Information Security
Belgrade, Serbia
Main objectives: To identify, quantify, and prioritize risks against criteria for risk acceptance and objectives relevant to the Bank. To provide management direction and support for information security in accordance with business requirements, relevant laws and regulations, and state policy. Managing information security within the Bank. To achieve and maintain appropriate protection of Bank assets. To ensure that employees, contractors, and third party users understand their responsibilities, that they are suitable for the roles they are considered for, and to reduce the risk of theft, fraud, or misuse of facilities by recognizing information security problems and incidents. To prevent unauthorized physical access, damage, and interference to the Bank’s premises and information. To ensure the correct and secure operation of information processing facilities. To control access to information. To ensure that security is an integral part of information systems. To ensure information security events and weaknesses associated with information systems are communicated in a manner allowing timely corrective action to be taken. To counteract interruptions to business activities, protect critical business processes from the effects of major failures of information systems or disasters, and ensure their timely resumption. To avoid breaches of any law, statutory, regulatory, or contractual obligations, and state requirements. Symantec DLP, Symantec Endpoint Encryption, Paloalto NGFW, Fireeye Anti-APT, Bluecoat proxy, Nessus Vulnerability Scanner.Currently on project of implementing requirements imposed by GDPR.