False Sense of Security of the Month
An untested control is not a control, it’s a wish. I’m not the kind of person who trusts technology or controls. It’s just not in me. But I do trust my wife’s intuition. So when I saw this youtube video, forwarded to me by my friend Joe Cychosz, I was not surprised to find that […]
The FDIC Audit is In! The FDIC Audit is In!
The GAO audited the FDIC’s technology and information systems and found some familiar results!
Vendor Management 2014
Mark your calendars! Dan Hadaway will be delivering a workshop with the Indiana Bankers Association to outline what makes an effective vendor management program. The workshop will be on August 21st starting at 9:00 AM and ending at 4:00 PM. For information on how to register, visit the IBA’s website. Sharpening Your Vendor Management Tools Because financial […]
What’s Missing from your SSAE-16 SOC Report?
It’s what’s NOT in the report that matters . . . Five Suggestions to Learn What Controls to Expect Another one of those Dan’s New Leaf Posts, meant to inspire thought about IT Governance . . . . We’ve discussed the difference between a SOC1 and a SOC2 report in a previous article. As a result of […]
The OCC’s Risk Analysis Executive Summary
Dan answers the OCC’s Top 6 Risks with the “Top 6 Reasons to Read the Report!”
Quick Lesson on Your Auditors Wanting Remote Access!
Several of our Clients have been asking about whether they should allow their auditors to have remote access to their systems. That’s an awkward question to have to ask your auditor, so we thought we’d post a quick summary of our response.
For our Brian Krebs Fans!
Target Security Breach Movie Deal Okay, I admit, the Brian Krebs fans out there already know about this. So, for those of you who have not yet started monitoring his blog, if you’d like to know why you truly SHOULD start monitoring his blog, check it out here! Dan Hadaway, CRISC
Simplicity
Another Dan’s New Leaf Post I want to write an article about Simplicity; but where do you start with such a complicated subject? —– Maybe the reason I’m writing this article is because one way to learn about something is to write about it. And we all need to learn about Simplicity. Nothing has made […]
On Reviewing the Social Media Guidance Kit
Note: infotex plans to release a response kit for the 12/11/2013 FFIEC Guidance entitled “Social Media: Consumer Compliance Risk Management Guidance.” . . . . . a Dan’s New Leaf post . . . . . As I continue to swim neck-deep in the language and meanings and implications of the FFIEC Social Media Guidance, […]
Get Ready to Respond to the Social Media Guidance!
The 12/11/2013 social media guidance has some weaknesses. The good news: the infotex response kit will be designed to address them!