Home / Blog / Data Privacy
January 13, 2022 by Christopher Salone
This past year proved to be a year of rapid development for the cybersecurity and IT landscape. As new threats emerged, others continued to develop and evolve. Throughout the year, the FFIEC, in an effort to help its institutions combat these threats, issued new guidance for examiners and organizations in two major areas.
First, the Council renamed the previously existing “Operations” IT booklet to “Architecture, Infrastructure, and Operations” to incorporate updated information technology (IT) risk practices and frameworks. The members developed the booklet using a principles-based approach to IT risk management to allow the booklet’s central tenets to remain relevant to examiners even as innovation and technological changes in the financial services sector occur.
According to the FFIEC’s official press release, some of the major highlights and changes to the booklet include:
In addition, in August 2021, the FFIEC issued new guidance, titled “Authentication and Access to Financial Institution Services and Systems” to provide financial institutions with examples of effective risk management principles and practices for access and authentication. These principles and practices address business and consumer customers, employees, and third parties that access digital banking services and financial institution information systems.
The Guidance acknowledges the emerging cybersecurity threat landscape, which reinforces the need for financial institutions to effectively authenticate customers, as well as the expansion of authentication considerations beyond customers to include employees, third parties, and system-to-system communications.
Some of the items the Guidance touches on include:
Within the Appendix of the Guidance includes practices or controls related to access management and authentication, as well as a list of resources to assist financial institutions with authentication and access management.
The Guidance is intended to apply not only to financial institutions, but also to any third party acting on behalf of a financial institution that provides the accessed information systems and authentication controls.
FoxPointe Solutions, which is a division of The Bonadio Group, is equipped and prepared to help your organization prepare for these requirements. We would be happy to answer any questions you may have or provide you with additional information.