Shared Assessments Program
Home > Financial Services Information Security Definitions - Shared Assessments Program
SearchFinancialSecurity.com Definitions (Powered by WhatIs.com)
EMAIL THIS
LOOK UP TECH TERMS Powered by: WhatIs.com
Search listings for thousands of IT terms:
Browse tech terms alphabetically:
A B C D E F G H I J K L M N O P Q R S T U V W X Y Z #

Shared Assessments Program


Show me everything on Business partner and vendor security issues


Word of the Day


DEFINITION - Shared Assessments is a program that provides organizations with a way to obtain a detailed report about a service provider's controls (people, process and procedures) and a procedure for verifying that the information in the report is accurate.

Shared Assessments was created by the Bank of America Corporation, The Bank of New York Mellon, Citi, JPMorgan Chase & Company, U.S. Bankcorp, and Wells Fargo & Company in collaboration with leading service providers and the Big 4 accounting firms to help financial services companies assess service providers. The goal of Shared Assessments is to streamline the process of selecting and maintaining a vendor by creating an industry-wide standard to which service providers must adhere. To that end, the BITS consortium created the Standardized Information Gathering questionnaire (SIG), which is used to assess how well service providers adhere to those procedures.

The Shared Assessments program is not a certification. The SIG simply allows vendors to do a self-assessment of their security controls and provide that to their financial-services clients. In conjunction with the SIG, the Shared Assessments program offers Agreed Upon Procedures (AUP), which are audit standards that an independent assessment firm can use when conducting an onsite audit of a managed service provider. The service provider can share the report with multiple financial services clients, alleviating the need for separate audits.

See also: IT controls, compliance audit

Learn more about Business partner and vendor security issues
How to manage security risks in vendor contracts: Learn what financial firms need to include in their vendor contracts in order to conform with regulatory guidance and industry best practices for vendor risk management.
Download presentations from Financial Information Security Decisions 2009: Download a number of the compelling presentations from the 2009 Financial Information Security Decisions conference.
Financial Information Security Decisions 2008: Presentation downloads: Download a number of the fascinating presentations from the 2008 Financial Information Security Decisions conference.
Vendor risk management: process and documentation: As part of the vendor risk management process, regulators expect information security officers will document vendor relationships and have proper vendor documentation.
Data breach protection: Implementing vendor breach safeguards: Financial firms must include data breach protections in their vendor contracts, including data breach notification and reporting.

LAST UPDATED: 20 Oct 2009

Do you have something to add to this definition? Let us know.
Send your comments to techterms@whatis.com





FILE EXTENSION AND FILE FORMAT LIST
File Extension and File Format List:
A B C D E F G H I J K L M N O P Q R S T U V W X Y Z #


RELATED CONTENT
New vendor risk assessment tools address cloud computing
Shared Assessments program unveils updated tools for assessing security of service providers, including cloud providers
Don't forget the cleaning crew in your vendor management program
Banks often overlook non-IT vendors in their vendor management program, putting their organization and customers' data at risk, experts say
Vendor contract management: Regulatory guidance is risk-based
Financial-services firms are subject to many requirements for managing vendor information security risks by contract. Learn how regulatory guidance is...




Shared Assessments Program White Papers by Financial Security Experts
About Us  |  Contact Us  |  For Advertisers  |  For Business Partners  |  Site Index  |  RSS
SEARCH 
TechTarget provides technology professionals with the information they need to perform their jobs - from developing strategy, to making cost-effective purchase decisions and managing their organizations' technology projects - with its network of technology-specific websites, events and online magazines.

TechTarget Corporate Web Site  |  Media Kits  |  Site Map




All Rights Reserved, Copyright 2008 - 2009, TechTarget | Read our Privacy Policy
  TechTarget - The IT Media ROI Experts