SBS enables client banks to have successful IT exams by guiding the bank through our..... more Our chief concern every day for our clients is what needs to be done to ensure successful IT..... more The SBS team is one of the largest teams of bank information security professionals..... more

Resources

Regulating Agencies

FDIC

Federal Deposit Insurance Corporation

Federal Reserve

Board of Governors of the Federal Reserve System

OCC

Comptroller of the Currency

NCUA

National Credit Union Administration

OTS

Office of Thrift Supervision

Guidance

FDIC FIL-4-2009: Risk Management of Remote Deposit Capture

This January 2009 FIL gives guidance and requirements to banks on managing risk for their remote deposit capture systems, vendors, and users.

FDIC FIL-44-2008: Third-Party Risk

This June 2008 FIL gives guidance to banks on managing third-party risk (aka vendor management). SBS has released a TRAC module to help banks comply with this guidance.

FDIC FIL-6-2008: Interagency Statement on Pandemic Planning

This February 2008 FIL gives guidance for minimizing a pandemic's potential adverse effects.

FDIC FIL-5-2008: Annual Auditing and Reporting Requirements

In February 2008 the FDIC released a FIL talking about auditing requirements for banks. There are changes to the old auditing practices that you need to make sure are covered in your bank.

FDIC IT Officer Questionnaire Changes

FIL-105-2007
The FDIC updated its risk-focused Information Technology (IT) examination procedures for FDIC-supervised financial institutions. As part of the revision, the IT Officer's Questionnaire was enhanced to provide greater coverage of vendor management and outsourcing topics, credit card and ACH (automated clearing house) payment system risks, and an institution's overall information security program.

FDIC Information Technology Examination Officer's Questionnaire

Go here to download a PDF or Word version of the questionnaire.

FDIC Information Technology Risk Management Program

FIL-81-2005

Federal Financial Institutions Examination Council

The Council is a formal interagency body empowered to prescribe uniform principles, standards, and report forms for the federal examination of financial institutions by the Board of Governors of the Federal Reserve System (FRB), the Federal Deposit Insurance Corporation (FDIC), the National Credit Union Administration (NCUA), the Office of the Comptroller of the Currency (OCC), and the Office of Thrift Supervision (OTS) and to make recommendations to promote uniformity in the supervision of financial institutions.

FFIEC Information Technology Examination Handbook

Go here to download booklets in Audit, Business Continuity Planning, Development and Acquisition, E-Banking, FedLine, Information Security, Management, Operations, Outsourcing Technology Services, Retail Payment Systems, Supervision of Technology Service Providers, and Wholesale Payment Systems.

FFIEC Regulatory Resources
GLBA Appendix B to Part 364

Interagency Guidelines Establishing Information Security Standards

RSA Data Encryption Best Practices Kit

Download the Data Encryption Best Practices Kit and get expert views on how protecting data at all points of use ensures the security of individuals' personal information, sensitive corporate data, and intellectual property.

Security Articles & Information

Final Report & Recommendations by the National Infrastructure Advisory Council

The National Infrastructure Advisory council released this report entitled: "The Prioritization of Critical Infrastructure for a Pandemic Outbreak in the United States Working Group"

Are Banks' IT Systems Ready?

An article from "Banks Systems & Technology" on the preparedness of banks if a pandemic flu outbreak happened.

Pandemic Influenza Impact on Communication Network Study

A December 2007 from the Department of Homeland Security discussing the effects of pandemic flu on communication.

Emerging Pandemic Flu Threat - Are You Prepared?

Pandemic Flu has once again been brought to the center of our attention. Bank regulators have required financial institutions to develop a documented plan to prepare for an event such as this. If you are still trying to develop this plan and don't know where to turn, contact SBS for help!

Improving Security from the Inside Out

A business case for corporate security awareness prepared by the National Security Institute (NSI).

The 25 Most Common Mistakes in E-Mail Security

25 tips to bring Internet and E-Mail users up to speed so they stop compromising your network security.

Watchdog Issues ID Theft Warning

People are risking identity theft by not protecting their personal details, an information watchdog says. Click for more...