Building Your IT Risk Management Program
Dan Hadaway, Managing Partner of infotex, is presenting his workshop titled “Building Your IT Risk Management Program” through the Indiana Bankers Association on Wednesday, June 15th from 9:00 to 4:00 p.m.
Examiners have made it clear: if your management team understands the risk exposure of information and technology to your bank, you are definitely heading in the right direction. If risk is considered in all technology decision making, an effective IT risk management process has been implemented.
The standards themselves call for a risk assessment of all information assets. Beyond creating an inventory of assets, identifying threats and vulnerabilities, and assessing risk mitigation techniques, an effective risk management program puts the organization on guard in real time, in a manner that avoids threats and vulnerabilities as much as it mitigates the unavoidable risks or unpredictable problems.
- The FFIEC Standards and Effective Risk Management Strategy
- The Importance of Permeation
- The Meaning of Multi-Disciplinary
- Formal Risk Measurement Requirements (Vendor, Project, Infrastructure, Physical, GLBA, MFA)
- Risk Metrics
- Risk Measurement Process
- Risk Measurement Tools
- Breakout Sessions
- Asset Inventory
- Asset Criticality Analysis
- Vendor Risk Threshold Analysis
- Project Risk Threshold Analysis
- Drill Down Risk Assessments (using Mobile Banking, iPads, and Social Media examples)
All workshop attendees receive free access to boilerplated policies, procedures, and tools, including drill-down assessements for Mobile Banking, Social Media and iPad deployment.
Is this New?
If you’ve attended Dan Hadaway’s previous workshops on IT Risk Assessment, this one differs because it:
- Includes drill-down risk assessments for Mobile Banking, Social Media and iPad deployment.
- Presents a new, asset-based method of analyzing information security risk.
- Emphasizes methods to involve “all four corners of the bank” in the risk management process.
- Focuses breakout sessions on real-time risk management as well as RFP, new project, and reactive risk measurement techniques (whereas the last workshops focused on the annual risk assessment).
Who Should Attend?
This workshop is directed to bank management, compliance personnel, and information technology managers . . . anyone involved in your bank’s CIRT or involved in developing information security policies / procedures should attend this hands-on workshop.
Presenter: Dan Hadaway
Dan Hadaway, CISA, CISM, is managing partner of Infotex, Inc, an Indiana Bankers Association preferred service provider in many areas of information technology including Risk Assessments and Information Security Training. Dan speaks regularly at conventions, conferences, and workshops. He is the facilitator of the IBA’s Annual Information Technology Security Conference, and is published in various trade magazines.
Dan has been managing information technology risk since the late 1980’s. He has helped create risk assessment programs for banks ranging in size from 40 million to 2.5 billion in assets.
You can find the registration for and additional information on the Indiana Bankers Association’s website: Building Your IT Risk Management Program
Another awareness poster for YOUR customers (and users). Now that we have our own employees aware, maybe it’s time to start posting content for our customers! Download the large versions here: Awareness Poster (Portrait) Awareness Poster (Landscape) You are welcome to print out and distribute this around your office.
Intelligence agencies from five nations contributed to the new advisory… An article review. For the first time, the cybersecurity divisions of the nations in the “Five Eyes” alliance (The United States, United Kingdom, Canada, Australia and New Zealand) have released a joint advisory concerning incident response. The report, available here, does not provide a complete […]
PRESS RELEASE – FOR IMMEDIATE RELEASE BUSINESS NEWS NEW EMPLOYEE FOR INFOTEX infotex has just hired Nathan Harrell, to be a new Engagement Coordinator to assist with all communications between both current and prospective Clients. “We’re really excited to have Nate joining the team to help us keep the channels of communication open!” says Bryan […]
A Webinar-Movie Short Back by popular demand! Our Board Awareness Training program continues with this movie, entitled Vulnerability Management for Directors, that can be presented directly to your board of directors.
Nearly half of all companies expect a security issue due to telecommuting… An article review. A few months ago we discussed a warning from the Department of Homeland Security regarding hackers taking advantage of the business disruptions caused by COVID-19, and according to an article shared with us by our friend Wes Pollard it appears […]