CREATORS OF THE COMPLIANCE TUNE-UP®

AARMR | ABA | ACAMS | ALTA | ARMCP | IAPP | IIA | MBA | MERS® | MISMO | NAMB

Showing posts with label Information Security. Show all posts
Showing posts with label Information Security. Show all posts

Monday, March 9, 2020

Announcement: Interagency Statement on Pandemic Planning

PRINT THIS

FFIEC has issued guidance on pandemic planning, entitled Interagency Statement on Pandemic Planning (“Guidance”). This issuance is meant to heighten the response of financial institutions to the coronavirus pandemic. The Guidance identifies actions that financial institutions should take to minimize the potential adverse effects of a pandemic. Specifically, the institution’s business continuity plan (BCP) should address pandemics and provide for a preventive program, a documented strategy scaled to the stages of a pandemic outbreak, a comprehensive framework to ensure the continuance of critical operations, a testing program and an oversight program to ensure that the plan is reviewed and updated.
We have been notifying you on how to protect your companies, customers, employees, families, and communities HERE. Please review those articles and act accordingly. 
If you want to discuss your specific pandemic preparation requirements, please contact us at compliance@lenderscompliancegroup.com.
We believe that Disaster Recovery and Business Continuity should be combined, but, as the Guidance states “pandemic planning activities should involve senior business management from all functional, business and product areas, including administrative, human resources, legal, IT support functions, and key product lines.”

The pandemic segment of the BCP must be "sufficiently flexible to address a wide range of possible effects that could result from a pandemic," and also be reflective of the institution’s size, complexity, and business activities. 

Our position is that there are two types of BCPs: standard and enhanced. 

The standard version lacks due diligence and independent risk assessment but does provide a basic outline to follow to ensure business continuity. 

The enhanced version is preferred by regulators because it contains due diligence and independent risk assessment. The enhanced version is obviously preferable to the standard version, because it provides specific due diligence, auditing done by subject matter experts, and leads to an independent risk assessment. The risk assessment reveals strengths and weaknesses further provides actionable recommendations. The standard version is less expensive to draft than the latter, but can be used as a baseline to ensure that your company is taking some affirmative actions to contain the spread of the coronavirus.

The Guidance is unequivocal in its directives: 
The adverse economic effects of a pandemic could be significant, both nationally and internationally. Due to their crucial financial and economic role, financial institutions should have plans in place that describe how they will manage through a pandemic event. Sound planning should minimize the disruptions to the local and national economy and should help the institution maintain the trust and confidence of its customers. [Emphasis in original.]
According to the Guidance, “pandemic planning presents unique challenges to financial institution management. Unlike natural disasters, technical disasters, malicious acts, or terrorist events, the impact of a pandemic is much more difficult to determine because of the anticipated difference in scale and duration.”
The following constitute the actions that management should be undertaking, per the Guidance:
1. A preventive program to reduce the likelihood that an institution’s operations will be significantly affected by a pandemic event, including the monitoring of potential outbreaks, educating employees, communicating and coordinating with critical service providers and suppliers, in addition to providing appropriate hygiene training and tools to employees.
2. A documented strategy that provides for scaling the institution’s pandemic efforts so they are consistent with the effects of a particular stage of a pandemic outbreak, such as first cases of humans contracting the disease overseas, first cases within the United States, and first cases within the organization itself. The strategy will also need to outline plans that state how to recover from a pandemic wave and proper preparations for any following wave(s).
3. A comprehensive framework of facilities, systems, or procedures that provide the organization the capability to continue its critical operations in the event that large numbers of the institution’s staff are unavailable for prolonged periods. Such procedures could include social distancing to minimize staff contact, telecommuting, redirecting customers from branch to electronic banking services, or conducting operations from alternative sites. The framework should consider the impact of customer reactions and the potential demand for, and increased reliance on, online banking, telephone banking, ATMs, and call support services. In addition, consideration should be given to possible actions by public health and other government authorities that may affect critical business functions of a financial institution.
4. A testing program to ensure that the institution’s pandemic planning practices and capabilities are effective and will allow critical operations to continue.
5. An oversight program to ensure ongoing review and updates to the pandemic plan so that policies, standards, and procedures include up-to-date, relevant information provided by governmental sources or by the institution’s monitoring program.
The Guidance provides helpful and important links to information resources, as follows:
1. The National Strategy for Pandemic Influenza (National Strategy) and the Implementation Plan for the National Strategy for Pandemic Influenza  (National Implementation Plan) issued by the federal government provide a complete guide to pandemic planning. 

Friday, February 28, 2020

Coronavirus: CDC Guidance - An Urgent Message

PRINT THIS

The Center for Disease Control and Prevention (CDC) has issued an alert regarding the Coronavirus Disease, entitled Interim Guidance for Businesses and Employers to Plan and Respond to Coronavirus Disease 2019 (COVID-19), February 2020.

This Interim Guidance (“Guidance”) is based on what is currently known about the coronavirus disease 2019 (COVID-19). The CDC will update this Guidance as needed and as additional information becomes available.

Read the CDC's Guidance HERE.

Unfortunately, much is unknown about how the virus that causes COVID-19 spreads. Current knowledge is largely based on what is known about similar coronaviruses.

The Guidance is meant to help prevent workplace exposures to acute respiratory illnesses, including COVID-19, in non-healthcare settings. The guidance also provides planning considerations if there are more widespread, community outbreaks of COVID-19.

Lenders Compliance Group is willing to help!

At this time, we suggest that you review your Disaster Recovery and Business Continuity Plan (“DRBC”), as the impact, features, factors, procedures, and policy requirements relating to COVID-19 should be set forth therein. The plan should include the CDC’s recommended strategies for employers to implement. 

Due to this emergency, if you need help with your DRBC, Lenders Compliance Group is offering to provide its DRBC review, assessment, risk rating, recommendations, and policy at a 20% discount from our already low fee. If the cost is a bit tough to manage, we will give you an affordable payment plan. Avoid the manual mills, one-size-fits-all, and fill-in-the-blanks versions. The DRBC must be customized to your institution to be effective and meet regulatory scrutiny!

To request support with your DRBC, click HERE.

EMPLOYER ACTIONS
  • Ensure the plan is flexible and involve your employees in developing and reviewing your plan.
  • Conduct a focused discussion or exercise using your plan to find out ahead of time whether the plan has gaps or problems that need to be corrected.
  • Share your plan with employees and explain what human resources policies, workplace and leave flexibilities, and pay and benefits will be available to them.
  • Share best practices with other businesses in your communities (especially those in your supply chain), chambers of commerce, and associations to improve community response efforts. 
Response Plan

There are numerous actions that must be implemented now. 
Do not wait! 
Time is not on your side!

  • Identify possible work-related exposure and health risks to your employees.
  • Review human resources policies to make sure that policies and practices are consistent with public health recommendations and are consistent with existing state and federal workplace laws.
  • Explore whether you can establish policies and practices, such as flexible worksites (i.e., telecommuting) and flexible work hours (i.e., staggered shifts), to increase the physical distance among employees and between employees and others if state and local health authorities recommend the use of social distancing strategies.
  • Identify essential business functions, essential jobs or roles, and critical elements within your supply chains (i.e., raw materials, suppliers, subcontractor services/products, and logistics) required to maintain business operations.
  • Plan for how your business will operate if there is increasing absenteeism or these supply chains are interrupted.
  • Set up authorities, triggers, and procedures for activating and terminating the company’s infectious disease outbreak response plan, altering business operations (i.e., possibly changing or closing operations in affected areas), and transferring business knowledge to key employees.
  • Plan to minimize exposure between employees and also between employees and the public, if public health officials call for social distancing.
  • Establish a process to communicate information to employees and business partners on your infectious disease outbreak response plans and latest COVID-19 information.
  • Anticipate employee fear, anxiety, rumors, and misinformation, and plan communications accordingly.
  • In some communities, early childhood programs and K-12 schools may be dismissed, particularly if COVID-19 worsens. Determine how you will operate if absenteeism spikes from increases in sick employees, those who stay home to care for sick family members, and those who must stay home to watch their children if dismissed from school.
  • Local conditions will influence the decisions that public health officials make regarding community-level strategies; employers should take the time now to learn about plans in place in each community where they have a business.
  • If there is evidence of a COVID-19 outbreak in the US, consider canceling non-essential business travel to additional countries per travel guidance on the CDC website.
  • Travel restrictions may be enacted by other countries which may limit the ability of employees to return home if they become sick while on travel status.
  • Consider cancelling large work-related meetings or events.
  • Engage state and local health departments to confirm channels of communication and methods for dissemination of local outbreak information.

Thursday, January 12, 2017

Cybersecurity Guidelines – “First-in-the-Nation” Regulation

President & Managing Director

WHITE PAPER

On December 28, 2016, the New York Department of Financial Services (DFS) announced that it had revised its proposed cybersecurity regulations in response to public comments that they would be too burdensome, particularly on smaller institutions. The proposed rules, which were initially announced on September 13, 2016, and set to take effect on January 1, 2017, were billed as a “first-in-the-nation regulation” to protect New York residents from cyberattacks.

The “Cybersecurity Requirements for Financial Services Companies (“Regulation”) is promulgated through Part 500 of Title 23 of the Official Compilation of Codes, Rules and Regulations of the State of New York, and takes effect upon publication in the State Register.[i]

These guidelines would require banks, insurers and other financial services companies regulated by the DFS to set up a cybersecurity program aimed at protecting consumer information from cyberattacks. The revised regulation eases certain reporting and encryption requirements, and exempts small institutions from complying with certain sections of the rule.

The Regulation, as revised, is set to take effect on March 1, 2017. There is a transitional period, which is 180 days from the effective date of March 1st, with implementation timeframes layered in as exceptions granted for certain requirements, from 12 months to 18 months to 24 months. Covered entities will be required to annually prepare and submit to the DFS a Certification of Compliance[ii] with the New York State Department of Financial Services Cybersecurity Regulations, commencing February 15, 2018.

In this article, I will provide a high-level overview of these guidelines. This outline is not meant to be comprehensive. However, I will hit on several salient areas of interest. Expect these requirements to become a model for examination and enforcement in most other states. Lenders Compliance Group has provided risk assessments for cybersecurity, information security, and information technology based on the Federal Financial Institutions Examination Council's (FFIEC) procedures. So, my firm has experience in cybersecurity risk assessments. Given that familiarity, we now are providing an overlay for the DFS cybersecurity requirements that are promulgated in the Regulation.

Cybersecurity Program

Each covered entity – that is, any person operating under or required to operate under a license, registration, charter, certificate, permit, accreditation or similar authorization under the New York State Banking Law, the Insurance Law or the Financial Services Law – must maintain a cybersecurity program designed to protect the confidentiality, integrity and availability of the covered entity’s Information Systems.

The Regulation defines a “cybersecurity event” as any act or attempt, successful or unsuccessful, to gain unauthorized access to, disrupt or misuse an information system or information stored on such information system. For purposes of this regulation, an information system is a “discrete set of electronic information resources organized for the collection, processing, maintenance, use, sharing, dissemination or disposition of electronic information,” as well as any specialized system such as industrial and process controls systems, telephone switching and private branch exchange systems, and environmental control systems.

A risk assessment must be conducted by the covered entity and the cybersecurity program must be based on that risk assessment and also be designed to perform the following core cybersecurity functions:
  1. identify and assess internal and external cybersecurity risks that may threaten the security or integrity of all electronic information that is not publicly available information, known as Nonpublic Information (“NPI”), stored on the covered entity’s information systems;
  2. use defensive infrastructure and the implementation of policies and procedures to protect the covered entity’s information systems, and the NPI stored on those information systems, from unauthorized access, use or other malicious acts;
  3. detect cybersecurity events;
  4. respond to identified or detected cybersecurity events to mitigate any negative effects;
  5. recover from cybersecurity events and restore normal operations and services; and
  6. fulfill applicable regulatory reporting obligations. 
With respect to covered entities that have affiliates, the requirements of the Regulation permit adoption of a cybersecurity program maintained by an affiliate, provided that the affiliate’s cybersecurity program covers the covered entity’s information systems and NPI and meets the requirements of the Regulation. An affiliate is any Person that controls, is controlled by or is under common control with another Person. For purposes of the Regulation, control means the possession, direct or indirect, of the power to direct or cause the direction of the management and policies of a Person, whether through the ownership of stock of such Person or otherwise.

Tuesday, October 11, 2016

Cybersecurity - A Model Approach

Managing Director
Lenders Compliance Group

As some of you know, Lenders Compliance Group is the first risk management firm in the country to provide both a risk assessment and a disaster recovery plan for banks and nonbanks. The goal is to make the due diligence approach both affordable and consequential. Importantly, the resulting findings must meet regulatory scrutiny, since liability remains with the financial institution with respect to implementing Internet Technology, Information Security, and Cybersecurity requirements. The review process is conducted by Kevin Origoni, our Director/IT-IS-Cybersecurity, who is a Six Sigma awardee for his knowledge and experience. Our interest in this area has only grown more attentive as federal and state regulators have become very active in implementing disaster recovery and cybersecurity guidelines.

Our attentiveness has been borne out by the recently proposed regulation involving cybersecurity issued by the New York State Department of Financial Services (DFS). The regulation would impose significant cybersecurity standards on entities it supervises. The proposal is subject to a 45-day public comment period, which will end on November 14, 2016. Importantly, some of these standards exceed current state and federal requirements. It is valuable, therefore, to take a brief look at these prospective standards.

INSTITUTIONS
The proposed regulation would apply to entities operating or required to operate under a license, registration or other authorization under the New York Banking Law, Insurance Law or Financial Services Law. These covered entities include:
  • New York state chartered banks,
  • New York licensed branches and agencies of foreign banks,
  • insurance companies,
  • money transmitters,
  • licensed lenders,
  • mortgage brokers, and
  • mortgage bankers, lenders and servicers.

Certain small entities would be exempt from some, but not all, of the requirements of the proposed regulation.

If adopted, the proposed regulation would require covered entities to adopt a written cybersecurity program and implement various safeguards to protect nonpublic information, as broadly defined in the proposal. Covered entities would have to annually certify to the DFS their compliance with the proposed regulation.

NATIONAL STANDARDS
We believe that the DFS proposal will set a nationwide standard for cybersecurity and should be carefully considered as a model for disaster recovery, IT, IS, and cybersecurity requirements.

As it is currently drafted, the proposed regulation is prescriptive, inasmuch as it goes beyond the requirements imposed by the federal banking regulators on the depository institutions they supervise. For instance, guidance provided by the Federal Financial Institutions Examination Council (FFIEC) in its September 2016 Examination Handbook suggests that financial institutions should implement the type and level of encryption that is commensurate with the sensitivity of information being protected. However, FFIEC does not mandate that all nonpublic information be encrypted while in transit and at rest, or resident, as the DFS has proposed. But the DFS proposal also appears to require multi-factor authentication in a much broader range of circumstances than the guidance provided by federal regulators to depository institutions, which is mostly focused on online banking.

Similarly, the federal banking regulators require financial institutions to provide notice of information security breaches involving unauthorized access to or use of sensitive customer information; however, the DFS would mandate such notification within 72 hours of any cybersecurity event, a timeframe which the federal banking regulators do not require.

SPECIFIC STANDARDS
The DFS sets forth standards for policies and procedures. Each covered entity’s cybersecurity program would need to be designed to ensure the confidentiality, integrity and availability of the covered entity’s information systems and to perform the following functions:

Thursday, April 24, 2014

Mitigating the Risk of Distributed Denial-of-Service (DDoS) Attacks

DOWNLOAD ARTICLE

On Tuesday, April 1, 2014, Ellie Mae’s systems were compromised by a Distributed Denial-of-Service (DDoS) attack. Resources known to be affected were all Encompass services, including Encompass Docs Solution™, Electronic Document Management (“eFolder”), Encompass Product and Pricing Service™, Encompass Compliance Service™, and Ellie Mae Network Services.[1]

Ellie Mae itself proactively published a Press Release on April 1st, announcing that “recent outages [that] have made Ellie Mae’s Encompass services unavailable to users.” And further stating that it “has detected unusually high demand for services consistent with an external malicious attack characteristic of a distributed denial of service (DDoS).”[2]

As reported by Bloomberg at the time, the system failure “prevented some mortgages from closing.” One client complained that “our business is at a standstill.”[3]

For our own clients, we sought to know how Ellie Mae was challenging this attack and also we monitored its status page.[4]

By Wednesday, April 2nd, Ellie Mae’s focused and deliberative handling of this matter was bringing the overall problem to the stage of being resolved. The completion was met with a statement by Sig Anderman, Ellie Mae’s CEO, with a statement affirming that, “as of 2:15 p.m. PT, we verified that Encompass Homepage login and load times have returned to normal.”[5]

As it happens, and quite coincidentally, on April 2nd the Federal Financial Institutions Examination Council (“FFIEC”) issued a statement to notify institutions of “the risks associated with the continued distributed denial of service (DDoS) attacks on public-facing Web sites and the steps institutions are expected to take to address the risks posed by such attacks.”[6]

I well remember meeting a compliance officer of a relatively large bank at his office. He asked me to step around his desk and take a look at his screen. I was astonished to see thousands and thousands of green coded lines scrolling on the screen. I asked him what was going on, and he told me that the bank’s systems were under attack and these were the unending attempts to penetrate their systems. I had never seen anything like it!

Let’s take a brief trip into this area of Internet madness that IT professionals deal with daily.

Since 2012, there has been an increasing number of DDoS attacks launched against financial institutions by politically motivated groups, so says FFIEC. However, we also know that DDoS attacks have come from foreign country proxies, mafia-type criminals, and sundry other nefarious individuals and organizations hell bent on disrupting financial institutions. DDoS attacks serve as a diversionary tactic by criminals attempting to commit fraud using stolen customer or bank employee credentials to initiate fraudulent wire or automated clearinghouse transfers.

These DDoS attacks have increased in sophistication and intensity, almost to the point that they are commonplace. The attacks cause slow website response times, intermittently prevent customers from accessing institutions’ public websites, and adversely affect back office operations.

Thus, many financial institutions are considerably at risk to information security failures and even entire system implosions. Financial institutions of all sizes that experience DDoS attacks may face a variety of risks, including operational risks and reputation risks. And if the attack is coupled with attempted fraud, a financial institution may also experience fraud losses as well as liquidity and capital risks.

FFIEC suggests that financial institutions should address DDoS readiness as part of ongoing information security and incident response plans. Through FFIEC, such readiness has been proposed by the Board of Governors of the Federal Reserve System (FRS), Federal Deposit Insurance Corporation (FDIC), National Credit Union Administration (NCUA), Office of the Comptroller of the Currency (OCC), Consumer Financial Protection Bureau (CFPB), and the State Liaison Committee. Many states now mandate adopting an Information Security Plan that contains many elements of readiness, incident response, and certain risk mitigation procedures.

There are actions a financial institution’s management would be wise to take to mitigate the risks associated with DDoS attacks, given the company’s size, complexity and risk profile. Any plan to mitigate such risks should include the following elements:[7]

1. Maintain an ongoing program to assess information security risk that identifies, prioritizes, and assesses the risk to critical systems, including threats to external websites and online accounts;

2. Monitor Internet traffic to the institution’s website to detect attacks;

3. Activate incident response plans and notify service providers, including Internet Service Providers (ISPs), as appropriate, if the institution suspects that a DDoS attack is occurring. Response plans should include appropriate communication strategies with customers concerning the safety of their accounts;

4. Ensure sufficient staffing for the duration of the DDoS attack and consider hiring pre- contracted third-party services, as appropriate, that can assist in managing the Internet-based traffic flow. Identify how the institution’s ISP can assist in responding to and mitigating an attack;

5. Consider sharing information with organizations, such as the Financial Services Information Sharing and Analysis Center[8] and law enforcement because attacks can change rapidly and sharing the information can help institutions to identify and mitigate new threats and tactics; and

6. Evaluate any gaps in the institution’s response following attacks and in its ongoing risk assessments, and adjust risk management controls accordingly.

I strongly recommend that the management of a financial institution meet regularly with the Chief Information Officer (“CIO”) or, in lieu of a CIO, the IT professional who is in charge of maintaining the institution’s systems. Furthermore, every CIO and IT professional should be fully versed in the requirements set forth in FFIEC’s booklets, Information Technology Handbook on Business Continuity Planning[9] and Information Security.[10]

Another resource is the DDoS Quick Guide, dated January 29, 2014, published by the Department of Homeland Security’s National Cybersecurity and Communications Integration Center.[11] This guide provides useful information on attack possibilities and traffic types. It should be shared with an institution’s IT department and the institution’s online banking and website service providers, if applicable.