<?xml version="1.0" encoding="UTF-8"?><rss version="2.0"
	xmlns:content="http://purl.org/rss/1.0/modules/content/"
	xmlns:dc="http://purl.org/dc/elements/1.1/"
	xmlns:atom="http://www.w3.org/2005/Atom"
	xmlns:sy="http://purl.org/rss/1.0/modules/syndication/"
		>
<channel>
	<title>Comments for FFIEC Bank &amp; Credit Union Compliance Help presented by Safe Systems – Compliance Guru</title>
	<atom:link href="http://www.complianceguru.com/comments/feed/" rel="self" type="application/rss+xml" />
	<link>http://www.complianceguru.com</link>
	<description>Keeping Financial Institutions Informed</description>
	<lastBuildDate>Wed, 09 Nov 2011 14:14:27 +0000</lastBuildDate>
	<sy:updatePeriod>hourly</sy:updatePeriod>
	<sy:updateFrequency>1</sy:updateFrequency>
	<generator>http://wordpress.org/?v=3.3.1</generator>
	<item>
		<title>Comment on Access Rights a frequent finding by Education</title>
		<link>http://www.complianceguru.com/2011/11/access-rights-a-frequent-finding/#comment-186</link>
		<dc:creator>Education</dc:creator>
		<pubDate>Wed, 09 Nov 2011 14:14:27 +0000</pubDate>
		<guid isPermaLink="false">http://www.complianceguru.com/?p=2225#comment-186</guid>
		<description>If you are a Safe Systems NetComply customer, we can send you some screen shots on how to set this up and execute within Active Directory and File Servers.  Just shoot us an email at Education@safesystems.com.</description>
		<content:encoded><![CDATA[<p>If you are a Safe Systems NetComply customer, we can send you some screen shots on how to set this up and execute within Active Directory and File Servers.  Just shoot us an email at <a href="mailto:Education@safesystems.com">Education@safesystems.com</a>.</p>
]]></content:encoded>
	</item>
	<item>
		<title>Comment on SSAE 16 replaces SAS 70 &#8211; UPDATE by Tom</title>
		<link>http://www.complianceguru.com/2010/08/ssae-16-replaces-sas-70/#comment-163</link>
		<dc:creator>Tom</dc:creator>
		<pubDate>Fri, 02 Sep 2011 19:00:14 +0000</pubDate>
		<guid isPermaLink="false">http://www.complianceguru.com/?p=378#comment-163</guid>
		<description>True, the SSAE 16 is the functional replacement for the SAS 70 for ICFR.  My (admittedly misleading) point is that since the SAS 70 had morphed into an all-purpose IT controls assessment, the IACPA was careful to position the SSAE 16 as an ICFR attestation ONLY.  

Good point, and thanks for the comment!</description>
		<content:encoded><![CDATA[<p>True, the SSAE 16 is the functional replacement for the SAS 70 for ICFR.  My (admittedly misleading) point is that since the SAS 70 had morphed into an all-purpose IT controls assessment, the IACPA was careful to position the SSAE 16 as an ICFR attestation ONLY.  </p>
<p>Good point, and thanks for the comment!</p>
]]></content:encoded>
	</item>
	<item>
		<title>Comment on SSAE 16 replaces SAS 70 &#8211; UPDATE by HedgeHogCPA</title>
		<link>http://www.complianceguru.com/2010/08/ssae-16-replaces-sas-70/#comment-162</link>
		<dc:creator>HedgeHogCPA</dc:creator>
		<pubDate>Thu, 01 Sep 2011 20:37:07 +0000</pubDate>
		<guid isPermaLink="false">http://www.complianceguru.com/?p=378#comment-162</guid>
		<description>&quot;Most importantly, the SSAE 16 will not be the de facto replacement for the SAS 70.  Stay tuned, we are expecting additional guidance from the AICPA later this fall.&quot;

SSAE 16 is THE replacement for SAS 70.  The standards are virtually the same as SAS 70 was the basis for the ISAE standard which served as the basis for SSAE 16.</description>
		<content:encoded><![CDATA[<p>&#8220;Most importantly, the SSAE 16 will not be the de facto replacement for the SAS 70.  Stay tuned, we are expecting additional guidance from the AICPA later this fall.&#8221;</p>
<p>SSAE 16 is THE replacement for SAS 70.  The standards are virtually the same as SAS 70 was the basis for the ISAE standard which served as the basis for SSAE 16.</p>
]]></content:encoded>
	</item>
	<item>
		<title>Comment on Interpreting The New FFIEC Authentication Guidance &#8211; 5 Steps to Compliance by Tom</title>
		<link>http://www.complianceguru.com/2011/07/interpreting-the-new-ffiec-authentication-guidance/#comment-157</link>
		<dc:creator>Tom</dc:creator>
		<pubDate>Mon, 18 Jul 2011 15:57:18 +0000</pubDate>
		<guid isPermaLink="false">http://www.complianceguru.com/?p=1925#comment-157</guid>
		<description>Hi Leesa!  Yes, I&#039;m sure they will have their interpretation of this as well.  Problem is I hear many folks say that they will wait until the regulators tell them what to do, but that won&#039;t work because this is not just a &quot;compliance response&quot; type of regulation.  The risks are real, and account takeover is happening every day.  The regulators may indeed have a slightly different approach, but as long as you stick to the fundamentals of risk management you&#039;ll have fewer, and less severe, findings (and potential losses!).  

As you know, you don&#039;t have to be a mile ahead of the regulators...1/2 inch will do!</description>
		<content:encoded><![CDATA[<p>Hi Leesa!  Yes, I&#8217;m sure they will have their interpretation of this as well.  Problem is I hear many folks say that they will wait until the regulators tell them what to do, but that won&#8217;t work because this is not just a &#8220;compliance response&#8221; type of regulation.  The risks are real, and account takeover is happening every day.  The regulators may indeed have a slightly different approach, but as long as you stick to the fundamentals of risk management you&#8217;ll have fewer, and less severe, findings (and potential losses!).  </p>
<p>As you know, you don&#8217;t have to be a mile ahead of the regulators&#8230;1/2 inch will do!</p>
]]></content:encoded>
	</item>
	<item>
		<title>Comment on Interpreting The New FFIEC Authentication Guidance &#8211; 5 Steps to Compliance by Leesa</title>
		<link>http://www.complianceguru.com/2011/07/interpreting-the-new-ffiec-authentication-guidance/#comment-156</link>
		<dc:creator>Leesa</dc:creator>
		<pubDate>Mon, 18 Jul 2011 15:31:43 +0000</pubDate>
		<guid isPermaLink="false">http://www.complianceguru.com/?p=1925#comment-156</guid>
		<description>Thanks for interpreting this for us, Tom!  &quot;Nothing to it&#039;???  Well, it all depends on how ticky the examiners are!  :)</description>
		<content:encoded><![CDATA[<p>Thanks for interpreting this for us, Tom!  &#8220;Nothing to it&#8217;???  Well, it all depends on how ticky the examiners are!  <img src='http://www.complianceguru.com/wp-includes/images/smilies/icon_smile.gif' alt=':)' class='wp-smiley' /> </p>
]]></content:encoded>
	</item>
	<item>
		<title>Comment on Final FFIEC Authentication Guidance just released by Tom</title>
		<link>http://www.complianceguru.com/2011/06/final-ffiec-authentication-guidance-just-released/#comment-155</link>
		<dc:creator>Tom</dc:creator>
		<pubDate>Thu, 30 Jun 2011 13:29:03 +0000</pubDate>
		<guid isPermaLink="false">http://www.complianceguru.com/?p=1875#comment-155</guid>
		<description>Absolutely correct Jackie.  Personally I was hoping to see something like a stronger MFA + OOB (out-of-band)  requirement, but there was nothing stronger than a recommendation to consider additional controls.  Not only was there no major take-away from this update, but they seemed to water down the MFA requirement, which was the major take-away from 2005.  Very odd.</description>
		<content:encoded><![CDATA[<p>Absolutely correct Jackie.  Personally I was hoping to see something like a stronger MFA + OOB (out-of-band)  requirement, but there was nothing stronger than a recommendation to consider additional controls.  Not only was there no major take-away from this update, but they seemed to water down the MFA requirement, which was the major take-away from 2005.  Very odd.</p>
]]></content:encoded>
	</item>
	<item>
		<title>Comment on Final FFIEC Authentication Guidance just released by Jackie Marshall</title>
		<link>http://www.complianceguru.com/2011/06/final-ffiec-authentication-guidance-just-released/#comment-154</link>
		<dc:creator>Jackie Marshall</dc:creator>
		<pubDate>Wed, 29 Jun 2011 15:39:04 +0000</pubDate>
		<guid isPermaLink="false">http://www.complianceguru.com/?p=1875#comment-154</guid>
		<description>Thanks for sharing excellent commentary on the supplemental guidance. I&#039;d like to add another interesting observation in regard to the specific MFA references. I was really hoping to see a somewhat more descriptive and prescriptive reference to and acknowledgement of MFA (as this has been the most discussed aspect of FI&#039;s following short of the 2005 guidance). Instead, MFA appears to get only a &quot;passing glance&quot; and general reference on page 4...As you stated, removing MFA as a requirement with such lttle supporting detail, does not clarify (Bad and Odd!).</description>
		<content:encoded><![CDATA[<p>Thanks for sharing excellent commentary on the supplemental guidance. I&#8217;d like to add another interesting observation in regard to the specific MFA references. I was really hoping to see a somewhat more descriptive and prescriptive reference to and acknowledgement of MFA (as this has been the most discussed aspect of FI&#8217;s following short of the 2005 guidance). Instead, MFA appears to get only a &#8220;passing glance&#8221; and general reference on page 4&#8230;As you stated, removing MFA as a requirement with such lttle supporting detail, does not clarify (Bad and Odd!).</p>
]]></content:encoded>
	</item>
	<item>
		<title>Comment on SOC 2 vs. SAS 70 &#8211; 5 reasons to embrace the change by Jackie Marshall</title>
		<link>http://www.complianceguru.com/2011/06/soc-2-vs-sas-70-5-reasons-to-embrace-the-change/#comment-124</link>
		<dc:creator>Jackie Marshall</dc:creator>
		<pubDate>Thu, 16 Jun 2011 16:12:56 +0000</pubDate>
		<guid isPermaLink="false">http://www.complianceguru.com/?p=1833#comment-124</guid>
		<description>Excellent information! Thanks for the straight forward interpretation. The new reports (esp SOC 2, Type 2) appear to provide beneficial assurance and will increase the confidence level of FIs in third-party service providers relationships...</description>
		<content:encoded><![CDATA[<p>Excellent information! Thanks for the straight forward interpretation. The new reports (esp SOC 2, Type 2) appear to provide beneficial assurance and will increase the confidence level of FIs in third-party service providers relationships&#8230;</p>
]]></content:encoded>
	</item>
	<item>
		<title>Comment on Management of IT reflects overall management by The IT Strategic Plan – Why, Who, &#38; How : FFIEC Banking Compliance Help presented by Safe Systems – FFIEC Guru</title>
		<link>http://www.complianceguru.com/2011/02/management-of-it-reflects-overall-management/#comment-47</link>
		<dc:creator>The IT Strategic Plan – Why, Who, &#38; How : FFIEC Banking Compliance Help presented by Safe Systems – FFIEC Guru</dc:creator>
		<pubDate>Tue, 17 May 2011 23:31:16 +0000</pubDate>
		<guid isPermaLink="false">http://www.ffiecguru.com/?p=1169#comment-47</guid>
		<description>[...] has been the lack of an IT Strategic Plan. I&#8217;m not sure why the focus lately (perhaps the shift from the CAMELS &#8220;A&#8221; to the &#8220;M&#8221;?), but the concept is certainly not new. The [...]</description>
		<content:encoded><![CDATA[<p>[...] has been the lack of an IT Strategic Plan. I&#8217;m not sure why the focus lately (perhaps the shift from the CAMELS &#8220;A&#8221; to the &#8220;M&#8221;?), but the concept is certainly not new. The [...]</p>
]]></content:encoded>
	</item>
	<item>
		<title>Comment on The FFIEC Handbooks and the SAS 70 by SAS 70 replacement…3 alternatives : FFIEC Banking Compliance Help presented by Safe Systems – FFIEC Guru</title>
		<link>http://www.complianceguru.com/2010/10/the-ffiec-handbooks-and-the-sas-70/#comment-22</link>
		<dc:creator>SAS 70 replacement…3 alternatives : FFIEC Banking Compliance Help presented by Safe Systems – FFIEC Guru</dc:creator>
		<pubDate>Fri, 29 Apr 2011 14:20:15 +0000</pubDate>
		<guid isPermaLink="false">http://www.ffiecguru.com/?p=792#comment-22</guid>
		<description>[...] written about this  here, here and here, and we are still waiting on additional guidance from the AICPA, now expected March/April 2011.   [...] </description>
		<content:encoded><![CDATA[<p>[...] written about this  here, here and here, and we are still waiting on additional guidance from the AICPA, now expected March/April 2011.   [...]</p>
]]></content:encoded>
	</item>
</channel>
</rss>

