1 min read
Asset Management Lessons Learned from Morgan Stanley
Asset Management is one of the foundations of a sound Information Security Program, but it is also often neglected in the rush to replace or...

Information security programs are like onions. They have layers. Understanding the control layers of an information security program helps management of a financial institution stop seeing the program as a set of ugly policies and start seeing it as a way to provide peace of mind for themselves and for their customers.
Whenever I start working with a new customer, my brain immediately goes to “onion mode”, where I mentally start to put the controls of the institution into the right layers to identify the strengths and weaknesses of existing controls. You can also do this if you start thinking in terms of these layers. The layers and controls I look for are as follows:
By going through each of the layers above, you will start to gain a better understanding of all of the layers an attacker would need to penetrate to get to your data. If you need some help navigating these layers, please contact us at support@bedelsecurity.com.
Information Security Strategy: 5 Tips for Success
https://www.bedelsecurity.com/blog/information-security-strategy-5-tips-for-success
5 Tips for Creating an Information Security Program That Works
https://www.bedelsecurity.com/blog/5-tips-for-creating-an-information-security-program-that-works
Free Resource: Information Security Program Tasklist
https://www.bedelsecurity.com/isp-tasklist
1 min read
Asset Management is one of the foundations of a sound Information Security Program, but it is also often neglected in the rush to replace or...
1 min read
If your Information Security Program feels more like you’re constantly putting out fires than preventing them, you’re not alone. Many community banks...
1 min read
While the FFIEC has released three major guidance updates since July 2019, the FDIC has not updated its examination program to include the newer...