Skip to content
BOL Conferences
Thread Options
#557620 - 05/24/06 09:12 PM Multi-Factor Authentication Prep Poll
Andy_Z Offline
10K Club
Andy_Z
Joined: Oct 2000
Posts: 27,749
On the Net
If you have internet banking or telephone banking, the FFIEC multi-factor authentication guidance requires that you be ready by year end. This is an anonymous survey to check on preparations.
As the MF preparation requirements go:
single choice


Votes accepted starting: 05/24/06 09:11 PM
You must vote before you can view the results of this poll.
_________________________
AndyZ CRCM
My opinions are not necessarily my employers.
R+R-R=R+R
Rules and Regs minus Relationships equals Resentment and Rebellion. John Maxwell

Return to Top
eBanking / Technology
#557621 - 05/25/06 03:15 PM Re: Multi-Factor Authentication Prep Poll
deppfan Offline
Power Poster
Joined: Dec 2000
Posts: 5,184
All over the map.
May I ask what others are actually using? I'm hoping for the grid card, or "bingo" card (as our provider calls it), but we may end up with the key token.
_________________________
On the road again.....I just can't wait to get on the road again.

Return to Top
#557622 - 05/27/06 03:16 PM Re: Multi-Factor Authentication Prep Poll
ChicagoGuy Offline
Diamond Poster
ChicagoGuy
Joined: Nov 2003
Posts: 1,577
Chicago, IL
DI (digital insight) is our vendor. They are a pretty good sized vendor. They are basically using a combination of "placing a cookie on the pc" and the use of challenge questions for authorization. They will allow someone to use multiple computers (home, work, etc.) if they so choose.

Return to Top
#557623 - 05/30/06 02:11 PM Re: Multi-Factor Authentication Prep Poll
Neytiri Offline
Platinum Poster
Neytiri
Joined: Jul 2002
Posts: 645
Pandora
We are going to have customers answer their security question for authorization in additon to ID and passcode, plus suggest they change passcode and security question every 30 days. We also review a daily login report that risk rates customer logins on various categories; anyone getting a high score we call. OCC was OK with this approach.

Return to Top
#557624 - 05/30/06 11:58 PM Re: Multi-Factor Authentication Prep Poll
Dip Offline
Power Poster
Dip
Joined: Mar 2005
Posts: 6,298
San Diego, CA
we use Digital Insight as well and their method seems reasonable and less cumbersome than having to change your password every 30 days
_________________________
Dabbling in banking, law, accounting...the life of a trustee.

Return to Top
#557625 - 06/08/06 03:43 PM Re: Multi-Factor Authentication Prep Poll
RR Sarah Offline
Power Poster
RR Sarah
Joined: Mar 2004
Posts: 2,505
Up North
We will be using a challenge/response question. Has anyone actually done the risk assessment yet?
_________________________
Sometimes you have to burn a few bridges to keep the crazies from following you.

Return to Top
#557626 - 06/08/06 03:55 PM Re: Multi-Factor Authentication Prep Poll
deppfan Offline
Power Poster
Joined: Dec 2000
Posts: 5,184
All over the map.
Don't you have to use any two of the following 3?
1. Something you know (password, pin#...)
2. Something you are (biometrics ~ fingerprint, retinal scan...)
3. Something you have (grid card, key token...)

How can they use a password AND a pin number, and still be in compliance?
_________________________
On the road again.....I just can't wait to get on the road again.

Return to Top
#557627 - 06/09/06 01:51 PM Re: Multi-Factor Authentication Prep Poll
Oursisnottoreasonwhy Offline
Platinum Poster
Oursisnottoreasonwhy
Joined: Nov 2004
Posts: 503
Central Illinois
Password plus Pin plus Challenge Question = non compliance in my understanding of the FIL. As Deppfan states you have to have 2 of the 3 to have dual authentification. Having 3 somethings you know instead of 2 doesn't cut it.

Return to Top
#557628 - 06/09/06 03:36 PM Re: Multi-Factor Authentication Prep Poll
deppfan Offline
Power Poster
Joined: Dec 2000
Posts: 5,184
All over the map.
Gurus? Am I overthinking this, or do these companies need to re-read the FIL?
_________________________
On the road again.....I just can't wait to get on the road again.

Return to Top
#557629 - 06/09/06 04:32 PM Re: Multi-Factor Authentication Prep Poll
inbtfa Offline
New Poster
Joined: Jun 2006
Posts: 7
Both of these seem to be what the customer knows?

Return to Top
#557630 - 06/09/06 09:03 PM Re: Multi-Factor Authentication Prep Poll
RR Sarah Offline
Power Poster
RR Sarah
Joined: Mar 2004
Posts: 2,505
Up North
Okay, you guys had me questioning our decision as a bank. To clarify, our added security is not simply a challenge question but will monitor IP addresses, transaction patterns and the like. So anyway, I went back and reread the FFIECs guidance and Deppfan, the three things you listed are basic factors in authentication methodologies. From what I can understand of what I read, the level of security you choose is risk based and, according to the Conclusion paragraph, "Where risk assessments indicate that the use of single-factor authentication is inadequate, financial institutions should implement multifactor authentication, layered security, or other controls reasonably calculated to mitigate those risks."
_________________________
Sometimes you have to burn a few bridges to keep the crazies from following you.

Return to Top
#557631 - 06/09/06 10:32 PM Re: Multi-Factor Authentication Prep Poll
Dip Offline
Power Poster
Dip
Joined: Mar 2005
Posts: 6,298
San Diego, CA
can something you have be a cookie installed on your computer after successfully answering 2 or three questions? if so, then somethgin you knwo if the password, and somethign you have is the cookie. right?
_________________________
Dabbling in banking, law, accounting...the life of a trustee.

Return to Top
#557632 - 06/12/06 03:04 PM Re: Multi-Factor Authentication Prep Poll
BusyInOz Offline
New Poster
Joined: Jun 2006
Posts: 4
Kansas
My question...exactly what does the FFIEC Guidance apply too? I am hearing (and reading in your poll) that more than just Internet Access should be considered. How have others interpreted this guidance (does it apply to telephone banking-whether automated or call center)? Thanks in advance!!

Return to Top
#557633 - 06/12/06 06:58 PM Re: Multi-Factor Authentication Prep Poll
PJ Offline
100 Club
Joined: Sep 2005
Posts: 115
SarahH - just remember that regulators consider transactional websites to be high risk.

Return to Top
#557634 - 06/12/06 07:23 PM Re: Multi-Factor Authentication Prep Poll
RR Sarah Offline
Power Poster
RR Sarah
Joined: Mar 2004
Posts: 2,505
Up North
Thanks, I understand that. We actually have an exam next month so I will let you all know if they find our risk assessment and solution acceptable. According to our lead examiner they do not have a lot of guidance themselves yet so it should be interesting.

So then what I got from the guidance is that the reason we do the risk assessment is to determine whether or not single factor authentication is still a viable option. We did ours and determined that no it was not. So, we looked to our internet banking provider to see what options they would be providing. They had two options and we went with the more vigorous of the two. Not that I want the examiners to get here any quicker but I am real curious to hear from them what they find acceptable.
_________________________
Sometimes you have to burn a few bridges to keep the crazies from following you.

Return to Top
#557635 - 06/12/06 07:35 PM Re: Multi-Factor Authentication Prep Poll
Skittles Online
10K Club
Skittles
Joined: Sep 2002
Posts: 13,965
TN
OK - I've been out of banking (in a compliance role) for approximatley 14 months. I am unfamiliar with the m utli-factor authentication. Where can I find out more information, please?
_________________________
My Opinions Only

Return to Top
#557636 - 06/12/06 07:43 PM Re: Multi-Factor Authentication Prep Poll
RR Sarah Offline
Power Poster
RR Sarah
Joined: Mar 2004
Posts: 2,505
Up North
Skittles, you can get the guidance from the FFIEC website. I don't know how to do the "click here for the link", sorry.
_________________________
Sometimes you have to burn a few bridges to keep the crazies from following you.

Return to Top
#557637 - 06/12/06 09:07 PM Re: Multi-Factor Authentication Prep Poll
Oursisnottoreasonwhy Offline
Platinum Poster
Oursisnottoreasonwhy
Joined: Nov 2004
Posts: 503
Central Illinois

Return to Top
#557638 - 06/12/06 10:18 PM Re: Multi-Factor Authentication Prep Poll
Dip Offline
Power Poster
Dip
Joined: Mar 2005
Posts: 6,298
San Diego, CA
hi guys...we offer bill pay on our website, but customers may add "PEOPLE" to their billpay payees. thsi seems really risky to me...I'm callign it high risk, but has anyone esle heard of banks allowing this? i thought you could only set up companies for bill pay, nto individual people.

your thoughts?
_________________________
Dabbling in banking, law, accounting...the life of a trustee.

Return to Top
#557639 - 06/15/06 07:10 PM Re: Multi-Factor Authentication Prep Poll
deppfan Offline
Power Poster
Joined: Dec 2000
Posts: 5,184
All over the map.
Do you have your own bill payment service, or do you have another company that actually is the provider?
_________________________
On the road again.....I just can't wait to get on the road again.

Return to Top
#557640 - 06/18/06 01:20 AM Re: Multi-Factor Authentication Prep Poll
smalone Offline
New Poster
smalone
Joined: Nov 2003
Posts: 10
Kentucky
We are also a DI bank and was wondering if you had gotten a response about the risk assessment. I have been reading everything that DI has produced regarding the assessment and just not sure where to start.

Return to Top
#557641 - 06/26/06 08:31 PM Re: Multi-Factor Authentication Prep Poll
Joseph Steinberg Offline
New Poster
Joined: Apr 2006
Posts: 6
Hackensack, NJ, USA
Green Armor Solutions is offering a free multi-factor authentication checklist on its web site:

http://www.greenarmor.com/a-checklistforum.shtml

Return to Top
#557642 - 06/26/06 09:03 PM Re: Multi-Factor Authentication Prep Poll
UKcatsFan Offline
100 Club
UKcatsFan
Joined: Dec 2004
Posts: 141
Anywhere but here
I attended a PBS seminar on Compliance and Internet Banking last week and this issue came up. The instructor indicated that the regulators weren't requiring institutions to have thier multifactor authentication in place by year end, only that they had taken reasonable steps towards getting it in place. His reasonable steps included:

- risk assessment
- implementing a customer awareness program

thoughts?
_________________________
I still say Christian Laettner didn't get the shot off in time!!

Return to Top
#557643 - 06/27/06 02:31 PM Re: Multi-Factor Authentication Prep Poll
vaforlovers Offline
100 Club
Joined: Nov 2004
Posts: 107
What is everyone doing for the customer awareness program?
How are you going about educating the customers?

Return to Top

Moderator:  Andy_Z