October 8, 2009 8:33 PM
Posted by: David Schneier
Audit,
COBIT,
GLBA,
ISACA,
ITGI,
NCUA,
Regulatory Compliance,
risk,
risk assessment,
Risk IT,
SOX,
Val ITI have an associate who has an addiction to certifications. He’s one of those “too smart for his own good” geniuses who often decides to change his career course and starts by obtaining whatever accreditation or cert is needed to do so....
September 30, 2009 7:34 PM
Posted by: David Schneier
Audit,
bank,
banking,
compliance,
credit union,
CU,
DIF,
FDIC,
GLBA,
NCUA,
Regulatory ComplianceEvery day, I receive a semi-deluge of industry related emails. Between the various agencies, media sites, organizations and associations I tend to receive more communiqués than I know what to do with. But I developed an interesting habit last year when the banking...
September 16, 2009 9:02 PM
Posted by: David Schneier
Audit,
bank,
compliance,
credit,
GLBA,
NCUA,
real estate,
Regulatory ComplianceI had one of those odd moments yesterday regarding the banking industry that I wanted to share with you.
On the homepage of a major news website were two headline stories. The first was about how Ben Bernanke believes the recession we’re...
September 1, 2009 3:29 PM
Posted by: David Schneier
Audit,
compliance,
general controls,
GLBA,
governance,
GRC,
IT,
ITGC,
NCUA,
Regulatory Compliance,
risk,
risk assessmentI had mentioned in my last post a recent conversation with my partner regarding a proposed IT general controls (ITGC) audit. My primary role in our practice is to head up regulatory compliance services which includes audits, assessments and program development; my...
August 18, 2009 8:05 PM
Posted by: David Schneier
Audit,
FDIC,
GLBA,
PCI,
regulatory,
Regulatory Compliance,
SOXI was away from the office last week trying squeeze in a family vacation before the kids head back to school. Despite taking the occasional phone call and replying to a number of emails, there was still plenty waiting for me today when I returned to my normal...
July 17, 2009 1:58 PM
Posted by: David Schneier
Audit,
compliance,
cyber security,
FFIEC,
GLBA,
PCI,
regulations,
Regulatory Compliance,
Security,
SOXDespite earning a living in the space, I often question the value of regulatory compliance.
How is it that a business can be PCI-compliant but still have glaring vulnerabilities? How is it that despite layer upon layer of controls...
July 8, 2009 3:45 PM
Posted by: David Schneier
Audit,
compliance,
cyber security,
FERC cyber security,
GLBA,
NERC,
Regulatory Compliance,
SOXI had a eureka moment recently that I’d like to share.
In considering the implications of the recently announced changes by MasterCard that will now require PCI Level 2 merchants to be assessed by a Qualified Security Assessor (QSA) it occurred to me...
July 2, 2009 2:53 AM
Posted by: David Schneier
Audit,
compliance,
GLBA,
governance,
GRC,
PCI,
Regulatory Compliance,
SOXA while back I’d written about the Unified Compliance Framework from Network Frontiers, which takes quite literally every regulation and framework within the IT domain and maps them in such a way where you can identify how a single control addresses multiple requirements. In...
June 22, 2009 3:46 PM
Posted by: David Schneier
Audit,
compliance,
GLBA,
obama,
OTS,
PCI,
Regulatory Compliance,
SOXI had a great piece lined up for this week about a governance project I’m working on but was waylaid by all the news that hit the radar around regulatory reform.
In what may be the understatement of the year, the plans revealed last week by President...