About Us | Contact Us
View Cart

Building Your IT Risk Management Program

By Vigilize | Wednesday, June 1, 2011 - Leave a Comment

Dan Hadaway, Managing Partner of infotex, is presenting his workshop titled “Building Your IT Risk Management Program” through the Indiana Bankers Association on Wednesday, June 15th from 9:00 to 4:00 p.m.


Examiners have made it clear: if your management team understands the risk exposure of information and technology to your bank, you are definitely heading in the right direction. If risk is considered in all technology decision making, an effective IT risk management process has been implemented.

The standards themselves call for a risk assessment of all information assets. Beyond creating an inventory of assets, identifying threats and vulnerabilities, and assessing risk mitigation techniques, an effective risk management program puts the organization on guard in real time, in a manner that avoids threats and vulnerabilities as much as it mitigates the unavoidable risks or unpredictable problems.

Agenda Topics

  • The FFIEC Standards and Effective Risk Management Strategy
  • The Importance of Permeation
  • The Meaning of Multi-Disciplinary
  • Formal Risk Measurement Requirements (Vendor, Project, Infrastructure, Physical, GLBA, MFA)
  • Risk Metrics
  • Risk Measurement Process
  • Risk Measurement Tools
  • Breakout Sessions
  • Asset Inventory
  • Asset Criticality Analysis
  • Vendor Risk Threshold Analysis
  • Project Risk Threshold Analysis
  • Drill Down Risk Assessments (using Mobile Banking, iPads, and Social Media examples)

Deliverables
All workshop attendees receive free access to boilerplated policies, procedures, and tools, including drill-down assessements for Mobile Banking, Social Media and iPad deployment.

Is this New?
If you’ve attended Dan Hadaway’s previous workshops on IT Risk Assessment, this one differs because it:

  • Includes drill-down risk assessments for Mobile Banking, Social Media and iPad deployment.
  • Presents a new, asset-based method of analyzing information security risk.
  • Emphasizes methods to involve “all four corners of the bank” in the risk management process.
  • Focuses breakout sessions on real-time risk management as well as RFP, new project, and reactive risk measurement techniques (whereas the last workshops focused on the annual risk assessment).

Who Should Attend?
This workshop is directed to bank management, compliance personnel, and information technology managers . . . anyone involved in your bank’s CIRT or involved in developing information security policies / procedures should attend this hands-on workshop.

Presenter: Dan Hadaway
Dan Hadaway, CISA, CISM, is managing partner of Infotex, Inc, an Indiana Bankers Association preferred service provider in many areas of information technology including Risk Assessments and Information Security Training. Dan speaks regularly at conventions, conferences, and workshops. He is the facilitator of the IBA’s Annual Information Technology Security Conference, and is published in various trade magazines.

Dan has been managing information technology risk since the late 1980’s. He has helped create risk assessment programs for banks ranging in size from 40 million to 2.5 billion in assets.


You can find the registration for and additional information on the Indiana Bankers Association’s website: Building Your IT Risk Management Program


Latest News
    A Webinar-Movie What are the top seven risks your board should know about in 2022? Since his first board presentation in 2000, when Dan presents audit reports to boards of directors, he also talks to the board about the top risks the institution is facing. Since 2006, Dan has been compiling a list of the […]
    Seven Trends . . . that small bank Information Security Officers face in 2022 Another one of those Dan’s New Leaf Posts, meant to inspire thought about IT Governance . . . . Welcome to the Magnificent Seven, my annual predictive article about the seven trends in technology that will impact the Information Security Officers of […]
    Another awareness poster for YOUR customers (and users).  Now that we have our own employees aware, maybe it’s time to start posting content for our customers! Download the large versions here: Awareness Poster (Portrait) Awareness Poster (Landscape)   You are welcome to print out and distribute this around your office. Interested in one of ours […]
    Millions of phishing emails will get through automated defenses this year, are your employees ready? An article review. With cybersecurity threats such as cryptocurrency miners and ransomware seeming to dominate the news, it can be easy to forget about older threats such as phishing…but a recent report from cybersecurity firm Tessian reminds us that criminals […]
    The FFIEC’s latest guidance: The Architecture, Infrastructure, and Operations, has brought many changes to exactly how a small financial institution may look at their Technology Planning for 2022. Included in that will be the opportunity to write your first Architecture Plan and we intend to show you what may be involved in that! Have any […]
    While we’re not a news service, we often use current events to comment on trends and our services. This blog is intended to get people thinking about topics and trends in Technology Risk Management, through our article reviews, as well as through original blog articles about current events and our MSSP services (such as our […]
    Following the contribution, Have I Been Pwned will host more than 800 million compromised credentials… An article review. Have any of your login credentials been revealed in a breach?  If you’re unsure about that, Have I Been Pwned (HIBP) can help you out by letting you check against over 600 million compromised credentials…and with the […]
    infotex and Log4j We are keeping our Clients’ safety in mind. To all infotex managed security service Clients: On Friday December 10th, infotex became aware of a zero-day vulnerability in the Apache Log4j library that allows unauthenticated remote code execution. We began incident response and took steps to proactively disable potentially vulnerable applications until we […]
    Another awareness poster for YOUR customers (and users).  Now that we have our own employees aware, maybe it’s time to start posting content for our customers! Download the large versions here: Awareness Poster (Portrait) Awareness Poster (Landscape)   You are welcome to print out and distribute this around your office. Interested in one of ours […]