Carefully consider the risks of wireless technology;
Take appropriate steps to mitigate the risks before deploying either wireless networks or applications.
The Appendix to the FIL is divided into three major parts:
Risks Associated with Wireless Internal Networks
Risks Associated with Wireless Internet Devices
Risks Associated with Both Internal Wireless Networks and Wireless Internet Devices
If your institution utilizes a wireless network or is going to be offering wireless customer access, someone in your institution should study the FIL (even if you aren't a state chartered bank, because it's still solid protective guidance, regardless of your charter type) and formulate a checklist from it of steps to take and points to consider.
FDIC suggests that appropriate steps to mitigate risk could include:
* Establishing a minimum set of security requirements for wireless networks and applications;
* Adopting proven security policies and procedures to address the security weaknesses of the wireless environment;
* Adopting strong encryption methods that encompass end-to-end encryption of information as it passes throughout the wireless network;
* Adopting authentication protocols for customers using wireless applications that are separate and distinct from those provided by the wireless network operator;
* Ensuring that the wireless software includes appropriate audit capabilities (for such things as recording dropped transactions);
* Providing appropriate training to IT personnel on network, application and security controls so that they understand and can respond to potential risks; and
* Performing independent security testing of wireless network and application implementations.
The original version appeared in the January/February 2002 edition of the Oklahoma Bankers Association Compliance Informer.
BankersOnline is a free service made possible by the generous support of our
advertisers and sponsors. Advertisers and sponsors are not responsible for site content. Please help us keep BankersOnline FREE to all
banking professionals. Support our advertisers and sponsors by clicking
through to learn more about their products and services.