October 1, 2010 7:41 PM
Posted by: David Schneier
Audit,
bank,
banking,
compliance,
credit union,
CU,
FDIC,
FFIEC,
financial,
financial institutions,
personally identifiable informaiton,
regulations,
regulatory,
Regulatory Compliance,
security PIIGrowing up I was a huge fan of the sitcom "The Odd Couple." Some of my favorite catch phrases have in some part been influenced by lines of dialogue that I memorized. One in particular serves as the best pure definition for a phenomenon I encounter frequently enough in my audit/compliance...
January 27, 2010 12:13 AM
Posted by: David Schneier
bank,
banking,
Basel,
FDIC,
FFIEC,
GLBA,
NCUA,
Regulatory ComplianceI was scanning through emails the other day and almost missed a good one. It was from the FDIC on Friday, January 22. As we’ve all come to know Friday is the FDIC’s equivalent of “bring out the dead day” when they almost always announce the...
July 17, 2009 1:58 PM
Posted by: David Schneier
Audit,
compliance,
cyber security,
FFIEC,
GLBA,
PCI,
regulations,
Regulatory Compliance,
Security,
SOXDespite earning a living in the space, I often question the value of regulatory compliance.
How is it that a business can be PCI-compliant but still have glaring vulnerabilities? How is it that despite layer upon layer of controls...
May 20, 2009 7:31 PM
Posted by: David Schneier
Audit,
FDIC,
FFIEC,
fraud,
GLBA,
NCUA,
phishing,
Regulatory ComplianceMy practice has been busy lately helping a number of clients catch up on required tasks before their scheduled exams (it's a case of the old "if it wasn't for the last minute nothing would ever happen" philosophy). And in authoring some of our reports we're identifying issues and gaps that are in...
April 27, 2009 5:28 PM
Posted by: David Schneier
bcp,
business continuity planning,
FFIEC,
GLBA,
NCUA,
pandemic,
Regulatory ComplianceI started my day yesterday by finding my 12-year-old sitting with his eyes riveted on the laptop screen reading what I figured was something either on Facebook or a sports related website. I only wish. Turns out he was fixated on the breaking news covering the swine flu.
Much like his...
April 13, 2009 9:36 PM
Posted by: David Schneier
FDIC,
FFIEC,
GLBA,
Regulatory Compliance,
shared assessment,
Vendor ManagementI received an email from a colleague last week in regards to my recent post about the BITS Shared Assessments Program. In the entry I offered my high opinion of the framework but went out of my way to point out that by itself the assessment is not a vendor management program. The subject line...