Skip to content
BOL Conferences
Thread Options
#1986422 - 01/05/15 10:57 PM FDIC Exam request
dg Offline
Platinum Poster
Joined: Jan 2005
Posts: 811
Pacific NW
Upcoming exam request includes a list of reports management/BOD use to monitor compliance with GLBA and reports given to the BOD. Not sure what they are asking for, we do not have a formal monitoring system for GLBA. We have a information privacy policy that is reviewed and approved annually. Would this suffice?

Return to Top
eBanking / Technology
#1986431 - 01/06/15 01:36 AM Re: FDIC Exam request dg
rlcarey Offline
10K Club
rlcarey
Joined: Jul 2001
Posts: 83,370
Galveston, TX
IT audits, penetration testing, vendor due diligence - there is a lot more to GLBA compliance than writing and approving a policy.
_________________________
The opinions expressed here should not be construed to be those of my employer: PPDocs.com

Return to Top
#1986457 - 01/06/15 02:26 PM Re: FDIC Exam request dg
Russ Horn Offline
100 Club
Russ Horn
Joined: May 2008
Posts: 139
I believe that request is coming from 12 CFR Part 364 Appendix B III F:

"Report to the Board. Each bank shall report to its board or an appropriate committee of the board at least annually. This report should describe the overall status of the information security program and the bank's compliance with these Guidelines. The report, which will vary depending upon the complexity of each bank's program should discuss material matters related to its program, addressing issues such as: risk assessment; risk management and control decisions; service provider arrangements; results from testing; security breaches or violations, and management's response; and recommendations for changes in the information security program."

Last edited by Russ Horn; 01/06/15 02:27 PM.
_________________________
Russ Horn, CISA, CISSP, CRISC
CoNetrix
rhorn@conetrix.com

Return to Top

Moderator:  Andy_Z