FFIEC Releases Update to Cybersecurity Assessment Tool
The Federal Financial Institutions Examination Council (FFIEC) recently released an update to the Cybersecurity Assessment Tool (Assessment). This update to the Assessment addresses changes to the FFIEC IT Examination Handbook by providing a revised mapping in Appendix A to the updated Information Security and Management booklets. The updated Assessment will also provide additional response options, allowing financial institution management to include supplementary or complementary behaviors, practices and processes that represent current practices of the institution in supporting its cybersecurity activity assessment.
The FFIEC members developed the Assessment to help financial institution management determine the institution’s risk profile, inherent risks and cybersecurity preparedness. The Assessment provides a repeatable and measurable process that financial institution management may use to measure cybersecurity preparedness over time. Use of the tool is voluntary, and financial institution management may choose to use the Assessment or another framework, or another risk assessment process to identify inherent risk and cybersecurity preparedness.
Management of financial institutions and management of third-party service providers are primarily responsible for assessing and mitigating their entities’ cybersecurity risk. Financial institutions can find the latest information about cybersecurity risk management on the FFIEC website. Want to know more about how to use this cybersecurity tool in your institution? Contact our financial institutions IT assurance advisors – they stand ready to answer your questions.