The single most important vendor management control

Pop quiz…according to the FFIEC Handbook on Outsourcing Technology Services

“The ________ is the single most important control in the outsourcing process”:

  1. Initial due diligence process
  2. Review of third-party

  3. Read the rest of the article

NIST releases new Cloud Computing Guidelines

Although not specific to the financial industry, the new guidelines provide a comprehensive overview of the privacy and security challenges of this increasingly popular computing model.  It’s worth a look …
Read the rest of the article

2012 Compliance Trends, Part 5 – Uncertainty (UPDATE)

Similar to my previous post on Risk Assessments, I believe Uncertainty is also a 2-part trend:

- Uncertainty about future regulatory changes, and
- Uncertainty about the interpretation of existing …
Read the rest of the article

2012 Compliance Trends, Part 4 – Risk Assessments

Information security, business continuity, vendor management, ID theft, RDC, Internet banking…it seems that every time you do anything these days you’re expected to perform a risk assessment. This is nothing …
Read the rest of the article

Filed under Hot Topics · Tagged with

Top Topics for 2011

With every one else doing their end-of-the-year top ten lists, I thought I might join in and see what topics were most popular with visitors to the Compliance Guru site …
Read the rest of the article

Filed under Hot Topics · Tagged with

2012 Compliance Trends, Part 3 – Management

I’ve written about the importance of this before, and from many different angles, but I want to recap and explain why I think management (both IT and enterprise) will be …
Read the rest of the article

2012 Compliance Trends, Part 2 – Vendor Management

In my first post in this series I discussed training (employee and customer) as a good candidate for increased regulatory scrutiny in 2012.  Although these posts are in no particular …
Read the rest of the article

Filed under Hot Topics · Tagged with , , ,

2012 Compliance Trends, Part 1 – Training

This post will begin a series of 5 topics that I consider to be good candidates for increased regulatory scrutiny in the coming year.  For each topic, I will make …
Read the rest of the article

The “Security Breach” and your Incident Response Program

Last week Wells Fargo said that some of their customers in South Carolina and Florida received portions of other customers’ bank statements in the mail as the result of a …
Read the rest of the article

Risk Assessing iCloud (and other online backups) – UPDATE

(Updated the Challenges & Solutions section)

Apple recently introduced the iCloud service for Apple devices such as the iPhone and iPad.  The free version offers 5GB of storage, and additional …
Read the rest of the article