- 90
- 184 420
Mark Thomas
Приєднався 5 вер 2013
202502 NEO ISACA Promo
The ISACA Northeast Ohio chapter will be hosting a great event on February 20, 2025 in Cleveland. For more information, check out the Northeast Ohio Engage site, or comments on the Linked-In posts advertising the event.
Переглядів: 9
Відео
Risk Radar: Crafting KRIs that matter
Переглядів 95День тому
Key Risk Indicators (KRIs) are essential for effective risk management, but not all KRIs are created equal. In this video, I dive into my suggestions to crafting KRIs that truly matter. Learn how to identify, design, and implement KRIs that provide actionable insights and drive better decision-making for your organization. Whether you're new to risk management or looking to refine your approach...
Digital Trust Ownership - Who's Steering the Ship?
Переглядів 24Місяць тому
Who should lead, own, and manage digital trust in an organization? I get asked this question often. This vid should help you understand the key considerations and options you have to creating an organizational structure supporting digital trust. It can feel overwhelming to keep up with all the latest trends, as the stakes are higher than ever. A single misstep can damage trust, disrupt operatio...
2024 Escoute Year In Review
Переглядів 74Місяць тому
I've just finished up my last business trip of 2024 and counted up the flights, hotels, and weeks I was out during the year and put together this short vid to celebrate. Thank you all for making this year a great one, and I look forward to working with you all in 2025! -Mark
Aligning the CISO and the Board on Cybersecurity
Переглядів 78Місяць тому
Cybersecurity is a board-level priority, but aligning the CISO and the board can be challenging. In this short video, I’ll share key strategies to bridge the gap and foster effective communication. This is a preview of my full premium course available on my e-learning platform, where I dive deeper into the tools and techniques CISOs need to drive impactful board discussions. To be fully transpa...
The Intersection of Zero Trust and Digital Trust
Переглядів 742 місяці тому
In this video, I explore the intersection of Zero Trust and Digital Trust, breaking down how these two concepts complement each other to create a secure and resilient digital environment. Learn how implementing Zero Trust principles can enhance digital trust and why both are essential for modern cybersecurity strategies and enabling trust between digital providers and their consumers.
DTEF Digital Trust Relationship Mediums
Переглядів 863 місяці тому
Digital trust relationships rely on various mediums that facilitate secure interactions, ensuring privacy, security, and compliance without exposing sensitive data. These relationship mediums, or proxy technologies, play a critical role in building trust between stakeholders, such as providers, consumers, and peers. The ISACA Digital Trust Ecosystem Framework (DTEF) provides a comprehensive str...
DTEF - Digital Trust Relationships in the Digital Trust Ecosystem Framework Overview
Переглядів 1553 місяці тому
I you are familiar with the ISACA DTEF, you understand that in today's digital landscape, trust is everything. In this video, I explore why understanding digital trust relationships is critical to building and maintaining digital trust. From user confidence to secure interactions, these relationships are the foundation of a trusted digital environment. Join me as I dive into how fostering these...
Course promotion for "AI Governance Suggestions for Boards"
Переглядів 743 місяці тому
I just published a new premium course on my e-learning site, “AI Governance Suggestions for Boards.” This sneak peek features a few highlights from this course which breaks down essential strategies and best practices that every board member should know about governing AI. I'd love to have you join me at at e-learning.escoute.com. In full disclosure, premium accounts include a small monthly fee :)
ISACA Birmingham 2024 Fall Conference Promo
Переглядів 603 місяці тому
2024 Birmingham ISACA Fall Audit Conference Please join us for the 2024 Birmingham ISACA Fall Audit Conference where I will be presenting "A deep dive into ISACA’s Digital Trust Ecosystem Framework in an AI Environment". Sign-up information is on the Linked-In post.
COBIT Deep Dive BAI10 Managed Configuration Course Promo
Переглядів 1253 місяці тому
I just finished a project with a global client on configuration management so I put together my next COBIT "deep dive" course about BAI10 Managed Configuration as a premium course on my E-Learning site. Many of you are premium members, so you can watch the entire course. If you are not, enjoy this short compilation of the course, and I hope it convinces you to join our premium membership! Thank...
COBIT Deep Dive DSS03, Managed Problems (short version)
Переглядів 1346 місяців тому
Problem management is one of my favorite processes. Unfortunately, many organizations think they can simply 'copy and paste' from frameworks and somehow problem management will magically occur. Here is a short version of my longer course in my e-learning library on COBIT's guidance in DSS03, Managed Problems. There's enough info here to get you started, and hopefully get you some value. To be f...
Digital Trust Overview Hype or a Real Concern
Переглядів 1277 місяців тому
This is a short version of a longer course on my e-learning site. There's enough in this version to get some of my key points to Digital Trust, and learn a little more about the ISACA Digital Trust Ecosystem Framework, or DTEF. To watch the full course, sign up at e-learning.escoute.com. To be fully transparent, the site is a monthly subscription for the full courses. I hope you get some value ...
Digital Trust Hierarchy and Activities
Переглядів 2297 місяців тому
Since the launch of the ISACA Digital Trust Ecosystem Framework (DTEF), I've received a lot of questions about the relevance and usage of the hierarchy and activities section (what I call the pyramids). Here's a quick vid on how I see these adding value to your digital trust journey. I hope this helps! You can also see this and many others on e-learning.escoute.com/
COBIT BAI06 Managed Changes Deep Dive
Переглядів 2998 місяців тому
This is a short version of one of my latest COBIT deep dive videos. Every month, I'm posting a course on how to practically use COBIT in your enterprise on my e-learning site. To be fully transparent, this video is not the full course, which can be viewed by paid subscribers on my site. I hope this compilation of the course highlights helps you! If you are interested in this, or other COBIT and...
2024 Belgium ISACA Promo Creating a digital trust assurance program based on business risk scenarios
Переглядів 7710 місяців тому
2024 Belgium ISACA Promo Creating a digital trust assurance program based on business risk scenarios
ISACA NE Ohio Digital Trust Promo 18 Jan 2024
Переглядів 92Рік тому
ISACA NE Ohio Digital Trust Promo 18 Jan 2024
202312 ISACA Lagos GRC Conference Promo
Переглядів 147Рік тому
202312 ISACA Lagos GRC Conference Promo
IIA Data Privacy Forum - MThomas presentation highlights 20231012
Переглядів 91Рік тому
IIA Data Privacy Forum - MThomas presentation highlights 20231012
Hartford ISACA Digital Trust Event 8 Dec 2023
Переглядів 135Рік тому
Hartford ISACA Digital Trust Event 8 Dec 2023
Digital Trust Overview Hype or a Real Concern
Переглядів 286Рік тому
Digital Trust Overview Hype or a Real Concern
20230307 Birmingham ISACA Event Promotion
Переглядів 134Рік тому
20230307 Birmingham ISACA Event Promotion
Not clear - your slides faded
Thanks, I'll check this out.
Thank you for this information, I have experience serving on different boards currently transitioning towards IT governance getting my certification.
Great to hear this - best of luck with your cert. Are you going for the CGEIT cert?
Hope you have a greater 2025
Lovely Mark....
just checked the official website, and found the NACD handbook was published back in 2023-03, looks like it is not updated annually ?
Ya, from what I can tell, they update it every few years. You are correct, the one on their site is the latest. I believe they update this when there are some significant changes to the guidance. Thanks!
Thanks for sharing such valuable information! I have a quick question: My OKX wallet holds some USDT, and I have the seed phrase. (alarm fetch churn bridge exercise tape speak race clerk couch crater letter). Could you explain how to move them to Binance?
Thank you so much for the information.
Finally a video I don’t have to try and understand through a thick accent.
Really good explanation. Thank you for your effort. Is there a way to get the template of the mapping matrices? Thanks!
Thanks! The only way I'm aware of is to get the COBIT Governance and Management Objectives guide. The mapping tables are Appendix A. Here's the link to the ISACA site where you can find it. Good luck! www.isaca.org/resources/cobit#2
@@MarkThomasGRC Found it! Thank you so much!
Interesting topic
Great thoughts there
Hey, Mark thanks you for your explanation, so I need to make a question in step 4 we have a colun to adjust +100 or -100 it's necessary adjust them?
Yes. You can adjust this to your needs. I've had situations where clients demand a higher priority on some of the objectives. There is no guidance on exactly what number to use (+100 or -100), but you can play around with the outcomes to gain a satisfactory management consensus. I hope this helps!
@@MarkThomasGRC Thank you for your attention, it help me for sure!!
Great stuff
Thank you!
Mark the animation is really cool! What would you say about Google's SREs - how would SRE fit into the 3 LoD model? Can't quite figure if SRE architects or teams fit in 1st/2nd LoD. They're directly doing the ops work while ensuring resilience & monitor controls (1st LoD) but also they de-facto shape the risk policies & standards + generate the metrics for reporting and compliance (2nd-ish LoD).
Thanks for your comment and sorry for the late reply. Good question. Assuming you are referring to site reliability engineering, my first instinct is 1st line. Of course this widely depends on the organization and how SRE is positioned.
Excelente Mark. Muchas gracias por compartir!
How will be the graph for double materiality assessment? Is there any difference?
Hi Mark, thank you for this lecture. Please, do you have any information to explain us how dfXmap sheets values were set in the design toolkit ?
Good question. Check out the COBIT "Design Guide" if you haven't already. The publication outlines the mapping tables for each of the design factors. store.isaca.org/s/store#/store/browse/detail/a2S4w000004Ko9bEAC
Very informative Mark , much appreciated
Glad it was helpful!
very helpful. thank you
Wow this is genuinely such a good explanation of the relationship between the three lines, as well as the other relevant bodies. Very helpful for my final :)
Thank you for making a concise, effective and clear video. Much appreciated
Thanks 💖
Congratulations on a fruitful 2023. Have an awesome 2024!
Thank you very much, and the same to you!
Hello, excuse me, if I buy the book "CRIC Review Questions, Answers & Explanations Manual, 6th Edition" is a good book to pass this exam?, this book contain some questions equal that the exam or contain similar question only, ? or what book you suggest, thanks so much in advance.
I'm glad you asked! Don't use the 6th Edition - get the 7th Edition. There was a lot of information updated in this, and the exam is based on the 7th Edition. Also, I definitely suggest getting a subscription to the online Q/A database. One other area that you might find helpful is in the ISACA Engage site. There are exam prep forums where questions and answers are discussed. Good luck!
Thank you for producing this
Quick Question >>Where does the IT Auditor sit in this Model? 2nd OR 3rd Line?
Third line.
Hi Mark, assist me with the PDF document
Hi Joe. As I mentioned in the video, the pdf's are only available on the premium course site at e-learning site elearning.escoute.com/ The premium subscription is about $20/month. Thanks!
The domain percentages sum up to 110%. Domain 4 should be 22% in stead of 32%.
You are too kind, thank you for the correction.
Hey there, may I ask, hope you notice this question. So, to the point of my question: Do we HAVE to do the Design Factor first before we assess a company IT Governance with CPM method COBIT 2019? thanks in advance
You certainly don't have to!
Looking forward to it
"Promo SM"
Incredible marketing from the King of COBIT. Thank you Mark, you always leave me wanting more :)
Haha you are too kind @Jaynie - thank you!
Would you mind throwing some information on me regarding COBIT? I am TOGAF certified, will COBIT be add-on to it? I am from software Dev background and currently working as Technical/Solution Architect and exposure to Enterprise Architecture.
@@matthayden1979 Check out some of the COBIT vids I have here on UA-cam. If you have a Linked-In learning account, there is also a short course here: nam06.safelinks.protection.outlook.com/?url=https%3A%2F%2Fwww.linkedin.com%2Flearning%2Flearning-cobit&data=02%7C01%7Cbianderson%40linkedin.com%7C3e1118977e6849f9743308d83b010ce9%7C72f988bf86f141af91ab2d7cd011db47%7C1%7C0%7C637324222980052116&sdata=yJjAJgJo8%2FN4dTjhuWpsZGEhzX7KJRrjKMtJTayRFd0%3D&reserved=0
Thank you, Thomas.
Como se adquiere el excel
Nice animations Mark 👍🏻
Thanks 😁
The baseline in each design factor i should change or it’s built from tool ?
Thankyou Mark,,, Can you help to give a link where I can find that excel for info specific relevant Nist to cobit 2019? because i only have with reference cobit 5..will be appreciated for your answer and thank you
I didn't found this sheet on isaca website please can anyone to share the link
Its a must-attend event
really awesome explanation!
My CGEIT exam is in 2 weeks and your Tips really helped me to get the final phase of my preparation going and to focus on the exam! THANK YOU for your efforts!
Thanks Karl and best of luck on the exam! I look forward to having you on the CGEIT team!
Hi Karl , Can you share with me the preparation material ?
@@salmanabdulaziz7552 sorry no, the ISACA exam pre-testing is just online no downloads and even my access expired last week (only valid 12 for months). The preparation material is also online only and has 450 pages to read, the download for offline usage is encrypted and cannot be sent. ISACA is very much aware about piracy and the costs for the material is their business case...
@@karlpetermichl2700 Thanks for quick feedback. What exactly to study? Can you share the link
This was great, thanks for putting it together :)
Hi, can I use you're material for internal training presentation?
If it's internal only, yes. All I ask is that you reference "Mark Thomas, Escoute LLC" in your presentation. Thank you for asking :)
Thank you Sir Mark, you're video is really good and informative, thank you so much
Well put together and explained. Thanks
Is it possible to get the presentation slides?
Nice video, mind covering all the principles aligning with ESG
ᎮᏒᎧᎷᎧᏕᎷ 😴
Is there a way to access the full course?
Hi Yusuf. Thanks for asking. This is part of my full e-learning catalog at elearning.escoute.com/ I hope to see you there!
Hi Mark Can i have excel file for cobit? I can't download it
You have to get that from the ISACA site here: store.isaca.org/s/store#/store/browse/detail/a2S4w000004Ko9bEAC You can find it in the toolkit download. Good luck!
Really appreciate the short and concise walk through. I’m likin it.