SOC What? SOC1 v SOC2
The reason we’re seeing SOC1s acquired instead of SOC2s, is because Sarbanes Oxley wants a SOC1 report and we IT people want the SOC2 report, and they’re very expensive to get.
Social Media Policy Implications
Thank you for reaching out to an infotex Employee via Social Media! Please know that, because of the nature of our business, our company has some rather peculiar policies that could affect how that employee responds to you. If you are a Client of Infotex, we cannot “friend” you on Facebook (unless we were already friended with you prior […]
The Magnificent Seven 2013 (M7-2013)
Dan’s last Dan’s New Leaf post of the year, his annual articulation of trends in small bank technology governance.
Top 20 Tactics for 2014
The companion article to Dan’s Magnificent Seven.
What should we focus our 2014 Audit Plan upon?
Risk Based Auditing! I am often asked, especially at the end of a year, what should we be focusing our next audit plan upon? My answer: Focus your auditing on testing YOUR controls that mitigate the most risk in YOUR environment. Don’t bother testing controls which do not mitigate risk. Other than compliance risk*, […]
Infotex Endorses TRAC
For the first time in the firm’s fourteen year history, infotex has selected a technology that it will recommend and sell to its Clients.
Why We Endorse TRAC!
For the first time in the firm’s fourteen year history, infotex has selected a technology partner. Until now, we have taken great pride in our “technology neutrality,” which we felt was essential in remaining independent.
Protected: policy_set_proposal_110215
There is no excerpt because this is a protected post.
New Control For E-mail Auto-Fill Vulnerability
By now our risk assessments should have led us to concern about the risk of accidentally addressing a sensitive e-mail message to the wrong person. A person needs to send a message to “Jane Doe” and she accidentally chooses “Jane Plain” instead. This can be costly: E-mail gaffe leads to billion-dollar news leak. So for […]
Hadaway to Deliver FFIEC Education Requirements Workshop via Webinar
The long-standing awareness training workshop, now broken into three two hour webinars! Awareness Training Webinar Dan Hadaway CRISC, CISM, CISA will be delivering a webinar through the Ohio Banker’s League centered around developing an Awareness Training Program that meets FFIEC requirements. “And that means,” says Hadaway, “that it considers all four corners of the organization, […]