Skip to content
BOL Conferences
Thread Options Tools
#96579 - 07/11/03 06:59 PM Customer Info Security report to board or committe
BKB Offline
100 Club
BKB
Joined: May 2002
Posts: 120
Midwest
I am curious how other banks may be handling who reports to the board each year on the effectiveness, etc. of the bank's customer information security program.

Would the audit report suffice? Or should the customer information security officer (CISO) complete the report? Or a combination of both?

Return to Top
General Discussion
#96580 - 07/11/03 07:02 PM Re: Customer Info Security report to board or committe
Andy_Z Online
10K Club
Andy_Z
Joined: Oct 2000
Posts: 27,735
On the Net
Our COO overseas the data center, operations and security. He provides a report for us as he is always in the board meeting anyway.
_________________________
AndyZ CRCM
My opinions are not necessarily my employers.
R+R-R=R+R
Rules and Regs minus Relationships equals Resentment and Rebellion. John Maxwell

Return to Top
#96581 - 07/11/03 07:12 PM Re: Customer Info Security report to board or committe
111 Offline
Gold Star
111
Joined: Jun 2003
Posts: 484
The Customer Information Security Officer should report to the board, either directly or through someone that he/she reports to that attends the board meetings.

Return to Top
#96582 - 07/11/03 07:22 PM Re: Customer Info Security report to board or committe
BKB Offline
100 Club
BKB
Joined: May 2002
Posts: 120
Midwest
Any banks relying on audit to prepare and submit this report to the audit committee, as part of their audit of this area?

Return to Top
#96583 - 07/11/03 07:47 PM Re: Customer Info Security report to board or committe
Lu Offline
Platinum Poster
Joined: Apr 2002
Posts: 597
We just had an FDIC exam and they said that it would be fine for me as the Internal Auditor to report on the program when I perform the audit.
_________________________
"If you only laugh and enjoy life when your problems are all solved, you'll never enjoy life."

Return to Top
#96584 - 07/11/03 08:02 PM Re: Customer Info Security report to board or committe
Risk Officer Offline
100 Club
Joined: Apr 2001
Posts: 205
Dallas
The Information Security Officer sends a dedicated report to the board annually specifically addressing the areas mentioned in the law.
_________________________
My opinions are just that...my opinions.

Return to Top
#96585 - 07/11/03 08:24 PM Re: Customer Info Security report to board or committe
Michelle D Offline
Gold Star
Michelle D
Joined: Oct 2001
Posts: 313
Terminator Country
We're the same, the Info Security Officer submits and discusses the annual report, IA only addresses deficiencies in program and does not adress any of the other "reportable" issues. We do however, try and make both reports in the same month so that they get the most complete picture available.
_________________________
The opinions are mine and do not necessarily reflect those of my employer.

Return to Top