<?xml version="1.0" encoding="UTF-8"?>
<rss version="2.0"
	xmlns:content="http://purl.org/rss/1.0/modules/content/"
	xmlns:wfw="http://wellformedweb.org/CommentAPI/"
	xmlns:dc="http://purl.org/dc/elements/1.1/"
	xmlns:atom="http://www.w3.org/2005/Atom"
	xmlns:sy="http://purl.org/rss/1.0/modules/syndication/"
	xmlns:slash="http://purl.org/rss/1.0/modules/slash/"
	>

<channel>
	<title>The Garland Group</title>
	<atom:link href="http://www.thegarlandgroup.net/feed/" rel="self" type="application/rss+xml" />
	<link>http://www.thegarlandgroup.net</link>
	<description></description>
	<lastBuildDate>Tue, 31 Aug 2010 03:11:25 +0000</lastBuildDate>
	<generator>http://wordpress.org/?v=abc</generator>
	<language>en</language>
	<sy:updatePeriod>hourly</sy:updatePeriod>
	<sy:updateFrequency>1</sy:updateFrequency>
			<item>
		<title>Success Story: Los Alamos National Bank</title>
		<link>http://www.thegarlandgroup.net/2010/08/26/success-story-los-almos-national-bank-2/</link>
		<comments>http://www.thegarlandgroup.net/2010/08/26/success-story-los-almos-national-bank-2/#comments</comments>
		<pubDate>Thu, 26 Aug 2010 20:33:10 +0000</pubDate>
		<dc:creator>Natasha</dc:creator>
				<category><![CDATA[Blog]]></category>
		<category><![CDATA[bank]]></category>
		<category><![CDATA[banking]]></category>
		<category><![CDATA[banks]]></category>
		<category><![CDATA[Compliance]]></category>
		<category><![CDATA[FFIEC]]></category>
		<category><![CDATA[IT Audit]]></category>
		<category><![CDATA[IT Security]]></category>
		<category><![CDATA[mobile banking]]></category>
		<category><![CDATA[Risk Assessment]]></category>
		<category><![CDATA[RiskKey]]></category>
		<category><![CDATA[Security]]></category>

		<guid isPermaLink="false">http://www.thegarlandgroup.net/?p=1893</guid>
		<description><![CDATA[At A Glance
Organization: Los Alamos National Bank (LANB)
Industry: Banking – LANB provides full-service banking (including deposit accounts, consumer, safe deposit box rentals; commercial and real estate loans; international services including currency exchange and wires; trust and investment services).
Solution:

Comprehensive IT FFIEC/COBIT audit 
Vulnerability Testing
Penetration Testing
Review of technology department’s services, security, infrastructure and future objectives

Benefits:

Improved   [...]]]></description>
			<content:encoded><![CDATA[<p><strong><span style="text-decoration: underline;">At A Glance</span></strong></p>
<p><strong>Organization:</strong> Los Alamos National Bank (LANB)</p>
<p><strong>Industry:</strong> Banking – LANB provides full-service banking (including deposit accounts, consumer, safe deposit box rentals; commercial and real estate loans; international services including currency exchange and wires; trust and investment services).</p>
<p><strong>Solution:</strong></p>
<ul>
<li><strong>Comprehensive IT FFIEC/COBIT audit</strong><strong> </strong></li>
<li><strong>Vulnerability Testing</strong></li>
<li><strong>Penetration Testing</strong></li>
<li><strong>Review of technology department’s services, security, infrastructure and future objectives</strong></li>
</ul>
<p><strong>Benefits:</strong></p>
<ul>
<li>Improved      Security &#8212; both physical and information</li>
<li>Continuous      Compliance with FFIEC</li>
<li>Improved      Risk Awareness Across the Bank</li>
<li>Refined      Business Processes, Standards and Policies</li>
</ul>
<p><strong>“</strong><strong>The key to our success in any endeavor, whether regulatory requirement or need based, is the importance of f</strong><strong>inding a partner that understands our needs, collaborates and communicates well the needs and potential solutions to the challenges we are faced with.”  Michelle Sturgeon, IT Group of LANB</strong></p>
<p>Los Alamos National Bank (LANB) was established in June 1963 by a group of local investors who saw the need for a convenient, full-service community bank.  Now one of the largest and strongest banks in the state of New Mexico, LANB continues to be locally owned and operated by Trinity Capital Corporation (TCC), a one-bank holding company.  LANB has 6 locations in Northern New Mexico, provides careers for over 300 banking professionals and current assets over $1.6 billion.  In November of 2000, Los Alamos National Bank was the first corporation in New Mexico, as well as the first bank in the nation, to be awarded the Malcolm Baldrige National Quality Award.  They are committed to their customers and to those activities that foster a better quality of life in the communities they serve.</p>
<p>“Like all financial institutions, we face ever changing regulatory requirements and pressures.” said Michelle Sturgeon of the LANB IT Group.  “…our organization was growing rapidly and the direction and complexity of our technology and services were also changing.  In an effort to ensure strong implementation, proper risk management and best practices were in place, it was determined that a knowledgeable 3<sup>rd</sup> party should be brought in for an objective look at the services, security, infrastructure and future direction of the technology department.” LANB’s goal is to provide individuals with the best financial products available, combined with excellent customer service.  Excellent customer service entailed secure banking and ensuring they minimized any risks to their customer’s information. In an information age they needed to find a solution that would help them do this.</p>
<p>The Garland Group (TGG) delivered a comprehensive IT FFIEC/COBIT audit.  This included providing LANB with a thorough audit and risk management evaluation to ensure they were following effective information technology (IT) processes.  TGG also provided LANB with an overall risk profile of their bank so they could understand how their processes and technologies impact their business operations and implement measures to mitigate risk.  TGG has also completed internal vulnerability testing and external penetration testing for LANB.</p>
<p>“The turnaround time has always been satisfactory and we are very happy with the service [TGG] has provided us,” said Sturgeon. The key to our success in any endeavor, whether regulatory or need based, is the importance of finding a partner that understands our needs, then collaborates and communicates those needs and potential solutions to our challenges.  TGG is respected by our regulators, industry peers and are constantly up to date on industry trends, developments and solutions.”</p>
<p>The Garland Group used its expertise to deliver improved security – physical and information, business processes, configurations and policies at LANB.  Los Alamos National Bank also implemented RiskKey and employs it for their IT Audits to monitor and track supporting documents and create an audit history.</p>
<p>The Garland Group ensured that LANB was compliant with their changing regulatory environment. “…[The Garland Group] has made us better.” said Sturgeon. “Their solutions provided us with the competent advice we needed to maintain our edge in a dynamic regulatory environment.  Whether it has been in our approach, awareness or solution implementations,  TGG helps us maintain the edge we need to successfully operate in this dynamic environment filled with risks that did not exist a few years ago.”</p>
<p>Los Alamos National Bank has been a client for over five years and continues to use The Garland Group today for their annual third party information technology audits.</p>
]]></content:encoded>
			<wfw:commentRss>http://www.thegarlandgroup.net/2010/08/26/success-story-los-almos-national-bank-2/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>Webinar &#8211; Social Media and Compliance Part I</title>
		<link>http://www.thegarlandgroup.net/2010/08/09/webinar-social-media-and-compliance-part-i/</link>
		<comments>http://www.thegarlandgroup.net/2010/08/09/webinar-social-media-and-compliance-part-i/#comments</comments>
		<pubDate>Mon, 09 Aug 2010 15:00:56 +0000</pubDate>
		<dc:creator>Brad</dc:creator>
				<category><![CDATA[Blog]]></category>
		<category><![CDATA[banking]]></category>
		<category><![CDATA[Compliance]]></category>
		<category><![CDATA[disclosures]]></category>
		<category><![CDATA[privacy]]></category>
		<category><![CDATA[Social Media]]></category>
		<category><![CDATA[Social Networking]]></category>

		<guid isPermaLink="false">http://www.thegarlandgroup.net/?p=1877</guid>
		<description><![CDATA[Thanks to all that were able to attend our webinar last Friday on Social Media and Compliance.  It was our highest attended to date. If you are wanting the slides for the presentation, you can download the PDF here. Next month, September 3rd, we will be continuing this topic by showing some examples of [...]]]></description>
			<content:encoded><![CDATA[<p>Thanks to all that were able to attend our webinar last Friday on <strong>Social Media and Compliance</strong>.  It was our highest attended to date. If you are wanting the slides for the presentation, you can <a href="http://www.thegarlandgroup.net/assets//2010/08/Social-Media-Compliance-Prod.pdf">download the PDF here</a>. Next month, <strong>September 3rd</strong>, we will be continuing this topic by showing some examples of policies and technologies that are affecting this space.</p>
<p><object width="500" height="281" id="wistia_163206" classid="clsid:D27CDB6E-AE6D-11cf-96B8-444553540000"><param name="movie" value="http://embed.wistia.com/flash/embed_player_v1.1.swf"/><param name="allowfullscreen" value="true"/><param name="allowscriptaccess" value="always"/><param name="wmode" value="opaque"/><param name="flashvars" value="videoUrl=http://embed.wistia.com/deliveries/e411b8f2d1353f3fa4bfd5aed55447b35a3c06ea.bin&#038;stillUrl=http://embed.wistia.com/deliveries/95488286f015e1a993b7ddee2a3c728cf105c060.bin&#038;unbufferedSeek=false&#038;controlsVisibleOnLoad=false&#038;autoPlay=false&#038;playButtonVisible=true&#038;embedServiceURL=http://distillery.wistia.com/x&#038;accountKey=wistia-production_1505&#038;mediaID=wistia-production_163206&#038;mediaDuration=1828.5"/><embed src="http://embed.wistia.com/flash/embed_player_v1.1.swf" width="500" height="281" name="wistia_163206" type="application/x-shockwave-flash" allowfullscreen="true" allowscriptaccess="always" wmode="opaque" flashvars="videoUrl=http://embed.wistia.com/deliveries/e411b8f2d1353f3fa4bfd5aed55447b35a3c06ea.bin&#038;stillUrl=http://embed.wistia.com/deliveries/95488286f015e1a993b7ddee2a3c728cf105c060.bin&#038;unbufferedSeek=false&#038;controlsVisibleOnLoad=false&#038;autoPlay=false&#038;playButtonVisible=true&#038;embedServiceURL=http://distillery.wistia.com/x&#038;accountKey=wistia-production_1505&#038;mediaID=wistia-production_163206&#038;mediaDuration=1828.5"></embed></object><script src="http://embed.wistia.com/embeds/v.js" charset="ISO-8859-1"></script><script>if(!navigator.mimeTypes['application/x-shockwave-flash'])Wistia.VideoEmbed('wistia_163206',500,281,{videoUrl:'http://embed.wistia.com/deliveries/e411b8f2d1353f3fa4bfd5aed55447b35a3c06ea.bin',stillUrl:'http://embed.wistia.com/deliveries/95488286f015e1a993b7ddee2a3c728cf105c060.bin',distilleryUrl:'http://distillery.wistia.com/x',accountKey:'wistia-production_1505',mediaId:'wistia-production_163206',mediaDuration:1828.5})</script></p>
<p>Thanks everyone!</p>
]]></content:encoded>
			<wfw:commentRss>http://www.thegarlandgroup.net/2010/08/09/webinar-social-media-and-compliance-part-i/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
<enclosure url="http://embed.wistia.com/deliveries/e411b8f2d1353f3fa4bfd5aed55447b35a3c06ea.bin" length="38736188" type="video/mp4" />
		</item>
		<item>
		<title>Electronic Workpapers &amp; Preparing for an Audit</title>
		<link>http://www.thegarlandgroup.net/2010/08/02/electronic-workpapers-preparing-for-an-audit/</link>
		<comments>http://www.thegarlandgroup.net/2010/08/02/electronic-workpapers-preparing-for-an-audit/#comments</comments>
		<pubDate>Mon, 02 Aug 2010 06:00:30 +0000</pubDate>
		<dc:creator>dan</dc:creator>
				<category><![CDATA[Blog]]></category>
		<category><![CDATA[auditor]]></category>
		<category><![CDATA[documentation]]></category>
		<category><![CDATA[electronic]]></category>
		<category><![CDATA[RiskKey]]></category>
		<category><![CDATA[workflow]]></category>
		<category><![CDATA[workpapers]]></category>

		<guid isPermaLink="false">http://www.thegarlandgroup.net/?p=1842</guid>
		<description><![CDATA[Let me begin by introducing myself, I’m Dan Nerada and was very excited to accept a position with The Garland Group earlier this year.  I come to The Garland Group with over twenty-five plus years internal bank audit experience.  My years in banking consisted in working for one south Texas bank and two [...]]]></description>
			<content:encoded><![CDATA[<p><img align=right vspace=5 hspace=5 src="http://www.thegarlandgroup.net/assets//2010/08/dan-002-225x300.jpg" />Let me begin by introducing myself, I’m Dan Nerada and was very excited to accept a position with The Garland Group earlier this year.  I come to The Garland Group with over twenty-five plus years internal bank audit experience.  My years in banking consisted in working for one south Texas bank and two banks within the north Dallas area.  During my banking years, I spent the entire time as an Internal Audit manager.  Needless to say, switching from an internal bank auditor, to an external IT auditor has enlightened me to see both sides of the audit experience.  </p>
<p>Looking back, whenever it was time to prepare for an external audit, document preparation was always a major event!  I would spend days, even weeks, gathering information and camping out at a copy machine, only to run out of paper!  After all that copying, now it was time to arrange all this information in some logical order.  Needless to say, having information in order before the auditors arrived would save a great deal of time and hopefully make the audit run smoother.  As I have now experienced from the other side, that remains true.  I can definitely say preparation sets the tone for the entire engagement.  </p>
<p>My last engagement as an internal bank auditor introduced me to RiskKey provided by The Garland Group.  This program truly cut down what use to be weeks of document preparation to simply only a few hours of downloading documents.  It was simple, quick and efficient, and this is only one of the applications available within RiskKey.  As a prior internal bank auditor, efficiency is the key to run a productive department and also in preparing for an external audit.  Checkout RiskKey, it’s a tool that will increase your department’s efficiencies.</p>
]]></content:encoded>
			<wfw:commentRss>http://www.thegarlandgroup.net/2010/08/02/electronic-workpapers-preparing-for-an-audit/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>Achieving Security Efficiency</title>
		<link>http://www.thegarlandgroup.net/2010/07/27/achieving-security-efficiency/</link>
		<comments>http://www.thegarlandgroup.net/2010/07/27/achieving-security-efficiency/#comments</comments>
		<pubDate>Tue, 27 Jul 2010 07:25:44 +0000</pubDate>
		<dc:creator>Natasha</dc:creator>
				<category><![CDATA[Blog]]></category>
		<category><![CDATA[bank]]></category>
		<category><![CDATA[banking]]></category>
		<category><![CDATA[banks]]></category>
		<category><![CDATA[Banktastic]]></category>
		<category><![CDATA[Compliance]]></category>
		<category><![CDATA[credit cards]]></category>
		<category><![CDATA[Credit Union]]></category>
		<category><![CDATA[FFIEC]]></category>
		<category><![CDATA[Information Security]]></category>
		<category><![CDATA[IT Audit]]></category>
		<category><![CDATA[IT Security]]></category>
		<category><![CDATA[Risk Assessment]]></category>
		<category><![CDATA[RiskKey]]></category>

		<guid isPermaLink="false">http://www.thegarlandgroup.net/?p=1822</guid>
		<description><![CDATA[Recently the Ponemom Insitute released its’ latest research on “Benchmarking Information Security Efficiency” Their goal was to help organizations determine the “most operationally efficient route to their desired security posture.” I’d hope that their desire would be continuous compliance. The research showed five key areas that affected security efficiency:
Appoint a CISO or organizational leader for [...]]]></description>
			<content:encoded><![CDATA[<p>Recently the Ponemom Insitute released its’ latest research on <a href="https://ponemon.webex.com/ec0605lb/eventcenter/recording/recordAction.do;jsessionid=7NLwMTvLBK5bnF5mSJFJ3tRXtvLybZ7G4Q3WbLlR1V41GljxV1x9!263384053?theAction=poprecord&amp;actname=%2Feventcenter%2Fframe%2Fg.do&amp;actappname=ec0605lb&amp;renewticket=0&amp;renewticket=0&amp;apiname=lsr.php&amp;entappname=url0107lb&amp;needFilter=false&amp;&amp;isurlact=true&amp;rID=2495262&amp;entactname=%2FnbrRecordingURL.do&amp;rKey=3721c8ad515df4d1&amp;recordID=2495262&amp;siteurl=ponemon&amp;rnd=6122528725&amp;SP=EC&amp;AT=pb&amp;format=short">“Benchmarking Information Security Efficiency”</a> Their goal was to help organizations determine the “most operationally efficient route to their desired security posture.” I’d hope that their desire would be continuous compliance. The research showed five key areas that affected security efficiency:</p>
<p><strong>Appoint a CISO or organizational leader for information security:</strong><br /> Every project needs a champion. Your security and compliance program is no different. Security programs that garner support not just from IT but from departments across the enterprises improve their security outlook.</p>
<p><strong>Initiate training and awareness programs on data protection and security for end-users:</strong><br /> Such great advice that many organizations take for granted. Policies and procedures cannot be followed and maintained if your staff does not know about them. Organizations must keep retraining as they hire new employees as well as to ensure security awareness is always at the forefront.<br /> <strong><br /> Achieve an organizational culture that respects privacy and data protection:</strong><br /> Cultural change does not happen overnight. Top level management must first define and document the organization’s desired security and compliance culture. They then need to implement programs and activities that communicate and reinforce this desired security compliance culture all departments across the enterprise.</p>
<p><strong>Obtain executive-level support for security:</strong><br /> Agreed! Security compliance is not just the IT or Compliance department’s responsibility and transcends CIOs to the CEO and board of directors. The organization with top executive 100% engaged in its security compliance posture has an immediate advantage.</p>
<p><strong>Deploy strong endpoint controls:</strong><br /> Choosing the right technology for your security programs is critical to achieving continuous compliance. Pick a solution that provides maximum security, automation, and flexibility.</p>
]]></content:encoded>
			<wfw:commentRss>http://www.thegarlandgroup.net/2010/07/27/achieving-security-efficiency/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>Understanding Continuous Compliance</title>
		<link>http://www.thegarlandgroup.net/2010/06/23/understanding-continuous-compliance/</link>
		<comments>http://www.thegarlandgroup.net/2010/06/23/understanding-continuous-compliance/#comments</comments>
		<pubDate>Wed, 23 Jun 2010 17:44:20 +0000</pubDate>
		<dc:creator>Natasha</dc:creator>
				<category><![CDATA[Blog]]></category>
		<category><![CDATA[bank]]></category>
		<category><![CDATA[banking]]></category>
		<category><![CDATA[banks]]></category>
		<category><![CDATA[Compliance]]></category>
		<category><![CDATA[Credit Union]]></category>
		<category><![CDATA[FFIEC]]></category>
		<category><![CDATA[Information Security]]></category>
		<category><![CDATA[RiskKey]]></category>
		<category><![CDATA[Security]]></category>

		<guid isPermaLink="false">http://www.thegarlandgroup.net/?p=1736</guid>
		<description><![CDATA[
Continuous Compliance means developing a pro-active, enterprise risk assessment and audit program. In the wake of our current economy, security threats, and the customer’s need for privacy, financial institutions must implement continuous compliance programs to be successful.
It enables transparency as organizations have a clear picture of the risks their organization may be exposed to and [...]]]></description>
			<content:encoded><![CDATA[<p><a href="http://www.thegarlandgroup.net/assets//2010/06/compliance.jpg" rel="lightbox[1736]"><img class="alignleft size-full wp-image-1738" title="compliance" src="http://www.thegarlandgroup.net/assets//2010/06/compliance.jpg" alt="" width="300" height="258" /></a></p>
<p><a href="http://www.thegarlandgroup.net/services/continuous-compliance-service/">Continuous Compliance</a> means developing a pro-active, enterprise risk assessment and audit program. In the wake of our current economy, security threats, and the customer’s need for privacy, financial institutions must implement continuous compliance programs to be successful.</p>
<p><strong>It enables transparency as organizations have a clear picture of the risks their organization may be exposed to and take measures to rectify. Organizations are able to:</strong></p>
<ul>
<li>Implement an enterprise-wide      approach to risk and compliance.</li>
<li>Continuously manage and monitor risks      across the enterprise.</li>
<li>Understand their business      environs and make insightful decisions.</li>
</ul>
<p><strong>It increases efficiency as organizations use less manpower and resources to complete audits and compliance requirements.  Organizations are able to:</strong></p>
<ul>
<li>Automate risk, audit and      compliance processes.</li>
<li>Eliminate labor intensive tasks,      thus maximizing resources and reducing cost.</li>
</ul>
<p><strong>It improves agility enabling organization to stay abreast of risks and threats. Organizations are able to:</strong></p>
<ul>
<li>Be nimble and react quickly to any      changes in business environs.</li>
<li>Implement and enforce policies      that govern the enterprise.</li>
</ul>
<p>To learn more <a href="https://garlandgroup.wufoo.com/forms/we-cant-wait-to-hear-from-you/">contact us</a> or comment below!</p>
]]></content:encoded>
			<wfw:commentRss>http://www.thegarlandgroup.net/2010/06/23/understanding-continuous-compliance/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>Finovate Video is Up!</title>
		<link>http://www.thegarlandgroup.net/2010/06/09/finovate-video-is-up/</link>
		<comments>http://www.thegarlandgroup.net/2010/06/09/finovate-video-is-up/#comments</comments>
		<pubDate>Wed, 09 Jun 2010 16:00:08 +0000</pubDate>
		<dc:creator>Brad</dc:creator>
				<category><![CDATA[Blog]]></category>
		<category><![CDATA[2010]]></category>
		<category><![CDATA[finovate]]></category>

		<guid isPermaLink="false">http://www.thegarlandgroup.net/?p=1715</guid>
		<description><![CDATA[The videos for the FinovateSpring conference have been posted and are now up.  We prepared close to 10 hours for this seven minutes and based off audience, they really liked what we did.  Thanks to Jim Bruene and Eric Mattson again for the opportunity!
[Video below]
if(!navigator.mimeTypes['application/x-shockwave-flash'])Wistia.VideoEmbed('wistia_134550',500,281,{videoUrl:'http://embed.wistia.com/deliveries/c38b692d0f08108874828a6ce796a054f44d8c56.bin',stillUrl:'http://embed.wistia.com/deliveries/b25e0f3a77804511ac9e2c23fb0b38864f5ffc2e.bin',distilleryUrl:'http://distillery.wistia.com/x',accountKey:'wistia-production_1505',mediaId:'wistia-production_134550',mediaDuration:434.77})
]]></description>
			<content:encoded><![CDATA[<p>The videos for the <a href="http://finovate.com">FinovateSpring</a> conference have been posted and are now up.  We prepared close to 10 hours for this seven minutes and based off audience, they really liked what we did.  Thanks to Jim Bruene and Eric Mattson again for the opportunity!</p>
<p>[Video below]<br />
<object width="500" height="281" id="wistia_134550" classid="clsid:D27CDB6E-AE6D-11cf-96B8-444553540000"><param name="movie" value="http://embed.wistia.com/flash/embed_player_v1.1.swf"/><param name="allowfullscreen" value="true"/><param name="allowscriptaccess" value="always"/><param name="wmode" value="opaque"/><param name="flashvars" value="videoUrl=http://embed.wistia.com/deliveries/c38b692d0f08108874828a6ce796a054f44d8c56.bin&#038;stillUrl=http://embed.wistia.com/deliveries/b25e0f3a77804511ac9e2c23fb0b38864f5ffc2e.bin&#038;unbufferedSeek=false&#038;controlsVisibleOnLoad=false&#038;autoPlay=false&#038;playButtonVisible=true&#038;embedServiceURL=http://distillery.wistia.com/x&#038;accountKey=wistia-production_1505&#038;mediaID=wistia-production_134550&#038;mediaDuration=434.77"/><embed src="http://embed.wistia.com/flash/embed_player_v1.1.swf" width="500" height="281" name="wistia_134550" type="application/x-shockwave-flash" allowfullscreen="true" allowscriptaccess="always" wmode="opaque" flashvars="videoUrl=http://embed.wistia.com/deliveries/c38b692d0f08108874828a6ce796a054f44d8c56.bin&#038;stillUrl=http://embed.wistia.com/deliveries/b25e0f3a77804511ac9e2c23fb0b38864f5ffc2e.bin&#038;unbufferedSeek=false&#038;controlsVisibleOnLoad=false&#038;autoPlay=false&#038;playButtonVisible=true&#038;embedServiceURL=http://distillery.wistia.com/x&#038;accountKey=wistia-production_1505&#038;mediaID=wistia-production_134550&#038;mediaDuration=434.77"></embed></object><script src="http://embed.wistia.com/embeds/v.js" charset="ISO-8859-1"></script><script>if(!navigator.mimeTypes['application/x-shockwave-flash'])Wistia.VideoEmbed('wistia_134550',500,281,{videoUrl:'http://embed.wistia.com/deliveries/c38b692d0f08108874828a6ce796a054f44d8c56.bin',stillUrl:'http://embed.wistia.com/deliveries/b25e0f3a77804511ac9e2c23fb0b38864f5ffc2e.bin',distilleryUrl:'http://distillery.wistia.com/x',accountKey:'wistia-production_1505',mediaId:'wistia-production_134550',mediaDuration:434.77})</script></p>
]]></content:encoded>
			<wfw:commentRss>http://www.thegarlandgroup.net/2010/06/09/finovate-video-is-up/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
<enclosure url="http://embed.wistia.com/deliveries/c38b692d0f08108874828a6ce796a054f44d8c56.bin" length="37804368" type="video/mp4" />
		</item>
		<item>
		<title>Webinar &#8211; Benefits of Virtualization and the Compliance Behind It</title>
		<link>http://www.thegarlandgroup.net/2010/06/07/webinar-benefits-of-virtualization-and-the-compliance-behind-it/</link>
		<comments>http://www.thegarlandgroup.net/2010/06/07/webinar-benefits-of-virtualization-and-the-compliance-behind-it/#comments</comments>
		<pubDate>Mon, 07 Jun 2010 15:59:50 +0000</pubDate>
		<dc:creator>Brad</dc:creator>
				<category><![CDATA[Webinars]]></category>
		<category><![CDATA[datacenters]]></category>
		<category><![CDATA[servers]]></category>
		<category><![CDATA[virtualization]]></category>
		<category><![CDATA[vmware]]></category>

		<guid isPermaLink="false">http://www.thegarlandgroup.net/?p=1710</guid>
		<description><![CDATA[Thanks to all that were able to attend our webinar last Friday on Benefits of Virtualization and the Compliance Behind It. If you are wanting the slides for the presentation, you can download the PDF and watch the video inside.]]></description>
			<content:encoded><![CDATA[<p>Thanks to all that were able to attend our webinar last Friday on <strong>Benefits of Virtualization and the Compliance Behind It</strong>.  If you are wanting the slides for the presentation, you can <a href="http://www.thegarlandgroup.net/assets//2010/05/Virtualization.pdf">download the PDF</a> here.</p>
<p><object width="500" height="281" id="wistia_133640" classid="clsid:D27CDB6E-AE6D-11cf-96B8-444553540000"><param name="movie" value="http://embed.wistia.com/flash/embed_player_v1.1.swf"/><param name="allowfullscreen" value="true"/><param name="allowscriptaccess" value="always"/><param name="wmode" value="opaque"/><param name="flashvars" value="videoUrl=http://embed.wistia.com/deliveries/8d4380dad13cece6915b851a550790afad0a109f.bin&#038;stillUrl=http://embed.wistia.com/deliveries/06ddb551cfef0325c2e51b7c90c9c40c4938b22e.bin&#038;unbufferedSeek=false&#038;controlsVisibleOnLoad=false&#038;autoPlay=false&#038;playButtonVisible=true&#038;embedServiceURL=http://distillery.wistia.com/x&#038;accountKey=wistia-production_1505&#038;mediaID=wistia-production_133640&#038;mediaDuration=1820.23"/><embed src="http://embed.wistia.com/flash/embed_player_v1.1.swf" width="500" height="281" name="wistia_133640" type="application/x-shockwave-flash" allowfullscreen="true" allowscriptaccess="always" wmode="opaque" flashvars="videoUrl=http://embed.wistia.com/deliveries/8d4380dad13cece6915b851a550790afad0a109f.bin&#038;stillUrl=http://embed.wistia.com/deliveries/06ddb551cfef0325c2e51b7c90c9c40c4938b22e.bin&#038;unbufferedSeek=false&#038;controlsVisibleOnLoad=false&#038;autoPlay=false&#038;playButtonVisible=true&#038;embedServiceURL=http://distillery.wistia.com/x&#038;accountKey=wistia-production_1505&#038;mediaID=wistia-production_133640&#038;mediaDuration=1820.23"></embed></object><script src="http://embed.wistia.com/embeds/v.js" charset="ISO-8859-1"></script><script>if(!navigator.mimeTypes['application/x-shockwave-flash'])Wistia.VideoEmbed('wistia_133640',500,281,{videoUrl:'http://embed.wistia.com/deliveries/8d4380dad13cece6915b851a550790afad0a109f.bin',stillUrl:'http://embed.wistia.com/deliveries/06ddb551cfef0325c2e51b7c90c9c40c4938b22e.bin',distilleryUrl:'http://distillery.wistia.com/x',accountKey:'wistia-production_1505',mediaId:'wistia-production_133640',mediaDuration:1820.23})</script></p>
<p>Thanks everyone!</p>
]]></content:encoded>
			<wfw:commentRss>http://www.thegarlandgroup.net/2010/06/07/webinar-benefits-of-virtualization-and-the-compliance-behind-it/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
<enclosure url="http://embed.wistia.com/deliveries/8d4380dad13cece6915b851a550790afad0a109f.bin" length="35704892" type="video/mp4" />
		</item>
		<item>
		<title>RiskKey &#8211; New and Improved Reporting</title>
		<link>http://www.thegarlandgroup.net/2010/06/02/riskkey-new-and-improved-reporting/</link>
		<comments>http://www.thegarlandgroup.net/2010/06/02/riskkey-new-and-improved-reporting/#comments</comments>
		<pubDate>Wed, 02 Jun 2010 17:00:47 +0000</pubDate>
		<dc:creator>Brad</dc:creator>
				<category><![CDATA[RiskKey]]></category>
		<category><![CDATA[changes]]></category>
		<category><![CDATA[Development]]></category>
		<category><![CDATA[reports]]></category>
		<category><![CDATA[updates]]></category>

		<guid isPermaLink="false">http://www.thegarlandgroup.net/?p=1693</guid>
		<description><![CDATA[
Hi everybody, 
Hope you all had a great Memorial Day weekend.  We wanted to share with you the updates that are coming out today.  Along with a longer list of updates (see bottom of our dev updates post for details) we are happy to announce our newly organized reporting area within RiskKey.  [...]]]></description>
			<content:encoded><![CDATA[<p><img src="http://img.skitch.com/20100601-qpa5rmg4gwrng23rfmknsa92pq.jpg" alt="IT Compliance (demo) | Company Recommendations (Consultants Only) - (Build 20100401064631)"/></p>
<p>Hi everybody, </p>
<p>Hope you all had a great Memorial Day weekend.  We wanted to share with you the updates that are coming out today.  Along with a longer list of updates (<a href="https://garlandgroup.tenderapp.com/discussions/announcements/7-development-changes-for-6-2-10">see bottom of our dev updates post for details</a>) we are happy to announce our newly organized reporting area within <a href="http://riskkey.com">RiskKey</a>.  </p>
<p><img src="http://img.skitch.com/20100601-q4jkxx7gy387f3kmy8qumcd3nb.jpg" alt="new-reports"/></p>
<p>With reports, we want to create a better alignment with the different project types that come within RiskKey (project mgmt, risk assessment, and audit workflows).  So our reports reflect that with the new category headers.  The only additional category we created was the &#8216;Recommendation Reports&#8217; area due to the recommendations (AKA findings) are in both risk assessments and audit projects.</p>
<h3>Reports Permissions by Project Type</h3>
<p>With all that said, we also included the permissions to only be able to run reports depending on the type of project that you selected.  Here&#8217;s an example of a &#8216;project management&#8217; type project.  See how the other reports are grayed out because they don&#8217;t apply:</p>
<p><img src="http://img.skitch.com/20100601-8tmcnh53gkewj1qr7m88541dr6.jpg" alt="reporting"/><br />
<em>You will be unable to run grayed out options.</em></p>
<h3>New Reports Added</h3>
<p>While we were at it, we added some new reports to use at your disposal.  Here in a brief description of each of the new reports:</p>
<ul>
<li>
Requested Documents &#8211; This is a printable document request list for the project you&#8217;re in.  This will allow you to see the status of all files being requested and additional details like fulfilled, person responsible, and file name.
</li>
<li>
By Starred Items &#8211; See screenshot below for where you can &#8217;star&#8217; an assessment or objective item.  This report will run any assessment or objective report (depending on which report you run) and show you which items are currently starred.  Great for going back to the ones that you need to follow back up on.</li>
<p><img src="http://img.skitch.com/20100601-r4ms5w5sqk54emmcwqebjf6bwb.jpg" alt="IT Compliance (demo) | Assessments - (Build 20100401064631)"/></p>
<li>
By Current Status &#8211; This report was created in combination of our folks and some user feedback to create a report that will really knock your socks off.  This allows you to see the current status of any recommendation within a project.  The categories statuses include: Past Due, Outstanding, Incomplete, and Completed Recommendations.  This is a recommendations report.  <a href="http://skitch.com/bradgarland/dggyh/it-compliance-demo-company-recommendations-consultants-only-build-20100401064631">See the screenshot</a>.</li>
</ul>
<p>Lastly, within the reports we spent some time improving the readability by increasing the font sizes, bolding some category headings, and reorganizing the information in a more easy, readable way.  </p>
<p>We hope you like what we&#8217;ve done!</p>
]]></content:encoded>
			<wfw:commentRss>http://www.thegarlandgroup.net/2010/06/02/riskkey-new-and-improved-reporting/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>Success Story: Lubbock National Bank</title>
		<link>http://www.thegarlandgroup.net/2010/05/25/success-story-lubbock-national-bank/</link>
		<comments>http://www.thegarlandgroup.net/2010/05/25/success-story-lubbock-national-bank/#comments</comments>
		<pubDate>Tue, 25 May 2010 15:36:01 +0000</pubDate>
		<dc:creator>Natasha</dc:creator>
				<category><![CDATA[Blog]]></category>
		<category><![CDATA[bank]]></category>
		<category><![CDATA[banking]]></category>
		<category><![CDATA[banks]]></category>
		<category><![CDATA[Banktastic]]></category>
		<category><![CDATA[Compliance]]></category>
		<category><![CDATA[Information Security]]></category>
		<category><![CDATA[Innovation]]></category>
		<category><![CDATA[IT]]></category>
		<category><![CDATA[IT Audit]]></category>
		<category><![CDATA[IT Security]]></category>
		<category><![CDATA[Lubbock National Bank]]></category>
		<category><![CDATA[Risk]]></category>
		<category><![CDATA[Risk Assessment]]></category>
		<category><![CDATA[RiskKey]]></category>
		<category><![CDATA[Security]]></category>

		<guid isPermaLink="false">http://www.thegarlandgroup.net/?p=1689</guid>
		<description><![CDATA[At A Glance
Organization: Lubbock National Bank (LNB)
Industry: Banking
Solution: Full Risk-Based Technology Controls Review &#38; Risk Assessment
Benefits:

Simplified risk and audit assessment process
Clear picture of LNB’s compliance and security standards
Standardized policies and procedures across locations

“RiskKey was great to use and simplified the entire assessment and audit process”  Eddie Schulz, COO of LNB
Lubbock National Bank (LNB) has operated [...]]]></description>
			<content:encoded><![CDATA[<p><strong><span style="text-decoration: underline;">At A Glance</span></strong></p>
<p><strong>Organization:</strong> Lubbock National Bank (LNB)</p>
<p><strong>Industry:</strong> Banking</p>
<p><strong>Solution:</strong> Full Risk-Based Technology Controls Review &amp; Risk Assessment</p>
<p><strong>Benefits:</strong></p>
<ul>
<li>Simplified risk and audit assessment process</li>
<li>Clear picture of LNB’s compliance and security standards</li>
<li>Standardized policies and procedures across locations</li>
</ul>
<p><strong>“RiskKey was great to use and simplified the entire assessment and audit process”  Eddie Schulz, COO of LNB</strong></p>
<p>Lubbock National Bank (LNB) has operated in the Lubbock Market for over 90 years.  As a commercial bank it serves the Lubbock market as well as the Bryan/College Station and Austin markets under the name of Commerce National Bank.  With over 20,000 customers in these markets today, LNB is committed to growing their bank by providing small business customers with strong retail products.</p>
<p>An integral factor in LNB’s business strategy has always been to “provide customers with a trusted place to manage and grow their hard-earned money.” With the current business landscape this is even more challenging.  Everyday there’s a new security threat, new risk levels, as well as even more stringent regulations to comply with.  LNB needed to implement initiatives to ensure they stayed true to their mission.</p>
<p>“We needed to have a strong audit company to do an extensive audit on our technology,” said Eddie Schulz, COO of LNB. “We wanted to make sure that the bank was in compliance and practicing good security and technology standards.  The Garland Group offered the exact comprehensive audit the bank needed.”</p>
<p>The Garland Group delivered a Full Risk-Based Technology Controls Review &amp; Risk Assessment to LNB. This included a thorough risk assessment and policy review. We also did a penetration test on their technology infrastructure and continue to day with quarterly penetration tests. LNB was able to utilize our SaaS application RiskKey to give them the assurance they needed that their customers could trust them to protect their investments.</p>
<p>“RiskKey was great to use and simplified the entire assessment and audit process,” said Schulz. “The Garland Group gave us a complete technology audit and penetration testing.  We were very pleased with the response from our compliance team.”</p>
<p>After the engagement LNB was able to know exactly how the bank measured up with regards to their technology standards and what they needed to do to close any gaps in those standards.  “The Garland Group allowed us to understand the overall scope of our technology issues and how to shape the banks standards in policy and procedures,” said Schulz. “We immediately implemented the recommended new standards on polices and standardized our procedures across locations.”</p>
]]></content:encoded>
			<wfw:commentRss>http://www.thegarlandgroup.net/2010/05/25/success-story-lubbock-national-bank/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>Virtualization?  Why Not!</title>
		<link>http://www.thegarlandgroup.net/2010/05/17/virtualization-why-not/</link>
		<comments>http://www.thegarlandgroup.net/2010/05/17/virtualization-why-not/#comments</comments>
		<pubDate>Mon, 17 May 2010 15:00:46 +0000</pubDate>
		<dc:creator>Heath</dc:creator>
				<category><![CDATA[Blog]]></category>
		<category><![CDATA[costs]]></category>
		<category><![CDATA[data center]]></category>
		<category><![CDATA[hardware]]></category>
		<category><![CDATA[servers]]></category>
		<category><![CDATA[virtualization]]></category>

		<guid isPermaLink="false">http://www.thegarlandgroup.net/?p=1594</guid>
		<description><![CDATA[
Well, I&#8217;ll tell you.  Let me start by saying I do think the overall benefits of Virtualization heavily outweigh the risks.
Since I don&#8217;t want this to be a doom and gloom blog, I&#8217;ll start with the positives of Virtualization. 

Less hardware costs for servers and maintenance, but routers and switches too with VLANing.
Saving valuable physical [...]]]></description>
			<content:encoded><![CDATA[<p><img src="http://img.skitch.com/20100507-b2am595sq28m1b3pa7ucae92xd.jpg" alt="virtualize"/></p>
<p>Well, I&#8217;ll tell you.  Let me start by saying I do think the overall benefits of <a href="http://en.wikipedia.org/wiki/Hardware_virtualization#Reasons_for_virtualization">Virtualization</a> heavily outweigh the risks.<br />
Since I don&#8217;t want this to be a doom and gloom blog, I&#8217;ll start with the positives of Virtualization. </p>
<ul>
<li>Less hardware costs for servers and maintenance, but routers and switches too with VLANing.</li>
<li>Saving valuable physical space in server rooms.</li>
<li>Going green with energy consumption and generator/battery backups.</li>
<li>Normalizing platforms across multiple systems.</li>
<li>Agility in an environment.  Imagine if you had a server crash, you can just boot up a Virtual Machine and like that you are good to go!</li>
<li>Saving money in licensing.  I&#8217;m not an expert at all on licensing, but I know vendors have laxed on licensing because they are real sure how to manage it with virtualization.</li>
</ul>
<p>Now, I&#8217;ll focus more on the potential risks of Virtualization because they aren&#8217;t discussed as much as the benefits, and we are security people&#8230;<strong>it&#8217;s what we do!</strong></p>
<ul>
<li>Currently there are no definite standards yet, especially from the FFIEC, but we haven&#8217;t even gotten any standards to audit to from PCI or DISA.  There are some some best practices docs from DISA in their Virtualization STIG (search Virtualization on DISA&#8217;s website) and VMWare&#8217;s best practices (Google:  VMWare Best Practices)</li>
<li>In virtualization transparency is reduced so it is hard to find where applications are running at a specific time.  In other words, visibility within an environment is blurred. </li>
<li>Applications must be secure within themselves.  What I mean is that any piece of hardware that is compromised, and data on that server can be compromised as well.  So if your football bowl picks.xls is compromised and it is on the same server as customer data, you may be S.O.L.</li>
<li>Virtual Machine Managers have extreme access to the network like never before.  Consider segregations of duties for different IT staff managing network and core servers on separate VM installs.</li>
<li>VM migrations present risk because data may be changed during the migration.  Consider encrypting channels, heavily restricing access to who can migrate VM&#8217;s, or isolate LAN&#8217;s from each other. </li>
<li>With virtual security appliances Real Time Monitoring needs to always have dedicated resources.  Or else Anti-Virus or internal Intrusion Detections may not be getting the resources to operate in real time.</li>
<li>Cloud Computing is a risk in itself.  I do believe there is risk in cloud computing. I don&#8217;t believe it is dire as CNET, but this is a <a href="http://news.cnet.com/8301-1001_3-20001921-92.html">good article</a>.</li>
<li>Currently there are multiple CVE&#8217;s associated with virtualization and may be mitigated.  Just be sure your internal vulnerability scans check for virtualization risks.</li>
</ul>
<p>Don&#8217;t let this scare you away!  I&#8217;m excited about the potential of virtualization and the $$$ savings are hard to argue with.  Good Luck Virtualizing and don&#8217;t forget about our upcoming <strong>June 4th webinar on Virtualization and the Compliance Around it</strong>!</p>
]]></content:encoded>
			<wfw:commentRss>http://www.thegarlandgroup.net/2010/05/17/virtualization-why-not/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
	</channel>
</rss>
