About Us | Contact Us
View Cart

Risk Management

By Vigilize | Sunday, January 1, 2012 - Leave a Comment

Risk Management Program

Examiners have made it clear:  if your management team understands the risk exposure of information and technology to your bank, you are definitely heading in the right direction.  If risk is considered in all technology decision making, an effective IT risk management process has been implemented.

The standards themselves call for a risk assessment of all information assets.  Beyond creating an inventory of assets, identifying threats and vulnerabilities, and assessing risk mitigation techniques, an effective risk management program puts the organization on guard in real time, in a manner that avoids threats and vulnerabilities as much as it mitigates the unavoidable risks or unpredictable problems.

Agenda

  • The FFIEC Standards and Effective Risk Management Strategy
  • The Importance of Permeation
  • The Meaning of Multi-Disciplinary
  • Formal Risk Measurement Requirements (Vendor, Project, Infrastructure, Physical, GLBA, MFA)
  • Risk Metrics
  • Risk Measurement Process
  • Risk Measurement Tools (Technical and Non-Technical)
  • Breakout Sessions:
    • Asset Inventory
    • Asset Criticality Analysis
    • Vendor Risk Threshold Analysis
    • Project Risk Threshold Analysis

Testing Processes

Time will be allotted to present training on testing procedures so that management personnel can be assured of proper compliance, BEFORE the auditors show up!

  • How-to of Network Configuration Audits
  • Microsoft Security Baseline Analyze
  • Nessus Scanning

Deliverables (Templates / Boilerplates)

All workshop attendees receive free access to boilerplated policies, procedures, and tools.

Who Should Attend

This workshop is directed to bank management, compliance personnel, and information technology managers . . . anyone involved in your bank’s CIRT or involved in developing information security policies / procedures should attend this hands-on workshop.

Is This New?

If you’ve attended Dan Hadaway’s previous workshops on IT Risk Assessment, this one differs because it:

  • Presents a new, asset-based method of analyzing information security risk.
  • Emphasizes methods to involve “all four corners of the bank” in the risk management process.
  • Focuses breakout sessions on real-time risk management as well as RFP, new project, and reactive risk measurement techniques (whereas the last workshops focused on the annual risk assessment).

About the Presenter

Dan Hadaway, CISA, CISM
Dan is managing partner of Infotex, Inc, an Indiana Bankers Association preferred service provider in many areas of information technology including Risk Assessments and Information Security Training.  Dan speaks regularly at conventions, conferences, and workshops.  He is the facilitator of the IBA’s Annual Information Technology Security Conference, and is published in various trade magazines.

Dan has been managing information technology risk since the late 1980’s.  He has helped create risk assessment programs for banks ranging in size from 40 million to 2.5 billion in assets.

Latest News
    How Do We Know What We Know? Making Sure You Can Understand What Happened in an Incident. Another one of those Dan’s New Leaf Posts, meant to inspire thought about IT Governance . . . . Until I reclined on my front yard, looking at the sky, following the instructions on how not to look […]
    Another awareness poster for YOUR customers (and users).  Now that we have our own employees aware, maybe it’s time to start posting content for our customers! Download the large versions here: Awareness Poster (Portrait) Awareness Poster (Landscape)   You are welcome to print out and distribute this around your office. Interested in one of ours […]
    President Biden recently signed a bill tasking the agency with evaluating the unique risks that schools face… An article review. Taking note of the unique challenges educational institutions face in securing their networks, President Biden has signed a bill into law directing the Cybersecurity and Infrastructure Security Agency (CISA) to look into ways that they can […]
    Thanks for being interested in our Technology Planning Webinars! This year‘s annual update to our annual Technology Planning webinar will include a panel discussion, a review of the previous years’ movies that are already available, and a discussion about alternative tactics that have arisen from recent conferences as well as the impact of the AIO […]
    Welcome Cybersecurity Conference Attendees! Thanks for joining us for the Cybersecurity Conference today! We have created this page for you to have access to the deliverables from Dan’s talk.  
    What you need to know for compliance coast-to-coast. Back in 2020 we posted an article containing links to data breach laws from each state, and it has proven to be one of our more popular posts.  Because laws surrounding the use (and abuse) of technology are always evolving, we thought it was worth taking another […]
    Why It Rhymes With SEEM (And its Not the I Before E Rule) Another one of those Dan’s New Leaf Posts, meant to inspire thought about IT Governance . . . . It’s the Gestalt. The idea that the whole is greater than the sum of it’s parts. That’s not something that is often brought […]
    Another awareness poster for YOUR customers (and users).  Now that we have our own employees aware, maybe it’s time to start posting content for our customers! Download the large versions here: Awareness Poster (Portrait) Awareness Poster (Landscape)   You are welcome to print out and distribute this around your office. Interested in one of ours […]
    Questions about China’s new disclosure laws only highlight the uncertainty about disclosure in general… An article review. China recently made waves in the security world by announcing a new set of data security laws, one of which has added new fuel to a long running debate: how and when should security vulnerabilities be disclosed…and to […]