month, ISACA’s SheLeadsTech initiative brings together three inspiring leaders in cybersecurity for a special fireside conversation.</p>
<p>Join Debbie Lew and Jo Stewart-Rattray, both ISACA Hall of Fame inductees and recipients of the Eugene Frank Founders Award, as they sit down with Gail Coury, who will be inducted into the ISACA Hall of Fame in 2026.</p>
<p>In this warm and engaging discussion, they reflect on their journeys into cybersecurity, the evolving role of women in technology, and the power of mentorship, leadership, and community in shaping the future of the profession.</p>
<p>In this episode, they discuss:
• Their personal paths into cybersecurity and IT
• How opportunities for women in tech have evolved over time
• Lessons learned from leadership and service within the ISACA community
• Advice for the next generation of women entering the field</p>
<p>The conversation wraps up with a fun rapid-fire round that offers a glimpse into the personalities behind these accomplished careers.</p>
<p>Whether you're an experienced professional or just beginning your journey in technology, this fireside chat offers inspiration, insight, and encouragement from women helping shape the future of cybersecurity.</p>

<p>🔗 Learn more about ISACA’s SheLeadsTech initiative:
<a href='https://www.isaca.org/membership/sheleadstech'>https://www.isaca.org/membership/sheleadstech</a></p>
<p>🎧 Explore more ISACA Podcasts:
<a href='https://www.isaca.org/resources/news-and-trends/isaca-podcast-library'>https://www.isaca.org/resources/news-and-trends/isaca-podcast-library</a></p>
<p>📺 Subscribe to ISACA on YouTube:
<a class="decorated-link cursor-pointer">https://www.youtube.com/@IsacaHq</a></p>

<p>#WomenInCybersecurity
#SheLeadsTech
#WomenInTech</p>
]]></description>
                                                            <content:encoded><![CDATA[<p>Women in cybersecurity leaders share their stories and career advice in this SheLeadsTech fireside chat celebrating International Women’s Day.</p>
<p>In celebration of International Women’s Day and Women’s History Month, ISACA’s SheLeadsTech initiative brings together three inspiring leaders in cybersecurity for a special fireside conversation.</p>
<p>Join Debbie Lew and Jo Stewart-Rattray, both ISACA Hall of Fame inductees and recipients of the Eugene Frank Founders Award, as they sit down with Gail Coury, who will be inducted into the ISACA Hall of Fame in 2026.</p>
<p>In this warm and engaging discussion, they reflect on their journeys into cybersecurity, the evolving role of women in technology, and the power of mentorship, leadership, and community in shaping the future of the profession.</p>
<p>In this episode, they discuss:<br>
• Their personal paths into cybersecurity and IT<br>
• How opportunities for women in tech have evolved over time<br>
• Lessons learned from leadership and service within the ISACA community<br>
• Advice for the next generation of women entering the field</p>
<p>The conversation wraps up with a fun rapid-fire round that offers a glimpse into the personalities behind these accomplished careers.</p>
<p>Whether you're an experienced professional or just beginning your journey in technology, this fireside chat offers inspiration, insight, and encouragement from women helping shape the future of cybersecurity.</p>

<p>🔗 Learn more about ISACA’s SheLeadsTech initiative:<br>
<a href='https://www.isaca.org/membership/sheleadstech'>https://www.isaca.org/membership/sheleadstech</a></p>
<p>🎧 Explore more ISACA Podcasts:<br>
<a href='https://www.isaca.org/resources/news-and-trends/isaca-podcast-library'>https://www.isaca.org/resources/news-and-trends/isaca-podcast-library</a></p>
<p>📺 Subscribe to ISACA on YouTube:<br>
<a class="decorated-link cursor-pointer">https://www.youtube.com/@IsacaHq</a></p>

<p>#WomenInCybersecurity<br>
#SheLeadsTech<br>
#WomenInTech</p>
]]></content:encoded>
                                    
        <enclosure url="https://mcdn.podbean.com/mf/web/czhh5jh9pry6zypi/25_089_FiresideChat_SLT_D27jwxm.mp3" length="74059644" type="audio/mpeg"/>
        <itunes:summary><![CDATA[Women in cybersecurity leaders share their stories and career advice in this SheLeadsTech fireside chat celebrating International Women’s Day.
In celebration of International Women’s Day and Women’s History Month, ISACA’s SheLeadsTech initiative brings together three inspiring leaders in cybersecurity for a special fireside conversation.
Join Debbie Lew and Jo Stewart-Rattray, both ISACA Hall of Fame inductees and recipients of the Eugene Frank Founders Award, as they sit down with Gail Coury, who will be inducted into the ISACA Hall of Fame in 2026.
In this warm and engaging discussion, they reflect on their journeys into cybersecurity, the evolving role of women in technology, and the power of mentorship, leadership, and community in shaping the future of the profession.
In this episode, they discuss:• Their personal paths into cybersecurity and IT• How opportunities for women in tech have evolved over time• Lessons learned from leadership and service within the ISACA community• Advice for the next generation of women entering the field
The conversation wraps up with a fun rapid-fire round that offers a glimpse into the personalities behind these accomplished careers.
Whether you're an experienced professional or just beginning your journey in technology, this fireside chat offers inspiration, insight, and encouragement from women helping shape the future of cybersecurity.

🔗 Learn more about ISACA’s SheLeadsTech initiative:https://www.isaca.org/membership/sheleadstech
🎧 Explore more ISACA Podcasts:https://www.isaca.org/resources/news-and-trends/isaca-podcast-library
📺 Subscribe to ISACA on YouTube:https://www.youtube.com/@IsacaHq

#WomenInCybersecurity#SheLeadsTech#WomenInTech]]></itunes:summary>
        <itunes:author>ISACA Podcast</itunes:author>
        <itunes:explicit>false</itunes:explicit>
        <itunes:block>No</itunes:block>
        <itunes:duration>3065</itunes:duration>
                <itunes:episode>316</itunes:episode>
        <itunes:episodeType>full</itunes:episodeType>
            </item>
    <item>
        <title>Humans Are IT Security’s Weakest Link</title>
        <itunes:title>Humans Are IT Security’s Weakest Link</itunes:title>
        <link>https://isacapodcast.podbean.com/e/trxcvx/</link>
                    <comments>https://isacapodcast.podbean.com/e/trxcvx/#comments</comments>        <pubDate>Tue, 03 Mar 2026 05:00:00 +0000</pubDate>
        <guid isPermaLink="false">isacapodcast.podbean.com/5a52cafb-514e-3bad-aef1-7fe50ae3fce9</guid>
                                    <description><![CDATA[On this episode of the ISACA Podcast, host Chris McGowan is joined by Amit Patel, Senior Vice President at Consulting Solutions, to explore one of the most underestimated threats in cybersecurity: the human element. From accidental errors to insider breaches, they discuss why employee behavior is at the heart of most security incidents—and what organizations can do about it.
 
Amit shares insights on how ongoing training, strong policies, and AI-powered tools like behavior analytics can help bridge the gap between tech and human responsibility. Whether you're a cybersecurity leader or simply navigating today’s digital landscape, this episode offers practical strategies to strengthen your organization’s human-centric security posture.


📚 Related Resources &amp; Stay Connected
<p>📖 Read the full article:
Humans Are IT Security’s Weakest Link
<a href='https://www.isaca.org/resources/news-and-trends/industry-news/2024/humans-are-it-securitys-weakest-link'>https://www.isaca.org/resources/news-and-trends/industry-news/2024/humans-are-it-securitys-weakest-link</a></p>
<p>🎙 Explore More ISACA Podcast Episodes:
Dive deeper into cybersecurity, governance, risk, and emerging tech insights.
<a href='https://www.isaca.org/resources/news-and-trends/isaca-podcast-library'>https://www.isaca.org/resources/news-and-trends/isaca-podcast-library</a></p>
<p>▶️ Subscribe to ISACA on YouTube:
Stay ahead with expert interviews, industry analysis, and cybersecurity leadership insights.
<a href='https://www.youtube.com/@IsacaHq'>https://www.youtube.com/@IsacaHq</a></p>
<p>🔔 Don’t forget to like, comment, and subscribe for more conversations shaping the future of IT and cybersecurity.</p>
]]></description>
                                                            <content:encoded><![CDATA[On this episode of the ISACA Podcast, host Chris McGowan is joined by Amit Patel, Senior Vice President at Consulting Solutions, to explore one of the most underestimated threats in cybersecurity: the human element. From accidental errors to insider breaches, they discuss why employee behavior is at the heart of most security incidents—and what organizations can do about it.
 
Amit shares insights on how ongoing training, strong policies, and AI-powered tools like behavior analytics can help bridge the gap between tech and human responsibility. Whether you're a cybersecurity leader or simply navigating today’s digital landscape, this episode offers practical strategies to strengthen your organization’s human-centric security posture.<br>
<br>

📚 Related Resources &amp; Stay Connected
<p>📖 Read the full article:<br>
Humans Are IT Security’s Weakest Link<br>
<a href='https://www.isaca.org/resources/news-and-trends/industry-news/2024/humans-are-it-securitys-weakest-link'>https://www.isaca.org/resources/news-and-trends/industry-news/2024/humans-are-it-securitys-weakest-link</a></p>
<p>🎙 Explore More ISACA Podcast Episodes:<br>
Dive deeper into cybersecurity, governance, risk, and emerging tech insights.<br>
<a href='https://www.isaca.org/resources/news-and-trends/isaca-podcast-library'>https://www.isaca.org/resources/news-and-trends/isaca-podcast-library</a></p>
<p>▶️ Subscribe to ISACA on YouTube:<br>
Stay ahead with expert interviews, industry analysis, and cybersecurity leadership insights.<br>
<a href='https://www.youtube.com/@IsacaHq'>https://www.youtube.com/@IsacaHq</a></p>
<p>🔔 Don’t forget to like, comment, and subscribe for more conversations shaping the future of IT and cybersecurity.</p>
]]></content:encoded>
                                    
        <enclosure url="https://mcdn.podbean.com/mf/web/c2ghwyeprxa9pcn6/ISACA_Podcast_Amit_Patel6wdki.mp3" length="48011713" type="audio/mpeg"/>
        <itunes:summary><![CDATA[On this episode of the ISACA Podcast, host Chris McGowan is joined by Amit Patel, Senior Vice President at Consulting Solutions, to explore one of the most underestimated threats in cybersecurity: the human element. From accidental errors to insider breaches, they discuss why employee behavior is at the heart of most security incidents—and what organizations can do about it.
 
Amit shares insights on how ongoing training, strong policies, and AI-powered tools like behavior analytics can help bridge the gap between tech and human responsibility. Whether you're a cybersecurity leader or simply navigating today’s digital landscape, this episode offers practical strategies to strengthen your organization’s human-centric security posture.
📚 Related Resources &amp; Stay Connected
📖 Read the full article:Humans Are IT Security’s Weakest Linkhttps://www.isaca.org/resources/news-and-trends/industry-news/2024/humans-are-it-securitys-weakest-link
🎙 Explore More ISACA Podcast Episodes:Dive deeper into cybersecurity, governance, risk, and emerging tech insights.https://www.isaca.org/resources/news-and-trends/isaca-podcast-library
▶️ Subscribe to ISACA on YouTube:Stay ahead with expert interviews, industry analysis, and cybersecurity leadership insights.https://www.youtube.com/@IsacaHq
🔔 Don’t forget to like, comment, and subscribe for more conversations shaping the future of IT and cybersecurity.
]]></itunes:summary>
        <itunes:author>ISACA Podcast</itunes:author>
        <itunes:explicit>false</itunes:explicit>
        <itunes:block>No</itunes:block>
        <itunes:duration>2997</itunes:duration>
                <itunes:episode>315</itunes:episode>
        <itunes:episodeType>full</itunes:episodeType>
            </item>
    <item>
        <title>Secure Your Privacy:  A security and privacy podcast: real conversations, real consequences, real solutions?</title>
        <itunes:title>Secure Your Privacy:  A security and privacy podcast: real conversations, real consequences, real solutions?</itunes:title>
        <link>https://isacapodcast.podbean.com/e/secure-your-privates-a-security-and-privacy-podcast-real-conversations-real-consequences-real-solutions/</link>
                    <comments>https://isacapodcast.podbean.com/e/secure-your-privates-a-security-and-privacy-podcast-real-conversations-real-consequences-real-solutions/#comments</comments>        <pubDate>Thu, 19 Feb 2026 05:00:00 +0000</pubDate>
        <guid isPermaLink="false">isacapodcast.podbean.com/43c49e1e-35d1-306c-9fcd-9091cde65ea0</guid>
                                    <description><![CDATA[<p>You’re listening to Secure Your Privates™ brought to you by ISACA Podcasts - where security meets privacy, risk meets reality, and governance finally makes sense. We’re here to cut through the noise and get real about what’s actually happening in cyber. The no-BS podcast on security and privacy. We talk about what’s broken, what’s working, and what nobody’s telling you in between.</p>
]]></description>
                                                            <content:encoded><![CDATA[<p>You’re listening to Secure Your Privates™ brought to you by ISACA Podcasts - where security meets privacy, risk meets reality, and governance finally makes sense. We’re here to cut through the noise and get real about what’s actually happening in cyber. The no-BS podcast on security and privacy. We talk about what’s broken, what’s working, and what nobody’s telling you in between.</p>
]]></content:encoded>
                                    
        <enclosure url="https://mcdn.podbean.com/mf/web/t66qeuaeuijybxh5/26_012_Podcast_-_Ep_1_-_Lisa_Ray_D27026c.mp3" length="107851316" type="audio/mpeg"/>
        <itunes:summary><![CDATA[You’re listening to Secure Your Privates™ brought to you by ISACA Podcasts - where security meets privacy, risk meets reality, and governance finally makes sense. We’re here to cut through the noise and get real about what’s actually happening in cyber. The no-BS podcast on security and privacy. We talk about what’s broken, what’s working, and what nobody’s telling you in between.]]></itunes:summary>
        <itunes:author>ISACA Podcast</itunes:author>
        <itunes:explicit>false</itunes:explicit>
        <itunes:block>No</itunes:block>
        <itunes:duration>4487</itunes:duration>
                <itunes:episode>314</itunes:episode>
        <itunes:episodeType>full</itunes:episodeType>
            </item>
    <item>
        <title>Securing Data in the Age of AI with DSPM: Lessons from a High-Impact ISACA Webinar</title>
        <itunes:title>Securing Data in the Age of AI with DSPM: Lessons from a High-Impact ISACA Webinar</itunes:title>
        <link>https://isacapodcast.podbean.com/e/securing-data-in-the-age-of-ai-with-dspm-lessons-from-a-high-impact-isaca-webinar/</link>
                    <comments>https://isacapodcast.podbean.com/e/securing-data-in-the-age-of-ai-with-dspm-lessons-from-a-high-impact-isaca-webinar/#comments</comments>        <pubDate>Thu, 12 Feb 2026 06:00:00 +0000</pubDate>
        <guid isPermaLink="false">isacapodcast.podbean.com/35fdb0f5-7c0f-32ca-ab12-9105318d25bb</guid>
                                    <description><![CDATA[<p>In this ISACA Podcast episode, host Safia Kazi, Principal Research Analyst – Privacy, is joined by Dirk Schrader, VP of Security Research at Netwrix, to discuss how generative AI is revealing long-standing gaps in enterprise data security and governance.</p>
<p>This episode builds on insights from a recent ISACA webinar that explored how generative AI is exposing weaknesses in enterprise data security and governance. The discussion examines why many organizations lack visibility into where sensitive data resides and who can access it, particularly across hybrid and cloud environments. The conversation also addresses emerging risks introduced by AI tools, including non-human access and overexposed data. Listeners will gain practical, governance-focused guidance on how DSPM helps organizations assess risk, support compliance, and prepare data responsibly for AI initiatives.</p>
<p>Related Resources:</p>
<ul>
<li>
<p>Watch the ISACA Webinar from the ISACA Virtual Summit 2025: “Securing Data in the Age of AI with DSPM”
<a href='https://www.isaca.org/training-and-events/online-training/virtual-summits/ai-governance-strategies'>https://www.isaca.org/training-and-events/online-training/virtual-summits/ai-governance-strategies</a></p>
</li>
<li>
<p>Learn more from Netwrix:
<a href='https://netwrix.com/en/resources/'>https://netwrix.com/en/resources/</a></p>
</li>
<li>
<p>Explore more ISACA Podcasts:
<a href='https://www.isaca.org/resources/news-and-trends/isaca-podcast-library'>https://www.isaca.org/resources/news-and-trends/isaca-podcast-library</a></p>
</li>
<li>
<p>ISACA on YouTube:
<a href='https://www.youtube.com/@IsacaHq'>https://www.youtube.com/@IsacaHq</a></p>
</li>
</ul>
]]></description>
                                                            <content:encoded><![CDATA[<p>In this ISACA Podcast episode, host Safia Kazi, Principal Research Analyst – Privacy, is joined by Dirk Schrader, VP of Security Research at Netwrix, to discuss how generative AI is revealing long-standing gaps in enterprise data security and governance.</p>
<p>This episode builds on insights from a recent ISACA webinar that explored how generative AI is exposing weaknesses in enterprise data security and governance. The discussion examines why many organizations lack visibility into where sensitive data resides and who can access it, particularly across hybrid and cloud environments. The conversation also addresses emerging risks introduced by AI tools, including non-human access and overexposed data. Listeners will gain practical, governance-focused guidance on how DSPM helps organizations assess risk, support compliance, and prepare data responsibly for AI initiatives.</p>
<p>Related Resources:</p>
<ul>
<li>
<p>Watch the ISACA Webinar from the ISACA Virtual Summit 2025: <em>“Securing Data in the Age of AI with DSPM”</em><br>
<a href='https://www.isaca.org/training-and-events/online-training/virtual-summits/ai-governance-strategies'>https://www.isaca.org/training-and-events/online-training/virtual-summits/ai-governance-strategies</a></p>
</li>
<li>
<p>Learn more from Netwrix:<br>
<a href='https://netwrix.com/en/resources/'>https://netwrix.com/en/resources/</a></p>
</li>
<li>
<p>Explore more ISACA Podcasts:<br>
<a href='https://www.isaca.org/resources/news-and-trends/isaca-podcast-library'>https://www.isaca.org/resources/news-and-trends/isaca-podcast-library</a></p>
</li>
<li>
<p>ISACA on YouTube:<br>
<a href='https://www.youtube.com/@IsacaHq'>https://www.youtube.com/@IsacaHq</a></p>
</li>
</ul>
]]></content:encoded>
                                    
        <enclosure url="https://mcdn.podbean.com/mf/web/cn2pxkrqxqsi7388/26_005_ISACA_Podcast_-_Dirk_Schrader_-_Netwrix_D1asrfp.mp3" length="37469517" type="audio/mpeg"/>
        <itunes:summary><![CDATA[In this ISACA Podcast episode, host Safia Kazi, Principal Research Analyst – Privacy, is joined by Dirk Schrader, VP of Security Research at Netwrix, to discuss how generative AI is revealing long-standing gaps in enterprise data security and governance.
This episode builds on insights from a recent ISACA webinar that explored how generative AI is exposing weaknesses in enterprise data security and governance. The discussion examines why many organizations lack visibility into where sensitive data resides and who can access it, particularly across hybrid and cloud environments. The conversation also addresses emerging risks introduced by AI tools, including non-human access and overexposed data. Listeners will gain practical, governance-focused guidance on how DSPM helps organizations assess risk, support compliance, and prepare data responsibly for AI initiatives.
Related Resources:


Watch the ISACA Webinar from the ISACA Virtual Summit 2025: “Securing Data in the Age of AI with DSPM”https://www.isaca.org/training-and-events/online-training/virtual-summits/ai-governance-strategies


Learn more from Netwrix:https://netwrix.com/en/resources/


Explore more ISACA Podcasts:https://www.isaca.org/resources/news-and-trends/isaca-podcast-library


ISACA on YouTube:https://www.youtube.com/@IsacaHq

]]></itunes:summary>
        <itunes:author>ISACA Podcast</itunes:author>
        <itunes:explicit>false</itunes:explicit>
        <itunes:block>No</itunes:block>
        <itunes:duration>1553</itunes:duration>
                <itunes:episode>313</itunes:episode>
        <itunes:episodeType>full</itunes:episodeType>
            </item>
    <item>
        <title>Elevate Your Career with Lauren Hasson</title>
        <itunes:title>Elevate Your Career with Lauren Hasson</itunes:title>
        <link>https://isacapodcast.podbean.com/e/elevate-your-career-with-lauren-hasson/</link>
                    <comments>https://isacapodcast.podbean.com/e/elevate-your-career-with-lauren-hasson/#comments</comments>        <pubDate>Thu, 04 Sep 2025 13:27:27 +0000</pubDate>
        <guid isPermaLink="false">isacapodcast.podbean.com/8a59afbb-3898-3d0e-82c4-b6122d865b68</guid>
                                    <description><![CDATA[<p>Lauren Hasson is the Founder of DevelopHer, an award-winning career development platform. In this podcast, she'll share a bit about her background and give a sneak peek at her upcoming CPE-eligible event. </p>
]]></description>
                                                            <content:encoded><![CDATA[<p>Lauren Hasson is the Founder of DevelopHer, an award-winning career development platform. In this podcast, she'll share a bit about her background and give a sneak peek at her upcoming CPE-eligible event. </p>
]]></content:encoded>
                                    
        <enclosure url="https://mcdn.podbean.com/mf/web/uvgc58sxr5h9pwdr/25_044_ISACA_Podcast_-_Lauren_and_Safia_D2a6m74.mp3" length="17544901" type="audio/mpeg"/>
        <itunes:summary><![CDATA[Lauren Hasson is the Founder of DevelopHer, an award-winning career development platform. In this podcast, she'll share a bit about her background and give a sneak peek at her upcoming CPE-eligible event. ]]></itunes:summary>
        <itunes:author>ISACA Podcast</itunes:author>
        <itunes:explicit>false</itunes:explicit>
        <itunes:block>No</itunes:block>
        <itunes:duration>1086</itunes:duration>
                <itunes:episode>312</itunes:episode>
        <itunes:episodeType>full</itunes:episodeType>
            </item>
    <item>
        <title>Cyberrisk Quantification: Strengthening Financial Resilience</title>
        <itunes:title>Cyberrisk Quantification: Strengthening Financial Resilience</itunes:title>
        <link>https://isacapodcast.podbean.com/e/cyberrisk-quantification-strengthening-financial-resilience/</link>
                    <comments>https://isacapodcast.podbean.com/e/cyberrisk-quantification-strengthening-financial-resilience/#comments</comments>        <pubDate>Wed, 04 Jun 2025 06:00:00 +0000</pubDate>
        <guid isPermaLink="false">isacapodcast.podbean.com/6a2574e0-2cb6-33de-882b-7269410229b6</guid>
                                    <description><![CDATA[<p>In this episode, ISACA's Lisa Cook engages with Yakir Golan, Executive Officer (CEO) and Co-Founder of Kovrr, to explore the critical role of Cyberrisk Quantification (CRQ) in enhancing organizational financial resilience. They discuss how CRQ solutions provide objective assessments of an organization's cybersecurity posture, enabling leaders to make informed decisions that align risk mitigation strategies with business objectives. The conversation also highlights the importance of translating cyberrisk exposure into monetary terms to facilitate high-level discussions and protect shareholder confidence.

Listen &amp; Subscribe Catch this episode—and more—on the ISACA Podcast Library: <a href='https://www.isaca.org/resources/news-and-trends/isaca-podcast-library'>https://www.isaca.org/resources/news-and-trends/isaca-podcast-library </a></p>
<p>or on your favorite podcast platform.</p>
]]></description>
                                                            <content:encoded><![CDATA[<p>In this episode, ISACA's Lisa Cook engages with Yakir Golan, Executive Officer (CEO) and Co-Founder of Kovrr, to explore the critical role of Cyberrisk Quantification (CRQ) in enhancing organizational financial resilience. They discuss how CRQ solutions provide objective assessments of an organization's cybersecurity posture, enabling leaders to make informed decisions that align risk mitigation strategies with business objectives. The conversation also highlights the importance of translating cyberrisk exposure into monetary terms to facilitate high-level discussions and protect shareholder confidence.<br>
<br>
Listen &amp; Subscribe Catch this episode—and more—on the ISACA Podcast Library: <a href='https://www.isaca.org/resources/news-and-trends/isaca-podcast-library'>https://www.isaca.org/resources/news-and-trends/isaca-podcast-library </a></p>
<p>or on your favorite podcast platform.</p>
]]></content:encoded>
                                    
        <enclosure url="https://mcdn.podbean.com/mf/web/x2zep8u43vuit72u/25_008_ISACA_Podcast_-_Yakir_Golan_D18jvow.mp3" length="51395742" type="audio/mpeg"/>
        <itunes:summary><![CDATA[In this episode, ISACA's Lisa Cook engages with Yakir Golan, Executive Officer (CEO) and Co-Founder of Kovrr, to explore the critical role of Cyberrisk Quantification (CRQ) in enhancing organizational financial resilience. They discuss how CRQ solutions provide objective assessments of an organization's cybersecurity posture, enabling leaders to make informed decisions that align risk mitigation strategies with business objectives. The conversation also highlights the importance of translating cyberrisk exposure into monetary terms to facilitate high-level discussions and protect shareholder confidence.Listen &amp; Subscribe Catch this episode—and more—on the ISACA Podcast Library: https://www.isaca.org/resources/news-and-trends/isaca-podcast-library 
or on your favorite podcast platform.]]></itunes:summary>
        <itunes:author>ISACA Podcast</itunes:author>
        <itunes:explicit>false</itunes:explicit>
        <itunes:block>No</itunes:block>
        <itunes:duration>2133</itunes:duration>
                <itunes:episode>311</itunes:episode>
        <itunes:episodeType>full</itunes:episodeType>
            </item>
    <item>
        <title>Securing Desktops and Data from Ransomware Attacks</title>
        <itunes:title>Securing Desktops and Data from Ransomware Attacks</itunes:title>
        <link>https://isacapodcast.podbean.com/e/securing-desktops-and-data-from-ransomware-attacks/</link>
                    <comments>https://isacapodcast.podbean.com/e/securing-desktops-and-data-from-ransomware-attacks/#comments</comments>        <pubDate>Thu, 15 May 2025 18:02:49 +0000</pubDate>
        <guid isPermaLink="false">isacapodcast.podbean.com/0b316255-b06c-3a8d-86bc-e2455f863189</guid>
                                    <description><![CDATA[<p>Ransomware remains one of the most formidable cybersecurity threats facing organizations worldwide.</p>
<p>In this episode of the ISACA Podcast, host Chris McGowan speaks with Netwrix endpoint protection expert Jeremy Moskowitz, who explains how ransomware infiltrates and cripples desktop environments. He explains cybercriminals' tactics to exploit social engineering and system misconfigurations to gain unauthorized access, offering actionable insights on the most effective prevention and mitigation strategies.</p>
<p>Additionally, Jeremy delivers practical advice that security teams can use to resist ransomware. He shares tips on safeguarding locally stored data, implementing robust backup solutions, enforcing strict access controls and system patching, and educating staff on common red flags associated with ransomware.</p>
<p> Listen &amp; Subscribe to ISACA Podcast </p>
<p>Catch this episode—and more—on the <a href='https://www.isaca.org/resources/news-and-trends/isaca-podcast-library'>ISACA Podcast Library</a>
or on your favorite podcast platform.</p>
<p> Connect &amp; Learn More about Netwrix</p>
<ul>
<li>Netwrix Data Loss Prevention Solution: <a href='https://www.netwrix.com/data-loss-prevention-software.html'>Learn more</a></li>
<li>Follow Netwrix on LinkedIn: <a href='https://www.linkedin.com/company/netwrix'>Netwrix Corporation: Posts | LinkedIn</a></li>
<li>Additional Resources Provided by Netwrix:
<ul>
<li><a href='https://www.cisa.gov/stopransomware'>CISA’s Ransomware Guidance</a></li>
<li><a href='https://www.sans.org/white-papers/ransomware/'>SANS Institute White Papers on Ransomware</a></li>
<li><a href='https://csrc.nist.gov/publications/detail/sp/800-61/rev-2/final'>NIST SP 800-61 Rev. 2 – Incident Handling Guide</a></li>
<li><a href='https://krebsonsecurity.com/?s=ransomware'>Krebs on Security – Ransomware Articles</a></li>
</ul>
</li>
</ul>
]]></description>
                                                            <content:encoded><![CDATA[<p>Ransomware remains one of the most formidable cybersecurity threats facing organizations worldwide.</p>
<p>In this episode of the ISACA Podcast, host Chris McGowan speaks with Netwrix endpoint protection expert Jeremy Moskowitz, who explains how ransomware infiltrates and cripples desktop environments. He explains cybercriminals' tactics to exploit social engineering and system misconfigurations to gain unauthorized access, offering actionable insights on the most effective prevention and mitigation strategies.</p>
<p>Additionally, Jeremy delivers practical advice that security teams can use to resist ransomware. He shares tips on safeguarding locally stored data, implementing robust backup solutions, enforcing strict access controls and system patching, and educating staff on common red flags associated with ransomware.</p>
<p> Listen &amp; Subscribe to ISACA Podcast </p>
<p>Catch this episode—and more—on the <a href='https://www.isaca.org/resources/news-and-trends/isaca-podcast-library'>ISACA Podcast Library</a><br>
or on your favorite podcast platform.</p>
<p> Connect &amp; Learn More about Netwrix</p>
<ul>
<li>Netwrix Data Loss Prevention Solution: <a href='https://www.netwrix.com/data-loss-prevention-software.html'>Learn more</a></li>
<li>Follow Netwrix on LinkedIn: <a href='https://www.linkedin.com/company/netwrix'>Netwrix Corporation: Posts | LinkedIn</a></li>
<li>Additional Resources Provided by Netwrix:
<ul>
<li><a href='https://www.cisa.gov/stopransomware'>CISA’s Ransomware Guidance</a></li>
<li><a href='https://www.sans.org/white-papers/ransomware/'>SANS Institute White Papers on Ransomware</a></li>
<li><a href='https://csrc.nist.gov/publications/detail/sp/800-61/rev-2/final'>NIST SP 800-61 Rev. 2 – Incident Handling Guide</a></li>
<li><a href='https://krebsonsecurity.com/?s=ransomware'>Krebs on Security – Ransomware Articles</a></li>
</ul>
</li>
</ul>
]]></content:encoded>
                                    
        <enclosure url="https://mcdn.podbean.com/mf/web/qsn2762ts9yk2iir/25_001_ISACA_Podcast_-_Netwrix_D1bs2e2.mp3" length="38311506" type="audio/mpeg"/>
        <itunes:summary><![CDATA[Ransomware remains one of the most formidable cybersecurity threats facing organizations worldwide.
In this episode of the ISACA Podcast, host Chris McGowan speaks with Netwrix endpoint protection expert Jeremy Moskowitz, who explains how ransomware infiltrates and cripples desktop environments. He explains cybercriminals' tactics to exploit social engineering and system misconfigurations to gain unauthorized access, offering actionable insights on the most effective prevention and mitigation strategies.
Additionally, Jeremy delivers practical advice that security teams can use to resist ransomware. He shares tips on safeguarding locally stored data, implementing robust backup solutions, enforcing strict access controls and system patching, and educating staff on common red flags associated with ransomware.
 Listen &amp; Subscribe to ISACA Podcast 
Catch this episode—and more—on the ISACA Podcast Libraryor on your favorite podcast platform.
 Connect &amp; Learn More about Netwrix

Netwrix Data Loss Prevention Solution: Learn more
Follow Netwrix on LinkedIn: Netwrix Corporation: Posts | LinkedIn
Additional Resources Provided by Netwrix:

CISA’s Ransomware Guidance
SANS Institute White Papers on Ransomware
NIST SP 800-61 Rev. 2 – Incident Handling Guide
Krebs on Security – Ransomware Articles


]]></itunes:summary>
        <itunes:author>ISACA Podcast</itunes:author>
        <itunes:explicit>false</itunes:explicit>
        <itunes:block>No</itunes:block>
        <itunes:duration>2370</itunes:duration>
                <itunes:episode>310</itunes:episode>
        <itunes:episodeType>full</itunes:episodeType>
            </item>
    <item>
        <title>Cyberresilience and Cybersecurity</title>
        <itunes:title>Cyberresilience and Cybersecurity</itunes:title>
        <link>https://isacapodcast.podbean.com/e/cyberresilience-and-cybersecurity/</link>
                    <comments>https://isacapodcast.podbean.com/e/cyberresilience-and-cybersecurity/#comments</comments>        <pubDate>Tue, 11 Mar 2025 18:28:30 +0000</pubDate>
        <guid isPermaLink="false">isacapodcast.podbean.com/1ac7de4c-1822-3632-b5ef-98fa2a59ea49</guid>
                                    <description><![CDATA[<p>Cybersecurity and the role of internal audit, an urgent call to action: The forces driving business growth and efficiency contribute to a broad attack surface for cyber assaults. How is the end user protected with good service while not being compromised?</p>
<ul>
<li>First Line includes internet, cloud, mobile, and social technologies, now mainstream, are platforms inherently oriented for sharing. Outsourcing, contracting, and remote workforces are shifting operational control.</li>
<li>Second line includes information and technology risk management leaders who establish governance and oversight, monitor security operations, and take-action as needed, often under the direction of the chief information security officer (CISO)</li>
<li>Third line of cyber defense—independent review of security measures and performance by the internal audit function. Internal audit should play an integral role in assessing and identifying opportunities to strengthen enterprise security. At the same time, internal audit has a duty to inform the audit committee and board of directors that the controls for which they are responsible are in place and functioning correctly, a growing concern across boardrooms as directors face potential legal and financial liabilities.</li>
</ul>
<p> </p>
]]></description>
                                                            <content:encoded><![CDATA[<p>Cybersecurity and the role of internal audit, an urgent call to action: The forces driving business growth and efficiency contribute to a broad attack surface for cyber assaults. How is the end user protected with good service while not being compromised?</p>
<ul>
<li>First Line includes internet, cloud, mobile, and social technologies, now mainstream, are platforms inherently oriented for sharing. Outsourcing, contracting, and remote workforces are shifting operational control.</li>
<li>Second line includes information and technology risk management leaders who establish governance and oversight, monitor security operations, and take-action as needed, often under the direction of the chief information security officer (CISO)</li>
<li>Third line of cyber defense—independent review of security measures and performance by the internal audit function. Internal audit should play an integral role in assessing and identifying opportunities to strengthen enterprise security. At the same time, internal audit has a duty to inform the audit committee and board of directors that the controls for which they are responsible are in place and functioning correctly, a growing concern across boardrooms as directors face potential legal and financial liabilities.</li>
</ul>
<p> </p>
]]></content:encoded>
                                    
        <enclosure url="https://mcdn.podbean.com/mf/web/83nyncxzdea22zzx/ISACA_Podcast_Vanguard_Integrity_with_Milt6eocm.mp3" length="34846507" type="audio/mpeg"/>
        <itunes:summary><![CDATA[Cybersecurity and the role of internal audit, an urgent call to action: The forces driving business growth and efficiency contribute to a broad attack surface for cyber assaults. How is the end user protected with good service while not being compromised?

First Line includes internet, cloud, mobile, and social technologies, now mainstream, are platforms inherently oriented for sharing. Outsourcing, contracting, and remote workforces are shifting operational control.
Second line includes information and technology risk management leaders who establish governance and oversight, monitor security operations, and take-action as needed, often under the direction of the chief information security officer (CISO)
Third line of cyber defense—independent review of security measures and performance by the internal audit function. Internal audit should play an integral role in assessing and identifying opportunities to strengthen enterprise security. At the same time, internal audit has a duty to inform the audit committee and board of directors that the controls for which they are responsible are in place and functioning correctly, a growing concern across boardrooms as directors face potential legal and financial liabilities.

 ]]></itunes:summary>
        <itunes:author>ISACA Podcast</itunes:author>
        <itunes:explicit>false</itunes:explicit>
        <itunes:block>No</itunes:block>
        <itunes:duration>1450</itunes:duration>
                <itunes:episode>309</itunes:episode>
        <itunes:episodeType>full</itunes:episodeType>
            </item>
    <item>
        <title>Cybersecurity Predictions for 2025</title>
        <itunes:title>Cybersecurity Predictions for 2025</itunes:title>
        <link>https://isacapodcast.podbean.com/e/cybersecurity-predictions-for-2025/</link>
                    <comments>https://isacapodcast.podbean.com/e/cybersecurity-predictions-for-2025/#comments</comments>        <pubDate>Tue, 07 Jan 2025 16:11:07 +0000</pubDate>
        <guid isPermaLink="false">isacapodcast.podbean.com/186eedd0-ab3d-3b69-b8ca-030fa37ab1ca</guid>
                                    <description><![CDATA[<p>The prevalence of ransomware and the security concerns associated with AI have made the role of cybersecurity professionals vital for enterprise success. The complex security landscape can make cybersecurity jobs stressful, but enterprises can take steps to retain cybersecurity talent and ensure enterprise assets are protected. In this podcast, Justin Rende, founder and CEO at Rhymetec, shares insight on the top concerns for cybersecurity professionals, the most in-demand skills, and the impact of AI on cybersecurity. </p>
]]></description>
                                                            <content:encoded><![CDATA[<p>The prevalence of ransomware and the security concerns associated with AI have made the role of cybersecurity professionals vital for enterprise success. The complex security landscape can make cybersecurity jobs stressful, but enterprises can take steps to retain cybersecurity talent and ensure enterprise assets are protected. In this podcast, Justin Rende, founder and CEO at Rhymetec, shares insight on the top concerns for cybersecurity professionals, the most in-demand skills, and the impact of AI on cybersecurity. </p>
]]></content:encoded>
                                    
        <enclosure url="https://mcdn.podbean.com/mf/web/gcxi7iwmvy49pzxf/814_Safia_and_Justin_Podcast_Audio_D286g3f.mp3" length="37801037" type="audio/mpeg"/>
        <itunes:summary><![CDATA[The prevalence of ransomware and the security concerns associated with AI have made the role of cybersecurity professionals vital for enterprise success. The complex security landscape can make cybersecurity jobs stressful, but enterprises can take steps to retain cybersecurity talent and ensure enterprise assets are protected. In this podcast, Justin Rende, founder and CEO at Rhymetec, shares insight on the top concerns for cybersecurity professionals, the most in-demand skills, and the impact of AI on cybersecurity. ]]></itunes:summary>
        <itunes:author>ISACA Podcast</itunes:author>
        <itunes:explicit>false</itunes:explicit>
        <itunes:block>No</itunes:block>
        <itunes:duration>1567</itunes:duration>
                <itunes:episode>308</itunes:episode>
        <itunes:episodeType>full</itunes:episodeType>
            </item>
    <item>
        <title>Examining Authentication in the Deepfake Era with Dr. Chase Cunningham</title>
        <itunes:title>Examining Authentication in the Deepfake Era with Dr. Chase Cunningham</itunes:title>
        <link>https://isacapodcast.podbean.com/e/isaca-podcast/</link>
                    <comments>https://isacapodcast.podbean.com/e/isaca-podcast/#comments</comments>        <pubDate>Tue, 10 Dec 2024 06:00:00 +0000</pubDate>
        <guid isPermaLink="false">isacapodcast.podbean.com/620d5943-d113-374a-921f-081feb69512d</guid>
                                    <description><![CDATA[<p>Given the dynamic nature of cyberthreats and the ever-expanding digital ecosystem, authentication is more critical than ever. In this episode, ISACA director of professional practices and innovation discusses a new content piece titled, "Examining Authentication in the Deepfake Era" with author Dr. Chase Cunningham. Their conversation of the paper explores the evolution, current state, and future trajectory of authentication technologies. </p>
]]></description>
                                                            <content:encoded><![CDATA[<p>Given the dynamic nature of cyberthreats and the ever-expanding digital ecosystem, authentication is more critical than ever. In this episode, ISACA director of professional practices and innovation discusses a new content piece titled, "Examining Authentication in the Deepfake Era" with author Dr. Chase Cunningham. Their conversation of the paper explores the evolution, current state, and future trajectory of authentication technologies. </p>
]]></content:encoded>
                                    
        <enclosure url="https://mcdn.podbean.com/mf/web/9mg2idad8ykvucz4/797_ISACA_Podcast_Jon_Brandt_Chase_Cunningham_D19cjqd.mp3" length="55629358" type="audio/mpeg"/>
        <itunes:summary><![CDATA[Given the dynamic nature of cyberthreats and the ever-expanding digital ecosystem, authentication is more critical than ever. In this episode, ISACA director of professional practices and innovation discusses a new content piece titled, "Examining Authentication in the Deepfake Era" with author Dr. Chase Cunningham. Their conversation of the paper explores the evolution, current state, and future trajectory of authentication technologies. ]]></itunes:summary>
        <itunes:author>ISACA Podcast</itunes:author>
        <itunes:explicit>false</itunes:explicit>
        <itunes:block>No</itunes:block>
        <itunes:duration>2308</itunes:duration>
                <itunes:episode>306</itunes:episode>
        <itunes:episodeType>full</itunes:episodeType>
            </item>
    <item>
        <title>Safely and Responsibly Using Emerging Health Technology</title>
        <itunes:title>Safely and Responsibly Using Emerging Health Technology</itunes:title>
        <link>https://isacapodcast.podbean.com/e/safely-and-responsibly-using-emerging-health-technology/</link>
                    <comments>https://isacapodcast.podbean.com/e/safely-and-responsibly-using-emerging-health-technology/#comments</comments>        <pubDate>Thu, 05 Dec 2024 06:00:00 +0000</pubDate>
        <guid isPermaLink="false">isacapodcast.podbean.com/ee0f3746-b36a-3dbe-85d0-dd3389032d14</guid>
                                    <description><![CDATA[<p>Emerging healthcare technologies have the potential to revolutionize healthcare and accessibility-related concerns, but these advancements are not without risk. To maximize the value and minimize the harms associated with emerging health technologies, it is critical to address ethical, privacy, and societal concerns to ensure that these technologies help rather than hurt humanity. </p>
<p> </p>
<p>In this ISACA Podcast, join Safia Kazi and Collin Bedder as they explore the applications and risks associated with emerging healthcare technologies.</p>
]]></description>
                                                            <content:encoded><![CDATA[<p>Emerging healthcare technologies have the potential to revolutionize healthcare and accessibility-related concerns, but these advancements are not without risk. To maximize the value and minimize the harms associated with emerging health technologies, it is critical to address ethical, privacy, and societal concerns to ensure that these technologies help rather than hurt humanity. </p>
<p> </p>
<p>In this ISACA Podcast, join Safia Kazi and Collin Bedder as they explore the applications and risks associated with emerging healthcare technologies.</p>
]]></content:encoded>
                                    
        <enclosure url="https://mcdn.podbean.com/mf/web/4cecywwuzzt5utkd/804_ISACA_Podcast_Safia_and_Collin_D181j7z.mp3" length="36445771" type="audio/mpeg"/>
        <itunes:summary><![CDATA[Emerging healthcare technologies have the potential to revolutionize healthcare and accessibility-related concerns, but these advancements are not without risk. To maximize the value and minimize the harms associated with emerging health technologies, it is critical to address ethical, privacy, and societal concerns to ensure that these technologies help rather than hurt humanity. 
 
In this ISACA Podcast, join Safia Kazi and Collin Bedder as they explore the applications and risks associated with emerging healthcare technologies.]]></itunes:summary>
        <itunes:author>ISACA Podcast</itunes:author>
        <itunes:explicit>false</itunes:explicit>
        <itunes:block>No</itunes:block>
        <itunes:duration>1510</itunes:duration>
                <itunes:episode>307</itunes:episode>
        <itunes:episodeType>full</itunes:episodeType>
            </item>
    <item>
        <title>Addressing SAP Security Gaps</title>
        <itunes:title>Addressing SAP Security Gaps</itunes:title>
        <link>https://isacapodcast.podbean.com/e/addressing-sap-security-gaps/</link>
                    <comments>https://isacapodcast.podbean.com/e/addressing-sap-security-gaps/#comments</comments>        <pubDate>Tue, 17 Sep 2024 06:00:00 +0000</pubDate>
        <guid isPermaLink="false">isacapodcast.podbean.com/f96d1474-db33-308d-a681-ccd520e3fee5</guid>
                                    <description><![CDATA[<p>SAP systems are treated differently than many other enterprise applications from a cybersecurity perspective. Most SAP security teams are siloed and left to meet security objectives on their own. Since SAP is so integral to organizations, it is unusual for SAP security objectives to not be on the radar of an existing 24/7 cybersecurity team executing response actions for Linux or Microsoft environments. SAP teams must be integrated w</p>
<p>SAP systems are treated differently than many other enterprise applications from a cybersecurity perspective. Most SAP security teams are siloed and left to meet security objectives on their own. Since SAP is so integral to organizations, it is unusual for SAP security objectives to not be on the radar of an existing 24/7 cybersecurity team executing response actions for Linux or Microsoft environments. SAP teams must be integrated with other cybersecurity groups within an organization to empower them with a security approach that unifies the entire enterprise landscape.</p>
<p>A chief information security officer (CISO) has many priorities, but when it comes to SAP environments, CISOs must fully understand how SAP applies to the IT enterprise and organizational environment to help them achieve all security goals. In addition, CISOs need to know their SAP team members personally so they can integrate them rather than contain them in silos. Finally, SAP must be secured to the same degree as other enterprise applications. When there is a Linux, Microsoft, or even a hybrid cloud incident, cybersecurity teams have a detailed plan of action upon which they are ready to act. SAP requires high-level consideration, or critical elements of the business will be vulnerable to malicious cyber actors—with no apparent response.</p>
]]></description>
                                                            <content:encoded><![CDATA[<p>SAP systems are treated differently than many other enterprise applications from a cybersecurity perspective. Most SAP security teams are siloed and left to meet security objectives on their own. Since SAP is so integral to organizations, it is unusual for SAP security objectives to not be on the radar of an existing 24/7 cybersecurity team executing response actions for Linux or Microsoft environments. SAP teams must be integrated w</p>
<p>SAP systems are treated differently than many other enterprise applications from a cybersecurity perspective. Most SAP security teams are siloed and left to meet security objectives on their own. Since SAP is so integral to organizations, it is unusual for SAP security objectives to not be on the radar of an existing 24/7 cybersecurity team executing response actions for Linux or Microsoft environments. SAP teams must be integrated with other cybersecurity groups within an organization to empower them with a security approach that unifies the entire enterprise landscape.</p>
<p>A chief information security officer (CISO) has many priorities, but when it comes to SAP environments, CISOs must fully understand how SAP applies to the IT enterprise and organizational environment to help them achieve all security goals. In addition, CISOs need to know their SAP team members personally so they can integrate them rather than contain them in silos. Finally, SAP must be secured to the same degree as other enterprise applications. When there is a Linux, Microsoft, or even a hybrid cloud incident, cybersecurity teams have a detailed plan of action upon which they are ready to act. SAP requires high-level consideration, or critical elements of the business will be vulnerable to malicious cyber actors—with no apparent response.</p>
]]></content:encoded>
                                    
        <enclosure url="https://mcdn.podbean.com/mf/web/9av2ga9uamgjtkyx/766_ISACA_Podcast_with_Ivan_Mans_D38wnxo.mp3" length="37362574" type="audio/mpeg"/>
        <itunes:summary><![CDATA[SAP systems are treated differently than many other enterprise applications from a cybersecurity perspective. Most SAP security teams are siloed and left to meet security objectives on their own. Since SAP is so integral to organizations, it is unusual for SAP security objectives to not be on the radar of an existing 24/7 cybersecurity team executing response actions for Linux or Microsoft environments. SAP teams must be integrated w
SAP systems are treated differently than many other enterprise applications from a cybersecurity perspective. Most SAP security teams are siloed and left to meet security objectives on their own. Since SAP is so integral to organizations, it is unusual for SAP security objectives to not be on the radar of an existing 24/7 cybersecurity team executing response actions for Linux or Microsoft environments. SAP teams must be integrated with other cybersecurity groups within an organization to empower them with a security approach that unifies the entire enterprise landscape.
A chief information security officer (CISO) has many priorities, but when it comes to SAP environments, CISOs must fully understand how SAP applies to the IT enterprise and organizational environment to help them achieve all security goals. In addition, CISOs need to know their SAP team members personally so they can integrate them rather than contain them in silos. Finally, SAP must be secured to the same degree as other enterprise applications. When there is a Linux, Microsoft, or even a hybrid cloud incident, cybersecurity teams have a detailed plan of action upon which they are ready to act. SAP requires high-level consideration, or critical elements of the business will be vulnerable to malicious cyber actors—with no apparent response.]]></itunes:summary>
        <itunes:author>ISACA Podcast</itunes:author>
        <itunes:explicit>false</itunes:explicit>
        <itunes:block>No</itunes:block>
        <itunes:duration>1549</itunes:duration>
                <itunes:episode>305</itunes:episode>
        <itunes:episodeType>full</itunes:episodeType>
            </item>
    <item>
        <title>What Enterprises Need to Know About ChatGPT and Cybersecurity</title>
        <itunes:title>What Enterprises Need to Know About ChatGPT and Cybersecurity</itunes:title>
        <link>https://isacapodcast.podbean.com/e/what-enterprises-need-to-know-about-chatgpt-and-cybersecurity/</link>
                    <comments>https://isacapodcast.podbean.com/e/what-enterprises-need-to-know-about-chatgpt-and-cybersecurity/#comments</comments>        <pubDate>Wed, 24 Jul 2024 09:00:00 +0000</pubDate>
        <guid isPermaLink="false">isacapodcast.podbean.com/0a0697cc-2644-3c33-8ada-2eca0b2693d7</guid>
                                    <description><![CDATA[<p>Many people are pondering whether generative artificial intelligence (AI) tool ChatGPT is a friend or a foe.</p>
<p> </p>
<p>In this ISACA podcast episode, Camelot Secure Director of Solutions Engineering Zachary Folks discusses not only his view of how ChatGPT can be considered an evolution of the encyclopedia, but importantly how it is aiding cybersecurity professionals and the overall goal of enterprise security, as well as how cybercriminals who want to exploit it can leverage it as well. He believes the world is entering a time when AI is fighting AI, and security professionals must focus on feeding ChatGPT technology more relevant data faster than the adversary. Folk also addresses how AI is affecting social engineering and his predictions for upcoming AI developments.</p>
]]></description>
                                                            <content:encoded><![CDATA[<p>Many people are pondering whether generative artificial intelligence (AI) tool ChatGPT is a friend or a foe.</p>
<p> </p>
<p>In this ISACA podcast episode, Camelot Secure Director of Solutions Engineering Zachary Folks discusses not only his view of how ChatGPT can be considered an evolution of the encyclopedia, but importantly how it is aiding cybersecurity professionals and the overall goal of enterprise security, as well as how cybercriminals who want to exploit it can leverage it as well. He believes the world is entering a time when AI is fighting AI, and security professionals must focus on feeding ChatGPT technology more relevant data faster than the adversary. Folk also addresses how AI is affecting social engineering and his predictions for upcoming AI developments.</p>
]]></content:encoded>
                                    
        <enclosure url="https://mcdn.podbean.com/mf/web/fipdui96k4pv7whk/P_655_ISACA_Podcast_Zachary_Folk_FINAL8m1sx.mp3" length="21115921" type="audio/mpeg"/>
        <itunes:summary><![CDATA[Many people are pondering whether generative artificial intelligence (AI) tool ChatGPT is a friend or a foe.
 
In this ISACA podcast episode, Camelot Secure Director of Solutions Engineering Zachary Folks discusses not only his view of how ChatGPT can be considered an evolution of the encyclopedia, but importantly how it is aiding cybersecurity professionals and the overall goal of enterprise security, as well as how cybercriminals who want to exploit it can leverage it as well. He believes the world is entering a time when AI is fighting AI, and security professionals must focus on feeding ChatGPT technology more relevant data faster than the adversary. Folk also addresses how AI is affecting social engineering and his predictions for upcoming AI developments.]]></itunes:summary>
        <itunes:author>ISACA Podcast</itunes:author>
        <itunes:explicit>false</itunes:explicit>
        <itunes:block>No</itunes:block>
        <itunes:duration>1304</itunes:duration>
                <itunes:episode>304</itunes:episode>
        <itunes:episodeType>full</itunes:episodeType>
            </item>
    <item>
        <title>The Cyber Standard Podcast - Episode 4</title>
        <itunes:title>The Cyber Standard Podcast - Episode 4</itunes:title>
        <link>https://isacapodcast.podbean.com/e/the-cyber-standard-podcast-episode-4/</link>
                    <comments>https://isacapodcast.podbean.com/e/the-cyber-standard-podcast-episode-4/#comments</comments>        <pubDate>Thu, 30 May 2024 06:00:00 +0000</pubDate>
        <guid isPermaLink="false">isacapodcast.podbean.com/7ac0a20b-d14d-36cb-85a9-c6f860bc8d7c</guid>
                                    <description><![CDATA[<p>Welcome to Episode 4 of "The Cyber Standard Podcast"!</p>
<p>Join host Ameet Jugnauth, Vice President of the London Chapter of ISACA, as he delves into the world of cybersecurity standardization. In this episode, titled "Becoming a License Body," Ameet is joined by esteemed guests Bryan Lillie, Strategic Technical Lead at the UK Cyber Security Council, and Peter Leitch, Co-Founder and Managing Partner at ANSEC. Together, they explore the intricacies of licensed bodies in shaping the cyber profession. Don't miss this insightful conversation!</p>
<p>Explore Further:</p>
<p>Delve deeper into the subject with additional resources provided in the episode description.</p>
<p><a href='https://www.isaca.org/about-us/newsroom/press-releases/2023/uk-cyber-security-council-partners-with-isaca-for-audit-and-assurance-pilot-scheme'>https://www.isaca.org/about-us/newsroom/press-releases/2023/uk-cyber-security-council-partners-with-isaca-for-audit-and-assurance-pilot-scheme</a></p>
]]></description>
                                                            <content:encoded><![CDATA[<p>Welcome to Episode 4 of "The Cyber Standard Podcast"!</p>
<p>Join host Ameet Jugnauth, Vice President of the London Chapter of ISACA, as he delves into the world of cybersecurity standardization. In this episode, titled "Becoming a License Body," Ameet is joined by esteemed guests Bryan Lillie, Strategic Technical Lead at the UK Cyber Security Council, and Peter Leitch, Co-Founder and Managing Partner at ANSEC. Together, they explore the intricacies of licensed bodies in shaping the cyber profession. Don't miss this insightful conversation!</p>
<p>Explore Further:</p>
<p>Delve deeper into the subject with additional resources provided in the episode description.</p>
<p><a href='https://www.isaca.org/about-us/newsroom/press-releases/2023/uk-cyber-security-council-partners-with-isaca-for-audit-and-assurance-pilot-scheme'>https://www.isaca.org/about-us/newsroom/press-releases/2023/uk-cyber-security-council-partners-with-isaca-for-audit-and-assurance-pilot-scheme</a></p>
]]></content:encoded>
                                    
        <enclosure url="https://mcdn.podbean.com/mf/web/k9g5scv7kj274xg6/The_Cyber_Standard_Podcast_Episode_4_AUDIO_ONLY67ec2.mp3" length="70378409" type="audio/mpeg"/>
        <itunes:summary><![CDATA[Welcome to Episode 4 of "The Cyber Standard Podcast"!
Join host Ameet Jugnauth, Vice President of the London Chapter of ISACA, as he delves into the world of cybersecurity standardization. In this episode, titled "Becoming a License Body," Ameet is joined by esteemed guests Bryan Lillie, Strategic Technical Lead at the UK Cyber Security Council, and Peter Leitch, Co-Founder and Managing Partner at ANSEC. Together, they explore the intricacies of licensed bodies in shaping the cyber profession. Don't miss this insightful conversation!
Explore Further:
Delve deeper into the subject with additional resources provided in the episode description.
https://www.isaca.org/about-us/newsroom/press-releases/2023/uk-cyber-security-council-partners-with-isaca-for-audit-and-assurance-pilot-scheme]]></itunes:summary>
        <itunes:author>ISACA Podcast</itunes:author>
        <itunes:explicit>false</itunes:explicit>
        <itunes:block>No</itunes:block>
        <itunes:duration>2925</itunes:duration>
                <itunes:episode>301</itunes:episode>
        <itunes:episodeType>full</itunes:episodeType>
            </item>
    <item>
        <title>The Cyber Standard Podcast - Episode 3</title>
        <itunes:title>The Cyber Standard Podcast - Episode 3</itunes:title>
        <link>https://isacapodcast.podbean.com/e/the-cyber-standard-podcast-episode-3/</link>
                    <comments>https://isacapodcast.podbean.com/e/the-cyber-standard-podcast-episode-3/#comments</comments>        <pubDate>Thu, 25 Apr 2024 06:00:00 +0000</pubDate>
        <guid isPermaLink="false">isacapodcast.podbean.com/741429f0-dbc3-34a1-85c9-f284337556ec</guid>
                                    <description><![CDATA[<p>Welcome to Episode 3 of "The Cyber Standard Podcast"!</p>
<p>Join host Ameet Jugnauth, Vice President of the London Chapter of ISACA, as he delves into the essential aspects of applying for and assessing candidates in the cybersecurity field. In this episode, titled "How to Apply," Ameet is joined by distinguished guests Ethan Duffell, representing the UK Cyber Security Council, and Allan Broadman, Director of CyberAdvisor London. Together, they shed light on the launch of specializations and the significance of professional standards in the cybersecurity sector. Don't miss this insightful conversation!</p>
<p>Explore Further:</p>
<p>Delve deeper into the subject with additional resources provided in the episode description.</p>
<p><a href='https://www.isaca.org/about-us/newsroom/press-releases/2023/uk-cyber-security-council-partners-with-isaca-for-audit-and-assurance-pilot-scheme'>https://www.isaca.org/about-us/newsroom/press-releases/2023/uk-cyber-security-council-partners-with-isaca-for-audit-and-assurance-pilot-scheme</a></p>
]]></description>
                                                            <content:encoded><![CDATA[<p>Welcome to Episode 3 of "The Cyber Standard Podcast"!</p>
<p>Join host Ameet Jugnauth, Vice President of the London Chapter of ISACA, as he delves into the essential aspects of applying for and assessing candidates in the cybersecurity field. In this episode, titled "How to Apply," Ameet is joined by distinguished guests Ethan Duffell, representing the UK Cyber Security Council, and Allan Broadman, Director of CyberAdvisor London. Together, they shed light on the launch of specializations and the significance of professional standards in the cybersecurity sector. Don't miss this insightful conversation!</p>
<p>Explore Further:</p>
<p>Delve deeper into the subject with additional resources provided in the episode description.</p>
<p><a href='https://www.isaca.org/about-us/newsroom/press-releases/2023/uk-cyber-security-council-partners-with-isaca-for-audit-and-assurance-pilot-scheme'>https://www.isaca.org/about-us/newsroom/press-releases/2023/uk-cyber-security-council-partners-with-isaca-for-audit-and-assurance-pilot-scheme</a></p>
]]></content:encoded>
                                    
        <enclosure url="https://mcdn.podbean.com/mf/web/peumzvnbzx4r6ptq/P_635_The_Cyber_Standard_Podcast_Episode_3_AUDIO_ONLY9cj3n.mp3" length="79992794" type="audio/mpeg"/>
        <itunes:summary><![CDATA[Welcome to Episode 3 of "The Cyber Standard Podcast"!
Join host Ameet Jugnauth, Vice President of the London Chapter of ISACA, as he delves into the essential aspects of applying for and assessing candidates in the cybersecurity field. In this episode, titled "How to Apply," Ameet is joined by distinguished guests Ethan Duffell, representing the UK Cyber Security Council, and Allan Broadman, Director of CyberAdvisor London. Together, they shed light on the launch of specializations and the significance of professional standards in the cybersecurity sector. Don't miss this insightful conversation!
Explore Further:
Delve deeper into the subject with additional resources provided in the episode description.
https://www.isaca.org/about-us/newsroom/press-releases/2023/uk-cyber-security-council-partners-with-isaca-for-audit-and-assurance-pilot-scheme]]></itunes:summary>
        <itunes:author>ISACA Podcast</itunes:author>
        <itunes:explicit>false</itunes:explicit>
        <itunes:block>No</itunes:block>
        <itunes:duration>3325</itunes:duration>
                <itunes:episode>300</itunes:episode>
        <itunes:episodeType>full</itunes:episodeType>
            </item>
    <item>
        <title>Effective Third Party Risk Management in 2024: AI’s Impact and Future Trends</title>
        <itunes:title>Effective Third Party Risk Management in 2024: AI’s Impact and Future Trends</itunes:title>
        <link>https://isacapodcast.podbean.com/e/effective-third-party-risk-management-in-2024-ai-s-impact-and-future-trends/</link>
                    <comments>https://isacapodcast.podbean.com/e/effective-third-party-risk-management-in-2024-ai-s-impact-and-future-trends/#comments</comments>        <pubDate>Wed, 24 Apr 2024 09:00:00 +0000</pubDate>
        <guid isPermaLink="false">isacapodcast.podbean.com/528c0e2f-de12-3bcd-ade3-8a68324b660e</guid>
                                    <description><![CDATA[<p>Traditional security questionnaires just aren't cutting it anymore.</p>
<p>Tune into this ISACA Podcast episode, Chris McGowan chats with VISO TRUST CEO and Co-founder, Paul Valente as they delve into the evolving landscape of Third-Party Risk Management (TPRM), exposing the limitations of current methods and exploring how emerging AI trends are shaping a more secure future and driving more effective third-party risk management programs.</p>
<p>To learn more about VISO Trust please go to https://visotrust.com/</p>
]]></description>
                                                            <content:encoded><![CDATA[<p>Traditional security questionnaires just aren't cutting it anymore.</p>
<p>Tune into this ISACA Podcast episode, Chris McGowan chats with VISO TRUST CEO and Co-founder, Paul Valente as they delve into the evolving landscape of Third-Party Risk Management (TPRM), exposing the limitations of current methods and exploring how emerging AI trends are shaping a more secure future and driving more effective third-party risk management programs.</p>
<p>To learn more about VISO Trust please go to https://visotrust.com/</p>
]]></content:encoded>
                                    
        <enclosure url="https://mcdn.podbean.com/mf/web/rbu368cmi3rf8bsg/701_ISACA_Podcast_-_VISO_TRUST_Sponsor_April_D168d2v.mp3" length="45361456" type="audio/mpeg"/>
        <itunes:summary><![CDATA[Traditional security questionnaires just aren't cutting it anymore.
Tune into this ISACA Podcast episode, Chris McGowan chats with VISO TRUST CEO and Co-founder, Paul Valente as they delve into the evolving landscape of Third-Party Risk Management (TPRM), exposing the limitations of current methods and exploring how emerging AI trends are shaping a more secure future and driving more effective third-party risk management programs.
To learn more about VISO Trust please go to https://visotrust.com/]]></itunes:summary>
        <itunes:author>ISACA Podcast</itunes:author>
        <itunes:explicit>false</itunes:explicit>
        <itunes:block>No</itunes:block>
        <itunes:duration>1883</itunes:duration>
                <itunes:episode>303</itunes:episode>
        <itunes:episodeType>full</itunes:episodeType>
            </item>
    <item>
        <title>Unlocking Strategic Value from a Bug Bounty Program</title>
        <itunes:title>Unlocking Strategic Value from a Bug Bounty Program</itunes:title>
        <link>https://isacapodcast.podbean.com/e/unlocking-strategic-value-from-a-bug-bounty-program/</link>
                    <comments>https://isacapodcast.podbean.com/e/unlocking-strategic-value-from-a-bug-bounty-program/#comments</comments>        <pubDate>Wed, 03 Apr 2024 06:00:00 +0000</pubDate>
        <guid isPermaLink="false">isacapodcast.podbean.com/5e95ba4f-d559-31da-b6af-0fdfa5903dfc</guid>
                                    <description><![CDATA[<p>Are you curious about how to maximize the strategic value and impact of your bug bounty program?</p>
<p>In this episode, you can learn how Adobe continuously develops and improves its bounty program to engage security researchers and hackers globally and improve its security posture from an adversary perspective.</p>
<p>In this ISACA Podcast, Chris McGown, ISACA's Information Security Professional Practices Principal, chats with Alex Stan, Product Security Engineer and member of the Product Security Incident Response Team (PSIRT), discusses the value of bug bounty programs and shares how you can develop a metrics-driven approach to enhance the internal security testing and detection capabilities of your organization.</p>
<p>Explore Further: Delve deeper into the subject with additional resources</p>
<p><a href='https://blog.developer.adobe.com/adobe-announces-researcher-hall-of-fame-initiative-for-security-researchers-5e677286dbd6'>https://blog.developer.adobe.com/adobe-announces-researcher-hall-of-fame-initiative-for-security-researchers-5e677286dbd6</a></p>
<p><a href='https://blog.developer.adobe.com/researcher-q-a-aem-solution-architect-by-day-adobe-bug-bounty-hunter-by-night-aed39a4750e4'>https://blog.developer.adobe.com/researcher-q-a-aem-solution-architect-by-day-adobe-bug-bounty-hunter-by-night-aed39a4750e4</a></p>
<p><a href='https://blog.developer.adobe.com/attention-security-researchers-level-up-your-skills-and-join-our-private-bug-bounty-program-2da9d5979d8b'>https://blog.developer.adobe.com/attention-security-researchers-level-up-your-skills-and-join-our-private-bug-bounty-program-2da9d5979d8b</a></p>
<p><a href='https://blog.developer.adobe.com/adobe-recap-2023-ambassador-world-cup-final-four-df701e1a1b12'>https://blog.developer.adobe.com/adobe-recap-2023-ambassador-world-cup-final-four-df701e1a1b12</a> 


</p>
]]></description>
                                                            <content:encoded><![CDATA[<p>Are you curious about how to maximize the strategic value and impact of your bug bounty program?</p>
<p>In this episode, you can learn how Adobe continuously develops and improves its bounty program to engage security researchers and hackers globally and improve its security posture from an adversary perspective.</p>
<p>In this ISACA Podcast, Chris McGown, ISACA's Information Security Professional Practices Principal, chats with Alex Stan, Product Security Engineer and member of the Product Security Incident Response Team (PSIRT), discusses the value of bug bounty programs and shares how you can develop a metrics-driven approach to enhance the internal security testing and detection capabilities of your organization.</p>
<p>Explore Further: Delve deeper into the subject with additional resources</p>
<p><a href='https://blog.developer.adobe.com/adobe-announces-researcher-hall-of-fame-initiative-for-security-researchers-5e677286dbd6'>https://blog.developer.adobe.com/adobe-announces-researcher-hall-of-fame-initiative-for-security-researchers-5e677286dbd6</a></p>
<p><a href='https://blog.developer.adobe.com/researcher-q-a-aem-solution-architect-by-day-adobe-bug-bounty-hunter-by-night-aed39a4750e4'>https://blog.developer.adobe.com/researcher-q-a-aem-solution-architect-by-day-adobe-bug-bounty-hunter-by-night-aed39a4750e4</a></p>
<p><a href='https://blog.developer.adobe.com/attention-security-researchers-level-up-your-skills-and-join-our-private-bug-bounty-program-2da9d5979d8b'>https://blog.developer.adobe.com/attention-security-researchers-level-up-your-skills-and-join-our-private-bug-bounty-program-2da9d5979d8b</a></p>
<p><a href='https://blog.developer.adobe.com/adobe-recap-2023-ambassador-world-cup-final-four-df701e1a1b12'>https://blog.developer.adobe.com/adobe-recap-2023-ambassador-world-cup-final-four-df701e1a1b12</a> <br>
<br>
<br>
</p>
]]></content:encoded>
                                    
        <enclosure url="https://mcdn.podbean.com/mf/web/mbz9gt/P_702_ISACA_Podcast_Adobe_Sponsor_April_Audio_Onlyap6xx.mp3" length="39385947" type="audio/mpeg"/>
        <itunes:summary><![CDATA[Are you curious about how to maximize the strategic value and impact of your bug bounty program?
In this episode, you can learn how Adobe continuously develops and improves its bounty program to engage security researchers and hackers globally and improve its security posture from an adversary perspective.
In this ISACA Podcast, Chris McGown, ISACA's Information Security Professional Practices Principal, chats with Alex Stan, Product Security Engineer and member of the Product Security Incident Response Team (PSIRT), discusses the value of bug bounty programs and shares how you can develop a metrics-driven approach to enhance the internal security testing and detection capabilities of your organization.
Explore Further: Delve deeper into the subject with additional resources
https://blog.developer.adobe.com/adobe-announces-researcher-hall-of-fame-initiative-for-security-researchers-5e677286dbd6
https://blog.developer.adobe.com/researcher-q-a-aem-solution-architect-by-day-adobe-bug-bounty-hunter-by-night-aed39a4750e4
https://blog.developer.adobe.com/attention-security-researchers-level-up-your-skills-and-join-our-private-bug-bounty-program-2da9d5979d8b
https://blog.developer.adobe.com/adobe-recap-2023-ambassador-world-cup-final-four-df701e1a1b12 ]]></itunes:summary>
        <itunes:author>ISACA Podcast</itunes:author>
        <itunes:explicit>false</itunes:explicit>
        <itunes:block>No</itunes:block>
        <itunes:duration>1634</itunes:duration>
                <itunes:episode>302</itunes:episode>
        <itunes:episodeType>full</itunes:episodeType>
            </item>
    <item>
        <title>The Cyber Standard Podcast - Episode 2</title>
        <itunes:title>The Cyber Standard Podcast - Episode 2</itunes:title>
        <link>https://isacapodcast.podbean.com/e/the-cyber-standard-podcast-episode-2/</link>
                    <comments>https://isacapodcast.podbean.com/e/the-cyber-standard-podcast-episode-2/#comments</comments>        <pubDate>Thu, 28 Mar 2024 06:00:00 +0000</pubDate>
        <guid isPermaLink="false">isacapodcast.podbean.com/bd8751ff-4615-340b-b75c-715ac9c655cc</guid>
                                    <description><![CDATA[<p>Welcome to Episode 2 of "The Cyber Standard Podcast"!</p>
<p>Join host Ameet Jugnauth, Vice President of the London Chapter of ISACA, as he delves into the intricacies of cybersecurity standardization. In this episode, titled "Audit and Assurance," Ameet is joined by esteemed guests Leanne Sperry, Project Manager for Standards Development at the UK Cyber Security Council, and Mike Hughes, the ISACA Immediate Past President for ISACA Central UK. Together, they explore key challenges, lessons learned, and insights from related workshops in the realm of Audit and Assurance. Don't miss this insightful conversation!</p>
<p>Explore Further:</p>
<p>Delve deeper into the subject with additional resources provided in the episode description.</p>
<p><a href='https://www.isaca.org/about-us/newsroom/press-releases/2023/uk-cyber-security-council-partners-with-isaca-for-audit-and-assurance-pilot-scheme'>https://www.isaca.org/about-us/newsroom/press-releases/2023/uk-cyber-security-council-partners-with-isaca-for-audit-and-assurance-pilot-scheme</a></p>
]]></description>
                                                            <content:encoded><![CDATA[<p>Welcome to Episode 2 of "The Cyber Standard Podcast"!</p>
<p>Join host Ameet Jugnauth, Vice President of the London Chapter of ISACA, as he delves into the intricacies of cybersecurity standardization. In this episode, titled "Audit and Assurance," Ameet is joined by esteemed guests Leanne Sperry, Project Manager for Standards Development at the UK Cyber Security Council, and Mike Hughes, the ISACA Immediate Past President for ISACA Central UK. Together, they explore key challenges, lessons learned, and insights from related workshops in the realm of Audit and Assurance. Don't miss this insightful conversation!</p>
<p>Explore Further:</p>
<p>Delve deeper into the subject with additional resources provided in the episode description.</p>
<p><a href='https://www.isaca.org/about-us/newsroom/press-releases/2023/uk-cyber-security-council-partners-with-isaca-for-audit-and-assurance-pilot-scheme'>https://www.isaca.org/about-us/newsroom/press-releases/2023/uk-cyber-security-council-partners-with-isaca-for-audit-and-assurance-pilot-scheme</a></p>
]]></content:encoded>
                                    
        <enclosure url="https://mcdn.podbean.com/mf/web/y6b4g3bk8e95rjvq/605_The_Cyber_Standard_Podcast_Episode_2_Audit_and_Assurance_D38e9fr.mp3" length="61495947" type="audio/mpeg"/>
        <itunes:summary><![CDATA[Welcome to Episode 2 of "The Cyber Standard Podcast"!
Join host Ameet Jugnauth, Vice President of the London Chapter of ISACA, as he delves into the intricacies of cybersecurity standardization. In this episode, titled "Audit and Assurance," Ameet is joined by esteemed guests Leanne Sperry, Project Manager for Standards Development at the UK Cyber Security Council, and Mike Hughes, the ISACA Immediate Past President for ISACA Central UK. Together, they explore key challenges, lessons learned, and insights from related workshops in the realm of Audit and Assurance. Don't miss this insightful conversation!
Explore Further:
Delve deeper into the subject with additional resources provided in the episode description.
https://www.isaca.org/about-us/newsroom/press-releases/2023/uk-cyber-security-council-partners-with-isaca-for-audit-and-assurance-pilot-scheme]]></itunes:summary>
        <itunes:author>ISACA Podcast</itunes:author>
        <itunes:explicit>false</itunes:explicit>
        <itunes:block>No</itunes:block>
        <itunes:duration>2555</itunes:duration>
                <itunes:episode>299</itunes:episode>
        <itunes:episodeType>full</itunes:episodeType>
            </item>
    <item>
        <title>The Cyber Standard Podcast - Episode 1</title>
        <itunes:title>The Cyber Standard Podcast - Episode 1</itunes:title>
        <link>https://isacapodcast.podbean.com/e/the-cyber-standard-podcast-episode-1/</link>
                    <comments>https://isacapodcast.podbean.com/e/the-cyber-standard-podcast-episode-1/#comments</comments>        <pubDate>Wed, 28 Feb 2024 02:00:00 +0000</pubDate>
        <guid isPermaLink="false">isacapodcast.podbean.com/dd2afad6-e087-364a-9485-0aa6ae682475</guid>
                                    <description><![CDATA[<p>Tune in to the inaugural episode of "The Cyber Standard Podcast," “The Vision!”</p>
<p>Join host Ameet Jugnauth as he interviews Robin Lyons, ISACA Principal, IT Audit Professional Practices, and Annmarie Dann, Director of Professional Standards at the UK Cyber Security Council, in a compelling discussion about the standardization of specialisms in cybersecurity. Explore the Council's and ISACA's visions for the future, the significance of the Audit &amp; Assurance specialism, and the collaborative efforts between the two organizations. Don't miss this insightful conversation that sets the stage for the podcast's journey into the world of cybersecurity standardization.</p>
<p>Explore Further: Delve deeper into the subject with additional resources provided in the episode description.</p>
<p><a href='https://www.isaca.org/about-us/newsroom/press-releases/2023/uk-cyber-security-council-partners-with-isaca-for-audit-and-assurance-pilot-scheme'>https://www.isaca.org/about-us/newsroom/press-releases/2023/uk-cyber-security-council-partners-with-isaca-for-audit-and-assurance-pilot-scheme</a> </p>
]]></description>
                                                            <content:encoded><![CDATA[<p>Tune in to the inaugural episode of "The Cyber Standard Podcast," “The Vision!”</p>
<p>Join host Ameet Jugnauth as he interviews Robin Lyons, ISACA Principal, IT Audit Professional Practices, and Annmarie Dann, Director of Professional Standards at the UK Cyber Security Council, in a compelling discussion about the standardization of specialisms in cybersecurity. Explore the Council's and ISACA's visions for the future, the significance of the Audit &amp; Assurance specialism, and the collaborative efforts between the two organizations. Don't miss this insightful conversation that sets the stage for the podcast's journey into the world of cybersecurity standardization.</p>
<p>Explore Further: Delve deeper into the subject with additional resources provided in the episode description.</p>
<p><a href='https://www.isaca.org/about-us/newsroom/press-releases/2023/uk-cyber-security-council-partners-with-isaca-for-audit-and-assurance-pilot-scheme'>https://www.isaca.org/about-us/newsroom/press-releases/2023/uk-cyber-security-council-partners-with-isaca-for-audit-and-assurance-pilot-scheme</a> </p>
]]></content:encoded>
                                    
        <enclosure url="https://mcdn.podbean.com/mf/web/74xnez/P_576_Audio_Edit_d19in44.mp3" length="60016345" type="audio/mpeg"/>
        <itunes:summary><![CDATA[Tune in to the inaugural episode of "The Cyber Standard Podcast," “The Vision!”
Join host Ameet Jugnauth as he interviews Robin Lyons, ISACA Principal, IT Audit Professional Practices, and Annmarie Dann, Director of Professional Standards at the UK Cyber Security Council, in a compelling discussion about the standardization of specialisms in cybersecurity. Explore the Council's and ISACA's visions for the future, the significance of the Audit &amp; Assurance specialism, and the collaborative efforts between the two organizations. Don't miss this insightful conversation that sets the stage for the podcast's journey into the world of cybersecurity standardization.
Explore Further: Delve deeper into the subject with additional resources provided in the episode description.
https://www.isaca.org/about-us/newsroom/press-releases/2023/uk-cyber-security-council-partners-with-isaca-for-audit-and-assurance-pilot-scheme ]]></itunes:summary>
        <itunes:author>ISACA Podcast</itunes:author>
        <itunes:explicit>false</itunes:explicit>
        <itunes:block>No</itunes:block>
        <itunes:duration>2499</itunes:duration>
                <itunes:episode>298</itunes:episode>
        <itunes:episodeType>full</itunes:episodeType>
            </item>
    <item>
        <title>Measuring Security Risk Against Dynamic Threats</title>
        <itunes:title>Measuring Security Risk Against Dynamic Threats</itunes:title>
        <link>https://isacapodcast.podbean.com/e/measuring-security-risk-against-dynamic-threats/</link>
                    <comments>https://isacapodcast.podbean.com/e/measuring-security-risk-against-dynamic-threats/#comments</comments>        <pubDate>Wed, 21 Feb 2024 06:00:00 +0000</pubDate>
        <guid isPermaLink="false">isacapodcast.podbean.com/6615fa6e-e06c-3d9a-bf66-96d0ed08c517</guid>
                                    <description><![CDATA[<p>Getting dressed is a routine example of everyday life packed with choices. Should I wear pants or shorts? Do I need a sweater? Shoes or sandals? While we often make these choices subconsciously, even actions that don’t appear as choices include several microscopic risk-based calculations. 

These judgments are executed based on some estimate of risk, and as known in the cybersecurity industry, what is believed to be safe today may no longer be safe tomorrow (or possibly even within the hour). Given this unique challenge, how do you establish a process that allows you to identify, analyze, prioritize, and treat security risks that are constantly evolving and where the threat is persistently adapting?

In this podcast, ISACA's Lisa Cook discusses with Adobe's Matt Carroll, Senior Manager of Technology Governance, Risk, and Compliance the risk methodology and practices his team has developed at Adobe that have helped the company rapidly measure security risk in a constantly changing landscape.</p>
]]></description>
                                                            <content:encoded><![CDATA[<p>Getting dressed is a routine example of everyday life packed with choices. Should I wear pants or shorts? Do I need a sweater? Shoes or sandals? While we often make these choices subconsciously, even actions that don’t appear as choices include several microscopic risk-based calculations. <br>
<br>
These judgments are executed based on some estimate of risk, and as known in the cybersecurity industry, what is believed to be safe today may no longer be safe tomorrow (or possibly even within the hour). Given this unique challenge, how do you establish a process that allows you to identify, analyze, prioritize, and treat security risks that are constantly evolving and where the threat is persistently adapting?<br>
<br>
In this podcast, ISACA's Lisa Cook discusses with Adobe's Matt Carroll, Senior Manager of Technology Governance, Risk, and Compliance the risk methodology and practices his team has developed at Adobe that have helped the company rapidly measure security risk in a constantly changing landscape.</p>
]]></content:encoded>
                                    
        <enclosure url="https://mcdn.podbean.com/mf/web/j9t8zf/P_679_ISACA_Podcast_-_Sponsor_Adobe_D1am3gm.mp3" length="41179129" type="audio/mpeg"/>
        <itunes:summary><![CDATA[Getting dressed is a routine example of everyday life packed with choices. Should I wear pants or shorts? Do I need a sweater? Shoes or sandals? While we often make these choices subconsciously, even actions that don’t appear as choices include several microscopic risk-based calculations. These judgments are executed based on some estimate of risk, and as known in the cybersecurity industry, what is believed to be safe today may no longer be safe tomorrow (or possibly even within the hour). Given this unique challenge, how do you establish a process that allows you to identify, analyze, prioritize, and treat security risks that are constantly evolving and where the threat is persistently adapting?In this podcast, ISACA's Lisa Cook discusses with Adobe's Matt Carroll, Senior Manager of Technology Governance, Risk, and Compliance the risk methodology and practices his team has developed at Adobe that have helped the company rapidly measure security risk in a constantly changing landscape.]]></itunes:summary>
        <itunes:author>ISACA Podcast</itunes:author>
        <itunes:explicit>false</itunes:explicit>
        <itunes:block>No</itunes:block>
        <itunes:duration>1714</itunes:duration>
                <itunes:episode>296</itunes:episode>
        <itunes:episodeType>full</itunes:episodeType>
            </item>
    <item>
        <title>Reflecting on 25 Years of Information Security Matters</title>
        <itunes:title>Reflecting on 25 Years of Information Security Matters</itunes:title>
        <link>https://isacapodcast.podbean.com/e/reflecting-on-25-years-of-information-security-matters/</link>
                    <comments>https://isacapodcast.podbean.com/e/reflecting-on-25-years-of-information-security-matters/#comments</comments>        <pubDate>Wed, 14 Feb 2024 06:00:00 +0000</pubDate>
        <guid isPermaLink="false">isacapodcast.podbean.com/ef53d48b-1f12-35d1-a6d6-3c3858fcd629</guid>
                                    <description><![CDATA[<p>ISACA recently marked the 25th anniversary of Steve Ross’ ISACA Journal Information Security Matters column. Over the last quarter century, technology, security, and the workforce have evolved, while certain challenges remain the same.</p>
<p>In this ISACA Podcast episode, Safia Kazi speaks to Steve about how he started writing for the Journal, societal shifts in security perceptions, and how writing skills are invaluable for anyone in the security industry.</p>
]]></description>
                                                            <content:encoded><![CDATA[<p>ISACA recently marked the 25th anniversary of Steve Ross’ <em>ISACA Journal </em>Information Security Matters column. Over the last quarter century, technology, security, and the workforce have evolved, while certain challenges remain the same.</p>
<p>In this ISACA Podcast episode, Safia Kazi speaks to Steve about how he started writing for the <em>Journal</em>, societal shifts in security perceptions, and how writing skills are invaluable for anyone in the security industry.</p>
]]></content:encoded>
                                    
        <enclosure url="https://mcdn.podbean.com/mf/web/2u8ndr/659_ISACA_Podcast_-_Steve_Ross_D27xv0z.mp3" length="20205277" type="audio/mpeg"/>
        <itunes:summary><![CDATA[ISACA recently marked the 25th anniversary of Steve Ross’ ISACA Journal Information Security Matters column. Over the last quarter century, technology, security, and the workforce have evolved, while certain challenges remain the same.
In this ISACA Podcast episode, Safia Kazi speaks to Steve about how he started writing for the Journal, societal shifts in security perceptions, and how writing skills are invaluable for anyone in the security industry.]]></itunes:summary>
        <itunes:author>ISACA Podcast</itunes:author>
        <itunes:explicit>false</itunes:explicit>
        <itunes:block>No</itunes:block>
        <itunes:duration>834</itunes:duration>
                <itunes:episode>297</itunes:episode>
        <itunes:episodeType>full</itunes:episodeType>
            </item>
    <item>
        <title>A View into CTEM Exposure Management: Reducing your Attack Surface 3x</title>
        <itunes:title>A View into CTEM Exposure Management: Reducing your Attack Surface 3x</itunes:title>
        <link>https://isacapodcast.podbean.com/e/a-view-into-ctem-exposure-management-reducing-your-attack-surface-3x/</link>
                    <comments>https://isacapodcast.podbean.com/e/a-view-into-ctem-exposure-management-reducing-your-attack-surface-3x/#comments</comments>        <pubDate>Wed, 07 Feb 2024 15:25:11 +0000</pubDate>
        <guid isPermaLink="false">isacapodcast.podbean.com/8e85d02f-dcbf-3236-b1a6-71651ba6ae1e</guid>
                                    <description><![CDATA[<p>Organizations can no longer rely on legacy vulnerability management solutions to protect against even basic attacks. Instead, vulnerability management is just one small component in a unified continuous threat exposure management (CTEM) approach to securing an enterprise from malicious intruders and ransomware. In addition to vulnerability management, security around misconfigurations, patching, identity, software, external attack surfaces, and more must be included.</p>
<p>In this ISACA Podcast, Nanitor Chief Strategist Derek Melber explains that an organization can prevent breaches and ransomware by taking an asset-centric prioritized-security approach that includes all of these security areas.</p>
<p>For more ISACA Podcasts, visit <a href='http://www.isaca.org/podcasts'>www.isaca.org/podcasts </a></p>
<p>To learn more about Nanitor, please visit <a href='https://nanitor.com/'>https://nanitor.com/</a></p>
<p>To view the Nanitor article, please click <a href='https://nanitor.com/resources/blog/cybersecurity/exploring-continuous-threat-exposure-management-ctem/'>https://na</a><a href='https://nanitor.com/resources/blog/cybersecurity/exploring-continuous-threat-exposure-management-ctem/'>ni</a><a href='https://nanitor.com/resources/blog/cybersecurity/exploring-continuous-threat-exposure-management-ctem/'>tor.com/resources/blog/cybersecurity/exploring-continuous-threat-exposure-management-ctem/</a></p>
]]></description>
                                                            <content:encoded><![CDATA[<p>Organizations can no longer rely on legacy vulnerability management solutions to protect against even basic attacks. Instead, vulnerability management is just one small component in a unified continuous threat exposure management (CTEM) approach to securing an enterprise from malicious intruders and ransomware. In addition to vulnerability management, security around misconfigurations, patching, identity, software, external attack surfaces, and more must be included.</p>
<p>In this ISACA Podcast, Nanitor Chief Strategist Derek Melber explains that an organization can prevent breaches and ransomware by taking an asset-centric prioritized-security approach that includes all of these security areas.</p>
<p>For more ISACA Podcasts, visit <a href='http://www.isaca.org/podcasts'>www.isaca.org/podcasts </a></p>
<p>To learn more about Nanitor, please visit <a href='https://nanitor.com/'>https://nanitor.com/</a></p>
<p>To view the Nanitor article, please click <a href='https://nanitor.com/resources/blog/cybersecurity/exploring-continuous-threat-exposure-management-ctem/'>https://na</a><a href='https://nanitor.com/resources/blog/cybersecurity/exploring-continuous-threat-exposure-management-ctem/'>ni</a><a href='https://nanitor.com/resources/blog/cybersecurity/exploring-continuous-threat-exposure-management-ctem/'>tor.com/resources/blog/cybersecurity/exploring-continuous-threat-exposure-management-ctem/</a></p>
]]></content:encoded>
                                    
        <enclosure url="https://mcdn.podbean.com/mf/web/pm5h93/ISACA_Sponsored_Podcast_-_Nanitor_AUDIO_ONLYmp4buqfv.mp3" length="62094995" type="audio/mpeg"/>
        <itunes:summary><![CDATA[Organizations can no longer rely on legacy vulnerability management solutions to protect against even basic attacks. Instead, vulnerability management is just one small component in a unified continuous threat exposure management (CTEM) approach to securing an enterprise from malicious intruders and ransomware. In addition to vulnerability management, security around misconfigurations, patching, identity, software, external attack surfaces, and more must be included.
In this ISACA Podcast, Nanitor Chief Strategist Derek Melber explains that an organization can prevent breaches and ransomware by taking an asset-centric prioritized-security approach that includes all of these security areas.
For more ISACA Podcasts, visit www.isaca.org/podcasts 
To learn more about Nanitor, please visit https://nanitor.com/
To view the Nanitor article, please click https://nanitor.com/resources/blog/cybersecurity/exploring-continuous-threat-exposure-management-ctem/]]></itunes:summary>
        <itunes:author>ISACA Podcast</itunes:author>
        <itunes:explicit>false</itunes:explicit>
        <itunes:block>No</itunes:block>
        <itunes:duration>2580</itunes:duration>
                <itunes:episode>295</itunes:episode>
        <itunes:episodeType>full</itunes:episodeType>
            </item>
    <item>
        <title>Leveraging Agile Concepts for Neurodiverse Auditors</title>
        <itunes:title>Leveraging Agile Concepts for Neurodiverse Auditors</itunes:title>
        <link>https://isacapodcast.podbean.com/e/leveraging-agile-concepts-for-neurodiverse-auditors/</link>
                    <comments>https://isacapodcast.podbean.com/e/leveraging-agile-concepts-for-neurodiverse-auditors/#comments</comments>        <pubDate>Wed, 17 Jan 2024 15:14:39 +0000</pubDate>
        <guid isPermaLink="false">isacapodcast.podbean.com/7003502b-477b-3dfa-9353-e219486aa804</guid>
                                    <description><![CDATA[<p>In this ISACA Podcast episode, we’ll delve into how leveraging Agile concepts can mitigate common challenges neurodiverse auditors face in the workplace. Neurodivergent auditors can bring a fresh and dynamic energy to projects if given appropriate accommodation.</p>
<p>Join us as ISACA's Robin Lyons chats with Program External Audit IT Program Manager Amanda Tucker as they explore small changes that can significantly impact not only neurodiverse individuals on your team but the entire team itself. </p>
]]></description>
                                                            <content:encoded><![CDATA[<p>In this ISACA Podcast episode, we’ll delve into how leveraging Agile concepts can mitigate common challenges neurodiverse auditors face in the workplace. Neurodivergent auditors can bring a fresh and dynamic energy to projects if given appropriate accommodation.</p>
<p>Join us as ISACA's Robin Lyons chats with Program External Audit IT Program Manager Amanda Tucker as they explore small changes that can significantly impact not only neurodiverse individuals on your team but the entire team itself. </p>
]]></content:encoded>
                                    
        <enclosure url="https://mcdn.podbean.com/mf/web/stbzgt/P_619_ISACA_Podcast_Amanda_Tucker_Audio_Only_FINAL6ckgg.mp3" length="27736377" type="audio/mpeg"/>
        <itunes:summary><![CDATA[In this ISACA Podcast episode, we’ll delve into how leveraging Agile concepts can mitigate common challenges neurodiverse auditors face in the workplace. Neurodivergent auditors can bring a fresh and dynamic energy to projects if given appropriate accommodation.
Join us as ISACA's Robin Lyons chats with Program External Audit IT Program Manager Amanda Tucker as they explore small changes that can significantly impact not only neurodiverse individuals on your team but the entire team itself. ]]></itunes:summary>
        <itunes:author>ISACA Podcast</itunes:author>
        <itunes:explicit>false</itunes:explicit>
        <itunes:block>No</itunes:block>
        <itunes:duration>1723</itunes:duration>
                <itunes:episode>294</itunes:episode>
        <itunes:episodeType>full</itunes:episodeType>
            </item>
    <item>
        <title>Minimizing Risk and Audit Requests</title>
        <itunes:title>Minimizing Risk and Audit Requests</itunes:title>
        <link>https://isacapodcast.podbean.com/e/minimizing-risk-and-audit-requests/</link>
                    <comments>https://isacapodcast.podbean.com/e/minimizing-risk-and-audit-requests/#comments</comments>        <pubDate>Wed, 03 Jan 2024 06:00:00 +0000</pubDate>
        <guid isPermaLink="false">isacapodcast.podbean.com/76b7ef83-2fbc-3d58-93e0-a3719de591c4</guid>
                                    <description><![CDATA[<p>With the increasing demand for audits and risk assessments, artifact requests will not be going away anytime soon. However, the burden these activities bring to the organization can be drastically reduced when audit and risk work together.</p>
<p>In this ISACA Podcast episode, Paul Phillips, Director of Event Content Development at ISACA, hosts Staff Governance, Risk, and Compliance Analyst Benjamin Bartz. Ben takes a deeper dive and elaborates on some of the must-haves for this partnership to live to its full potential.</p>
]]></description>
                                                            <content:encoded><![CDATA[<p>With the increasing demand for audits and risk assessments, artifact requests will not be going away anytime soon. However, the burden these activities bring to the organization can be drastically reduced when audit and risk work together.</p>
<p>In this ISACA Podcast episode, Paul Phillips, Director of Event Content Development at ISACA, hosts Staff Governance, Risk, and Compliance Analyst Benjamin Bartz. Ben takes a deeper dive and elaborates on some of the must-haves for this partnership to live to its full potential.</p>
]]></content:encoded>
                                    
        <enclosure url="https://mcdn.podbean.com/mf/web/3qexnw/P_661_ISACA_Podcast_Benjamin_Bartz_Audio_Onlya64fz.mp3" length="30816091" type="audio/mpeg"/>
        <itunes:summary><![CDATA[With the increasing demand for audits and risk assessments, artifact requests will not be going away anytime soon. However, the burden these activities bring to the organization can be drastically reduced when audit and risk work together.
In this ISACA Podcast episode, Paul Phillips, Director of Event Content Development at ISACA, hosts Staff Governance, Risk, and Compliance Analyst Benjamin Bartz. Ben takes a deeper dive and elaborates on some of the must-haves for this partnership to live to its full potential.]]></itunes:summary>
        <itunes:author>ISACA Podcast</itunes:author>
        <itunes:explicit>false</itunes:explicit>
        <itunes:block>No</itunes:block>
        <itunes:duration>1276</itunes:duration>
                <itunes:episode>290</itunes:episode>
        <itunes:episodeType>full</itunes:episodeType>
            </item>
    <item>
        <title>Issue Management Confidential: Tools and Best Practices for Improving IT Issue Management</title>
        <itunes:title>Issue Management Confidential: Tools and Best Practices for Improving IT Issue Management</itunes:title>
        <link>https://isacapodcast.podbean.com/e/issue-management-confidential-tools-and-best-practices-for-improving-it-issue-management/</link>
                    <comments>https://isacapodcast.podbean.com/e/issue-management-confidential-tools-and-best-practices-for-improving-it-issue-management/#comments</comments>        <pubDate>Wed, 27 Dec 2023 06:00:00 +0000</pubDate>
        <guid isPermaLink="false">isacapodcast.podbean.com/99fac1c2-44df-3fd7-b3ed-e19f48993c5d</guid>
                                    <description><![CDATA[<p>Effective IT issue management is crucial for organizations to mitigate financial loss, reputational damage, and operational disruptions. Issue management tools streamline the process by tracking and resolving issues, while risk rating helps prioritize responses based on their impact and likelihood.</p>
<p>In this ISACA Podcast episode, ISACA's GRC Professional Practices Principal, Lisa Cook chats with IT Risk Manager, Eric Peck about why acknowledging and addressing high-risk issues with a structured approach empowers organizations to protect themselves and ensure compliance in today's complex regulatory landscape.</p>
]]></description>
                                                            <content:encoded><![CDATA[<p>Effective IT issue management is crucial for organizations to mitigate financial loss, reputational damage, and operational disruptions. Issue management tools streamline the process by tracking and resolving issues, while risk rating helps prioritize responses based on their impact and likelihood.</p>
<p>In this ISACA Podcast episode, ISACA's GRC Professional Practices Principal, Lisa Cook chats with IT Risk Manager, Eric Peck about why acknowledging and addressing high-risk issues with a structured approach empowers organizations to protect themselves and ensure compliance in today's complex regulatory landscape.</p>
]]></content:encoded>
                                    
        <enclosure url="https://mcdn.podbean.com/mf/web/r5ki4g/616_ISACA_Podcast_Eric_Peck_Tools_and_Best_Practices_for_Improving_IT_Issue_Management_D17fl0v.mp3" length="41455592" type="audio/mpeg"/>
        <itunes:summary><![CDATA[Effective IT issue management is crucial for organizations to mitigate financial loss, reputational damage, and operational disruptions. Issue management tools streamline the process by tracking and resolving issues, while risk rating helps prioritize responses based on their impact and likelihood.
In this ISACA Podcast episode, ISACA's GRC Professional Practices Principal, Lisa Cook chats with IT Risk Manager, Eric Peck about why acknowledging and addressing high-risk issues with a structured approach empowers organizations to protect themselves and ensure compliance in today's complex regulatory landscape.]]></itunes:summary>
        <itunes:author>ISACA Podcast</itunes:author>
        <itunes:explicit>false</itunes:explicit>
        <itunes:block>No</itunes:block>
        <itunes:duration>1720</itunes:duration>
                <itunes:episode>292</itunes:episode>
        <itunes:episodeType>full</itunes:episodeType>
            </item>
    <item>
        <title>Improving Security while Enabling Market Access with CCF</title>
        <itunes:title>Improving Security while Enabling Market Access with CCF</itunes:title>
        <link>https://isacapodcast.podbean.com/e/improving-security-while-enabling-market-access-with-ccf-1702405984/</link>
                    <comments>https://isacapodcast.podbean.com/e/improving-security-while-enabling-market-access-with-ccf-1702405984/#comments</comments>        <pubDate>Wed, 13 Dec 2023 06:00:00 +0000</pubDate>
        <guid isPermaLink="false">isacapodcast.podbean.com/bdd837cc-191a-303c-99c7-15bdb9cb4bb7</guid>
                                    <description><![CDATA[<p>Software-as-a-Service (SaaS) providers continue to face increasing customer demand to attain security compliance certifications that demonstrate commitment to security, privacy, confidentiality, and more. Pursuing every national and international certification individually results in a repetitive cycle of ongoing walkthroughs, interviews, testing, and evidence requests (i.e., audits).</p>
<p>A central CCF can be considered a one-stop shop response to the complex alphabet soup of compliance standards on the market today.</p>
<p>In this ISACA Podcast episode, ISACA's Lisa Cook listens in as James Huang, Global Cloud Compliance Senior Manager, explains why having a central CCF can help various product engineering teams meet their security compliance needs and understand the level of effort required for each compliance certification.</p>
]]></description>
                                                            <content:encoded><![CDATA[<p>Software-as-a-Service (SaaS) providers continue to face increasing customer demand to attain security compliance certifications that demonstrate commitment to security, privacy, confidentiality, and more. Pursuing every national and international certification individually results in a repetitive cycle of ongoing walkthroughs, interviews, testing, and evidence requests (i.e., audits).</p>
<p>A central CCF can be considered a one-stop shop response to the complex alphabet soup of compliance standards on the market today.</p>
<p>In this ISACA Podcast episode, ISACA's Lisa Cook listens in as James Huang, Global Cloud Compliance Senior Manager, explains why having a central CCF can help various product engineering teams meet their security compliance needs and understand the level of effort required for each compliance certification.</p>
]]></content:encoded>
                                    
        <enclosure url="https://mcdn.podbean.com/mf/web/psvz5b/P_603_ISACA_Podcast_James_Huang_FINAL9dd7h.mp3" length="21635139" type="audio/mpeg"/>
        <itunes:summary><![CDATA[Software-as-a-Service (SaaS) providers continue to face increasing customer demand to attain security compliance certifications that demonstrate commitment to security, privacy, confidentiality, and more. Pursuing every national and international certification individually results in a repetitive cycle of ongoing walkthroughs, interviews, testing, and evidence requests (i.e., audits).
A central CCF can be considered a one-stop shop response to the complex alphabet soup of compliance standards on the market today.
In this ISACA Podcast episode, ISACA's Lisa Cook listens in as James Huang, Global Cloud Compliance Senior Manager, explains why having a central CCF can help various product engineering teams meet their security compliance needs and understand the level of effort required for each compliance certification.]]></itunes:summary>
        <itunes:author>ISACA Podcast</itunes:author>
        <itunes:explicit>false</itunes:explicit>
        <itunes:block>No</itunes:block>
        <itunes:duration>1342</itunes:duration>
                <itunes:episode>293</itunes:episode>
        <itunes:episodeType>full</itunes:episodeType>
            </item>
    <item>
        <title>Scaling Your Threat Modeling Program</title>
        <itunes:title>Scaling Your Threat Modeling Program</itunes:title>
        <link>https://isacapodcast.podbean.com/e/scaling-your-threat-modeling-program/</link>
                    <comments>https://isacapodcast.podbean.com/e/scaling-your-threat-modeling-program/#comments</comments>        <pubDate>Wed, 15 Nov 2023 06:00:00 +0000</pubDate>
        <guid isPermaLink="false">isacapodcast.podbean.com/d91463c7-8cdd-3343-9e73-a23631fd3a18</guid>
                                    <description><![CDATA[<p>Understanding product security risk starts before a single code line is written. Teams can discover threats to the architecture of a system early in the development life cycle with Threat Modeling. While it’s not a new concept, how do we transform traditional ways of Threat Modeling to meet the complexities of modern software development at scale?</p>
<p>In this ISACA Podcast episode, Chris McGowan chats with Lauren Strope, Manager of Application Security at Adobe. Lauren offers her expertise on strategies for scaling your program and provides unique perspectives on the future of Threat Modeling.</p>
<p>Learn more about Adobe at <a href='http://www.adobe.com'>www.adobe.com</a></p>
<p>For more ISACA Podcasts, please visit <a href='https://www.isaca.org/resources/news-and-trends/isaca-podcast-library'>https://www.isaca.org/resources/news-and-trends/isaca-podcast-library</a> </p>
]]></description>
                                                            <content:encoded><![CDATA[<p>Understanding product security risk starts before a single code line is written. Teams can discover threats to the architecture of a system early in the development life cycle with Threat Modeling. While it’s not a new concept, how do we transform traditional ways of Threat Modeling to meet the complexities of modern software development at scale?</p>
<p>In this ISACA Podcast episode, Chris McGowan chats with Lauren Strope, Manager of Application Security at Adobe. Lauren offers her expertise on strategies for scaling your program and provides unique perspectives on the future of Threat Modeling.</p>
<p>Learn more about Adobe at <a href='http://www.adobe.com'>www.adobe.com</a></p>
<p>For more ISACA Podcasts, please visit <a href='https://www.isaca.org/resources/news-and-trends/isaca-podcast-library'>https://www.isaca.org/resources/news-and-trends/isaca-podcast-library</a> </p>
]]></content:encoded>
                                    
        <enclosure url="https://mcdn.podbean.com/mf/web/nkm6y9/641_Adobe_November_Sponsored_Podcast_-_Scaling_Your_Threat_Modeling_Program_D1bkzv7.mp3" length="27258757" type="audio/mpeg"/>
        <itunes:summary><![CDATA[Understanding product security risk starts before a single code line is written. Teams can discover threats to the architecture of a system early in the development life cycle with Threat Modeling. While it’s not a new concept, how do we transform traditional ways of Threat Modeling to meet the complexities of modern software development at scale?
In this ISACA Podcast episode, Chris McGowan chats with Lauren Strope, Manager of Application Security at Adobe. Lauren offers her expertise on strategies for scaling your program and provides unique perspectives on the future of Threat Modeling.
Learn more about Adobe at www.adobe.com
For more ISACA Podcasts, please visit https://www.isaca.org/resources/news-and-trends/isaca-podcast-library ]]></itunes:summary>
        <itunes:author>ISACA Podcast</itunes:author>
        <itunes:explicit>false</itunes:explicit>
        <itunes:block>No</itunes:block>
        <itunes:duration>1125</itunes:duration>
                <itunes:episode>289</itunes:episode>
        <itunes:episodeType>full</itunes:episodeType>
            </item>
    <item>
        <title>Secure your Supply Chain with an Effective Vendor Security Program</title>
        <itunes:title>Secure your Supply Chain with an Effective Vendor Security Program</itunes:title>
        <link>https://isacapodcast.podbean.com/e/secure-your-supply-chain-with-an-effective-vendor-security-program/</link>
                    <comments>https://isacapodcast.podbean.com/e/secure-your-supply-chain-with-an-effective-vendor-security-program/#comments</comments>        <pubDate>Thu, 05 Oct 2023 06:00:00 +0000</pubDate>
        <guid isPermaLink="false">isacapodcast.podbean.com/ff3f40e2-8639-3dea-918c-04d88285da37</guid>
                                    <description><![CDATA[<p>Security risks introduced by vendors have become a top-of-mind concern for executives today, driven by recent supply chain incidents that have exposed organizations to operational and reputational risks.</p>
<p>A robust vendor security program is now a must, as it helps ensure compliance and proactively identifies and mitigates these risks throughout the vendor lifecycle. However, many vendor security teams today face an ever-growing backlog of security reviews, creating increased urgency and pressure for teams to maintain quality assessments. These reviews are often perceived as time-consuming in the procurement process, calling for a balance between meeting business demands and conducting thorough assessments to identify and isolate potential risks.</p>
<p>In this ISACA Podcast, Adobe's Manager of Vendor Security Nidhi Bandi shares about recent enhancements Adobe has made to calculate risk in the vendor space better and provides guidance on how you can stand up a strong vendor security program that balances procurement needs at your organization.</p>
<p>Learn more about Adobe at <a href='https://www.adobe.com/'>https://www.adobe.com/</a></p>
<p>Listen to more ISACA Podcasts at <a href='https://www.isaca.org/resources/news-and-trends/isaca-podcast-library'>https://www.isaca.org/resources/news-and-trends/isaca-podcast-library</a> </p>
]]></description>
                                                            <content:encoded><![CDATA[<p>Security risks introduced by vendors have become a top-of-mind concern for executives today, driven by recent supply chain incidents that have exposed organizations to operational and reputational risks.</p>
<p>A robust vendor security program is now a must, as it helps ensure compliance and proactively identifies and mitigates these risks throughout the vendor lifecycle. However, many vendor security teams today face an ever-growing backlog of security reviews, creating increased urgency and pressure for teams to maintain quality assessments. These reviews are often perceived as time-consuming in the procurement process, calling for a balance between meeting business demands and conducting thorough assessments to identify and isolate potential risks.</p>
<p>In this ISACA Podcast, Adobe's Manager of Vendor Security Nidhi Bandi shares about recent enhancements Adobe has made to calculate risk in the vendor space better and provides guidance on how you can stand up a strong vendor security program that balances procurement needs at your organization.</p>
<p>Learn more about Adobe at <a href='https://www.adobe.com/'>https://www.adobe.com/</a></p>
<p>Listen to more ISACA Podcasts at <a href='https://www.isaca.org/resources/news-and-trends/isaca-podcast-library'>https://www.isaca.org/resources/news-and-trends/isaca-podcast-library</a> </p>
]]></content:encoded>
                                    
        <enclosure url="https://mcdn.podbean.com/mf/web/ke7q53/604_ISACA_Podcast_Adobe_September_Sponsored_Podcast_D26pd17.mp3" length="22996403" type="audio/mpeg"/>
        <itunes:summary><![CDATA[Security risks introduced by vendors have become a top-of-mind concern for executives today, driven by recent supply chain incidents that have exposed organizations to operational and reputational risks.
A robust vendor security program is now a must, as it helps ensure compliance and proactively identifies and mitigates these risks throughout the vendor lifecycle. However, many vendor security teams today face an ever-growing backlog of security reviews, creating increased urgency and pressure for teams to maintain quality assessments. These reviews are often perceived as time-consuming in the procurement process, calling for a balance between meeting business demands and conducting thorough assessments to identify and isolate potential risks.
In this ISACA Podcast, Adobe's Manager of Vendor Security Nidhi Bandi shares about recent enhancements Adobe has made to calculate risk in the vendor space better and provides guidance on how you can stand up a strong vendor security program that balances procurement needs at your organization.
Learn more about Adobe at https://www.adobe.com/
Listen to more ISACA Podcasts at https://www.isaca.org/resources/news-and-trends/isaca-podcast-library ]]></itunes:summary>
        <itunes:author>ISACA Podcast</itunes:author>
        <itunes:explicit>false</itunes:explicit>
        <itunes:block>No</itunes:block>
        <itunes:duration>943</itunes:duration>
                <itunes:episode>288</itunes:episode>
        <itunes:episodeType>full</itunes:episodeType>
            </item>
    <item>
        <title>Cultivating Inspired Leaders with Kristi Hedges</title>
        <itunes:title>Cultivating Inspired Leaders with Kristi Hedges</itunes:title>
        <link>https://isacapodcast.podbean.com/e/cultivating-inspired-leaders-with-kristi-hedges/</link>
                    <comments>https://isacapodcast.podbean.com/e/cultivating-inspired-leaders-with-kristi-hedges/#comments</comments>        <pubDate>Tue, 03 Oct 2023 06:00:00 +0000</pubDate>
        <guid isPermaLink="false">isacapodcast.podbean.com/67a0beb2-bf1f-39f9-a039-17c01b531611</guid>
                                    <description><![CDATA[<p>If we want people to bring their most creative, innovative selves to work, we need to cultivate a culture where inspiration is given, encouraged, and fostered.</p>
<p> </p>
<p>In this ISACA Podcast, Kristi Hedges, executive coach, and leadership development consultant, speaker, and author, gives a sneak peek of her upcoming member-exclusive 'Cultivating Inspired Leaders, a CPE-eligible event. At the event, Kristi Hedges will provide a roadmap for building an inspired mindset for leaders, teams, and individuals.</p>
<p> </p>
<p>Register for this ISACA event at https://www.isaca.org/membership/member-exclusive-speaker-series</p>
]]></description>
                                                            <content:encoded><![CDATA[<p>If we want people to bring their most creative, innovative selves to work, we need to cultivate a culture where inspiration is given, encouraged, and fostered.</p>
<p> </p>
<p>In this ISACA Podcast, Kristi Hedges, executive coach, and leadership development consultant, speaker, and author, gives a sneak peek of her upcoming member-exclusive 'Cultivating Inspired Leaders, a CPE-eligible event. At the event, Kristi Hedges will provide a roadmap for building an inspired mindset for leaders, teams, and individuals.</p>
<p> </p>
<p>Register for this ISACA event at https://www.isaca.org/membership/member-exclusive-speaker-series</p>
]]></content:encoded>
                                    
        <enclosure url="https://mcdn.podbean.com/mf/web/rkzui5/629_Member-Exclusive_Speaker_Series_MESS_Podcast_-_Kristi_Hedges_D16pxnp.mp3" length="30671746" type="audio/mpeg"/>
        <itunes:summary><![CDATA[If we want people to bring their most creative, innovative selves to work, we need to cultivate a culture where inspiration is given, encouraged, and fostered.
 
In this ISACA Podcast, Kristi Hedges, executive coach, and leadership development consultant, speaker, and author, gives a sneak peek of her upcoming member-exclusive 'Cultivating Inspired Leaders, a CPE-eligible event. At the event, Kristi Hedges will provide a roadmap for building an inspired mindset for leaders, teams, and individuals.
 
Register for this ISACA event at https://www.isaca.org/membership/member-exclusive-speaker-series]]></itunes:summary>
        <itunes:author>ISACA Podcast</itunes:author>
        <itunes:explicit>false</itunes:explicit>
        <itunes:block>No</itunes:block>
        <itunes:duration>1271</itunes:duration>
                <itunes:episode>287</itunes:episode>
        <itunes:episodeType>full</itunes:episodeType>
            </item>
    <item>
        <title>Exploring the Benefits of Neurodiversity within Cybersecurity</title>
        <itunes:title>Exploring the Benefits of Neurodiversity within Cybersecurity</itunes:title>
        <link>https://isacapodcast.podbean.com/e/exploring-the-benefits-of-neurodiversity-within-cybersecurity/</link>
                    <comments>https://isacapodcast.podbean.com/e/exploring-the-benefits-of-neurodiversity-within-cybersecurity/#comments</comments>        <pubDate>Wed, 27 Sep 2023 16:07:00 +0000</pubDate>
        <guid isPermaLink="false">isacapodcast.podbean.com/d1008c4e-a1b0-3b01-b124-875a04a6fedb</guid>
                                    <description><![CDATA[<p>Neurodiversity within cybersecurity offers many benefits but requires organizations and hiring managers to re-evaluate hiring practices and job descriptions typically structured for neurotypical applicants.</p>
<p>Join ISACA's Director of Professional Practices and Innovation as he hosts a conversation with a company helping to remove barriers and maximize the value neurodiverse talent brings to cybersecurity.</p>
<p> </p>
<p>For more ISACA Podcast, go to <a href='https://www.isaca.org/resources/news-and-trends/isaca-podcast-library'>https://www.isaca.org/resources/news-and-trends/isaca-podcast-library</a> </p>
]]></description>
                                                            <content:encoded><![CDATA[<p>Neurodiversity within cybersecurity offers many benefits but requires organizations and hiring managers to re-evaluate hiring practices and job descriptions typically structured for neurotypical applicants.</p>
<p>Join ISACA's Director of Professional Practices and Innovation as he hosts a conversation with a company helping to remove barriers and maximize the value neurodiverse talent brings to cybersecurity.</p>
<p> </p>
<p>For more ISACA Podcast, go to <a href='https://www.isaca.org/resources/news-and-trends/isaca-podcast-library'>https://www.isaca.org/resources/news-and-trends/isaca-podcast-library</a> </p>
]]></content:encoded>
                                    
        <enclosure url="https://mcdn.podbean.com/mf/web/qcmhdd/P_574_Audio_Edit_d18fjb7.mp3" length="48957494" type="audio/mpeg"/>
        <itunes:summary><![CDATA[Neurodiversity within cybersecurity offers many benefits but requires organizations and hiring managers to re-evaluate hiring practices and job descriptions typically structured for neurotypical applicants.
Join ISACA's Director of Professional Practices and Innovation as he hosts a conversation with a company helping to remove barriers and maximize the value neurodiverse talent brings to cybersecurity.
 
For more ISACA Podcast, go to https://www.isaca.org/resources/news-and-trends/isaca-podcast-library ]]></itunes:summary>
        <itunes:author>ISACA Podcast</itunes:author>
        <itunes:explicit>false</itunes:explicit>
        <itunes:block>No</itunes:block>
        <itunes:duration>2038</itunes:duration>
                <itunes:episode>286</itunes:episode>
        <itunes:episodeType>full</itunes:episodeType>
            </item>
    <item>
        <title>Internal Audits That Create Stakeholder Value Adopting an Agile Mindset</title>
        <itunes:title>Internal Audits That Create Stakeholder Value Adopting an Agile Mindset</itunes:title>
        <link>https://isacapodcast.podbean.com/e/internal-audits-that-create-stakeholder-value-adopting-an-agile-mindset/</link>
                    <comments>https://isacapodcast.podbean.com/e/internal-audits-that-create-stakeholder-value-adopting-an-agile-mindset/#comments</comments>        <pubDate>Wed, 16 Aug 2023 09:00:00 +0000</pubDate>
        <guid isPermaLink="false">isacapodcast.podbean.com/fd7f2314-663b-3ec9-a393-0e53b6769f03</guid>
                                    <description><![CDATA[<p>Agile Scrum is a lightweight framework that promises to significantly improve internal audits by creating a mindset that generates stakeholder value through adaptive solutions for complex auditing problems. This mindset is needed as organizations face unprecedented changes and pressures in today's business landscape. Internal audits must keep leaders informed and aware of potential risks.</p>
<p>Such a mindset addresses some of the often-experienced auditing challenges such as a lack of senior management support, insufficient audit preparation time, difficult auditees and lack of time needed to write audit results.</p>
<p>Featuring special guest Thomas Bell and hosted by ISACA's Robin Lyons.</p>
]]></description>
                                                            <content:encoded><![CDATA[<p>Agile Scrum is a lightweight framework that promises to significantly improve internal audits by creating a mindset that generates stakeholder value through adaptive solutions for complex auditing problems. This mindset is needed as organizations face unprecedented changes and pressures in today's business landscape. Internal audits must keep leaders informed and aware of potential risks.</p>
<p>Such a mindset addresses some of the often-experienced auditing challenges such as a lack of senior management support, insufficient audit preparation time, difficult auditees and lack of time needed to write audit results.</p>
<p>Featuring special guest Thomas Bell and hosted by ISACA's Robin Lyons.</p>
]]></content:encoded>
                                    
        <enclosure url="https://mcdn.podbean.com/mf/web/6nyyab/P_514_Audio_Edit_d199q1c.mp3" length="31929484" type="audio/mpeg"/>
        <itunes:summary><![CDATA[Agile Scrum is a lightweight framework that promises to significantly improve internal audits by creating a mindset that generates stakeholder value through adaptive solutions for complex auditing problems. This mindset is needed as organizations face unprecedented changes and pressures in today's business landscape. Internal audits must keep leaders informed and aware of potential risks.
Such a mindset addresses some of the often-experienced auditing challenges such as a lack of senior management support, insufficient audit preparation time, difficult auditees and lack of time needed to write audit results.
Featuring special guest Thomas Bell and hosted by ISACA's Robin Lyons.]]></itunes:summary>
        <itunes:author>ISACA Podcast</itunes:author>
        <itunes:explicit>false</itunes:explicit>
        <itunes:block>No</itunes:block>
        <itunes:duration>1329</itunes:duration>
                <itunes:episode>285</itunes:episode>
        <itunes:episodeType>full</itunes:episodeType>
            </item>
    <item>
        <title>Strategies for Avoiding Burnout</title>
        <itunes:title>Strategies for Avoiding Burnout</itunes:title>
        <link>https://isacapodcast.podbean.com/e/strategies-for-avoiding-burnout/</link>
                    <comments>https://isacapodcast.podbean.com/e/strategies-for-avoiding-burnout/#comments</comments>        <pubDate>Wed, 09 Aug 2023 09:00:00 +0000</pubDate>
        <guid isPermaLink="false">isacapodcast.podbean.com/d528b01f-e40e-341a-a117-50e275ea6cb4</guid>
                                    <description><![CDATA[<p>Chronic workplace stress can lead to burnout, which poses a significant risk to the mental health of busy professionals, such as auditors. But how can these professionals protect themselves from burnout? And how can their employers help them do so? If you are interested in learning the answers to these questions, then watch as ISACA’s Robin Lyons and Dr. Elena Klevsky, Assistant Professor of Accounting at the University of Tampa, discuss strategies for avoiding burnout.</p>
<p>Inspired by the Sustainable Model of Human Energy proposed by Ryan Quinn, Gretchen Spreitzer and Chak Fu Lam, these strategies focus on managing your personal energy by increasing resources, decreasing job demands, practicing skills and tasks, and monitoring energy.</p>
<p>Properly implementing these strategies has the potential to help busy professionals ensure that they have sufficient resources to meet their job demands, and, therefore, increase the likelihood that they feel energized instead of exhausted.</p>
]]></description>
                                                            <content:encoded><![CDATA[<p>Chronic workplace stress can lead to burnout, which poses a significant risk to the mental health of busy professionals, such as auditors. But how can these professionals protect themselves from burnout? And how can their employers help them do so? If you are interested in learning the answers to these questions, then watch as ISACA’s Robin Lyons and Dr. Elena Klevsky, Assistant Professor of Accounting at the University of Tampa, discuss strategies for avoiding burnout.</p>
<p>Inspired by the Sustainable Model of Human Energy proposed by Ryan Quinn, Gretchen Spreitzer and Chak Fu Lam, these strategies focus on managing your personal energy by increasing resources, decreasing job demands, practicing skills and tasks, and monitoring energy.</p>
<p>Properly implementing these strategies has the potential to help busy professionals ensure that they have sufficient resources to meet their job demands, and, therefore, increase the likelihood that they feel energized instead of exhausted.</p>
]]></content:encoded>
                                    
        <enclosure url="https://mcdn.podbean.com/mf/web/5ti7jy/P_565_Audio_Edit_d163g5z.mp3" length="38418670" type="audio/mpeg"/>
        <itunes:summary><![CDATA[Chronic workplace stress can lead to burnout, which poses a significant risk to the mental health of busy professionals, such as auditors. But how can these professionals protect themselves from burnout? And how can their employers help them do so? If you are interested in learning the answers to these questions, then watch as ISACA’s Robin Lyons and Dr. Elena Klevsky, Assistant Professor of Accounting at the University of Tampa, discuss strategies for avoiding burnout.
Inspired by the Sustainable Model of Human Energy proposed by Ryan Quinn, Gretchen Spreitzer and Chak Fu Lam, these strategies focus on managing your personal energy by increasing resources, decreasing job demands, practicing skills and tasks, and monitoring energy.
Properly implementing these strategies has the potential to help busy professionals ensure that they have sufficient resources to meet their job demands, and, therefore, increase the likelihood that they feel energized instead of exhausted.]]></itunes:summary>
        <itunes:author>ISACA Podcast</itunes:author>
        <itunes:explicit>false</itunes:explicit>
        <itunes:block>No</itunes:block>
        <itunes:duration>1599</itunes:duration>
                <itunes:episode>284</itunes:episode>
        <itunes:episodeType>full</itunes:episodeType>
            </item>
    <item>
        <title>The Danger of Distraction in Augmented Reality</title>
        <itunes:title>The Danger of Distraction in Augmented Reality</itunes:title>
        <link>https://isacapodcast.podbean.com/e/the-danger-of-distraction-in-augmented-reality/</link>
                    <comments>https://isacapodcast.podbean.com/e/the-danger-of-distraction-in-augmented-reality/#comments</comments>        <pubDate>Wed, 02 Aug 2023 09:00:00 +0000</pubDate>
        <guid isPermaLink="false">isacapodcast.podbean.com/f2fcab88-e76b-3aca-b0b5-65aa4cb28f4f</guid>
                                    <description><![CDATA[<p>While users of technology are becoming more educated in how to avoid cyberattacks such as phishing, a distracted user might be more prone to missing signs of social engineering. This project explored whether users immersed in augmented reality applications were more inclined to fall for an on-screen text message that prompted familiarity (such as a friend calling in) or urgency (such as a warning to update software or be subject to an automatic device re-boot within a certain timeframe).</p>
<p>Featuring special guest Sarah Katz and hosted by ISACA's Collin Beder.</p>
]]></description>
                                                            <content:encoded><![CDATA[<p>While users of technology are becoming more educated in how to avoid cyberattacks such as phishing, a distracted user might be more prone to missing signs of social engineering. This project explored whether users immersed in augmented reality applications were more inclined to fall for an on-screen text message that prompted familiarity (such as a friend calling in) or urgency (such as a warning to update software or be subject to an automatic device re-boot within a certain timeframe).</p>
<p>Featuring special guest Sarah Katz and hosted by ISACA's Collin Beder.</p>
]]></content:encoded>
                                    
        <enclosure url="https://mcdn.podbean.com/mf/web/hz594m/P_572_Audio_Edit_Generic_Article_Title_d175rxs.mp3" length="31142362" type="audio/mpeg"/>
        <itunes:summary><![CDATA[While users of technology are becoming more educated in how to avoid cyberattacks such as phishing, a distracted user might be more prone to missing signs of social engineering. This project explored whether users immersed in augmented reality applications were more inclined to fall for an on-screen text message that prompted familiarity (such as a friend calling in) or urgency (such as a warning to update software or be subject to an automatic device re-boot within a certain timeframe).
Featuring special guest Sarah Katz and hosted by ISACA's Collin Beder.]]></itunes:summary>
        <itunes:author>ISACA Podcast</itunes:author>
        <itunes:explicit>false</itunes:explicit>
        <itunes:block>No</itunes:block>
        <itunes:duration>1295</itunes:duration>
                <itunes:episode>283</itunes:episode>
        <itunes:episodeType>full</itunes:episodeType>
            </item>
    <item>
        <title>Managing Human Risk Requires More Than Just Awareness Training</title>
        <itunes:title>Managing Human Risk Requires More Than Just Awareness Training</itunes:title>
        <link>https://isacapodcast.podbean.com/e/managing-human-risk-requires-more-than-just-awareness-training/</link>
                    <comments>https://isacapodcast.podbean.com/e/managing-human-risk-requires-more-than-just-awareness-training/#comments</comments>        <pubDate>Wed, 26 Jul 2023 17:00:00 +0000</pubDate>
        <guid isPermaLink="false">isacapodcast.podbean.com/e402856a-08f9-370c-ac58-5afca30627cd</guid>
                                    <description><![CDATA[<p>A comprehensive information security awareness program must be in place to ensure that employees are aware of and educated about the threats they may encounter at the workplace. The workforce needs to be prepared to know how to respond to these threats. It all starts with a risk assessment to identity the most critical of risks that need to be mitigated through preparedness. Making security a part of the organization’s culture reduces these risks to an acceptable level.</p>
<p>Featuring special guest Chris Madeksho and hosted by ISACA's Lisa Cook.</p>
]]></description>
                                                            <content:encoded><![CDATA[<p>A comprehensive information security awareness program must be in place to ensure that employees are aware of and educated about the threats they may encounter at the workplace. The workforce needs to be prepared to know how to respond to these threats. It all starts with a risk assessment to identity the most critical of risks that need to be mitigated through preparedness. Making security a part of the organization’s culture reduces these risks to an acceptable level.</p>
<p>Featuring special guest Chris Madeksho and hosted by ISACA's Lisa Cook.</p>
]]></content:encoded>
                                    
        <enclosure url="https://mcdn.podbean.com/mf/web/afnd5f/P_573_Audio_Edit_d185ikp.mp3" length="30814907" type="audio/mpeg"/>
        <itunes:summary><![CDATA[A comprehensive information security awareness program must be in place to ensure that employees are aware of and educated about the threats they may encounter at the workplace. The workforce needs to be prepared to know how to respond to these threats. It all starts with a risk assessment to identity the most critical of risks that need to be mitigated through preparedness. Making security a part of the organization’s culture reduces these risks to an acceptable level.
Featuring special guest Chris Madeksho and hosted by ISACA's Lisa Cook.]]></itunes:summary>
        <itunes:author>ISACA Podcast</itunes:author>
        <itunes:explicit>false</itunes:explicit>
        <itunes:block>No</itunes:block>
        <itunes:duration>1282</itunes:duration>
                <itunes:episode>282</itunes:episode>
        <itunes:episodeType>full</itunes:episodeType>
            </item>
    <item>
        <title>Preparing for Interruptions, Disruptions and Emergence Events</title>
        <itunes:title>Preparing for Interruptions, Disruptions and Emergence Events</itunes:title>
        <link>https://isacapodcast.podbean.com/e/preparing-for-interruptions-disruptions-and-emergence-events/</link>
                    <comments>https://isacapodcast.podbean.com/e/preparing-for-interruptions-disruptions-and-emergence-events/#comments</comments>        <pubDate>Wed, 19 Jul 2023 10:00:00 +0000</pubDate>
        <guid isPermaLink="false">isacapodcast.podbean.com/7f5741fa-af74-3f4d-8a66-24870b7f343d</guid>
                                    <description><![CDATA[<p>This podcast speaks about how an Information Systems (IS) Auditor can prepare for the Interruptions, Disruptions and the Emergence events that happen to the business and to technology.</p>
<p>Describing the features of Interruptions, Disruptions and Emergence events and distinguishing the differences between them, special guest Anantha Sayana outlines how the IS Auditor can prepare, react, and contribute to all the three.</p>
<p>Hosted by ISACA's Hollee Mangrum-Willis.</p>
]]></description>
                                                            <content:encoded><![CDATA[<p>This podcast speaks about how an Information Systems (IS) Auditor can prepare for the Interruptions, Disruptions and the Emergence events that happen to the business and to technology.</p>
<p>Describing the features of Interruptions, Disruptions and Emergence events and distinguishing the differences between them, special guest Anantha Sayana outlines how the IS Auditor can prepare, react, and contribute to all the three.</p>
<p>Hosted by ISACA's Hollee Mangrum-Willis.</p>
]]></content:encoded>
                                    
        <enclosure url="https://mcdn.podbean.com/mf/web/dkw2a5/P_581_Audio_Edit_d16n5ez.mp3" length="34866905" type="audio/mpeg"/>
        <itunes:summary><![CDATA[This podcast speaks about how an Information Systems (IS) Auditor can prepare for the Interruptions, Disruptions and the Emergence events that happen to the business and to technology.
Describing the features of Interruptions, Disruptions and Emergence events and distinguishing the differences between them, special guest Anantha Sayana outlines how the IS Auditor can prepare, react, and contribute to all the three.
Hosted by ISACA's Hollee Mangrum-Willis.]]></itunes:summary>
        <itunes:author>ISACA Podcast</itunes:author>
        <itunes:explicit>false</itunes:explicit>
        <itunes:block>No</itunes:block>
        <itunes:duration>2160</itunes:duration>
                <itunes:episode>281</itunes:episode>
        <itunes:episodeType>full</itunes:episodeType>
            </item>
    <item>
        <title>IS Audit in Practice: Data Integrity On Demand</title>
        <itunes:title>IS Audit in Practice: Data Integrity On Demand</itunes:title>
        <link>https://isacapodcast.podbean.com/e/is-audit-in-practice-data-integrity-on-demand/</link>
                    <comments>https://isacapodcast.podbean.com/e/is-audit-in-practice-data-integrity-on-demand/#comments</comments>        <pubDate>Tue, 11 Jul 2023 10:00:00 +0000</pubDate>
        <guid isPermaLink="false">isacapodcast.podbean.com/5986a7a6-c1fc-3fb1-88e2-3447a709f459</guid>
                                    <description><![CDATA[<p>On this podcast, ISACA's Hollee Mangrum-Willis and special guest Cindy Baxter discuss the disparities between American communities and access to electronic health records. From there, they examine how key data insights from the ISACA community can help us all be healthier.</p>
]]></description>
                                                            <content:encoded><![CDATA[<p>On this podcast, ISACA's Hollee Mangrum-Willis and special guest Cindy Baxter discuss the disparities between American communities and access to electronic health records. From there, they examine how key data insights from the ISACA community can help us all be healthier.</p>
]]></content:encoded>
                                    
        <enclosure url="https://mcdn.podbean.com/mf/web/m384wq/P_510_Audio_Edit_d161n8u.mp3" length="59591777" type="audio/mpeg"/>
        <itunes:summary><![CDATA[On this podcast, ISACA's Hollee Mangrum-Willis and special guest Cindy Baxter discuss the disparities between American communities and access to electronic health records. From there, they examine how key data insights from the ISACA community can help us all be healthier.]]></itunes:summary>
        <itunes:author>ISACA Podcast</itunes:author>
        <itunes:explicit>false</itunes:explicit>
        <itunes:block>No</itunes:block>
        <itunes:duration>2481</itunes:duration>
                <itunes:episode>280</itunes:episode>
        <itunes:episodeType>full</itunes:episodeType>
            </item>
    <item>
        <title>ISACA Live | Digital Trust Priorities for Privacy and Emerging Tech</title>
        <itunes:title>ISACA Live | Digital Trust Priorities for Privacy and Emerging Tech</itunes:title>
        <link>https://isacapodcast.podbean.com/e/isaca-live-digital-trust-priorities-for-privacy-and-emerging-tech/</link>
                    <comments>https://isacapodcast.podbean.com/e/isaca-live-digital-trust-priorities-for-privacy-and-emerging-tech/#comments</comments>        <pubDate>Wed, 28 Jun 2023 15:00:00 +0000</pubDate>
        <guid isPermaLink="false">isacapodcast.podbean.com/4aff0035-5d59-3b9c-8191-5571dd9a81bb</guid>
                                    <description><![CDATA[<p>ISACA Digital Trust Advisory Council Members Anne Toth and Michelle Finneran Dennedy will discuss privacy concerns and priorities around emerging tech and the most critical considerations for ensuring strong digital trust. Hosted by ISACA's Safia Kazi. </p>
]]></description>
                                                            <content:encoded><![CDATA[<p>ISACA Digital Trust Advisory Council Members Anne Toth and Michelle Finneran Dennedy will discuss privacy concerns and priorities around emerging tech and the most critical considerations for ensuring strong digital trust. Hosted by ISACA's Safia Kazi. </p>
]]></content:encoded>
                                    
        <enclosure url="https://mcdn.podbean.com/mf/web/7cdv8e/P_447_Audio_Edit_d1bgfbv.mp3" length="41670021" type="audio/mpeg"/>
        <itunes:summary><![CDATA[ISACA Digital Trust Advisory Council Members Anne Toth and Michelle Finneran Dennedy will discuss privacy concerns and priorities around emerging tech and the most critical considerations for ensuring strong digital trust. Hosted by ISACA's Safia Kazi. ]]></itunes:summary>
        <itunes:author>ISACA Podcast</itunes:author>
        <itunes:explicit>false</itunes:explicit>
        <itunes:block>No</itunes:block>
        <itunes:duration>1734</itunes:duration>
                <itunes:episode>279</itunes:episode>
        <itunes:episodeType>full</itunes:episodeType>
            </item>
    <item>
        <title>Processes of Engagement with Scott Gould</title>
        <itunes:title>Processes of Engagement with Scott Gould</itunes:title>
        <link>https://isacapodcast.podbean.com/e/processes-of-engagement-with-scott-gould/</link>
                    <comments>https://isacapodcast.podbean.com/e/processes-of-engagement-with-scott-gould/#comments</comments>        <pubDate>Wed, 21 Jun 2023 14:00:00 +0000</pubDate>
        <guid isPermaLink="false">isacapodcast.podbean.com/e0cc7c2e-c49b-36ba-ad66-ef44939a4123</guid>
                                    <description><![CDATA[<p>Scott Gould is the author of 'The Shape of Engagement: The Simple Process Behind how Engagement Works.' In this podcast, Scott gives a sneak peak at his upcoming member-exclusive, CPE-eligible event. Scott will discuss the essential frameworks for understanding and operationalizing engagement and building enduring connections with your networks and communities.</p>
]]></description>
                                                            <content:encoded><![CDATA[<p>Scott Gould is the author of 'The Shape of Engagement: The Simple Process Behind how Engagement Works.' In this podcast, Scott gives a sneak peak at his upcoming member-exclusive, CPE-eligible event. Scott will discuss the essential frameworks for understanding and operationalizing engagement and building enduring connections with your networks and communities.</p>
]]></content:encoded>
                                    
        <enclosure url="https://mcdn.podbean.com/mf/web/4f6mh4/P_508_Audio_Edit_d1ab3hu.mp3" length="34672398" type="audio/mpeg"/>
        <itunes:summary><![CDATA[Scott Gould is the author of 'The Shape of Engagement: The Simple Process Behind how Engagement Works.' In this podcast, Scott gives a sneak peak at his upcoming member-exclusive, CPE-eligible event. Scott will discuss the essential frameworks for understanding and operationalizing engagement and building enduring connections with your networks and communities.]]></itunes:summary>
        <itunes:author>ISACA Podcast</itunes:author>
        <itunes:explicit>false</itunes:explicit>
        <itunes:block>No</itunes:block>
        <itunes:duration>1436</itunes:duration>
                <itunes:episode>278</itunes:episode>
        <itunes:episodeType>full</itunes:episodeType>
            </item>
    <item>
        <title>Delivering Security Value to Product Teams Using the Power of Data</title>
        <itunes:title>Delivering Security Value to Product Teams Using the Power of Data</itunes:title>
        <link>https://isacapodcast.podbean.com/e/delivering-security-value-to-product-teams-using-the-power-of-data/</link>
                    <comments>https://isacapodcast.podbean.com/e/delivering-security-value-to-product-teams-using-the-power-of-data/#comments</comments>        <pubDate>Tue, 13 Jun 2023 08:00:00 +0000</pubDate>
        <guid isPermaLink="false">isacapodcast.podbean.com/65f35c02-a8a8-3fd8-bb19-a9023410be6d</guid>
                                    <description><![CDATA[<p>In security, aligning with product teams has never been more important, especially when outmaneuvering adversaries. To foster a truly productive and action-oriented cybersecurity culture, security teams must begin addressing their product engineering counterparts as customers they serve rather than entities they govern.</p>
<p>In this podcast, ISACA’s Chris McGowan listens in as Adobe’s Manager of Adversary Intelligence Gurpartap “GP” Sandhu provides unique insight into how he’s bringing intrapreneurship to life in product security through a key project that delivers actionable data that product teams can use to enhance their security posture more rapidly.</p>
<p>They’ll also discuss how his team is harnessing strong adversary focus using the power of data and share advice on how you can stay ahead of adversaries by better predicting their next move in the ever-changing threat landscape. Tune into this ISACA Podcast to learn more!</p>
<p>Check out more from Adobe, <a href='https://www.adobe.com/trust.html'>https://www.adobe.com/trust.html </a></p>
<p>For more ISACA podcasts, <a href='http://www.isaca.org/podcasts'>www.isaca.org/podcasts</a></p>
<p> </p>
]]></description>
                                                            <content:encoded><![CDATA[<p>In security, aligning with product teams has never been more important, especially when outmaneuvering adversaries. To foster a truly productive and action-oriented cybersecurity culture, security teams must begin addressing their product engineering counterparts as customers they serve rather than entities they govern.</p>
<p>In this podcast, ISACA’s Chris McGowan listens in as Adobe’s Manager of Adversary Intelligence Gurpartap “GP” Sandhu provides unique insight into how he’s bringing intrapreneurship to life in product security through a key project that delivers actionable data that product teams can use to enhance their security posture more rapidly.</p>
<p>They’ll also discuss how his team is harnessing strong adversary focus using the power of data and share advice on how you can stay ahead of adversaries by better predicting their next move in the ever-changing threat landscape. Tune into this ISACA Podcast to learn more!</p>
<p>Check out more from Adobe, <a href='https://www.adobe.com/trust.html'>https://www.adobe.com/trust.html </a></p>
<p>For more ISACA podcasts, <a href='http://www.isaca.org/podcasts'>www.isaca.org/podcasts</a></p>
<p> </p>
]]></content:encoded>
                                    
        <enclosure url="https://mcdn.podbean.com/mf/web/2zczu7/P_445_Audio_Edit_d181bf7.mp3" length="31729801" type="audio/mpeg"/>
        <itunes:summary><![CDATA[In security, aligning with product teams has never been more important, especially when outmaneuvering adversaries. To foster a truly productive and action-oriented cybersecurity culture, security teams must begin addressing their product engineering counterparts as customers they serve rather than entities they govern.
In this podcast, ISACA’s Chris McGowan listens in as Adobe’s Manager of Adversary Intelligence Gurpartap “GP” Sandhu provides unique insight into how he’s bringing intrapreneurship to life in product security through a key project that delivers actionable data that product teams can use to enhance their security posture more rapidly.
They’ll also discuss how his team is harnessing strong adversary focus using the power of data and share advice on how you can stay ahead of adversaries by better predicting their next move in the ever-changing threat landscape. Tune into this ISACA Podcast to learn more!
Check out more from Adobe, https://www.adobe.com/trust.html 
For more ISACA podcasts, www.isaca.org/podcasts
 ]]></itunes:summary>
        <itunes:author>ISACA Podcast</itunes:author>
        <itunes:explicit>false</itunes:explicit>
        <itunes:block>No</itunes:block>
        <itunes:duration>1320</itunes:duration>
                <itunes:episode>277</itunes:episode>
        <itunes:episodeType>full</itunes:episodeType>
            </item>
    <item>
        <title>AI Ethics and the Role of IT Auditors</title>
        <itunes:title>AI Ethics and the Role of IT Auditors</itunes:title>
        <link>https://isacapodcast.podbean.com/e/ai-ethics-and-the-role-of-it-auditors/</link>
                    <comments>https://isacapodcast.podbean.com/e/ai-ethics-and-the-role-of-it-auditors/#comments</comments>        <pubDate>Tue, 06 Jun 2023 09:00:00 +0000</pubDate>
        <guid isPermaLink="false">isacapodcast.podbean.com/3c8938fc-d092-386c-b0d9-ca2c954adf46</guid>
                                    <description><![CDATA[<p>We, as a society, have always lived by certain norms that are driven by our communities. These norms are enforced by rules and regulations, societal influence and public interactions. But is the same true for artificial intelligence (AI)?</p>
<p>In this podcast we discuss and explore the answers to some of the key questions related to the rapid adoption of AI, such as: What are the risks associated with AI and the impact of its increasing adaption within almost every industry? And, what role should we as IT Auditors should play in this fast changing technological landscape?</p>
<p>Hosted by ISACA's Hollee Mangrum-Willis and featuring special guest Jai Sisodia.</p>
]]></description>
                                                            <content:encoded><![CDATA[<p>We, as a society, have always lived by certain norms that are driven by our communities. These norms are enforced by rules and regulations, societal influence and public interactions. But is the same true for artificial intelligence (AI)?</p>
<p>In this podcast we discuss and explore the answers to some of the key questions related to the rapid adoption of AI, such as: What are the risks associated with AI and the impact of its increasing adaption within almost every industry? And, what role should we as IT Auditors should play in this fast changing technological landscape?</p>
<p>Hosted by ISACA's Hollee Mangrum-Willis and featuring special guest Jai Sisodia.</p>
]]></content:encoded>
                                    
        <enclosure url="https://mcdn.podbean.com/mf/web/53akr3/P_513_Audio_Edit_d17i9vu.mp3" length="43438922" type="audio/mpeg"/>
        <itunes:summary><![CDATA[We, as a society, have always lived by certain norms that are driven by our communities. These norms are enforced by rules and regulations, societal influence and public interactions. But is the same true for artificial intelligence (AI)?
In this podcast we discuss and explore the answers to some of the key questions related to the rapid adoption of AI, such as: What are the risks associated with AI and the impact of its increasing adaption within almost every industry? And, what role should we as IT Auditors should play in this fast changing technological landscape?
Hosted by ISACA's Hollee Mangrum-Willis and featuring special guest Jai Sisodia.]]></itunes:summary>
        <itunes:author>ISACA Podcast</itunes:author>
        <itunes:explicit>false</itunes:explicit>
        <itunes:block>No</itunes:block>
        <itunes:duration>1808</itunes:duration>
                <itunes:episode>276</itunes:episode>
        <itunes:episodeType>full</itunes:episodeType>
            </item>
    <item>
        <title>Using a Risk-Based Approach to Prioritize Vulnerability Remediation</title>
        <itunes:title>Using a Risk-Based Approach to Prioritize Vulnerability Remediation</itunes:title>
        <link>https://isacapodcast.podbean.com/e/using-a-risk-based-approach-to-prioritize-vulnerability-remediation/</link>
                    <comments>https://isacapodcast.podbean.com/e/using-a-risk-based-approach-to-prioritize-vulnerability-remediation/#comments</comments>        <pubDate>Thu, 01 Jun 2023 08:00:00 +0000</pubDate>
        <guid isPermaLink="false">isacapodcast.podbean.com/6a02d44a-830d-3945-8389-79df3ba3b150</guid>
                                    <description><![CDATA[<p>Organizations today struggle with vulnerability management. More specifically, remediating vulnerabilities in a timely manner poses a challenge. With vulnerability remediation backlogs growing at an alarming rate, what can organizations do to meet their established remediation timelines and to protect the organization from cybersecurity threats. Cybersecurity leader Ray Payano will discuss the exponential increase in published vulnerabilities, the lack of resources in cybersecurity to perform remediation and balancing remediation with reduced maintenance windows. These challenges contribute to organizations struggling with remediation backlogs. Ray will explain how calculating vulnerability risk can help organizations prioritize their vulnerabilities based on risk level to help determine the order in which vulnerabilities are addressed.</p>
<p>Hosted by ISACA's Chris McGowan.</p>
]]></description>
                                                            <content:encoded><![CDATA[<p>Organizations today struggle with vulnerability management. More specifically, remediating vulnerabilities in a timely manner poses a challenge. With vulnerability remediation backlogs growing at an alarming rate, what can organizations do to meet their established remediation timelines and to protect the organization from cybersecurity threats. Cybersecurity leader Ray Payano will discuss the exponential increase in published vulnerabilities, the lack of resources in cybersecurity to perform remediation and balancing remediation with reduced maintenance windows. These challenges contribute to organizations struggling with remediation backlogs. Ray will explain how calculating vulnerability risk can help organizations prioritize their vulnerabilities based on risk level to help determine the order in which vulnerabilities are addressed.</p>
<p>Hosted by ISACA's Chris McGowan.</p>
]]></content:encoded>
                                    
        <enclosure url="https://mcdn.podbean.com/mf/web/hbja9y/P_502_Audio_Edit_d1a9o1d.mp3" length="26818244" type="audio/mpeg"/>
        <itunes:summary><![CDATA[Organizations today struggle with vulnerability management. More specifically, remediating vulnerabilities in a timely manner poses a challenge. With vulnerability remediation backlogs growing at an alarming rate, what can organizations do to meet their established remediation timelines and to protect the organization from cybersecurity threats. Cybersecurity leader Ray Payano will discuss the exponential increase in published vulnerabilities, the lack of resources in cybersecurity to perform remediation and balancing remediation with reduced maintenance windows. These challenges contribute to organizations struggling with remediation backlogs. Ray will explain how calculating vulnerability risk can help organizations prioritize their vulnerabilities based on risk level to help determine the order in which vulnerabilities are addressed.
Hosted by ISACA's Chris McGowan.]]></itunes:summary>
        <itunes:author>ISACA Podcast</itunes:author>
        <itunes:explicit>false</itunes:explicit>
        <itunes:block>No</itunes:block>
        <itunes:duration>1673</itunes:duration>
                <itunes:episode>275</itunes:episode>
        <itunes:episodeType>full</itunes:episodeType>
            </item>
    <item>
        <title>The True Cost of a Data Breach</title>
        <itunes:title>The True Cost of a Data Breach</itunes:title>
        <link>https://isacapodcast.podbean.com/e/the-true-cost-of-a-data-breach/</link>
                    <comments>https://isacapodcast.podbean.com/e/the-true-cost-of-a-data-breach/#comments</comments>        <pubDate>Tue, 23 May 2023 08:00:00 +0000</pubDate>
        <guid isPermaLink="false">isacapodcast.podbean.com/bc8f2426-9501-336c-a4fc-db2cd77a2833</guid>
                                    <description><![CDATA[<p>Guests Jack Freund and Natalie Jorion discuss the need for additional data for quantitative risk analyses and methods to derive that data when it does not exist. They cover how this was done in the past and their updated method for interpolation of such data from record losses and other firmographic data. They end with a discussion of the role of model validation and how it can enable reliable risk management decision making.</p>
<p>Hosted by ISACA's Safia Kazi.</p>
]]></description>
                                                            <content:encoded><![CDATA[<p>Guests Jack Freund and Natalie Jorion discuss the need for additional data for quantitative risk analyses and methods to derive that data when it does not exist. They cover how this was done in the past and their updated method for interpolation of such data from record losses and other firmographic data. They end with a discussion of the role of model validation and how it can enable reliable risk management decision making.</p>
<p>Hosted by ISACA's Safia Kazi.</p>
]]></content:encoded>
                                    
        <enclosure url="https://mcdn.podbean.com/mf/web/8apayp/P_521_Audio_Edit_d16ezi5.mp3" length="46098698" type="audio/mpeg"/>
        <itunes:summary><![CDATA[Guests Jack Freund and Natalie Jorion discuss the need for additional data for quantitative risk analyses and methods to derive that data when it does not exist. They cover how this was done in the past and their updated method for interpolation of such data from record losses and other firmographic data. They end with a discussion of the role of model validation and how it can enable reliable risk management decision making.
Hosted by ISACA's Safia Kazi.]]></itunes:summary>
        <itunes:author>ISACA Podcast</itunes:author>
        <itunes:explicit>false</itunes:explicit>
        <itunes:block>No</itunes:block>
        <itunes:duration>1918</itunes:duration>
                <itunes:episode>274</itunes:episode>
        <itunes:episodeType>full</itunes:episodeType>
            </item>
    <item>
        <title>2023 IT Compliance and Risk Benchmark Report</title>
        <itunes:title>2023 IT Compliance and Risk Benchmark Report</itunes:title>
        <link>https://isacapodcast.podbean.com/e/2023-it-compliance-and-risk-benchmark-report/</link>
                    <comments>https://isacapodcast.podbean.com/e/2023-it-compliance-and-risk-benchmark-report/#comments</comments>        <pubDate>Tue, 16 May 2023 10:00:00 +0000</pubDate>
        <guid isPermaLink="false">isacapodcast.podbean.com/763344dc-41ac-36ea-a8b2-4a9086c55246</guid>
                                    <description><![CDATA[<p>Are you wondering about the ever-changing landscape of IT compliance and risk management? Look no further. Hyperproof, a leading SaaS compliance operations provider, conducts an annual survey of over 1,000 IT risk, compliance, and security professionals to uncover their top challenges. Tune in to this exclusive episode to hear about the top five most important statistics uncovered from the survey and get an overview of how your industry peers are managing IT risk and compliance programs within their organizations.</p>
<p>We’ll cover:</p>
<p>● The top five findings from the survey</p>
<p>● How your peers are planning to handle compliance, audit management, and risk management in the midst of this year’s volatile economy</p>
<p>● What companies are doing differently in response to recent and highly publicized security breaches to avoid security lapses and compliance violations</p>
<p> </p>
<p>Download Hyperproof’s 2023 IT Compliance and Risk Benchmark Report https://hyperproof.io/it-compliance-benchmarks/</p>
]]></description>
                                                            <content:encoded><![CDATA[<p>Are you wondering about the ever-changing landscape of IT compliance and risk management? Look no further. Hyperproof, a leading SaaS compliance operations provider, conducts an annual survey of over 1,000 IT risk, compliance, and security professionals to uncover their top challenges. Tune in to this exclusive episode to hear about the top five most important statistics uncovered from the survey and get an overview of how your industry peers are managing IT risk and compliance programs within their organizations.</p>
<p>We’ll cover:</p>
<p>● The top five findings from the survey</p>
<p>● How your peers are planning to handle compliance, audit management, and risk management in the midst of this year’s volatile economy</p>
<p>● What companies are doing differently in response to recent and highly publicized security breaches to avoid security lapses and compliance violations</p>
<p> </p>
<p>Download Hyperproof’s 2023 IT Compliance and Risk Benchmark Report https://hyperproof.io/it-compliance-benchmarks/</p>
]]></content:encoded>
                                    
        <enclosure url="https://mcdn.podbean.com/mf/web/b757ew/P_444_Audio_Edit_d169bns.mp3" length="35529569" type="audio/mpeg"/>
        <itunes:summary><![CDATA[Are you wondering about the ever-changing landscape of IT compliance and risk management? Look no further. Hyperproof, a leading SaaS compliance operations provider, conducts an annual survey of over 1,000 IT risk, compliance, and security professionals to uncover their top challenges. Tune in to this exclusive episode to hear about the top five most important statistics uncovered from the survey and get an overview of how your industry peers are managing IT risk and compliance programs within their organizations.
We’ll cover:
● The top five findings from the survey
● How your peers are planning to handle compliance, audit management, and risk management in the midst of this year’s volatile economy
● What companies are doing differently in response to recent and highly publicized security breaches to avoid security lapses and compliance violations
 
Download Hyperproof’s 2023 IT Compliance and Risk Benchmark Report https://hyperproof.io/it-compliance-benchmarks/]]></itunes:summary>
        <itunes:author>ISACA Podcast</itunes:author>
        <itunes:explicit>false</itunes:explicit>
        <itunes:block>No</itunes:block>
        <itunes:duration>1479</itunes:duration>
                <itunes:episode>273</itunes:episode>
        <itunes:episodeType>full</itunes:episodeType>
            </item>
    <item>
        <title>What Kind of Glasses Are You Wearing? Your View of Risk May Be Your Biggest Risk of All</title>
        <itunes:title>What Kind of Glasses Are You Wearing? Your View of Risk May Be Your Biggest Risk of All</itunes:title>
        <link>https://isacapodcast.podbean.com/e/what-kind-of-glasses-are-you-wearing-your-view-of-risk-may-be-your-biggest-risk-of-all/</link>
                    <comments>https://isacapodcast.podbean.com/e/what-kind-of-glasses-are-you-wearing-your-view-of-risk-may-be-your-biggest-risk-of-all/#comments</comments>        <pubDate>Tue, 09 May 2023 16:00:00 +0000</pubDate>
        <guid isPermaLink="false">isacapodcast.podbean.com/1fe0d77b-9792-3858-ae38-918997143adb</guid>
                                    <description><![CDATA[<p>The world of business has changed dramatically over the past few years. Our digital world is more connected than ever, leaving security and technology teams stretched even thinner. Privacy and data regulations are increasing on a state and national level, threat actors are learning and evolving, and cybersecurity has finally become a boardroom priority! Now that you have leadership’s attention- what will you do? If your answer is “risk management as usual”, that may be holding you back.</p>
<p>Traditional risk management approaches make a lot of promises, but most of them are myths. Do any of these sound familiar?</p>
<p>● You can make better-informed decisions by using a single platform.</p>
<p>● You can use automation to achieve continuous compliance.</p>
<p>● You can implement risk management by creating a risk register.</p>
<p>● You can use qualitative attributes to measure and assess risk.</p>
<p>In this episode, we’ll assess risk management myths and discuss how to establish scalable, quantifiable, and always-on risk management for the future.</p>
<p> </p>
<p>Hosted by Lisa Cook and featuring special guest Megan Maneval.</p>
]]></description>
                                                            <content:encoded><![CDATA[<p>The world of business has changed dramatically over the past few years. Our digital world is more connected than ever, leaving security and technology teams stretched even thinner. Privacy and data regulations are increasing on a state and national level, threat actors are learning and evolving, and cybersecurity has finally become a boardroom priority! Now that you have leadership’s attention- what will you do? If your answer is “risk management as usual”, that may be holding you back.</p>
<p>Traditional risk management approaches make a lot of promises, but most of them are myths. Do any of these sound familiar?</p>
<p>● You can make better-informed decisions by using a single platform.</p>
<p>● You can use automation to achieve continuous compliance.</p>
<p>● You can implement risk management by creating a risk register.</p>
<p>● You can use qualitative attributes to measure and assess risk.</p>
<p>In this episode, we’ll assess risk management myths and discuss how to establish scalable, quantifiable, and always-on risk management for the future.</p>
<p> </p>
<p>Hosted by Lisa Cook and featuring special guest Megan Maneval.</p>
]]></content:encoded>
                                    
        <enclosure url="https://mcdn.podbean.com/mf/web/pafhpu/P_507_Audio_Edit_d1aljoy.mp3" length="40400567" type="audio/mpeg"/>
        <itunes:summary><![CDATA[The world of business has changed dramatically over the past few years. Our digital world is more connected than ever, leaving security and technology teams stretched even thinner. Privacy and data regulations are increasing on a state and national level, threat actors are learning and evolving, and cybersecurity has finally become a boardroom priority! Now that you have leadership’s attention- what will you do? If your answer is “risk management as usual”, that may be holding you back.
Traditional risk management approaches make a lot of promises, but most of them are myths. Do any of these sound familiar?
● You can make better-informed decisions by using a single platform.
● You can use automation to achieve continuous compliance.
● You can implement risk management by creating a risk register.
● You can use qualitative attributes to measure and assess risk.
In this episode, we’ll assess risk management myths and discuss how to establish scalable, quantifiable, and always-on risk management for the future.
 
Hosted by Lisa Cook and featuring special guest Megan Maneval.]]></itunes:summary>
        <itunes:author>ISACA Podcast</itunes:author>
        <itunes:explicit>false</itunes:explicit>
        <itunes:block>No</itunes:block>
        <itunes:duration>1682</itunes:duration>
                <itunes:episode>272</itunes:episode>
        <itunes:episodeType>full</itunes:episodeType>
            </item>
    <item>
        <title>How Organizations Can Consistently Reduce Cyberrisk</title>
        <itunes:title>How Organizations Can Consistently Reduce Cyberrisk</itunes:title>
        <link>https://isacapodcast.podbean.com/e/how-organizations-can-consistently-reduce-cyberrisk/</link>
                    <comments>https://isacapodcast.podbean.com/e/how-organizations-can-consistently-reduce-cyberrisk/#comments</comments>        <pubDate>Thu, 04 May 2023 09:00:00 +0000</pubDate>
        <guid isPermaLink="false">isacapodcast.podbean.com/eeffa2df-10a1-3b0c-85e7-f8078a10e69a</guid>
                                    <description><![CDATA[<p>Cyber threats are now a “clear and present danger” to most organizations, companies and governments of the world. A good cyber defense involves many, intricate layers. You can never have enough layers, just like you can never remove all the risk. In order for organizations to reduce as much risk as possible, in a rapidly shifting threat landscape, they must constantly make improvements. The threat groups are making rapid improvements and increasing their expertise at a steady rate. They are investing  in R&D and Zero-Day exploits. To offer a good defense, we must make progress at the same rate as the threat groups or we may fall behind, increasing risks and allowing the cyber world to become like the “wild-wild west.”</p>
]]></description>
                                                            <content:encoded><![CDATA[<p>Cyber threats are now a “clear and present danger” to most organizations, companies and governments of the world. A good cyber defense involves many, intricate layers. You can never have enough layers, just like you can never remove all the risk. In order for organizations to reduce as much risk as possible, in a rapidly shifting threat landscape, they must constantly make improvements. The threat groups are making rapid improvements and increasing their expertise at a steady rate. They are investing  in R&D and Zero-Day exploits. To offer a good defense, we must make progress at the same rate as the threat groups or we may fall behind, increasing risks and allowing the cyber world to become like the “wild-wild west.”</p>
]]></content:encoded>
                                    
        <enclosure url="https://mcdn.podbean.com/mf/web/mkuq4n/P_515_Audio_Edit_d187ztt.mp3" length="46752085" type="audio/mpeg"/>
        <itunes:summary><![CDATA[Cyber threats are now a “clear and present danger” to most organizations, companies and governments of the world. A good cyber defense involves many, intricate layers. You can never have enough layers, just like you can never remove all the risk. In order for organizations to reduce as much risk as possible, in a rapidly shifting threat landscape, they must constantly make improvements. The threat groups are making rapid improvements and increasing their expertise at a steady rate. They are investing  in R&D and Zero-Day exploits. To offer a good defense, we must make progress at the same rate as the threat groups or we may fall behind, increasing risks and allowing the cyber world to become like the “wild-wild west.”]]></itunes:summary>
        <itunes:author>ISACA Podcast</itunes:author>
        <itunes:explicit>false</itunes:explicit>
        <itunes:block>No</itunes:block>
        <itunes:duration>1946</itunes:duration>
                <itunes:episode>271</itunes:episode>
        <itunes:episodeType>full</itunes:episodeType>
            </item>
    <item>
        <title>Key Considerations for Conducting Remote IT Audits</title>
        <itunes:title>Key Considerations for Conducting Remote IT Audits</itunes:title>
        <link>https://isacapodcast.podbean.com/e/key-considerations-for-conducting-remote-it-audits/</link>
                    <comments>https://isacapodcast.podbean.com/e/key-considerations-for-conducting-remote-it-audits/#comments</comments>        <pubDate>Tue, 02 May 2023 09:00:00 +0000</pubDate>
        <guid isPermaLink="false">isacapodcast.podbean.com/60d45f93-dce9-303c-bc69-b6482d66147e</guid>
                                    <description><![CDATA[<p>Conducting adequate preparation including risk assessments, assessing resource requirements and ensuring ongoing communication to harness both the benefits and to address the potential challenges faced when conducting hybrid or fully virtual audits.</p>
]]></description>
                                                            <content:encoded><![CDATA[<p>Conducting adequate preparation including risk assessments, assessing resource requirements and ensuring ongoing communication to harness both the benefits and to address the potential challenges faced when conducting hybrid or fully virtual audits.</p>
]]></content:encoded>
                                    
        <enclosure url="https://mcdn.podbean.com/mf/web/54g9dr/P_491_Audio_Edit_d19q8uc.mp3" length="24407500" type="audio/mpeg"/>
        <itunes:summary><![CDATA[Conducting adequate preparation including risk assessments, assessing resource requirements and ensuring ongoing communication to harness both the benefits and to address the potential challenges faced when conducting hybrid or fully virtual audits.]]></itunes:summary>
        <itunes:author>ISACA Podcast</itunes:author>
        <itunes:explicit>false</itunes:explicit>
        <itunes:block>No</itunes:block>
        <itunes:duration>1016</itunes:duration>
                <itunes:episode>270</itunes:episode>
        <itunes:episodeType>full</itunes:episodeType>
            </item>
    <item>
        <title>Seven Things to Know Before Automating IT General Control Audits</title>
        <itunes:title>Seven Things to Know Before Automating IT General Control Audits</itunes:title>
        <link>https://isacapodcast.podbean.com/e/seven-things-to-know-before-automating-it-general-control-audits/</link>
                    <comments>https://isacapodcast.podbean.com/e/seven-things-to-know-before-automating-it-general-control-audits/#comments</comments>        <pubDate>Thu, 27 Apr 2023 10:00:00 +0000</pubDate>
        <guid isPermaLink="false">isacapodcast.podbean.com/647e795f-35df-3309-89e5-3e9524af245b</guid>
                                    <description><![CDATA[<p>This podcast is a practical discussion with two IT Internal Auditors, Frans Geldenhuys and Gustav Silvo, that have automated IT General Controls across their highly diversified and decentralized group. They will share some of the pitfalls they have experienced in their automation roll out and advise on how to avoid or manage these pitfalls with host, Robin Lyons.</p>
<p>Check out Frans and Gustav’s full ISACA Industry News article, “Seven Things to Know Before Automating IT General Control Audits,” <a href='http://www.isaca.org/automating-it-general-control-audits'>http://www.isaca.org/automating-it-general-control-audits</a></p>
<p>For more ISACA Podcasts, <a href='https://www.isaca.org/podcasts'>https://www.isaca.org/podcasts</a></p>
<p> </p>
]]></description>
                                                            <content:encoded><![CDATA[<p>This podcast is a practical discussion with two IT Internal Auditors, Frans Geldenhuys and Gustav Silvo, that have automated IT General Controls across their highly diversified and decentralized group. They will share some of the pitfalls they have experienced in their automation roll out and advise on how to avoid or manage these pitfalls with host, Robin Lyons.</p>
<p>Check out Frans and Gustav’s full ISACA Industry News article, “Seven Things to Know Before Automating IT General Control Audits,” <a href='http://www.isaca.org/automating-it-general-control-audits'>http://www.isaca.org/automating-it-general-control-audits</a></p>
<p>For more ISACA Podcasts, <a href='https://www.isaca.org/podcasts'>https://www.isaca.org/podcasts</a></p>
<p> </p>
]]></content:encoded>
                                    
        <enclosure url="https://mcdn.podbean.com/mf/web/9iaj74/P_479_Frans_and_Gustav_Audio_Edit_d2997hk.mp3" length="48704296" type="audio/mpeg"/>
        <itunes:summary><![CDATA[This podcast is a practical discussion with two IT Internal Auditors, Frans Geldenhuys and Gustav Silvo, that have automated IT General Controls across their highly diversified and decentralized group. They will share some of the pitfalls they have experienced in their automation roll out and advise on how to avoid or manage these pitfalls with host, Robin Lyons.
Check out Frans and Gustav’s full ISACA Industry News article, “Seven Things to Know Before Automating IT General Control Audits,” http://www.isaca.org/automating-it-general-control-audits
For more ISACA Podcasts, https://www.isaca.org/podcasts
 ]]></itunes:summary>
        <itunes:author>ISACA Podcast</itunes:author>
        <itunes:explicit>false</itunes:explicit>
        <itunes:block>No</itunes:block>
        <itunes:duration>2026</itunes:duration>
                <itunes:episode>269</itunes:episode>
        <itunes:episodeType>full</itunes:episodeType>
            </item>
    <item>
        <title>Understanding, Assessing, Aligning and Transforming Organizational Culture</title>
        <itunes:title>Understanding, Assessing, Aligning and Transforming Organizational Culture</itunes:title>
        <link>https://isacapodcast.podbean.com/e/understanding-assessing-aligning-and-transforming-organizational-culture/</link>
                    <comments>https://isacapodcast.podbean.com/e/understanding-assessing-aligning-and-transforming-organizational-culture/#comments</comments>        <pubDate>Thu, 20 Apr 2023 09:00:00 +0000</pubDate>
        <guid isPermaLink="false">isacapodcast.podbean.com/432f2d71-28de-3589-8134-d6734179d7d6</guid>
                                    <description><![CDATA[<p>Organizational culture is crucial because it shapes behaviors and attitudes in the workplace, which can profoundly impact operations and overall success. However, it is sometimes difficult for CISOs and other infosec managers to fully understand their culture because they are inside it constantly.</p>
<p>In this ISACA Podcast episode, author and journalist Mark Tarallo chats with ISACA's Safia Kazi about how infosec managers can assess the organizational culture by using a culture model to examine the behaviors, relationships, attitudes, values, and environment that the culture sustains. It also discusses possible ways to lead a culture change initiative.</p>
<p>To read Mark's full ISACA Journal article, "Understanding, Assessing, Aligning and Transforming Organizational Culture," click the link <a href='https://www.isaca.org/organizational-culture'>https://www.isaca.org/organizational-culture </a></p>
<p>For more ISACA Podcasts: <a href='https://www.isaca.org/podcasts'>https://www.isaca.org/podcasts</a> </p>
]]></description>
                                                            <content:encoded><![CDATA[<p>Organizational culture is crucial because it shapes behaviors and attitudes in the workplace, which can profoundly impact operations and overall success. However, it is sometimes difficult for CISOs and other infosec managers to fully understand their culture because they are inside it constantly.</p>
<p>In this ISACA Podcast episode, author and journalist Mark Tarallo chats with ISACA's Safia Kazi about how infosec managers can assess the organizational culture by using a culture model to examine the behaviors, relationships, attitudes, values, and environment that the culture sustains. It also discusses possible ways to lead a culture change initiative.</p>
<p>To read Mark's full ISACA Journal article, "Understanding, Assessing, Aligning and Transforming Organizational Culture," click the link <a href='https://www.isaca.org/organizational-culture'>https://www.isaca.org/organizational-culture </a></p>
<p>For more ISACA Podcasts: <a href='https://www.isaca.org/podcasts'>https://www.isaca.org/podcasts</a> </p>
]]></content:encoded>
                                    
        <enclosure url="https://mcdn.podbean.com/mf/web/56uwak/P_469_Mark_Tarello_Audio_Edit_d29mn0n.mp3" length="41949097" type="audio/mpeg"/>
        <itunes:summary><![CDATA[Organizational culture is crucial because it shapes behaviors and attitudes in the workplace, which can profoundly impact operations and overall success. However, it is sometimes difficult for CISOs and other infosec managers to fully understand their culture because they are inside it constantly.
In this ISACA Podcast episode, author and journalist Mark Tarallo chats with ISACA's Safia Kazi about how infosec managers can assess the organizational culture by using a culture model to examine the behaviors, relationships, attitudes, values, and environment that the culture sustains. It also discusses possible ways to lead a culture change initiative.
To read Mark's full ISACA Journal article, "Understanding, Assessing, Aligning and Transforming Organizational Culture," click the link https://www.isaca.org/organizational-culture 
For more ISACA Podcasts: https://www.isaca.org/podcasts ]]></itunes:summary>
        <itunes:author>ISACA Podcast</itunes:author>
        <itunes:explicit>false</itunes:explicit>
        <itunes:block>No</itunes:block>
        <itunes:duration>1743</itunes:duration>
                <itunes:episode>268</itunes:episode>
        <itunes:episodeType>full</itunes:episodeType>
            </item>
    <item>
        <title>Topics in Emerging Technology, Governance and Ethics</title>
        <itunes:title>Topics in Emerging Technology, Governance and Ethics</itunes:title>
        <link>https://isacapodcast.podbean.com/e/topics-in-emerging-technology-governance-and-ethics/</link>
                    <comments>https://isacapodcast.podbean.com/e/topics-in-emerging-technology-governance-and-ethics/#comments</comments>        <pubDate>Tue, 18 Apr 2023 08:00:00 +0000</pubDate>
        <guid isPermaLink="false">isacapodcast.podbean.com/ca921dab-6f26-307c-96e6-f3b13c3e044a</guid>
                                    <description><![CDATA[<p>What are the primary risks associated with the adoption of emerging technologies, particularly during periods of high market volatility and changing governance requirements? We talk with Samuel Zaruba Smith, PhD(c) about his learnings from working in government regulated industries and emerging technology. We deep dive into the problems of business strategy, security, policy, social engineering ethics, and audits within a business environment of emerging technology systems such as Artificial Intelligence and Web3 decentralized technologies. Given the current business landscape of early 2023, changing market conditions and rapidly evolving governance concerns need to be top of the mind for all organizational leaders. Samuel provides insightful recommendations for improving your organizational structure and technology governance to create a more productive, inclusive, and ethical workplace. </p>
]]></description>
                                                            <content:encoded><![CDATA[<p>What are the primary risks associated with the adoption of emerging technologies, particularly during periods of high market volatility and changing governance requirements? We talk with Samuel Zaruba Smith, PhD(c) about his learnings from working in government regulated industries and emerging technology. We deep dive into the problems of business strategy, security, policy, social engineering ethics, and audits within a business environment of emerging technology systems such as Artificial Intelligence and Web3 decentralized technologies. Given the current business landscape of early 2023, changing market conditions and rapidly evolving governance concerns need to be top of the mind for all organizational leaders. Samuel provides insightful recommendations for improving your organizational structure and technology governance to create a more productive, inclusive, and ethical workplace. </p>
]]></content:encoded>
                                    
        <enclosure url="https://mcdn.podbean.com/mf/web/fe3uu4/P_462_Audio_Edit_d1arfq7.mp3" length="47948006" type="audio/mpeg"/>
        <itunes:summary><![CDATA[What are the primary risks associated with the adoption of emerging technologies, particularly during periods of high market volatility and changing governance requirements? We talk with Samuel Zaruba Smith, PhD(c) about his learnings from working in government regulated industries and emerging technology. We deep dive into the problems of business strategy, security, policy, social engineering ethics, and audits within a business environment of emerging technology systems such as Artificial Intelligence and Web3 decentralized technologies. Given the current business landscape of early 2023, changing market conditions and rapidly evolving governance concerns need to be top of the mind for all organizational leaders. Samuel provides insightful recommendations for improving your organizational structure and technology governance to create a more productive, inclusive, and ethical workplace. ]]></itunes:summary>
        <itunes:author>ISACA Podcast</itunes:author>
        <itunes:explicit>false</itunes:explicit>
        <itunes:block>No</itunes:block>
        <itunes:duration>1993</itunes:duration>
                <itunes:episode>267</itunes:episode>
        <itunes:episodeType>full</itunes:episodeType>
            </item>
    <item>
        <title>Industry Spotlight - Julia Kanouse</title>
        <itunes:title>Industry Spotlight - Julia Kanouse</itunes:title>
        <link>https://isacapodcast.podbean.com/e/industry-spotlight-julia-kanouse/</link>
                    <comments>https://isacapodcast.podbean.com/e/industry-spotlight-julia-kanouse/#comments</comments>        <pubDate>Tue, 11 Apr 2023 13:56:26 +0000</pubDate>
        <guid isPermaLink="false">isacapodcast.podbean.com/5b5beded-2c38-3fb2-be46-eeb41b20b405</guid>
                                    <description><![CDATA[<p>Get to know Chief Membership and Marketing Officer Julia Kanouse as she sits down with childhood best friend and ISACA VP Amanda Raible. The duo discuss everything from leadership to motherhood while competing in Mario Kart! Tune in!</p>
]]></description>
                                                            <content:encoded><![CDATA[<p>Get to know Chief Membership and Marketing Officer Julia Kanouse as she sits down with childhood best friend and ISACA VP Amanda Raible. The duo discuss everything from leadership to motherhood while competing in Mario Kart! Tune in!</p>
]]></content:encoded>
                                    
        <enclosure url="https://mcdn.podbean.com/mf/web/x4mq3t/P_435_Full_Podcast_Edit_Audio_Only_No_Mario6k3ud.mp3" length="32257270" type="audio/mpeg"/>
        <itunes:summary><![CDATA[Get to know Chief Membership and Marketing Officer Julia Kanouse as she sits down with childhood best friend and ISACA VP Amanda Raible. The duo discuss everything from leadership to motherhood while competing in Mario Kart! Tune in!]]></itunes:summary>
        <itunes:author>ISACA Podcast</itunes:author>
        <itunes:explicit>false</itunes:explicit>
        <itunes:block>No</itunes:block>
        <itunes:duration>1314</itunes:duration>
                <itunes:episode>266</itunes:episode>
        <itunes:episodeType>full</itunes:episodeType>
            </item>
    <item>
        <title>What Is Your IP Address Cybersecurity IQ? The Role of IP Address Data in a Digital World</title>
        <itunes:title>What Is Your IP Address Cybersecurity IQ? The Role of IP Address Data in a Digital World</itunes:title>
        <link>https://isacapodcast.podbean.com/e/what-is-your-ip-address-cybersecurity-iq-the-role-of-ip-address-data-in-a-digital-world/</link>
                    <comments>https://isacapodcast.podbean.com/e/what-is-your-ip-address-cybersecurity-iq-the-role-of-ip-address-data-in-a-digital-world/#comments</comments>        <pubDate>Tue, 04 Apr 2023 15:00:00 +0000</pubDate>
        <guid isPermaLink="false">isacapodcast.podbean.com/e44775cd-6922-3344-a3a2-0a9b95e5309a</guid>
                                    <description><![CDATA[<p>There are literally thousands of VPN services on the market. Some are undeniably benign, but others offer a slate of features that are friendly to cyber criminals. Keeping your network safe from hackers requires you to understand the VPN market, and make decisions based on your company’s appetite for risk. Fortunately, by analyzing IP address data associated with these devices, security professionals can get access to a wealth of VPN contextual data that helps them distinguish between perfectly legitimate providers and those that turn a blind eye toward crime. In today’s world, it is vital for security professionals to know how to leverage IP address data and its contextual insights to protect enterprise networks.</p>
]]></description>
                                                            <content:encoded><![CDATA[<p>There are literally thousands of VPN services on the market. Some are undeniably benign, but others offer a slate of features that are friendly to cyber criminals. Keeping your network safe from hackers requires you to understand the VPN market, and make decisions based on your company’s appetite for risk. Fortunately, by analyzing IP address data associated with these devices, security professionals can get access to a wealth of VPN contextual data that helps them distinguish between perfectly legitimate providers and those that turn a blind eye toward crime. In today’s world, it is vital for security professionals to know how to leverage IP address data and its contextual insights to protect enterprise networks.</p>
]]></content:encoded>
                                    
        <enclosure url="https://mcdn.podbean.com/mf/web/dx9g5e/P_470_Jonathan_Tomek_Audio_Edit_d19yk24.mp3" length="40838215" type="audio/mpeg"/>
        <itunes:summary><![CDATA[There are literally thousands of VPN services on the market. Some are undeniably benign, but others offer a slate of features that are friendly to cyber criminals. Keeping your network safe from hackers requires you to understand the VPN market, and make decisions based on your company’s appetite for risk. Fortunately, by analyzing IP address data associated with these devices, security professionals can get access to a wealth of VPN contextual data that helps them distinguish between perfectly legitimate providers and those that turn a blind eye toward crime. In today’s world, it is vital for security professionals to know how to leverage IP address data and its contextual insights to protect enterprise networks.]]></itunes:summary>
        <itunes:author>ISACA Podcast</itunes:author>
        <itunes:explicit>false</itunes:explicit>
        <itunes:block>No</itunes:block>
        <itunes:duration>1700</itunes:duration>
                <itunes:episode>265</itunes:episode>
        <itunes:episodeType>full</itunes:episodeType>
            </item>
    <item>
        <title>The Future of Technology Risk: 4 Ways to Build Stakeholder Trust in the Technology Risk Imperative</title>
        <itunes:title>The Future of Technology Risk: 4 Ways to Build Stakeholder Trust in the Technology Risk Imperative</itunes:title>
        <link>https://isacapodcast.podbean.com/e/the-future-of-technology-risk-4-ways-to-build-stakeholder-trust-in-the-technology-risk-imperative/</link>
                    <comments>https://isacapodcast.podbean.com/e/the-future-of-technology-risk-4-ways-to-build-stakeholder-trust-in-the-technology-risk-imperative/#comments</comments>        <pubDate>Tue, 21 Mar 2023 10:00:00 +0000</pubDate>
        <guid isPermaLink="false">isacapodcast.podbean.com/e5edd1e9-c28f-3733-a8a8-a4da49e7310d</guid>
                                    <description><![CDATA[<p>Today, the pace of change across industries is quicker than ever before. Economic, political, and social unrest and a global climate crisis have placed unprecedented disruption and pressures on organizations looking to navigate a rapidly changing environment.</p>
<p>Firms are being out-innovated and entire industries are being disrupted in a matter of months or years, as opposed to decades. Shifting regulations, data as an asset, dynamic customer behavior and employee expectations of continued flexibility in a more virtual workplace add to the challenge.</p>
<p>Technology risk and compliance needs to adjust to this new reality. The strategy and value of an organization’s technology risk management are becoming essential to build and secure stakeholder trust. That means moving closer to the point where the risk events occur and using preventative, detective, and automated controls as much as possible.</p>
<p>In this podcast, Beth McKenney, a Principal in the KPMG Technology Risk service network, offers a game plan for companies to meet these today’s challenges with an eye on building stakeholder trust. That means having a proactive, rather than a reactive, approach to risk management.</p>
]]></description>
                                                            <content:encoded><![CDATA[<p>Today, the pace of change across industries is quicker than ever before. Economic, political, and social unrest and a global climate crisis have placed unprecedented disruption and pressures on organizations looking to navigate a rapidly changing environment.</p>
<p>Firms are being out-innovated and entire industries are being disrupted in a matter of months or years, as opposed to decades. Shifting regulations, data as an asset, dynamic customer behavior and employee expectations of continued flexibility in a more virtual workplace add to the challenge.</p>
<p>Technology risk and compliance needs to adjust to this new reality. The strategy and value of an organization’s technology risk management are becoming essential to build and secure stakeholder trust. That means moving closer to the point where the risk events occur and using preventative, detective, and automated controls as much as possible.</p>
<p>In this podcast, Beth McKenney, a Principal in the KPMG Technology Risk service network, offers a game plan for companies to meet these today’s challenges with an eye on building stakeholder trust. That means having a proactive, rather than a reactive, approach to risk management.</p>
]]></content:encoded>
                                    
        <enclosure url="https://mcdn.podbean.com/mf/web/g75uar/P_442_Audio_Edit_d17yj0q.mp3" length="36824625" type="audio/mpeg"/>
        <itunes:summary><![CDATA[Today, the pace of change across industries is quicker than ever before. Economic, political, and social unrest and a global climate crisis have placed unprecedented disruption and pressures on organizations looking to navigate a rapidly changing environment.
Firms are being out-innovated and entire industries are being disrupted in a matter of months or years, as opposed to decades. Shifting regulations, data as an asset, dynamic customer behavior and employee expectations of continued flexibility in a more virtual workplace add to the challenge.
Technology risk and compliance needs to adjust to this new reality. The strategy and value of an organization’s technology risk management are becoming essential to build and secure stakeholder trust. That means moving closer to the point where the risk events occur and using preventative, detective, and automated controls as much as possible.
In this podcast, Beth McKenney, a Principal in the KPMG Technology Risk service network, offers a game plan for companies to meet these today’s challenges with an eye on building stakeholder trust. That means having a proactive, rather than a reactive, approach to risk management.]]></itunes:summary>
        <itunes:author>ISACA Podcast</itunes:author>
        <itunes:explicit>false</itunes:explicit>
        <itunes:block>No</itunes:block>
        <itunes:duration>1532</itunes:duration>
                <itunes:episode>264</itunes:episode>
        <itunes:episodeType>full</itunes:episodeType>
            </item>
    <item>
        <title>Measuring Security Resilience from the Lens of the Adversary Community</title>
        <itunes:title>Measuring Security Resilience from the Lens of the Adversary Community</itunes:title>
        <link>https://isacapodcast.podbean.com/e/measuring-security-resilience-from-the-lens-of-the-adversary-community/</link>
                    <comments>https://isacapodcast.podbean.com/e/measuring-security-resilience-from-the-lens-of-the-adversary-community/#comments</comments>        <pubDate>Tue, 14 Mar 2023 10:00:00 +0000</pubDate>
        <guid isPermaLink="false">isacapodcast.podbean.com/7b17fe11-08c2-367e-8772-187e9021e6ab</guid>
                                    <description><![CDATA[<p>In a world where adversaries are constantly adapting to improve tactics, techniques, and procedures (TTPs), it is crucial to understand the unique traits and goals of various types of adversaries that actively seek to cause harm to an organization. The personification of these threats will ultimately help measure resilience against specific threat actors, identify investment and hardening opportunities, and improve trust with customers.</p>
<p>In this podcast, Daniel Ventura, Manager of Product Security Incident Response Team (PSIRT), shares insight into Adobe’s approach to adversary personification as well as provides guidance on how you can better measure the security resilience of your products. He’ll also talk about Adobe’s bug bounty program which helps his team identify new trends in adversary interest and defend against real incident response events.</p>
]]></description>
                                                            <content:encoded><![CDATA[<p>In a world where adversaries are constantly adapting to improve tactics, techniques, and procedures (TTPs), it is crucial to understand the unique traits and goals of various types of adversaries that actively seek to cause harm to an organization. The personification of these threats will ultimately help measure resilience against specific threat actors, identify investment and hardening opportunities, and improve trust with customers.</p>
<p>In this podcast, Daniel Ventura, Manager of Product Security Incident Response Team (PSIRT), shares insight into Adobe’s approach to adversary personification as well as provides guidance on how you can better measure the security resilience of your products. He’ll also talk about Adobe’s bug bounty program which helps his team identify new trends in adversary interest and defend against real incident response events.</p>
]]></content:encoded>
                                    
        <enclosure url="https://mcdn.podbean.com/mf/web/cxgyg2/P_443_Adobe_Audio_Edit_d1aokt9.mp3" length="31183418" type="audio/mpeg"/>
        <itunes:summary><![CDATA[In a world where adversaries are constantly adapting to improve tactics, techniques, and procedures (TTPs), it is crucial to understand the unique traits and goals of various types of adversaries that actively seek to cause harm to an organization. The personification of these threats will ultimately help measure resilience against specific threat actors, identify investment and hardening opportunities, and improve trust with customers.
In this podcast, Daniel Ventura, Manager of Product Security Incident Response Team (PSIRT), shares insight into Adobe’s approach to adversary personification as well as provides guidance on how you can better measure the security resilience of your products. He’ll also talk about Adobe’s bug bounty program which helps his team identify new trends in adversary interest and defend against real incident response events.]]></itunes:summary>
        <itunes:author>ISACA Podcast</itunes:author>
        <itunes:explicit>false</itunes:explicit>
        <itunes:block>No</itunes:block>
        <itunes:duration>1297</itunes:duration>
                <itunes:episode>263</itunes:episode>
        <itunes:episodeType>full</itunes:episodeType>
            </item>
    <item>
        <title>Risky Business – Jon Brandt</title>
        <itunes:title>Risky Business – Jon Brandt</itunes:title>
        <link>https://isacapodcast.podbean.com/e/cyber-pros-with-ryan-cloutier/</link>
                    <comments>https://isacapodcast.podbean.com/e/cyber-pros-with-ryan-cloutier/#comments</comments>        <pubDate>Tue, 07 Mar 2023 16:00:00 +0000</pubDate>
        <guid isPermaLink="false">isacapodcast.podbean.com/f66fdeea-9605-3681-b49b-826bebb40f89</guid>
                                    <description><![CDATA[<p>For the average person, life moves quickly. But for business leaders and anyone involved in any aspect of IT, the pace at which technology is changing is overwhelming. Technology can help businesses and individuals do more with less and increase profit margins. However, technological advances carry tremendous risk and increase the criticality of risk management. No longer can business and personal use of technology be viewed in siloes. ISACAs Director of Professional Practices and Innovation, Jon Brandt, is joined by Ryan Cloutier as they discuss some of the latest headlines and impact to intellectual property.</p>
]]></description>
                                                            <content:encoded><![CDATA[<p>For the average person, life moves quickly. But for business leaders and anyone involved in any aspect of IT, the pace at which technology is changing is overwhelming. Technology can help businesses and individuals do more with less and increase profit margins. However, technological advances carry tremendous risk and increase the criticality of risk management. No longer can business and personal use of technology be viewed in siloes. ISACAs Director of Professional Practices and Innovation, Jon Brandt, is joined by Ryan Cloutier as they discuss some of the latest headlines and impact to intellectual property.</p>
]]></content:encoded>
                                    
        <enclosure url="https://mcdn.podbean.com/mf/web/x3nw6j/P_201_Audio_Edit_d1aplvw.mp3" length="71155933" type="audio/mpeg"/>
        <itunes:summary><![CDATA[For the average person, life moves quickly. But for business leaders and anyone involved in any aspect of IT, the pace at which technology is changing is overwhelming. Technology can help businesses and individuals do more with less and increase profit margins. However, technological advances carry tremendous risk and increase the criticality of risk management. No longer can business and personal use of technology be viewed in siloes. ISACAs Director of Professional Practices and Innovation, Jon Brandt, is joined by Ryan Cloutier as they discuss some of the latest headlines and impact to intellectual property.]]></itunes:summary>
        <itunes:author>ISACA Podcast</itunes:author>
        <itunes:explicit>false</itunes:explicit>
        <itunes:block>No</itunes:block>
        <itunes:duration>2952</itunes:duration>
                <itunes:episode>262</itunes:episode>
        <itunes:episodeType>full</itunes:episodeType>
            </item>
    <item>
        <title>Building Digital Trust Through Advocacy</title>
        <itunes:title>Building Digital Trust Through Advocacy</itunes:title>
        <link>https://isacapodcast.podbean.com/e/building-digital-trust-through-advocacy/</link>
                    <comments>https://isacapodcast.podbean.com/e/building-digital-trust-through-advocacy/#comments</comments>        <pubDate>Thu, 02 Mar 2023 10:00:00 +0000</pubDate>
        <guid isPermaLink="false">isacapodcast.podbean.com/7fba4184-1fba-3840-a8a4-46749a180a1e</guid>
                                    <description><![CDATA[<p>If you thought ISACA was only about certification and education, get ready to listen to this podcast and see how ISACA advocates for the IT Audit and Risk Management professions! Join Cindy Baxter, author of the Audit in Practice column in the ISACA Journal, as she interviews two members of the ISACA New England Board of Directors who attended ISACA’s Hill Day in Washington DC.  Hear how they met with their government representatives and with ISACA’s help, discussed legislation that supports our profession!  It’s an opportunity to think about the impacts you can have in your own back yard and with civic leaders!</p>
]]></description>
                                                            <content:encoded><![CDATA[<p>If you thought ISACA was only about certification and education, get ready to listen to this podcast and see how ISACA advocates for the IT Audit and Risk Management professions! Join Cindy Baxter, author of the Audit in Practice column in the ISACA Journal, as she interviews two members of the ISACA New England Board of Directors who attended ISACA’s Hill Day in Washington DC.  Hear how they met with their government representatives and with ISACA’s help, discussed legislation that supports our profession!  It’s an opportunity to think about the impacts you can have in your own back yard and with civic leaders!</p>
]]></content:encoded>
                                    
        <enclosure url="https://mcdn.podbean.com/mf/web/vatfah/P_432_Cindy_Baxter_Audio_Edit_d1b84ab.mp3" length="40394564" type="audio/mpeg"/>
        <itunes:summary><![CDATA[If you thought ISACA was only about certification and education, get ready to listen to this podcast and see how ISACA advocates for the IT Audit and Risk Management professions! Join Cindy Baxter, author of the Audit in Practice column in the ISACA Journal, as she interviews two members of the ISACA New England Board of Directors who attended ISACA’s Hill Day in Washington DC.  Hear how they met with their government representatives and with ISACA’s help, discussed legislation that supports our profession!  It’s an opportunity to think about the impacts you can have in your own back yard and with civic leaders!]]></itunes:summary>
        <itunes:author>ISACA Podcast</itunes:author>
        <itunes:explicit>false</itunes:explicit>
        <itunes:block>No</itunes:block>
        <itunes:duration>1682</itunes:duration>
                <itunes:episode>260</itunes:episode>
        <itunes:episodeType>full</itunes:episodeType>
            </item>
    <item>
        <title>Advertising Information Security</title>
        <itunes:title>Advertising Information Security</itunes:title>
        <link>https://isacapodcast.podbean.com/e/advertising-information-security/</link>
                    <comments>https://isacapodcast.podbean.com/e/advertising-information-security/#comments</comments>        <pubDate>Tue, 28 Feb 2023 10:00:00 +0000</pubDate>
        <guid isPermaLink="false">isacapodcast.podbean.com/b59680bf-352b-3d69-980a-1424b50cc3ee</guid>
                                    <description><![CDATA[<p>In this episode, executive principal at Risk Masters International’s Steven Ross discusses why vendors of IT products and services are advertising information security, why businesses are not advertising their security and how to use information security as a component of organizations’ public images with host Safia Kazi.</p>
]]></description>
                                                            <content:encoded><![CDATA[<p>In this episode, executive principal at Risk Masters International’s Steven Ross discusses why vendors of IT products and services are advertising information security, why businesses are not advertising their security and how to use information security as a component of organizations’ public images with host Safia Kazi.</p>
]]></content:encoded>
                                    
        <enclosure url="https://mcdn.podbean.com/mf/web/66wfax/P_433_Audio_Edit_d1adjyx.mp3" length="33076545" type="audio/mpeg"/>
        <itunes:summary><![CDATA[In this episode, executive principal at Risk Masters International’s Steven Ross discusses why vendors of IT products and services are advertising information security, why businesses are not advertising their security and how to use information security as a component of organizations’ public images with host Safia Kazi.]]></itunes:summary>
        <itunes:author>ISACA Podcast</itunes:author>
        <itunes:explicit>false</itunes:explicit>
        <itunes:block>No</itunes:block>
        <itunes:duration>1376</itunes:duration>
                <itunes:episode>261</itunes:episode>
        <itunes:episodeType>full</itunes:episodeType>
            </item>
    <item>
        <title>Rethinking Identity Governance</title>
        <itunes:title>Rethinking Identity Governance</itunes:title>
        <link>https://isacapodcast.podbean.com/e/iga-is-broken-how-can-we-fix-it/</link>
                    <comments>https://isacapodcast.podbean.com/e/iga-is-broken-how-can-we-fix-it/#comments</comments>        <pubDate>Tue, 21 Feb 2023 10:00:00 +0000</pubDate>
        <guid isPermaLink="false">isacapodcast.podbean.com/3198c2a1-1f18-37cd-90be-62d0c8d95971</guid>
                                    <description><![CDATA[<p>SaaS is eating the world even more than we think. Companies are dealing with SaaS sprawl: hundreds of apps distributed across different owners that store sensitive data and which are used to orchestrate critical business workflows. Security-minded teams are turning to external compliance frameworks to help protect their customers and data.
 
However, traditional identity governance controls have fallen short of delivering real security outcomes in this digital-first world. They’re missing a critical piece: automation. In this episode, ConductorOne’s CEO and Co-Founder, Alex Bovee joins this episode to discuss why we need to change the way we think about compliance and risk and what a security-led governance program could look like.</p>
<p>Learn more about ConductorOne at <a href='https://www.linkedin.com/company/conductorone/'>https://www.linkedin.com/company/conductorone/</a> or <a href='https://www.conductorone.com/blog/automating-compliance-controls-least-privilege-access/'>https://www.conductorone.com/blog/automating-compliance-controls-least-privilege-access/</a></p>
]]></description>
                                                            <content:encoded><![CDATA[<p>SaaS is eating the world even more than we think. Companies are dealing with SaaS sprawl: hundreds of apps distributed across different owners that store sensitive data and which are used to orchestrate critical business workflows. Security-minded teams are turning to external compliance frameworks to help protect their customers and data.<br>
 <br>
However, traditional identity governance controls have fallen short of delivering real security outcomes in this digital-first world. They’re missing a critical piece: automation. In this episode, ConductorOne’s CEO and Co-Founder, Alex Bovee joins this episode to discuss why we need to change the way we think about compliance and risk and what a security-led governance program could look like.</p>
<p>Learn more about ConductorOne at <a href='https://www.linkedin.com/company/conductorone/'>https://www.linkedin.com/company/conductorone/</a> or <a href='https://www.conductorone.com/blog/automating-compliance-controls-least-privilege-access/'>https://www.conductorone.com/blog/automating-compliance-controls-least-privilege-access/</a></p>
]]></content:encoded>
                                    
        <enclosure url="https://mcdn.podbean.com/mf/web/7icpi2/P_441_ConductorOne_Audio_Edit_d19x9fw.mp3" length="40057825" type="audio/mpeg"/>
        <itunes:summary><![CDATA[SaaS is eating the world even more than we think. Companies are dealing with SaaS sprawl: hundreds of apps distributed across different owners that store sensitive data and which are used to orchestrate critical business workflows. Security-minded teams are turning to external compliance frameworks to help protect their customers and data. However, traditional identity governance controls have fallen short of delivering real security outcomes in this digital-first world. They’re missing a critical piece: automation. In this episode, ConductorOne’s CEO and Co-Founder, Alex Bovee joins this episode to discuss why we need to change the way we think about compliance and risk and what a security-led governance program could look like.
Learn more about ConductorOne at https://www.linkedin.com/company/conductorone/ or https://www.conductorone.com/blog/automating-compliance-controls-least-privilege-access/]]></itunes:summary>
        <itunes:author>ISACA Podcast</itunes:author>
        <itunes:explicit>false</itunes:explicit>
        <itunes:block>No</itunes:block>
        <itunes:duration>1667</itunes:duration>
                <itunes:episode>259</itunes:episode>
        <itunes:episodeType>full</itunes:episodeType>
            </item>
    <item>
        <title>2023: The Year of Risk</title>
        <itunes:title>2023: The Year of Risk</itunes:title>
        <link>https://isacapodcast.podbean.com/e/2023-the-year-of-risk/</link>
                    <comments>https://isacapodcast.podbean.com/e/2023-the-year-of-risk/#comments</comments>        <pubDate>Tue, 14 Feb 2023 21:00:00 +0000</pubDate>
        <guid isPermaLink="false">isacapodcast.podbean.com/adb8ecab-04ed-31fa-b32e-46c3d0ed583c</guid>
                                    <description><![CDATA[<p> A review of the events of 2022 shows that 2023 will not be the year of dire new cyber attacks waged by hoodie-wearing cyber criminals or office-bound nation-state APTs. Instead, 2023 will be when multiple regulatory bodies express their mounting frustration with public and private companies' collective inability to reduce the volume and impact of prior cyber attacks.  </p>
<p>Tune into this ISACA Episode as Hyperproof’s Field CISO, Kayne McGladrey, speaks with ISACA’s Jeff Champion on how 2023 will be the year of risk.  </p>
<p>Learn more about Hyperproof at:  </p>
<p><a href='https://twitter.com/Hyperproof'>https://twitter.com/Hyperproof</a> </p>
<p><a href='https://www.linkedin.com/company/hyperproof/'>https://www.linkedin.com/company/hyperproof/</a> </p>
<p><a href='https://www.instagram.com/hyperproof/'>https://www.instagram.com/hyperproof/</a> </p>
<p>Additional Hyperproof Resources:  </p>
<p><a href='https://hyperproof.io/resource/the-ultimate-guide-to-enterprise-risk-management/'>https://hyperproof.io/resource/the-ultimate-guide-to-enterprise-risk-management/</a> </p>
<p><a href='https://www.isaca.org/resources/news-and-trends/isaca-now-blog/2022/three-key-predictions-for-2023-the-year-of-risk'>https://www.isaca.org/resources/news-and-trends/isaca-now-blog/2022/three-key-predictions-for-2023-the-year-of-risk</a> </p>
<p><a href='https://hyperproof.io/resource/risk-management-software-buyer-guide/'>https://hyperproof.io/resource/risk-management-software-buyer-guide/</a> </p>
<p><a href='https://hyperproof.io/case-studies/pythian-uses-hyperproof-to-get-time-back-and-improve-its-risk-management-maturity/'>https://hyperproof.io/case-studies/pythian-uses-hyperproof-to-get-time-back-and-improve-its-risk-management-maturity/</a> </p>
]]></description>
                                                            <content:encoded><![CDATA[<p> A review of the events of 2022 shows that 2023 will not be the year of dire new cyber attacks waged by hoodie-wearing cyber criminals or office-bound nation-state APTs. Instead, 2023 will be when multiple regulatory bodies express their mounting frustration with public and private companies' collective inability to reduce the volume and impact of prior cyber attacks.  </p>
<p>Tune into this ISACA Episode as Hyperproof’s Field CISO, Kayne McGladrey, speaks with ISACA’s Jeff Champion on how 2023 will be the year of risk.  </p>
<p>Learn more about Hyperproof at:  </p>
<p><a href='https://twitter.com/Hyperproof'>https://twitter.com/Hyperproof</a> </p>
<p><a href='https://www.linkedin.com/company/hyperproof/'>https://www.linkedin.com/company/hyperproof/</a> </p>
<p><a href='https://www.instagram.com/hyperproof/'>https://www.instagram.com/hyperproof/</a> </p>
<p>Additional Hyperproof Resources:  </p>
<p><a href='https://hyperproof.io/resource/the-ultimate-guide-to-enterprise-risk-management/'>https://hyperproof.io/resource/the-ultimate-guide-to-enterprise-risk-management/</a> </p>
<p><a href='https://www.isaca.org/resources/news-and-trends/isaca-now-blog/2022/three-key-predictions-for-2023-the-year-of-risk'>https://www.isaca.org/resources/news-and-trends/isaca-now-blog/2022/three-key-predictions-for-2023-the-year-of-risk</a> </p>
<p><a href='https://hyperproof.io/resource/risk-management-software-buyer-guide/'>https://hyperproof.io/resource/risk-management-software-buyer-guide/</a> </p>
<p><a href='https://hyperproof.io/case-studies/pythian-uses-hyperproof-to-get-time-back-and-improve-its-risk-management-maturity/'>https://hyperproof.io/case-studies/pythian-uses-hyperproof-to-get-time-back-and-improve-its-risk-management-maturity/</a> </p>
]]></content:encoded>
                                    
        <enclosure url="https://mcdn.podbean.com/mf/web/rw5uji/P_439_Hyperproof_Audio_Edit_d167lo2.mp3" length="61567676" type="audio/mpeg"/>
        <itunes:summary><![CDATA[ A review of the events of 2022 shows that 2023 will not be the year of dire new cyber attacks waged by hoodie-wearing cyber criminals or office-bound nation-state APTs. Instead, 2023 will be when multiple regulatory bodies express their mounting frustration with public and private companies' collective inability to reduce the volume and impact of prior cyber attacks.  
Tune into this ISACA Episode as Hyperproof’s Field CISO, Kayne McGladrey, speaks with ISACA’s Jeff Champion on how 2023 will be the year of risk.  
Learn more about Hyperproof at:  
https://twitter.com/Hyperproof 
https://www.linkedin.com/company/hyperproof/ 
https://www.instagram.com/hyperproof/ 
Additional Hyperproof Resources:  
https://hyperproof.io/resource/the-ultimate-guide-to-enterprise-risk-management/ 
https://www.isaca.org/resources/news-and-trends/isaca-now-blog/2022/three-key-predictions-for-2023-the-year-of-risk 
https://hyperproof.io/resource/risk-management-software-buyer-guide/ 
https://hyperproof.io/case-studies/pythian-uses-hyperproof-to-get-time-back-and-improve-its-risk-management-maturity/ ]]></itunes:summary>
        <itunes:author>ISACA Podcast</itunes:author>
        <itunes:explicit>false</itunes:explicit>
        <itunes:block>No</itunes:block>
        <itunes:duration>2562</itunes:duration>
                <itunes:episode>258</itunes:episode>
        <itunes:episodeType>full</itunes:episodeType>
            </item>
    <item>
        <title>Improving Cyber Resilience in an Age of Continuous Attacks</title>
        <itunes:title>Improving Cyber Resilience in an Age of Continuous Attacks</itunes:title>
        <link>https://isacapodcast.podbean.com/e/improving-cyber-resilience-in-an-age-of-continuous-attacks/</link>
                    <comments>https://isacapodcast.podbean.com/e/improving-cyber-resilience-in-an-age-of-continuous-attacks/#comments</comments>        <pubDate>Thu, 09 Feb 2023 10:00:00 +0000</pubDate>
        <guid isPermaLink="false">isacapodcast.podbean.com/0882821c-1016-32a5-9944-2e2262dcb99a</guid>
                                    <description><![CDATA[<p>We live in the age of continuous compromise. This podcast dives into why so many organizations continue to be breached even after spending money on cybersecurity point solutions. Many organizations gravitate towards silver bullet solutions without understanding the threat and impact.</p>
<p>In this ISACA Podcast episode, Chris McGown speaks to Rex Johnson and Hamlet Khodaverdian about why a holistic and collaborative approach is absolutely critical to creating cyber-resilience. </p>
<p>For more information check out <a href='http://www.isaca.org/improving-cyberresilience-in-an-age-of-continuous-attacks'>www.isaca.org/improving-cyberresilience-in-an-age-of-continuous-attacks</a> </p>
]]></description>
                                                            <content:encoded><![CDATA[<p>We live in the age of continuous compromise. This podcast dives into why so many organizations continue to be breached even after spending money on cybersecurity point solutions. Many organizations gravitate towards silver bullet solutions without understanding the threat and impact.</p>
<p>In this ISACA Podcast episode, Chris McGown speaks to Rex Johnson and Hamlet Khodaverdian about why a holistic and collaborative approach is absolutely critical to creating cyber-resilience. </p>
<p>For more information check out <a href='http://www.isaca.org/improving-cyberresilience-in-an-age-of-continuous-attacks'>www.isaca.org/improving-cyberresilience-in-an-age-of-continuous-attacks</a> </p>
]]></content:encoded>
                                    
        <enclosure url="https://mcdn.podbean.com/mf/web/pikfee/P_419_Rex-Hamlet_Audio_Edit_d29do21.mp3" length="46895360" type="audio/mpeg"/>
        <itunes:summary><![CDATA[We live in the age of continuous compromise. This podcast dives into why so many organizations continue to be breached even after spending money on cybersecurity point solutions. Many organizations gravitate towards silver bullet solutions without understanding the threat and impact.
In this ISACA Podcast episode, Chris McGown speaks to Rex Johnson and Hamlet Khodaverdian about why a holistic and collaborative approach is absolutely critical to creating cyber-resilience. 
For more information check out www.isaca.org/improving-cyberresilience-in-an-age-of-continuous-attacks ]]></itunes:summary>
        <itunes:author>ISACA Podcast</itunes:author>
        <itunes:explicit>false</itunes:explicit>
        <itunes:block>No</itunes:block>
        <itunes:duration>1946</itunes:duration>
                <itunes:episode>257</itunes:episode>
        <itunes:episodeType>full</itunes:episodeType>
            </item>
    <item>
        <title>Advancing Digital Trust Through Audit and Assurance</title>
        <itunes:title>Advancing Digital Trust Through Audit and Assurance</itunes:title>
        <link>https://isacapodcast.podbean.com/e/advancing-digital-trust-through-audit-and-assurance-1672866411/</link>
                    <comments>https://isacapodcast.podbean.com/e/advancing-digital-trust-through-audit-and-assurance-1672866411/#comments</comments>        <pubDate>Tue, 07 Feb 2023 10:00:00 +0000</pubDate>
        <guid isPermaLink="false">isacapodcast.podbean.com/5614c35e-e7c9-373b-b180-baa9ea67ab45</guid>
                                    <description><![CDATA[<p>A strong audit and assurance function is critical to achieving digital trust in an organization. This conversation spotlights audit's role in digital trust and outlines key priorities. It also shares new ISACA resources for auditors.</p>
<p>For more information, go to https://isaca.org/digital-trust</p>
]]></description>
                                                            <content:encoded><![CDATA[<p>A strong audit and assurance function is critical to achieving digital trust in an organization. This conversation spotlights audit's role in digital trust and outlines key priorities. It also shares new ISACA resources for auditors.</p>
<p>For more information, go to https://isaca.org/digital-trust</p>
]]></content:encoded>
                                    
        <enclosure url="https://mcdn.podbean.com/mf/web/ddp5q5/ISACA_LIve_Digital_Trust_Audit_Spotlight-_AUDIO_ONLY7pykz.mp3" length="24744039" type="audio/mpeg"/>
        <itunes:summary><![CDATA[A strong audit and assurance function is critical to achieving digital trust in an organization. This conversation spotlights audit's role in digital trust and outlines key priorities. It also shares new ISACA resources for auditors.
For more information, go to https://isaca.org/digital-trust]]></itunes:summary>
        <itunes:author>ISACA Podcast</itunes:author>
        <itunes:explicit>false</itunes:explicit>
        <itunes:block>No</itunes:block>
        <itunes:duration>1530</itunes:duration>
                <itunes:episode>255</itunes:episode>
        <itunes:episodeType>full</itunes:episodeType>
            </item>
    <item>
        <title>ISACA Live_Critical Infrastructure Security</title>
        <itunes:title>ISACA Live_Critical Infrastructure Security</itunes:title>
        <link>https://isacapodcast.podbean.com/e/isaca-live_critical-infrastructure-security/</link>
                    <comments>https://isacapodcast.podbean.com/e/isaca-live_critical-infrastructure-security/#comments</comments>        <pubDate>Thu, 02 Feb 2023 10:00:00 +0000</pubDate>
        <guid isPermaLink="false">isacapodcast.podbean.com/274c2edf-53d1-3269-b1d1-74263e8ec612</guid>
                                    <description><![CDATA[<p>ISACA's Chris Dimitriadis and the US GAO's Nick Marinos discuss the current state of critical infrastructure security, escalating threats and how to better prepare.</p>
<p>For more information check out www.isaca.org/heightened-threats</p>
]]></description>
                                                            <content:encoded><![CDATA[<p>ISACA's Chris Dimitriadis and the US GAO's Nick Marinos discuss the current state of critical infrastructure security, escalating threats and how to better prepare.</p>
<p>For more information check out www.isaca.org/heightened-threats</p>
]]></content:encoded>
                                    
        <enclosure url="https://mcdn.podbean.com/mf/web/d6mgi7/P_179_ISACA_Live_Audio_Edit_d1bgoiz.mp3" length="38664386" type="audio/mpeg"/>
        <itunes:summary><![CDATA[ISACA's Chris Dimitriadis and the US GAO's Nick Marinos discuss the current state of critical infrastructure security, escalating threats and how to better prepare.
For more information check out www.isaca.org/heightened-threats]]></itunes:summary>
        <itunes:author>ISACA Podcast</itunes:author>
        <itunes:explicit>false</itunes:explicit>
        <itunes:block>No</itunes:block>
        <itunes:duration>1608</itunes:duration>
                <itunes:episode>254</itunes:episode>
        <itunes:episodeType>full</itunes:episodeType>
            </item>
    <item>
        <title>ISACA Live | Risk Scenarios</title>
        <itunes:title>ISACA Live | Risk Scenarios</itunes:title>
        <link>https://isacapodcast.podbean.com/e/isaca-live-risk-scenarios-1672866060/</link>
                    <comments>https://isacapodcast.podbean.com/e/isaca-live-risk-scenarios-1672866060/#comments</comments>        <pubDate>Tue, 31 Jan 2023 10:00:00 +0000</pubDate>
        <guid isPermaLink="false">isacapodcast.podbean.com/e7169d69-ebe5-3841-a6e7-f046c0f06c63</guid>
                                    <description><![CDATA[<p>Paul Philips and Lisa Young will discuss how risk scenarios help decision-makers understand how certain events can impact organizational strategy and objectives. Good risk scenario building is a skill and can take some time to truly master. Paul and Lisa will provide actionable advice on building the best possible scenarios to help your organization better manage risk</p>
<p>For more information check out https://www.isaca.org/resources/it-risk</p>
]]></description>
                                                            <content:encoded><![CDATA[<p>Paul Philips and Lisa Young will discuss how risk scenarios help decision-makers understand how certain events can impact organizational strategy and objectives. Good risk scenario building is a skill and can take some time to truly master. Paul and Lisa will provide actionable advice on building the best possible scenarios to help your organization better manage risk</p>
<p>For more information check out https://www.isaca.org/resources/it-risk</p>
]]></content:encoded>
                                    
        <enclosure url="https://mcdn.podbean.com/mf/web/wfndec/P_203_ISACA_Live_Lisa_Young_Audio_Podcast_d1990b7.mp3" length="21968440" type="audio/mpeg"/>
        <itunes:summary><![CDATA[Paul Philips and Lisa Young will discuss how risk scenarios help decision-makers understand how certain events can impact organizational strategy and objectives. Good risk scenario building is a skill and can take some time to truly master. Paul and Lisa will provide actionable advice on building the best possible scenarios to help your organization better manage risk
For more information check out https://www.isaca.org/resources/it-risk]]></itunes:summary>
        <itunes:author>ISACA Podcast</itunes:author>
        <itunes:explicit>false</itunes:explicit>
        <itunes:block>No</itunes:block>
        <itunes:duration>1369</itunes:duration>
                <itunes:episode>253</itunes:episode>
        <itunes:episodeType>full</itunes:episodeType>
            </item>
    <item>
        <title>ISACA Live | How to Mature Your Privacy Compliance Program</title>
        <itunes:title>ISACA Live | How to Mature Your Privacy Compliance Program</itunes:title>
        <link>https://isacapodcast.podbean.com/e/how-to-mature-your-privacy-compliance-program-a-conversation-with-onetrust-dpo-linda-thielova/</link>
                    <comments>https://isacapodcast.podbean.com/e/how-to-mature-your-privacy-compliance-program-a-conversation-with-onetrust-dpo-linda-thielova/#comments</comments>        <pubDate>Thu, 26 Jan 2023 10:00:00 +0000</pubDate>
        <guid isPermaLink="false">isacapodcast.podbean.com/a5b95c8a-d789-391d-b2b8-a57d5a1800ea</guid>
                                    <description><![CDATA[<p>Compliance with the world’s ever-increasing list of privacy laws can be a tricky undertaking for any organization, but by taking a few simple steps, you can begin to mature your privacy program from a series of check-box exercises into an intelligent compliance program that can help organizations to build consumer trust and protect brand reputation.</p>
<p>Join this conversation with OneTrust DPO Linda Thielova and ISACA's Paul Phillips to learn how to operationalize privacy compliance within your organization and get practical tips on how to mature your privacy compliance program.</p>
]]></description>
                                                            <content:encoded><![CDATA[<p>Compliance with the world’s ever-increasing list of privacy laws can be a tricky undertaking for any organization, but by taking a few simple steps, you can begin to mature your privacy program from a series of check-box exercises into an intelligent compliance program that can help organizations to build consumer trust and protect brand reputation.</p>
<p>Join this conversation with OneTrust DPO Linda Thielova and ISACA's Paul Phillips to learn how to operationalize privacy compliance within your organization and get practical tips on how to mature your privacy compliance program.</p>
]]></content:encoded>
                                    
        <enclosure url="https://mcdn.podbean.com/mf/web/mk6xhg/P_365_How_to_Mature_Your_Privacy_Linda_Thielova_Audio_Edit_d18nny1.mp3" length="37672668" type="audio/mpeg"/>
        <itunes:summary><![CDATA[Compliance with the world’s ever-increasing list of privacy laws can be a tricky undertaking for any organization, but by taking a few simple steps, you can begin to mature your privacy program from a series of check-box exercises into an intelligent compliance program that can help organizations to build consumer trust and protect brand reputation.
Join this conversation with OneTrust DPO Linda Thielova and ISACA's Paul Phillips to learn how to operationalize privacy compliance within your organization and get practical tips on how to mature your privacy compliance program.]]></itunes:summary>
        <itunes:author>ISACA Podcast</itunes:author>
        <itunes:explicit>false</itunes:explicit>
        <itunes:block>No</itunes:block>
        <itunes:duration>1567</itunes:duration>
                <itunes:episode>252</itunes:episode>
        <itunes:episodeType>full</itunes:episodeType>
            </item>
    <item>
        <title>Career Coach Advice: How to Launch Your IT Audit Career</title>
        <itunes:title>Career Coach Advice: How to Launch Your IT Audit Career</itunes:title>
        <link>https://isacapodcast.podbean.com/e/career-coach-advice-how-to-launch-your-it-audit-career/</link>
                    <comments>https://isacapodcast.podbean.com/e/career-coach-advice-how-to-launch-your-it-audit-career/#comments</comments>        <pubDate>Tue, 24 Jan 2023 10:00:00 +0000</pubDate>
        <guid isPermaLink="false">isacapodcast.podbean.com/d8ca8bc7-31fe-354c-a69c-a5484bd55bae</guid>
                                    <description><![CDATA[<p>Career coach Caitlin McGaw will share her top tips for young professionals and career changes on how to launch a successful career in IT audit--from acing your first interview and landing your first job to career resources to help your career continue to grow and thrive.</p>
<p>To learn more, check out www.caitlinmcgaw.com </p>
]]></description>
                                                            <content:encoded><![CDATA[<p>Career coach Caitlin McGaw will share her top tips for young professionals and career changes on how to launch a successful career in IT audit--from acing your first interview and landing your first job to career resources to help your career continue to grow and thrive.</p>
<p>To learn more, check out www.caitlinmcgaw.com </p>
]]></content:encoded>
                                    
        <enclosure url="https://mcdn.podbean.com/mf/web/wxfcee/P_302_Career_Coach_Advice_Audio_Edit_d1blt66.mp3" length="26218349" type="audio/mpeg"/>
        <itunes:summary><![CDATA[Career coach Caitlin McGaw will share her top tips for young professionals and career changes on how to launch a successful career in IT audit--from acing your first interview and landing your first job to career resources to help your career continue to grow and thrive.
To learn more, check out www.caitlinmcgaw.com ]]></itunes:summary>
        <itunes:author>ISACA Podcast</itunes:author>
        <itunes:explicit>false</itunes:explicit>
        <itunes:block>No</itunes:block>
        <itunes:duration>1090</itunes:duration>
                <itunes:episode>251</itunes:episode>
        <itunes:episodeType>full</itunes:episodeType>
            </item>
    <item>
        <title>ISACA Live | Advancing Digital Trust Through Data Privacy</title>
        <itunes:title>ISACA Live | Advancing Digital Trust Through Data Privacy</itunes:title>
        <link>https://isacapodcast.podbean.com/e/isaca-live-advancing-digital-trust-through-data-privacy/</link>
                    <comments>https://isacapodcast.podbean.com/e/isaca-live-advancing-digital-trust-through-data-privacy/#comments</comments>        <pubDate>Thu, 19 Jan 2023 10:00:00 +0000</pubDate>
        <guid isPermaLink="false">isacapodcast.podbean.com/c128a3dc-7dd1-3dac-91ec-c0deec5b3a15</guid>
                                    <description><![CDATA[<p>Learn more at isaca.org/digital-trust </p>
]]></description>
                                                            <content:encoded><![CDATA[<p>Learn more at isaca.org/digital-trust </p>
]]></content:encoded>
                                    
        <enclosure url="https://mcdn.podbean.com/mf/web/hz8qap/P_303_Data_Privacy_Betsie_Estes_Audio_Edit_d18yi3j.mp3" length="24362084" type="audio/mpeg"/>
        <itunes:summary><![CDATA[Learn more at isaca.org/digital-trust ]]></itunes:summary>
        <itunes:author>ISACA Podcast</itunes:author>
        <itunes:explicit>false</itunes:explicit>
        <itunes:block>No</itunes:block>
        <itunes:duration>1013</itunes:duration>
                <itunes:episode>250</itunes:episode>
        <itunes:episodeType>full</itunes:episodeType>
            </item>
    <item>
        <title>ISACA Live | The Dark Future of Privacy</title>
        <itunes:title>ISACA Live | The Dark Future of Privacy</itunes:title>
        <link>https://isacapodcast.podbean.com/e/isaca-live-the-dark-future-of-privacy/</link>
                    <comments>https://isacapodcast.podbean.com/e/isaca-live-the-dark-future-of-privacy/#comments</comments>        <pubDate>Tue, 17 Jan 2023 10:00:00 +0000</pubDate>
        <guid isPermaLink="false">isacapodcast.podbean.com/178f91e7-9ae2-3e86-84e5-ffb5dca0d16a</guid>
                                    <description><![CDATA[<p>Privacy Mining will increase because of billions of IoT devices being connected every day. Combined with advanced psychologic research, this can be a very powerful tool for manipulating people's behavior. A Fake reality also poses a big threat to our future of privacy. Software, such as Deep Fakes, has the ability to use someone's facial structure and create fake videos featuring digitally created characters with an uncanny resemblance of real people, such as celebrities.</p>
<p>This technology is so advanced, that our minds aren't sophisticated enough to comprehend the difference between real and fake data created by it, which leads to the next point. We are entering a trust crisis.</p>
<p>Trust is the foundation for innovation and technological advance. If people don't trust autonomous cars - they won't use them; if people don't certain websites - they won't read their news; Without trust, we cannot move forward, which is why we need to raise awareness about the dark future of privacy.</p>
]]></description>
                                                            <content:encoded><![CDATA[<p>Privacy Mining will increase because of billions of IoT devices being connected every day. Combined with advanced psychologic research, this can be a very powerful tool for manipulating people's behavior. A Fake reality also poses a big threat to our future of privacy. Software, such as Deep Fakes, has the ability to use someone's facial structure and create fake videos featuring digitally created characters with an uncanny resemblance of real people, such as celebrities.</p>
<p>This technology is so advanced, that our minds aren't sophisticated enough to comprehend the difference between real and fake data created by it, which leads to the next point. We are entering a trust crisis.</p>
<p>Trust is the foundation for innovation and technological advance. If people don't trust autonomous cars - they won't use them; if people don't certain websites - they won't read their news; Without trust, we cannot move forward, which is why we need to raise awareness about the dark future of privacy.</p>
]]></content:encoded>
                                    
        <enclosure url="https://mcdn.podbean.com/mf/web/c78586/P_304_Dark_Future_of_Privacy_MennyB_d1avrsp.mp3" length="44654555" type="audio/mpeg"/>
        <itunes:summary><![CDATA[Privacy Mining will increase because of billions of IoT devices being connected every day. Combined with advanced psychologic research, this can be a very powerful tool for manipulating people's behavior. A Fake reality also poses a big threat to our future of privacy. Software, such as Deep Fakes, has the ability to use someone's facial structure and create fake videos featuring digitally created characters with an uncanny resemblance of real people, such as celebrities.
This technology is so advanced, that our minds aren't sophisticated enough to comprehend the difference between real and fake data created by it, which leads to the next point. We are entering a trust crisis.
Trust is the foundation for innovation and technological advance. If people don't trust autonomous cars - they won't use them; if people don't certain websites - they won't read their news; Without trust, we cannot move forward, which is why we need to raise awareness about the dark future of privacy.]]></itunes:summary>
        <itunes:author>ISACA Podcast</itunes:author>
        <itunes:explicit>false</itunes:explicit>
        <itunes:block>No</itunes:block>
        <itunes:duration>1858</itunes:duration>
                <itunes:episode>249</itunes:episode>
        <itunes:episodeType>full</itunes:episodeType>
            </item>
    <item>
        <title>Information Privacy Contradiction: Interest-Based Posture of Compliance and Violation</title>
        <itunes:title>Information Privacy Contradiction: Interest-Based Posture of Compliance and Violation</itunes:title>
        <link>https://isacapodcast.podbean.com/e/information-privacy-contradiction-interest-based-posture-of-compliance-and-violation/</link>
                    <comments>https://isacapodcast.podbean.com/e/information-privacy-contradiction-interest-based-posture-of-compliance-and-violation/#comments</comments>        <pubDate>Thu, 12 Jan 2023 10:00:00 +0000</pubDate>
        <guid isPermaLink="false">isacapodcast.podbean.com/3872b7e6-f135-347e-bbd4-2d4708f5c894</guid>
                                    <description><![CDATA[<p>Why do individuals, organizations, institutions, nations, or responsible agents work hard to preserve their personal and enterprise data, personnel information, trade secrets, intellectual properties, technical know-how, or national data, yet easily trade on the individual and enterprise data and national data of others?</p>
<p>To understand and answer the question appropriately, one must examine the underlying of the Information Privacy Realities Contradiction Theory (IPRCT), which is integral to (1) our natural unity of opposites, (2) our material dialectic mechanism or struggle of choosing from the opposites, and (3) the role of our self-interest in time and circumstance. Therefore, understanding the intricacies of the IPRCT would be instrumental to the proper and timely introduction of privacy requirements early in our system development lifecycle and in the development and enactment of information privacy policies, directives, guidance, and regulations around the world.</p>
<p>In this ISACA Podcast episode, Safia Kazi host Dr. Patrick Offor, Chief Warrant Officer Five Retired (CW5(R)); Associate Faculty, to discuss his recently released ISACA Journal article.</p>
<p>To read Dr. Offor’s full article, please visit <a href='https://www.isaca.org/resources/isaca-journal/issues/2022/volume-6/the-information-privacy-contradiction'>https://www.isaca.org/resources/isaca-journal/issues/2022/volume-6/the-information-privacy-contradiction</a>.</p>
<p>To listen to more ISACA podcasts, please visit <a href='http://www.isaca.org/podcasts'>www.isaca.org/podcasts</a>.</p>
]]></description>
                                                            <content:encoded><![CDATA[<p>Why do individuals, organizations, institutions, nations, or responsible agents work hard to preserve their personal and enterprise data, personnel information, trade secrets, intellectual properties, technical know-how, or national data, yet easily trade on the individual and enterprise data and national data of others?</p>
<p>To understand and answer the question appropriately, one must examine the underlying of the Information Privacy Realities Contradiction Theory (IPRCT), which is integral to (1) our natural unity of opposites, (2) our material dialectic mechanism or struggle of choosing from the opposites, and (3) the role of our self-interest in time and circumstance. Therefore, understanding the intricacies of the IPRCT would be instrumental to the proper and timely introduction of privacy requirements early in our system development lifecycle and in the development and enactment of information privacy policies, directives, guidance, and regulations around the world.</p>
<p>In this ISACA Podcast episode, Safia Kazi host Dr. Patrick Offor, Chief Warrant Officer Five Retired (CW5(R)); Associate Faculty, to discuss his recently released ISACA Journal article.</p>
<p>To read Dr. Offor’s full article, please visit <a href='https://www.isaca.org/resources/isaca-journal/issues/2022/volume-6/the-information-privacy-contradiction'>https://www.isaca.org/resources/isaca-journal/issues/2022/volume-6/the-information-privacy-contradiction</a>.</p>
<p><em>To listen to more ISACA podcasts, please visit </em><a href='http://www.isaca.org/podcasts'><em>www.isaca.org/podcasts</em></a><em>.</em></p>
]]></content:encoded>
                                    
        <enclosure url="https://mcdn.podbean.com/mf/web/ss2gha/P_401_Patrick_Offor_Audio_Edit_d18gxpn.mp3" length="47420774" type="audio/mpeg"/>
        <itunes:summary><![CDATA[Why do individuals, organizations, institutions, nations, or responsible agents work hard to preserve their personal and enterprise data, personnel information, trade secrets, intellectual properties, technical know-how, or national data, yet easily trade on the individual and enterprise data and national data of others?
To understand and answer the question appropriately, one must examine the underlying of the Information Privacy Realities Contradiction Theory (IPRCT), which is integral to (1) our natural unity of opposites, (2) our material dialectic mechanism or struggle of choosing from the opposites, and (3) the role of our self-interest in time and circumstance. Therefore, understanding the intricacies of the IPRCT would be instrumental to the proper and timely introduction of privacy requirements early in our system development lifecycle and in the development and enactment of information privacy policies, directives, guidance, and regulations around the world.
In this ISACA Podcast episode, Safia Kazi host Dr. Patrick Offor, Chief Warrant Officer Five Retired (CW5(R)); Associate Faculty, to discuss his recently released ISACA Journal article.
To read Dr. Offor’s full article, please visit https://www.isaca.org/resources/isaca-journal/issues/2022/volume-6/the-information-privacy-contradiction.
To listen to more ISACA podcasts, please visit www.isaca.org/podcasts.]]></itunes:summary>
        <itunes:author>ISACA Podcast</itunes:author>
        <itunes:explicit>false</itunes:explicit>
        <itunes:block>No</itunes:block>
        <itunes:duration>1973</itunes:duration>
                <itunes:episode>256</itunes:episode>
        <itunes:episodeType>full</itunes:episodeType>
            </item>
    <item>
        <title>ISACA Live | Advancing Digital Trust Through IT</title>
        <itunes:title>ISACA Live | Advancing Digital Trust Through IT</itunes:title>
        <link>https://isacapodcast.podbean.com/e/isaca-live-advancing-digital-trust-through-it/</link>
                    <comments>https://isacapodcast.podbean.com/e/isaca-live-advancing-digital-trust-through-it/#comments</comments>        <pubDate>Thu, 05 Jan 2023 10:00:00 +0000</pubDate>
        <guid isPermaLink="false">isacapodcast.podbean.com/10bda83b-7ff0-3876-a27b-3950fc83cdd6</guid>
                                    <description><![CDATA[On National IT Professionals Day, ISACA's Kevin Keh explains how IT professionals can advance digital trust in their organizations and in their industries.

Learn more at isaca.org/digital-trust 
]]></description>
                                                            <content:encoded><![CDATA[On National IT Professionals Day, ISACA's Kevin Keh explains how IT professionals can advance digital trust in their organizations and in their industries.<br>
<br>
Learn more at isaca.org/digital-trust 
]]></content:encoded>
                                    
        <enclosure url="https://mcdn.podbean.com/mf/web/adjnew/P_357_Digital_Trust_Through_IT_Estes_and_Keh_Audio_Edit_d194bdv.mp3" length="17642550" type="audio/mpeg"/>
        <itunes:summary><![CDATA[On National IT Professionals Day, ISACA's Kevin Keh explains how IT professionals can advance digital trust in their organizations and in their industries.Learn more at isaca.org/digital-trust 
]]></itunes:summary>
        <itunes:author>ISACA Podcast</itunes:author>
        <itunes:explicit>false</itunes:explicit>
        <itunes:block>No</itunes:block>
        <itunes:duration>733</itunes:duration>
                <itunes:episode>248</itunes:episode>
        <itunes:episodeType>full</itunes:episodeType>
            </item>
    <item>
        <title>Should Cybersecurity Be Subject to a SOX-Type Regulation?</title>
        <itunes:title>Should Cybersecurity Be Subject to a SOX-Type Regulation?</itunes:title>
        <link>https://isacapodcast.podbean.com/e/should-cybersecurity-be-subject-to-a-sox-type-regulation/</link>
                    <comments>https://isacapodcast.podbean.com/e/should-cybersecurity-be-subject-to-a-sox-type-regulation/#comments</comments>        <pubDate>Thu, 29 Dec 2022 15:00:00 +0000</pubDate>
        <guid isPermaLink="false">isacapodcast.podbean.com/bf84bca5-e71a-3acb-9a9b-0211a22cf89d</guid>
                                    <description><![CDATA[<p>Numerous laws and regulations have been passed to protect sensitive information, both at the federal and state level, creating a patchwork of requirements for companies to comply with. </p>
<p>However, with limited resources for cybersecurity investment, this uncoordinated approach has clouded objectives and led to decision paralysis within firms. Could cybersecurity implementation benefit from a Sarbanes-Oxley Act (SOX) type approach?</p>
<p>In this ISACA Podcast, Senior Director Mike Tomaselli joins ISACA’s Robin Lyons in this episode to discuss how this approach would create a risk-based, internal control model focused on cybersecurity that includes enforcement capabilities and requires third-party oversight and executive accountability.</p>
<p>To read Should Cybersecurity Be Subject to a SOX-Type Regulation? Please visit <a href='http://www.isaca.org/should-cybersecurity-be-subject-to-a-sox-type-regulation'>www.isaca.org/should-cybersecurity-be-subject-to-a-sox-type-regulation</a>. </p>
<p>To listen to more ISACA podcasts, please visit <a href='http://www.isaca.org/podcasts'>www.isaca.org/podcasts</a>. </p>
]]></description>
                                                            <content:encoded><![CDATA[<p>Numerous laws and regulations have been passed to protect sensitive information, both at the federal and state level, creating a patchwork of requirements for companies to comply with. </p>
<p>However, with limited resources for cybersecurity investment, this uncoordinated approach has clouded objectives and led to decision paralysis within firms. Could cybersecurity implementation benefit from a Sarbanes-Oxley Act (SOX) type approach?</p>
<p>In this ISACA Podcast, Senior Director Mike Tomaselli joins ISACA’s Robin Lyons in this episode to discuss how this approach would create a risk-based, internal control model focused on cybersecurity that includes enforcement capabilities and requires third-party oversight and executive accountability.</p>
<p>To read Should Cybersecurity Be Subject to a SOX-Type Regulation? Please visit <a href='http://www.isaca.org/should-cybersecurity-be-subject-to-a-sox-type-regulation'>www.isaca.org/should-cybersecurity-be-subject-to-a-sox-type-regulation</a>. </p>
<p>To listen to more ISACA podcasts, please visit <a href='http://www.isaca.org/podcasts'>www.isaca.org/podcasts</a>. </p>
]]></content:encoded>
                                    
        <enclosure url="https://mcdn.podbean.com/mf/web/dvem9h/P_342_Mike_Tomaselli_Audio_Edit_d1ahkyt.mp3" length="34148457" type="audio/mpeg"/>
        <itunes:summary><![CDATA[Numerous laws and regulations have been passed to protect sensitive information, both at the federal and state level, creating a patchwork of requirements for companies to comply with. 
However, with limited resources for cybersecurity investment, this uncoordinated approach has clouded objectives and led to decision paralysis within firms. Could cybersecurity implementation benefit from a Sarbanes-Oxley Act (SOX) type approach?
In this ISACA Podcast, Senior Director Mike Tomaselli joins ISACA’s Robin Lyons in this episode to discuss how this approach would create a risk-based, internal control model focused on cybersecurity that includes enforcement capabilities and requires third-party oversight and executive accountability.
To read Should Cybersecurity Be Subject to a SOX-Type Regulation? Please visit www.isaca.org/should-cybersecurity-be-subject-to-a-sox-type-regulation. 
To listen to more ISACA podcasts, please visit www.isaca.org/podcasts. ]]></itunes:summary>
        <itunes:author>ISACA Podcast</itunes:author>
        <itunes:explicit>false</itunes:explicit>
        <itunes:block>No</itunes:block>
        <itunes:duration>1420</itunes:duration>
                <itunes:episode>247</itunes:episode>
        <itunes:episodeType>full</itunes:episodeType>
            </item>
    <item>
        <title>Beware the Traps of Data Governance and Data Management Practice</title>
        <itunes:title>Beware the Traps of Data Governance and Data Management Practice</itunes:title>
        <link>https://isacapodcast.podbean.com/e/beware-the-traps-of-data-governance-and-data-management-practice/</link>
                    <comments>https://isacapodcast.podbean.com/e/beware-the-traps-of-data-governance-and-data-management-practice/#comments</comments>        <pubDate>Tue, 27 Dec 2022 15:00:00 +0000</pubDate>
        <guid isPermaLink="false">isacapodcast.podbean.com/de976331-93b9-3441-8724-3dbfce0868b7</guid>
                                    <description><![CDATA[<p>Guy Pearce joins ISACA’s Lisa Villanueva for a conversation about the traps of Data Governance and management. Guy breaks down Lore vs. Data, reasons for not using information for decision-making, and why data is a shared benefit for the organization.</p>
<p>Stay tuned until the close to hear Guy’s advice on using metaphors when communicating technical concepts to executive leadership.</p>
<p>To read Guy's full article, visit: <a href='https://nam10.safelinks.protection.outlook.com/?url=http%3A%2F%2Fwww.isaca.org%2Fbeware-the-traps-of-data-governance&data=05%7C01%7Clbuckley%40isaca.org%7C8f20c88955d849d8925808dae90b6de4%7C5454b19596ed4cc083a101b9255a3aee%7C1%7C0%7C638078532559501079%7CUnknown%7CTWFpbGZsb3d8eyJWIjoiMC4wLjAwMDAiLCJQIjoiV2luMzIiLCJBTiI6Ik1haWwiLCJXVCI6Mn0%3D%7C3000%7C%7C%7C&sdata=LtuX7YllGcswmfHunQu69Bo4qsyisE4k5AGbTWjgNiI%3D&reserved=0'>www.isaca.org/beware-the-traps-of-data-governance</a>.</p>
<p>To listen to more ISACA podcasts, please visit: <a href='https://www.isaca.org/podcasts'>www.isaca.org/podcasts</a>.</p>
]]></description>
                                                            <content:encoded><![CDATA[<p>Guy Pearce joins ISACA’s Lisa Villanueva for a conversation about the traps of Data Governance and management. Guy breaks down Lore vs. Data, reasons for not using information for decision-making, and why data is a shared benefit for the organization.</p>
<p>Stay tuned until the close to hear Guy’s advice on using metaphors when communicating technical concepts to executive leadership.</p>
<p>To read Guy's full article, visit: <a href='https://nam10.safelinks.protection.outlook.com/?url=http%3A%2F%2Fwww.isaca.org%2Fbeware-the-traps-of-data-governance&data=05%7C01%7Clbuckley%40isaca.org%7C8f20c88955d849d8925808dae90b6de4%7C5454b19596ed4cc083a101b9255a3aee%7C1%7C0%7C638078532559501079%7CUnknown%7CTWFpbGZsb3d8eyJWIjoiMC4wLjAwMDAiLCJQIjoiV2luMzIiLCJBTiI6Ik1haWwiLCJXVCI6Mn0%3D%7C3000%7C%7C%7C&sdata=LtuX7YllGcswmfHunQu69Bo4qsyisE4k5AGbTWjgNiI%3D&reserved=0'>www.isaca.org/beware-the-traps-of-data-governance</a>.</p>
<p>To listen to more ISACA podcasts, please visit: <a href='https://www.isaca.org/podcasts'>www.isaca.org/podcasts</a>.</p>
]]></content:encoded>
                                    
        <enclosure url="https://mcdn.podbean.com/mf/web/uizn7p/P_385_Guy_Pearce_Audio_Edit_d172ble.mp3" length="52150236" type="audio/mpeg"/>
        <itunes:summary><![CDATA[Guy Pearce joins ISACA’s Lisa Villanueva for a conversation about the traps of Data Governance and management. Guy breaks down Lore vs. Data, reasons for not using information for decision-making, and why data is a shared benefit for the organization.
Stay tuned until the close to hear Guy’s advice on using metaphors when communicating technical concepts to executive leadership.
To read Guy's full article, visit: www.isaca.org/beware-the-traps-of-data-governance.
To listen to more ISACA podcasts, please visit: www.isaca.org/podcasts.]]></itunes:summary>
        <itunes:author>ISACA Podcast</itunes:author>
        <itunes:explicit>false</itunes:explicit>
        <itunes:block>No</itunes:block>
        <itunes:duration>2171</itunes:duration>
                <itunes:episode>246</itunes:episode>
        <itunes:episodeType>full</itunes:episodeType>
            </item>
    <item>
        <title>Convergence: Where Next?</title>
        <itunes:title>Convergence: Where Next?</itunes:title>
        <link>https://isacapodcast.podbean.com/e/convergence-where-next/</link>
                    <comments>https://isacapodcast.podbean.com/e/convergence-where-next/#comments</comments>        <pubDate>Thu, 22 Dec 2022 15:00:00 +0000</pubDate>
        <guid isPermaLink="false">isacapodcast.podbean.com/158450c6-bdac-33de-b58f-855ea845f880</guid>
                                    <description><![CDATA[<p>ISACA’s Jeff Champion welcomes Steven Ross to the ISACA podcast. Steven asks what the effect of Convergence on the Control Community and concludes that everything is connected to every role, and it is becoming risky to have employees siloed within their own practice. He also remarks on how he once wrote an ISACA Journal article about companies creating a role for Chief Security Officer and now that is becoming a reality within the industry. Tune in now!</p>
<p>To read Steven’s full-length article, visit: <a href='http://www.isaca.org/convergence-where-next'>www.isaca.org/convergence-where-next</a></p>
<p>To listen to more ISACA podcasts, visit: <a href='http://www.isaca.org/podcasts'>www.isaca.org/podcasts</a></p>
]]></description>
                                                            <content:encoded><![CDATA[<p>ISACA’s Jeff Champion welcomes Steven Ross to the ISACA podcast. Steven asks what the effect of Convergence on the Control Community and concludes that everything is connected to every role, and it is becoming risky to have employees siloed within their own practice. He also remarks on how he once wrote an ISACA Journal article about companies creating a role for Chief Security Officer and now that is becoming a reality within the industry. Tune in now!</p>
<p>To read Steven’s full-length article, visit: <a href='http://www.isaca.org/convergence-where-next'>www.isaca.org/convergence-where-next</a></p>
<p>To listen to more ISACA podcasts, visit: <a href='http://www.isaca.org/podcasts'>www.isaca.org/podcasts</a></p>
]]></content:encoded>
                                    
        <enclosure url="https://mcdn.podbean.com/mf/web/wc4fg3/P_074_Steven_Ross_Audio_Edit_d1633qq.mp3" length="31975224" type="audio/mpeg"/>
        <itunes:summary><![CDATA[ISACA’s Jeff Champion welcomes Steven Ross to the ISACA podcast. Steven asks what the effect of Convergence on the Control Community and concludes that everything is connected to every role, and it is becoming risky to have employees siloed within their own practice. He also remarks on how he once wrote an ISACA Journal article about companies creating a role for Chief Security Officer and now that is becoming a reality within the industry. Tune in now!
To read Steven’s full-length article, visit: www.isaca.org/convergence-where-next
To listen to more ISACA podcasts, visit: www.isaca.org/podcasts]]></itunes:summary>
        <itunes:author>ISACA Podcast</itunes:author>
        <itunes:explicit>false</itunes:explicit>
        <itunes:block>No</itunes:block>
        <itunes:duration>1329</itunes:duration>
                <itunes:episode>245</itunes:episode>
        <itunes:episodeType>full</itunes:episodeType>
            </item>
    <item>
        <title>Do Data Go To Waste</title>
        <itunes:title>Do Data Go To Waste</itunes:title>
        <link>https://isacapodcast.podbean.com/e/do-data-go-to-waste/</link>
                    <comments>https://isacapodcast.podbean.com/e/do-data-go-to-waste/#comments</comments>        <pubDate>Tue, 20 Dec 2022 17:11:17 +0000</pubDate>
        <guid isPermaLink="false">isacapodcast.podbean.com/3f2a9a80-73f3-335a-ae38-9091791c04d2</guid>
                                    <description><![CDATA[<p>The Impact of SOX on the Industry 20 Years Ago and Today. Opponents of Sarbanes Oxley, (SOX) contend the law is too costly for companies to operationalize given the small benefit that SOX regulation provide. Proponents say that a world without SOX is a world in chaos. </p>
<p>This article discusses how SOX measures up 20 years after the law was enacted.</p>
<p>To read Cindy's ISACA Journal article, Do Data Go to Waste, please visit: <a href='https://www.isaca.org/do-data-go-to-waste'>www.isaca.org/do-data-go-to-waste</a></p>
<p>To listen to more ISACA Podcasts, please visit <a href='https://www.isaca.org/podcasts.'>www.isaca.org/podcasts.</a></p>
]]></description>
                                                            <content:encoded><![CDATA[<p>The Impact of SOX on the Industry 20 Years Ago and Today. Opponents of Sarbanes Oxley, (SOX) contend the law is too costly for companies to operationalize given the small benefit that SOX regulation provide. Proponents say that a world without SOX is a world in chaos. </p>
<p>This article discusses how SOX measures up 20 years after the law was enacted.</p>
<p>To read Cindy's ISACA Journal article, Do Data Go to Waste, please visit: <a href='https://www.isaca.org/do-data-go-to-waste'>www.isaca.org/do-data-go-to-waste</a></p>
<p>To listen to more ISACA Podcasts, please visit <a href='https://www.isaca.org/podcasts.'>www.isaca.org/podcasts.</a></p>
]]></content:encoded>
                                    
        <enclosure url="https://mcdn.podbean.com/mf/web/yckukj/ISACA_Podcast_Cindy_Baxter_-_Do_Data_Go_to_Waste_83_D19yc64.mp3" length="26132593" type="audio/mpeg"/>
        <itunes:summary><![CDATA[The Impact of SOX on the Industry 20 Years Ago and Today. Opponents of Sarbanes Oxley, (SOX) contend the law is too costly for companies to operationalize given the small benefit that SOX regulation provide. Proponents say that a world without SOX is a world in chaos. 
This article discusses how SOX measures up 20 years after the law was enacted.
To read Cindy's ISACA Journal article, Do Data Go to Waste, please visit: www.isaca.org/do-data-go-to-waste
To listen to more ISACA Podcasts, please visit www.isaca.org/podcasts.]]></itunes:summary>
        <itunes:author>ISACA Podcast</itunes:author>
        <itunes:explicit>false</itunes:explicit>
        <itunes:block>No</itunes:block>
        <itunes:duration>1084</itunes:duration>
                <itunes:episode>244</itunes:episode>
        <itunes:episodeType>full</itunes:episodeType>
            </item>
    <item>
        <title>Protecting Your Enterprise and Deterring Fraud in a New Risk Era</title>
        <itunes:title>Protecting Your Enterprise and Deterring Fraud in a New Risk Era</itunes:title>
        <link>https://isacapodcast.podbean.com/e/protecting-your-enterprise-and-deterring-fraud-in-a-new-risk-era/</link>
                    <comments>https://isacapodcast.podbean.com/e/protecting-your-enterprise-and-deterring-fraud-in-a-new-risk-era/#comments</comments>        <pubDate>Tue, 13 Dec 2022 16:41:57 +0000</pubDate>
        <guid isPermaLink="false">isacapodcast.podbean.com/764d3f21-574e-338d-a343-29910961acb1</guid>
                                    <description><![CDATA[<p>As uncertainty persists due to the COVID-19 pandemic, the war in Ukraine, international cyberthreats, inflation, and a looming recession, it is clear that the world has entered a new era of risk. These factors have created the perfect storm for rising fraud. In the past year, unauthorized digital account openings increased by 21%, while smartphone-related cyberattacks soared by 71%, reflecting a changing threat landscape impacting enterprises and consumers alike.</p>
<p>According to one global survey, nearly half of all respondents experienced fraud in the past 24 months, 3 compromising financial resources, personal data, and peace of mind with frightening rapidity. Recent research we have completed also reflects that “60% of Consumers Don't Believe Companies Do Enough to Protect Their Data as Demand for Security Grows".</p>
<p>Listen to the CEO of GBG Americas, Christina Luttrell, as she explains that, as a result, identity verification is a priority for organizations and government agencies that view it as a strategic differentiator that allows them to enhance the customer experience while improving their defensive posture at a critical time in this ISACA podcast episode.</p>
<p>To read the ISACA Journal article, Protecting Your Enterprise and Deterring Fraud in a New Risk Era, please visit: <a href='https://www.isaca.org/protecting-your-enterprise'>https://www.isaca.org/protecting-your-enterprise</a>.</p>
<p>To listen to more ISACA Podcasts, please visit <a href='http://www.isaca.org/podcasts'>www.isaca.org/podcasts</a>.</p>
<p> </p>
]]></description>
                                                            <content:encoded><![CDATA[<p>As uncertainty persists due to the COVID-19 pandemic, the war in Ukraine, international cyberthreats, inflation, and a looming recession, it is clear that the world has entered a new era of risk. These factors have created the perfect storm for rising fraud. In the past year, unauthorized digital account openings increased by 21%, while smartphone-related cyberattacks soared by 71%, reflecting a changing threat landscape impacting enterprises and consumers alike.</p>
<p>According to one global survey, nearly half of all respondents experienced fraud in the past 24 months, 3 compromising financial resources, personal data, and peace of mind with frightening rapidity. Recent research we have completed also reflects that “60% of Consumers Don't Believe Companies Do Enough to Protect Their Data as Demand for Security Grows".</p>
<p>Listen to the CEO of GBG Americas, Christina Luttrell, as she explains that, as a result, identity verification is a priority for organizations and government agencies that view it as a strategic differentiator that allows them to enhance the customer experience while improving their defensive posture at a critical time in this ISACA podcast episode.</p>
<p>To read the ISACA Journal article, Protecting Your Enterprise and Deterring Fraud in a New Risk Era, please visit: <a href='https://www.isaca.org/protecting-your-enterprise'>https://www.isaca.org/protecting-your-enterprise</a>.</p>
<p>To listen to more ISACA Podcasts, please visit <a href='http://www.isaca.org/podcasts'>www.isaca.org/podcasts</a>.</p>
<p> </p>
]]></content:encoded>
                                    
        <enclosure url="https://mcdn.podbean.com/mf/web/hia59c/P_389_Christina_Luttrell_Audio_Edit_d18nj2t.mp3" length="31801016" type="audio/mpeg"/>
        <itunes:summary><![CDATA[As uncertainty persists due to the COVID-19 pandemic, the war in Ukraine, international cyberthreats, inflation, and a looming recession, it is clear that the world has entered a new era of risk. These factors have created the perfect storm for rising fraud. In the past year, unauthorized digital account openings increased by 21%, while smartphone-related cyberattacks soared by 71%, reflecting a changing threat landscape impacting enterprises and consumers alike.
According to one global survey, nearly half of all respondents experienced fraud in the past 24 months, 3 compromising financial resources, personal data, and peace of mind with frightening rapidity. Recent research we have completed also reflects that “60% of Consumers Don't Believe Companies Do Enough to Protect Their Data as Demand for Security Grows".
Listen to the CEO of GBG Americas, Christina Luttrell, as she explains that, as a result, identity verification is a priority for organizations and government agencies that view it as a strategic differentiator that allows them to enhance the customer experience while improving their defensive posture at a critical time in this ISACA podcast episode.
To read the ISACA Journal article, Protecting Your Enterprise and Deterring Fraud in a New Risk Era, please visit: https://www.isaca.org/protecting-your-enterprise.
To listen to more ISACA Podcasts, please visit www.isaca.org/podcasts.
 ]]></itunes:summary>
        <itunes:author>ISACA Podcast</itunes:author>
        <itunes:explicit>false</itunes:explicit>
        <itunes:block>No</itunes:block>
        <itunes:duration>1322</itunes:duration>
                <itunes:episode>243</itunes:episode>
        <itunes:episodeType>full</itunes:episodeType>
            </item>
    <item>
        <title>The Circle of Failure: Why the Cyber Security Industry Doesn’t Work</title>
        <itunes:title>The Circle of Failure: Why the Cyber Security Industry Doesn’t Work</itunes:title>
        <link>https://isacapodcast.podbean.com/e/the-circle-of-failure-why-the-cyber-security-industry-doesn-t-work/</link>
                    <comments>https://isacapodcast.podbean.com/e/the-circle-of-failure-why-the-cyber-security-industry-doesn-t-work/#comments</comments>        <pubDate>Fri, 09 Dec 2022 15:55:46 +0000</pubDate>
        <guid isPermaLink="false">isacapodcast.podbean.com/ba6a6278-cefb-38d1-9cd1-d45dc5d88bb6</guid>
                                    <description><![CDATA[<p>Richard Hollis, Director of Rick Crew, is serious about asking the tough questions.</p>
<p>ISACA’s Jon Brandt welcomes him to the ISACA podcast to have a conversation that challenges the status quo: Does the Cyber Security Industry work? After decades of experience in the security industry, Richard asks, “have I affected any change?” Richard points out that if we buy a toaster at the store and it doesn’t work, we return it, but as security professionals, we don’t hold products to the same standards. Why is this? Jon and Richard go back and forth on FUD, vendors, false positives, and where accountability lies in the industry.</p>
<p>Join Richard and Jon in the conversation to think about how we can affect the positive change that we want to see in our industry in the future!</p>
<p>To read Richard's full report, please visit <a href='https://nam10.safelinks.protection.outlook.com/?url=http%3A%2F%2Fwww.isaca.org%2Fthe-circle-of-failure&data=05%7C01%7Clbuckley%40isaca.org%7Cc2766bf9511d4b0bc2fd08dac7330864%7C5454b19596ed4cc083a101b9255a3aee%7C1%7C0%7C638041319245295528%7CUnknown%7CTWFpbGZsb3d8eyJWIjoiMC4wLjAwMDAiLCJQIjoiV2luMzIiLCJBTiI6Ik1haWwiLCJXVCI6Mn0%3D%7C3000%7C%7C%7C&sdata=Ci97XgwbC4MSKYX6PYcCwnqxyP3i2BG6gXeMoN%2Bi2dY%3D&reserved=0'>www.isaca.org/the-circle-of-failure</a>.</p>
<p>To listen to more ISACA podcasts, visit <a href='http://www.isaca.org/podcasts'>www.isaca.org/podcasts</a>.</p>
]]></description>
                                                            <content:encoded><![CDATA[<p>Richard Hollis, Director of Rick Crew, is serious about asking the tough questions.</p>
<p>ISACA’s Jon Brandt welcomes him to the ISACA podcast to have a conversation that challenges the status quo: Does the Cyber Security Industry work? After decades of experience in the security industry, Richard asks, “have I affected any change?” Richard points out that if we buy a toaster at the store and it doesn’t work, we return it, but as security professionals, we don’t hold products to the same standards. Why is this? Jon and Richard go back and forth on FUD, vendors, false positives, and where accountability lies in the industry.</p>
<p>Join Richard and Jon in the conversation to think about how we can affect the positive change that we want to see in our industry in the future!</p>
<p>To read Richard's full report, please visit <a href='https://nam10.safelinks.protection.outlook.com/?url=http%3A%2F%2Fwww.isaca.org%2Fthe-circle-of-failure&data=05%7C01%7Clbuckley%40isaca.org%7Cc2766bf9511d4b0bc2fd08dac7330864%7C5454b19596ed4cc083a101b9255a3aee%7C1%7C0%7C638041319245295528%7CUnknown%7CTWFpbGZsb3d8eyJWIjoiMC4wLjAwMDAiLCJQIjoiV2luMzIiLCJBTiI6Ik1haWwiLCJXVCI6Mn0%3D%7C3000%7C%7C%7C&sdata=Ci97XgwbC4MSKYX6PYcCwnqxyP3i2BG6gXeMoN%2Bi2dY%3D&reserved=0'>www.isaca.org/the-circle-of-failure</a>.</p>
<p>To listen to more ISACA podcasts, visit <a href='http://www.isaca.org/podcasts'>www.isaca.org/podcasts</a>.</p>
]]></content:encoded>
                                    
        <enclosure url="https://mcdn.podbean.com/mf/web/hi3v5s/P_383_Richard_Hollis_Audio_Edit_d19fd7r.mp3" length="72926589" type="audio/mpeg"/>
        <itunes:summary><![CDATA[Richard Hollis, Director of Rick Crew, is serious about asking the tough questions.
ISACA’s Jon Brandt welcomes him to the ISACA podcast to have a conversation that challenges the status quo: Does the Cyber Security Industry work? After decades of experience in the security industry, Richard asks, “have I affected any change?” Richard points out that if we buy a toaster at the store and it doesn’t work, we return it, but as security professionals, we don’t hold products to the same standards. Why is this? Jon and Richard go back and forth on FUD, vendors, false positives, and where accountability lies in the industry.
Join Richard and Jon in the conversation to think about how we can affect the positive change that we want to see in our industry in the future!
To read Richard's full report, please visit www.isaca.org/the-circle-of-failure.
To listen to more ISACA podcasts, visit www.isaca.org/podcasts.]]></itunes:summary>
        <itunes:author>ISACA Podcast</itunes:author>
        <itunes:explicit>false</itunes:explicit>
        <itunes:block>No</itunes:block>
        <itunes:duration>3035</itunes:duration>
                <itunes:episode>242</itunes:episode>
        <itunes:episodeType>full</itunes:episodeType>
            </item>
    <item>
        <title>Meeting Attackers Where They Are</title>
        <itunes:title>Meeting Attackers Where They Are</itunes:title>
        <link>https://isacapodcast.podbean.com/e/meeting-attackers-where-they-are/</link>
                    <comments>https://isacapodcast.podbean.com/e/meeting-attackers-where-they-are/#comments</comments>        <pubDate>Tue, 29 Nov 2022 08:00:00 +0000</pubDate>
        <guid isPermaLink="false">isacapodcast.podbean.com/624509f9-e535-3b63-9fcf-55a0292eeedb</guid>
                                    <description><![CDATA[<p>The world's largest software companies leverage modern-day Red Teams to protect against real-world attacks. Many companies focus on vulnerability management, compliance, and patching to secure themselves, but this is only a tiny part of the big picture. An improved security posture is achieved by leveraging the Red Team to pressure test the attack surface and discover the impact that can be made by actively exploiting the soft spots of the company.</p>
<p>In this podcast, Justin Tiplitsky, Director of the Red Team at Adobe, talks about how his team uses adversary intel to perform continuous testing on the parts of the company that attackers are the most interested in targeting. This continuous testing leads to the relentless identification of the most opportunistic areas to attack, more closely emulating the never-ending threat from real adversaries. Testing is followed up by storytelling and data to influence change within the company.</p>
<p>To learn more about Adobe, please visit: <a href='http://www.adobe.com'>www.adobe.com</a></p>
<p>To listen to more ISACA Podcasts, please visit: <a href='http://www.isaca.org/podcasts'>www.isaca.org/podcasts</a></p>
]]></description>
                                                            <content:encoded><![CDATA[<p>The world's largest software companies leverage modern-day Red Teams to protect against real-world attacks. Many companies focus on vulnerability management, compliance, and patching to secure themselves, but this is only a tiny part of the big picture. An improved security posture is achieved by leveraging the Red Team to pressure test the attack surface and discover the impact that can be made by actively exploiting the soft spots of the company.</p>
<p>In this podcast, Justin Tiplitsky, Director of the Red Team at Adobe, talks about how his team uses adversary intel to perform continuous testing on the parts of the company that attackers are the most interested in targeting. This continuous testing leads to the relentless identification of the most opportunistic areas to attack, more closely emulating the never-ending threat from real adversaries. Testing is followed up by storytelling and data to influence change within the company.</p>
<p>To learn more about Adobe, please visit: <a href='http://www.adobe.com'>www.adobe.com</a></p>
<p>To listen to more ISACA Podcasts, please visit: <a href='http://www.isaca.org/podcasts'>www.isaca.org/podcasts</a></p>
]]></content:encoded>
                                    
        <enclosure url="https://mcdn.podbean.com/mf/web/p7hnjz/P_249_Adobe_Audio_Editabot5.mp3" length="32540807" type="audio/mpeg"/>
        <itunes:summary><![CDATA[The world's largest software companies leverage modern-day Red Teams to protect against real-world attacks. Many companies focus on vulnerability management, compliance, and patching to secure themselves, but this is only a tiny part of the big picture. An improved security posture is achieved by leveraging the Red Team to pressure test the attack surface and discover the impact that can be made by actively exploiting the soft spots of the company.
In this podcast, Justin Tiplitsky, Director of the Red Team at Adobe, talks about how his team uses adversary intel to perform continuous testing on the parts of the company that attackers are the most interested in targeting. This continuous testing leads to the relentless identification of the most opportunistic areas to attack, more closely emulating the never-ending threat from real adversaries. Testing is followed up by storytelling and data to influence change within the company.
To learn more about Adobe, please visit: www.adobe.com
To listen to more ISACA Podcasts, please visit: www.isaca.org/podcasts]]></itunes:summary>
        <itunes:author>ISACA Podcast</itunes:author>
        <itunes:explicit>false</itunes:explicit>
        <itunes:block>No</itunes:block>
        <itunes:duration>1353</itunes:duration>
                <itunes:episode>241</itunes:episode>
        <itunes:episodeType>full</itunes:episodeType>
            </item>
    <item>
        <title>Taking Security Strategy to the Next Level: The Cyber Kill Chain vs. MITRE ATT&amp;CK</title>
        <itunes:title>Taking Security Strategy to the Next Level: The Cyber Kill Chain vs. MITRE ATT&amp;CK</itunes:title>
        <link>https://isacapodcast.podbean.com/e/taking-security-strategy-to-the-next-level-the-cyber-kill-chain-vs-mitre-attck/</link>
                    <comments>https://isacapodcast.podbean.com/e/taking-security-strategy-to-the-next-level-the-cyber-kill-chain-vs-mitre-attck/#comments</comments>        <pubDate>Tue, 22 Nov 2022 16:34:13 +0000</pubDate>
        <guid isPermaLink="false">isacapodcast.podbean.com/36c3fe0a-143b-3f3c-961e-45e55a9d0c23</guid>
                                    <description><![CDATA[<p>In an era of rampant ransomware and other malicious cyberattacks, it’s mandatory to double down on cybersecurity analysis and strategy to ensure an optimal security posture and the protection of critical assets and data.</p>
<p>Today, two models can help security professionals harden network resources and protect against modern-day threats and attacks: the cyber kill chain (CKC)and the MITRE ATT&CK framework.</p>
<p>Tim Liu, long-term security technologist, co-founder, and CTO, will provide an overview of these two frameworks and the limitations or benefits of each approach. </p>
<p>To read Taking Security Strategy to the Next Level, please visit <a href='http://www.isaca.org/taking-security-strategy-to-the-next-level'>www.isaca.org/taking-security-strategy-to-the-next-level</a>.</p>
<p>To listen to more ISACA podcasts, please visit <a href='http://www.isaca.org/podcasts'>www.isaca.org/podcasts.</a></p>
]]></description>
                                                            <content:encoded><![CDATA[<p>In an era of rampant ransomware and other malicious cyberattacks, it’s mandatory to double down on cybersecurity analysis and strategy to ensure an optimal security posture and the protection of critical assets and data.</p>
<p>Today, two models can help security professionals harden network resources and protect against modern-day threats and attacks: the cyber kill chain (CKC)and the MITRE ATT&CK framework.</p>
<p>Tim Liu, long-term security technologist, co-founder, and CTO, will provide an overview of these two frameworks and the limitations or benefits of each approach. </p>
<p>To read Taking Security Strategy to the Next Level, please visit <a href='http://www.isaca.org/taking-security-strategy-to-the-next-level'>www.isaca.org/taking-security-strategy-to-the-next-level</a>.</p>
<p>To listen to more ISACA podcasts, please visit <a href='http://www.isaca.org/podcasts'>www.isaca.org/podcasts.</a></p>
]]></content:encoded>
                                    
        <enclosure url="https://mcdn.podbean.com/mf/web/axhwz3/P_369_Tim_Liu_Audio_Edit_d1bk4dg.mp3" length="33459876" type="audio/mpeg"/>
        <itunes:summary><![CDATA[In an era of rampant ransomware and other malicious cyberattacks, it’s mandatory to double down on cybersecurity analysis and strategy to ensure an optimal security posture and the protection of critical assets and data.
Today, two models can help security professionals harden network resources and protect against modern-day threats and attacks: the cyber kill chain (CKC)and the MITRE ATT&CK framework.
Tim Liu, long-term security technologist, co-founder, and CTO, will provide an overview of these two frameworks and the limitations or benefits of each approach. 
To read Taking Security Strategy to the Next Level, please visit www.isaca.org/taking-security-strategy-to-the-next-level.
To listen to more ISACA podcasts, please visit www.isaca.org/podcasts.]]></itunes:summary>
        <itunes:author>ISACA Podcast</itunes:author>
        <itunes:explicit>false</itunes:explicit>
        <itunes:block>No</itunes:block>
        <itunes:duration>1390</itunes:duration>
                <itunes:episode>240</itunes:episode>
        <itunes:episodeType>full</itunes:episodeType>
            </item>
    <item>
        <title>Auditee Buy-In—A Key Component of Effective Audits</title>
        <itunes:title>Auditee Buy-In—A Key Component of Effective Audits</itunes:title>
        <link>https://isacapodcast.podbean.com/e/auditee-buy-in%e2%80%94a-key-component-of-effective-audits/</link>
                    <comments>https://isacapodcast.podbean.com/e/auditee-buy-in%e2%80%94a-key-component-of-effective-audits/#comments</comments>        <pubDate>Thu, 10 Nov 2022 18:02:31 +0000</pubDate>
        <guid isPermaLink="false">isacapodcast.podbean.com/234ef59b-5b0b-373c-8466-ef821ecea173</guid>
                                    <description><![CDATA[<p>As you plan and execute your audit, do you take time to invest in the stakeholder relationship? This can be an often-overlooked element but essential in an effective audit.</p>
<p>Tune into this ISACA Podcast as Steve Jackson, IT Audit Manager at Airbnb, chats with ISACA’s Robin Lyons about ways to gain auditee buy-in and have a successful and effective audit.</p>
<p>To read Steve’s full-length article, “Auditee Buy-In—A Key Component of Effective Audits,” visit <a href='http://www.isaca.org/auditee-buy-in'>www.isaca.org/auditee-buy-in</a></p>
<p>To watch the ISACA Video Podcast of this episode, visit, <a href='https://youtu.be/nWFcXC24ueA'>https://youtu.be/nWFcXC24ueA</a>. </p>
<p>For more ISACA Podcasts, please visit: <a href='http://www.isaca.org/podcasts'>www.isaca.org/podcasts</a> or visit ISACA YouTube Channel at <a href='https://www.youtube.com/c/IsacaHq'>https://www.youtube.com/c/IsacaHq</a>.</p>
<p> </p>
]]></description>
                                                            <content:encoded><![CDATA[<p>As you plan and execute your audit, do you take time to invest in the stakeholder relationship? This can be an often-overlooked element but essential in an effective audit.</p>
<p>Tune into this ISACA Podcast as Steve Jackson, IT Audit Manager at Airbnb, chats with ISACA’s Robin Lyons about ways to gain auditee buy-in and have a successful and effective audit.</p>
<p>To read Steve’s full-length article, <em>“Auditee Buy-In—A Key Component of Effective Audits,”</em> visit <a href='http://www.isaca.org/auditee-buy-in'>www.isaca.org/auditee-buy-in</a></p>
<p>To watch the ISACA Video Podcast of this episode, visit, <a href='https://youtu.be/nWFcXC24ueA'>https://youtu.be/nWFcXC24ueA</a>. </p>
<p>For more ISACA Podcasts, please visit: <a href='http://www.isaca.org/podcasts'>www.isaca.org/podcasts</a> or visit ISACA YouTube Channel at <a href='https://www.youtube.com/c/IsacaHq'>https://www.youtube.com/c/IsacaHq</a>.</p>
<p> </p>
]]></content:encoded>
                                    
        <enclosure url="https://mcdn.podbean.com/mf/web/qbe29m/ISACA_Productions_Steve_Jackson_370_Audio__FINAL7pqmv.mp3" length="29013971" type="audio/mpeg"/>
        <itunes:summary><![CDATA[As you plan and execute your audit, do you take time to invest in the stakeholder relationship? This can be an often-overlooked element but essential in an effective audit.
Tune into this ISACA Podcast as Steve Jackson, IT Audit Manager at Airbnb, chats with ISACA’s Robin Lyons about ways to gain auditee buy-in and have a successful and effective audit.
To read Steve’s full-length article, “Auditee Buy-In—A Key Component of Effective Audits,” visit www.isaca.org/auditee-buy-in
To watch the ISACA Video Podcast of this episode, visit, https://youtu.be/nWFcXC24ueA. 
For more ISACA Podcasts, please visit: www.isaca.org/podcasts or visit ISACA YouTube Channel at https://www.youtube.com/c/IsacaHq.
 ]]></itunes:summary>
        <itunes:author>ISACA Podcast</itunes:author>
        <itunes:explicit>false</itunes:explicit>
        <itunes:block>No</itunes:block>
        <itunes:duration>1205</itunes:duration>
                <itunes:episode>239</itunes:episode>
        <itunes:episodeType>full</itunes:episodeType>
            </item>
    <item>
        <title>Breaking Down the ESET T2 2022 Threat Report</title>
        <itunes:title>Breaking Down the ESET T2 2022 Threat Report</itunes:title>
        <link>https://isacapodcast.podbean.com/e/breaking-down-the-eset-t2-2022-threat-report/</link>
                    <comments>https://isacapodcast.podbean.com/e/breaking-down-the-eset-t2-2022-threat-report/#comments</comments>        <pubDate>Tue, 08 Nov 2022 21:55:56 +0000</pubDate>
        <guid isPermaLink="false">isacapodcast.podbean.com/c65cd7db-f1af-3a94-8521-a277120d85fd</guid>
                                    <description><![CDATA[<p> In this ISACA Podcast episode, ESET’s Chief Security Evangelist, Tony Anscombe, joins ISACA’s Principal, Emerging Technology Professional Practices, Collin Beder to discuss ESET’s recently released T2 2022 Threat Report.</p>
<p>As a global leader in cybersecurity, ESET’s T2 2022 Threat Report summarizes the most notable trends that have shaped the threat landscape for the past four months. This report dives into CloudMensis, the previously unknown macOS malware discovered by ESET researchers.</p>
<p>To read the full ESET report: <a href='https://www.welivesecurity.com/wpcontent/uploads/2022/10/eset_threat_report_t22022.pdf'>https://www.welivesecurity.com/wpcontent/uploads/2022/10/eset_threat_report_t22022.pdf</a>.</p>
<p>For more information, check out ESET’s award-winning blog: WeLiveSecurity. Make sure to follow ESET Research on Twitter for the latest news from ESET Research.</p>
<p>To listen to more ISACA Podcasts, please visit <a href='http://www.isaca.org/podcasts'>www.isaca.org/podcasts</a>.</p>
]]></description>
                                                            <content:encoded><![CDATA[<p> In this ISACA Podcast episode, ESET’s Chief Security Evangelist, Tony Anscombe, joins ISACA’s Principal, Emerging Technology Professional Practices, Collin Beder to discuss ESET’s recently released T2 2022 Threat Report.</p>
<p>As a global leader in cybersecurity, ESET’s T2 2022 Threat Report summarizes the most notable trends that have shaped the threat landscape for the past four months. This report dives into CloudMensis, the previously unknown macOS malware discovered by ESET researchers.</p>
<p>To read the full ESET report: <a href='https://www.welivesecurity.com/wpcontent/uploads/2022/10/eset_threat_report_t22022.pdf'>https://www.welivesecurity.com/wpcontent/uploads/2022/10/eset_threat_report_t22022.pdf</a>.</p>
<p>For more information, check out ESET’s award-winning blog: WeLiveSecurity. Make sure to follow ESET Research on Twitter for the latest news from ESET Research.</p>
<p>To listen to more ISACA Podcasts, please visit <a href='http://www.isaca.org/podcasts'>www.isaca.org/podcasts</a>.</p>
]]></content:encoded>
                                    
        <enclosure url="https://mcdn.podbean.com/mf/web/f2qbx5/P_121_ESET_T2_2022_Audio_Podcast_d1811s9.mp3" length="31208234" type="audio/mpeg"/>
        <itunes:summary><![CDATA[ In this ISACA Podcast episode, ESET’s Chief Security Evangelist, Tony Anscombe, joins ISACA’s Principal, Emerging Technology Professional Practices, Collin Beder to discuss ESET’s recently released T2 2022 Threat Report.
As a global leader in cybersecurity, ESET’s T2 2022 Threat Report summarizes the most notable trends that have shaped the threat landscape for the past four months. This report dives into CloudMensis, the previously unknown macOS malware discovered by ESET researchers.
To read the full ESET report: https://www.welivesecurity.com/wpcontent/uploads/2022/10/eset_threat_report_t22022.pdf.
For more information, check out ESET’s award-winning blog: WeLiveSecurity. Make sure to follow ESET Research on Twitter for the latest news from ESET Research.
To listen to more ISACA Podcasts, please visit www.isaca.org/podcasts.]]></itunes:summary>
        <itunes:author>ISACA Podcast</itunes:author>
        <itunes:explicit>false</itunes:explicit>
        <itunes:block>No</itunes:block>
        <itunes:duration>1297</itunes:duration>
                <itunes:episode>238</itunes:episode>
        <itunes:episodeType>full</itunes:episodeType>
            </item>
    <item>
        <title>Enabling Digital Trust through Canada’s Digital Charter</title>
        <itunes:title>Enabling Digital Trust through Canada’s Digital Charter</itunes:title>
        <link>https://isacapodcast.podbean.com/e/enabling-digital-trust-through-canada-s-digital-charter/</link>
                    <comments>https://isacapodcast.podbean.com/e/enabling-digital-trust-through-canada-s-digital-charter/#comments</comments>        <pubDate>Fri, 04 Nov 2022 17:07:42 +0000</pubDate>
        <guid isPermaLink="false">isacapodcast.podbean.com/619d0208-50f4-33c5-83ec-a2b4d81e5a9a</guid>
                                    <description><![CDATA[<p>Data are the lifelines of a digital economy. They drive innovation, enabling cutting-edge research and next-generation technologies, including artificial intelligence (AI), robotics, and the Internet of things (IoT). But these opportunities introduce new sources of risk that must be managed appropriately. Canadians are raising important questions such as, “How will personal data be used?” and “What controls are in place to safeguard privacy and security?” </p>
<p>To encourage innovation within the digital economy while managing this risk, the Government of Canada has established the need for digital trust between citizens and organizations as an enabler by implementing a Digital Charter. As the Canadian government cites, “Trust is the foundation on which our digital and data-driven Canadian economy will be built.” This digital trust is defined by the “confidence that users have in the ability of people, technology, and processes to create a secure digital world.</p>
<p>Tune into this ISACA Podcast as the Acting Director of Internal Assurance at the Office of Enterprise Risk & Assurance of the University of British Columbia (UBC), Mary Carmichael, join’s ISACA’s Safia Kazi to explore topics including what is the Digital Charter and how it supports digital trust; what are critical elements of the Digital Charter (e.g., AI Ethics, Privacy, Principles for the Digital Economy); what are the implications for organizations and the public.</p>
<p> </p>
<p>To read Mary’s full-length article, visit <a href='https://www.isaca.org/enabling-digital-trust-with-canadas-digital-charter'>https://www.isaca.org/enabling-digital-trust-with-canadas-digital-charter</a>.</p>
]]></description>
                                                            <content:encoded><![CDATA[<p>Data are the lifelines of a digital economy. They drive innovation, enabling cutting-edge research and next-generation technologies, including artificial intelligence (AI), robotics, and the Internet of things (IoT). But these opportunities introduce new sources of risk that must be managed appropriately. Canadians are raising important questions such as, “How will personal data be used?” and “What controls are in place to safeguard privacy and security?” </p>
<p>To encourage innovation within the digital economy while managing this risk, the Government of Canada has established the need for digital trust between citizens and organizations as an enabler by implementing a Digital Charter. As the Canadian government cites, “Trust is the foundation on which our digital and data-driven Canadian economy will be built.” This digital trust is defined by the “confidence that users have in the ability of people, technology, and processes to create a secure digital world.</p>
<p>Tune into this ISACA Podcast as the Acting Director of Internal Assurance at the Office of Enterprise Risk & Assurance of the University of British Columbia (UBC), Mary Carmichael, join’s ISACA’s Safia Kazi to explore topics including what is the Digital Charter and how it supports digital trust; what are critical elements of the Digital Charter (e.g., AI Ethics, Privacy, Principles for the Digital Economy); what are the implications for organizations and the public.</p>
<p> </p>
<p>To read Mary’s full-length article, visit <a href='https://www.isaca.org/enabling-digital-trust-with-canadas-digital-charter'>https://www.isaca.org/enabling-digital-trust-with-canadas-digital-charter</a>.</p>
]]></content:encoded>
                                    
        <enclosure url="https://mcdn.podbean.com/mf/web/9k3c5k/P_351_Mary_Carmichael_Audio_Podcast_d1704yn.mp3" length="36179474" type="audio/mpeg"/>
        <itunes:summary><![CDATA[Data are the lifelines of a digital economy. They drive innovation, enabling cutting-edge research and next-generation technologies, including artificial intelligence (AI), robotics, and the Internet of things (IoT). But these opportunities introduce new sources of risk that must be managed appropriately. Canadians are raising important questions such as, “How will personal data be used?” and “What controls are in place to safeguard privacy and security?” 
To encourage innovation within the digital economy while managing this risk, the Government of Canada has established the need for digital trust between citizens and organizations as an enabler by implementing a Digital Charter. As the Canadian government cites, “Trust is the foundation on which our digital and data-driven Canadian economy will be built.” This digital trust is defined by the “confidence that users have in the ability of people, technology, and processes to create a secure digital world.
Tune into this ISACA Podcast as the Acting Director of Internal Assurance at the Office of Enterprise Risk & Assurance of the University of British Columbia (UBC), Mary Carmichael, join’s ISACA’s Safia Kazi to explore topics including what is the Digital Charter and how it supports digital trust; what are critical elements of the Digital Charter (e.g., AI Ethics, Privacy, Principles for the Digital Economy); what are the implications for organizations and the public.
 
To read Mary’s full-length article, visit https://www.isaca.org/enabling-digital-trust-with-canadas-digital-charter.]]></itunes:summary>
        <itunes:author>ISACA Podcast</itunes:author>
        <itunes:explicit>false</itunes:explicit>
        <itunes:block>No</itunes:block>
        <itunes:duration>1505</itunes:duration>
                <itunes:episode>237</itunes:episode>
        <itunes:episodeType>full</itunes:episodeType>
            </item>
    <item>
        <title>It’s About (Down) Time</title>
        <itunes:title>It’s About (Down) Time</itunes:title>
        <link>https://isacapodcast.podbean.com/e/it-s-about-down-time/</link>
                    <comments>https://isacapodcast.podbean.com/e/it-s-about-down-time/#comments</comments>        <pubDate>Tue, 01 Nov 2022 14:14:37 +0000</pubDate>
        <guid isPermaLink="false">isacapodcast.podbean.com/c50e5919-2c7e-3f2b-900e-8df346179c04</guid>
                                    <description><![CDATA[<p>It is all about the system's downtime.</p>
<p>In this ISACA Podcast episode, Risk Masters International's Steven Ross tells ISACA's Collin Beder that organizations should start focusing on hours of unavailable systems and data when measuring the cost of a cyber-attack. Steven also discusses the causes and targets of system downtime and why he thinks the IT world is currently living in a dangerous time.</p>
<p> </p>
<p>To read Steven's full-length article, visit <a href='http://www.isaca.org/its-about-down-time'>www.isaca.org/its-about-down-time.</a></p>
<p>To listen to more ISACA Podcasts, visit <a href='http://www.isaca.org/podcasts'>www.isaca.org/podcasts</a>.</p>
]]></description>
                                                            <content:encoded><![CDATA[<p>It is all about the system's downtime.</p>
<p>In this ISACA Podcast episode, Risk Masters International's Steven Ross tells ISACA's Collin Beder that organizations should start focusing on hours of unavailable systems and data when measuring the cost of a cyber-attack. Steven also discusses the causes and targets of system downtime and why he thinks the IT world is currently living in a dangerous time.</p>
<p> </p>
<p>To read Steven's full-length article, visit <a href='http://www.isaca.org/its-about-down-time'>www.isaca.org/its-about-down-time.</a></p>
<p>To listen to more ISACA Podcasts, visit <a href='http://www.isaca.org/podcasts'>www.isaca.org/podcasts</a>.</p>
]]></content:encoded>
                                    
        <enclosure url="https://mcdn.podbean.com/mf/web/fgf2ze/P_073_Steven_Ross_Audio_Podcast_d1ar6qi.mp3" length="14066662" type="audio/mpeg"/>
        <itunes:summary><![CDATA[It is all about the system's downtime.
In this ISACA Podcast episode, Risk Masters International's Steven Ross tells ISACA's Collin Beder that organizations should start focusing on hours of unavailable systems and data when measuring the cost of a cyber-attack. Steven also discusses the causes and targets of system downtime and why he thinks the IT world is currently living in a dangerous time.
 
To read Steven's full-length article, visit www.isaca.org/its-about-down-time.
To listen to more ISACA Podcasts, visit www.isaca.org/podcasts.]]></itunes:summary>
        <itunes:author>ISACA Podcast</itunes:author>
        <itunes:explicit>false</itunes:explicit>
        <itunes:block>No</itunes:block>
        <itunes:duration>876</itunes:duration>
                <itunes:episode>236</itunes:episode>
        <itunes:episodeType>full</itunes:episodeType>
            </item>
    <item>
        <title>How Social Engineering Bypasses Technical Controls</title>
        <itunes:title>How Social Engineering Bypasses Technical Controls</itunes:title>
        <link>https://isacapodcast.podbean.com/e/how-social-engineering-bypasses-technical-controls/</link>
                    <comments>https://isacapodcast.podbean.com/e/how-social-engineering-bypasses-technical-controls/#comments</comments>        <pubDate>Thu, 27 Oct 2022 09:00:00 +0000</pubDate>
        <guid isPermaLink="false">isacapodcast.podbean.com/ec72ffd3-6a55-3691-9cd5-a6f5fdce5a51</guid>
                                    <description><![CDATA[<p>We are subjected to phishing scams almost every day, and even the most seasoned professional must examine an email to ensure the links included are safe.</p>
<p>Brown University and Federal Reserve Bank of Cleveland's Allen Dziwa says people are the weakest link and that customized messaging using regional language for targeted attacks is becoming more prevalent. Allen breaks down the many types of attacks (phishing, spear phishing, smishing, vishing, whaling) with ISACA's Kevin Keh. Tune in now to learn how to be vigilant when facing potential attacks from scammers.</p>
<p>To read Allen’s full article, please visit: <a href='http://www.isaca.org/how-social-engineering-bypasses-technical-controls'>www.isaca.org/how-social-engineering-bypasses-technical-controls</a></p>
<p>To listen to more ISACA Podcasts, please visit: <a href='http://www.isaca.org/podcasts'>www.isaca.org/podcasts</a></p>
]]></description>
                                                            <content:encoded><![CDATA[<p>We are subjected to phishing scams almost every day, and even the most seasoned professional must examine an email to ensure the links included are safe.</p>
<p>Brown University and Federal Reserve Bank of Cleveland's Allen Dziwa says people are the weakest link and that customized messaging using regional language for targeted attacks is becoming more prevalent. Allen breaks down the many types of attacks (phishing, spear phishing, smishing, vishing, whaling) with ISACA's Kevin Keh. Tune in now to learn how to be vigilant when facing potential attacks from scammers.</p>
<p>To read Allen’s full article, please visit: <a href='http://www.isaca.org/how-social-engineering-bypasses-technical-controls'>www.isaca.org/how-social-engineering-bypasses-technical-controls</a></p>
<p>To listen to more ISACA Podcasts, please visit: <a href='http://www.isaca.org/podcasts'>www.isaca.org/podcasts</a></p>
]]></content:encoded>
                                    
        <enclosure url="https://mcdn.podbean.com/mf/web/ms9zrm/P_329_Allen_Dziwa_Audio_Podcast_d1akzhi.mp3" length="21907322" type="audio/mpeg"/>
        <itunes:summary><![CDATA[We are subjected to phishing scams almost every day, and even the most seasoned professional must examine an email to ensure the links included are safe.
Brown University and Federal Reserve Bank of Cleveland's Allen Dziwa says people are the weakest link and that customized messaging using regional language for targeted attacks is becoming more prevalent. Allen breaks down the many types of attacks (phishing, spear phishing, smishing, vishing, whaling) with ISACA's Kevin Keh. Tune in now to learn how to be vigilant when facing potential attacks from scammers.
To read Allen’s full article, please visit: www.isaca.org/how-social-engineering-bypasses-technical-controls
To listen to more ISACA Podcasts, please visit: www.isaca.org/podcasts]]></itunes:summary>
        <itunes:author>ISACA Podcast</itunes:author>
        <itunes:explicit>false</itunes:explicit>
        <itunes:block>No</itunes:block>
        <itunes:duration>910</itunes:duration>
                <itunes:episode>235</itunes:episode>
        <itunes:episodeType>full</itunes:episodeType>
            </item>
    <item>
        <title>What Makes Risk Assessments So Unpleasant and How to Change That</title>
        <itunes:title>What Makes Risk Assessments So Unpleasant and How to Change That</itunes:title>
        <link>https://isacapodcast.podbean.com/e/what-makes-risk-assessments-so-unpleasant-and-how-to-change-that/</link>
                    <comments>https://isacapodcast.podbean.com/e/what-makes-risk-assessments-so-unpleasant-and-how-to-change-that/#comments</comments>        <pubDate>Wed, 26 Oct 2022 20:44:42 +0000</pubDate>
        <guid isPermaLink="false">isacapodcast.podbean.com/08b1342f-0685-38d5-a209-c66efe15b07f</guid>
                                    <description><![CDATA[<p>Ryan Cloutier's child came home from school one day and told him that he had figured out the staff Wi-Fi password. Frustrated that the security wasn't better for a school network, Ryan decided to do something about it. Since then, his career has been focused on serving K12, local government, and socio-economically disadvantaged communities with his company Security Studio.</p>
<p>ISACA's Jeff Champion asks him about ways to overcome technical language barriers when completing risk assessments and Ryan discusses key issues with risk assessments and a path forward to resolving them. Tune in to start thinking about more interesting ways to approach risk assessments!</p>
<p> </p>
<p>To read Ryan's full-length article, visit: <a href='http://www.isaca.org/what-makes-risk-assessments-so-unpleasant'>www.isaca.org/what-makes-risk-assessments-so-unpleasant</a></p>
<p>To listen to more ISACA Podcasts, visit: <a href='http://www.isaca.org/podcasts'>www.isaca.org/podcasts</a></p>
]]></description>
                                                            <content:encoded><![CDATA[<p>Ryan Cloutier's child came home from school one day and told him that he had figured out the staff Wi-Fi password. Frustrated that the security wasn't better for a school network, Ryan decided to do something about it. Since then, his career has been focused on serving K12, local government, and socio-economically disadvantaged communities with his company Security Studio.</p>
<p>ISACA's Jeff Champion asks him about ways to overcome technical language barriers when completing risk assessments and Ryan discusses key issues with risk assessments and a path forward to resolving them. Tune in to start thinking about more interesting ways to approach risk assessments!</p>
<p> </p>
<p>To read Ryan's full-length article, visit: <a href='http://www.isaca.org/what-makes-risk-assessments-so-unpleasant'>www.isaca.org/what-makes-risk-assessments-so-unpleasant</a></p>
<p>To listen to more ISACA Podcasts, visit: <a href='http://www.isaca.org/podcasts'>www.isaca.org/podcasts</a></p>
]]></content:encoded>
                                    
        <enclosure url="https://mcdn.podbean.com/mf/web/kgny8z/P_324_Ryan_Cloutier_Audio_Podcast_d17yeu9.mp3" length="22761502" type="audio/mpeg"/>
        <itunes:summary><![CDATA[Ryan Cloutier's child came home from school one day and told him that he had figured out the staff Wi-Fi password. Frustrated that the security wasn't better for a school network, Ryan decided to do something about it. Since then, his career has been focused on serving K12, local government, and socio-economically disadvantaged communities with his company Security Studio.
ISACA's Jeff Champion asks him about ways to overcome technical language barriers when completing risk assessments and Ryan discusses key issues with risk assessments and a path forward to resolving them. Tune in to start thinking about more interesting ways to approach risk assessments!
 
To read Ryan's full-length article, visit: www.isaca.org/what-makes-risk-assessments-so-unpleasant
To listen to more ISACA Podcasts, visit: www.isaca.org/podcasts]]></itunes:summary>
        <itunes:author>ISACA Podcast</itunes:author>
        <itunes:explicit>false</itunes:explicit>
        <itunes:block>No</itunes:block>
        <itunes:duration>1419</itunes:duration>
                <itunes:episode>234</itunes:episode>
        <itunes:episodeType>full</itunes:episodeType>
            </item>
    <item>
        <title>ISACA CyberPros – Naomi Buckwalter</title>
        <itunes:title>ISACA CyberPros – Naomi Buckwalter</itunes:title>
        <link>https://isacapodcast.podbean.com/e/isaca-cyberpros-%e2%80%93-naomi-buckwalter/</link>
                    <comments>https://isacapodcast.podbean.com/e/isaca-cyberpros-%e2%80%93-naomi-buckwalter/#comments</comments>        <pubDate>Fri, 21 Oct 2022 15:49:55 +0000</pubDate>
        <guid isPermaLink="false">isacapodcast.podbean.com/1366b029-ab12-3dea-8ee4-c7a74447bf05</guid>
                                    <description><![CDATA[<p>Executive Director of Cybersecurity Gatebreakers Foundation, Naomi Buckwalter, joins ISACA’s Jon Brandt to discuss burnout.</p>
<p>There are many factors at play when discussing burnout: company culture, work-from-home flexibility, unrealistic expectations from supervisors, and industry pressure, but Naomi gives you multiple action plans for combatting workplace burnout and creating healthy boundaries with your colleagues. Tune into this ISACA Podcast now!</p>
<p>To learn more about Naomi, please visit: <a href='https://www.linkedin.com/in/naomi-buckwalter/'>https://www.linkedin.com/in/naomi-buckwalter/</a></p>
<p>To listen to more ISACA podcasts, please visit: <a href='http://www.isaca.org/podcasts'>www.isaca.org/podcasts</a></p>
]]></description>
                                                            <content:encoded><![CDATA[<p>Executive Director of Cybersecurity Gatebreakers Foundation, Naomi Buckwalter, joins ISACA’s Jon Brandt to discuss burnout.</p>
<p>There are many factors at play when discussing burnout: company culture, work-from-home flexibility, unrealistic expectations from supervisors, and industry pressure, but Naomi gives you multiple action plans for combatting workplace burnout and creating healthy boundaries with your colleagues. Tune into this ISACA Podcast now!</p>
<p>To learn more about Naomi, please visit: <a href='https://www.linkedin.com/in/naomi-buckwalter/'>https://www.linkedin.com/in/naomi-buckwalter/</a></p>
<p>To listen to more ISACA podcasts, please visit: <a href='http://www.isaca.org/podcasts'>www.isaca.org/podcasts</a></p>
]]></content:encoded>
                                    
        <enclosure url="https://mcdn.podbean.com/mf/web/tjbgz8/P_199_Naomi_Buckwalter_Audio_podcast_d17kfay.mp3" length="38713394" type="audio/mpeg"/>
        <itunes:summary><![CDATA[Executive Director of Cybersecurity Gatebreakers Foundation, Naomi Buckwalter, joins ISACA’s Jon Brandt to discuss burnout.
There are many factors at play when discussing burnout: company culture, work-from-home flexibility, unrealistic expectations from supervisors, and industry pressure, but Naomi gives you multiple action plans for combatting workplace burnout and creating healthy boundaries with your colleagues. Tune into this ISACA Podcast now!
To learn more about Naomi, please visit: https://www.linkedin.com/in/naomi-buckwalter/
To listen to more ISACA podcasts, please visit: www.isaca.org/podcasts]]></itunes:summary>
        <itunes:author>ISACA Podcast</itunes:author>
        <itunes:explicit>false</itunes:explicit>
        <itunes:block>No</itunes:block>
        <itunes:duration>2415</itunes:duration>
                <itunes:episode>233</itunes:episode>
        <itunes:episodeType>full</itunes:episodeType>
            </item>
    <item>
        <title>Quantifying the Qualitative Risk Assessment</title>
        <itunes:title>Quantifying the Qualitative Risk Assessment</itunes:title>
        <link>https://isacapodcast.podbean.com/e/quantifying-the-qualitative-risk-assessment/</link>
                    <comments>https://isacapodcast.podbean.com/e/quantifying-the-qualitative-risk-assessment/#comments</comments>        <pubDate>Tue, 18 Oct 2022 15:11:29 +0000</pubDate>
        <guid isPermaLink="false">isacapodcast.podbean.com/d4767301-7fc3-3396-a36c-12f57897e2ea</guid>
                                    <description><![CDATA[<p>In this ISACA podcast episode, IT Risk Director and Senior Vice President Mike Powers and IT Segment Risk Manager Julie Ebersbach discuss using the qualitative risk assessment as part of an organization's enterprise risk framework, focusing on using data to inform subjective judgments. </p>
<p>The value and accuracy of a qualitative risk assessment, based on subject matter expert judgment, can be improved with focused data. Tune in now to hear Mike and Julie chat with ISACA's Jeff Champion about how quantifiable data increases the qualitative risk assessment's reliability, accuracy, and credibility.</p>
<p>To read ISACA Journal article, Quantifying the Qualitative Technology Risk Assessment, please visit: <a href='http://www.isaca.org/quantifying-the-qualitative-technology-risk-assessment'>www.isaca.org/quantifying-the-qualitative-technology-risk-assessment</a></p>
<p>To listen to more ISACA Podcasts, please visit <a href='http://www.isaca.org/podcasts'>www.isaca.org/podcasts</a>.</p>
]]></description>
                                                            <content:encoded><![CDATA[<p>In this ISACA podcast episode, IT Risk Director and Senior Vice President Mike Powers and IT Segment Risk Manager Julie Ebersbach discuss using the qualitative risk assessment as part of an organization's enterprise risk framework, focusing on using data to inform subjective judgments. </p>
<p>The value and accuracy of a qualitative risk assessment, based on subject matter expert judgment, can be improved with focused data. Tune in now to hear Mike and Julie chat with ISACA's Jeff Champion about how quantifiable data increases the qualitative risk assessment's reliability, accuracy, and credibility.</p>
<p>To read ISACA Journal article, <em>Quantifying the Qualitative Technology Risk Assessment</em>, please visit: <a href='http://www.isaca.org/quantifying-the-qualitative-technology-risk-assessment'>www.isaca.org/quantifying-the-qualitative-technology-risk-assessment</a></p>
<p>To listen to more ISACA Podcasts, please visit <a href='http://www.isaca.org/podcasts'>www.isaca.org/podcasts</a>.</p>
]]></content:encoded>
                                    
        <enclosure url="https://mcdn.podbean.com/mf/web/dm842w/P_325_Mike_Powers_and_Julie_Ebersbach_Audio_Podcast_d1bo297.mp3" length="39935513" type="audio/mpeg"/>
        <itunes:summary><![CDATA[In this ISACA podcast episode, IT Risk Director and Senior Vice President Mike Powers and IT Segment Risk Manager Julie Ebersbach discuss using the qualitative risk assessment as part of an organization's enterprise risk framework, focusing on using data to inform subjective judgments. 
The value and accuracy of a qualitative risk assessment, based on subject matter expert judgment, can be improved with focused data. Tune in now to hear Mike and Julie chat with ISACA's Jeff Champion about how quantifiable data increases the qualitative risk assessment's reliability, accuracy, and credibility.
To read ISACA Journal article, Quantifying the Qualitative Technology Risk Assessment, please visit: www.isaca.org/quantifying-the-qualitative-technology-risk-assessment
To listen to more ISACA Podcasts, please visit www.isaca.org/podcasts.]]></itunes:summary>
        <itunes:author>ISACA Podcast</itunes:author>
        <itunes:explicit>false</itunes:explicit>
        <itunes:block>No</itunes:block>
        <itunes:duration>1659</itunes:duration>
                <itunes:episode>232</itunes:episode>
        <itunes:episodeType>full</itunes:episodeType>
            </item>
    <item>
        <title>Gaining More Actionable Intelligence Using a Smarter Security Data Lake</title>
        <itunes:title>Gaining More Actionable Intelligence Using a Smarter Security Data Lake</itunes:title>
        <link>https://isacapodcast.podbean.com/e/gaining-more-actionable-intelligence-using-a-smarter-security-data-lake/</link>
                    <comments>https://isacapodcast.podbean.com/e/gaining-more-actionable-intelligence-using-a-smarter-security-data-lake/#comments</comments>        <pubDate>Thu, 13 Oct 2022 09:00:00 +0000</pubDate>
        <guid isPermaLink="false">isacapodcast.podbean.com/ad7bebad-0e10-3a80-ad73-c4a4393490ab</guid>
                                    <description><![CDATA[<p>In today’s dynamic world of distributed computing and cloud-scale systems, traditional security data platforms and tools such as SIEM typically fall short of actually delivering the intelligence needed to better adapt to the rapidly changing threat landscape. This is primarily due to a lack of core data lifecycle management, analytics, and integration capabilities. In addition to closing these functional gaps, security organizations could benefit by making AI/ML-driven advanced analytics a core component of their security intelligence capabilities. While there is admittedly a lot of hype around the concept of a “security data lake” in the industry, most approaches to date have not really delivered the type of usable intelligence needed to be as nimble as we must be in today’s cybersecurity world.
 
To address these issues, Adobe is taking a holistic approach to data and analytics that aims to enable efficiencies and scale for its Security organization. We have embarked on a journey to build an integrated and holistic security data and analytics platform as a foundational building block in its security organization. Join Krishna Patil, Principal Architect, Security, from Adobe as he discusses with ISACA's Collin Beder the approach we have taken to provide insights you can use to help tackle the problem of not just gathering the right data but making it more actionable to your security teams. Tune into this ISACA Podcast now! </p>
<p>To learn more about Adobe, please visit: <a href='http://www.adobe.com'>www.adobe.com</a></p>
<p>To listen to more ISACA Podcasts, please visit: <a href='http://www.isaca.org/podcasts'>www.isaca.org/podcasts</a></p>
<p> </p>
]]></description>
                                                            <content:encoded><![CDATA[<p>In today’s dynamic world of distributed computing and cloud-scale systems, traditional security data platforms and tools such as SIEM typically fall short of actually delivering the intelligence needed to better adapt to the rapidly changing threat landscape. This is primarily due to a lack of core data lifecycle management, analytics, and integration capabilities. In addition to closing these functional gaps, security organizations could benefit by making AI/ML-driven advanced analytics a core component of their security intelligence capabilities. While there is admittedly a lot of hype around the concept of a “security data lake” in the industry, most approaches to date have not really delivered the type of usable intelligence needed to be as nimble as we must be in today’s cybersecurity world.<br>
 <br>
To address these issues, Adobe is taking a holistic approach to data and analytics that aims to enable efficiencies and scale for its Security organization. We have embarked on a journey to build an integrated and holistic security data and analytics platform as a foundational building block in its security organization. Join Krishna Patil, Principal Architect, Security, from Adobe as he discusses with ISACA's Collin Beder the approach we have taken to provide insights you can use to help tackle the problem of not just gathering the right data but making it more actionable to your security teams. Tune into this ISACA Podcast now! </p>
<p>To learn more about Adobe, please visit: <a href='http://www.adobe.com'>www.adobe.com</a></p>
<p>To listen to more ISACA Podcasts, please visit: <a href='http://www.isaca.org/podcasts'>www.isaca.org/podcasts</a></p>
<p> </p>
]]></content:encoded>
                                    
        <enclosure url="https://mcdn.podbean.com/mf/web/mntz9g/P_248_Adobe_Krishna_Patil_Audio_Podcast_Edit_d1b758u.mp3" length="52605587" type="audio/mpeg"/>
        <itunes:summary><![CDATA[In today’s dynamic world of distributed computing and cloud-scale systems, traditional security data platforms and tools such as SIEM typically fall short of actually delivering the intelligence needed to better adapt to the rapidly changing threat landscape. This is primarily due to a lack of core data lifecycle management, analytics, and integration capabilities. In addition to closing these functional gaps, security organizations could benefit by making AI/ML-driven advanced analytics a core component of their security intelligence capabilities. While there is admittedly a lot of hype around the concept of a “security data lake” in the industry, most approaches to date have not really delivered the type of usable intelligence needed to be as nimble as we must be in today’s cybersecurity world. To address these issues, Adobe is taking a holistic approach to data and analytics that aims to enable efficiencies and scale for its Security organization. We have embarked on a journey to build an integrated and holistic security data and analytics platform as a foundational building block in its security organization. Join Krishna Patil, Principal Architect, Security, from Adobe as he discusses with ISACA's Collin Beder the approach we have taken to provide insights you can use to help tackle the problem of not just gathering the right data but making it more actionable to your security teams. Tune into this ISACA Podcast now! 
To learn more about Adobe, please visit: www.adobe.com
To listen to more ISACA Podcasts, please visit: www.isaca.org/podcasts
 ]]></itunes:summary>
        <itunes:author>ISACA Podcast</itunes:author>
        <itunes:explicit>false</itunes:explicit>
        <itunes:block>No</itunes:block>
        <itunes:duration>2185</itunes:duration>
                <itunes:episode>231</itunes:episode>
        <itunes:episodeType>full</itunes:episodeType>
            </item>
    <item>
        <title>ISACA Industry Spotlight | Ali Pabrai</title>
        <itunes:title>ISACA Industry Spotlight | Ali Pabrai</itunes:title>
        <link>https://isacapodcast.podbean.com/e/industry-spotlight-ali-pabrai/</link>
                    <comments>https://isacapodcast.podbean.com/e/industry-spotlight-ali-pabrai/#comments</comments>        <pubDate>Tue, 11 Oct 2022 14:03:59 +0000</pubDate>
        <guid isPermaLink="false">isacapodcast.podbean.com/dccf8ce6-01ce-3d93-8ee7-ee2eccac7852</guid>
                                    <description><![CDATA[<p>There is no denying the passion that ecfirst's CEO, Ali Pabrai has for cybersecurity. In this ISACA Podcast, Ali tells ISACA's Hollee Mangrum-Willis that after all his years in the industry, he is still more excited than a two-year-old at the entrance to Disneyland.</p>
<p>Listen in as Ali discusses his origin story as a first-generation American working for Fermi National Accelerator Laboratory, creating a startup soon after the new millennium and how he has balanced all his career accomplishments while raising a neurodivergent child. Tune in now to hear about why Ali thinks we should compare the human body to cybersecurity and much more!</p>
<p>To learn more about Ali, please visit: <a href='https://www.linkedin.com/in/pabrai/'>https://www.linkedin.com/in/pabrai/</a></p>
<p>To learn more about OneInTech, please visit: <a href='http://www.oneintech.org'>www.oneintech.org</a></p>
<p>To listen to more ISACA Podcasts, please visit: <a href='http://www.isaca.org/podcasts'>www.isaca.org/podcasts</a></p>
]]></description>
                                                            <content:encoded><![CDATA[<p>There is no denying the passion that ecfirst's CEO, Ali Pabrai has for cybersecurity. In this ISACA Podcast, Ali tells ISACA's Hollee Mangrum-Willis that after all his years in the industry, he is still more excited than a two-year-old at the entrance to Disneyland.</p>
<p>Listen in as Ali discusses his origin story as a first-generation American working for Fermi National Accelerator Laboratory, creating a startup soon after the new millennium and how he has balanced all his career accomplishments while raising a neurodivergent child. Tune in now to hear about why Ali thinks we should compare the human body to cybersecurity and much more!</p>
<p>To learn more about Ali, please visit: <a href='https://www.linkedin.com/in/pabrai/'>https://www.linkedin.com/in/pabrai/</a></p>
<p>To learn more about OneInTech, please visit: <a href='http://www.oneintech.org'>www.oneintech.org</a></p>
<p>To listen to more ISACA Podcasts, please visit: <a href='http://www.isaca.org/podcasts'>www.isaca.org/podcasts</a></p>
]]></content:encoded>
                                    
        <enclosure url="https://mcdn.podbean.com/mf/web/3z6dn8/P_312_Ali_Pabrai_Audio_Podcast_d1717ut.mp3" length="39085250" type="audio/mpeg"/>
        <itunes:summary><![CDATA[There is no denying the passion that ecfirst's CEO, Ali Pabrai has for cybersecurity. In this ISACA Podcast, Ali tells ISACA's Hollee Mangrum-Willis that after all his years in the industry, he is still more excited than a two-year-old at the entrance to Disneyland.
Listen in as Ali discusses his origin story as a first-generation American working for Fermi National Accelerator Laboratory, creating a startup soon after the new millennium and how he has balanced all his career accomplishments while raising a neurodivergent child. Tune in now to hear about why Ali thinks we should compare the human body to cybersecurity and much more!
To learn more about Ali, please visit: https://www.linkedin.com/in/pabrai/
To learn more about OneInTech, please visit: www.oneintech.org
To listen to more ISACA Podcasts, please visit: www.isaca.org/podcasts]]></itunes:summary>
        <itunes:author>ISACA Podcast</itunes:author>
        <itunes:explicit>false</itunes:explicit>
        <itunes:block>No</itunes:block>
        <itunes:duration>2431</itunes:duration>
                <itunes:episode>230</itunes:episode>
        <itunes:episodeType>full</itunes:episodeType>
            </item>
    <item>
        <title>Managing Cybersecurity Risk as Enterprise Risk</title>
        <itunes:title>Managing Cybersecurity Risk as Enterprise Risk</itunes:title>
        <link>https://isacapodcast.podbean.com/e/managing-cybersecurity-risk-as-enterprise-risk/</link>
                    <comments>https://isacapodcast.podbean.com/e/managing-cybersecurity-risk-as-enterprise-risk/#comments</comments>        <pubDate>Thu, 06 Oct 2022 13:04:05 +0000</pubDate>
        <guid isPermaLink="false">isacapodcast.podbean.com/b04dc5c3-7c7f-310d-a23c-6e730519d313</guid>
                                    <description><![CDATA[<p>Cybersecurity incidents like ransomware can potentially bring operations to a standstill. Recent regulatory changes by the FTC and proposed changes by the SEC show that both agencies are drafting cybersecurity rules similar to ERM concepts. This would include board oversight of cybersecurity and the responsibility of senior management to implement cybersecurity policies and procedures and provide training for information security staff that is sufficient for them to address relevant security risks. In addition, this could mean that your organization may be required to report incidents and disclose cybersecurity policies and procedures.</p>
<p>Tune in to this ISACA Podcast episode to listen in as Cyber Defense Labs’ Manager of Cybersecurity Advisory Services Tom Schneider tells ISACA’s Jeff Champion that any threat to this essential information is an enterprise risk that needs to be managed by the enterprise through teamwork, with leadership from both the board and senior management. Tom also gives insights into managing cybersecurity risk as an enterprise risk.</p>
<p>To read Managing Cybersecurity Risk as Enterprise Risk, please visit: <a href='http://www.isaca.org/managing-cybersecurity-risk-as-enterprise-risk'>www.isaca.org/managing-cybersecurity-risk-as-enterprise-risk</a>.</p>
<p>To listen to more ISACA Podcasts, please visit: <a href='http://www.isaca.org/podcasts'>www.isaca.org/podcasts</a>.</p>
]]></description>
                                                            <content:encoded><![CDATA[<p>Cybersecurity incidents like ransomware can potentially bring operations to a standstill. Recent regulatory changes by the FTC and proposed changes by the SEC show that both agencies are drafting cybersecurity rules similar to ERM concepts. This would include board oversight of cybersecurity and the responsibility of senior management to implement cybersecurity policies and procedures and provide training for information security staff that is sufficient for them to address relevant security risks. In addition, this could mean that your organization may be required to report incidents and disclose cybersecurity policies and procedures.</p>
<p>Tune in to this ISACA Podcast episode to listen in as Cyber Defense Labs’ Manager of Cybersecurity Advisory Services Tom Schneider tells ISACA’s Jeff Champion that any threat to this essential information is an enterprise risk that needs to be managed by the enterprise through teamwork, with leadership from both the board and senior management. Tom also gives insights into managing cybersecurity risk as an enterprise risk.</p>
<p>To read Managing Cybersecurity Risk as Enterprise Risk, please visit: <a href='http://www.isaca.org/managing-cybersecurity-risk-as-enterprise-risk'>www.isaca.org/managing-cybersecurity-risk-as-enterprise-risk</a>.</p>
<p>To listen to more ISACA Podcasts, please visit: <a href='http://www.isaca.org/podcasts'>www.isaca.org/podcasts</a>.</p>
]]></content:encoded>
                                    
        <enclosure url="https://mcdn.podbean.com/mf/web/bxkn9w/P_310_Tom_Schneider_Audio_Podcast_d1boqaq.mp3" length="18262698" type="audio/mpeg"/>
        <itunes:summary><![CDATA[Cybersecurity incidents like ransomware can potentially bring operations to a standstill. Recent regulatory changes by the FTC and proposed changes by the SEC show that both agencies are drafting cybersecurity rules similar to ERM concepts. This would include board oversight of cybersecurity and the responsibility of senior management to implement cybersecurity policies and procedures and provide training for information security staff that is sufficient for them to address relevant security risks. In addition, this could mean that your organization may be required to report incidents and disclose cybersecurity policies and procedures.
Tune in to this ISACA Podcast episode to listen in as Cyber Defense Labs’ Manager of Cybersecurity Advisory Services Tom Schneider tells ISACA’s Jeff Champion that any threat to this essential information is an enterprise risk that needs to be managed by the enterprise through teamwork, with leadership from both the board and senior management. Tom also gives insights into managing cybersecurity risk as an enterprise risk.
To read Managing Cybersecurity Risk as Enterprise Risk, please visit: www.isaca.org/managing-cybersecurity-risk-as-enterprise-risk.
To listen to more ISACA Podcasts, please visit: www.isaca.org/podcasts.]]></itunes:summary>
        <itunes:author>ISACA Podcast</itunes:author>
        <itunes:explicit>false</itunes:explicit>
        <itunes:block>No</itunes:block>
        <itunes:duration>1137</itunes:duration>
                <itunes:episode>229</itunes:episode>
        <itunes:episodeType>full</itunes:episodeType>
            </item>
    <item>
        <title>Implementing Artificial Intelligence: Capabilities and Risk</title>
        <itunes:title>Implementing Artificial Intelligence: Capabilities and Risk</itunes:title>
        <link>https://isacapodcast.podbean.com/e/implementing-artificial-intelligence-capabilities-and-risk/</link>
                    <comments>https://isacapodcast.podbean.com/e/implementing-artificial-intelligence-capabilities-and-risk/#comments</comments>        <pubDate>Tue, 04 Oct 2022 09:00:00 +0000</pubDate>
        <guid isPermaLink="false">isacapodcast.podbean.com/7acbdc75-610d-3cc9-bab7-f5b0091c28f9</guid>
                                    <description><![CDATA[<p>University of Florida's Ivy Munoko is passionate about AI and has plenty to share regarding implementation and usage, but ISACA's Collin Beder asks, "is it ethical"? </p>
<p>Ivy breaks down the ethical considerations for AI and the four types of intelligence (Mechanical, Analytical, Intuitive, Empathetic), and she shares her take on why she thinks AI won't be replacing our jobs for a very long time to come</p>
<p>To read Ivy's article, please visit <a href='http://www.isaca.org/implementing-ai-capabilities-and-risk'>www.isaca.org/implementing-ai-capabilities-and-risk</a>.</p>
<p>To listen to more ISACA Podcasts, please visit <a href='http://www.isaca.org/podcasts'>www.isaca.org/podcasts</a>. </p>
]]></description>
                                                            <content:encoded><![CDATA[<p>University of Florida's Ivy Munoko is passionate about AI and has plenty to share regarding implementation and usage, but ISACA's Collin Beder asks, "is it ethical"? </p>
<p>Ivy breaks down the ethical considerations for AI and the four types of intelligence (Mechanical, Analytical, Intuitive, Empathetic), and she shares her take on why she thinks AI won't be replacing our jobs for a very long time to come</p>
<p>To read Ivy's article, please visit <a href='http://www.isaca.org/implementing-ai-capabilities-and-risk'>www.isaca.org/implementing-ai-capabilities-and-risk</a>.</p>
<p>To listen to more ISACA Podcasts, please visit <a href='http://www.isaca.org/podcasts'>www.isaca.org/podcasts</a>. </p>
]]></content:encoded>
                                    
        <enclosure url="https://mcdn.podbean.com/mf/web/qrifbd/P_289_Ivy_Munuko_Audio_Podcast_FINALb7812.mp3" length="50988289" type="audio/mpeg"/>
        <itunes:summary><![CDATA[University of Florida's Ivy Munoko is passionate about AI and has plenty to share regarding implementation and usage, but ISACA's Collin Beder asks, "is it ethical"? 
Ivy breaks down the ethical considerations for AI and the four types of intelligence (Mechanical, Analytical, Intuitive, Empathetic), and she shares her take on why she thinks AI won't be replacing our jobs for a very long time to come
To read Ivy's article, please visit www.isaca.org/implementing-ai-capabilities-and-risk.
To listen to more ISACA Podcasts, please visit www.isaca.org/podcasts. ]]></itunes:summary>
        <itunes:author>ISACA Podcast</itunes:author>
        <itunes:explicit>false</itunes:explicit>
        <itunes:block>No</itunes:block>
        <itunes:duration>2121</itunes:duration>
                <itunes:episode>228</itunes:episode>
        <itunes:episodeType>full</itunes:episodeType>
            </item>
    <item>
        <title>Audit in Practice: Auditing Culture</title>
        <itunes:title>Audit in Practice: Auditing Culture</itunes:title>
        <link>https://isacapodcast.podbean.com/e/audit-in-practice-auditing-culture/</link>
                    <comments>https://isacapodcast.podbean.com/e/audit-in-practice-auditing-culture/#comments</comments>        <pubDate>Thu, 29 Sep 2022 13:03:42 +0000</pubDate>
        <guid isPermaLink="false">isacapodcast.podbean.com/e6b98b08-9b89-3c11-be06-ca1b2339d200</guid>
                                    <description><![CDATA[<p>What’s The Risk LLC’s Cindy Baxter sits down with ISACA’s Robin Lyons to discuss auditing culture, which can be one of the most interesting areas to audit. We all have things we want out of our work environment like remote work, flexible hours or as Cindy comments: “I’d love to take my dog to work with me!”, but she and Robin question what is really important to workplace culture, and does it start with a “tone at the top”? Cindy gives advice on auditing approaches and key assessments when auditing as culture can be a critical part of an organization, making or breaking its effectiveness.</p>
<p>To read Cindy’s full length article, please visit: <a href='http://www.isaca.org/auditing-culture'>www.isaca.org/auditing-culture</a> </p>
<p>To listen to more ISACA Podcasts, please visit: <a href='http://www.isaca.org/podcasts'>www.isaca.org/podcasts</a> </p>
]]></description>
                                                            <content:encoded><![CDATA[<p>What’s The Risk LLC’s Cindy Baxter sits down with ISACA’s Robin Lyons to discuss auditing culture, which can be one of the most interesting areas to audit. We all have things we want out of our work environment like remote work, flexible hours or as Cindy comments: “I’d love to take my dog to work with me!”, but she and Robin question what is really important to workplace culture, and does it start with a “tone at the top”? Cindy gives advice on auditing approaches and key assessments when auditing as culture can be a critical part of an organization, making or breaking its effectiveness.</p>
<p>To read Cindy’s full length article, please visit: <a href='http://www.isaca.org/auditing-culture'>www.isaca.org/auditing-culture</a> </p>
<p>To listen to more ISACA Podcasts, please visit: <a href='http://www.isaca.org/podcasts'>www.isaca.org/podcasts</a> </p>
]]></content:encoded>
                                    
        <enclosure url="https://mcdn.podbean.com/mf/web/iguumd/P_082_Cindy_Baxter_Audio_Podcast_FINAL6p60j.mp3" length="32177660" type="audio/mpeg"/>
        <itunes:summary><![CDATA[What’s The Risk LLC’s Cindy Baxter sits down with ISACA’s Robin Lyons to discuss auditing culture, which can be one of the most interesting areas to audit. We all have things we want out of our work environment like remote work, flexible hours or as Cindy comments: “I’d love to take my dog to work with me!”, but she and Robin question what is really important to workplace culture, and does it start with a “tone at the top”? Cindy gives advice on auditing approaches and key assessments when auditing as culture can be a critical part of an organization, making or breaking its effectiveness.
To read Cindy’s full length article, please visit: www.isaca.org/auditing-culture 
To listen to more ISACA Podcasts, please visit: www.isaca.org/podcasts ]]></itunes:summary>
        <itunes:author>ISACA Podcast</itunes:author>
        <itunes:explicit>false</itunes:explicit>
        <itunes:block>No</itunes:block>
        <itunes:duration>2005</itunes:duration>
                <itunes:episode>227</itunes:episode>
        <itunes:episodeType>full</itunes:episodeType>
            </item>
    <item>
        <title>Incident Report &amp; Continuous Control Monitoring</title>
        <itunes:title>Incident Report &amp; Continuous Control Monitoring</itunes:title>
        <link>https://isacapodcast.podbean.com/e/incident-report-continuous-control-monitoring/</link>
                    <comments>https://isacapodcast.podbean.com/e/incident-report-continuous-control-monitoring/#comments</comments>        <pubDate>Tue, 27 Sep 2022 12:40:21 +0000</pubDate>
        <guid isPermaLink="false">isacapodcast.podbean.com/1777e734-8da0-354b-9db0-cd0c85742417</guid>
                                    <description><![CDATA[<p>This episode of the ISACA Podcast is all about incident reporting. Lesotho Postbank's Relebohile Kobeli talks to ISACA's Collin Beder about mitigating risk, minimizing losses from events, and good communication. As Relebohile says: "as we carry out our daily tasks at work, we should always be proactive... and recognize abnormal behavior". Tune in now!</p>
<p>To read Relebohile's full article, please visit: <a href='http://www.isaca.org/how-enterprises-can-leverage-incident-reporting'>www.isaca.org/how-enterprises-can-leverage-incident-reporting</a> </p>
<p>To listen to more ISACA Podcasts, please visit: <a href='http://www.isaca.org/podcasts'>www.isaca.org/podcasts</a> </p>
]]></description>
                                                            <content:encoded><![CDATA[<p>This episode of the ISACA Podcast is all about incident reporting. Lesotho Postbank's Relebohile Kobeli talks to ISACA's Collin Beder about mitigating risk, minimizing losses from events, and good communication. As Relebohile says: "as we carry out our daily tasks at work, we should always be proactive... and recognize abnormal behavior". Tune in now!</p>
<p>To read Relebohile's full article, please visit: <a href='http://www.isaca.org/how-enterprises-can-leverage-incident-reporting'>www.isaca.org/how-enterprises-can-leverage-incident-reporting</a> </p>
<p>To listen to more ISACA Podcasts, please visit: <a href='http://www.isaca.org/podcasts'>www.isaca.org/podcasts</a> </p>
]]></content:encoded>
                                    
        <enclosure url="https://mcdn.podbean.com/mf/web/v5jesx/P_298_Relebohili_Kobeli_Audio_Podcast_d17ys4k.mp3" length="24291710" type="audio/mpeg"/>
        <itunes:summary><![CDATA[This episode of the ISACA Podcast is all about incident reporting. Lesotho Postbank's Relebohile Kobeli talks to ISACA's Collin Beder about mitigating risk, minimizing losses from events, and good communication. As Relebohile says: "as we carry out our daily tasks at work, we should always be proactive... and recognize abnormal behavior". Tune in now!
To read Relebohile's full article, please visit: www.isaca.org/how-enterprises-can-leverage-incident-reporting 
To listen to more ISACA Podcasts, please visit: www.isaca.org/podcasts ]]></itunes:summary>
        <itunes:author>ISACA Podcast</itunes:author>
        <itunes:explicit>false</itunes:explicit>
        <itunes:block>No</itunes:block>
        <itunes:duration>1010</itunes:duration>
                <itunes:episode>226</itunes:episode>
        <itunes:episodeType>full</itunes:episodeType>
            </item>
    <item>
        <title>Industry Spotlight - Lisa Young</title>
        <itunes:title>Industry Spotlight - Lisa Young</itunes:title>
        <link>https://isacapodcast.podbean.com/e/industry-spotlight-lisa-young/</link>
                    <comments>https://isacapodcast.podbean.com/e/industry-spotlight-lisa-young/#comments</comments>        <pubDate>Thu, 22 Sep 2022 13:02:55 +0000</pubDate>
        <guid isPermaLink="false">isacapodcast.podbean.com/bbe3af55-c1a3-3f47-8bb4-a01a80afdf00</guid>
                                    <description><![CDATA[<p>Netflix's Lisa Young started as a bank teller that learned tech by fixing and servicing ATMs, which transitioned to her joining the network ops field and leading her to "help organizations understand what could keep them from meeting their strategy, objectives or mission". After rough telecom layoffs, she re-educated herself with ISACA certifications and started leading a chapter, which included the honor of hosting an ISACA conference and she has developed content with ISACA's Paul Phillips. In this episode she sits down with Paul to discuss their shared work on ISACA-related projects, cyber careers and why you should be curious and ask how things work. Lisa loves the idea of continuous learning and asks, "what is a good next step for you?"</p>
<p>To listen to more ISACA Podcasts, go to isaca.org/podcasts</p>
<p>Be sure to like, comment, and subscribe for more ISACA Productions content.</p>
]]></description>
                                                            <content:encoded><![CDATA[<p>Netflix's Lisa Young started as a bank teller that learned tech by fixing and servicing ATMs, which transitioned to her joining the network ops field and leading her to "help organizations understand what could keep them from meeting their strategy, objectives or mission". After rough telecom layoffs, she re-educated herself with ISACA certifications and started leading a chapter, which included the honor of hosting an ISACA conference and she has developed content with ISACA's Paul Phillips. In this episode she sits down with Paul to discuss their shared work on ISACA-related projects, cyber careers and why you should be curious and ask how things work. Lisa loves the idea of continuous learning and asks, "what is a good next step for you?"</p>
<p>To listen to more ISACA Podcasts, go to isaca.org/podcasts</p>
<p>Be sure to like, comment, and subscribe for more ISACA Productions content.</p>
]]></content:encoded>
                                    
        <enclosure url="https://mcdn.podbean.com/mf/web/jwisng/P_290_Lisa_Young_Audio_Podcast_FINAL9g9gg.mp3" length="26543027" type="audio/mpeg"/>
        <itunes:summary><![CDATA[Netflix's Lisa Young started as a bank teller that learned tech by fixing and servicing ATMs, which transitioned to her joining the network ops field and leading her to "help organizations understand what could keep them from meeting their strategy, objectives or mission". After rough telecom layoffs, she re-educated herself with ISACA certifications and started leading a chapter, which included the honor of hosting an ISACA conference and she has developed content with ISACA's Paul Phillips. In this episode she sits down with Paul to discuss their shared work on ISACA-related projects, cyber careers and why you should be curious and ask how things work. Lisa loves the idea of continuous learning and asks, "what is a good next step for you?"
To listen to more ISACA Podcasts, go to isaca.org/podcasts
Be sure to like, comment, and subscribe for more ISACA Productions content.]]></itunes:summary>
        <itunes:author>ISACA Podcast</itunes:author>
        <itunes:explicit>false</itunes:explicit>
        <itunes:block>No</itunes:block>
        <itunes:duration>1103</itunes:duration>
                <itunes:episode>225</itunes:episode>
        <itunes:episodeType>full</itunes:episodeType>
            </item>
    <item>
        <title>Defending Data Smartly</title>
        <itunes:title>Defending Data Smartly</itunes:title>
        <link>https://isacapodcast.podbean.com/e/cyberpros-defending-data-smartly/</link>
                    <comments>https://isacapodcast.podbean.com/e/cyberpros-defending-data-smartly/#comments</comments>        <pubDate>Tue, 20 Sep 2022 12:45:12 +0000</pubDate>
        <guid isPermaLink="false">isacapodcast.podbean.com/328118cd-b1df-37c5-889b-26e4843bd4f9</guid>
                                    <description><![CDATA[<p>Some industry watchers estimate that by 2025 the collective data of humanity will reach 175 Zettabytes. ISACA's Jon Brandt invites Dr. Chase Cunningham (aka Dr. Zero Trust) to discuss how to defend the ever-growing amount data, problem-solving for business units and compliance. Chase also questions the idea of “never compromise” and “perfect defense” when defending data. Tune in now!</p>
<p>To Learn more about Dr. Zero Trust, visit: <a href='http://www.zerotrustedge.com/dr-zero-trust'>www.zerotrustedge.com/dr-zero-trust</a></p>
<p>
To listen to more ISACA Podcasts, visit: <a href='http://www.isaca.org/podcasts'>www.isaca.org/podcasts</a> </p>
]]></description>
                                                            <content:encoded><![CDATA[<p>Some industry watchers estimate that by 2025 the collective data of humanity will reach 175 Zettabytes. ISACA's Jon Brandt invites Dr. Chase Cunningham (aka Dr. Zero Trust) to discuss how to defend the ever-growing amount data, problem-solving for business units and compliance. Chase also questions the idea of “never compromise” and “perfect defense” when defending data. Tune in now!</p>
<p>To Learn more about Dr. Zero Trust, visit: <a href='http://www.zerotrustedge.com/dr-zero-trust'>www.zerotrustedge.com/dr-zero-trust</a></p>
<p><br>
To listen to more ISACA Podcasts, visit: <a href='http://www.isaca.org/podcasts'>www.isaca.org/podcasts</a> </p>
]]></content:encoded>
                                    
        <enclosure url="https://mcdn.podbean.com/mf/web/tf5pmq/P_198_Audio_Podcast_FINAL9y8s1.mp3" length="34561316" type="audio/mpeg"/>
        <itunes:summary><![CDATA[Some industry watchers estimate that by 2025 the collective data of humanity will reach 175 Zettabytes. ISACA's Jon Brandt invites Dr. Chase Cunningham (aka Dr. Zero Trust) to discuss how to defend the ever-growing amount data, problem-solving for business units and compliance. Chase also questions the idea of “never compromise” and “perfect defense” when defending data. Tune in now!
To Learn more about Dr. Zero Trust, visit: www.zerotrustedge.com/dr-zero-trust
To listen to more ISACA Podcasts, visit: www.isaca.org/podcasts ]]></itunes:summary>
        <itunes:author>ISACA Podcast</itunes:author>
        <itunes:explicit>false</itunes:explicit>
        <itunes:block>No</itunes:block>
        <itunes:duration>1438</itunes:duration>
                <itunes:episode>224</itunes:episode>
        <itunes:episodeType>full</itunes:episodeType>
            </item>
    <item>
        <title>Foco de la industria - Arnulfo Espinosa Dominguez Parte II</title>
        <itunes:title>Foco de la industria - Arnulfo Espinosa Dominguez Parte II</itunes:title>
        <link>https://isacapodcast.podbean.com/e/foco-de-la-industria-arnulfo-espinosa-dominguez-parte-ii/</link>
                    <comments>https://isacapodcast.podbean.com/e/foco-de-la-industria-arnulfo-espinosa-dominguez-parte-ii/#comments</comments>        <pubDate>Fri, 16 Sep 2022 11:13:17 +0000</pubDate>
        <guid isPermaLink="false">isacapodcast.podbean.com/f4dff459-4aff-3d4d-88cf-e2a185e12317</guid>
                                    <description><![CDATA[<p>Parte I: https://isacapodcast.podbean.com/e/foco-de-la-industria-arnulfo-espinosa-dominguez/</p>
<p>El vicepresidente del Capítulo Monterrey de ISACA y Director de Auditoría y Fraude de TI de uno de los Grupos Financieros más grandes de México, Arnulfo Espinosa Domínguez, se une a Jocelyn Alcantar de ISACA para compartir muchas cosas que ha aprendido durante sus 20 años de experiencia profesional en la industria. Habiéndose dado cuenta del valor de la información a una edad temprana, Arnulfo ha forjado su camino dentro de la comunidad de TI. Es un formador acreditado para múltiples certificaciones, asesor independiente y presidente de varios comités de Ciberseguridad, Riesgo y Auditoría, y es reconocido mundialmente por un apodo que sus compañeros le han dado, "El AudiTHOR".</p>
<p>Como voluntario de ISACA desde hace mucho tiempo y orador de conferencias, Arnulfo ha sido premiado en numerosas ocasiones por sus destacados logros. En 2019, se le otorgó el "Premio al Líder de Capítulo Sobresaliente" (Outstanding Chapter Leader Award) de ISACA, en 2020, recibió el "Premio John Kuyers al Mejor Orador" (John Kuyers Award for Best), y recibió el mayor logro, el "Premio Salón de la Fama de ISACA" (ISACA Hall of Fame Award) en 2021. </p>
<p>¡Únase a la escucha de este episodio mientras Arnulfo ofrece sus mejores consejos y prácticas para convertirse en un orador excepcional, consejos sobre cómo los profesionales emergentes pueden entrar en la industria, y cómo su alter ego, AudiTHOR, alimenta su pasión por la auditoría!</p>
<p>Para leer más sobre Arnulfo, visite <a href='http://www.isaca.org/resources/news-and-trends/isaca-now-blog/2020/iamisaca-from-rock-star-to-speak-star'>www.isaca.org/resources/news-and-trends/isaca-now-blog/2020/iamisaca-from-rock-star-to-speak-star</a></p>
<p>Para escuchar más Podcasts de ISACA, visite <a href='http://www.isaca.org/podcasts'>www.isaca.org/podcasts</a></p>
]]></description>
                                                            <content:encoded><![CDATA[<p>Parte I: https://isacapodcast.podbean.com/e/foco-de-la-industria-arnulfo-espinosa-dominguez/</p>
<p>El vicepresidente del Capítulo Monterrey de ISACA y Director de Auditoría y Fraude de TI de uno de los Grupos Financieros más grandes de México, Arnulfo Espinosa Domínguez, se une a Jocelyn Alcantar de ISACA para compartir muchas cosas que ha aprendido durante sus 20 años de experiencia profesional en la industria. Habiéndose dado cuenta del valor de la información a una edad temprana, Arnulfo ha forjado su camino dentro de la comunidad de TI. Es un formador acreditado para múltiples certificaciones, asesor independiente y presidente de varios comités de Ciberseguridad, Riesgo y Auditoría, y es reconocido mundialmente por un apodo que sus compañeros le han dado, "El AudiTHOR".</p>
<p>Como voluntario de ISACA desde hace mucho tiempo y orador de conferencias, Arnulfo ha sido premiado en numerosas ocasiones por sus destacados logros. En 2019, se le otorgó el "Premio al Líder de Capítulo Sobresaliente" (Outstanding Chapter Leader Award) de ISACA, en 2020, recibió el "Premio John Kuyers al Mejor Orador" (John Kuyers Award for Best), y recibió el mayor logro, el "Premio Salón de la Fama de ISACA" (ISACA Hall of Fame Award) en 2021. </p>
<p>¡Únase a la escucha de este episodio mientras Arnulfo ofrece sus mejores consejos y prácticas para convertirse en un orador excepcional, consejos sobre cómo los profesionales emergentes pueden entrar en la industria, y cómo su alter ego, AudiTHOR, alimenta su pasión por la auditoría!</p>
<p>Para leer más sobre Arnulfo, visite <a href='http://www.isaca.org/resources/news-and-trends/isaca-now-blog/2020/iamisaca-from-rock-star-to-speak-star'>www.isaca.org/resources/news-and-trends/isaca-now-blog/2020/iamisaca-from-rock-star-to-speak-star</a></p>
<p>Para escuchar más Podcasts de ISACA, visite <a href='http://www.isaca.org/podcasts'>www.isaca.org/podcasts</a></p>
]]></content:encoded>
                                    
        <enclosure url="https://mcdn.podbean.com/mf/web/3u67c4/P_259_Edit_Part_II_Audio_Podcast_FINALbspxj.mp3" length="45354725" type="audio/mpeg"/>
        <itunes:summary><![CDATA[Parte I: https://isacapodcast.podbean.com/e/foco-de-la-industria-arnulfo-espinosa-dominguez/
El vicepresidente del Capítulo Monterrey de ISACA y Director de Auditoría y Fraude de TI de uno de los Grupos Financieros más grandes de México, Arnulfo Espinosa Domínguez, se une a Jocelyn Alcantar de ISACA para compartir muchas cosas que ha aprendido durante sus 20 años de experiencia profesional en la industria. Habiéndose dado cuenta del valor de la información a una edad temprana, Arnulfo ha forjado su camino dentro de la comunidad de TI. Es un formador acreditado para múltiples certificaciones, asesor independiente y presidente de varios comités de Ciberseguridad, Riesgo y Auditoría, y es reconocido mundialmente por un apodo que sus compañeros le han dado, "El AudiTHOR".
Como voluntario de ISACA desde hace mucho tiempo y orador de conferencias, Arnulfo ha sido premiado en numerosas ocasiones por sus destacados logros. En 2019, se le otorgó el "Premio al Líder de Capítulo Sobresaliente" (Outstanding Chapter Leader Award) de ISACA, en 2020, recibió el "Premio John Kuyers al Mejor Orador" (John Kuyers Award for Best), y recibió el mayor logro, el "Premio Salón de la Fama de ISACA" (ISACA Hall of Fame Award) en 2021. 
¡Únase a la escucha de este episodio mientras Arnulfo ofrece sus mejores consejos y prácticas para convertirse en un orador excepcional, consejos sobre cómo los profesionales emergentes pueden entrar en la industria, y cómo su alter ego, AudiTHOR, alimenta su pasión por la auditoría!
Para leer más sobre Arnulfo, visite www.isaca.org/resources/news-and-trends/isaca-now-blog/2020/iamisaca-from-rock-star-to-speak-star
Para escuchar más Podcasts de ISACA, visite www.isaca.org/podcasts]]></itunes:summary>
        <itunes:author>ISACA Podcast</itunes:author>
        <itunes:explicit>false</itunes:explicit>
        <itunes:block>No</itunes:block>
        <itunes:duration>1879</itunes:duration>
                <itunes:episode>223</itunes:episode>
        <itunes:episodeType>full</itunes:episodeType>
            </item>
    <item>
        <title>Ethical AI Shifting the Conversation Left</title>
        <itunes:title>Ethical AI Shifting the Conversation Left</itunes:title>
        <link>https://isacapodcast.podbean.com/e/ethical-ai-shifting-the-conversation-left/</link>
                    <comments>https://isacapodcast.podbean.com/e/ethical-ai-shifting-the-conversation-left/#comments</comments>        <pubDate>Thu, 15 Sep 2022 13:31:53 +0000</pubDate>
        <guid isPermaLink="false">isacapodcast.podbean.com/e68f5b9a-d33d-3017-934b-03b8a47c555e</guid>
                                    <description><![CDATA[<p>Many organizations prioritize goals such as gains and profits, which often require rich data sets, but fail to consider the eventual impact of their data handling methodologies on foundational social justice issues. ISACA's Collin Beder talks to Josh Scarpino about his recently released article Evaluating Ethical Challenges in AI and ML. Josh discusses issues such as ethical behavior, systemic issues and how to create trusted systems. Collin also asks what is the future for humans in regards to AI. Tune in now!</p>
<p>To read Evaluating Ethical Challenges in AI and ML, visit: <a href='http://www.isaca.org/evaluating-ethical-challenges-in-ai-and-ml'>www.isaca.org/evaluating-ethical-challenges-in-ai-and-ml </a></p>
<p>To listen to more ISACA Podcasts, visit: <a href='http://www.isaca.org/podcasts'>www.isaca.org/podcasts</a> </p>
]]></description>
                                                            <content:encoded><![CDATA[<p>Many organizations prioritize goals such as gains and profits, which often require rich data sets, but fail to consider the eventual impact of their data handling methodologies on foundational social justice issues. ISACA's Collin Beder talks to Josh Scarpino about his recently released article Evaluating Ethical Challenges in AI and ML. Josh discusses issues such as ethical behavior, systemic issues and how to create trusted systems. Collin also asks what is the future for humans in regards to AI. Tune in now!</p>
<p>To read Evaluating Ethical Challenges in AI and ML, visit: <a href='http://www.isaca.org/evaluating-ethical-challenges-in-ai-and-ml'>www.isaca.org/evaluating-ethical-challenges-in-ai-and-ml </a></p>
<p>To listen to more ISACA Podcasts, visit: <a href='http://www.isaca.org/podcasts'>www.isaca.org/podcasts</a> </p>
]]></content:encoded>
                                    
        <enclosure url="https://mcdn.podbean.com/mf/web/6kyw3e/P_279_Audio_Podcast_FINAL7cmf4.mp3" length="24888714" type="audio/mpeg"/>
        <itunes:summary><![CDATA[Many organizations prioritize goals such as gains and profits, which often require rich data sets, but fail to consider the eventual impact of their data handling methodologies on foundational social justice issues. ISACA's Collin Beder talks to Josh Scarpino about his recently released article Evaluating Ethical Challenges in AI and ML. Josh discusses issues such as ethical behavior, systemic issues and how to create trusted systems. Collin also asks what is the future for humans in regards to AI. Tune in now!
To read Evaluating Ethical Challenges in AI and ML, visit: www.isaca.org/evaluating-ethical-challenges-in-ai-and-ml 
To listen to more ISACA Podcasts, visit: www.isaca.org/podcasts ]]></itunes:summary>
        <itunes:author>ISACA Podcast</itunes:author>
        <itunes:explicit>false</itunes:explicit>
        <itunes:block>No</itunes:block>
        <itunes:duration>1035</itunes:duration>
                <itunes:episode>222</itunes:episode>
        <itunes:episodeType>full</itunes:episodeType>
            </item>
    <item>
        <title>Foco de la industria - Arnulfo Espinosa Dominguez Parte I</title>
        <itunes:title>Foco de la industria - Arnulfo Espinosa Dominguez Parte I</itunes:title>
        <link>https://isacapodcast.podbean.com/e/foco-de-la-industria-arnulfo-espinosa-dominguez/</link>
                    <comments>https://isacapodcast.podbean.com/e/foco-de-la-industria-arnulfo-espinosa-dominguez/#comments</comments>        <pubDate>Wed, 14 Sep 2022 14:42:38 +0000</pubDate>
        <guid isPermaLink="false">isacapodcast.podbean.com/a63a62b1-0e14-3be7-b24c-4b714c1915df</guid>
                                    <description><![CDATA[<p>Parte II: https://isacapodcast.podbean.com/e/foco-de-la-industria-arnulfo-espinosa-dominguez-parte-ii/</p>
<p>El vicepresidente del Capítulo Monterrey de ISACA y Director de Auditoría y Fraude de TI de uno de los Grupos Financieros más grandes de México, Arnulfo Espinosa Domínguez, se une a Jocelyn Alcantar de ISACA para compartir muchas cosas que ha aprendido durante sus 20 años de experiencia profesional en la industria. Habiéndose dado cuenta del valor de la información a una edad temprana, Arnulfo ha forjado su camino dentro de la comunidad de TI. Es un formador acreditado para múltiples certificaciones, asesor independiente y presidente de varios comités de Ciberseguridad, Riesgo y Auditoría, y es reconocido mundialmente por un apodo que sus compañeros le han dado, "El AudiTHOR".</p>
<p>Como voluntario de ISACA desde hace mucho tiempo y orador de conferencias, Arnulfo ha sido premiado en numerosas ocasiones por sus destacados logros. En 2019, se le otorgó el "Premio al Líder de Capítulo Sobresaliente" (Outstanding Chapter Leader Award) de ISACA, en 2020, recibió el "Premio John Kuyers al Mejor Orador" (John Kuyers Award for Best), y recibió el mayor logro, el "Premio Salón de la Fama de ISACA" (ISACA Hall of Fame Award) en 2021. </p>
<p>¡Únase a la escucha de este episodio mientras Arnulfo ofrece sus mejores consejos y prácticas para convertirse en un orador excepcional, consejos sobre cómo los profesionales emergentes pueden entrar en la industria, y cómo su alter ego, AudiTHOR, alimenta su pasión por la auditoría!</p>
<p>Para leer más sobre Arnulfo, visite <a href='http://www.isaca.org/resources/news-and-trends/isaca-now-blog/2020/iamisaca-from-rock-star-to-speak-star'>www.isaca.org/resources/news-and-trends/isaca-now-blog/2020/iamisaca-from-rock-star-to-speak-star</a></p>
<p>Para escuchar más Podcasts de ISACA, visite <a href='http://www.isaca.org/podcasts'>www.isaca.org/podcasts</a></p>
]]></description>
                                                            <content:encoded><![CDATA[<p>Parte II: https://isacapodcast.podbean.com/e/foco-de-la-industria-arnulfo-espinosa-dominguez-parte-ii/</p>
<p>El vicepresidente del Capítulo Monterrey de ISACA y Director de Auditoría y Fraude de TI de uno de los Grupos Financieros más grandes de México, Arnulfo Espinosa Domínguez, se une a Jocelyn Alcantar de ISACA para compartir muchas cosas que ha aprendido durante sus 20 años de experiencia profesional en la industria. Habiéndose dado cuenta del valor de la información a una edad temprana, Arnulfo ha forjado su camino dentro de la comunidad de TI. Es un formador acreditado para múltiples certificaciones, asesor independiente y presidente de varios comités de Ciberseguridad, Riesgo y Auditoría, y es reconocido mundialmente por un apodo que sus compañeros le han dado, "El AudiTHOR".</p>
<p>Como voluntario de ISACA desde hace mucho tiempo y orador de conferencias, Arnulfo ha sido premiado en numerosas ocasiones por sus destacados logros. En 2019, se le otorgó el "Premio al Líder de Capítulo Sobresaliente" (Outstanding Chapter Leader Award) de ISACA, en 2020, recibió el "Premio John Kuyers al Mejor Orador" (John Kuyers Award for Best), y recibió el mayor logro, el "Premio Salón de la Fama de ISACA" (ISACA Hall of Fame Award) en 2021. </p>
<p>¡Únase a la escucha de este episodio mientras Arnulfo ofrece sus mejores consejos y prácticas para convertirse en un orador excepcional, consejos sobre cómo los profesionales emergentes pueden entrar en la industria, y cómo su alter ego, AudiTHOR, alimenta su pasión por la auditoría!</p>
<p>Para leer más sobre Arnulfo, visite <a href='http://www.isaca.org/resources/news-and-trends/isaca-now-blog/2020/iamisaca-from-rock-star-to-speak-star'>www.isaca.org/resources/news-and-trends/isaca-now-blog/2020/iamisaca-from-rock-star-to-speak-star</a></p>
<p>Para escuchar más Podcasts de ISACA, visite <a href='http://www.isaca.org/podcasts'>www.isaca.org/podcasts</a></p>
]]></content:encoded>
                                    
        <enclosure url="https://mcdn.podbean.com/mf/web/npnvte/P_259_Edit_Part_I_Audio_Podcast_FINAL5zu9m.mp3" length="46603595" type="audio/mpeg"/>
        <itunes:summary><![CDATA[Parte II: https://isacapodcast.podbean.com/e/foco-de-la-industria-arnulfo-espinosa-dominguez-parte-ii/
El vicepresidente del Capítulo Monterrey de ISACA y Director de Auditoría y Fraude de TI de uno de los Grupos Financieros más grandes de México, Arnulfo Espinosa Domínguez, se une a Jocelyn Alcantar de ISACA para compartir muchas cosas que ha aprendido durante sus 20 años de experiencia profesional en la industria. Habiéndose dado cuenta del valor de la información a una edad temprana, Arnulfo ha forjado su camino dentro de la comunidad de TI. Es un formador acreditado para múltiples certificaciones, asesor independiente y presidente de varios comités de Ciberseguridad, Riesgo y Auditoría, y es reconocido mundialmente por un apodo que sus compañeros le han dado, "El AudiTHOR".
Como voluntario de ISACA desde hace mucho tiempo y orador de conferencias, Arnulfo ha sido premiado en numerosas ocasiones por sus destacados logros. En 2019, se le otorgó el "Premio al Líder de Capítulo Sobresaliente" (Outstanding Chapter Leader Award) de ISACA, en 2020, recibió el "Premio John Kuyers al Mejor Orador" (John Kuyers Award for Best), y recibió el mayor logro, el "Premio Salón de la Fama de ISACA" (ISACA Hall of Fame Award) en 2021. 
¡Únase a la escucha de este episodio mientras Arnulfo ofrece sus mejores consejos y prácticas para convertirse en un orador excepcional, consejos sobre cómo los profesionales emergentes pueden entrar en la industria, y cómo su alter ego, AudiTHOR, alimenta su pasión por la auditoría!
Para leer más sobre Arnulfo, visite www.isaca.org/resources/news-and-trends/isaca-now-blog/2020/iamisaca-from-rock-star-to-speak-star
Para escuchar más Podcasts de ISACA, visite www.isaca.org/podcasts]]></itunes:summary>
        <itunes:author>ISACA Podcast</itunes:author>
        <itunes:explicit>false</itunes:explicit>
        <itunes:block>No</itunes:block>
        <itunes:duration>1932</itunes:duration>
                <itunes:episode>221</itunes:episode>
        <itunes:episodeType>full</itunes:episodeType>
            </item>
    <item>
        <title>Why (And How to) Dispose of Digital Data</title>
        <itunes:title>Why (And How to) Dispose of Digital Data</itunes:title>
        <link>https://isacapodcast.podbean.com/e/why-and-how-to-dispose-of-digital-data/</link>
                    <comments>https://isacapodcast.podbean.com/e/why-and-how-to-dispose-of-digital-data/#comments</comments>        <pubDate>Tue, 13 Sep 2022 13:08:45 +0000</pubDate>
        <guid isPermaLink="false">isacapodcast.podbean.com/6f010bc0-0527-3fe0-bc26-cc6690e04788</guid>
                                    <description><![CDATA[<p>The stakes are too high for organizations not to comply with data privacy regulations,” Bassel Kablawi states in his article, "Why (and How to) Dispose of Digital Data." As the Information Security and Data Privacy Consultant for System Solutions, Bassel Kablawi has the knowledge and experience to determine that the value of data disposal can help an organization protect personal data from being exposed and why the final step in the Data Lifecycle could be considered the most crucial.</p>
<p>Bassel takes us on a deep dive into digital data with ISACA's Safia Kazi on the five stages of data disposal in this ISACA podcast episode. He explains why it is essential to understand that destruction should be performed based on an organization’s retention policy and the five main disposal methods of data, which include date anonymization, data deletion, data crypto shredding (for encrypted data), data degaussing, and data destruction.</p>
<p>Tune in to hear Bassel explain why data destruction is critical to developing digital trust with customers and stakeholders and could save an organization’s reputation.</p>
<p>To read Bassel's article, please visit: <a href='http://www.isaca.org/resources/news-and-trends/industry-news/2022/why-and-how-to-dispose-of-digital-data'>www.isaca.org/resources/news-and-trends/industry-news/2022/why-and-how-to-dispose-of-digital-data</a></p>
<p>To listen to more ISACA Podcasts, please visit: <a href='http://www.isaca.org/podcasts'>www.isaca.org/podcasts</a></p>
]]></description>
                                                            <content:encoded><![CDATA[<p>The stakes are too high for organizations not to comply with data privacy regulations,” Bassel Kablawi states in his article, "Why (and How to) Dispose of Digital Data." As the Information Security and Data Privacy Consultant for System Solutions, Bassel Kablawi has the knowledge and experience to determine that the value of data disposal can help an organization protect personal data from being exposed and why the final step in the Data Lifecycle could be considered the most crucial.</p>
<p>Bassel takes us on a deep dive into digital data with ISACA's Safia Kazi on the five stages of data disposal in this ISACA podcast episode. He explains why it is essential to understand that destruction should be performed based on an organization’s retention policy and the five main disposal methods of data, which include date anonymization, data deletion, data crypto shredding (for encrypted data), data degaussing, and data destruction.</p>
<p>Tune in to hear Bassel explain why data destruction is critical to developing digital trust with customers and stakeholders and could save an organization’s reputation.</p>
<p>To read Bassel's article, please visit: <a href='http://www.isaca.org/resources/news-and-trends/industry-news/2022/why-and-how-to-dispose-of-digital-data'>www.isaca.org/resources/news-and-trends/industry-news/2022/why-and-how-to-dispose-of-digital-data</a></p>
<p>To listen to more ISACA Podcasts, please visit: <a href='http://www.isaca.org/podcasts'>www.isaca.org/podcasts</a></p>
]]></content:encoded>
                                    
        <enclosure url="https://mcdn.podbean.com/mf/web/de8ij4/P_284_Audio_Podcast_FINALafhiy.mp3" length="24688520" type="audio/mpeg"/>
        <itunes:summary><![CDATA[The stakes are too high for organizations not to comply with data privacy regulations,” Bassel Kablawi states in his article, "Why (and How to) Dispose of Digital Data." As the Information Security and Data Privacy Consultant for System Solutions, Bassel Kablawi has the knowledge and experience to determine that the value of data disposal can help an organization protect personal data from being exposed and why the final step in the Data Lifecycle could be considered the most crucial.
Bassel takes us on a deep dive into digital data with ISACA's Safia Kazi on the five stages of data disposal in this ISACA podcast episode. He explains why it is essential to understand that destruction should be performed based on an organization’s retention policy and the five main disposal methods of data, which include date anonymization, data deletion, data crypto shredding (for encrypted data), data degaussing, and data destruction.
Tune in to hear Bassel explain why data destruction is critical to developing digital trust with customers and stakeholders and could save an organization’s reputation.
To read Bassel's article, please visit: www.isaca.org/resources/news-and-trends/industry-news/2022/why-and-how-to-dispose-of-digital-data
To listen to more ISACA Podcasts, please visit: www.isaca.org/podcasts]]></itunes:summary>
        <itunes:author>ISACA Podcast</itunes:author>
        <itunes:explicit>false</itunes:explicit>
        <itunes:block>No</itunes:block>
        <itunes:duration>1026</itunes:duration>
                <itunes:episode>220</itunes:episode>
        <itunes:episodeType>full</itunes:episodeType>
            </item>
    <item>
        <title>Industry Spotlight - Johann Dettweiler Part II</title>
        <itunes:title>Industry Spotlight - Johann Dettweiler Part II</itunes:title>
        <link>https://isacapodcast.podbean.com/e/industry-spotlight-johann-dettweiler-part-ii/</link>
                    <comments>https://isacapodcast.podbean.com/e/industry-spotlight-johann-dettweiler-part-ii/#comments</comments>        <pubDate>Thu, 08 Sep 2022 13:08:37 +0000</pubDate>
        <guid isPermaLink="false">isacapodcast.podbean.com/c4e3782f-d71d-3a6c-b567-8cc0ff620222</guid>
                                    <description><![CDATA[<p>Link to Part I: https://isacapodcast.podbean.com/e/industry-spotlight-johann-dettweiler-part-1/</p>
<p>In this ISACA podcast episode, we connect with TalaTek Director of Operations Johann Dettweiler to discuss his almost two decades of experience across multiple industry fields, his involvement in FEDRAMP compliance, and why the next generation should focus on adding certifications to their resumes.</p>
<p>Johann tells ISACA's Keith Karlsson that it was his work ethic and guidance of a trusted mentor that provided an opportunity in the IT security field. In less than 12 months, he racked up multiple impressive certifications such as CISSP, CCSP, and CEH that rapidly advanced his career and, as he explains it, allows him to be “the person that everyone hates because I tell you what is wrong with your system.”</p>
<p>Johann’s strong background in research and his constant quest for knowledge about this evolving industry, he is more than willing to provide listeners with his efficiency hacks to stay productive, motivational career advice, and why the next-generation cyber professionals may have an advantage over him. Tune in now to meet Senior Security Information Security Consultant Johann Dettweiler.</p>
<p>To learn more about Johann, visit <a href='https://talatek.com/project/johann-dettweiler/'>https://talatek.com/project/johann-dettweiler/</a></p>
<p>To listen to other ISACA Podcast episodes, visit <a href='http://www.isaca.org/podcast'>www.isaca.org/podcast</a></p>
]]></description>
                                                            <content:encoded><![CDATA[<p>Link to Part I: https://isacapodcast.podbean.com/e/industry-spotlight-johann-dettweiler-part-1/</p>
<p>In this ISACA podcast episode, we connect with TalaTek Director of Operations Johann Dettweiler to discuss his almost two decades of experience across multiple industry fields, his involvement in FEDRAMP compliance, and why the next generation should focus on adding certifications to their resumes.</p>
<p>Johann tells ISACA's Keith Karlsson that it was his work ethic and guidance of a trusted mentor that provided an opportunity in the IT security field. In less than 12 months, he racked up multiple impressive certifications such as CISSP, CCSP, and CEH that rapidly advanced his career and, as he explains it, allows him to be “the person that everyone hates because I tell you what is wrong with your system.”</p>
<p>Johann’s strong background in research and his constant quest for knowledge about this evolving industry, he is more than willing to provide listeners with his efficiency hacks to stay productive, motivational career advice, and why the next-generation cyber professionals may have an advantage over him. Tune in now to meet Senior Security Information Security Consultant Johann Dettweiler.</p>
<p>To learn more about Johann, visit <a href='https://talatek.com/project/johann-dettweiler/'>https://talatek.com/project/johann-dettweiler/</a></p>
<p>To listen to other ISACA Podcast episodes, visit <a href='http://www.isaca.org/podcast'>www.isaca.org/podcast</a></p>
]]></content:encoded>
                                    
        <enclosure url="https://mcdn.podbean.com/mf/web/v2dv9x/P_274_Audio_Podcast_Part_02_FINALahje7.mp3" length="31319141" type="audio/mpeg"/>
        <itunes:summary><![CDATA[Link to Part I: https://isacapodcast.podbean.com/e/industry-spotlight-johann-dettweiler-part-1/
In this ISACA podcast episode, we connect with TalaTek Director of Operations Johann Dettweiler to discuss his almost two decades of experience across multiple industry fields, his involvement in FEDRAMP compliance, and why the next generation should focus on adding certifications to their resumes.
Johann tells ISACA's Keith Karlsson that it was his work ethic and guidance of a trusted mentor that provided an opportunity in the IT security field. In less than 12 months, he racked up multiple impressive certifications such as CISSP, CCSP, and CEH that rapidly advanced his career and, as he explains it, allows him to be “the person that everyone hates because I tell you what is wrong with your system.”
Johann’s strong background in research and his constant quest for knowledge about this evolving industry, he is more than willing to provide listeners with his efficiency hacks to stay productive, motivational career advice, and why the next-generation cyber professionals may have an advantage over him. Tune in now to meet Senior Security Information Security Consultant Johann Dettweiler.
To learn more about Johann, visit https://talatek.com/project/johann-dettweiler/
To listen to other ISACA Podcast episodes, visit www.isaca.org/podcast]]></itunes:summary>
        <itunes:author>ISACA Podcast</itunes:author>
        <itunes:explicit>false</itunes:explicit>
        <itunes:block>No</itunes:block>
        <itunes:duration>1303</itunes:duration>
                <itunes:episode>219</itunes:episode>
        <itunes:episodeType>full</itunes:episodeType>
            </item>
</channel>
</rss>
