Building Your IT Risk Management Program
Dan Hadaway, Managing Partner of infotex, is presenting his workshop titled “Building Your IT Risk Management Program” through the Indiana Bankers Association on Wednesday, June 15th from 9:00 to 4:00 p.m.
Examiners have made it clear: if your management team understands the risk exposure of information and technology to your bank, you are definitely heading in the right direction. If risk is considered in all technology decision making, an effective IT risk management process has been implemented.
The standards themselves call for a risk assessment of all information assets. Beyond creating an inventory of assets, identifying threats and vulnerabilities, and assessing risk mitigation techniques, an effective risk management program puts the organization on guard in real time, in a manner that avoids threats and vulnerabilities as much as it mitigates the unavoidable risks or unpredictable problems.
- The FFIEC Standards and Effective Risk Management Strategy
- The Importance of Permeation
- The Meaning of Multi-Disciplinary
- Formal Risk Measurement Requirements (Vendor, Project, Infrastructure, Physical, GLBA, MFA)
- Risk Metrics
- Risk Measurement Process
- Risk Measurement Tools
- Breakout Sessions
- Asset Inventory
- Asset Criticality Analysis
- Vendor Risk Threshold Analysis
- Project Risk Threshold Analysis
- Drill Down Risk Assessments (using Mobile Banking, iPads, and Social Media examples)
All workshop attendees receive free access to boilerplated policies, procedures, and tools, including drill-down assessements for Mobile Banking, Social Media and iPad deployment.
Is this New?
If you’ve attended Dan Hadaway’s previous workshops on IT Risk Assessment, this one differs because it:
- Includes drill-down risk assessments for Mobile Banking, Social Media and iPad deployment.
- Presents a new, asset-based method of analyzing information security risk.
- Emphasizes methods to involve “all four corners of the bank” in the risk management process.
- Focuses breakout sessions on real-time risk management as well as RFP, new project, and reactive risk measurement techniques (whereas the last workshops focused on the annual risk assessment).
Who Should Attend?
This workshop is directed to bank management, compliance personnel, and information technology managers . . . anyone involved in your bank’s CIRT or involved in developing information security policies / procedures should attend this hands-on workshop.
Presenter: Dan Hadaway
Dan Hadaway, CISA, CISM, is managing partner of Infotex, Inc, an Indiana Bankers Association preferred service provider in many areas of information technology including Risk Assessments and Information Security Training. Dan speaks regularly at conventions, conferences, and workshops. He is the facilitator of the IBA’s Annual Information Technology Security Conference, and is published in various trade magazines.
Dan has been managing information technology risk since the late 1980’s. He has helped create risk assessment programs for banks ranging in size from 40 million to 2.5 billion in assets.
You can find the registration for and additional information on the Indiana Bankers Association’s website: Building Your IT Risk Management Program
Leave a comment
A lack of funding and IT staff makes for an inviting target… An article review. While Read more