Blog

Archive for December, 2009

Compliance and Collaboration | The Perfect Marriage

Natasha December 15th, 2009 View Comments

Wedding
People marry for various reasons. Some for financial gain, companionship, and some I dare say for love. A select few marry because it just makes good business sense. When we introduced collaboration to our compliance solutions it was a match made in heaven. Research indicates that collaboration increases productivity by 99% and reduces expenses by 50 %. The alphabet soup of the FDIC, OTS, OCC, NCUA, SOX, and GLBA,  all demand efficiency.  Hmmph, an inevitable pairing.

Collaboration and compliance seem like quite an unlikely match yet you simply cannot achieve compliance without collaboration. Even in the most basic form collaboration enables efficient dissemination of policy across the enterprise, implementation of security awareness training, and shared knowledge between business units. What we need to understand and embrace is that security does not stop at the IT department gate, the audit department window sill, or the risk manager’s office door. However, it blankets the width and breadth of the enterprise touching every department, strategic business unit (SBU), and division within the organization. Therefore continuous compliance demands that everyone in the organization be responsible daily for security. Ironically, collaboration is defined as “people working together.” What a symbiotic marriage. To effectively manage risk, security initiatives, and ensure continuous compliance, organizations must employ collaboration techniques and eliminate silos. This will result in:

  • Shared knowledge: As one SBU or division conquers a security or audit methodology this can easily translate to other divisions
  • Increased visibility: Collaboration increases visibility into the gaps and security deficiencies across the enterprise
  • Increased efficiency: Using collaboration greatly reduces the time and resources spent to gather data, perform technology audits and assess risk especially for an organization that spans states and borders
  • Reduced expenses: Collaboration coupled with your compliance initiatives lessens the cost of compliance and the burden on your bottom-line

So, despite how unlikely the marriage may seem take a closer look at your compliance initiatives and identify the areas that collaboration can simplify. Talk about making good business sense…just say yes.

Has collaboration been successfully employed in your organization? How are you streamlining your compliance initiatives? We would love to hear from you!

  • Print
  • Digg
  • Twitter
  • Facebook

Observations from BarcampBank Chicago

Brad December 14th, 2009 View Comments

Last Friday, I attended my fourth BarcampBank. It was in a suburban area of Chicago (Naperville) and the event was located at the Illnois Credit Union League offices. It is always interesting to see the slight differences in how these events come to life but this event, for me, didn’t disappoint. There were about twenty participants for the day and everyone else was new to the whole Barcamp vibe and experience.

BCBChi

I was happy to see that there was a nice range of discussions that didn’t all center around social media (which has become a consistent topic at this events). There were topics ranging from marketing segments, what’s the future of the financial industry & assocations/leagues, Board of Director diversity and even a little compliance talk (yay!).

The day went by really fast and I left in a rush and didn’t get a chance to adequately thank everyone for the good discussions and their hospitality but I truly had a great time. I really believe that conferences should shift a major portion of their agendas to this crowd-sourced, roundtable format. I tried to take some notes during the event and had my snazzy pen taking up all the good audio points so I’ll include the first discussion of the day on what became titled as “Social Media 102 | Case Studies & Examples.”

Note: Takes about twenty seconds for audio to load and you can click around on the embedded page below to fast forward to that part of the conversation (cool eh?)

Also, here are some more pictures from the event. Thanks to Carla Day, Stacy Dugan, and Christopher Morris on the hospitality and running such a great first event in Chicago!

  • Print
  • Digg
  • Twitter
  • Facebook

Compliance as Security: The Root of Insanity

The Community December 13th, 2009 View Comments

December 08, 2009CSO

There is an ever-increasing pressure for security executives to be a champion of compliance within their respective organizations. Given that there seem to be new or changing compliance requirements emerging on a fairly regular basis, this can be viewed as both a blessing and a curse.

As our government acquires increasing financial interests in some private business sectors, this trend may continue to escalate.

The blessing is that in some instances it gives the security function some additional leverage to drive results and deliver greater overall value. The curse is that the regulatory compliance requirements just add to the already voluminous amount of reactionary items that already exist on the security executive’s plate. The security function is an area of responsibility that already has far too many variables that cause reactionary behavior if permitted. In some organizations this additional set of variables can be the straw that breaks the camel’s back.

Great article from CSO magazine talking about how organizations just chase their tails with the regulatory framework of the month and should instead build a information security framework that is more comprehensive and proactive.

  • Print
  • Digg
  • Twitter
  • Facebook

RiskKey Template Spotlight: Vendor Management

Courtney December 3rd, 2009 View Comments

Vendor Management

Vendor Management.  Its been a hot topic over the last couple of years with examiners, and best practices require that this process be done well.  It can be a daunting task, and many organizations struggle to do it well.  A well-rounded risk assessment process is critical to managing your vendor management program.  RiskKey can help!  Our vendor management templates are one of the many templated offerings available to the RiskKey community.

Vendor Management Template

This public template will guide you in the initial due diligence phase of vendor selection.  It can also help risk assess vendors on an ongoing basis to determine which vendors and how often your vendors need to be reviewed.  For additional information, login or sign up and check it out!

  • Print
  • Digg
  • Twitter
  • Facebook