PSCU, the nation¹s leading credit union service organization, was selected as a finalist for the 2015 Information Security Executive® (ISE®) Southeast Awards. The nomination recognizes the PSCU Enterprise Risk Office (ERO) team as an industry leader that has made a significant, positive impact on the entire PSCU organization in terms of managing internal risk and security, developing innovative solutions, and effectively managing and executing risk management strategies. The award is sponsored by T.E.N., an Atlanta-based technology and information security executive networking and relationship-marketing firm.
For over a decade, the ISE® Southeast Awards have recognized nominees from Alabama, Florida, Georgia, Kentucky, Maryland, Mississippi, North Carolina, South Carolina, Tennessee, Virginia and West Virginia.
³This is a commendable recognition for our entire team,² said Rini Fredette, SVP of the Enterprise Risk Office at PSCU. ³An opportunity was available for us to be proactive in third-party risk, and this nomination reflects the efforts of the collaborative multi-departmental team.²
The project, ³Vendor Governance & Oversight Program Phase 1,² which earned PSCU a place among ten nominees for the Project of the Year Award, was initiated in December 2014 to reduce risk from third-party service providers. The project included the formalization of PSCU¹s third-party onboarding process and the elevation of criteria for potential new partners. ³Every day we work to develop processes to help manage risk and tightly align with our company¹s strategic objectives,² said Fredette. ³This project was an excellent example of that work, as it raised awareness and visibility of risk with third-party suppliers.²
An important element of the ³Vendor Governance & Oversight Program Phase 1² was the re-engineering of PSCU¹s third-party provider risk scorecard. According to Fredette, this helped identify where risk considerations may have changed due to shifts in the services provided or the information shared. ³The additional level of diligence from the scorecard redesign provides a mechanism to evaluate that our partners comply with industry best practices and regulatory requirements,² said Fredette.
Additionally, the program developed and executed executive level reporting and dashboards. The dashboards provide PSCU executives with a snapshot of third-party partner risk within their organizations, highlighting where there may be areas of concern. ³Visibility into third-party partner risk at the executive level is critical to enabling good decision-making,² added Fredette.²