FFIEC Authentication Guidance: What Your Vendors Won't Tell You (Unless You Ask)

- Does your vendor outsource the work they're doing for you to a fourth-party service provider - particularly overseas?
- Does the vendor employ fulltime employees only, or does it also hire temporary workers, (contractors) who may be allowed to work remotely?
- Is the potential loss resulting from a data breach greater than the vendor's contractual liability plus the vendor's total net worth?
See Also: Rapid Digitization and Risk: A Roundtable Preview
The entire FFIEC Guidance series:
- FDIC on Understanding and Complying with the 2011 Update
- FFIEC Authentication Guidance: How to Prepare for Your Next Exam
- FFIEC Authentication Guidance: Essential Questions You Need to Ask Your Vendors
- FFIEC Authentication Guidance: What Your Vendors Won't Tell You (Unless You Ask)
- Customer Education: Developing a Program That's Effective and Meets Regulators' Expectations
- FFIEC Authentication Guidance: How to Create a Layered Security Strategy
- Vendors' Guide to the FFIEC Authentication Guidance