Transcription of FFIEC Information Technology Examination Handbook ...
{{id}} {{{paragraph}}}
FFIEC Information Technology Examination Handbook Information Security SEPTEMBER 2016 FFIEC IT Examination Handbook Information Security September 2016 i Contents INTRODUCTION .. 1 I GOVERNANCE OF THE Information SECURITY PROGRAM .. 3 Security Culture .. 3 Responsibility and Accountability .. 3 Resources .. 5 II Information SECURITY PROGRAM MANAGEMENT .. 6 Risk Identification .. 7 Threats .. 8 Vulnerabilities .. 8 Supervision of Cybersecurity Risk and Resources for Cybersecurity Preparedness .. 9 Risk Measurement .. 10 Risk Mitigation .. 11 Policies, Standards, and Procedures .. 11 Technology Design .. 12 Control Types .. 12 Control Implementation .. 13 Inventory and Classification of Assets.
Information Technology Examination Handbook (IT Handbook) and should be read in conjunction with the other booklets in the . IT Handbook. This booklet provides guidance to examiners and addresses factors necessary to assess the level of security risks to a financial 3institution’s. 2.
Domain:
Source:
Link to this page:
Please notify us if you found a problem with this document:
{{id}} {{{paragraph}}}