Welcome Guest. | Log In | Register | Membership Benefits

Financial Institutions Shoring Up Compliance Plans For FFIEC Deadline

Most large to midsize banks are well on their way with at least a road map to comply with tougher FFIEC authentication and anti-fraud guidelines

Nov 07, 2011 | 05:00 PM | 

By Ericka Chickowski, Contributing Editor
Dark Reading


For banking and financial organizations, Jan. 1 looms large as deadline day for a new set of regulations under the supplements added to the Federal Financial Institutions Examination Council's (FFIEC) "Authentication in an Internet Banking Environment" guidance. First developed in 2005 to require multifactor authentication, the new guidance released this past June added stronger requirements for increased layers of security to combat the increased threats of fraud that are assaulting institutions by the hour.

"In the intervening five years since the guidance first came out, the threat environment in terms of fraudsters and cybercriminals simply kept getting worse and worse, to the point where they were defeating multifactor authentication. It was appropriate for us to put out a supplement," says Jeff Kopchik, senior policy analyst with the Federal Deposit Insurance Corp.'s Division of Risk Management Supervision, and one of the authors of the guidance.

"Banks are moving to other security controls that address the reality the FFIEC notes: 'Virtually all authentication techniques can be compromised.' If someone hijacks your computer, it doesn't matter how you've authenticated yourself,” says Kevin Bocek, director of product marketing for online banking security firm IronKey. "They're inside your browser and inside your computer. So what's really happening is the banks are moving to secure browsing as a way to isolate customers from any threats on the computer. That’s their motivation, and that’s what IronKey customers are saying."

East Carolina Bank, The Coastal Bank, and Fairfield County Bank are recent examples of customers that have added IronKey Trusted Access as an additional layer to prevent successful execution of attacks on customers’ computers.

Some of the added controls FFIEC demands are fraud-prevention measures, such as anomaly detection, and more frequent assessment of risks than annual reviews to keep up with the dynamic nature of today's threats.

"One of the things that the supplement really talks about is that the banks need to use layered security to protect online banking. In other words, it can't just rely on controls at log-in to screen the customer, and then once the customer has logged in to basically just forget about it," Kopchik says. "The bank needs to have different types of controls at different points in the process to constantly be looking for what we refer to as anomalous activity."

The guidance also specifically calls for greater protection for business banking customers, which were not mentioned before -- a fact that had many banks assuming the regulation was solely consumer-focused.

"I think it's significant that the agency for the first time distinguished between retail accounts and business accounts and set standards for each, " Kopchik says. "The reason for that is the agency said, in our opinion the risk posed to business accounts is greater because business accounts tend to have more transactions flowing through them, so it's more difficult to monitor and, quite frankly, they have more money flowing out of them and more funds going out more frequently, so there are potentially more bad things that could happen there."

According to many within the security world, the banking industry is in a much better state to deal with the increased regulations now than it was in 2005. Many banking institutions have already employed anti-fraud technologies to stem the losses they've faced in recent years; the FFIEC is simply helping them tie those efforts together.

"Many organizations have deployed anti-fraud controls over the past few years, creating a foundation for compliance. However, some organizations have deployed these controls in response to fraud losses without a coherent fraud-prevention strategy," says Yishay Yovel, vice president of marketing for Trusteer. "We believe the FFIEC compliance process will drive organizations to assess the quality and effectiveness of their controls and make the necessary changes."

Even those organizations that might be missing specific pieces of technology or processes to truly create a cohesive and compliant program are likely already on their way with a plan to get there.

"Within any large organization, trying to get something done in six months technology-wise is very hard -- you've got lots of different systems to deal with, you've got budgets and other projects that are in flight, so some of those are the execution challenges organizations face," says Ben Knieff, director of product marketing at NICE Actimize. "But most of the larger organizations and even the midsize organizations we have talked to have got their road map in place. They've got a plan, and they've got a budget, and if a regulator were to walk in in January, they'd be in good shape because they could show they're executing a very clear plan."

This, says Kopchik, is really what the examiners will be looking for. As he puts it, the agencies participating in the FFIEC are realists. They understand that not everyone will have executed on their compliance plan by Jan. 1. But he does warn that they better have one by then.

"What examiners will be concerned about is if they go into an institution shortly after the first of the year and the institution either doesn't even know about the guidance -- that's a problem -- or they do know about it, but they haven't done anything to try to prepare and get a plan together to get into conformance," Kopchik says. "And if we go farther into the year, the examiners will expect that institutions that have exams at the end of the year will be more likely to be in compliance and closer to conformance than exams that will be done in the first quarter."

According to Kopchik, documentation is key for the examiners.

"Have some sort of planning documents that can show the examiner what you've done. If you've got nothing down on paper, examiners sometimes become uncomfortable with that. They get concerned that maybe you really haven't been working on it as long as you told them," he says.

"But if you can show them some documents that show them you did put your teams together two weeks after or a month after the guidance was issued, and the team has met on X number of occasions and that's recorded in some fashions, examiners are much more comfortable with that."

Have a comment on this story? Please click "Add Your Comment" below. If you'd like to contact Dark Reading's editors directly, send us a message.



Currently we allow the following HTML tags in comments:

Single tags

These tags can be used alone and don't need an ending tag.

<br> Defines a single line break

<hr> Defines a horizontal line

Matching tags

These require an ending tag - e.g. <i>italic text</i>

<a> Defines an anchor

<b> Defines bold text

<big> Defines big text

<blockquote> Defines a long quotation

<caption> Defines a table caption

<cite> Defines a citation

<code> Defines computer code text

<em> Defines emphasized text

<fieldset> Defines a border around elements in a form

<h1> This is heading 1

<h2> This is heading 2

<h3> This is heading 3

<h4> This is heading 4

<h5> This is heading 5

<h6> This is heading 6

<i> Defines italic text

<p> Defines a paragraph

<pre> Defines preformatted text

<q> Defines a short quotation

<samp> Defines sample computer code text

<small> Defines small text

<span> Defines a section in a document

<s> Defines strikethrough text

<strike> Defines strikethrough text

<strong> Defines strong text

<sub> Defines subscripted text

<sup> Defines superscripted text

<u> Defines underlined text

Dark Reading encourages readers to engage in spirited, healthy debate, including taking us to task. However, Dark Reading moderates all comments posted to our site, and reserves the right to modify or remove any content that it determines to be derogatory, offensive, inflammatory, vulgar, irrelevant/off-topic, racist or obvious marketing/SPAM. Dark Reading further reserves the right to disable the profile of any commenter participating in said activities.

Disqus Tips To upload an avatar photo, first complete your Disqus profile. | View the list of supported HTML tags you can use to style comments. | Please read our commenting policy.
Subscribe to RSS



Compliance Reports

report How To Boost Security Via FFIEC Compliance
With just a smartphone, users can conduct nearly all their banking business at any time of the day or night. However, all this flexibility and convenience opens up new avenues for fraud and cybercrime. Guidelines laid out by the FFIEC several years ago predate many of the capabilities-and vulnerabilities-that are in place today. In this report, we examine the latest guidelines and provide advice on how you can extend the work done to comply with FFIEC guidelines to strengthen your organization's overall security posture and keep customers and their data safe.

report Keeping Compliance In Check
Configuration mistakes, access control gaffes, poor documentation--it doesn?t take much for a compliance audit to go all wrong. In this special retrospective of recent news coverage, Dark Reading takes a look at the costs, common missteps and best practices for compliance, as well as the day the Internet nearly went dark due to the threat of new regulations.

report FISMA Lifts All Compliance Boats
FISMA may not be on your radar now, but it likely will be at some point. Geared specifically toward the federal government and its affiliate agencies and third parties, FISMA is a very specific set of requirements aimed at establishing and maintaining at least a baseline level of computer and network security. FISMA requires unique categorization and classification of information assets, not to mention a boatload of documentation to prove compliance. But once your organization achieves FISMA compliance, it will likely be compliant with just about every security mandate out there.

Other reports from the Compliance Tech Center:

Related Content

Log Management in 2012 and Beyond
2012 brings interesting changes to the log management world. Now, more than ever, it is critical to understand the impact to your log infrastructure and the solutions that will better prepare you to manage your security posture.

SANS Log Management Survey Report
Organizations are increasingly dependent on log management to support core business functions, including cost management, service level and line-of-business application monitoring, as well as traditional IT- and security-focused activities.

Cut the Time and Effort of Troubleshooting and Reporting
Organizations generate millions of logs a day and struggle with centralized collection, storage and analysis of those logs. ArcSight Logger is a universal log management solution that unifies searching, reporting, alerting and analysis across any type of IT data. It consolidates silos of logs into a single indexed repository for fast detection and mitigation of operational issues.

Get Turnkey and Automated PCI Compliance
PCI compliance monitoring is seamless with the self-contained ArcSight PCI Logger solution for log collection, storage and analysis. No database administration expertise is required and a web-based interface simplifies deployment and ongoing management.

Swiss Bank Meets Compliance Requirements and Protects Customer Data
Due to long-term data retention requirements, Swiss bank EFG needed a cost-effective way to collect, secure and store audit-quality log data in an easily accessible log repository. ArcSight Logger helps EFG meet key requirements of Switzerland?s banking laws fast and cost-effectively.




Featured Webcasts
Featured Whitepapers
Featured Reports