Category: Hot Topics

  • FFIEC Rewrites the Information Security IT Examination Handbook

    FFIEC Rewrites the Information Security IT Examination Handbook

    In the first update in over 10 years, the FFIEC just completely rewrote the definitive guidance on their expectations for managing information systems in financial institutions.  This was widely expected, as the IT world has changed considerably since 2006. There is much to unpack in this new handbook, starting with what appears to be a…

  • FDIC Updates IT Examination Procedures

    FDIC Updates IT Examination Procedures

    Starting immediately, all FDIC-examined institutions will be subjected to new IT examination procedures, the first major overhaul since December 2007.  The new format is dubbed the InTREx program (Information Technology Risk Examination), and is designed to be a bit simpler in the pre-examination phase.  In fact, the InTREx has only 26 questions vs. 59 for the 12/07…

  • FDIC Targets Board Responsibilities

    FDIC Targets Board Responsibilities

    “A topic is at times of such significant interest to bankers and examiners that it warrants a special issue…”  Whenever something from a regulatory body begins this way all bankers should take notice, and the latest Special Corporate Governance Edition from the FDIC is no exception.  In fact the Guru did a little research and the last time the FDIC released…

  • FDIC Expands Criteria for 18 Month Exam Cycle

    FDIC Expands Criteria for 18 Month Exam Cycle

    The FDIC released FIL-17-2016 today, which will increase the examination cycle for community banks meeting certain criteria from 12 months to 18 months, thereby potentially decreasing one of the most intrusive events in the bankers life. The criteria is as follows: Must be less than $1 B in assets Must have a CAMELS composite rating…

  • FFIEC Updates (and Greatly Expands) the Management Handbook

    FFIEC Updates (and Greatly Expands) the Management Handbook

    This latest update to the IT Examination Handbook series comes 11 years after the original version.  And although IT has changed significantly in the past 11 years, the requirement that financial institutions properly manage the risks of IT has not changed.  This new Handbook contains many changes that will introduce new requirements and new expectations…

  • FFIEC Releases Cybersecurity Assessment Tool

    FFIEC Releases Cybersecurity Assessment Tool

    UPDATE:  Safe Systems just released their Enhanced CyberSecurity Assessment Toolkit (ECAT) – This enhanced version of the FFIEC toolkit addresses the biggest drawback of the tool; the ability to collect, summarize, and report your risk and control maturity levels.   Once risks and controls have been assessed (Step 1 below), institutions will now be better able…