tandem - kn

Posts by:

GRC Content Analyst Savannah Richardson

How to Perform an Information Asset-Based Risk Assessment

Risk assessments are required part of a financial institution's Information Security Program, but understanding how to perform one based on information assets is where many organizations get stuck. What counts as an information asset? How do you evaluate risk at the information asset level? And how does this connect to your Information Security Program?

Read More

Frequently Asked Questions about the NIST Cybersecurity Framework (CSF)

The NIST Cybersecurity Framework (CSF) is a widely adopted, flexible framework that can help organizations of any size or complexity assess their cyber readiness. From large enterprises to small community banks, the NIST CSF's adaptable structure helps teams improve their cybersecurity posture without the pressure of rigid, one-size-fits-all standards.

Read More

How to Write an AI Policy

As artificial intelligence (AI) becomes more integrated with business operations, it's increasingly important to develop clear policies to manage AI-related risks, maintain compliance, and uphold ethical standards. A well-crafted AI policy helps define expectations, protect data, and guide employees on the responsible use of AI tools. Here's what you should consider when creating an AI policy for your organization.

Read More

What Financial Institutions Need to Know: FTC Safeguards Rule Breach Notification

On November 13, 2023, the Federal Trade Commission (FTC) published a Final Rule in the Federal Register updating the Standards for Safeguarding Customer Information (Safeguards Rule). The rule includes changes to the incident notification requirements for financial institutions. The Final Rule will be effective on May 13, 2024. 

Read More