Approaching Risk, Compliance and Security Through a Consistent Lens with Enterprise Training

Thomas Phelps
Author: ISACA Now
Date Published: 24 October 2024
Read Time: 2 minutes

Editor’s note:ISACA’s enterprise training and credentialing helps teams rise together, learning critical concepts in risk, security, and more, customized to the organization’s needs. Below, we visit with one of ISACA’s enterprise trainers, Thomas Phelps, Laserfiche CIO and SIM Research Institute Advisory Board, to explore his views on the value of group training. Find out more about ISACA’s enterprise training program here.

ISACA Now: What has your experience been so far with ISACA’s enterprise training program?

I've enjoyed being an instructor for ISACA's training programs. It's an opportunity to leverage my experience as a former USC adjunct professor teaching a master’s course on IT auditing and give back to the community. Many instructors like myself are passionate about helping organizations and people learn and grow. They are former partners at Big Four firms or industry leaders with deep experience in the subject matter. 

ISACA Now: What do you consider to be some of the most important benefits of training in a group setting?

There's tremendous value in taking ISACA training as a group. There's nothing better than to use training programs to bring teams together, collaborate, and learn about risk, compliance and security from a consistent lens.

ISACA Now: From your experience, what role do ISACA certifications play not only in improving individual certification-holders’ career prospects, but also for equipping those professionals to strengthen their organizations?

What you learn from ISACA certifications apply in all facets of your work, whether it's how to take appropriate risk based on your organization's risk appetite or making decisions about new initiatives while considering the cost of controls and compliance. It's either “pay me now, or pay me later,” and having a controls-focused mindset will help avoid costly pitfalls on major decisions.

ISACA Now: What are some ways that organizations can tailor ISACA training in a way that makes the most sense in the context of their business goals? 

ISACA excels in connecting the instructor with the organization prior to the training. Instructors have a keen interest in learning more about the organization, who are the learners, and what outcomes they want to achieve by taking the certification course. I took this approach for a major credit union that wanted their security and internal audit executives and team to take the course. I tailored the course based on what I heard and to make it relevant for an NCUA-regulated environment.

ISACA Now: Come budget season, what advice would you have for how to convince key decision-makers that they should prioritize training their teams? 

Think of the benefits with getting teams together, collaborating with each other, and taking actionable steps to apply the learning directly at work. It's a cost-effective way to create value for your organizations. 

About Thomas Phelps: Thomas Phelps IV is the CIO and SVP of Corporate Strategy for Laserfiche, the leading SaaS provider of document management and business process automation solutions. At Laserfiche, he leads Information Technology Services and the AI Governance Committee, along with several functions: GRC, Strategic Alliances, Business Transformation Office and Product & Customer Support. He has spearheaded strategic initiatives and technology innovation to transform the business, optimize costs, and enhance security and compliance. Under his leadership, Laserfiche was recognized as a visionary, leader and “Customers’ Choice” by industry analysts.

 

Additional resources