ISACA Kampala Chapter
Welcome to the ISACA Kampala Chapter
Our Vision: "Trust in, and Value from Information systems"
ISACA ( Information Systems Audit and Controls Association) is a world wide association of IS governance professionals. The association currently focuses on assurance, security, and governance and provides globally recognised certification in assurance (Certified Information Systems Auditor"CISA"), security (Certified Information Security Manager "CISM"), and governance (Certified in the Governan
08/06/2026
⚠️ A privacy incident and a security incident can overlap — but they are not the same thing, and they should not trigger the exact same response.
A security incident focuses on the compromise of systems, networks, or controls.
A privacy incident focuses on the impact on personal data and the rights of individuals.
That distinction matters.
A system outage may be a security issue.
Unauthorized disclosure of personal data may be a privacy issue.
A ransomware event involving customer records may be both.
Why this matters:
✨ different legal and regulatory obligations may apply
✨ notification requirements can differ
✨ affected stakeholders are not always the same
✨ the response team may need different expertise
A stronger incident response approach asks:
📌 Was personal data involved?
📌 What type of data was affected?
📌 Is there risk to individuals, not just to systems?
📌 Which playbook should lead the response?
Good governance means knowing when to activate the security response, the privacy response, or both.
Because protecting systems is not identical to protecting people’s data.
What do you think organizations confuse most: impact assessment, reporting obligations, or response ownership?
06/06/2026
📌
05/06/2026
📢 Still planning to join the CISA & CISM Certification Bootcamp?
The CISA & CISM Certification Bootcamp is the final upcoming training on the current ISACA Kampala Chapter 2026 Training Calendar — and a great opportunity to sharpen your preparation with focused, structured learning.
🗓️ 22–26 June 2026
📍 ICT Innovation Hub, Nakawa
💰 Member: UGX 1,000,000 per training
💰 Non-Member: UGX 1,200,000 per training
If you have not yet registered, this is the time to secure your place and stay on track for your certification journey.
04/06/2026
⚠️ Governance gets slower, messier, and riskier when decision rights are unclear.
One of the simplest questions in governance is also one of the most important:
Who approves what?
When that is not clear, organizations often run into:
✨ delayed decisions
✨ duplicated approvals
✨ weak accountability
✨ confusion during escalation
✨ unnecessary friction across teams
Clear decision rights matter because they define:
📌 who makes the decision
📌 who must be consulted
📌 who provides input
📌 who is accountable for the outcome
Without that clarity, even strong teams can lose momentum.
Good governance is not about adding more approvers.
It is about assigning the right decisions to the right people at the right level.
Because when approval paths are vague, risk increases.
When decision rights are clear, ex*****on improves.
What do you think hurts organizations most: too many approvers, unclear ownership, or slow escalation?
03/06/2026
Happy Martyrs Day from ISACA Kampala Chapter
Today, we join the nation in honoring the Uganda Martyrs whose faith, courage, and sacrifice continue to inspire generations.
As we reflect on their legacy, may this day remind us of the enduring power of conviction, resilience, and hope.
Wishing our members, partners, and the wider community a peaceful and meaningful Martyrs Day.
29/05/2026
⚠️ Treating AI like magic is risky. Treating it like a vendor is smarter.
When organizations adopt AI tools, they often focus on speed, features, and outputs.
But from a governance perspective, AI should also be managed like any other third party that can introduce risk into the business.
That means asking the same hard questions:
✨ Who provides the model?
✨ What data does it use or access?
✨ How has performance been validated?
✨ What bias, privacy, security, or explainability risks exist?
✨ What happens if the service changes, fails, or must be exited?
Model risk management becomes stronger when AI is not treated as a black box, but as a dependency that requires due diligence, oversight, and accountability.
Because if an AI system influences decisions, operations, or customer outcomes, it deserves the same governance discipline as any critical vendor.
What do you think organizations overlook most with AI vendors: validation, accountability, or exit planning?
27/05/2026
🌙 Eid al-Adha Mubarak from ISACA Kampala Chapter
As we mark this blessed occasion, we extend our warm wishes to our members, partners, and the wider community.
May Eid al-Adha bring peace, joy, and renewed purpose to you and your loved ones. May the values of faith, sacrifice, compassion, and service continue to inspire us in the way we lead, serve, and impact our communities.
Wishing you a blessed and peaceful Eid.
Click here to claim your Sponsored Listing.
Contact the practice
Telephone
Address
Uganda Institute Of/Communication And Information Technology (UICT), Plot 19-21 PortBell Road, Nakawa, Sat-Com Block 2
Kampala
256
Opening Hours
| Monday | 09:00 - 17:00 |
| Tuesday | 09:00 - 17:00 |
| Wednesday | 09:00 - 17:00 |
| Thursday | 09:00 - 17:00 |
| Friday | 09:00 - 17:00 |