BankInfoSecurity.com - Information Security News, Regulations, & Education

Bank Information Security Articles

ID Theft Red Flags Rule: 3 Keys to Successful Awareness Programs

Credit
Eligible
As a BankInfoSecurity.com annual member, this content can be used toward your membership credits and transcript tracking. Click For More Info
Regulators Discuss What's Missing Now, What Will Be Sought in Future Exams
August 25, 2008 - Linda McGlasson, Managing Editor

This article was originally created for BankInfoSecurity.com, and contains information that should interest our GovInfoSecurity.com readers.
Share

Comment on this article

We all know that employee and customer awareness are a big part of Identity Theft Red Flags Rule compliance. But what exactly is missing from banking institutions' current awareness programs, which must meet the new standards by Nov. 1?

We recently caught up with representatives of banking regulatory agencies to gain their insights on:

What's missing from current identity theft awareness programs;
Which key elements examiners will be looking for post-Nov. 1.

The Three Keys
Board involvement, documentation and consistency -- the same elements that make a financial institution's information security awareness and education program a success are the keys to effectively training employees on ID Theft Red Flags, and institutions should be ready to be examined for them, say federal regulators.

Below, we focus on each of these elements in terms of what's currently missing and what will be sought.

Board Involvement -- Making an understandable, repeatable education and awareness program first needs the support of the board of directors of an institution.

"Ultimately, the behavior and priorities of senior management heavily influence the level of employee awareness and policy compliance, so training and the commitment to security should start with senior management," says Aida Plaza Carter, Director, Bank Information Technology of the Office of The Comptroller of the Currency (OCC).

Click to Get Updates on the Latest Information Security News

Board involvement has always been a challenge for financial institutions, and so it is a major component of ID Theft Red Flags Rule compliance. This need for board level involvement spills over to training programs in an institution's ID Theft Red Flag examination. In these examinations federal regulators will verify that a financial institution trains appropriate staff to effectively implement and administer the program.

William Henley Director, IT Risk Management at the Office of Thrift Supervision (OTS) says that among the things OTS examiners will look for is a coordinated effort between the different areas of the institution. The training should be provided to the entire enterprise and have clear support and direction from board of directors. "The board doesn't have to develop the program, but needs to show their participation and support of it," Henley says.

Documentation -- Proper documentation of the institution's information security program is often not complete or up to date, say regulators, and this will also be applicable to ID Theft Red Flags Rule compliance. Institutions need to prepare their Identity Theft program documentation, as well as the training and awareness of employees and customers. The regulation says the identity theft prevention program and the training program must be written, so there has to be a document that they can show the examiner that summarizes and encapsulates the program. It cannot be merely a mission statement or strategy.

Consistency -- While examiners want to see security training on at least an annual basis, institutions aren't always consistent with their training programs. OCC's recommendations say training should include issues such as desktop security, log-on requirements, password administration guidelines, etc. Training should also address social engineering and the policies and procedures that protect against social engineering attacks. Training should support security awareness and strengthen compliance with security policies, standards and procedures, says Carter.

The National Credit Union Administration's Office of Examination and Insurance department says the NCUA expects credit unions to ensure their training program is sufficient to keep their employees knowledgeable about their credit union's security policies, procedures, and practices. Credit unions should ensure they conduct training at least annually and update their materials for any new threats, fraud schemes, or changes in the credit union's security stance or processes," says the NCUA's Office of Examination and Insurance.

With the inclusion of ID Theft Red Flags guidance requirements, examiners will be looking at a credit union's existing education program, as part of NCUA's risk-based examination program, examiners review significant changes in policies and procedures.

Credit unions may expect their examiner to inquire about the credit union's compliance with the ID Theft Red Flags rule as well as the type and frequency of training provided to their employees.


1 | 2


Next Related Article:


Question
Question
?Are your awareness programs ready for Red Flags Rule examination? If not, then what needs your attention before Nov. 1?
Here's your chance to be a part of the dialogue and engage with your peers! Just enter your comment to the right, click submit to send it to our Editor. All entries are posted anonymously.
Please login if you would like to post a comment on this question.

"Final Review of procedures and board presentation.