Is Your Risk Assessment Authentication & Access Ready?
In August, the FFIEC released new guidance titled “Authentication and Access to Financial Institution Services and Systems”. Because the guidance...
While the FFIEC has released three major guidance updates since July 2019, the FDIC has not updated its examination program to include the newer guidance. This is one of the findings of the January 2023 audit of the FDIC Information Technology Risk Examination (a.k.a. “InTREX”) program performed by the Office of the Inspector General (OIG). Also noted was the fact that the program does not reflect updates to NIST standards, including those for supply chain threats, issued since 2014.
We have been noticing for some time that many of the regulatory agencies seem to be behind in enforcing updated guidance and standards. They have been experiencing the same pandemic and staffing turnover pressures that we all have, and the cracks are beginning to show. We do expect that this recent audit report will cause a flurry of activity to reverse this trend across all regulatory agencies, so institutions should start preparing now to ensure that they have updated their controls to meet the newer requirements before their next exam. This includes reviewing the following guidance published since 2019:
We enjoy working with institutions proactively to keep them ahead of the exam curve. If you believe that your institution needs help in sifting through the large volume of guidance, we can help! Reach out to us anytime at support@bedelsecurity.com.
In August, the FFIEC released new guidance titled “Authentication and Access to Financial Institution Services and Systems”. Because the guidance...
The National Institute for Standards and Technology released an update to its Cybersecurity Framework (CSF) late February. The CSF was originally...
A little over a year ago, banking regulators released the “Authentication and Access to Financial Institution Services and Systems” guidance. Since...