About Us | Contact Us
View Cart

Sometimes Say Sometimes

By Dan Hadaway | Monday, March 22, 2021 - Leave a Comment

Another Manifesto


A supply-chain manifesto by the author of Never Say Never: A Password Manifesto!
Another one of those Dan’s New Leaf Posts, meant to inspire thought about IT Governance . . . .


[Sssshh.  Turn out the lights.  Let’s lower our inner voices, as I have something to propose that might be a bit ahead of its time, like my article about password aging a decade ago.]

In 2013, I helped a bank being hammered by an exam finding that required them to rewrite their entire vendor management program.  A member of the committee that helped with the engagement was a lawyer who, being on the board of directors of a bank, was very concerned about the extra compliance work that was arising from the notion of “Information Technology.”

In grilling me about my business, he learned that I oversaw a company that was in the FFIEC’s technology service provider examination program, and that I was being examined (literally that week) on a two year cycle.  He was fascinated by this . . . that the federal government would be in my office examining us as if we were a bank.  Almost as if I was in a deposition, I answered his questions, as he continued to drill down as far as he could, given that I was not allowed to share what happened in my exams.

This lawyer actually followed the link I had provided in my training to the guidance on the TSP Examination Program, downloaded the PDF of that guidance, and came to the conclusion that . . . “given my connections in the industry” . . . we should try to lobby the FFIEC to exempt community-based banks from having to review vendors that were in the TSP exam program.  As far as he could tell, the federal government was doing everything that they were requiring community-based banks to do.

At the time, I’ll have to admit, I told him I would look into it, flattered that he thought I was “connected.”  But I never was able to find a good time to raise it with governmental people I know.  The idea died right there, in 2013, and didn’t resurface again until we wrote the “interim post-mortem review” on the SolarWinds Incident  (I still love how something can be “interim” and “post” at the same time!).

But when our post-mortem review process drilled into the management lessons and action items, we realized that one of the things bank management could do was lobby the FFIEC to streamline the vendor management process so that community-based banks would not have to spend time on any residual risk that wasn’t high or critical.

Assuming inherent risk is high in order to get into the FFIEC TSP Exam Program, we are proposing community banks be exempted from the Assurance and Insurance aspects of due diligence with vendors in the program.  Banks would still need to perform contract, financial, and business continuity aspects of this review.  And we would still want community banks to review the TSP ROE, the SOC User Entity Control Considerations, and the “inventory of subservience providers” that arises from a SOC 2 review.

I understand and agree with some of the pushback that examiners would give on this notion.  They will tell you that the agreement and relationship between bank and vendor is already very customized and that the FFIEC exam is for generic inherent risk and not custom residual risk.  As a risk manager, I understand that notion, but I submit to you that there are many vendors NOT in the FFIEC examination program and the assurance review for these vendors suffers due to duplication of efforts with TSP ROE holders.

And I submit that sometimes we need to say sometimes.  Sometimes duplication of effort only hurts the overall process.  That is one of the takeaways of the SolarWinds incident.

The parts of the relationship that are custom is the contract, the user entity control considerations and the business continuity arrangements.  We do produce one set of financial statements for one Client, and another for a different Client.  So why should our Clients review them with the FFIEC already does?

If as bankers we could focus on the parts of the relationship that is INDEED custom to the bank, we would understand the business continuity arrangements better.  We could incorporate their tests into our own better. We can follow the residual risk, not the inherent risk.

Sometimes, we need to say sometimes.  I agree that in some cases, we should review everything.  If an FFIEC TSP Exam report does indicate there are issues, we should follow that.

Of course community banks will need to continue reviewing their vendor contracts.  That’s where the customization is defined.

Therefore, and this is where I’m a bit shy . . . . I encourage each person who reads this article to share it with the person in your bank who is responsible for lobbying your congressman.

We can really make a difference in community banking on this one, it is very clear to me that the TSP examination program already covers assurance from enough angles.  The FFIEC should learn to say sometimes, sometimes.  If the vendor is not in the TSP examination program . . . definitely look at the assurance.  But if the vendor is in the TSP examination program, maybe community-based banks under a billion should be exempted.

[Okay, we can turn the lights back on.]


Original article by Dan Hadaway CRISC CISA CISM. Founder and Managing Partner, infotex

“Dan’s New Leaf” is a “fun blog to inspire thought in the area of IT Governance.”

 


same_strip_012513


 

Latest News
    Another awareness poster for YOUR customers (and users).  Now that we have our own employees aware, maybe it’s time to start posting content for our customers! Check out posters.infotex.com for the whole collection! Download the large versions here: Awareness Poster (Portrait) Awareness Poster (Landscape)   You are welcome to print out and distribute this around […]
    The joint cybersecurity advisory includes the 15 most exploited vulnerabilities reported in 2021… An article review.  While a lot of attention is focused on previously undisclosed or “zero day” attacks, some of the most likely attack vectors are vulnerabilities that have been widely known for weeks or even months.  That’s according to a new joint […]
    Threats are changing, EDR can help us adapt . . . Today’s advanced persistent threat (APT) understands that the IT landscape has changed. In the post-COVID age, more and more organizations have adopted some form of work from home.  While WFH offers many conveniences, it also imparts increased risks. BitSight conducted a 2021 study of […]
    The Five Precepts of IT Vendor Management Webinar-Movie We’re going back to basics on Vendor Management. This webinar will give you a training tool to help out that new person that is starting to take on the gargantuan task that is Vendor Management.
    A new way of helping people “read” new guidance… Look for more in the future! To save you time, we are proud to present “Adam Reads” . . . recorded versions of our Guidance Summaries! Below you can find an embedded player for the audio file. If you are having issues with that working, you […]
    You think you’ve finally found stability in your to-do list. Your goals are set, and you’re even making great progress on them all. Audit findings: all addressed. Management requests: Under control. Heck, you might even be able to leave the office five minutes early at least once this year. Then BAM! A press release from […]
    Software Bill of Materials (SBOMs) are becoming more and more important. . . We are all very familiar with one aspect of the software supply chain – updates.  New features, bug fixes, and performance upgrades are a regular occurrence to any device’s lifecycle, however what if these kinds of updates also include deliberately malicious code? […]
    Another awareness poster for YOUR customers (and users).  Now that we have our own employees aware, maybe it’s time to start posting content for our customers! Check out posters.infotex.com for the whole collection! Download the large versions here: Awareness Poster (Portrait) Awareness Poster (Landscape)   You are welcome to print out and distribute this around […]
    According to a new survey, more organizations than ever are reporting problems with cybersecurity staffing… An article review. While pandemic related mandates and restrictions are gradually being lifted across the country, many organizations are still feeling the effects in one important area: staffing.  That’s according to ISACA’s annual State of Cybersecurity survey, which asked over […]
    Understanding Banking Trojans… Another Technical Article by Tanvee Dhir! What are Banking Trojans? A trojan is a malicious program that masquerades as a genuine one. They are often designed to steal sensitive information from users (login passwords, account numbers, financial information, credit card information, etc.). A banking trojan is a malicious computer program designed to […]