Author: The Safe Systems Compliance Team

  • Are You Required to Address Your COVID-19 Readiness with Your Customers?

    Are You Required to Address Your COVID-19 Readiness with Your Customers?

    Hey Guru! Are we required to post any kind of statement to the public or our customers as to our readiness for the COVID-19? If so, can you direct me to the kinds of things we need to say? We are working on an ad to educate our customers on how to use our online […]

  • FFIEC Issues Statement on Pandemic Planning

    FFIEC Issues Statement on Pandemic Planning

    Background Similar to the Joint Statement on Destructive Malware issued in January in response to heightened geopolitical cyber risks from foreign actors, the FFIEC just released an Interagency Statement on Pandemic Planning in response to the current COVID-19 epidemic. Similar to the Destructive Malware statement, this statement does not impose any additional regulatory expectations on […]

  • FFIEC Rewrites Business Continuity Guidance

    FFIEC Rewrites Business Continuity Guidance

    The all new IT Examination Handbook is more than an update, it’s a complete re-write, and represents a significant change in how the business continuity process is managed. It also has several new expectations regulators will be looking for from financial institutions1. In fact, that is one of the most interesting changes; the term “institution” […]

  • Using Risk Scoring to Determine the Frequency of IT Audits

    Using Risk Scoring to Determine the Frequency of IT Audits

    Hey Guru! In my last IT examination, one of the findings was that the scope and cycle of our IT audits should be more closely tied to risk. We have IT audits every 12 months, what else should we be doing? By conducting Information Technology audits every 12 months, you’ve effectively (and correctly) determined that […]

  • FFIEC Issues Press Release on Cybersecurity Preparedness Assessments (and Muddies the Waters)

    FFIEC Issues Press Release on Cybersecurity Preparedness Assessments (and Muddies the Waters)

    A Standardized Approach On August 28th, the FFIEC issued a press release entitled “FFIEC Encourages Standardized Approach to Assessing Cybersecurity Preparedness”. The release “…emphasized the benefits of using a standardized approach to assess and improve cybersecurity preparedness.” On the surface the this seems very logical and straightforward, but in fact this may have provided more […]

  • Pandemic Testing and the BCP

    Pandemic Testing and the BCP

    Hey Guru! We finished a FDIC exam earlier this year, and in the IT portion they hit us on our pandemic plan saying it “needed improvement.” Here is the actual finding: Management should improve the pandemic plan within the Business Continuity Plan. The pandemic plan has no defined action plan, nor has it been tested. […]