Skip to main content

Assessing Threats To Information Security In Financial Institutions

Threat assessment is an essential component of an information security risk evaluation. In order to prioritize vulnerabilities for remediation and to evaluate existing controls, a thorough understanding of potential threat sources is required. Particularly for financial institutions, this activity is a pre-requisite for a comprehensive information security program and a stated regulatory requirement. This paper explores key issues related to threat assessment, including essential elements, methodologies, and common pitfalls. A recommended approach for completing and documenting this activity is also provided. While the focus of this paper is on financial institutions and related regulatory requirements, the general concepts and the recommended approach for conducting a threat assessment are applicable to other organizations and industries.

1143 (PDF, 1.98MB)

8 Aug 2003
ByCynthia Bonnette
Share
All papers are copyrighted

No re-posting of papers is permitted

Subscribe to GIAC’s Monthly Newsletter

Receive expert insights, priority access to certifications, essential updates on regulatory changes and industry developments.