
The FFIEC's recent supplemental guidance calls for a much more comprehensive approach to risk management and establishes a new "best practice" standard for mitigating risks to online systems by the January 2012 deadline.
To provide some well-needed clarification, plus help institutions better understand what is needed to meet the new requirements by the compliance deadline of January 2012, TraceSecurity is offering several free resources available for download.
RiskManager™ is an extension the TraceSecurity ComplianceManager platform, the first cloud based platform to integrate all the vital information and tasks necessary to maintain security compliance into a centralized interface, allowing organizations to streamline security compliance procedures and simplify the processes involved with IT risk management.

RiskManager™ is a cloud-based tool that helps the organization facilitate an ongoing risk management program by analyzing an organization's vulnerabilities, threats, asset information, controls and loss expectancies. It assists in the overall analysis process and enables the user to assess critical focus areas to determine the overall level of risk. Plus, the entire risk assessment process is captured and managed through the software which automates the process and provides a foundation for future risk assessments.
RiskManager™ allows the institution to manage their processes locally with TraceSecurity providing technical support and enhancing their efforts with additional services. This method helps the organization facilitate an continuous risk management program without straining internal resources or incurring high vendor costs each time a risk assessment is needed.
Reduces employee resource costs of IT Risk Assessments
Develops a standard, repeatable audit process
Creates standardized, accurate reports and thoroughly prepares the IT department for audits by regulatory boards
RiskManager™ saves time and money by automating the steps of the risk management process:
Asset group analysis. Identifies core assets and assigns a level of criticality to each asset in the areas of CIA.
Threat analysis. Identifies all relevant threats, evaluates each threat to determine which assets are affected, then assigns a level of criticality to each asset in the areas of CIA.
Control analysis. Identifies safeguards that can be used to protect each asset, assigns values to each control in terms of how it protects against specified threats.
Risk assessment reporting. Automatically associates and calculates data to produce a detailed risk assessment report.

TraceSecurity's methodology provides the most thorough, objective, and easy to read information security risk assessment available.
Our risk assessments follow standard methodologies designed to meet all regulatory requirements and best practice guidelines, including the new standards for information security assessments set forth in the recently revised FFIEC Guidance.
During IT Risk Assessment process, our experts closely scrutinize the organization's controls, vulnerabilities, threat vectors, asset information, and loss expectancies. Each individual risk is then analyzed and compared against other identified risks, enabling the organization to prioritize remediation efforts and preempt losses with the most exposure.
The TraceSecurity Information Security Risk Assessment includes: