-
Reading Between the Lines: Recent Regulatory News
March 30, 2020 – Federal Reserve Statement on Supervisory Activities Where did it come from, and where can I find it? The Federal Reserve Who needs to know about it? All financial institutions supervised by the Federal Reserve Why was it Issued? To address adjustments in their supervisory approach in light of COVID-19 What does […]
-
Are You Required to Address Your COVID-19 Readiness with Your Customers?
Hey Guru! Are we required to post any kind of statement to the public or our customers as to our readiness for the COVID-19? If so, can you direct me to the kinds of things we need to say? We are working on an ad to educate our customers on how to use our online […]
-
FFIEC Rewrites Business Continuity Guidance
The all new IT Examination Handbook is more than an update, it’s a complete re-write, and represents a significant change in how the business continuity process is managed. It also has several new expectations regulators will be looking for from financial institutions1. In fact, that is one of the most interesting changes; the term “institution” […]
-
Using Risk Scoring to Determine the Frequency of IT Audits
Hey Guru! In my last IT examination, one of the findings was that the scope and cycle of our IT audits should be more closely tied to risk. We have IT audits every 12 months, what else should we be doing? By conducting Information Technology audits every 12 months, you’ve effectively (and correctly) determined that […]
-
Asset Lifecycle Management
Since both Windows 7 and Server 2008 R2 will reach end-of-life support in January of 2020, many organizations have already made the jump to Windows 10 and Windows Server 2012, 2016, 2019, or Azure. If you have full control over the asset lifecycle management process for your financial institution you may have already completed this […]
-
Ask the Guru: Do We Need to Perform a review on a New Vendor in a Foreign Country?
Hey Guru! Our institution works with a third-party that has recently engaged with a company in a foreign county to begin assisting them in taking care of our institution’s IT matters. Do we need to perform a review on this new foreign third-party? When evaluating this situation, the first step is to understand the parties […]