Gustavo Santana Executive Director Ernst & Young

Duration: 10 hours June 22 4:00 am - 6:00 pm June 23 8:00 am - 6:00 pm

Gustavo Santana Torrellas is Senior Manager of Financial Sector Consulting area and is responsible for the commercial development of commercial clients and development banks also for the Infrastructure and Security areas. Gustavo has worked with PwC since 2012 and participated in projects of IT Strategy, Development of models and solutions for Information Management and Security strategies Evaluation with emphasis on compliance with standards such as PCI and ISO27000. He has extensive experience in project management of Technology Innovation and Integration, for IT Network Security, particularly in the analysis and design of Security Schemes, methodological and practical specifications to implement Security Schemes, Policies and Mechanisms. Prior to join PwC, he developed technology consultancy activities in Accenture, from 2008 to 2012, previously worked as a Senior Researcher in the Mexican Petroleum Institute dedicated to the optimization of drilling oil (2002 - 2008), he was coordinator of research and systems development at INAP (1999-2002), was coordinator of the learning unit and distance education from the IPN (1997-1999). He has published over 120 research papers in international journals and conferences in the areas of Security, Information Systems, Mathematical Methods and Administration. Gustavo Santana has a BS in Mathematics and Computer Engineering from the Simon Bolivar University in Caracas, Venezuela. He received the degree of Master of Science in Mathematics from the State University of Odessa, Ukraine, and have a PhD in Mathematics and PhD in Telecommu nications Engineering from the Bonch Bruevich Institute in St. Petersburg, Russian Federation. He also had studied the MBA program from the College of Business and Management of IPN.

Course Description The operational risk passes through the management and lines of business, and by doing so, permeate the organizational units, the operational responsibilities and the different decision levels. As long as the risk perspective goes changing, the threats are becoming more sophisticated. Therefore, it would be an error to believe that they could be avoided, that is why, in the risk management those elements that allow the organizations to recover from incidents or situations of potential operational disruptions should be considered, at the same time, its sporadic and irregular nature, means that the mechanisms of response and recovery must conform a simple process. This new approach could be label as Continuity Management and Resilience of the Business and it could be defined as the great capacity of an organization to resist being affected by an incident. It takes into account the capacity to respond to an incident as soon as it has occurred, the personnel and environment protection, and allows the services continuity. Essentially, these two flows, the continuity and the crisis management, must work together to ensure the minimum impact to the services and operations. During the course, the speaker will share his more that 20 years of experience in finding a way to a more cohesive environment to reduce the uncertainty and promote a more stable operating environment. At the completion of the course, all participants will understand the concepts of Operational Risk and its relation with the elements of Business Continuity management.

Program: 1. Introduction to ERM. 2. Operational Risk Management under and after Basel 2. a. Risk Culture. b. Operational Risk Appetite – ORA. 3. Operational Risk Management Implementation Framework. 4. Risk Management Environment. a.Risk and Control Self Assessment – RCSA. b.Key Risk Performance & Control Indicators. 5. Risk Based Process Management. 6. Risk Measurement & Analysis. 7. Business Continuity Management - BCM. 8. Fundamentals. 9. BCP/Risk Management/Governance Structure. 10. BCP Scenario/Risk Based Analysis. 11. Crisis Management Structure. 12. Final Remarks.

