Skip to content
BOL Conferences
Thread Options
#347898 - 04/18/05 05:36 PM Incident Response - Timeframe
YosemiteSamIAm Offline
Power Poster
Joined: Jan 2004
Posts: 2,795
Guess
In all the guidance related to Response Programs for Unauthorized Access to Customer Information and Customer Notice (what a mouthful!), I have not seen anything that states WHEN the program must be in place. I assume it is preferable to have it in place before our next examination, but is there a "drop dead" date that anyone in aware of? Have I missed it?

Thanks!
_________________________
Sorry, did I just use my outside voice?

Return to Top
Security - PUBLIC
#347899 - 04/18/05 05:53 PM Re: Incident Response - Timeframe
Anonymous
Unregistered

It is effective now. Regulators are supposed to be "kind" and accept good faith effort to implement as timely as possible.

Return to Top
#347900 - 04/18/05 06:11 PM Re: Incident Response - Timeframe
P*Q Offline

Power Poster
P*Q
Joined: May 2001
Posts: 8,458
Somewhere
Anon is correct, it's effective now and for banks that don't have a program, there will be a little wiggle room for a little bit but if you don't currently have one, I'd suggest you do so immediately.

Return to Top
#347901 - 04/18/05 06:32 PM Re: Incident Response - Timeframe
Anonymous
Unregistered

The guidance is an interpretation of existing provisions in section 501(b) of the GLBA and Information Security Guidelines. Therefore, a delayed effective date is not required. Financial institutions should implement the interpretive guidance as soon as possible. The agencies recognize that not every financial institution currently has a response program that is consistent with the interpretive guidance. The agencies will take into account the good faith efforts made by each institution to develop a response program that is consistent with the interpretive guidance, however; any financial institution experiencing a breach in security that includes unauthorized access to customer information is expected to respond promptly in a manner consistent with the guidance, and provide customer notice, if warranted.

Return to Top
#347902 - 04/19/05 01:35 PM Re: Incident Response - Timeframe
YosemiteSamIAm Offline
Power Poster
Joined: Jan 2004
Posts: 2,795
Guess
Thank you everyone!
_________________________
Sorry, did I just use my outside voice?

Return to Top

Moderator:  Andy_Z