Skip to content
BOL Conferences
Thread Options Tools
#9070 - 01/17/02 08:58 PM Information Security/Privacy Exam
SusyG Offline
100 Club
Joined: Oct 2001
Posts: 120
Would it be appropriate to combine the two programs for examiner review since there is some duplication? I have read the threads discussing exam experience, anything else lately?



Return to Top
General Discussion
#9071 - 01/19/02 01:30 AM Re: Information Security/Privacy Exam
Bear Collector, CRCM Offline
Diamond Poster
Bear Collector, CRCM
Joined: Nov 2000
Posts: 1,830
District of Columbia
SusyG,
I don't know what kind of financial institution you are, but we are examined by the Federal Reserve. We are currently undergoing our first exam since Privacy was rolled out last year. The Fed examined our IS Policy as part of their IT exam, and will look at Privacy under Safety and Soundness. They did want to see our Privacy Policy during the IT exam, but not our Privacy Notice or our Identity Theft/Pretext Calling Policies. Therefore, combining the two would not have worked for us. Was that your question? I'm not sure I understood it completely.
Leslie
_________________________
Being kind is more important than being important.

Return to Top
#9072 - 01/22/02 03:31 PM Re: Information Security/Privacy Exam
SusyG Offline
100 Club
Joined: Oct 2001
Posts: 120
That's exactly what I needed to know. Thanks for the info!!!!Hope your exam went well.

[This message has been edited by SusyG (edited 01-22-2002).]


Return to Top
#9073 - 01/22/02 04:46 PM Re: Information Security/Privacy Exam
Ted Dreyer Offline
Diamond Poster
Ted Dreyer
Joined: Apr 2001
Posts: 2,245
Leslie: I'm not surprised that the examiners didn't look at the Privacy Notice, but are you sure that they didn't deal with the issue of preventing pretext calling? Section III(C)(1)(a) of the Information Security Guidelines lists "...controls to prevent employees from providing customer information to unauthorized individuals who may seek to obtain this information through fraudulent means" as one of the issues that should be addressed in an IS program. I realize that you aren't responsible for what the Fed examiners did or didn't do, but I can't imagine how the above quoted language doesn't require consideration of pretext calling.

------------------
This is a personal observation that should not be taken as legal advice nor relied upon for any purpose.


Return to Top