Skip to content
BOL Conferences
Thread Options
#359595 - 05/16/05 02:26 PM IT Risk Assessment
LinMarie Offline
100 Club
LinMarie
Joined: Nov 2001
Posts: 243
Our regulators have requested that I create a risk analysis specific to IT. Does anyone have anything that might help me with this?

Return to Top
Audit
#359596 - 05/16/05 02:44 PM Re: IT Risk Assessment
Creditcopper Offline
100 Club
Creditcopper
Joined: Sep 2004
Posts: 203
Michigan
Lin, what regulation or best practice are they asking this for? I'm curious if they are citing the FACT Act.
_________________________
Is it cocktail time yet? Make mine a double!

Return to Top
#359597 - 05/16/05 04:59 PM Re: IT Risk Assessment
Czargazer Offline
Gold Star
Czargazer
Joined: May 2003
Posts: 298
Pacific Northwest
Here's something that might help both of you. This requirement likely springs from the FFIEC's IT Handbooks, specifically the Information Security handbook. Read through the booklet and you should get a better understanding on where they are coming from and how you can go about fulfilling their requirement of a risk assessment.

If your IT auditor and/or IT department have not seen these before please share with them, these booklets are a tremendous resource.
_________________________
Everyone has to make a living, mine just happens to involve thumbscrews.

Return to Top
#359598 - 05/18/05 02:44 PM Re: IT Risk Assessment
litmachog Offline
Member
litmachog
Joined: Apr 2004
Posts: 83
Arkansas
I have done a risk assessment for our three banks for I/T. I at one time had it rolled up into the regular annual audit risk assessment but had to split it out. It attempts to cover each of the booklets of the FFIEC audit guidelines.

If you will send me your email address, I can send you a copy after I take all names and such out of it.
_________________________
Praise God from whom all blessings flow!

Return to Top
#359599 - 05/25/05 09:07 PM Re: IT Risk Assessment
maggiey711 Offline
New Poster
Joined: Mar 2005
Posts: 20
Could you share that with me as well? I have used the IT Risk Assessment found on BOL (which is a lot of policy audit) for 3 years and was wondering if anything else was out there. How have you addressed the response program for unauthorized access to customer information and customer notice? myates@cnbalva.com

Return to Top
#359600 - 05/26/05 03:26 AM Re: IT Risk Assessment
Ken Baer Offline
New Poster
Ken Baer
Joined: May 2005
Posts: 10
Arizona, United States
Please feel free to download our free Customer Notification procedure and notification templates.

We'll be happy to help if you have any questions.
_________________________
We help banks solve compliance challenges inexpensively. www.appliedintent.com

Return to Top
#359601 - 05/26/05 01:23 PM Re: IT Risk Assessment
Jay-Risk Offline
Gold Star
Joined: May 2004
Posts: 274
New England
Quote:

Please feel free to download our free Customer Notification procedure and notification templates.

We'll be happy to help if you have any questions.




I'm not trying to rain on anybody's parade, but when a link is offered, ostensibly to provide a "free" download, it is not appropriate to then have the "free" download weblinked to a fill-in-the-blanks format and a cookies scripting. Saying, "We'll be happy to help..." generally means that people can call you if they want, but by having a fill-in-the-blanks form means that this is an obvious method of gathering marketing leads. Finally, while you may be a BOL-authorized vendor, I'm unable to determine that because I don't see a sidebar display for your firm.

This almost appears to be a plug by a non-BOL vendor, which I thought was not allowed.
Last edited by Jay-Risk; 05/26/05 01:25 PM.
Return to Top
#359602 - 05/27/05 10:06 PM Re: IT Risk Assessment
Anonymous
Unregistered

Do like I did ---- fill in the blanks with fictitious information

Return to Top
#359603 - 06/03/05 02:55 AM Re: IT Risk Assessment
Anonymous
Unregistered

There are no cookies involved with our free download. We are a BOL-authorized vendor. We do not send spam nor do we inappropriately solicit information to those who are not interested. We offer a tremendous amount of free assistance but inevitably we are in business.

We are happy to help and answer questions and we've received very positive feedback regarding the Customer Notification templates. However, if our posting free tools in the threads (vs. Bankers Online Tools) is not generally accepted practice please let us or BOL know and we will discontinue posting the links.

Return to Top
#359604 - 06/03/05 03:24 AM Re: IT Risk Assessment
Ken Baer Offline
New Poster
Ken Baer
Joined: May 2005
Posts: 10
Arizona, United States
Sorry for the accidental anonymous. Reposting so you know it's us.

There are no cookies involved with our free download. We are a BOL-authorized vendor. We do not send spam nor do we inappropriately solicit information to those who are not interested. We offer a tremendous amount of free assistance but inevitably we are in business.

We are happy to help and answer questions and we've received very positive feedback regarding the Customer Notification templates. However, if our posting free tools in the threads (vs. Bankers Online Tools) is not generally accepted practice please let us or BOL know and we will discontinue posting the links.
_________________________
We help banks solve compliance challenges inexpensively. www.appliedintent.com

Return to Top
#359605 - 06/07/05 05:33 PM Re: IT Risk Assessment
GregS Offline
100 Club
Joined: Jan 2005
Posts: 135
Sunny Florida
Thanks for the download.
_________________________
We shall endeavor to persevere.

Return to Top

Moderator:  Andy_Z