ARTICLE
31 August 2021

FFIEC Issues Updated Guidance On Authentication And Access To Financial Institution Services And Systems

SM
Sheppard, Mullin, Richter & Hampton LLP

Contributor

Businesses turn to Sheppard to deliver sophisticated counsel to help clients move ahead. With more than 1,200 lawyers located in 16 offices worldwide, our client-centered approach is grounded in nearly a century of building enduring relationships on trust and collaboration. Our broad and diversified practices serve global clients—from startups to Fortune 500 companies—at every stage of the business cycle, including high-stakes litigation, complex transactions, sophisticated financings and regulatory issues. With leading edge technologies and innovation behind our team, we pride ourselves on being a strategic partner to our clients.
On August 11, the Federal Financial Institutions Examinations Council issued new guidance, providing examples of effective authentication and access risk management principles and practices for financial institutions.
United States Finance and Banking
Sheppard, Mullin, Richter & Hampton LLP are most popular:
  • within Cannabis & Hemp topic(s)

On August 11, the Federal Financial Institutions Examinations Council (FFIEC) issued new guidance, providing examples of effective authentication and access risk management principles and practices for financial institutions.  The principles and practices relate to access to digital banking services and information systems by customers, employees, and third parties accessing digital banking services and financial institution information systems.  The FFIEC - whose voting members include representatives from the FDIC, the NCUA, the OCC, the CFPB, the Federal Reserve Board, and the State Liaison Committee - issued the guidance as an update to prior submissions from 2005 and 2011.

Among other things, the guidance:

  • Highlights the current cybersecurity threat environment including increased remote access by customers and users, and attacks that leverage compromised credentials; and mentions the risks arising from push payment capabilities.
  • Recognizes the importance of the financial institution's risk assessment to determine appropriate access and authentication practices to determine the wide range of users accessing financial institution systems and services.
  • Supports a financial institution's adoption of layered security and underscores weaknesses in single-factor authentication.
  • Discusses how multi-factor authentication or controls of equivalent strength can more effectively mitigate risks.
  • Includes examples of authentication controls, and a list of government and industry resources and references to assist financial institutions with authentication and access management.

According to the FFIEC, the guidance is meant as neither an endorsement nor a "comprehensive framework" for any specific information security identity and access program, and is intended to apply not only to financial institutions, but also to any third-party acting on behalf of a financial institution that provides the accessed information systems and authentication controls.

Putting It Into Practice:  Financial institutions and their third-parties would be well-served to review their controls and procedures, including risk management practices that support oversight of identification and authentication, how to periodically evaluate the effectiveness of user and customer authentication controls, and what processes are in place to monitor, log, and report activities to identify and track unauthorized access.

The content of this article is intended to provide a general guide to the subject matter. Specialist advice should be sought about your specific circumstances.

[View Source]

Mondaq uses cookies on this website. By using our website you agree to our use of cookies as set out in our Privacy Policy.

Learn More