Notice: Function _load_textdomain_just_in_time was called incorrectly. Translation loading for the tm-polygon domain was triggered too early. This is usually an indicator for some code in the plugin or theme running too early. Translations should be loaded at the init action or later. Please see Debugging in WordPress for more information. (This message was added in version 6.7.0.) in /home/safesystems/public_html/Complianceguru.com/wp-includes/functions.php on line 6121
The 5 trickiest FDIC IT examination questions (part 2). – Compliance Guru

The 5 trickiest FDIC IT examination questions (part 2).


The 5 trickiest FDIC IT examination questions (part 2).

Last time we addressed a question from the FDIC IT Examination Questionnaire, found in PART 2, OPERATIONS SECURITY AND RISK MANAGEMENT titled “Do you have a process in place to monitor and adjust, as appropriate, the information security program”.

This time, we take a closer look at another potentially troublesome Part 2 question;

“Does the bank’s strategic planning process incorporate information security (Y/N)?”

Once again, the optimal answer is “Y”, but documenting compliance is a bit tricky because this is a complex question.  In fact, it’s really several questions with multiple parts, all requiring a “Y” answer.

  1. Do you have a strategic planning process?
    1. Do you have an enterprise-wide strategic plan?
    2. Do you have an IT strategic plan?
  2. Does the IT strategic plan support the overall enterprise-wide  strategic plan?
  3. Do you have an risk-based information security program?
  4. and finally (assuming “Y” to all the above)… Does your strategic planning process incorporate information security?

The reference for this is the FFIEC IT Examination Handbook, Management, June 2006, and although the entire document is an excellent guide for how management can address and control information security, I think the most relevant reference to the issue of strategic planning and information security is found on page 22:

“IT strategic plans provide insight into the organization’s planning process. Review and analysis of the strategic plans as part of the risk assessment process (my emphasis) may spotlight developing risk  exposures or other deficiencies that limit the institution’s ability to  implement strategic priorities.”

The FFIEC suggests that strategic planning be incorporated into the risk assessment process.  As I mentioned in my previous post, (and highly recommended by the FFIEC on page 5 of the same Management Handbook) the IT Steering Committee is the most logical forum for risk assessment process provided the committee consists of representatives from all departments, operates from a standardized agenda, and keeps meeting minutes.  (There is one more requirement; that it assign responsible parties to the issues and findings that arise in the meetings, and follow them through to resolution.  More about this in my next post).

So, assuming you have both an overall strategic plan, and an IT strategic plan, and assuming you incorporate discussion of these plans in the risk assessment section of your IT Steering Committee agenda, then the answer to this question is “Yes, The process is guided by the FFIEC Management Handbook, coordinated by our IT Committee, and documented in the meeting minutes.”

Next time, in Part 3;  “Are project management techniques and system  development life cycle processes used to guide efforts at acquiring and implementing technology (Y/N)?”

Tom Hinkel
As author of the Compliance Guru website, Hinkel shares easy to digest information security tidbits with financial institutions across the country. With almost twenty years’ experience, Hinkel’s areas of expertise spans the entire spectrum of information technology. He is also the VP of Compliance Services at Safe Systems, a community banking tech company, where he ensures that their services incorporate the appropriate financial industry regulations and best practices.

Write a Comment