Zum Inhalt springen
PodcastsNachrichtenISACA Podcast

ISACA Podcast

ISACA Podcast
ISACA Podcast
Neueste Episode

112 Episoden

  • ISACA Podcast

    Your Containers Are Probably Full of Holes: Fixing Docker Security with AI

    21.07.2026 | 28 Min.
    Containers run much of the software we depend on, and many are shipped with security problems that no one noticed. Traditional container scanning tools can miss important vulnerabilities, insecure configurations, embedded secrets, and risky Dockerfile patterns before they reach production.

    In this episode, ISACA’s Adedayo Ojo, Principal, Emerging Technologies and Professional Practices, Research Development, speaks with Advait Patel, Senior Site Reliability Engineer at Broadcom, Docker Captain, and Google Developer Expert in Google Cloud, about why traditional container scanning misses so much and what it takes to identify the issues that matter most.

    Advait shares lessons from running containers at scale on a large cloud platform and explains how he built DockSec, an open-source tool that uses AI to identify insecure Dockerfile patterns, embedded secrets, and misconfigurations that signature-based scanners tend to overlook. The conversation offers practical guidance that developers and security teams can apply immediately, along with an honest look at where AI can strengthen container security—and where it cannot.

    Related Resources & Stay Connected

    Explore DockSec on GitHub: Review the open-source DockSec project, explore its features, and learn how it uses AI to identify insecure Dockerfile patterns, embedded secrets, and container misconfigurations.
    https://github.com/OWASP/DockSec

    Learn More About DockSec from OWASP: Discover more about the DockSec project, its approach to container security, and how it helps developers identify risks that traditional signature-based scanners may miss.
    https://owasp.org/DockSec/

    Connect with Advait Patel on LinkedIn: Follow Advait for insights on container security, cloud infrastructure, site reliability engineering, Docker, and AI-powered security.
    https://www.linkedin.com/in/advaitpatel93/

    Explore Advait Patel’s GitHub: View Advait’s open-source projects, technical work, and contributions to cloud and container security.
    https://github.com/advaitpatel

    Explore More ISACA Podcast Episodes: Dive deeper into cybersecurity, governance, risk, privacy, and emerging technology insights.
    https://www.isaca.org/resources/news-and-trends/isaca-podcast-library

    Subscribe to ISACA on YouTube: Stay ahead with expert interviews, industry analysis, and cybersecurity leadership insights.
    https://www.youtube.com/@IsacaHq

    Don’t forget to like, comment, and subscribe for more conversations shaping the future of IT, cybersecurity, governance, risk, and emerging technology.
  • ISACA Podcast

    Modern Approach to Identity Security

    14.07.2026 | 30 Min.
    As threats have evolved, so too has the approach to modern identity security. A privilege-centric approach must be adopted to address this evolution. Identity management for all accounts within an organization must mature to meet the demands of the cloud, nonhuman identities (NHIs), agentic AI, and modern attack vectors. Your strategy must now manage and mitigate not only traditional privileged access (root and administrator accounts), but also attacks targeting modern identities with paths to privileged access.

    These paths to privilege remain one of the most valuable targets for cybercriminals because many organizations continue to defend their environments with fragmented or siloed security strategies and solutions. Security gaps and risks exist across endpoints, cloud environments, SaaS applications, third-party access, and now agentic AI and NHIs, making today's threat landscape more complex than ever.

    In this episode, ISACA's Donnie Carpenter, Principal, Information Security and Professional Practices Research Development, speaks with Christopher Hills, Chief Security Strategist at BeyondTrust, about the evolution of identity security and why organizations must rethink how they protect privileged access in today's rapidly changing technology landscape.

    Related Resources & Stay Connected
    Learn more about BeyondTrust: Discover how BeyondTrust helps organizations protect identities, manage privileged access, and reduce cyber risk across cloud, endpoint, SaaS, and hybrid environments.
    BeyondTrust

    Additional Resources from BeyondTrust:

    Shadow AI Governance: How to Detect Shadow AI Governance

    Microsoft Vulnerability Report: Microsoft Vulnerability Report

    Explore More ISACA Podcast Episodes: Dive deeper into cybersecurity, governance, risk, and emerging technology insights.
    ISACA Podcast Library

    Subscribe to ISACA on YouTube: Stay ahead with expert interviews, industry analysis, and cybersecurity leadership insights.
    ISACA YouTube Channel

    Don't forget to like, comment, and subscribe for more conversations shaping the future of IT, cybersecurity, governance, and risk.
  • ISACA Podcast

    ISACA Podcast: Why You Should Use the F Word More

    30.06.2026 | 23 Min.
    FedRAMP 20x is redefining what federal compliance looks like. Designed to modernize the authorization process, this bold initiative is moving cybersecurity governance toward automation while reducing the lengthy timelines and documentation burdens that have traditionally defined FedRAMP.

    Join host Safia Kazi as she speaks with Jake Bernardes, CISO at Anecdotes, about what FedRAMP 20x is, why it matters, and how this transformation will reshape governance, risk, and compliance (GRC) automation. Together, they explore what organizations can expect as federal compliance evolves and what the changes mean for enterprise customers navigating the future of cybersecurity governance.

    Related Resources & Stay Connected

    Learn more about Anecdotes: Discover how Anecdotes is helping organizations transform governance, risk, and compliance with AI-powered automation, continuous monitoring, and audit-grade data that enables faster, smarter, and more scalable GRC programs. https://www.anecdotes.ai/ 

    Explore More ISACA Podcast Episodes: Dive deeper into cybersecurity, governance, risk, and emerging tech insights. https://www.isaca.org/resources/news-and-trends/isaca-podcast-library

    Subscribe to ISACA on YouTube: Stay ahead with expert interviews, industry analysis, and cybersecurity leadership insights. https://www.youtube.com/@IsacaHq

    Don’t forget to like, comment, and subscribe for more conversations shaping the future of IT and cybersecurity.
  • ISACA Podcast

    The Future of IT Audit: Key Changes in ITAF 5

    28.05.2026 | 29 Min.
    Technology is transforming how organizations operate — and IT audit and assurance must evolve alongside it. In this episode, Paul Phillips sits down with Mary Carmichael, contributor to the newly updated IT Audit and Assurance Framework (ITAF 5), to discuss how audit professionals can adapt to today’s increasingly complex digital enterprise.

     

    Together, they explore the major shifts shaping modern audit, including AI governance, digital ecosystems, automation, evolving risk landscapes, cloud environments, and the growing need for stronger data literacy within audit teams. Mary also shares practical guidance on how organizations can begin modernizing their audit approach without overhauling everything overnight.

     

    Key discussion topics include:

    The evolution from traditional control testing to outcome-based assurance

    Why audit teams need stronger technology and data capabilities

    AI governance, automation, and digital risk considerations

    Building practical audit modernization strategies

    How ITAF 5 supports governance, credibility, and audit relevance in modern enterprises

     

    Whether you're an auditor, governance professional, cybersecurity leader, or risk practitioner, this conversation provides valuable insight into the future of audit and assurance in a technology-driven world.

     

    Related Resources & Stay Connected

    Download ITAF 5: https://www.isaca.org/resources/itaf-is-a-framework

     

    Explore More ISACA Podcast Episodes: Dive deeper into cybersecurity, governance, risk, and emerging tech insights. https://www.isaca.org/resources/news-and-trends/isaca-podcast-library

     

    ▶️Subscribe to ISACA on YouTube: Stay ahead with expert interviews, industry analysis, and cybersecurity leadership insights. https://www.youtube.com/@IsacaHq

     

    🔔 Don’t forget to like, comment, and subscribe for more conversations shaping the future of IT audit, governance, risk, and cybersecurity.

     

    #ITAudit #ITAF5 #AuditAndAssurance #Cybersecurity #Governance #RiskManagement #AI #ISACA #DigitalTransformation #InternalAudit
  • ISACA Podcast

    ​​Breaking the Compliance Mentality​

    21.05.2026 | 23 Min.
    In today’s evolving cybersecurity landscape, strong leadership is the foundation of an effective security posture. Yet many agencies struggle when a “compliance mentality” takes hold, where meeting minimum requirements overshadows proactive risk management.

    In this ISACA Podcast episode, Lisa Cook, ISACA's Principal Research Analyst, sits down with Patrick Bevill, Chief Information Security Officer (CISO) at the Federal Retirement Thrift Investment Board, to explore how agency leaders can establish a strong tone at the top and foster a culture that prioritizes security resilience over check-the-box compliance.​

    Related Resources & Stay Connected

    Learn more about Williams Adley: Discover how Williams Adley helps organizations navigate audit, assurance, cybersecurity, risk, and advisory services with a focus on integrity and innovation. https://www.williamsadley.com/

    Explore More ISACA Podcast Episodes: Dive deeper into cybersecurity, governance, risk, and emerging tech insights. https://www.isaca.org/resources/news-and-trends/isaca-podcast-library 

    Subscribe to ISACA on YouTube: Stay ahead with expert interviews, industry analysis, and cybersecurity leadership insights. https://www.youtube.com/@IsacaHq 

     

    Don’t forget to like, comment, and subscribe for more conversations shaping the future of IT and cybersecurity.
Weitere Nachrichten Podcasts
Über ISACA Podcast
The ISACA Podcast gives you insight into the latest regulations, trends and threats experienced by information systems auditors and governance and security professionals. Whether you are beginning your career or have decades of experience, the ISACA Podcast can help you be better equipped to address industry challenges and embrace opportunities.
Podcast-Website

Höre ISACA Podcast, Lanz + Precht und viele andere Podcasts aus aller Welt mit der radio.de-App

Hol dir die kostenlose radio.de App

  • Sender und Podcasts favorisieren
  • Streamen via Wifi oder Bluetooth
  • Unterstützt Carplay & Android Auto
  • viele weitere App Funktionen
Rechtliches
Social
v8.11.9 | © 2007-2026 radio.de GmbH
Generated: 7/26/2026 - 12:42:59 AM