Information Security Risk Assessment
Start with our risk assessment template, which includes more than 60 common enterprise-wide information security threats.
Answer a questionnaire to unlock risk level suggestions. Then customize the risk assessment so it perfectly reflects your organization.
Information Assets Inventory
Maintain an inventory of your information assets and rate their confidentiality, integrity, and availability requirements.
Use the inventory ratings to determine the right level of protection for each asset.
Asset-Based Risk Assessments
Once your priority information assets are identified through your inventory, efficiently conduct unique risk assessments for them using the Tandem framework.
Version Tracking
Use version tracking to access data from previous versions of the risk assessment, compare data in the risk assessment over time, and identify trends from year to year.
Framework
Use Tandem's asset risk assessment framework to go step-by-step through the assessment process.
Quantifying the likelihood and potential damage associated with threats is made easy with a simple control calculation tool. Use the information captured to easily report on your risk posture.
Asset Templates
Get started right away by using our risk assessment templates designed for common information security assets.
Begin with our recommended guidance, threats and controls. Then use the framework to tailor each assessment to perfectly reflect your organization.
Downloads
Effortlessly generate consistent and professional documents on the fly to share with your executive team, board of directors, auditors, and examiners.
These customizable documents are available in Microsoft Word and Adobe PDF formats.
Additional Features
- Visualize your risk exposure with charts and graphs
- Document a risk management plan
- Access storm and crime event statistics for geographical threats
- Create an unlimited number of information asset risk assessments
- Identify gaps with reports
- Utilize suggested threats, controls, guidance, and risk levels
- View risk at a high-level across all assets or by individual assets
- Assign responsibility and various levels of access to users
- Receive a calculated overall risk for each asset
Are you interested in
Risk Assessment Software?
Hope Federal Credit Union in Jackson, MS
"Tandem is extremely easy to use. I just started in the system (in earnest) and was able to quickly navigate through the steps. It’s very logical, comprehensive and I’m hopeful it will result in easier reports and exams. It’s a phenomenal option for a bank our size."
F & M Bank in Edmond, OK
"Thanks for all that you folks do to support and improve the software. We’ve been impressed with Tandem since day one; especially the responsiveness of the support and development teams with our needs and requests for new features. Thanks for all you do."
"We are so happy to have a partner like Tandem. Your products help our community bank compete with larger, regional and national banks without the expense of a huge staff."
Citizens Bank in Carthage, TN
"If honesty and integrity are values that resonate when selecting an Information Security technology partner, then Tandem software is for your institution. Every employee on the Tandem team is committed to sustaining tools for your bank to build a custom program compliant with current regulatory guidance."
First American Bank in Artesia, NM
"The Tandem Business Continuity Planning software has streamlined how we manage business continuity for our bank. Before Tandem, we lost files and had to update and make changes to a Word document. This software has helped us focus on the important aspects of business continuity and made it easier to update, train, and report to our Board of Directors."
North Dallas Bank & Trust Co in Dallas, TX
"Tandem’s Business Continuity Planning software is a strong program that integrates well with Tandem’s Vendor Management software. It provides good reports for our Board of Directors and Management. It is easy to update, and I am able to access it from anywhere… even on my phone."
North Dallas Bank & Trust Co. in Dallas, TX
"Tandem's Business Continuity Planning software has given us the direction we needed to establish good processes for our organization."
Texas Trust Credit Union in Mansfield, TX
"First, I want to thank Tandem for being such a great partner of ours. We are extremely grateful for the tools you have provided. Particularly, your BCP program and the employee alert system. As of right now that is our main communication system for most of our employees."
"Tandem Vendor Management has made the process for collecting and tracking documents a breeze. The Vendor Management system is easy to use, yet quite powerful software. The software has saved us time from old spreadsheets and a manual vendor review process. I would highly recommend any organization to this system."
Johnson City Bank in Johnson City, TX
Frequently Asked Questions
Does Tandem provide risk assessment templates?
Yes. Tandem provides an overall information security risk assessment template with a list of more than 60 common enterprise-wide information security threats.
The results of this comprehensive assessment are quickly generated based on a questionnaire. Each threat includes suggested controls, risk levels and regulatory guidance.
The following asset-based risk assessment templates are also included:
- ACH SystemsAssess noncompliance issues, operational risks, and external threats related to ACH systems
- ATMAssess operational risks and external threats, including malicious and cyber-attacks, related to ATMs
- Cloud ComputingAssess third-party considerations, external threats, operational risks, and noncompliance issues related to cloud computing
- Custom Information AssetsA custom template to get started with a generic technical asset's foundational operational risks and external threats to your information
- Generic Information Asset (Technical)A flexible starting point for assessing risks to any technical information assets when a more specific template does not apply.
- Mobile DevicesAssess operational risks, third-party considerations, and external threats related to mobile devices, provided or brought (BYOD)
- Mobile Financial ServicesAssess various mobile banking risks in relation to short message service (SMS), mobile-enabled websites, mobile applications, and wireless payment technologies
- Prepaid CardsAssess noncompliance issues, operational risks, and third-party considerations related to prepaid cards for mitigating related risks, including money laundering and other illegal transactions
- Remote Deposit Capture (RDC)Merchant and Consumer and Mobile Capture risk assessments help you assess operational risks, external threats, and third-party considerations related to general RDC, and RDC via mobile devices
- Remote WorkA Remote Work risk assessment can help you assess information security risks, technical threats, and employee-based threats related to staff working remotely.
- Social MediaAssess noncompliance issues, operational risks, and external threats related to the active use of social media, or non-participation in social media
- TandemBy creating risk assessments in the CoNetrix Tandem Security and Compliance Software as a Service application, Tandem is an information asset for your financial institution. Use this template to assess noncompliance issues, operational risks, and external threats that could disrupt your use of Tandem
- Wire Transfer SystemAssess noncompliance issues, legal and operational risks, and external threats related to wire transfer systems for electronic funds transfers (EFT), both for the financial institution and the customer
Is there instructional documentation to help me build my risk assessment?
Yes. Tandem offers a Knowledge Base with articles written by Tandem experts.
While you navigate the product you will also find help tips along the way.
Is there someone at Tandem who can help me build my risk assessment?
Yes. Tandem Support is available 8-5 (CT) M-F to answer your questions about Tandem application features.
For help with the contents of your risk assessments, check out our partners who can provide risk assessment consulting.
You are also invited to attend our annual KEYS conference to connect with other users and learn from Tandem experts.
What training options are available?
Tandem is pleased to offer complimentary training webinars each month for our customers. These webinars are recorded and available on-demand.
A Knowledge Base is available with articles to help you learn about Tandem. You can stay up-to-date on our latest features by subscribing to our Software Update emails.
Product training is also available by request for an additional fee.
Will my data be secure?
Yes. Tandem maintains high marks through the following testing: SSAE 18 SOC 1 Type 2, internal audits and assessments, quarterly penetration tests.
Security controls include:
- Secure data transmission between your browser and your servers
- Data encrypted at rest using AES-256
- User passwords are hashed and salted
- Datacenter protected by firewall and intrusion detection/prevention systems (IDS/IPS)
- Redundant internet connections
- Multifactor authentication options
- Single Sign On (SSO) integration using SAML 2.0
- IP address restrictions
- User activity log
- User access roles/restrictions
How is Tandem installed and updated?
Tandem products are delivered via the internet as Software-as-a-Service (SaaS) applications. Tandem can be accessed from any device with a modern web browser. No software installation or special equipment is required.
New features and updates are included with your annual subscription and are automatically available. Each new feature is documented in our Software Updates blog.
Does this product integrate with other Tandem products?
Yes. Tandem Risk Assessment integrates with other Tandem products to provide seamless sharing of data and help avoid duplication of information. All Tandem products are available under the same secure website.
The Tandem Internet Banking Security Program can be purchased separately and the risk assessments it includes are managed alongside your other risk assessments.
Policies contained in Tandem Policies can be referenced as controls in your overall information security risk assessment. This includes the customizable set of more than 40 pre-defined Information Security Policies, which are already mapped to threats.
Additionally, the asset management tool integrates with Tandem Vendor Management and Tandem Business Continuity Planning modules to show connections among assets, vendor services, systems and software.
Can I manage accounts for multiple companies?
Yes. With a single login you can manage several companies' risk assessments (requires a subscription for each company).