Red Flag – Separate Program Required?
by Russ Horn, CISA, CISSP
Question:
I already have Identity Theft covered in my Information Security Program or Fraud Prevention Program, is that good enough or do I need a separate Identity Theft Prevention Program document?
Answer: Unfortunately, the final ruling clearly states you must have a separate written Identity Theft Prevention Program designed to detect, prevent, and mitigate identity theft in connection with opening or accessing covered accounts. However, you can incorporate into your Identity Theft Prevention Program existing policies and procedures, such as those already developed in connection with your Information Security Program, Fraud Prevention Program, or Customer Identification Program.
CoNetrix specializes in providing information technology consulting and security and compliance services for banks. We offer a wide variety of solutions including IT/GLBA Audit and Assessment, Penetration Testing, Security Policies, Business Continuity Planning, Network Design and Implementation, Security Awareness Training, Information Security Program, and Identity Theft Prevention Program (Red Flag). For additional information, please call (800) 356-6568, e-mail info@conetrix.com or visit us at www.CoNetrix.com.
BankersOnline is a free service made possible by the generous support of our advertisers and sponsors. Advertisers and sponsors are not responsible for site content. Please help us keep BankersOnline FREE to all banking professionals. Support our advertisers and sponsors by clicking through to learn more about their products and services.