Cosaint Inc. - Security Through Knowledge

FREE TRIAL OR WEB DEMO

Overview

Course Details

SA-Centers

- Courses

- Policy Affirmation

- Document & Link Library

- Security Reminder Service

- Reporting & Administration

- Client "Branding"

- System Requirements

- Integration

Other Delivery Options

COBIT

Gramm-Leach-Bliley Act

HIPAA Privacy & Security

ISO 17799

PCI Data Security Standard

Sarbanes-Oxley Act

Shared Assessments

 
Best Practices for Security Awareness Training

Company Background

Clients

Management

Partners Program

Opportunities

Contact Us

Home


Financial Institution Shared Assessments Program

 

The Financial Institution Shared Assessments Program[1] is a standard process being promoted by BITS - a non-profit industry group representing 100 of the largest financial institutions in the United States.

The process has been designed for use by financial services organizations during the evaluation of IT service providers. The standard currently includes two documents - the Agreed Upon Procedures (AUP) and the Standardized Information Gathering (SIG) questionnaire - that can be downloaded from the BITS website.

The key provision of the AUP that relates to security awareness and training is in §3.1:

All employees of the service provider's organization, and where relevant, third-party users, should be made aware of information-security threats and concerns, and should be equipped to support the organizational security policy in the course of their normal work. Users should be trained in information-security procedures and the correct use of information-processing facilities to minimize possible security threats.

The procedures also specify that the service provider should be able to prove that this requirement has been satisfied by producing an attendance document (electronic or paper) for a number of students that confirms "their attendance at the company's security awareness training." It also notes that the security awareness training attendance reports could be maintained in the employee's personnel file or in a compliance tracking tool (database).

Cosaint's courses are an ideal way to make employees and third-party users aware of security threats, and an SA-Center™ is a perfect "compliance tracking tool" able to generate compliance reports quickly and easily when requested by a customer.

Note 1 - The 'Financial Institution Shared Assessments Program' was formerly known as 'FISAP'.