BankInfoSecurity.com - Banking Information Security News, Regulations, & Education  

Username:
Password:
 

Guidance on Developing an Information System

GuidanceOffice of Thrift Supervision (OTS)Patch Management

Guidance on Developing an Information System
Patch Management Program to Address Software Vulnerabilities

Introduction

As financial institutions become increasingly dependent on commercial software to support critical business processes, they also increase their exposure to software vulnerabilities. Most financial institutions use multiple commercial software packages. Therefore, it can be challenging to identify, test, and install all of the applicable patches that are necessary to maintain each software package.

A patch management program should be part of an institution's overall computer security program. Oversight and accountability should be assigned to an appropriate party; however, the patch management program should include management, information security, and systems operations personnel. Consumer privacy regulations require that periodic risk assessments be provided to the Board of Directors.

> Read entire regulation (log in required - registration is free)



Terms of Service | Advertise | Archive | Site Map | Contact | Bank Information Security RSS Syndication RSS Syndication
Copyright © 2007 BankInfoSecurity.com