On September 9, 2016, the Federal Financial Institutions Examination Council (FFIEC) released a revision of its IT Booklet on Information Security. In line with previous updates made by the FFIEC, the goal of the revision is to better standardized measures for determining, assessing, and manage risks to information technology solutions. The updates reduced redundancies, incorporated relevant cybersecurity language, and re-emphasized risk management as a program and process to be developed, implemented, and maintained. Also included is revised examination procedures, to again increase standardization, of risk management program evaluation amongst auditors and Federal examiners. The FFIEC continues to leverage the NIST Cybersecurity Framework as it did when developing and adopting the Cybersecurity Assessment Tool (CAT).
Questions or concerns about how these latest updates will impact your Compliance and Information Security programs? Contact GraVoc’s Information Security Department below.
In this blog post, we provide five cybersecurity awareness tips for employees to help them practice better cyber hygiene and defend sensitive data.
Click here to access KnowBe4’s FREE Resource Kit containing resources to share with employees throughout Cybersecurity Awareness Month!
We explore the top 3 red flags of phishing that businesses & employees should be aware of in order to recognize & mitigate a threat.