Security Program: Information Security

Last Reviewed: May, 2018

The Gramm-Leach-Bliley Act required the NCUA and other banking agencies to establish standards for their financial institutions relating to administrative, technical and physical safeguards of consumer records and information. The NCUA amended Part 748 of its Rules and Regulations and added Appendix A, "Guidelines for Safeguarding Member Information". The safeguards are intended to:

  1. Insure the security and confidentiality of member records and information;
  2. Protect against any anticipated threats or hazards to the security or integrity of such records; and
  3. Protect against unauthorized access to or use of such records or information that could result in substantial harm or inconvenience to a member.

Over the past few years there has been an increase in the number of breaches or attempted breaches of member information that has resulted in identity theft. To address this situation, NCUA issued a final rule amending Part 748, requiring credit unions to add to their security programs a response program that addresses incidents of unauthorized access to or use of member information that could result in substantial harm or serious inconvenience to a member. The rule includes Appendix B, "Guidance on Response Programs for Unauthorized Access to Member Information and Member Notice", which provides details of what should be included in these response programs. In addition, most states have requirements for notification in case of a security breach.

Definitions
Information security and response program (ISRP)- establishes a formalized process to prevent, detect, and respond to security vulnerabilities with respect to maintaining member data integrity and confidentiality.

Member information system – any method used to access, collect, store, use, transmit, protect or dispose of member information, including systems maintained by service providers.

Security incident – an adverse event, or the threat of one, that affects the credit union’s computer network and/or information system. Security incidents can occur in innumerable ways and include, but are not limited to:

Sensitive member information – a member’s name, address, or telephone number, in conjunction with the member’s social security number, driver’s license number, account number, credit or debit card number, or a personal identification number or password that would permit access to the member’s account. It also includes any combination of components of member information that would allow someone to log onto or access the member’s account, such as user name and password or password and account number.

Appendix A to Part 748 – Guidelines for Safeguarding Member Information
Each credit union must develop a comprehensive written information security program that includes administrative, technical, and physical safeguards that allow for enterprise-wide coordination of all required elements of the ISRP, which include the following.

Board Responsibilities
The board of directors or an appropriate committee of the board of each credit union must approve the credit union’s written ISRP. The board is also charged with overseeing the development, implementation, and maintenance of the ISRP, including assigning specific responsibility for its implementation and reviewing reports from management.

FFIEC exam questions regarding board involvement include:

Identify and Assess Risks to Member Information
Each credit union is required to perform a risk assessment which reasonably identifies foreseeable internal and external threats that could result in unauthorized disclosure, misuse, alteration, or destruction of member information or member information systems. Once vulnerabilities have been adequately identified, the credit union must evaluate the sufficiency of its policies, procedures, member information systems, and other arrangements in place to control risks.

FFIEC exam questions include:

Manage and Control Risk to Member Information
Each credit union is required to design its information security program to control the identified risks, commensurate with the sensitivity of the information, as well as the complexity and scope of the credit union’s activities.

FFIEC exam questions regarding management and risk controls include queries as to whether the credit union has adopted appropriate security measures to address the following:

Staff Training
Credit unions must train staff to implement the credit union’s information security program.

FFIEC exam questions:

Independent Testing
Credit unions should conduct regular, independent testing of key controls, systems, and procedures.

FFIEC exam questions:

Disposal of Member Information
Credit unions must develop, implement, and maintain appropriate measures to properly dispose of member information and consumer information.

FFIEC exam questions:

Oversee Third-Party Service Provider Arrangements
Credit unions are required to exercise appropriate due diligence in selecting third-party service providers. A service provider is defined as any person or entity that maintains, processes, or is otherwise permitted access to member information through its provision of services directly to the credit union. Exercising appropriate due diligence includes, but is not limited to:

FFIEC exam questions:

Adjust the Program to Reflect Changing Conditions
Each credit union should monitor, evaluate and adjust, as appropriate, its information security program in light of any relevant changes in technology, the sensitivity of its member information, internal or external threats to information, and the credit union’s own changing business arrangements, such as mergers, acquisitions, alliances and joint ventures, outsourcing arrangements, and changes to member information systems.

FFIEC exam questions:

Reports to the Board
Each credit union should report to its board or an appropriate committee of the board at least annually. The report should describe the overall status of the credit union’s information security program and its compliance with regulatory requirements.

The report should discuss material matters, such as risk assessments, risk management and control decisions, service-provider arrangements, results of testing, security breaches or violations and management’s response to the same, and recommendations for changes in the program.

FFIEC exam questions: