Bankers on FFIEC
- From: "Ken Kousky" <kkousky@xxxxxxxxxx>
- Date: Wed, 14 Mar 2007 20:42:52 -0400
The FFIEC guidance on online banking calls for strong authentication,
applied based on appropriate risk analysis and they even spell out the three
factors of authentication and state that single factor password
authentication isn't adequate. Yet, I've found many banks adding addition
questions to the login sequence and thinking they've added another factor.
Does anybody have experience with this situation and understand how banks
are getting around the Guidance for Online Banking requirements?
KWK
- Follow-Ups:
- Re: Bankers on FFIEC
- From: William M. Davis
- Re: Bankers on FFIEC
- References:
- The Value of GIAC/GSEC Certification
- From: andrews
- The Value of GIAC/GSEC Certification
- Prev by Date: Re: How secure is to open ports from inside the firewall?
- Next by Date: Re: NOC password management
- Previous by thread: RE: The Value of GIAC/GSEC Certification
- Next by thread: Re: Bankers on FFIEC
- Index(es):
Relevant Pages
|