Steven Jones is the Director of Information Security at Synovus. His responsibilities include policy definition and policy management, business resiliency, and disaster recovery. Jones: “We have been evolving our risk assessment methodology over the last three or four years, and the intent was really to align our activities and our efforts towards what is important to the business. So, we have an enterprise risk assessment. We have identified about 60 different microbusiness processes throughout the organization, and so we look at each of those. We interview with business process owners and bank facilitators which are information security officers at the banks.”]

