Risk and Security Workshops
These workshops are designed to introduce current risk and information security hot topics to Information Security Officers and Network Administrators.
Principles of Information Security
Introductory one day class for Information Security Officers, Network Administrators and anyone else working with technology and security in a financial institution. This class will address governing bodies, their requirements, and expectations. We will look at types of policies , what they include , and other security stances you should consider.
Areas of instruction will include:
Mandates
- Regulatory Guidance
- GLBA (501b)
- FFIEC
- Vendor best practices
- Audit/Exam experiences
Physical/System Security
- Security Policies
- User, email, computer, laptop, cell phone , and remote access policies
- Security Controls - User
- Password policies
- Employee training
- Security Controls - Vendor
- SAS 70
- Financials
- Contracts
- Independent tests
- Security Controls - Physical/Logical
- Wireless
- Encryption
- Other security controls
Information Security in Action
Introductory one day class for Information Security Officers, Network Administrators and anyone else working with technology and security in a financial institution. This class will take the principles of security and discuss ways to enforce, check, and report on them. With information security it is not enough to have a policy or procedure in place, but you must have a way to monitor, test, and/or report on the success of policies and procedures.
Areas of instruction will include:
- Review of information security principles
- Network Hardening - concepts and best practice
- Perimeter - Firewalls/IDS/IPS
- Host - Server
- Host - Workstation
- Host - Mobile devices
- Checklist of reports to review
- Data - retention and disposal
- Viruses/spam/malware
- Delegate control of admin roles
- Assigning security rights
- Admin accounts
- Active Directory - group policy settings
- Server software
- Backups & backup policy
- Patch management/MBSA
- Technology steering committees
Risk and Security - The Risk Management Process in Theory and Practice
Risk management is a battle all institutions must face. In this one day workshop aimed at Information Security Officers, we will discuss the risk management process as it relates to risk assessments and the requirements set forth in all 12 FFIEC IT Handbooks.
Areas of instruction will include:
- Risk Identification
- Inherent vs. residual
- Assessment
- Threats
- Impact vs. probability
- Prioritization
- Application of controls
- Avoid
- Mitigate
- Reduce
- Transfer
- Accept
- Management of program
- Assessment and adjustment
- Risk management in practice
- Information security
- Disaster recovery
- Remote deposit capture
IT Audits and Examinations - Real World Best Practices for Preparation and Response
The audit and examination process probably causes more anxiety for financial instructions than almost any other activity they perform. Knowing what to do in preparation for an exam, how to respond while the examiners are there, and how to follow up after the exit can ease this anxiety. We will look at auditor standards and questionnaires along with the standard exam questionnaire by various regulatory groups and lessons learned from our customers.
Areas of instruction will include:
- The Audit
- SAS 94
- BITS
- Other standards
- Defining scope of work
- Proper responses and documentation
- Response to findings
- Board of Directors reporting
- The Examination
- The examiners questionnaire
- FDIC
- OCC
- OTS
- NCUA
- Proper responses and documentation
- Response to findings
- Board of Directors reporting
- The examiners questionnaire
- Case Studies
To register for our classes, please visit our online registration form. If you have any questions, please email education@safesystems.com.
Is Your Financial Institution's Data Backup System Really Working?
Are you confident you have an effective and compliant disaster recovery plan?
Client Testimonials
“I appreciate all that Safe Systems does to keep us in compliance with the FDIC and regulators. The examiner could tell that we have worked hard on getting the IT area to where it is today. Safe Systems Managed Services made it much easier.”
Dawn Kelley
The Commercial Bank
“Safe Systems Managed Services offers a vast array of options to help us maximize our IT staff’s time, productivity, and budget in a way that is completely scalable to meet our specific needs as we grow and change.”
Leesa Anderson
State Bank of Cochran
“The focus on financial institutions has allowed Safe Systems to gain invaluable experience that we can tap into and learn from as we change to grow our network infrastructure to meet the needs of the bank.”
Leesa Anderson
State Bank of Cochran
“Safe Systems Managed Service is the BEST thing since sliced bread!!! GREAT JOB!!”
Glenda Miller
Williamsburg First National Bank
“Safe Systems has the BEST support team …everyone is full of personality and they each have their own way of making you feel IMPORTANT!!”
Kathy Godwin
Williamsburg First National Bank
“It’s easy to talk positively about my experience with Safe Systems. EVERYONE I’ve talked to has been overwhelmingly helpful. Thanks for providing top-notch service, and always doing so in a friendly manner.”
Mathew Tomlinson
Flint Community Bank
“The expertise that Safe Systems provided during the implementation of the Bank and on the ongoing assistance they give has enabled HNB to score very well on all of our regulatory and internal audit IT examinations.”
Michael Carleton
Herald National Bank, NYC
“With Safe Systems Managed Services, patching my servers and workstations is automated, I get daily reports and my servers and workstations stay patched with the latest Microsoft Updates. Which is great for audit time!”
Robert Gay
The Bank of Bonifay
“I wanted to let you know we just completed an IT audit, and the auditors were very complementary of and impressed with your NetComply product. This was the first time they had seen it in action.”
David Reynolds
InsBank
“We always receive exemplary customer service from Safe Systems. The entire group of engineers have always provided superior courteous service. This encompasses minor problems to the complex. I believe we receive an excellent value for the dollars we spend with your company.”
Charles Knight
United Americas Bank
“I could not ask for a better company to put my trust in when maintaining my network. As a Platinum customer, I don't worry about anything because I know I have knowledge, experience and professionalism standing behind me with the Safe Systems staff. Wouldn't go anywhere else!”
Nicole Rinehart
American Pride Bank
