Tag: Risk Assessment

  • Ask the Guru: Cybersecurity “Risk Appetite”

    Ask the Guru: Cybersecurity “Risk Appetite”

    Hey Guru I saw multiple references to the term “risk appetite” in the FFIEC Cybersecurity Assessment Tool.  What exactly is risk appetite, and how can I address this in my institution? They just released Management Handbook contains 10 new references to “risk appetite”, including a requirement that the Board  has defined the institution’s risk appetite and it’s risk tolerance levels.…

  • FFIEC Releases Cybersecurity Assessment Tool

    FFIEC Releases Cybersecurity Assessment Tool

    UPDATE:  Safe Systems just released their Enhanced CyberSecurity Assessment Toolkit (ECAT) – This enhanced version of the FFIEC toolkit addresses the biggest drawback of the tool; the ability to collect, summarize, and report your risk and control maturity levels.   Once risks and controls have been assessed (Step 1 below), institutions will now be better able…

  • FFIEC Issues 2 Statements on Cybersecurity

    Both statements address recent cybersecurity threats; one targeting online credentials (passwords, usernames, e-mail addresses that may be used by employees or customers to authenticate themselves), and one addressing destructive malware.  The statements advise specific risk mitigation steps institutions should consider, and I thought it would be instructive to compare the steps to see which are common to…

  • Vendor Management in 3 Parts. Part 2 – Risk Assessment (or, “will they or won’t they?”)

    In Part 1 I said that vendor management, just as any other risk management endeavor, consists of 3 basic phases; Identify the risk Assess the risk, and Control the risk I also discussed why risk identification was a more difficult task today because of the “access to data” question, and also because “data” includes not just NPI, but confidential…

  • Vendor Management in 3 Parts. Part 1 – Risk Identification (or, “do they or don’t they?”)

    Service provider oversight (aka vendor management) is undoubtedly the hottest hot-button item on the regulator’s agenda right now, and for good reason.  For one thing, regulators know that the vast majority of financial institutions outsource at some point, in fact recent studies put the number of FI’s that either transmit, process or store information with…

  • Windows XP and Vendor Management

    The FFIEC issued a joint statement recently regarding Microsoft’s discontinuation of support for Windows XP.  The statement requires financial institutions to identify, assess, and manage the risks of these devices in their institutions after April 8, 2014.   After this date Microsoft will no longer provide regular security patches or support for this product, potentially leaving…