October 22, 2012 2:09 PM
Posted by: David Schneier
ACH,
assess,
assessment,
assessments,
Audit,
auditor,
audits,
banking,
banks,
business,
CISA,
CISO,
community bank,
compliance,
credit unions,
CU,
exam,
examination,
examinations,
examiner,
examiners,
exams,
FFIEC,
financial institutions,
general controls,
GLBA,
identify theft,
identity theft,
information security,
information security office,
Information Technology General Controls,
internal audit,
internal controls,
ITGC,
NPPI,
observations,
oversight,
personally identifiable informaiton,
PII,
privacy,
risk assess,
risk assessment,
risk assessments,
risk management,
risk-based,
risksA few years back when I first cut over to working somewhat exclusively with financial institutions I memorized an elevator speech that still somewhat defines who I am and what I do professionally. Part of the speech pointed out that my firm helped "banks and credit unions meet regulatory...
April 29, 2012 7:43 PM
Posted by: David Schneier
assessment,
assessments,
Audit,
compliance,
control,
control owners,
controls,
findings,
GLBA,
internal audit,
NCUA,
regulations,
regulatory,
Regulatory Compliance,
risk,
risk assessments,
risksMy first encounter with an auditor was back in the mid-90's while working as an application project manager for a Fortune 100 company. The group responsible for change management was going through an audit of their process and one of the changes that was selected for review happened to belong to...