You are on page 1of 8

ISACARIYADHCHAPTERNEWSLETTERAPR2016|ISSUE#3

ISACA
Riyadh
Chapter
Newsletter

Apr 2016 |
TRUSTIN,ANDVALUEFROM,INFORMATIONSYSTEMS!

INTHISISSUE

Chapter Presidents Message


In the name of Allah SWT the Beneficent, Chapter has kickedoff the year 2016 in a
theMerciful progressive way and the following has been
achievedsofar:
AsourProphetSAWSsaid,
Theonewhodoesnotthankpeopledoes A Technical Sessions with support of
notthankAllahSWT. sponsorsnamelyProtivityMiddleEast
FiveAssociatePartnershipsagreements
Firstly thanking Allah SWT for all his foreventsinRiyadhandDubai
blessingsandmercy.Thankstooursponsors Arabization project launched for COBIT
who have and are supporting the Chapter 5forRisk
activities, the ISACA HQs, the Chapter Arabization project launched for COBIT
members who spare their valuable time to 5forSecurity
attend to Chapter events and the Chapter Revamped Chapter website as per
Leaders who have dedicated their time and ISACAstandardsandsynchronizedwith forward to your continued support so as to
efforts. ISACAwebsite cancontinuetheonwardsjourney.

BytheGraceofAlmightyAllahSWTtheyear And as we move into forward in 2016, the With the first quarter of 2016 over,
2015 ended on a high note for Riyadh Chapter will continue to work on initiatives companies globally and in the region are
Chapter as the Chapter managed to move that Chapter has established for itself, facing challenges and hence Governance,
forward towards its targeted goals. The overcome the challenges at hand and Security and Controls are getting more
following had been Chapters achievements contributemoretotheChaptermembersin importance than ever for sustaining and
duringtheyear2015: particularandtotheCommunityingeneral. coming out of the crunch times. With the
Three Technical Sessions with support blessed month of Ramadan approaching let
of sponsors namely AlFaisal University TheChaptersjourneyisgoingonwithquite us sincerely pray to Almighty Allah for His
&FireEye many goals and targets yet to be achieved. blessings for muchdue peace and stability
Three Associate Partnerships events in TheChapterintendstocontinuepursuingits forthe7billion+individualsacrossthevillage
RiyadhandDubai goals countering the challenges at hand by World.
CISAExamPreparationWorkshops effectivelyandefficientlyutilizingthelimited
Chapter channels on ISACA resourcesavailable. I would close by thanking to Chapter
International Website, FB, TW & Members and Chapter Friends who are
LinkedIn I would like to reiterate the support, already contributing towards this NL. Other
Extending helping hand to prospective assurances and dedication of all the members & friends interested in making
employersandaspiringcandidatesover sponsors, the ISACA HO, Chapter members contributions to the NL with their original
jobopportunities and Chapter Leaders towards the Chapter work are welcome to send them to the
Realization of the News Letter (NL) activities and Chapter targets. Had your Chapter Secretary for possible inclusion in
Initiativeandthisbeingthethirdedition continued support and resoluteness be not futureNLs.
oftheRiyadhChapterNL there, the Chapter would not have seen the AliFathiAlShaikh
daysinceitwentintothefamoussevenyear ChapterPresident

hibernation. The Chapter banks on and look


ISACARIYADHCHAPTERNEWSLETTERAPR2016|ISSUE#3|

What does the new


understoodandmayhideadditionalrisks. greatopportunityforaddingvaluetothe
Combinethesetrendswiththediluted business.Thiswontbepainfree.Asalways

digital frontier
networksecurityperimeter,added requirespreparingandplanningaheadto
complexityandmoreopportunitiesfor securesuccess.Whatfollowsisprobably
unforeseenutilizationofnewtechnologies, easier,buckleupandenjoythejourney.A
bring for the FSI IT eitherduelegitimateuseractivityorhacking,
andyougetareducedabilitytodefendan
welcomemessagefromRiyadhChapter
Presidentreachingouttoallmembersto
Risk Professionals? organization.Currentriskmanagement
practicesmayalsobecomelessrelevantand
concentrateonthechapterobjectivesand
highlightingtheachievementsandprogress
FSIhasbeenfrequentlyseenasoneof
effectiveastheyvebeendesigned madesofar.
theearlytechnologyadoptersbenefiting
forlessdynamicandinterconnectedrisk
frominnovation.ATMs,wiretransfers,e MembersinterestedinmakingcontributiontotheNL
scenarios.
banking,mobilebankingarejustafew withtheiroriginalworkarewelcometosendthemto

examplesfromalonglistof,once ChapterPresident/ChapterSecretary
ThesetrendsarefarfromFSIspecificand
revolutionary,technologieswhichare
couldaffectthebroadersocietyasawhole.
nowpartofourdailyvocabulary.Itisoften
However,onecouldarguetheimpactonFSI
said"thereisnothingpermanentexceptfrom
couldbemoreprofoundduetoits
change".Althoughchangeisconstant,
dependenceontechnologyandprogressive
mostofuswouldagreethepaceof
stancetowardtechnologicalinnovation.Isit
technologicalinnovationhasdramatically
allgloomanddoomfortheFSIITRisk
changedsincethetimeofHeraclitus.Block NassosOikonomopoulosis
professionals?Probablynot,amorerelevant
chain,Cryptocurrencies,Cognitive basedinSaudiArabiaandassociatedwithDeloitte
metaphorcouldbethisfeelslikea
ComputingandCollaborativeEconomyare &Touche(M.E.)asSeniorDirectorinEnterpriseRisk
bittersweetsituation.Yes,thereisaneedfor
allexistingdevelopmentsexpectedto Services(ERS)andLeaderforInformation&
indepthfamiliarizationwiththenewtrends,
becomefuture"disruptors"fortheFSI TechnologyRisk(ITR)services
researchandeducatingtheCsuite.Thiswill
industry
requireeffort,planningandbrushingupyour
(http://www2.deloitte.com/us/en/pages/finan
cialservices/articles/bankingtrends.html).
lobbyingskills.However,thisisalsoagreat ISACA Technical Session!!
anduniqueopportunitytoaddvaluetothe WebringyoupicturesofthesuccessfulTechnical
VirtualRealityisalsoanotherfastevolving
businessandstandoutofthecrowds.There sessionheldinFebruary2016!Page4
trendwhichcouldinfluencethebusiness
ismoregoodnews;neverbeforetheboard
channelsfordoingbanking.Thisnewdigital
hasbeensomuchintunewiththeITRisk
epochismindboggling,fascinatingand
agenda.ThewordsCyberandITRiskare
intimidatingallatthesametime.
pronouncedtooofteninexecutivemeetings

mesmerizingtheboard.Thereismore
Anumberofsurveyssuggestthethreat
budgetavailableandevenmorefrequently
environmentwillworsenintheupcoming
theawarenessandsupportfromExecutive
yearsalsoasaconsequenceofthis
Management.Nobodywouldliketoseetheir
technologicalinnovationandhighlight
namesnexttoanotherITorCyberfailure
commonthemes.Asanexample,the
headlineafterall.
InternetofThings(IoT)devices,whichplaya

keypartintheaforementionedtechnologies,
Concluding,thisexcitingtimeoftechnological
arestillvulnerableandleakinformation.
developmentscouldmarkanewmilestonefor
Also,someofthenewtechnologiesinclude
ITRiskManagers,especiallyinFSI,aswellasa
obscurealgorithmswhicharenotclearly
ISACARIYADHCHAPTERNEWSLETTERAPR2016|ISSUE#3

About the ISACA


Riyadh Chapter
ExComm
TheISACARiyadhChapterismanagedbyagroupofelectedvolunteers
whoformtheExecutiveCommittee.AsperISACAguidelinesthereare
specificrolesandpositionsassignedineachchapterinorderto
facilitatepropermanagementandgovernancewhilefocusingonallkey
areasrequiredtomakethechapterbeneficialtothemembersandthe
Chapter Leaders Meeting in Riyadh
ITauditcommunity.

ISACARiyadhChapterhasbeenfortunatetohaveonitsExecutive
Communitymembersthathavemanyyearsofexperiencebehindthem
andalsothewilltocontributetothechapteranditsmembers.The
ExCommiselectedbyvotesannuallyandcanmaintaintheirposition
for13yearsafterwhichareshufflingisencouragedtoensureother
membersgetachancetocontributetotheChapteraswell.

ThefollowingarethemembersoftheExComm:

1. President:AliAlFathi,CISA,CISM,CGEIT,CRISC,PMP,ISO
27001:2005LA.
2. VicePresident:AbobakrSalehBaazim,CISA,CISM,CRA,CCO.
3. GeneralSecretary&CRISC,CGEIT,MarketingCoordinator:
HasnainJaffery,CGEIT,CRISC,ITILV3Foundation,COBIT4
Foundation.
4. CISMCoordinator:AlaaEddinNabiehDabbagh,CISM,MBA,
CCNA.
5. ResearchDirector,CISACoordinator:AqelMohammedAqel, Chapter Leaders Meeting in Riyadh
CISA,MBA,COBIT5Trainer.
6. ChapterTreasurer:SyedAbbasReza,CISA,CGEIT,FCCA,CIA,
COBIT5Foundation
7. MembershipDirector:Dr.YousefMohammedAsfour,CGEIT,
CISM.
8. GRACoordinator:NaveedAhmed,CISA,CISM,CGEIT.
9. WebsiteDirector:KamranMushtaqAhmed,CISA,PMP.
10. PRDirector:RezeqAbuKhater
11. Newsletter:MohammedSalimSyed,CISA,CRISC,PMP,CCM.

FORMOREINFORMATION

Visitourwebsitewww.isacariyadh.org


ISACARIYADHCHAPTERNEWSLETTERAPR2016|ISSUE#3|

Technical Session on 15 February 2016 sponsored by


Protiviti ME


ISACARIYADHCHAPTERNEWSLETTERAPR2016|ISSUE#3|

Managing IT Resources in Data Centers (contd.)

by Aqel M. Aqel

1. Planning
Before hiring, it is rational to conduct an assessment for capabilities needed to operate the datacenter. Several factors
shouldbeconsideredtoarticulatethespecificskillsneededthatwillbeeitherdevelopedwithindatacentersteamorhired
to expand its set of capabilities. Reviewed references and personal experience articulated the follow factors: 1business
requirements,2implementedtechnology,and3availablebudget.

InastudybyGartnerabouthelpdeskratiosfindsimilarresults;endusersupportratioreached87usersperonestaff,the
highestratiowas275usersperonestaff,andthelowestwas12.Thesenumbersdonotindicateanypreferredmetricfor
certainindustry,yetitgivesaclue.Iadvisetobuildacapabilitiesmatrixthatjoinsskillsneededwithexistingprocesses,
tasks, and projects in datacenter. Such tables will help datacenter management understand resource utilization; while
there are many softwaresolutionsthatcangivebettermapping. Another table that matchesresourceswithskill sets is
requiredtoplanforcapabilitybuildingandknowledgetransferwithindatacenter.

2. Hiring
Regardlessifyouarestaffinganewlyestablisheddatacenterorinastageofimplementingyourannualhiringplan,quality
datacentercapacitybuildingstartsbyhiringcompetitivecandidateswhoownsknowledgeandpositiveattitudestowards
themselvesandothersintheworkplace.

Itsbecomingconventionalthatadoptingstreamlinedhiringprocesseswillattractqualifiedresources.Iwouldliketolist
setofbestpracticeswhichare:

Anticipateneedsandcollectsomeresumesbeforeyouareinarushtohire.
Screening, Interviewing, evaluating, and negotiating candidates are essential skills that are to be cultivated in key
workers. Team members should develop some best practices in the mentioned skills, and share knowledge and
experiences.
Hiringentrylevelworkersratherthanexperiencedonesmaylookpracticalforlimitedbudgetdatacenters.
Its a professional practice to allow certain period for the new worker to hand over his current job responsibilities
beforejoiningyourteam.
Conducting a background check for shortlisted candidates is recommended in order to identify any potential bad
attitudesorpreviousfraudbytheworker.
ANondisclosureagreement(NOD)mustbesignedbeforeorparallelwithsigningworkcontract.
Considergivinganycandidateanorientationbeforeinvolvinghiminrealoperations.
Conductadetailedskillassessmentforthenewworkerandlethimgetsometrainingbeforerelyingonhiminmission
criticaltasks.

Onceyou'veidentifiedpromisingemployees,makesuretheyunderstandyouhaveacareerpathinmindforthem.
[TobecontinuedinnextNewsletter]
ISACARIYADHCHAPTERNEWSLETTERAPR2016|ISSUE#3|

Chapter Website Revamped


ChapterExecutiveCommitteetakespleasureinannouncingthattheRiyadhChapterWebsitehasbeenrevampedandalignedwiththeISACAWebsite
design.
ThisalignmentwithISACAwebsitewasoneoftheChaptertargetsandtherevampingofChaptersitewaslongoverdue.
ChapterwouldliketothankISACAInternationalfortheirsupportinmakingthisalignmentpossible.
SpecialthankstoChapterWebmasterMr.KamranMushtaqforallhisvolunteeredeffortsinrealizationofthistask.
Onreachinghttp://www.isacariyadh.org/youwouldberoutedRiyadhChapterpageonISACAwebsite@RiyadhChapter

More Interesting Articles


ReadCybersecurityGuidanceforSmallandMediumsizedEnterprises.
www.isaca.org/cyberguidance

ReadImplementingCybersecurityGuidanceforSmallandMediumsizedEnterprises.
www.isaca.org/implementingcyberguidance

ISACARIYADHCHAPTERNEWSLETTERAPR2016|ISSUE#3|

ImportantChapter Statistics & Updates


FASTFACTS

601 members in Riyadh Chapter


CGEIT:34
CRISC:82
CISM:108
CISA:218

Exam Passers for Sep & Dec 2015 Exams



CISA: CISM:
Mr.MeshalHezamAlzahrani Mr.MostafaAbdulwahabAbukhodair
Mr.MahendraYashwantGawade Mr.YasserN.Alswailem
Mr.BabarMir Mr.SeanM.McPoland
Mr.MohammedA.Almozaiyn Mr.MoeenQaemiMahmoodzadeh
Mr.SamehF.Abulfotooh Mr.MohammedIbrahimDastagir
SheikhMuhammadAmirRauf Mr.MohammedAbdulazizAlmathami
Mr.MathewKevinPollick Mr.MohammedInamHameed
Mr.TarekAlmahmoud Mr.BadrAldayel
Mr.MohamedKatamish Mr.MuhammadMohsin
Mr.AbdulazizAbdullahAlkhodhairy Mr.KhalidAlfaheid
Mr.SyedMurtuza Mr.YasserRashad
Mr.NabilNabulsi Mr.MohammadAbbasAlsaadon
Mr.MohammedAbdullahMengash Mr.MohammedAhmadAlomari
Mr.MohammedWajdiKhashoggi Mr.ZiaulhaqIrfanMohammad
Mr.JassemM.AlAbdulsalam

CGEIT: CRISC:
Mr.MirzaAmirAli Mr.SalimBennis
Mr.ShivakumarManoharKeskar Mr.AbdulHamidMian
Mr.MohammedOmarAbdullahAhmedMohammed Mr.NilesWatterson
Mr.MathewKevinPollick Mr.AdelGaberHigazy
Mr.SaeedAbdullahAlDobas
Mr.OsamaElsayedGaafar
ISACARIYADHCHAPTERNEWSLETTERAPR2016|ISSUE#3|


Important Dates and Events in 2016


NextExamDate:11June2016
COBITConferenceNorthAmerica:30Apr1May2016,NewOrleans,USA
InformationSecurityEssentialsforITAuditors:1821stApril2016,Chicago,USA
NorthAmericaCACS:24thMay2016,NewOrleans,USA
EuroCACS:30May1stJun2016,Dublin,Ireland
CloudComputing:SeeingthroughtheCloudsWhattheITAuditorNeedstoKnow:2225Aug2016,Boston,USA
CSX2016NorthAmerica:1719thOct2016,LasVegas,USA

Important Links:
ISACAExamGuide:http://www.isaca.org/CERTIFICATION/Pages/CandidatesGuideforExams.aspx
ISACAMembershipdetails:http://www.isaca.org/membership/Pages/default.aspx
ISACACPEQuizzes:http://www.isaca.org/Journal/Quizzes/Pages/default.aspx
ISACACyberSecurityNexus:http://www.isaca.org/cyber/Pages/default.aspx
ISACAExamReviewCourses:http://www.isaca.org/Education/Training/examreviewcourses/Pages/default.aspx
ISACAJournal:http://www.isaca.org/Journal/Pages/default.aspxVolume2,2016
COBIT5:http://www.isaca.org/cobit/pages/default.aspx

ISACA
Riyadh
Chapter
Newsletter
Apr 2016 |
Issue # 3


Riyadh,SaudiArabia


Riyadh,KingdomofSaudiArabia

You might also like