About Us | Contact Us
View Cart

Building Your IT Risk Management Program

By Vigilize | Wednesday, June 1, 2011 - Leave a Comment

Dan Hadaway, Managing Partner of infotex, is presenting his workshop titled “Building Your IT Risk Management Program” through the Indiana Bankers Association on Wednesday, June 15th from 9:00 to 4:00 p.m.


Examiners have made it clear: if your management team understands the risk exposure of information and technology to your bank, you are definitely heading in the right direction. If risk is considered in all technology decision making, an effective IT risk management process has been implemented.

The standards themselves call for a risk assessment of all information assets. Beyond creating an inventory of assets, identifying threats and vulnerabilities, and assessing risk mitigation techniques, an effective risk management program puts the organization on guard in real time, in a manner that avoids threats and vulnerabilities as much as it mitigates the unavoidable risks or unpredictable problems.

Agenda Topics

  • The FFIEC Standards and Effective Risk Management Strategy
  • The Importance of Permeation
  • The Meaning of Multi-Disciplinary
  • Formal Risk Measurement Requirements (Vendor, Project, Infrastructure, Physical, GLBA, MFA)
  • Risk Metrics
  • Risk Measurement Process
  • Risk Measurement Tools
  • Breakout Sessions
  • Asset Inventory
  • Asset Criticality Analysis
  • Vendor Risk Threshold Analysis
  • Project Risk Threshold Analysis
  • Drill Down Risk Assessments (using Mobile Banking, iPads, and Social Media examples)

Deliverables
All workshop attendees receive free access to boilerplated policies, procedures, and tools, including drill-down assessements for Mobile Banking, Social Media and iPad deployment.

Is this New?
If you’ve attended Dan Hadaway’s previous workshops on IT Risk Assessment, this one differs because it:

  • Includes drill-down risk assessments for Mobile Banking, Social Media and iPad deployment.
  • Presents a new, asset-based method of analyzing information security risk.
  • Emphasizes methods to involve “all four corners of the bank” in the risk management process.
  • Focuses breakout sessions on real-time risk management as well as RFP, new project, and reactive risk measurement techniques (whereas the last workshops focused on the annual risk assessment).

Who Should Attend?
This workshop is directed to bank management, compliance personnel, and information technology managers . . . anyone involved in your bank’s CIRT or involved in developing information security policies / procedures should attend this hands-on workshop.

Presenter: Dan Hadaway
Dan Hadaway, CISA, CISM, is managing partner of Infotex, Inc, an Indiana Bankers Association preferred service provider in many areas of information technology including Risk Assessments and Information Security Training. Dan speaks regularly at conventions, conferences, and workshops. He is the facilitator of the IBA’s Annual Information Technology Security Conference, and is published in various trade magazines.

Dan has been managing information technology risk since the late 1980’s. He has helped create risk assessment programs for banks ranging in size from 40 million to 2.5 billion in assets.


You can find the registration for and additional information on the Indiana Bankers Association’s website: Building Your IT Risk Management Program


Latest News
    A Webinar Movie This presentation is intended for those who are planning to participate in an infotex incident response test. Please let us know what questions you have, when we have our Plan Walkthrough and Test Plan Approval meeting!
    What you need to know for compliance coast-to-coast. Back in 2020 we posted an article containing links to data breach laws from each state, and it has proven to be one of our more popular posts.  Because laws surrounding the use (and abuse) of technology are always evolving, we thought it was worth taking another […]
    Another awareness poster for YOUR customers (and users).  Now that we have our own employees aware, maybe it’s time to start posting content for our customers! In the spirit of October and Halloween we have put together a gallery of our “spooky” Awareness Posters at halloween.infotex.com. Use them to help decorate for the holiday! Check […]
    With nearly three in four people using third-party payment services tied to their bank accounts, the risk isn’t limited to your own policies and procedures… An article review. When working on cybersecurity awareness messages for your customers you may be inclined to focus on your own systems, but a new study on security in digital […]
    PRESS RELEASE – FOR IMMEDIATE RELEASE BUSINESS NEWS NEW EMPLOYEE FOR INFOTEX infotex is excited to announce that Cody Smith has joined the team as the newest Data Security Analyst. Cody holds several industry certifications (including the most recent: SSCP) as well as a B.S in Cyber Security & Information Assurance from Western Governors University. […]
    It’s all about protecting Customer information . . . In 1999 the Gramm-Leach-Bliley Act (GLBA) directed the Federal Deposit Insurance Corporation (FDIC) and other federal banking agencies to ensure that financial institutions have policies, procedures, and controls in place to prevent the unauthorized disclosure of customer financial information.  The FDIC and other federal banking agencies […]
    A Ghoulish Gallery! Just a few scary-themed Awareness posters from our collection, which you can see at posters.infotex.com! Below you will find both the vertical and horizontal versions of each of the posters, all you need to do is “right-click > “Save link as…” to download! Vertical 8.5″ x 11″ Format   Horizontal 11″ x […]
    What to Expect in an Annual Information Security Report to the Board Webinar-Movie Information security ranks as a top risk to financial institutions, both in terms of likelihood and overall impact. It is important that boards receive annual comprehensive reporting from management about the information security risks and incidents, and the actions taken to address […]
    Another awareness poster for YOUR customers (and users).  Now that we have our own employees aware, maybe it’s time to start posting content for our customers! Check out posters.infotex.com for the whole collection! Download the large versions here: Awareness Poster (Portrait) Awareness Poster (Landscape)   You are welcome to print out and distribute this around […]
    With the potential to break all existing forms of encryption, quantum computing poses a unique challenge… An article review. While quantum computing has been a buzzword for some time now the technology remains largely theoretical, with small scale proofs-of-concept that still suffer from serious limitations.  That hasn’t stopped security researchers from worrying about the technology’s […]