Skip to content

Evidence request lists

FFIEC IT Examination Handbook

Evidence request list. 78 controls, 78 carrying auditor artefact guidance. Generated from the compliance knowledge graph on 11 September 2026. Published by The Art of Service.

Architecture/Operations

IS-XI.A.1
Architecture and Operations Alignment

IT architecture and operations align with security requirements including secure baselines, zoning, and resilience patterns.

Artefacts an auditor will ask for
  • Architecture standards
  • Reference architectures
  • Operations procedures
Where this commonly fails
  • Reference architectures exist but are not enforced through governance
  • Operations teams deviate from architecture without exception tracking
  • Architectural decisions are not documented in a centralized repository
  • Standards updates do not flow into operational baselines
  • Architectural debt is not tracked or prioritized for remediation

Audit

IS-X.B.1
Independent Information Security Audit

Independent audit assesses design and operating effectiveness of information security controls with reporting to the audit committee.

Artefacts an auditor will ask for
  • Audit plan
  • Audit reports
  • Management responses
  • Audit committee minutes
Where this commonly fails
  • Independent audit of information security is not performed annually
  • Internal audit coverage of cyber topics is limited within the multi year plan
  • Audit issues exceed agreed remediation timelines without justification
  • Audit reports are not provided to the board or audit committee in full
  • Validation of management self assessments is not performed

Business Continuity

IS-VIII.A.1
Business Continuity Integration

Information security is integrated into business continuity and disaster recovery planning with consistent risk assessment and testing.

Artefacts an auditor will ask for
  • BCP
  • DRP
  • BIA
Where this commonly fails
  • Information security is not represented in the business continuity steering committee
  • Cyber recovery scenarios are not addressed in BCP documents
  • Recovery time and point objectives for security tools are undefined
  • Coordination between IR and BCP teams during cyber incidents is unclear
  • Joint exercises between security and BCP are not scheduled

Cybersecurity Assessment Tool

IS-X.B.2
Cybersecurity Assessment and Maturity

Institution periodically assesses inherent cyber risk and cybersecurity maturity across domains with board-reported results.

Artefacts an auditor will ask for
  • CAT assessment
  • Maturity scores
  • Board reports
Where this commonly fails
  • Cybersecurity maturity assessment is not performed using a recognized model
  • Maturity targets are not approved by senior management
  • Year over year progression on maturity is not reported
  • Peer benchmarking is not used to validate maturity scoring
  • Maturity outcomes are not linked to the strategic roadmap

FFIEC IT Examination Handbook: Cybersecurity Controls

FFIEC-06
Network security and segmentation

Network security and segmentation. Control from FFIEC IT Examination Handbook framework, domain: FFIEC IT Examination Handbook: Cybersecurity Controls.

Artefacts an auditor will ask for
  • network architecture diagram
  • segmentation policy
  • firewall rule reviews
  • zero trust roadmap
Where this commonly fails
  • flat networks
  • stale firewall rules
  • no micro segmentation
  • east west traffic unmonitored
FFIEC-07
Endpoint protection and detection

Endpoint protection and detection. Control from FFIEC IT Examination Handbook framework, domain: FFIEC IT Examination Handbook: Cybersecurity Controls.

Artefacts an auditor will ask for
  • EDR deployment report
  • endpoint hardening baseline
  • EDR alert metrics
  • incident integration
Where this commonly fails
  • EDR coverage gaps
  • no integration with SIEM
  • tuning weak
  • legacy systems unprotected
FFIEC-08
Application security controls

Application security controls. Control from FFIEC IT Examination Handbook framework, domain: FFIEC IT Examination Handbook: Cybersecurity Controls.

Artefacts an auditor will ask for
  • secure SDLC policy
  • SAST DAST results
  • code review records
  • app inventory
Where this commonly fails
  • SAST DAST not in CI CD
  • code review optional
  • no app inventory
  • third party libraries unscanned
FFIEC-09
Encryption and key management

Encryption and key management. Control from FFIEC IT Examination Handbook framework, domain: FFIEC IT Examination Handbook: Cybersecurity Controls.

Artefacts an auditor will ask for
  • encryption standards
  • key management policy
  • HSM inventory
  • key rotation logs
Where this commonly fails
  • legacy unencrypted
  • weak ciphers
  • no key rotation
  • key custody undocumented
FFIEC-10
Secure configuration standards

Secure configuration standards. Control from FFIEC IT Examination Handbook framework, domain: FFIEC IT Examination Handbook: Cybersecurity Controls.

Artefacts an auditor will ask for
  • secure config baselines
  • CIS benchmark assessments
  • drift detection reports
  • exception register
Where this commonly fails
  • no baseline for cloud
  • drift detection absent
  • exceptions not tracked
  • infrequent reassessment

FFIEC IT Examination Handbook: Incident Management & Reporting

FFIEC-21
Incident detection and classification

Incident detection and classification. Control from FFIEC IT Examination Handbook framework, domain: FFIEC IT Examination Handbook: Incident Management & Reporting.

Artefacts an auditor will ask for
  • detection use cases
  • classification taxonomy
  • triage runbooks
  • incident metrics
Where this commonly fails
  • classification inconsistent
  • MTTD high
  • triage runbooks absent
  • metrics not trended
FFIEC-22
Incident response and containment

Incident response and containment. Control from FFIEC IT Examination Handbook framework, domain: FFIEC IT Examination Handbook: Incident Management & Reporting.

Artefacts an auditor will ask for
  • IR plan
  • containment playbooks
  • recovery procedures
  • lessons learned reports
Where this commonly fails
  • plan untested
  • no containment automation
  • weak post incident review
  • lessons not implemented
FFIEC-23
Regulatory reporting requirements

Regulatory reporting requirements. Control from FFIEC IT Examination Handbook framework, domain: FFIEC IT Examination Handbook: Incident Management & Reporting.

Artefacts an auditor will ask for
  • regulator notification SOP
  • 36 hour rule procedure
  • notification templates
  • regulator contact list
Where this commonly fails
  • 36 hour SLA missed
  • notification template absent
  • no central log
  • regulator contacts stale
FFIEC-24
Customer notification procedures

Customer notification procedures. Control from FFIEC IT Examination Handbook framework, domain: FFIEC IT Examination Handbook: Incident Management & Reporting.

Artefacts an auditor will ask for
  • customer notification template
  • state law overlay matrix
  • communications log
  • call centre script
Where this commonly fails
  • no template
  • state law overlay missing
  • communications inconsistent
  • call centre unprepared
FFIEC-25
Post-incident review and improvement

Post-incident review and improvement. Control from FFIEC IT Examination Handbook framework, domain: FFIEC IT Examination Handbook: Incident Management & Reporting.

Artefacts an auditor will ask for
  • post incident review template
  • lessons learned register
  • action tracker
  • executive briefing
Where this commonly fails
  • reviews skipped
  • lessons not tracked
  • actions unclosed
  • no trend analysis

FFIEC IT Examination Handbook: Information Security Governance

FFIEC-01
Information security program management

Information security program management. Control from FFIEC IT Examination Handbook framework, domain: FFIEC IT Examination Handbook: Information Security Governance.

Artefacts an auditor will ask for
  • security program charter
  • policy library
  • annual report to board
  • program metrics
Where this commonly fails
  • program scope narrow
  • no board reporting
  • metrics absent
  • policies stale
FFIEC-02
Board and management oversight

Board and management oversight. Control from FFIEC IT Examination Handbook framework, domain: FFIEC IT Examination Handbook: Information Security Governance.

Artefacts an auditor will ask for
  • board agenda items
  • management committee charter
  • executive briefings
  • oversight evidence
Where this commonly fails
  • board cyber expertise gap
  • infrequent briefings
  • weak management oversight
  • no escalation criteria
FFIEC-03
Risk appetite and tolerance for IT risk

Risk appetite and tolerance for IT risk. Control from FFIEC IT Examination Handbook framework, domain: FFIEC IT Examination Handbook: Information Security Governance.

Artefacts an auditor will ask for
  • risk appetite statement
  • tolerance thresholds
  • board approval records
  • breach response process
Where this commonly fails
  • appetite not quantified
  • no tolerance thresholds
  • appetite not used in decisions
  • no breach response
FFIEC-04
Security policy framework

Security policy framework. Control from FFIEC IT Examination Handbook framework, domain: FFIEC IT Examination Handbook: Information Security Governance.

Artefacts an auditor will ask for
  • policy library
  • review schedule
  • approval log
  • policy attestation
Where this commonly fails
  • policies older than two years
  • no formal approval
  • attestation gaps
  • fragmented policies
FFIEC-05
Roles and responsibilities definition

Roles and responsibilities definition. Control from FFIEC IT Examination Handbook framework, domain: FFIEC IT Examination Handbook: Information Security Governance.

Artefacts an auditor will ask for
  • RACI matrix
  • job descriptions
  • org chart
  • security committee charter
Where this commonly fails
  • unclear accountability
  • no RACI
  • stale job descriptions
  • no committee charter

FFIEC IT Examination Handbook: Operational Resilience

FFIEC-11
Business continuity planning and testing

Business continuity planning and testing. Control from FFIEC IT Examination Handbook framework, domain: FFIEC IT Examination Handbook: Operational Resilience.

Artefacts an auditor will ask for
  • BCP plan
  • BIA results
  • test schedule
  • exercise reports
Where this commonly fails
  • BCP not tested
  • BIA outdated
  • scenarios narrow
  • no executive participation
FFIEC-12
Disaster recovery procedures

Disaster recovery procedures. Control from FFIEC IT Examination Handbook framework, domain: FFIEC IT Examination Handbook: Operational Resilience.

Artefacts an auditor will ask for
  • DR runbook
  • RTO RPO definitions
  • DR test reports
  • recovery automation
Where this commonly fails
  • DR untested
  • RTO unrealistic
  • no automation
  • back up restoration unverified
FFIEC-13
Third-party dependency management

Third-party dependency management. Control from FFIEC IT Examination Handbook framework, domain: FFIEC IT Examination Handbook: Operational Resilience.

Artefacts an auditor will ask for
  • vendor inventory
  • criticality classifications
  • dependency mapping
  • annual reviews
Where this commonly fails
  • dependency map missing
  • criticality not assessed
  • no concentration analysis
  • exit plans absent
FFIEC-14
Critical service identification

Critical service identification. Control from FFIEC IT Examination Handbook framework, domain: FFIEC IT Examination Handbook: Operational Resilience.

Artefacts an auditor will ask for
  • critical service register
  • BIA outputs
  • service dependency map
  • critical service review
Where this commonly fails
  • criticality definitions weak
  • register incomplete
  • no annual review
  • dependencies unmapped
FFIEC-15
Communication and escalation procedures

Communication and escalation procedures. Control from FFIEC IT Examination Handbook framework, domain: FFIEC IT Examination Handbook: Operational Resilience.

Artefacts an auditor will ask for
  • communications plan
  • escalation matrix
  • crisis comms templates
  • stakeholder mapping
Where this commonly fails
  • no crisis comms plan
  • escalation thresholds unclear
  • templates absent
  • stakeholders unmapped

FFIEC IT Examination Handbook: Third-Party Risk Management

FFIEC-16
Due diligence and onboarding

Due diligence and onboarding. Control from FFIEC IT Examination Handbook framework, domain: FFIEC IT Examination Handbook: Third-Party Risk Management.

Artefacts an auditor will ask for
  • vendor due diligence checklist
  • security questionnaires
  • evidence file
  • approval workflow
Where this commonly fails
  • due diligence light
  • no SOC 2 review
  • approvals informal
  • evidence gaps
FFIEC-17
Contractual security requirements

Contractual security requirements. Control from FFIEC IT Examination Handbook framework, domain: FFIEC IT Examination Handbook: Third-Party Risk Management.

Artefacts an auditor will ask for
  • contract template clauses
  • security addendum
  • audit rights clauses
  • termination clauses
Where this commonly fails
  • contracts lack audit rights
  • no security addendum
  • termination clauses weak
  • subcontractor flow down absent
FFIEC-18
Ongoing monitoring and assessment

Ongoing monitoring and assessment. Control from FFIEC IT Examination Handbook framework, domain: FFIEC IT Examination Handbook: Third-Party Risk Management.

Artefacts an auditor will ask for
  • vendor monitoring schedule
  • annual review reports
  • performance metrics
  • issue tracker
Where this commonly fails
  • no ongoing monitoring
  • annual reviews skipped
  • issues unclosed
  • metrics absent
FFIEC-19
Concentration risk management

Concentration risk management. Control from FFIEC IT Examination Handbook framework, domain: FFIEC IT Examination Handbook: Third-Party Risk Management.

Artefacts an auditor will ask for
  • concentration analysis
  • vendor dependency map
  • diversification strategy
  • executive briefing
Where this commonly fails
  • concentration not assessed
  • single sourced critical services
  • no diversification plan
  • no executive view
FFIEC-20
Exit strategy and transition planning

Exit strategy and transition planning. Control from FFIEC IT Examination Handbook framework, domain: FFIEC IT Examination Handbook: Third-Party Risk Management.

Artefacts an auditor will ask for
  • exit plans by vendor
  • data return procedure
  • transition testing records
  • service continuity plan
Where this commonly fails
  • no exit plans
  • data return untested
  • transition plans absent
  • no rehearsal

Information Security

IS-II.A.1
Board Oversight of Information Security

Board approves the information security program and holds senior management accountable for execution, risk acceptance, and program effectiveness.

Artefacts an auditor will ask for
  • Board charter with InfoSec oversight responsibilities
  • Board-approved information security program
  • Board meeting minutes showing InfoSec reporting
  • Annual board attestation of program
Where this commonly fails
  • No documented evidence of board approval of the information security program on an annual basis
  • Board meeting minutes lack discussion of cybersecurity risk posture and key metrics
  • Information security reporting to the board is ad hoc rather than scheduled
  • Directors lack documented cybersecurity training or briefings
  • Board charter does not assign explicit oversight responsibility for information security
IS-II.A.2
Senior Management Responsibilities

Senior management implements the security program, allocates resources, and ensures coordination across business lines.

Artefacts an auditor will ask for
  • Information security charter
  • Management committee minutes
  • Resource allocation budgets
  • RACI matrix
Where this commonly fails
  • CISO or equivalent role lacks documented reporting line to senior management or board
  • Senior management has not approved the information security policy within the last 12 months
  • Resource allocation decisions for security are not tied to documented risk appetite
  • No evidence senior management reviews independent audit findings and remediation status
  • Performance objectives for executives omit information security metrics
IS-II.B.1
Information Security Culture

Institution fosters a security-aware culture through tone at the top, training, and accountability mechanisms.

Artefacts an auditor will ask for
  • Code of conduct
  • Security culture communications
  • Training completion records
  • Disciplinary policy
Where this commonly fails
  • No regular communications from leadership reinforcing security expectations
  • Security culture is not measured through surveys or behavioral metrics
  • Disciplinary process for policy violations is undefined or inconsistently enforced
  • New hires are not introduced to the security culture during onboarding
  • No mechanism for staff to raise security concerns confidentially
IS-II.C.1
Information Security Roles and Responsibilities

CISO or equivalent role is designated with sufficient authority, independence, and access to the board.

Artefacts an auditor will ask for
  • CISO job description
  • Org chart showing reporting lines
  • CISO board reporting schedule
Where this commonly fails
  • Security roles are documented in job descriptions but not in a RACI matrix
  • Conflicts of duty between operations and security oversight are not addressed
  • Backups and successors for key security roles are not designated
  • Third party security responsibilities are not allocated between the institution and vendors
  • Roles do not reflect current organizational structure following reorganizations
IS-III.A.1
Information Security Risk Management Framework

Institution maintains a documented risk management framework integrating information security risk into enterprise risk management.

Artefacts an auditor will ask for
  • Risk management framework document
  • Risk appetite statement
  • Integration mapping to ERM
Where this commonly fails
  • Risk management framework is not formally documented or last update is more than 24 months old
  • Information security risk is not integrated with enterprise risk management taxonomy
  • Risk appetite statements are absent or not quantified
  • Framework does not address inherent versus residual risk distinctions
  • Methodology lacks defined risk acceptance authority levels
IS-III.B.1
Risk Identification

Institution identifies threats, vulnerabilities, and risks to information assets through systematic processes.

Artefacts an auditor will ask for
  • Risk register
  • Threat intelligence feeds
  • Vulnerability scan reports
Where this commonly fails
  • Threat catalog is not maintained or last refreshed more than 12 months ago
  • Risk identification does not consider emerging threats from threat intelligence sources
  • Identified risks are not linked to specific assets or processes
  • Insider threat scenarios are missing from the risk inventory
  • Risks from new technologies and projects are not assessed before deployment
IS-III.B.2
Risk Measurement and Analysis

Risks are measured using consistent methodologies considering likelihood, impact, velocity, and inherent versus residual risk.

Artefacts an auditor will ask for
  • Risk assessment methodology
  • Risk scoring rubrics
  • Risk heat maps
Where this commonly fails
  • Likelihood and impact scales are subjective without anchor definitions
  • No use of quantitative methods such as FAIR for material risks
  • Risk scoring does not differentiate between inherent and residual ratings
  • Aggregation of related risks across business units is not performed
  • Calibration of risk analysts is not validated through periodic exercises
IS-III.B.3
Risk Mitigation Strategy

Mitigation strategies including accept, transfer, avoid, or reduce are selected based on risk appetite and cost-benefit analysis.

Artefacts an auditor will ask for
  • Risk treatment plans
  • Cost-benefit analyses
  • Risk acceptance forms
Where this commonly fails
  • Mitigation strategies lack target completion dates and accountable owners
  • Risk acceptance documentation does not record approver and rationale
  • No cost benefit analysis supports control selection decisions
  • Compensating controls are used without documented justification or expiry
  • Mitigation effectiveness is not measured after implementation
IS-III.C.1
Risk Monitoring and Reporting

Risk posture is continuously monitored and reported to management, board, and risk committees through KRIs and dashboards.

Artefacts an auditor will ask for
  • KRI dashboard
  • Risk reporting templates
  • Committee reporting packages
Where this commonly fails
  • Key risk indicators are defined but not regularly reported to management
  • Risk register updates lag behind operational changes by more than one quarter
  • Trending and aging of open risks are not visualized in reports
  • Threshold breaches do not trigger documented escalation procedures
  • Reports to the board lack residual risk views and remediation progress
IS-III.D.1
Information Security Strategy

Multi-year information security strategy aligns with business strategy, regulatory expectations, and risk appetite.

Artefacts an auditor will ask for
  • InfoSec strategic plan
  • Roadmap
  • Maturity assessment
Where this commonly fails
  • Information security strategy document is missing or older than three years
  • Strategy is not linked to business objectives or technology roadmap
  • Budget is not aligned with stated strategic priorities
  • Progress against the strategy is not reported to the board
  • Strategy does not address evolving regulatory expectations
IS-IV.A.1
Inventory and Classification of Information Assets

Information assets, systems, and data are inventoried and classified based on sensitivity and criticality.

Artefacts an auditor will ask for
  • Asset inventory
  • Data classification policy
  • Classification labels
Where this commonly fails
  • Asset inventory does not include cloud workloads or SaaS applications
  • Information classification labels are inconsistently applied across repositories
  • Inventory reconciliation between CMDB and discovery tools is not performed
  • Data owners are not identified for all classified information assets
  • Retention and disposal expectations are not linked to classification tier
IS-IV.A.2
Data Flow Diagrams

Data flows including entry points, processing, storage, and transmission are documented for sensitive information.

Artefacts an auditor will ask for
  • Data flow diagrams
  • System interconnection diagrams
Where this commonly fails
  • Data flow diagrams exist for limited systems and are not maintained
  • Cross border data flows are not depicted or assessed
  • Diagrams do not identify encryption boundaries and trust zones
  • Third party data exchange points are not documented
  • Diagram updates are not triggered by change management
IS-IV.B.1
Identity and Access Management Program

Institution implements identity lifecycle, authentication, and authorization controls aligned with least privilege.

Artefacts an auditor will ask for
  • IAM policy
  • Provisioning workflow
  • Access matrices
Where this commonly fails
  • Identity and access management policy is fragmented across systems
  • Role based access model is not defined or enforced consistently
  • Service account ownership and review processes are missing
  • Federation and single sign on are not used for critical applications
  • IAM program metrics are not tracked or reported
IS-IV.B.2
Authentication Controls

Multi-factor authentication is enforced for privileged accounts, remote access, and access to sensitive systems and data.

Artefacts an auditor will ask for
  • MFA policy
  • MFA enforcement reports
  • Exceptions log
Where this commonly fails
  • Multi factor authentication is not enforced for all remote and privileged access
  • Password complexity and rotation standards are inconsistent with current guidance
  • Authentication logs are not centrally aggregated for monitoring
  • Legacy authentication protocols remain enabled on certain systems
  • Step up authentication is not implemented for sensitive transactions
IS-IV.B.3
Privileged Access Management

Privileged accounts are inventoried, vaulted, monitored, and subject to elevated controls including session recording.

Artefacts an auditor will ask for
  • PAM tool reports
  • Privileged account inventory
  • Session recordings
Where this commonly fails
  • Privileged accounts bypass the PAM vault for emergency access
  • Session recording is not enabled for high risk administrative actions
  • Shared administrator credentials remain in use without check out controls
  • Just in time elevation is not implemented for routine privileged tasks
  • Privileged access reviews occur less frequently than required by policy
IS-IV.B.4
Access Reviews and Recertification

User access rights are periodically reviewed and recertified by data and system owners with timely revocation of unneeded access.

Artefacts an auditor will ask for
  • Recertification campaign reports
  • Manager attestations
  • Revocation tickets
Where this commonly fails
  • Access reviews are not performed for all in scope applications on the required cadence
  • Reviewers rubber stamp recertifications without sufficient context
  • Findings from reviews are not tracked through to remediation
  • Reviews omit non human identities such as service accounts
  • Evidence of completed reviews is not retained in a tamper resistant repository
IS-IV.B.5
Joiner Mover Leaver Process

Access is granted, modified, and removed in alignment with employment lifecycle events with timely deprovisioning.

Artefacts an auditor will ask for
  • JML workflow
  • Termination checklist
  • Deprovisioning SLA report
Where this commonly fails
  • Termination access removal exceeds the policy SLA for a material number of cases
  • Mover events do not consistently trigger removal of prior access rights
  • Manual handoffs from HR to IT introduce delays and errors
  • Contractor lifecycle events are not integrated with the JML process
  • Reconciliation between HR records and IAM is not performed
IS-IV.C.1
Network Security Architecture

Network is segmented based on trust zones with defense in depth, including firewalls, IDS/IPS, and secure perimeter controls.

Artefacts an auditor will ask for
  • Network architecture diagrams
  • Firewall rulesets
  • Segmentation documentation
Where this commonly fails
  • Network segmentation between production and corporate environments is incomplete
  • Architecture diagrams are outdated and do not reflect cloud connectivity
  • Zero trust principles are not applied to internal east west traffic
  • DMZ design lacks documented trust boundaries and inspection points
  • Network architecture standards are not enforced in change reviews
IS-IV.C.2
Firewall Configuration and Review

Firewall rules follow deny-by-default with documented business justification and are reviewed periodically for staleness.

Artefacts an auditor will ask for
  • Firewall rule review reports
  • Change tickets
  • Justification records
Where this commonly fails
  • Firewall rulesets are not reviewed at the required frequency for stale rules
  • Any to any or overly permissive rules exist without documented justification
  • Change tickets do not consistently reference firewall rule modifications
  • Backup of firewall configurations is not validated regularly
  • Rule documentation does not identify the owning application or business purpose
IS-IV.C.3
Wireless Network Security

Wireless networks are secured with strong encryption, segmentation from production, and rogue access point detection.

Artefacts an auditor will ask for
  • Wireless security policy
  • Rogue AP scan reports
  • WPA configuration
Where this commonly fails
  • Rogue access point detection is not enabled or is ineffective
  • Guest wireless is not fully isolated from corporate network resources
  • Wireless authentication relies on shared keys rather than enterprise methods
  • Wireless coverage surveys are not performed to detect signal bleed
  • Wireless intrusion prevention alerts are not monitored
IS-IV.C.4
Remote Access Security

Remote access uses encrypted tunnels, MFA, endpoint posture checks, and session timeouts.

Artefacts an auditor will ask for
  • Remote access policy
  • VPN configuration
  • Posture check policy
Where this commonly fails
  • Remote access does not require posture validation of endpoints
  • Split tunneling is enabled without documented risk acceptance
  • Remote access logs are not retained for the policy required period
  • VPN concentrators run unsupported firmware versions
  • Privileged remote access lacks additional jump host controls
IS-IV.D.1
Endpoint Security Controls

Endpoints are hardened, deployed with anti-malware, EDR, and managed configurations resistant to tampering.

Artefacts an auditor will ask for
  • Endpoint hardening standards
  • EDR coverage reports
  • AV signature reports
Where this commonly fails
  • EDR coverage gaps exist on a portion of endpoints in the inventory
  • Endpoint hardening standards are not aligned with recognized benchmarks
  • Local administrator rights remain on user workstations without compensating controls
  • Endpoint configuration drift is not measured against baselines
  • Tamper protection for endpoint agents is not enforced
IS-IV.D.2
Mobile Device Management

Mobile devices accessing institution data are managed via MDM with encryption, remote wipe, and policy enforcement.

Artefacts an auditor will ask for
  • MDM policy
  • Enrollment reports
  • Compliance reports
Where this commonly fails
  • BYOD devices accessing corporate data are not enrolled in MDM
  • Mobile policy does not require encryption or remote wipe capability
  • Containerization of corporate data on mobile devices is not enforced
  • Mobile threat defense is not deployed to detect risky apps
  • Mobile inventory reconciliation with HR records is incomplete
IS-IV.D.3
Removable Media Controls

Use of removable media is restricted, encrypted, and logged with DLP controls to prevent unauthorized data exfiltration.

Artefacts an auditor will ask for
  • Removable media policy
  • DLP reports
  • USB block configurations
Where this commonly fails
  • USB ports are not restricted on endpoints handling sensitive data
  • Removable media encryption is not enforced when permitted
  • Use of removable media is not logged or monitored
  • Sanitization procedures for retired media are inconsistently followed
  • Exceptions to the removable media policy lack expiry dates
IS-IV.E.1
Secure Software Development Lifecycle

Applications follow secure SDLC including requirements, threat modeling, secure coding, testing, and deployment controls.

Artefacts an auditor will ask for
  • SDLC policy
  • Threat models
  • Code review records
Where this commonly fails
  • Threat modeling is not performed for material new applications
  • Secure coding training is not refreshed annually for developers
  • Security requirements are not captured as part of user stories
  • SDLC gates do not include mandatory security sign off
  • Findings from security activities are not tracked in the defect system
IS-IV.E.2
Application Security Testing

Applications undergo SAST, DAST, dependency scanning, and penetration testing with remediation tracking.

Artefacts an auditor will ask for
  • SAST/DAST reports
  • SCA reports
  • Pen test reports
  • Remediation tickets
Where this commonly fails
  • SAST and DAST are not integrated into CI pipelines for critical apps
  • Software composition analysis does not block builds with high severity vulnerabilities
  • Findings from testing tools accumulate without remediation SLAs
  • Penetration testing of applications is not performed annually
  • API security testing coverage is incomplete
IS-IV.E.3
Application Change Management

Application changes follow documented change management with separation of duties between development, test, and production.

Artefacts an auditor will ask for
  • Change management policy
  • Change tickets
  • Segregation matrix
Where this commonly fails
  • Emergency changes are deployed without retroactive security review
  • Segregation between development, test, and production is not consistently enforced
  • Code reviewers and approvers can overlap with developers
  • Configuration changes are not subjected to the same rigor as code changes
  • Rollback procedures are not tested for application releases
IS-IV.F.1
Encryption Standards and Key Management

Cryptographic standards approve algorithms and key strengths with centralized key management, rotation, and HSM use for sensitive keys.

Artefacts an auditor will ask for
  • Cryptographic policy
  • Approved algorithms list
  • Key inventory
  • HSM logs
Where this commonly fails
  • Cryptographic standards document is missing or last updated more than three years ago
  • Inventory of cryptographic keys and algorithms in use is incomplete
  • Key rotation schedules are not enforced for all material keys
  • HSM usage is inconsistent across critical systems
  • Deprecated algorithms remain in production without remediation plans
IS-IV.F.2
Data in Transit Encryption

Sensitive data is encrypted in transit using current TLS versions with strong cipher suites and certificate validation.

Artefacts an auditor will ask for
  • TLS configuration reports
  • SSL Labs grades
  • Certificate inventory
Where this commonly fails
  • Legacy TLS versions remain enabled on a subset of services
  • Certificate inventory and expiry monitoring are incomplete
  • Internal east west traffic is not encrypted in certain segments
  • Mutual TLS is not used between sensitive microservices
  • Cipher suite hardening does not match current guidance
IS-IV.F.3
Data at Rest Encryption

Sensitive data at rest is encrypted across databases, file systems, backups, and removable media using approved algorithms.

Artefacts an auditor will ask for
  • Encryption coverage report
  • Database encryption configuration
  • Backup encryption verification
Where this commonly fails
  • Database transparent data encryption is not enabled on all sensitive databases
  • Backups stored offsite are not consistently encrypted
  • File share and unstructured data encryption is limited
  • Key escrow and recovery procedures are not documented
  • Cloud storage encryption uses provider managed keys without business justification
IS-V.A.1
IT Operations Management

IT operations include capacity planning, performance monitoring, job scheduling, and operational metrics aligned with SLAs.

Artefacts an auditor will ask for
  • Operations runbooks
  • Capacity reports
  • SLA dashboards
Where this commonly fails
  • Capacity planning is reactive rather than forecast driven
  • Operational runbooks are outdated or not version controlled
  • Service level objectives are not defined for critical systems
  • Operational handovers between shifts are not documented
  • Operations metrics are not reviewed in management forums
IS-V.A.2
Configuration Management

System configurations are baselined, monitored for drift, and changes follow approved processes including patch management.

Artefacts an auditor will ask for
  • Configuration baselines
  • Drift reports
  • Patch compliance reports
Where this commonly fails
  • Configuration baselines are defined but not enforced through automation
  • Drift detection is not implemented for production systems
  • Golden images are not refreshed on a defined cadence
  • CMDB accuracy is below the policy threshold
  • Unauthorized configuration changes are not consistently detected
IS-V.A.3
Patch Management

Security patches are tracked and applied within risk-based SLAs with documented exceptions for delays.

Artefacts an auditor will ask for
  • Patch management policy
  • Patch compliance reports
  • Exception register
Where this commonly fails
  • Critical patches are not applied within the policy SLA on a material portion of assets
  • Patch exception process lacks documented compensating controls and expiry
  • Patch testing in lower environments is inconsistent
  • Reporting on patch posture is not provided to senior management
  • Out of band emergency patches do not follow the same documentation rigor
IS-V.B.1
Vulnerability Management Program

Vulnerabilities are identified through scanning, prioritized by risk, tracked to remediation, and reported to management.

Artefacts an auditor will ask for
  • VM policy
  • Scan reports
  • Remediation dashboards
Where this commonly fails
  • Authenticated scanning is not performed across the full estate
  • Cloud and container assets are excluded from regular scanning
  • Vulnerabilities older than the SLA persist without documented acceptance
  • Scan results are not reconciled with the asset inventory
  • Remediation tracking lacks ownership and trending
IS-V.B.2
Penetration Testing

Independent penetration testing is performed annually on external and internal environments with findings remediated.

Artefacts an auditor will ask for
  • Pen test reports
  • SOW
  • Remediation plans
Where this commonly fails
  • Penetration testing scope omits material applications or infrastructure
  • Findings from penetration tests are not retested after remediation
  • Testing is performed by the same team that operates the systems
  • Red team or purple team exercises are not conducted
  • Testing frequency does not match risk classification of systems
IS-V.C.1
Physical and Environmental Security

Data centers and facilities housing sensitive systems implement physical access controls, environmental monitoring, and surveillance.

Artefacts an auditor will ask for
  • Physical access logs
  • Visitor logs
  • Environmental monitoring reports
Where this commonly fails
  • Physical access reviews for data centers and wiring closets are infrequent
  • Visitor logs are inconsistently maintained at sensitive locations
  • Environmental monitoring alerts are not integrated with operations dashboards
  • Tailgating prevention measures are not validated
  • Decommissioned hardware disposal records are incomplete
IS-VI.A.1
Security Logging Standards

Security-relevant events are logged with consistent fields, time synchronization, and protection against tampering.

Artefacts an auditor will ask for
  • Logging standard
  • Log sources inventory
  • NTP configuration
Where this commonly fails
  • Logging standards do not specify required events per system type
  • Critical systems do not forward logs to the central collector
  • Log retention falls short of regulatory and policy requirements
  • Log integrity protections such as write once storage are missing
  • Time synchronization across sources is not enforced
IS-VI.A.2
Security Monitoring and SIEM

Centralized SIEM correlates logs across systems with use cases tuned to detect threats, with 24x7 monitoring.

Artefacts an auditor will ask for
  • SIEM use case catalog
  • Coverage matrix
  • SOC staffing schedule
Where this commonly fails
  • SIEM use case coverage is limited and not mapped to a recognized framework
  • Alert tuning is not performed regularly leading to high false positive rates
  • Triage SLAs are not measured or reported
  • After hours coverage relies on on call without documented playbooks
  • Detection content lifecycle management is not formalized
IS-VI.A.3
Threat Intelligence

Institution consumes threat intelligence from internal and external sources, including FS-ISAC, to inform detection and response.

Artefacts an auditor will ask for
  • Threat intel sources
  • Indicator feeds
  • Briefing reports
Where this commonly fails
  • Threat intelligence feeds are consumed but not operationalized into detection
  • Sector sharing memberships such as FS ISAC are underused
  • Strategic intelligence is not delivered to leadership in a regular brief
  • Indicators of compromise are not retroactively searched in historical logs
  • Attribution and campaign tracking are not maintained
IS-VI.B.1
User Behavior Analytics

Anomalous user and entity behavior is detected through analytics including insider threat indicators and impossible travel.

Artefacts an auditor will ask for
  • UEBA configuration
  • Alert review records
  • Insider threat program
Where this commonly fails
  • User behavior analytics is deployed but baselines are not maintained per role
  • Insider threat investigations lack documented procedures
  • Privileged user behavior is not analyzed separately from standard users
  • Integration with HR signals such as termination notice is missing
  • Analyst feedback loops to improve UBA models are not established
IS-VII.A.1
Incident Response Program

Incident response program defines roles, escalation paths, communication protocols, and regulatory notification requirements.

Artefacts an auditor will ask for
  • IR plan
  • Playbooks
  • Contact lists
  • Regulatory notification matrix
Where this commonly fails
  • Incident response plan has not been reviewed within the last 12 months
  • Severity classification criteria are inconsistently applied across teams
  • Legal and communications roles in the plan are not pre identified
  • Contact lists for response teams are stale
  • Integration with crisis management and BCP plans is unclear
IS-VII.A.2
Incident Detection and Classification

Incidents are detected, classified by severity, and triaged with timely engagement of incident response team.

Artefacts an auditor will ask for
  • Incident records
  • Severity classification matrix
  • Triage records
Where this commonly fails
  • Detection coverage for ransomware and business email compromise is limited
  • Triage playbooks exist for only a subset of common incident types
  • Mean time to detect is not measured or trended
  • Classification criteria do not address material impact for regulatory reporting
  • Cross domain incidents lack a single accountable incident commander
IS-VII.A.3
Incident Response Testing and Exercises

IR plan is tested at least annually through tabletop or full-scale exercises with lessons learned and plan updates.

Artefacts an auditor will ask for
  • Exercise plans
  • After-action reports
  • Lessons learned tracker
Where this commonly fails
  • Tabletop exercises are conducted annually but do not include executives or board
  • Technical simulation exercises such as purple team drills are not performed
  • Lessons learned actions from exercises are not tracked to completion
  • Exercise scenarios do not reflect current threat landscape
  • Third party participation in exercises is missing for critical vendors
IS-VII.A.4
Notification of Customers Regulators and Law Enforcement

Customer, regulator, and law enforcement notification follows applicable rules including the 36-hour incident notification requirement.

Artefacts an auditor will ask for
  • Notification procedures
  • Notification logs
  • Regulatory contacts
Where this commonly fails
  • Notification templates for customers and regulators are not pre approved by legal
  • Timelines for notification do not reflect the most stringent applicable jurisdiction
  • Law enforcement contacts and procedures are not documented
  • Notification decisions lack a documented materiality assessment
  • Post notification follow up communications are not planned
IS-VIII.A.2
Backup and Recovery

Backups are encrypted, isolated from production credentials, tested for restorability, and protected against ransomware.

Artefacts an auditor will ask for
  • Backup policy
  • Restoration test reports
  • Immutability configuration
Where this commonly fails
  • Immutable or offline backups are not maintained for ransomware resilience
  • Restoration testing is not performed at the required frequency for critical systems
  • Backup encryption keys and credentials are not segregated from production
  • Backup coverage gaps exist for cloud services and SaaS applications
  • Backup integrity monitoring does not detect silent corruption
IS-X.A.1
Security Awareness Training

All personnel complete annual security awareness training with role-based content and phishing simulations.

Artefacts an auditor will ask for
  • Training curriculum
  • Completion records
  • Phishing simulation reports
Where this commonly fails
  • Annual awareness training completion rates fall short of policy thresholds
  • Phishing simulation campaigns lack progressive difficulty and targeting
  • Role based training for high risk roles such as finance is not provided
  • Awareness content is not refreshed to reflect current threats
  • Effectiveness of training is not measured beyond completion

Management

IS-XI.A.2
Management Booklet Governance Alignment

Overall IT and information security governance aligns with the Management booklet expectations for risk management, strategy, and accountability.

Artefacts an auditor will ask for
  • IT governance framework
  • Strategy documents
  • Board reports
Where this commonly fails
  • Mapping between internal policies and FFIEC Management Booklet expectations is incomplete
  • Governance forums do not explicitly reference Management Booklet principles
  • IT steering committee charters are not aligned with handbook guidance
  • Three lines model responsibilities are not clearly delineated
  • Periodic gap assessment against the Management Booklet is not performed

Outsourcing

IS-IX.A.1
Third Party Risk Management

Third party service providers are subject to due diligence, contractual security requirements, and ongoing monitoring.

Artefacts an auditor will ask for
  • TPRM policy
  • Vendor inventory
  • Due diligence files
  • SOC 2 reports
Where this commonly fails
  • Third party inventory is incomplete and excludes fourth party dependencies
  • Due diligence is performed at onboarding but not refreshed periodically
  • Vendor risk tiering criteria are subjective and not consistently applied
  • Right to audit clauses are present but not exercised
  • Termination and exit planning for critical vendors is undocumented
IS-IX.A.2
Cloud Service Provider Oversight

Cloud service providers are governed with attention to shared responsibility, data residency, and exit strategies.

Artefacts an auditor will ask for
  • Cloud governance policy
  • Shared responsibility matrix
  • Exit plans
Where this commonly fails
  • Shared responsibility model is not documented for each cloud service in use
  • SOC 2 and equivalent reports are not reviewed for material exceptions
  • Cloud configuration baselines are not benchmarked against CIS or vendor guidance
  • Concentration risk across cloud providers is not assessed
  • Cloud event logs are not ingested into the central monitoring platform
Assembled from the framework's own control set. Every line traces to a control in the graph, so this pack is regenerated rather than written, and stays current as the graph does.

Assembled from the framework’s own control set, so this list is regenerated rather than written and stays current as the graph does. See the FFIEC IT Examination Handbook framework page.