Data Risk Governance

Exploring the intersection between information security, privacy, technology and the law.

Archive for June 10th, 2009

Analysis of the FFIEC Multi-Factor Authentication Guidance

Posted by Matt on June 10, 2009

An analysis of the FFIEC Multi-Factor Authentication Guidance can be found here.

Posted in Information Security, Regulation, Risk Assessment, Risk Management & Compliance | Leave a Comment »

A Sample Risk Assessment Model for Information Security

Posted by Matt on June 10, 2009

I’ve added a sample risk assessment that was conducted to help inform a decision on whether or not to encrypt internal network traffic. While the risk assessment is specific to one company in the financial sector, the underlying risk model is broadly applicable and can be modified to suit a variety of needs.  The can also be found under the Risk Management category.

Posted in Risk Assessment, Risk Management & Compliance, Risk Models | Leave a Comment »

 
Follow

Get every new post delivered to your Inbox.