Stay Informed

Keep yourself informed of current auditor & examiner trends & the latest FFIEC updates. Free compliance tools, news, & updates from the Guru. Sign up below!

Subscribe to our RSS feed

Got a Question?
Ask the Guru.

Email the Guru at tom@safesystems.com for answers to your compliance questions.

Or, search the Guru site for your answers!

GuruHeader

From the Field

Enlightenment from recent audits & exams

5 “random” facts

Fact 1 – According to the U.S. Bureau of Labor Statistics, the increasing complexity of financial regulations will spur employment growth of financial examiners.  In fact it is expected to …
Read the rest of the article

 

“Data-flow diagrams”

This request was seen in a recent State examiners pre-examination questionnaire, and although I usually like to see a request a couple of times from different examiners before identifying it …
Read the rest of the article

 

FDIC changing annual IT report to Board?

Based on recent examination findings, it would appear that the FDIC is changing what they expect to see in the annual information security report to the Board of Directors.  The …
Read the rest of the article

 

Hot Topics

The Guru reflects on recent events

Updated Incident Response guidance expected

Comments on draft 2 are closed, and the National Institute of Standards and Technology (NIST) is about to release an update to their Computer Security Incident Handling Guide (SP 800-61).   …
Read the rest of the article

 

FDIC Supervisory Letter Issued on Critical Service Provider

(NOTE:  Although the vendor in question has been publicized by the NCUA, I will not name it here because it is not relevant.  If you currently contract with the
Read the rest of the article

 

FFIEC Handbook Update – Outsourcing

The FFIEC has just added a section to the Outsourcing Technology Services IT Examination Handbook, and it should be required reading for financial institutions as well as any managed service …
Read the rest of the article

 

About the Compliance Guru

Tom Hinkel has over twenty years experience in IT regulatory compliance, risk management and information security both inside banks and as a consultant for institutions of all sizes, Hinkel also serves as a regulatory compliance resource and certified educator for Safe Systems' bank and credit union clients.

Safe Systems Compliance Services