Checklists and Samples
The samples and checklists below are written by TrustCC professionals to benefit the information security and financial services community. You may have seen these materials referenced in various trade magazines or publications. While we do not require registration to download the documents, we do appreciate your comments and suggestions for future materials.
Additional samples and checklists are available to clients and prospective clients who ask for additional samples. If you have comments or suggestions, we encourage you to contact us so we can improve our materials.
- Member or Customer Information Security Risk Assessment .PDF (26K)
Our current risk assessment template that ties reasonably foreseeable risks to countermeasures and tests of key controls.
- SAS70 Attestation Review Checklist.PDF (29K)
A new checklist to help financial institutions document their review of vendors with custody of customer or member data.
-
Vendor Due Diligence Checklist .PDF (29K)
An accompaniment to the article titled, "Vendor Due Diligence - Filtering Out Security Vendor Rhetoric." While designed for the selection of IT security and audit vendors, the checklist could certainly be used for other vendor types. -
Information Security Policy Framework .PDF (173K)
TrustCC is often asked to provide guidelines for information security policies. This framework incorporates standard security policy topics for a variety of organizations in different industries. Policies should address responsibility, practices and oversight methods for each topic listed. -
Generic BCP Process Diagram .PDF (287K)
One of the biggest challenges in business continuity planning is identifying which systems are critical to operations. This process diagram provides an example of how you might want to diagram your key processes. -
Security Self Testing Guidelines .PDF (173K)
Small financial institutions must comply with the same regulations as larger ones. Some requirements can be quite onerous to the smaller institution. One example is the GLBA requirement to regularly test key controls of the information security program. The TrustCC guidelines associated with this link provide a means to perform some testing with competent internal staff. While following these guidelines will NOT strictly comply with GLBA requirements, smaller financial institutions with very limited fiscal resources may not have a viable option.
If you have questions about using any of these resources, please contact us. We are happy to help!
Recent Quote
“TrustCC's professionalism, knowledge, and effective communication style are a welcome change compared to other firms. Their recommendations allowed us to easily implement the necessary control changes to not only pass examination, but ensure the proper protection of both the Bank’s and our Customer’s information." – Eric Jensen Chief Financial Officer of Fortune Bank; December 2007
About TrustCC
TrustCC’s team of professionals is unsurpassed in hands-on experience and regulatory knowledge. We focus our attention on detail, insightful reporting, and our customers’ needs.
TrustCC is known for its systems, security, and regulatory expertise, customer service and independence.
We are confident that our services will exceed your expectations.
Locations Served
TrustCC started in the Seattle/Tacoma area. Today TrustCC serves clients throughout the United States and elsewhere!


