<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: PDI Immersive Course in Governance, Risk, Compliance</title>
    <link>https://community.isc2.org/t5/Governance-Risk-Compliance/PDI-Immersive-Course/m-p/42556#M260</link>
    <description>&lt;P&gt;&lt;a href="https://community.isc2.org/t5/user/viewprofilepage/user-id/887781263"&gt;@AppDefects&lt;/a&gt;&amp;nbsp;Thank you for your recommendation and kind words.&amp;nbsp; As you observed, Chris did a better job of portraying me than I do portraying me - maybe I should hire him to portray me at my next client and see how that goes &lt;span class="lia-unicode-emoji" title=":slightly_smiling_face:"&gt;🙂&lt;/span&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;I wrote the script from several years of notes - and in a few cases, recordings - when organizations hired me to do essentially what you saw in the course.&amp;nbsp; The difference, and difficulty, was in deciding what to leave out.&amp;nbsp; Normally I'm with a client for a few weeks, a few months, or in rare cases, for a few years.&amp;nbsp; It depends on what they &lt;EM&gt;think&lt;/EM&gt; their problems are, what their problems &lt;EM&gt;really&lt;/EM&gt; are, and &lt;EM&gt;how committed&lt;/EM&gt; they are to finding fixes that are more than short-term bandages.&amp;nbsp; Trying to condense that down to just a few hours was tough and gave me a few more gray hairs.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;The simplicity of creating this fictional company was that I could staff it with intelligent, dedicated employees that truly wanted to learn and take responsibility for the problems in their organization.&amp;nbsp; If I had clients like that in the real world I could just point them to this course and call it a day.&amp;nbsp; Of course, then I'd be unemployed a lot... &lt;span class="lia-unicode-emoji" title=":slightly_smiling_face:"&gt;🙂&lt;/span&gt;&lt;/P&gt;</description>
    <pubDate>Fri, 15 Jan 2021 22:51:40 GMT</pubDate>
    <dc:creator>CyberLead</dc:creator>
    <dc:date>2021-01-15T22:51:40Z</dc:date>
    <item>
      <title>PDI Immersive Course</title>
      <link>https://community.isc2.org/t5/Governance-Risk-Compliance/PDI-Immersive-Course/m-p/42527#M256</link>
      <description>&lt;P&gt;Shameless self-promotion time.&amp;nbsp; If you're interested in learning how to identify, assess, and respond to risks in a straightforward and practical manner, consider the newest PDI fully immersive course, &lt;A title="Conducting Practical Risk Analysis for Security Professionals" href="https://enroll.isc2.org/product?catalog=ISC2-PDI-COND-PRACT-RISK-ANALYSIS-PUB" target="_blank" rel="noopener"&gt;&lt;EM&gt;Conducting Practical Risk Analysis for Security Professionals&lt;/EM&gt;&lt;/A&gt;, authored by yours truly.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;As with other PDI courses they are free to members and with mine you can earn 4 CPEs.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;As a consultant, my phone rings when people need to solve complex multi-dimensional problems; problems that they weren't able or willing to solve themselves.&amp;nbsp; Regardless of where they think these problems stem from, my investigations usually find causes and contributing factors that go well beyond the realm of security.&amp;nbsp; I apply my early background from my military service and my years as a cop, with my last few decades in business and technology as a Lean Six Sigma Black Belt, Public Service Technologist, and Industry Thought Leader.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;With that said, I'm a bit dense when it comes to understanding my own problems. After ignoring the warning signs for years I spent a week in a local hospital learning I had a heart attack and walking out with 3 new titanium stents in my coronary arteries as souvenirs.&amp;nbsp; It's been a slow and painful rehab and recovery, but one other message got through. It was time to accept that I have more yesterdays than tomorrows; it was time to share what I know.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;When the PDI approached me about creating course material I saw it as an opportunity to do just that and do so in a format whereby you, as the learner, become part of a fictional company's leadership team.&amp;nbsp; You'll join their meetings, read emails, make choices, and learn with them as a consultant guides and gently teaches them how to better protect their people, their customers, and their business.&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;However, I couldn't do it alone. Maci Devaney and Ty Crawford worked with me every step of the way.&amp;nbsp; (Actually, they held my hand for quite a few steps.). Their professionalism, attention to detail, and incredible skills made this a polished and high caliber production.&amp;nbsp; The actors enabled a sense of realism that a standard course would never emulate.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;It was a bit weird during the studio recording sessions as I watched a professional actor, Chris Hurt, portray me as the consultant.&amp;nbsp; I wrote the scripts (a first for me) based on what I've actually said to my clients in countless meetings over the years.&amp;nbsp; However, watching Chris in the studio as he spoke my words and perfectly captured the way I talk with my hands, my facial expressions, and the inflections in my voice, was unlike anything I ever experienced.&amp;nbsp; Now, no one will ever confuse the two of us - I know this because my wife leaned over during the first recording session and whispered to me that she loves me, but Chris is a "younger and better looking version" of me!&amp;nbsp; In all honesty, I have to agree, besides the fact that the consultant's name in the script isn't "Lloyd Diernisse," (it's "Steve Romano").&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Kindly check it out and provide feedback, positive or negative.&amp;nbsp; I created the course for you and I just verbally committed to create others (haven't signed the contract yet, but we're going ahead with it as soon as the paperwork is sorted out).&amp;nbsp; Therefore, I need to know what you think - it's the only way I can improve. &lt;span class="lia-unicode-emoji" title=":slightly_smiling_face:"&gt;🙂&lt;/span&gt;&lt;/P&gt;</description>
      <pubDate>Mon, 09 Oct 2023 09:46:12 GMT</pubDate>
      <guid>https://community.isc2.org/t5/Governance-Risk-Compliance/PDI-Immersive-Course/m-p/42527#M256</guid>
      <dc:creator>CyberLead</dc:creator>
      <dc:date>2023-10-09T09:46:12Z</dc:date>
    </item>
    <item>
      <title>Re: PDI Immersive Course</title>
      <link>https://community.isc2.org/t5/Governance-Risk-Compliance/PDI-Immersive-Course/m-p/42539#M257</link>
      <description>&lt;P&gt;I really enjoyed your course and have nothing but praise to say about it. I definitely learned some new terms and topics, i.e., Black and White Swan events. I really liked the aspect of being entrenched within the team as they work their way through the scenario. I think this set a pretty high bar going forward for the other course content creators.&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Any future classes that dive deeper into risk, e.g., third-party risk management? I also see a BCP course as an easy win if you have that as expertise as well.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Thanks for the brief behind the scenes look and acknowledging the people involved to help make this course a success.&lt;/P&gt;</description>
      <pubDate>Fri, 15 Jan 2021 14:35:12 GMT</pubDate>
      <guid>https://community.isc2.org/t5/Governance-Risk-Compliance/PDI-Immersive-Course/m-p/42539#M257</guid>
      <dc:creator>tmekelburg1</dc:creator>
      <dc:date>2021-01-15T14:35:12Z</dc:date>
    </item>
    <item>
      <title>Re: PDI Immersive Course</title>
      <link>https://community.isc2.org/t5/Governance-Risk-Compliance/PDI-Immersive-Course/m-p/42545#M258</link>
      <description>&lt;P&gt;Highly recommended course! Chris is simply amazing as the consultant!&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Fri, 15 Jan 2021 18:30:48 GMT</pubDate>
      <guid>https://community.isc2.org/t5/Governance-Risk-Compliance/PDI-Immersive-Course/m-p/42545#M258</guid>
      <dc:creator>AppDefects</dc:creator>
      <dc:date>2021-01-15T18:30:48Z</dc:date>
    </item>
    <item>
      <title>Re: PDI Immersive Course</title>
      <link>https://community.isc2.org/t5/Governance-Risk-Compliance/PDI-Immersive-Course/m-p/42556#M260</link>
      <description>&lt;P&gt;&lt;a href="https://community.isc2.org/t5/user/viewprofilepage/user-id/887781263"&gt;@AppDefects&lt;/a&gt;&amp;nbsp;Thank you for your recommendation and kind words.&amp;nbsp; As you observed, Chris did a better job of portraying me than I do portraying me - maybe I should hire him to portray me at my next client and see how that goes &lt;span class="lia-unicode-emoji" title=":slightly_smiling_face:"&gt;🙂&lt;/span&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;I wrote the script from several years of notes - and in a few cases, recordings - when organizations hired me to do essentially what you saw in the course.&amp;nbsp; The difference, and difficulty, was in deciding what to leave out.&amp;nbsp; Normally I'm with a client for a few weeks, a few months, or in rare cases, for a few years.&amp;nbsp; It depends on what they &lt;EM&gt;think&lt;/EM&gt; their problems are, what their problems &lt;EM&gt;really&lt;/EM&gt; are, and &lt;EM&gt;how committed&lt;/EM&gt; they are to finding fixes that are more than short-term bandages.&amp;nbsp; Trying to condense that down to just a few hours was tough and gave me a few more gray hairs.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;The simplicity of creating this fictional company was that I could staff it with intelligent, dedicated employees that truly wanted to learn and take responsibility for the problems in their organization.&amp;nbsp; If I had clients like that in the real world I could just point them to this course and call it a day.&amp;nbsp; Of course, then I'd be unemployed a lot... &lt;span class="lia-unicode-emoji" title=":slightly_smiling_face:"&gt;🙂&lt;/span&gt;&lt;/P&gt;</description>
      <pubDate>Fri, 15 Jan 2021 22:51:40 GMT</pubDate>
      <guid>https://community.isc2.org/t5/Governance-Risk-Compliance/PDI-Immersive-Course/m-p/42556#M260</guid>
      <dc:creator>CyberLead</dc:creator>
      <dc:date>2021-01-15T22:51:40Z</dc:date>
    </item>
    <item>
      <title>Re: PDI Immersive Course</title>
      <link>https://community.isc2.org/t5/Governance-Risk-Compliance/PDI-Immersive-Course/m-p/42572#M261</link>
      <description>&lt;P&gt;&lt;a href="https://community.isc2.org/t5/user/viewprofilepage/user-id/690706113"&gt;@tmekelburg1&lt;/a&gt;, Thank you for your kind words, and letting me know how you enjoyed my course. &amp;nbsp;My objective in sharing my experience in writing the course - and naming Maci and Ty - was two-fold. &amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;First, I believe that they are often the unsung heroes that make these courses not just possible, but very high-caliber and high quality productions. &amp;nbsp;As you saw, there was a page for me as the author to provide my background, but no similar pages for the employees of the PDI who made my script a performance. &amp;nbsp;Nor was there a place to credit the actors. &amp;nbsp;I asked for this and was informed that there is a policy proscribing it. &amp;nbsp;I am not a full time employee of the PDI or (ISC)2, I work under a contract as a Subject Matter Expert (SME) so my input on policies and procedures is not that of an employee, rather it as a member, like you.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Second, I wanted to share that while the character of Steve Romano is a pretty accurate portrayal of me and the type of work I do, I want to emphasize that the setting and characters, like the plot, are fiction. &amp;nbsp;The next time my phone rings I do not want the company that hires me expecting Steve Romano to show up at their door. Although, as I noted in another comment, that might work out better&amp;nbsp;&lt;span class="lia-unicode-emoji" title=":slightly_smiling_face:"&gt;🙂&lt;/span&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;As for future courses, I can say I am continuing to work for the PDI but a confidentially agreement prevents me from discussing what’s in the pipeline. &amp;nbsp;If you look at my Linked-In profile, you'll see my experience is broad and deep.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;One thing I can announce is my appearance as a panelist in a webinar for (ISC)2 on the topic of Extended Detection and Response (XDR). &amp;nbsp;&lt;A href="https://www.brighttalk.com/webcast/14671/462211/doing-xdr-right-what-it-is-and-what-it-can-do-for-your-organization" target="_blank" rel="noopener"&gt;Doing XDR Right: What It Is and What It Can Do For Your Organization.&lt;/A&gt;&lt;SPAN&gt;&amp;nbsp;Like other (ISC)2 Webinars on the BrighTalk platform, you’ll need a BrightTalk account. &amp;nbsp;They are free and easy to create. &amp;nbsp;It’s scheduled for a live broadcast on Thursday, January 28, 2021 at 1:00 PM (ET). &amp;nbsp;If you’re interested and cannot make the live broadcast, it’ll be recorded.&lt;/SPAN&gt;&lt;/P&gt;</description>
      <pubDate>Sat, 16 Jan 2021 23:31:48 GMT</pubDate>
      <guid>https://community.isc2.org/t5/Governance-Risk-Compliance/PDI-Immersive-Course/m-p/42572#M261</guid>
      <dc:creator>CyberLead</dc:creator>
      <dc:date>2021-01-16T23:31:48Z</dc:date>
    </item>
  </channel>
</rss>

