Finosec Official Blog

What Auditors and Examiners Expect You to Have Implemented For the Updated FFIEC Authentication Guidance

Zach Duke posted in Cybersecurity, FFIEC, User Access Reporting, preparedness, Risk Assessment, information security, Risk, Risk Review, infosec

0 Comments

The Federal Financial Institutions Examination Council (FFIEC) updated its Authentication Guidance in August 2021, which aims to standardize and enhance security measures for financial institutions. We are seeing a focus on these areas during exams and audits, and understanding these new guidelines is crucial for compliance and risk management.

Read More

Safeguarding Your Assets: Preventing Privilege Creep

Beth Sumner posted in Cybersecurity, system map, self assessment, User Access, User Access Reporting, training, preparedness, Risk Assessment, information security, Risk, Risk Review, infosec

0 Comments

Today, we’re delving into an essential topic that affects both the security and the integrity of your digital assets: privilege creep. In this blog, we’ll explore the potential risks, and provide you with actionable strategies to prevent this sneaky threat from undermining your cybersecurity efforts.

Read More

5 Steps For User Access Review Best Practices

FINOSEC posted in User Access, User Access Reporting, preparedness, Risk Assessment, information security, System Inventory, Risk Review, infosec

0 Comments

User Access Reviews (UAR) are crucial for financial institutions, examiners and auditors are focusing on them, and best practices mandate managing to least privilege.   However, the process can be complicated and time-consuming. This is why it's important to standardize and simplify the process as much as possible. Our User Access Review Best Practices white paper outlines five steps to help you achieve this. 

Read More

How you can deliver an all-star information security audit

FINOSEC posted in Cybersecurity, Guidance, checklist, board, board training, training, Exam, Exam Readiness, preparedness, Security, information security, Processess, independence, Information Security Officer

0 Comments

Bank examiners and auditors constantly change their expectations. The result is you feel as if your information security practices are trying to hit a moving target while the boundaries shift constantly.

Read More

Does your institution still have outdated processes in place?

FINOSEC posted in Cybersecurity, Innovation, board training, Exam Readiness, preparedness, Security, information security, Information Security Officer

0 Comments

In a video released to FINOSEC Academy, Co-Founder and CEO, Zach Duke, poses some questions around the processes you currently have in place at your institution. Regardless of which department you think of first, it is likely that some outdated processes are still in place, and your information security and cyber security teams are no exception.

Read More

Exams are never fun. But we know how to make bank regulator exams easier!

FINOSEC posted in Cybersecurity, Innovation, Banking, Exam, Exam Readiness, preparedness

0 Comments

And let’s acknowledge the tests associated with bank examiners definitely fall into the “not fun” category.

Read More