Focused on Industry Guidelines
En Garde understands that the best metrics for security should be reflective of industry best practices and allow risk to be evaluated accordingly. The Federal Financial Institution Examination Council (FFIEC) has one of the best collection of guidelines and recommendations for data and network security; combined with En Garde's extensive experience in the finance industry we can assist in not only determining your security risks but putting those into perspective relative to other institutions.
FFIEC coordinates efforts between the following five national organizations, all of which have GLB auditing responsibilities for member organizations.
- The Board of Governors for the Federal Reserve System (FRB),
- Federal Deposit Insurance Corporation (FDIC),
- National Credit Union Administration (NCUA),
- Office of the Comptroller of the Currency, and
- The Office of Thrift Supervision (OTS).
En Garde's Digital Risk Management takes into account all IT digital risks and can assist any institution in complying with industry-best-practices using both FFIEC and any local or organization specific regulations. We will work with you, to not only determine the set of areas and actions to be reviewed but also to, put in place the proper policies and procedures to make security audits go smoothly.
The FFIEC guidelines come in a collection of handbooks which are regularly updated. The following table lists the major handbooks and the federal agencies currently using them in their audits.
|
|
Congress |
FFIEC |
FRB |
FDIC |
NCUA |
OCC |
OTS |
|
Audit |
Yes |
Yes |
Yes |
Yes |
Yes |
Yes |
Yes |
|
Business Continuity Planning |
|
|
|
|
|
|
|
|
Development and Acquisition |
|
|
|
|
|
|
|
|
E-banking |
Yes |
|
Yes |
Yes |
Yes |
Yes |
Yes |
|
FedLine |
Yes |
|
Yes |
|
|
|
|
|
Information Security |
Yes |
|
Yes |
Yes |
Yes |
Yes |
Yes |
|
Management |
Yes |
|
Yes |
Yes |
Yes |
Yes |
Yes |
|
Operations |
|
|
|
|
|
|
|
|
Outsourcing Technology Services |
Yes |
|
Yes |
Yes |
Yes |
Yes |
Yes |
|
Retail Payment Systems |
Yes |
|
Yes |
Yes |
Yes |
Yes |
Yes |
|
Supervision of Technology Service Providers |
|
Yes |
|
|
|
|
|
|
Wholesale Payment Systems |
Yes |
|
Yes |
|
|
|
|
For more information to download the handbooks go to the FFIEC web site at: http://www.ffiec.gov/