September 21, 2012 3:44 PM
Posted by: David Schneier
assess,
assessment,
assessments,
Audit,
bank,
banking,
CISO,
CISSP,
compliance,
compliance officer,
compliant,
credit union,
credit unions,
CU,
disaster,
disaster recovery,
DR,
enterprise risk,
enterprise risk management,
ERM,
exam,
examination,
examinations,
examiner,
examiners,
exams,
framework,
governance,
GRC,
guidance,
information security,
information security office,
infrastructure,
ISO,
oversight,
policy,
procedure,
regulation,
regulations,
regulations audit,
regulatory,
regulatory guidance,
risk assess,
risk assessment,
risk assessments,
risk management,
risk-based,
risks,
technologyAbout a decade ago a family member chastised me for having an auto repair shop do my oil changes for me. She (yeah, you’re reading that right – “she”) pointed out how ridiculously easy it was to drain the old oil, replace it with the new stuff and check a wide variety of fluid levels,...
July 21, 2012 8:25 PM
Posted by: David Schneier
Add new tag,
assess,
assessment,
assessments,
bank,
banking,
banking crisis,
banks,
community bank,
compliance,
compliance officer,
compliant,
control,
credit,
credit card,
data security,
Dodd-Frank,
economy,
enterprise risk,
enterprise risk management,
ERM,
exam,
examination,
examinations,
examiner,
examiners,
exams,
Federal Reserve Bank,
FFIEC,
financial,
financial institutions,
framework,
information security office,
lending,
LinkedIn,
mortgage,
NCUA,
NCUA Sheila Bair,
NPPI,
observations,
oversight,
personally identifiable informaiton,
PII,
policy,
privacy,
procedure,
regulation,
regulations,
regulations audit,
regulatory,
regulatory guidance,
risk assess,
risk assessment,
risk assessments,
risk management,
risk-based,
risks,
security PII,
Sheila Bair,
social security numbers,
technology,
third party management,
third party oversight,
vendor,
Vendor Management,
vendor risk,
vendor risk assessmentI was an unabashed fan of Sheila Bair and made no secret of that fact. She was a breath of fresh air in a line of work where everything is stale and always at least a little boring. Not that Martin Gruenberg is any less effective running the FDIC, he's just a whole lot less interesting to pay...
July 6, 2012 3:18 AM
Posted by: David Schneier
assess,
assessment,
assessments,
Audit,
audits,
bank,
banking,
banks,
compliance,
compliant,
control,
credit union,
credit unions,
CU,
enterprise risk,
enterprise risk management,
ERM,
exam,
examination,
examinations,
examiner,
exams,
FDIC,
Federal Reserve Bank,
FFIEC,
financial institutions,
framework,
FRB,
general controls,
GLBA,
governance,
GRC,
guidance,
information security,
information security office,
infrastructure,
NCUA,
PII,
policy,
procedure,
regulation,
regulations,
regulations audit,
risk assessment,
risk assessments,
Risk IT,
risk management,
risk rating,
risk-based,
risks,
threats,
vendor,
Vendor Management,
vendor risk,
vendor risk assessmentThere's a joke of sorts within my personal circle of family and friends regarding what it is that I do these days. Ask me and I'll tell you that I'm a regulatory compliance expert who advises financial institutions on how to comply with the myriad rules and regulations governing information...
April 23, 2010 10:14 PM
Posted by: David Schneier
assessment,
assessments,
Audit,
bcp,
business continuity planning,
controls,
framework,
general controls,
GLBA,
IT General Controls,
NCUA,
Regulatory Compliance,
Security,
security awareness,
Vendor ManagementI've often surprised people when it comes to conducting audit/assessment work or developing compliance programs. Generally speaking I'm a reasonable person who typically exhibits an abundance of flexibility in my day-to-day life. However when it comes to my career, I tend to be much more of a...
March 14, 2010 3:59 AM
Posted by: David Schneier
assessment,
Audit,
framework,
GLBA,
GRC,
IT General Controls,
ITGC,
Regulatory Compliance,
risk,
risk managementI had an email exchange with a colleague last week in which GRC (governance, risk and compliance as a unified methodology) was central to the discussion. She felt that there's been a blurring of the lines in how people view GRC versus ERM (enterprise risk management) as disciplines and wanted to...