Skip to content
BOL Conferences
Thread Options
#1392580 - 05/18/10 03:33 PM FDIC and freeware/shareware
MarieR Offline
Platinum Poster
Joined: Nov 2005
Posts: 614
My IT department remembers reading something from the FDIC in regards to Shareware and Freeware programs. They can't find it now and have asked for my help. This is not my area, but do any of you know about such guidance? I appreciate your help. Thanks
_________________________
CRCM

Return to Top
eBanking / Technology
#1393297 - 05/19/10 02:51 PM Re: FDIC and freeware/shareware MarieR
MyBrainHurts Offline
Platinum Poster
Joined: Feb 2010
Posts: 960
Illinois
See the section in the FFIEC IT Information Security exam booklet called Software Development and Acquisition. It runs from page 63 to 66, and talks about the care one should take in knowing the developer of the software. That would eliminate the use of freeware and shareware whose authors aren't known and where the code cannot be examined.

Link to the booklets: http://www.ffiec.gov/ffiecinfobase/html_pages/It_01.html
_________________________
I thought getting old would take longer.

Return to Top
#1393775 - 05/20/10 12:23 PM Re: FDIC and freeware/shareware MyBrainHurts
MarieR Offline
Platinum Poster
Joined: Nov 2005
Posts: 614
Thank you - that is exactly what they were looking for.
_________________________
CRCM

Return to Top
#1395031 - 05/24/10 01:01 PM Re: FDIC and freeware/shareware MarieR
Russ Horn Offline
100 Club
Russ Horn
Joined: May 2008
Posts: 139
The FDIC released an FIL in 2004 titled “Risk Management of Free and Open Source Software” (FIL-114-2004). You can access it here.

Hope this helps some.

Thanks,
Russ
_________________________
Russ Horn, CISA, CISSP, CRISC
CoNetrix
rhorn@conetrix.com

Return to Top

Moderator:  Andy_Z