Link North America section Link Europe section Link Asia section
All programs Audit World 2010 CISO Executive Summit InfoSec World Conference & Expo 2010 Summit on Secure Virtualization and Cloud Computing SuperStrategies 2010
All programs The Audit Directors and Managers Symposium The IT Audit Management Summit
 
     Conferences            >      Seminars            >      Symposia            >      Webinars      Training Weeks      In-House Training      Online Training      Certificate Programs>      Exhibiting Info      Ways to Save      Request Info      Event Downloads      Products      White Papers      Call for Instructors      Contact MIS      Site Map
Internal Audit IT Audit Info Security
Internal Audit IT Audit Info Security

Instructor Bios

Sandy Bacik, CISSP, ISSMP, CISM, CHS-III
Sandy Bacik, Corporate Security Officer, Tekelec has over 11 years direct development, implementation, and management information security experience in the areas of Audit Management, Disaster Recovery/Business continuity, Incident investigation, Physical security, Regulatory compliance, Standard Operating Policies/Procedures.
Throughout her career Ms. Bacik has managed, architected and implemented comprehensive information assurance programs and managed internal, external, and contracted/outsourced information technology audits to ensure various regulatory compliance for state and local government entities and Fortune 200 companies Ms. Bacik has performed and managed engagements for assessment types and frameworks to ensure corporate compliance including Committee of Sponsoring Organizations of the Treadway Commission (COSO), Control Objectives for Information and related Technology (CobIT), Gramm-Leach Bliley Act (GLBA), Health Insurance Portability and Accountability Act (HIPAA), International Standards Organization (ISO) 17799, IT Infrastructure Library (ITIL), Sarbanes-Oxley Act (SOX), Cardholder Information Security Program (CISP), Restriction of Hazardous Substances (RoHS), and Waste Electrical & Electronic Equipment (WEEE).

Bobbe M. Barnes, CPA, CMA, CGFM
Bobbe Barnes is an educator and consultant with many years of professional experience providing IFRS and US GAAP training around the world. Most recently, Ms. Barnes developed the Certified International Professional Accounting certificate programs, including its training courses and examinations. Ms. Barnes’ international work includes assignments in Central and Eastern Europe, Central Asia, Russia, Ukraine, China, Indonesia, Mongolia, and South Korea. She also delivered a series of workshops for trainers to improve their technical knowledge and teaching methodologies for delivering IFRS courses. Ms. Barnes is a member of the Board of Directors of the Institute of Management Accountants, where she served for two years on the standing Committee on Ethics.

Anthony J. Bellezza, CPA,
Anthony J. Bellezza is the Senior Vice President and Chief Compliance Officer (CCO) at Rite Aid Corporation. He also serves as the Chief Ethics and Risk Officer for the company. During his three years at Rite Aid, he has created the company’s corporate governance framework, focusing on ethics, compliance and regulatory matters, investigations and fraud reporting, and enterprise risk management. Prior to joining Rite Aid, Mr. Bellezza was a Partner at Ernst & Young. He also served as the Mid-Atlantic Business Risk Services (BRS) Leader, responsible for developing and growing the BRS practice.

Doug S. Brown, CPA
Doug S. Brown, CPA is Professor of Accounting at Montana State University Billings, where he teaches courses on financial accounting, auditing, business law, and management. Previously, Mr. Brown was Lead Auditor for Chevron Corporation where his responsibilities included audits of Chevron USA's oil and gas accounting functions and providing audit expertise for large disputed construction contracts between Chevron and major vendors. During his 20-year career, Mr. Brown has held Senior Auditor positions at Crown Zellerback Corporation and Fluor Corporation, served as an Associate and Staff Auditor for BP America, and worked as a staff auditor for Coopers & Lybrand. A member of the AICPA and the IIA, Mr. Brown has published numerous articles in The Internal Auditor and Internal Auditing. He is also the Lead Instructor for the Montana Society of CPA's Ethics Continuing Professional Education Program and the Montana State University - Billings CPA Review Program.

Jason Claycomb, CISA
Jason D. Claycomb is a principal in INARMA LLC. He has 20 years of experience in computer system development, audit, and security evaluation. Previously, Mr. Claycomb was National Director of IT Services at Jefferson Wells LLC, a Manager at Price Waterhouse, and an IT Auditor at First Colonial Bankshares Corporation. Mr. Claycomb is a member of ISACA, IIA, and ISSA. He is on the Security White Paper Committee Co-Chairman of the Technology Executive’s Club.

Nicole Coutsonikas, CFE
Nicole Coutsonikas is the Forensic Manager at Fraud Auditing, Inc., a consulting firm that does financial investigations, fraud prevention, and litigation support. In this capacity, Ms. Coutsonikas has been involved in successful financial investigations involving contract fraud, embezzlement, asset theft, disbursement schemes, and in court proceedings as a financial investigator. Prior to her work with Fraud Auditing, Inc., Ms. Coutsonikas developed many of her skills in the private sector as lead internal auditor and Sarbanes-Oxley analyst at a publicly held pharmaceutical company. Her private sector experience includes extensive work in internal audit and SOX compliance surrounding project and general accounting, contracts administration, purchasing, and human resources, both domestically and internationally. She also led a team in implementing Oracle, where her responsibilities included documenting and reviewing all pieces of the implementation for SOX compliance and adherence to policy and procedure. Ms. Coutsonikas is a member of the National Association of Certified Fraud Examiners and The Institute of Internal Auditors.

Dennis Cox, BSC, FCA, FISI, is the Founder and Chief Executive of Risk Reward Ltd, where he oversees all consulting and training projects. In addition, he specializes in Basel Accord challenges surrounding credit, market, and operational risk, as well as other business and regulatory requirements.  Mr. Cox has more than 25 years of experience in the areas of risk, banking, audit, and accounting. Previously, he was with HSBC Bank where he held senior management roles that included Director of Risk Management and Senior Audit Manager. Prior to joining HSBC Bank, he was Global Risk Manager at Prudential Portfolio Managers Ltd., responsible for credit, legal, and operational risk for the global business. Mr. Cox is the author of Banking and Finance: Accounts, Audit and Practice. He co-authored The Mathematics of Banking & Finance, and is the senior editor and author of several chapters in The Frontiers of Risk Management.

Kathleen M. Crawford
Kathleen Crawford  is a Senior Consultant for MIS Training Institute and the President of Crawford Consulting and Communications LLC, a firm specializing in assurance and advisory projects for small firms without an internal audit function. Previously, she was an Internal Auditor for Vinfen Corporation, a private, nonprofit human services organization. Ms. Crawford’s responsibilities include assisting management in the standardization of operations, developing policies and procedures, and improving processes. In addition, she conducts operational and financial audits throughout the company.  Ms. Crawford began her career as a bank auditor, first with Bank of New England, then Eastern Bank, and State Street Bank. A member of the Institute of Internal Auditors, Ms. Crawford is a past President of the Greater Boston Chapter of the IIA. She is also a member of the Association of Certified Fraud Examiners and the American Society for Training and Development.

Ken Cutler, CISSP, CISA, CISM
Ken Cutler is the Vice President of Information Security at MIS Training Institute, where his responsibilities include directing MIS’ infosecurity public training programs.  In addition, he sets strategy for MIS’ information security certificate programs. He is also the principal consultant for Ken Cutler & Associates (KCA), an independent information security consulting firm. Mr. Cutler was formerly with American Express Travel Related Services where he had worldwide responsibilities for security standards, awareness programs, risk assessments, and security consulting services. Previously, he served as the CIO for Moore McCormack Resources. He also headed up the security program at Martin Marietta Data Systems. Mr. Cutler is the co-author of the Commercial International Security Requirements (CISR), which offers a commercial alternative to the military security standards for system design. Mr. Cutler was a featured speaker at the 1997-2002 COMDEX conferences. He is frequently quoted in such publications as Computerworld, InfoWorld, Communications Week, and Enterprise Computing, and was featured on Talk America.

Christopher Daugherty, CISSP, CISM, CPA
Christopher Daugherty is a Principle Solutions Architect Director with Computer Associates, where he works with Fortune 500 companies to develop solutions in such areas as IT governance, infosecurity, infrastructure management, business optimization and IT strategy, compliance initiatives, and systems development. He has over 12 years of experience in consulting focused on technical assessments, ERP implementations, IT infrastructure management, IT governance, and information security. He has performed numerous IT compliance engagements on S-OX, HIPAA, and other initiatives related to standards-based security objectives.

Barbara Davison CIA, CIDA, CISA, FLMI
Barbara Davison is President of the Investment Training and Consulting Institute, Inc. (ITCI). ITCI provides training and consulting in the areas of investments, derivatives, risk management, M&A strategies and communication development to management, operations and auditors. Previously, Ms. Davison was Vice President of a financial institution where she directed investment operations for the general account and mutual funds. Prior to her seven years in investments, she was Manager of Internal Audit for six years, responsible for the management of corporate audit activities, computer security, and information systems audits. She also assisted in new business strategies. Ms. Davison obtained her Series 7 and Series 65 from the National Association of Security Dealers (NASD). She has authored five books, including Auditing Investments, Auditing Derivative Strategies, Understanding and Auditing Mergers and Acquisitions, Understanding and Auditing Investment and Derivative Strategies, and Presentation, Persuasion and Facilitation Skills for Auditors.

Betty J. Dorsey
Betty Dorsey is a Senior Technical Consultant focusing on the areas of database management and systems development. She has extensive experience using, auditing, and providing training for CICS, DB2, Oracle, SQL Server, Sybase and other relational database management systems and data warehouses. Mrs. Dorsey has over 25 years of experience in information technology, and has worked with Oracle Financials since 1995.  Her clients include a number of Fortune 500 companies, as well as federal and state agencies. She has also served international clients in England, Holland, Hong Kong and Singapore. Mrs. Dorsey has authored several articles for Infosecurity News and the IS Audit and Control Journal. She is a  member of IEEE.

Edward A. Dorsey
Edward A. Dorsey is a specialist in the areas of Unix, C, C++, object-oriented development and tools, and computer-aided design. Mr. Dorsey's consulting customers include Westinghouse, General Electric, National Semiconductor, and Honeywell. Previously, Mr. Dorsey was Customer Support and Installations Manager for VR Information Systems, and prior to that he was Manager of Customer Systems for Primark, a natural gas utility, where he planned and initiated a complete network conversion, established the data communications department, and served as the senior DP representative to the Information Systems Planning Group. Before joining Primark, Mr. Dorsey was a Systems Engineer for IBM.

Greg Duckert, CIA, CISA, CMA, CPA
Greg Duckert, is CEO of Audit, Inc., a consulting firm specializing in risk assessment models, operational analysis, and audit process methodologies designed to maximize returns to the organization. Mr. Duckert is also a Senior Consultant for MIS Training Institute and has over 30 years of  national and international experience as an Internal/IS Audit Director. Mr. Duckert has held Audit Director positions in the manufacturing, construction and healthcare industries, assuming responsibilities for financial, operational, and information systems auditing functions. His information systems expertise includes application audits, software acquisition, systems development, controls, security design, adequacy and implementation, and systems' operational efficiencies. He has performed consulting services in IS, financial, and operational audits, as well as in business acquisitions and start-ups.

Mark T. Edmead, CISA, CISSP, SSCP
Mark Edmead is a Senior Instructor for MIS Training Institute. A 28-year-veteran of computer systems architecture, information security, and project management, Mr. Edmead has extensive knowledge of IT and application audits, IT governance, and SOX compliance auditing. Mr. Edmead’s expertise in the areas of information security and protection includes access controls, cryptography, security management practices, network and Internet security, computer security law and investigations, and physical security. He has consulted with Fortune 500 and Fortune 1000 companies and worked with a number of international firms. A much sought after presenter, Mr. Edmead has authored articles in Compliance Advisor Magazine, IT Compliance Journal, IIA Insights, and The Auditor. In addition, he is an adjunct professor at the Keller Graduate School of Management.

Lynn Fountain, CPA is the founder of ExpertGRC, a consulting practice specializing in internal audit, Sarbanes-Oxley, enterprise risk management, governance, and compliance. Ms. Fountain has more than 27 years of business experience, including more than 20 years in the areas of internal and external auditing. At ExpertGRC, she is currently providing project leadership to establish a Sarbanes-Oxley compliance and risk management program for a multi-national manufacturing company that is preparing for an IPO. In addition, she is helping a large agricultural cooperative establish a full enterprise risk management program.
Prior to founding ExpertGRC, Ms. Fountain was the Vice-President of Risk Assessment & Audit Service for Aquila Inc., where she was instrumental in initiating and developing COSO and risk management concepts. While at Aquila she was acknowledged as an experienced facilitator of risk management sessions and an expert in the areas of Sarbanes-Oxley and internal audit. A recognized industry speaker, Ms. Fountain has published articles in Compliance Weekly Magazine, IIA Magazine, and Protiviti Knowledgeleader.

Stan Fromhold, CISSP, CISA
Stan Fromhold is a Senior Consultant for BT Security Practice, where he is responsible for the design and bid of major customer security and governance programs. Mr. Fromhold has worked in information security for more than 25 years, with specializations in the area of enterprise security architecture solutions for converged networks, vulnerability assessments, security education, and security compliance audits. He has significant experience in assisting organizations define and implement security architectures and policies for vulnerability and threat management, enterprise security event monitoring, and intrusion detection and prevention architectures. Previously, Mr. Fromhold was Global Director of Security for Dun & Bradstreet,. Prior to joining D&B, Mr. Fromhold was Director of Security for Munich Re/Americas Internet Services.

Martin Green, Esq.
Martin Green, Esquire is head of Martin H. Green, P.C. Mr. Green concentrates his practice on the representation of companies in matters pertaining to computer technology, trade secrets, intellectual property, and copyright law. He also maintains an active consulting practice to lawyers and other professional service businesses regarding office automation and related auditing and security issues. Mr. Green is a member of the Massachusetts Bar, the Massachusetts Academy of Trial Attorneys, and the American Trial Lawyers Association.

W. Brad Hamilton, CPA
W. Brad Hamilton, CPA, is a Senior Instructor for MIS Training Institute. He also serves as a Senior Manager for the City of Tallahassee with responsibilities over PeopleSoft Reporting and Security Administration. In his prior position, Mr. Hamilton was involved in year-end budgetary and GAAP reporting with an emphasis in technology, human resources, pension, and payroll.   Mr. Hamilton has extensive experience using and providing training for PeopleSoft applications, PeopleSoft’s Query Tool and SQL. He is a frequent presenter at PeopleSoft national conferences and was formerly with Deloitte & Touche, a financial institution and a national real estate development company.

Larry Harrell
Larry Harrell is a consultant with over 25 years of experience in systems development, consulting, auditing, and training. A specialist in IBM mid-range systems, System 38, and System 36, Mr. Harrell has lectured and consulted worldwide for such companies as Citibank, Coca-Cola, IBM, and most of the Big 6 accounting firms. He is a frequently requested speaker at organizations with AS/400 systems.

Stuart Holoman
Stuart Holoman is a Senior Consultant for MIS Training Institute. He has over 35 years of experience in computer and data processing systems design, management, and audit and security consultation and training. In recent years, he has specialized in computication and distributed processing systems. Formerly with NorTel, Mr. Holoman directed computer/telecommunications operations, software/hardware acquisition, and software development. Prior to his work at NorTel, he was with Bell Laboratories, where he was involved in communications systems design and development. While at Bell, he developed new techniques and methodologies for the formal and systematic specification of computer systems. Mr. Holoman also pioneered work in abstract protocol theory and was a technical contributor to the ISO for the OSI Reference Model, which today forms the basis for many existing and emerging communications standards. As a principal consultant for HOLOCON, Inc., Mr. Holoman has been involved in network specification, vendor selection, and networking support. He has also designed and implemented numerous communications protocols and interfaces among disparate computing and process control systems. Recently, for the audit and security communities, he has been reapplying and simplifying engineering tools and developing new methodologies for auditing and securing interconnected computing systems with differing implementation philosophies (such as client/server systems and mainframes). Mr. Holoman’s fundamentally new approach to this rapidly changing environment concentrates on analyzing expected or required functionality rather than concentrating on specific hardware or software packages.

Ken Jaworski, CISSP, CIPP
Ken Jaworski is a Project Manager for Compuware Corporation, where he is responsible for a variety of assignments in both the public and private sectors. His areas of expertise encompass information security policy development, business resumption and disaster recovery planning (including business impact analysis), risk management, using the ISO-27002 framework to build an information security management system and records retention programs, and performing information security assessments. In addition, Mr.Jaworski has been concentrating much of his recent efforts on assisting clients in the data privacy arena. He has also developed a tool to perform a privacy impact assessment.  Prior to joining Compuware, Mr. Jaworski had a 31-year career with Detroit Edison. While at Detroit Edison, he worked in the information protection organization and helped build the 1996 Information Protection Program of the Year. Mr. Jaworski was a contributor to the application development and controls organization for more than 18 years. With MIS Training Institute since 1996, Mr. Jaworski is the primary instructor for MIS’ Information Risk Management, Data Privacy, and Business Continuity Planning seminars.

Joel F. Kramer, CPA
Joel F. Kramer, CPA, is Managing Director of the Internal Audit Division of MIS Training Institute, responsible for developing MIS' internal audit curriculum. Formerly worldwide Director of Internal Audit at Instrumentation Laboratory, Mr. Kramer and his staff conducted operational and financial audits in the United States, Canada, Mexico, and throughout Europe. Prior to Instrumentation Laboratory, he had been Internal Audit Manager for the Gillette Company. Previously, Mr. Kramer spent five years with Coopers & Lybrand. A recognized speaker on internal audit topics, he has addressed many IIA Chapters. He is a member of the Board of Governors of the Greater Boston Chapter of the IIA. Mr. Kramer has written articles on productivity and project management for Internal Auditing Magazine and has developed two highly successful videos, Day One in Internal Auditing and Modern Audit Tools and Techniques.

Frank W. Lyons, CISA, CNDE
Frank W. Lyons, CISA, is a consultant specializing in developing, managing, securing, and auditing large and small networked information systems. A recognized leader in the field, he has been involved in data security and database technology for nearly 21 years. As IS Audit Manager for Blue Shield and Sun Banks, Mr. Lyons designed a functional approach to IS auditing that he later used as Manager of Advanced Technology for the Institute of Internal Auditors. He has been with Cullinet Database Systems and a partner in the Plagman Group where he developed database auditing and data security seminars.

Derek Melber, MVP, MCSE 
Derek Melber is President and CTO of BrainCore.Net, LLC, an independent technology consulting and education firm specializing in Microsoft-centric solutions. One of only ten MVPs in the world on Group Policy, Mr. Melber is often called upon to develop end-to-end solutions regarding Active Directory, Group Policy and security. His expertise includes extensive knowledge of Group Policy and developing compliant desktops and the servers using them. In addition, he provides in-depth security audits for Windows domains and networks. Mr. Melber is also a nationally known trainer and author, focusing on Windows Server 2003/2008, Windows XP/Vista/7, Active Directory, Group Policy, and Windows security. Mr. Melber has written numerous books, including The Group Policy Resource Kit and Auditing Windows Security by the IIA. In addition, he is a contributing editor to WindowsSecurity.com, RIAG Journal, and other publications.

Dr. Hernan Murdock, CIA
Hernan Murdock is a Senior Consultant for MIS Training Institute. Before joining MIS he was the Director of Training at Control Solutions International where he oversaw the company’s training and employee development program. Prior to that, he was a Senior Project Manager leading audit and consulting projects for clients in the manufacturing, transportation, high tech, education, insurance and power generation industries. Dr. Murdock also worked at Northeastern University, Arthur Andersen, Liberty Mutual and KeyCorp and has completed projects in North America, Latin America, Europe and Asia. Dr. Murdock is a lecturer at Northeastern University where he teaches management, international business and ethics. He is the author of articles on whistleblowing programs, fraud, deception and behavioral profiling and has delivered numerous invited talks and conference presentations at internal audit, academic and government functions in the United States, Latin America and Europe.

William J. Nealon, CIA
William J. Nealon is an Adjunct Associate Professor of Management at the Graduate College of Union University, and an Adjunct Instructor at Rensselaer Polytechnic Institute’s Lally School of Management and Technology. A former Audit Manager for the New York State Comptroller’s Office, Mr. Nealon was responsible for identifying, planning, and overseeing financial, operational, and programmatic audits and studies in the Higher Education, Tax and Health areas of government. His experience includes audits of the State University of New York, the City University of New York, New York State Department of Taxation and Finance and the New York State Lottery. During his career, Mr. Nealon was also the Chief Auditor of Refunds for New York State. He has over 30 years experience in the auditing field, and is a member of the IIA and the Association of Certified Fraud Examiners.

Douglas E. Pickett, CPA, CISA, CFE, CISSP
Doug Pickett is the Principal Consultant for Pickett Consulting Services, where he applies his expertise to support information systems design, selection, and implementation; IT audits; fraud investigations; and management advisory and accounting services. He has helped clients achieve compliance with S-OX guidelines, perform general and application control reviews, evaluate information system adequacy. A much in demand trainer in the areas of accounting, information technology, fraud, auditing, and corporate governance frameworks such as S-OX and GLBA, Mr. Pickett is an adjunct professor of on-ground and on-line MBA-level finance and accounting courses for Webster University, Regis University, and Cardean University. Previously, Mr. Pickett was IT and Corporate Audit Senior Project Consultant for Blue Cross Blue Shield of Florida Inc. Prior to joining BCBS of Florida, he was an Internal Audit Manager with Jacksonville Electric Authority; Division Controller for Landstar Systems, Inc., and Mergers and Acquisitions Accounting Manager with First Union National Bank of Florida. Mr. Pickett is a member of the Florida Institute of CPAs, American Institute of CPAs, and the American Society of Training and Development.

Mark D. Rasch, Esq
.
Mark D. Rasch, Esq. is  the founder of SecurityITExpert, and a former US Department of Justice official. Previously, he was a Managing Director in the Technolgy Division of FTI Consulting, a computer forensics, economics, privacy, and security consulting firm. He was formerly the Senior Vice President and Chief Security Counsel for Solutionary, Inc. and the Vice President for cyberlaw for Predictive Systems, Inc., where he provided computer security consulting and implementation services to the US government, intelligence and law enforcement agencies, as well as commercial enterprises.  Mr. Rasch has written and lectured extensively on computer crime, privacy, trademark, and trade secret issues on the Internet, and has been featured in USA Today, The New York Times, NBC Nightly News, ABC’s Nightline, PBS’ Technopolitics, CNBC, and NPR as an expert on computer law and policy.  He is an adjunct faculty member of the Washington College of Law at the American University, where he teaches courses in white-collar crime.

Ronald D. Risner
Ron Risner is Founder and President of Risner Consulting Group, Inc., a professional audit and consulting services firm specializing in the construction industry.
Prior to beginning his construction consulting and audit services career, Mr. Risner was the Vice President and Auditor for Barnett Banks, Inc. Mr. Risner has been active in local professional organizations, including serving as past director for the Atlanta, Northeast Florida, and Central Florida Chapter of the IIA. He also served as Vice President of the Central Florida IIA chapter and as President of the Northeast chapter of the Bank Administration Institute. He has given construction-related presentations to both professional and private organizations and authored several construction-related articles for professional publications.

Fred  C. Roth, CISA
Fred C. Roth is Vice President of MIS Training Institute's IT Audit Division, where he is the primary developer of its IT Audit and Sarbanes-Oxley IT Audit curriculum. Mr. Roth has also provided extensive direction and training to organizations worldwide in planning and assessing IT risk areas for S-OX compliance. Previously, Mr. Roth spent more than 25 years in system development and information technology audit and security with Eastman Kodak Company. As Corporate Audit Project Manager, he had worldwide responsibility for planning and coordinating Kodak’s IS/IT audits in the United States, Asia, Europe and South America. Mr. Roth was a key player in Kodak’s successful worldwide SAP implementation, where he was responsible for the Corporate Audit partnership on the project and for assessing controls during system design and implementation. He is a frequent speaker at international conferences and does IT control and security training on a worldwide basis.

Thomas Salzman, CISA
Tom Salzman is IS Audit Manager for Illinois State University, where he manages all computer audits conducted by the University. Previously, Mr. Salzman was Director of Professional Services for the EDPAA (now ISACA), where he was responsible for establishing and supporting their worldwide network of educational programs, conferences, and special events. Prior to joining the EDPAA, Mr. Salzman was with Coopers & Lybrand, heading their Technical Training and Information Security practices. He has presented numerous CISA review courses, co-authored The EDPAA CISA Review Manual, and tracks providers of IS audit products and services worldwide for inclusion in an industry resource catalogue.

John Schela, CISSP, CAP
John Schela is a Project Manager with General Dynamics - Information Technology, where he supports the Veterans Administration as the VA Network and Security Operations Design and Architecture Group Manager.  He has more than 30 years of telecommunications, data automation, and information system security experience. He has an extensive industrial security background, is experienced in physical security analysis and design, and has a strong security certification and accreditation background. Previously, he functioned in several key program management positions, including Program Manager for consulting services provided to the Army Corps of Engineers, Department of Veterans Affairs, Department of Homeland Security, Library of Congress, GSA, US Coast Guard and the National Aeronautics and Space Administration, where he served as the NASA Certification Agent for all NASA moderate and high impact systems. Mr. Schela is a qualified Facility Security Officer and Information System Security Manager as defined by Defense Security Service. He holds a MSIAE from Capitol College, a NSA and Department of Homeland Security National Center of Academic Excellence in Information Assurance Education.

Phyllis Simon, CIA, CPA, CFE

Phyllis J. Simon, CIA, CPA, CFE, is CFO of SOS, where she is responsible for the daily management of financial operations.  Ms. Simon's more than 15 years of internal and external audit and management experience include positions as a Senior Internal Auditor with National Life Insurance, Audit Manager at KPMG Peat Marwick, and Auditor at Ernst & Young. Active in the IIA, Ms. Simon served as President, Vice President, and Newsletter Editor of the Green Mountain Chapter. She served three terms as Northeastern District Director. She is a member of the AICPA, VSCPA, and the ACFE.

Michael I. Sobol, CISA
Michael I. Sobol, CISA, is the Founder of MIS Training Institute and a recognized leader in the IS audit field. He was formerly IS Audit Manager for the North American Operations of The Gillette Company. While at Gillette he supervised and performed audits on data processing centers throughout North America, Europe, and South America. Mr. Sobol is a frequent speaker before national, regional, and international audit, security, and data processing organizations. He is a member of the Editorial Advisory Board of the Computer Fraud & Security Bulletin and a regular contributor to the Journal of Information Systems Security. Mr. Sobol has been the recipient of the Joseph J. Wasserman Award, for excellence in the fields of IS, Security, and Audit. Named one of the top pioneers in the field of IS audit by The IS Audit and Control Journal, Mr. Sobol was the recipient of ISACA's John W. Beveridge Award for outstanding contributions to the IS audit profession. He was recently honored with ISACA’s prestigious Harold Weiss Award for his efforts in advancing the IS audit profession.

Marilyn Stanton
Marilyn Stanton is a Consultant with Illuminated Consulting LLC, a leadership development consulting firm that partners with organizations pursuing strategic change and operational effectiveness.  Ms. Stanton’s 25 plus years of international and North American experience includes working with the United Arab Emirates Central Bank on management and infrastructure strengthening, implementing a systems-wide internal controls framework (COSO) at the US Federal Reserve Bank, and consulting to Fortune 500 firms in the manufacturing, retail, high-tech, and bio-tech sectors on strategic change initiatives such as S-OX implementation, private payments network installation, global supply chain redesign, off-shore outsourcing, drug commercialization process, and moving from a product to solutions strategy. Her firm also specializes in assessing and developing intercultural leadership competencies to reduce business risks associated with miscommunication and mistrust in critical international or domestic multicultural business relationships. Ms. Stanton has also been an instructor at the college and university level for 20 years where she taught various courses on organizational change and doing business globally.

Alan Sugano
Alan Sugano is President of ADS Consulting Group, Inc. Mr. Sugano’s areas of expertise include networking; server, workstation, and application virtualization; security; custom programming; Web development; SharePoint; and SQL server development. Previously, he was with Coopers & Lybrand (now PricewaterhouseCoopers) as an MAS consultant. Mr. Sugano speaks regularly on such topics as virtualization, network audit and security, troubleshooting, network design and implementation, server selection, network documentation and management, and disaster recovery. He is a Contributing Editor for Windows IT Pro and the author of the Real-World Network Troubleshooting Manual. He is a Microsoft Most Valuable Professional (MVP).

Glenn E. Sumners, CIA, DBA, CPA, CFE
Glenn E. Sumners is the Director of the Louisiana State University Center for Internal Auditing. Mr. Sumners has over ten years of professional experience in industry and public accounting, including three years as a Controller. He has authored two IIA monographs, as well as articles in IIA Today, Managerial Auditing Journal, Auditing: A Journal of Practice and Theory, Internal Auditing, Internal Auditor, and others. He serves on the Internal Auditor Editorial Advisory Board, and the editorial team of the International Journal of Auditing. Mr. Sumners is co-author of the textbook, Internal Auditing: Principles and Techniques. He received the LCPA Lifetime Achievement in Accounting Education Award in 1999.

Richard H. Tarr, CISA, CIA
Richard H. Tarr, CISA, CIA, is an audit and information systems consultant, specializing in quality assurance and training for all audit functions as well as disaster recovery planning and project management. A 28-year audit and information systems veteran, Mr. Tarr began his career with Electronic Data Systems Company. He served as Corporate EDP Audit Manager for the Walt Disney Company, and, after that, as Manager of Quality Assurance Review for the IIA. He authored the IIA's audit tool kit, Establishing an Internal Audit Function.

Leonard W. Vona, CPA, CFE
Leonard W. Vona is CEO of Fraud Auditing, Inc. He has more than 30 years of diversified auditing and forensic accounting experience, including a distinguished 18-year private industry career.  His firm advises clients in areas of litigation support, financial investigations, fraud prevention and income taxes. Mr. Vona has successfully conducted more than 100 financial investigations for some of the largest high-profile corporations in the United States. The net result of his efforts has saved clients millions of dollars through recovery or defense strategies. His financial investigation experience includes embezzlement, economic damage, asset theft, bribery, intellectual property, and various disbursement schemes. Mr. Vona’s trial experience is extensive, including appearances in federal and state courts.  He is qualified as an expert witness, and has been cited in West Law for the successful use of circumstantial evidence, and the author of Wiley Publishing's Fraud Risk Assessment: Building a Fraud Audit Program.

Scott Wright, CCP, CISSP, CISSR, CBCP
Scott Wright is a Senior Information Security Consultant with Computer Horizons Corp., where he is responsible for S-OX and HIPAA compliance, information security, policy development, contingency planning, and training programs. Previously, Mr. Wright was Senior Manager for the Education and Training division of Trident Data Systems. While there, he was responsible for security consulting services, training development, internal information security management, and contingency planning consulting. Mr. Wright  also served as Director of Technical Services for Advanced Information Management, where he consulted with the National Computer Security Center, and co-authored Trusted Distribution, one of the writings included in the nationally recognized Orange Book series on computer security.