FFIEC IT Examination Handbook
Evidence request list. 78 controls, 78 carrying auditor artefact guidance. Generated from the compliance knowledge graph on 11 September 2026. Published by The Art of Service.
Architecture/Operations
IT architecture and operations align with security requirements including secure baselines, zoning, and resilience patterns.
- Architecture standards
- Reference architectures
- Operations procedures
- Reference architectures exist but are not enforced through governance
- Operations teams deviate from architecture without exception tracking
- Architectural decisions are not documented in a centralized repository
- Standards updates do not flow into operational baselines
- Architectural debt is not tracked or prioritized for remediation
Audit
Independent audit assesses design and operating effectiveness of information security controls with reporting to the audit committee.
- Audit plan
- Audit reports
- Management responses
- Audit committee minutes
- Independent audit of information security is not performed annually
- Internal audit coverage of cyber topics is limited within the multi year plan
- Audit issues exceed agreed remediation timelines without justification
- Audit reports are not provided to the board or audit committee in full
- Validation of management self assessments is not performed
Business Continuity
Information security is integrated into business continuity and disaster recovery planning with consistent risk assessment and testing.
- BCP
- DRP
- BIA
- Information security is not represented in the business continuity steering committee
- Cyber recovery scenarios are not addressed in BCP documents
- Recovery time and point objectives for security tools are undefined
- Coordination between IR and BCP teams during cyber incidents is unclear
- Joint exercises between security and BCP are not scheduled
Cybersecurity Assessment Tool
Institution periodically assesses inherent cyber risk and cybersecurity maturity across domains with board-reported results.
- CAT assessment
- Maturity scores
- Board reports
- Cybersecurity maturity assessment is not performed using a recognized model
- Maturity targets are not approved by senior management
- Year over year progression on maturity is not reported
- Peer benchmarking is not used to validate maturity scoring
- Maturity outcomes are not linked to the strategic roadmap
FFIEC IT Examination Handbook: Cybersecurity Controls
Network security and segmentation. Control from FFIEC IT Examination Handbook framework, domain: FFIEC IT Examination Handbook: Cybersecurity Controls.
- network architecture diagram
- segmentation policy
- firewall rule reviews
- zero trust roadmap
- flat networks
- stale firewall rules
- no micro segmentation
- east west traffic unmonitored
Endpoint protection and detection. Control from FFIEC IT Examination Handbook framework, domain: FFIEC IT Examination Handbook: Cybersecurity Controls.
- EDR deployment report
- endpoint hardening baseline
- EDR alert metrics
- incident integration
- EDR coverage gaps
- no integration with SIEM
- tuning weak
- legacy systems unprotected
Application security controls. Control from FFIEC IT Examination Handbook framework, domain: FFIEC IT Examination Handbook: Cybersecurity Controls.
- secure SDLC policy
- SAST DAST results
- code review records
- app inventory
- SAST DAST not in CI CD
- code review optional
- no app inventory
- third party libraries unscanned
Encryption and key management. Control from FFIEC IT Examination Handbook framework, domain: FFIEC IT Examination Handbook: Cybersecurity Controls.
- encryption standards
- key management policy
- HSM inventory
- key rotation logs
- legacy unencrypted
- weak ciphers
- no key rotation
- key custody undocumented
Secure configuration standards. Control from FFIEC IT Examination Handbook framework, domain: FFIEC IT Examination Handbook: Cybersecurity Controls.
- secure config baselines
- CIS benchmark assessments
- drift detection reports
- exception register
- no baseline for cloud
- drift detection absent
- exceptions not tracked
- infrequent reassessment
FFIEC IT Examination Handbook: Incident Management & Reporting
Incident detection and classification. Control from FFIEC IT Examination Handbook framework, domain: FFIEC IT Examination Handbook: Incident Management & Reporting.
- detection use cases
- classification taxonomy
- triage runbooks
- incident metrics
- classification inconsistent
- MTTD high
- triage runbooks absent
- metrics not trended
Incident response and containment. Control from FFIEC IT Examination Handbook framework, domain: FFIEC IT Examination Handbook: Incident Management & Reporting.
- IR plan
- containment playbooks
- recovery procedures
- lessons learned reports
- plan untested
- no containment automation
- weak post incident review
- lessons not implemented
Regulatory reporting requirements. Control from FFIEC IT Examination Handbook framework, domain: FFIEC IT Examination Handbook: Incident Management & Reporting.
- regulator notification SOP
- 36 hour rule procedure
- notification templates
- regulator contact list
- 36 hour SLA missed
- notification template absent
- no central log
- regulator contacts stale
Customer notification procedures. Control from FFIEC IT Examination Handbook framework, domain: FFIEC IT Examination Handbook: Incident Management & Reporting.
- customer notification template
- state law overlay matrix
- communications log
- call centre script
- no template
- state law overlay missing
- communications inconsistent
- call centre unprepared
Post-incident review and improvement. Control from FFIEC IT Examination Handbook framework, domain: FFIEC IT Examination Handbook: Incident Management & Reporting.
- post incident review template
- lessons learned register
- action tracker
- executive briefing
- reviews skipped
- lessons not tracked
- actions unclosed
- no trend analysis
FFIEC IT Examination Handbook: Information Security Governance
Information security program management. Control from FFIEC IT Examination Handbook framework, domain: FFIEC IT Examination Handbook: Information Security Governance.
- security program charter
- policy library
- annual report to board
- program metrics
- program scope narrow
- no board reporting
- metrics absent
- policies stale
Board and management oversight. Control from FFIEC IT Examination Handbook framework, domain: FFIEC IT Examination Handbook: Information Security Governance.
- board agenda items
- management committee charter
- executive briefings
- oversight evidence
- board cyber expertise gap
- infrequent briefings
- weak management oversight
- no escalation criteria
Risk appetite and tolerance for IT risk. Control from FFIEC IT Examination Handbook framework, domain: FFIEC IT Examination Handbook: Information Security Governance.
- risk appetite statement
- tolerance thresholds
- board approval records
- breach response process
- appetite not quantified
- no tolerance thresholds
- appetite not used in decisions
- no breach response
Security policy framework. Control from FFIEC IT Examination Handbook framework, domain: FFIEC IT Examination Handbook: Information Security Governance.
- policy library
- review schedule
- approval log
- policy attestation
- policies older than two years
- no formal approval
- attestation gaps
- fragmented policies
Roles and responsibilities definition. Control from FFIEC IT Examination Handbook framework, domain: FFIEC IT Examination Handbook: Information Security Governance.
- RACI matrix
- job descriptions
- org chart
- security committee charter
- unclear accountability
- no RACI
- stale job descriptions
- no committee charter
FFIEC IT Examination Handbook: Operational Resilience
Business continuity planning and testing. Control from FFIEC IT Examination Handbook framework, domain: FFIEC IT Examination Handbook: Operational Resilience.
- BCP plan
- BIA results
- test schedule
- exercise reports
- BCP not tested
- BIA outdated
- scenarios narrow
- no executive participation
Disaster recovery procedures. Control from FFIEC IT Examination Handbook framework, domain: FFIEC IT Examination Handbook: Operational Resilience.
- DR runbook
- RTO RPO definitions
- DR test reports
- recovery automation
- DR untested
- RTO unrealistic
- no automation
- back up restoration unverified
Third-party dependency management. Control from FFIEC IT Examination Handbook framework, domain: FFIEC IT Examination Handbook: Operational Resilience.
- vendor inventory
- criticality classifications
- dependency mapping
- annual reviews
- dependency map missing
- criticality not assessed
- no concentration analysis
- exit plans absent
Critical service identification. Control from FFIEC IT Examination Handbook framework, domain: FFIEC IT Examination Handbook: Operational Resilience.
- critical service register
- BIA outputs
- service dependency map
- critical service review
- criticality definitions weak
- register incomplete
- no annual review
- dependencies unmapped
Communication and escalation procedures. Control from FFIEC IT Examination Handbook framework, domain: FFIEC IT Examination Handbook: Operational Resilience.
- communications plan
- escalation matrix
- crisis comms templates
- stakeholder mapping
- no crisis comms plan
- escalation thresholds unclear
- templates absent
- stakeholders unmapped
FFIEC IT Examination Handbook: Third-Party Risk Management
Due diligence and onboarding. Control from FFIEC IT Examination Handbook framework, domain: FFIEC IT Examination Handbook: Third-Party Risk Management.
- vendor due diligence checklist
- security questionnaires
- evidence file
- approval workflow
- due diligence light
- no SOC 2 review
- approvals informal
- evidence gaps
Contractual security requirements. Control from FFIEC IT Examination Handbook framework, domain: FFIEC IT Examination Handbook: Third-Party Risk Management.
- contract template clauses
- security addendum
- audit rights clauses
- termination clauses
- contracts lack audit rights
- no security addendum
- termination clauses weak
- subcontractor flow down absent
Ongoing monitoring and assessment. Control from FFIEC IT Examination Handbook framework, domain: FFIEC IT Examination Handbook: Third-Party Risk Management.
- vendor monitoring schedule
- annual review reports
- performance metrics
- issue tracker
- no ongoing monitoring
- annual reviews skipped
- issues unclosed
- metrics absent
Concentration risk management. Control from FFIEC IT Examination Handbook framework, domain: FFIEC IT Examination Handbook: Third-Party Risk Management.
- concentration analysis
- vendor dependency map
- diversification strategy
- executive briefing
- concentration not assessed
- single sourced critical services
- no diversification plan
- no executive view
Exit strategy and transition planning. Control from FFIEC IT Examination Handbook framework, domain: FFIEC IT Examination Handbook: Third-Party Risk Management.
- exit plans by vendor
- data return procedure
- transition testing records
- service continuity plan
- no exit plans
- data return untested
- transition plans absent
- no rehearsal
Information Security
Board approves the information security program and holds senior management accountable for execution, risk acceptance, and program effectiveness.
- Board charter with InfoSec oversight responsibilities
- Board-approved information security program
- Board meeting minutes showing InfoSec reporting
- Annual board attestation of program
- No documented evidence of board approval of the information security program on an annual basis
- Board meeting minutes lack discussion of cybersecurity risk posture and key metrics
- Information security reporting to the board is ad hoc rather than scheduled
- Directors lack documented cybersecurity training or briefings
- Board charter does not assign explicit oversight responsibility for information security
Senior management implements the security program, allocates resources, and ensures coordination across business lines.
- Information security charter
- Management committee minutes
- Resource allocation budgets
- RACI matrix
- CISO or equivalent role lacks documented reporting line to senior management or board
- Senior management has not approved the information security policy within the last 12 months
- Resource allocation decisions for security are not tied to documented risk appetite
- No evidence senior management reviews independent audit findings and remediation status
- Performance objectives for executives omit information security metrics
Institution fosters a security-aware culture through tone at the top, training, and accountability mechanisms.
- Code of conduct
- Security culture communications
- Training completion records
- Disciplinary policy
- No regular communications from leadership reinforcing security expectations
- Security culture is not measured through surveys or behavioral metrics
- Disciplinary process for policy violations is undefined or inconsistently enforced
- New hires are not introduced to the security culture during onboarding
- No mechanism for staff to raise security concerns confidentially
CISO or equivalent role is designated with sufficient authority, independence, and access to the board.
- CISO job description
- Org chart showing reporting lines
- CISO board reporting schedule
- Security roles are documented in job descriptions but not in a RACI matrix
- Conflicts of duty between operations and security oversight are not addressed
- Backups and successors for key security roles are not designated
- Third party security responsibilities are not allocated between the institution and vendors
- Roles do not reflect current organizational structure following reorganizations
Institution maintains a documented risk management framework integrating information security risk into enterprise risk management.
- Risk management framework document
- Risk appetite statement
- Integration mapping to ERM
- Risk management framework is not formally documented or last update is more than 24 months old
- Information security risk is not integrated with enterprise risk management taxonomy
- Risk appetite statements are absent or not quantified
- Framework does not address inherent versus residual risk distinctions
- Methodology lacks defined risk acceptance authority levels
Institution identifies threats, vulnerabilities, and risks to information assets through systematic processes.
- Risk register
- Threat intelligence feeds
- Vulnerability scan reports
- Threat catalog is not maintained or last refreshed more than 12 months ago
- Risk identification does not consider emerging threats from threat intelligence sources
- Identified risks are not linked to specific assets or processes
- Insider threat scenarios are missing from the risk inventory
- Risks from new technologies and projects are not assessed before deployment
Risks are measured using consistent methodologies considering likelihood, impact, velocity, and inherent versus residual risk.
- Risk assessment methodology
- Risk scoring rubrics
- Risk heat maps
- Likelihood and impact scales are subjective without anchor definitions
- No use of quantitative methods such as FAIR for material risks
- Risk scoring does not differentiate between inherent and residual ratings
- Aggregation of related risks across business units is not performed
- Calibration of risk analysts is not validated through periodic exercises
Mitigation strategies including accept, transfer, avoid, or reduce are selected based on risk appetite and cost-benefit analysis.
- Risk treatment plans
- Cost-benefit analyses
- Risk acceptance forms
- Mitigation strategies lack target completion dates and accountable owners
- Risk acceptance documentation does not record approver and rationale
- No cost benefit analysis supports control selection decisions
- Compensating controls are used without documented justification or expiry
- Mitigation effectiveness is not measured after implementation
Risk posture is continuously monitored and reported to management, board, and risk committees through KRIs and dashboards.
- KRI dashboard
- Risk reporting templates
- Committee reporting packages
- Key risk indicators are defined but not regularly reported to management
- Risk register updates lag behind operational changes by more than one quarter
- Trending and aging of open risks are not visualized in reports
- Threshold breaches do not trigger documented escalation procedures
- Reports to the board lack residual risk views and remediation progress
Multi-year information security strategy aligns with business strategy, regulatory expectations, and risk appetite.
- InfoSec strategic plan
- Roadmap
- Maturity assessment
- Information security strategy document is missing or older than three years
- Strategy is not linked to business objectives or technology roadmap
- Budget is not aligned with stated strategic priorities
- Progress against the strategy is not reported to the board
- Strategy does not address evolving regulatory expectations
Information assets, systems, and data are inventoried and classified based on sensitivity and criticality.
- Asset inventory
- Data classification policy
- Classification labels
- Asset inventory does not include cloud workloads or SaaS applications
- Information classification labels are inconsistently applied across repositories
- Inventory reconciliation between CMDB and discovery tools is not performed
- Data owners are not identified for all classified information assets
- Retention and disposal expectations are not linked to classification tier
Data flows including entry points, processing, storage, and transmission are documented for sensitive information.
- Data flow diagrams
- System interconnection diagrams
- Data flow diagrams exist for limited systems and are not maintained
- Cross border data flows are not depicted or assessed
- Diagrams do not identify encryption boundaries and trust zones
- Third party data exchange points are not documented
- Diagram updates are not triggered by change management
Institution implements identity lifecycle, authentication, and authorization controls aligned with least privilege.
- IAM policy
- Provisioning workflow
- Access matrices
- Identity and access management policy is fragmented across systems
- Role based access model is not defined or enforced consistently
- Service account ownership and review processes are missing
- Federation and single sign on are not used for critical applications
- IAM program metrics are not tracked or reported
Multi-factor authentication is enforced for privileged accounts, remote access, and access to sensitive systems and data.
- MFA policy
- MFA enforcement reports
- Exceptions log
- Multi factor authentication is not enforced for all remote and privileged access
- Password complexity and rotation standards are inconsistent with current guidance
- Authentication logs are not centrally aggregated for monitoring
- Legacy authentication protocols remain enabled on certain systems
- Step up authentication is not implemented for sensitive transactions
Privileged accounts are inventoried, vaulted, monitored, and subject to elevated controls including session recording.
- PAM tool reports
- Privileged account inventory
- Session recordings
- Privileged accounts bypass the PAM vault for emergency access
- Session recording is not enabled for high risk administrative actions
- Shared administrator credentials remain in use without check out controls
- Just in time elevation is not implemented for routine privileged tasks
- Privileged access reviews occur less frequently than required by policy
User access rights are periodically reviewed and recertified by data and system owners with timely revocation of unneeded access.
- Recertification campaign reports
- Manager attestations
- Revocation tickets
- Access reviews are not performed for all in scope applications on the required cadence
- Reviewers rubber stamp recertifications without sufficient context
- Findings from reviews are not tracked through to remediation
- Reviews omit non human identities such as service accounts
- Evidence of completed reviews is not retained in a tamper resistant repository
Access is granted, modified, and removed in alignment with employment lifecycle events with timely deprovisioning.
- JML workflow
- Termination checklist
- Deprovisioning SLA report
- Termination access removal exceeds the policy SLA for a material number of cases
- Mover events do not consistently trigger removal of prior access rights
- Manual handoffs from HR to IT introduce delays and errors
- Contractor lifecycle events are not integrated with the JML process
- Reconciliation between HR records and IAM is not performed
Network is segmented based on trust zones with defense in depth, including firewalls, IDS/IPS, and secure perimeter controls.
- Network architecture diagrams
- Firewall rulesets
- Segmentation documentation
- Network segmentation between production and corporate environments is incomplete
- Architecture diagrams are outdated and do not reflect cloud connectivity
- Zero trust principles are not applied to internal east west traffic
- DMZ design lacks documented trust boundaries and inspection points
- Network architecture standards are not enforced in change reviews
Firewall rules follow deny-by-default with documented business justification and are reviewed periodically for staleness.
- Firewall rule review reports
- Change tickets
- Justification records
- Firewall rulesets are not reviewed at the required frequency for stale rules
- Any to any or overly permissive rules exist without documented justification
- Change tickets do not consistently reference firewall rule modifications
- Backup of firewall configurations is not validated regularly
- Rule documentation does not identify the owning application or business purpose
Wireless networks are secured with strong encryption, segmentation from production, and rogue access point detection.
- Wireless security policy
- Rogue AP scan reports
- WPA configuration
- Rogue access point detection is not enabled or is ineffective
- Guest wireless is not fully isolated from corporate network resources
- Wireless authentication relies on shared keys rather than enterprise methods
- Wireless coverage surveys are not performed to detect signal bleed
- Wireless intrusion prevention alerts are not monitored
Remote access uses encrypted tunnels, MFA, endpoint posture checks, and session timeouts.
- Remote access policy
- VPN configuration
- Posture check policy
- Remote access does not require posture validation of endpoints
- Split tunneling is enabled without documented risk acceptance
- Remote access logs are not retained for the policy required period
- VPN concentrators run unsupported firmware versions
- Privileged remote access lacks additional jump host controls
Endpoints are hardened, deployed with anti-malware, EDR, and managed configurations resistant to tampering.
- Endpoint hardening standards
- EDR coverage reports
- AV signature reports
- EDR coverage gaps exist on a portion of endpoints in the inventory
- Endpoint hardening standards are not aligned with recognized benchmarks
- Local administrator rights remain on user workstations without compensating controls
- Endpoint configuration drift is not measured against baselines
- Tamper protection for endpoint agents is not enforced
Mobile devices accessing institution data are managed via MDM with encryption, remote wipe, and policy enforcement.
- MDM policy
- Enrollment reports
- Compliance reports
- BYOD devices accessing corporate data are not enrolled in MDM
- Mobile policy does not require encryption or remote wipe capability
- Containerization of corporate data on mobile devices is not enforced
- Mobile threat defense is not deployed to detect risky apps
- Mobile inventory reconciliation with HR records is incomplete
Use of removable media is restricted, encrypted, and logged with DLP controls to prevent unauthorized data exfiltration.
- Removable media policy
- DLP reports
- USB block configurations
- USB ports are not restricted on endpoints handling sensitive data
- Removable media encryption is not enforced when permitted
- Use of removable media is not logged or monitored
- Sanitization procedures for retired media are inconsistently followed
- Exceptions to the removable media policy lack expiry dates
Applications follow secure SDLC including requirements, threat modeling, secure coding, testing, and deployment controls.
- SDLC policy
- Threat models
- Code review records
- Threat modeling is not performed for material new applications
- Secure coding training is not refreshed annually for developers
- Security requirements are not captured as part of user stories
- SDLC gates do not include mandatory security sign off
- Findings from security activities are not tracked in the defect system
Applications undergo SAST, DAST, dependency scanning, and penetration testing with remediation tracking.
- SAST/DAST reports
- SCA reports
- Pen test reports
- Remediation tickets
- SAST and DAST are not integrated into CI pipelines for critical apps
- Software composition analysis does not block builds with high severity vulnerabilities
- Findings from testing tools accumulate without remediation SLAs
- Penetration testing of applications is not performed annually
- API security testing coverage is incomplete
Application changes follow documented change management with separation of duties between development, test, and production.
- Change management policy
- Change tickets
- Segregation matrix
- Emergency changes are deployed without retroactive security review
- Segregation between development, test, and production is not consistently enforced
- Code reviewers and approvers can overlap with developers
- Configuration changes are not subjected to the same rigor as code changes
- Rollback procedures are not tested for application releases
Cryptographic standards approve algorithms and key strengths with centralized key management, rotation, and HSM use for sensitive keys.
- Cryptographic policy
- Approved algorithms list
- Key inventory
- HSM logs
- Cryptographic standards document is missing or last updated more than three years ago
- Inventory of cryptographic keys and algorithms in use is incomplete
- Key rotation schedules are not enforced for all material keys
- HSM usage is inconsistent across critical systems
- Deprecated algorithms remain in production without remediation plans
Sensitive data is encrypted in transit using current TLS versions with strong cipher suites and certificate validation.
- TLS configuration reports
- SSL Labs grades
- Certificate inventory
- Legacy TLS versions remain enabled on a subset of services
- Certificate inventory and expiry monitoring are incomplete
- Internal east west traffic is not encrypted in certain segments
- Mutual TLS is not used between sensitive microservices
- Cipher suite hardening does not match current guidance
Sensitive data at rest is encrypted across databases, file systems, backups, and removable media using approved algorithms.
- Encryption coverage report
- Database encryption configuration
- Backup encryption verification
- Database transparent data encryption is not enabled on all sensitive databases
- Backups stored offsite are not consistently encrypted
- File share and unstructured data encryption is limited
- Key escrow and recovery procedures are not documented
- Cloud storage encryption uses provider managed keys without business justification
IT operations include capacity planning, performance monitoring, job scheduling, and operational metrics aligned with SLAs.
- Operations runbooks
- Capacity reports
- SLA dashboards
- Capacity planning is reactive rather than forecast driven
- Operational runbooks are outdated or not version controlled
- Service level objectives are not defined for critical systems
- Operational handovers between shifts are not documented
- Operations metrics are not reviewed in management forums
System configurations are baselined, monitored for drift, and changes follow approved processes including patch management.
- Configuration baselines
- Drift reports
- Patch compliance reports
- Configuration baselines are defined but not enforced through automation
- Drift detection is not implemented for production systems
- Golden images are not refreshed on a defined cadence
- CMDB accuracy is below the policy threshold
- Unauthorized configuration changes are not consistently detected
Security patches are tracked and applied within risk-based SLAs with documented exceptions for delays.
- Patch management policy
- Patch compliance reports
- Exception register
- Critical patches are not applied within the policy SLA on a material portion of assets
- Patch exception process lacks documented compensating controls and expiry
- Patch testing in lower environments is inconsistent
- Reporting on patch posture is not provided to senior management
- Out of band emergency patches do not follow the same documentation rigor
Vulnerabilities are identified through scanning, prioritized by risk, tracked to remediation, and reported to management.
- VM policy
- Scan reports
- Remediation dashboards
- Authenticated scanning is not performed across the full estate
- Cloud and container assets are excluded from regular scanning
- Vulnerabilities older than the SLA persist without documented acceptance
- Scan results are not reconciled with the asset inventory
- Remediation tracking lacks ownership and trending
Independent penetration testing is performed annually on external and internal environments with findings remediated.
- Pen test reports
- SOW
- Remediation plans
- Penetration testing scope omits material applications or infrastructure
- Findings from penetration tests are not retested after remediation
- Testing is performed by the same team that operates the systems
- Red team or purple team exercises are not conducted
- Testing frequency does not match risk classification of systems
Data centers and facilities housing sensitive systems implement physical access controls, environmental monitoring, and surveillance.
- Physical access logs
- Visitor logs
- Environmental monitoring reports
- Physical access reviews for data centers and wiring closets are infrequent
- Visitor logs are inconsistently maintained at sensitive locations
- Environmental monitoring alerts are not integrated with operations dashboards
- Tailgating prevention measures are not validated
- Decommissioned hardware disposal records are incomplete
Security-relevant events are logged with consistent fields, time synchronization, and protection against tampering.
- Logging standard
- Log sources inventory
- NTP configuration
- Logging standards do not specify required events per system type
- Critical systems do not forward logs to the central collector
- Log retention falls short of regulatory and policy requirements
- Log integrity protections such as write once storage are missing
- Time synchronization across sources is not enforced
Centralized SIEM correlates logs across systems with use cases tuned to detect threats, with 24x7 monitoring.
- SIEM use case catalog
- Coverage matrix
- SOC staffing schedule
- SIEM use case coverage is limited and not mapped to a recognized framework
- Alert tuning is not performed regularly leading to high false positive rates
- Triage SLAs are not measured or reported
- After hours coverage relies on on call without documented playbooks
- Detection content lifecycle management is not formalized
Institution consumes threat intelligence from internal and external sources, including FS-ISAC, to inform detection and response.
- Threat intel sources
- Indicator feeds
- Briefing reports
- Threat intelligence feeds are consumed but not operationalized into detection
- Sector sharing memberships such as FS ISAC are underused
- Strategic intelligence is not delivered to leadership in a regular brief
- Indicators of compromise are not retroactively searched in historical logs
- Attribution and campaign tracking are not maintained
Anomalous user and entity behavior is detected through analytics including insider threat indicators and impossible travel.
- UEBA configuration
- Alert review records
- Insider threat program
- User behavior analytics is deployed but baselines are not maintained per role
- Insider threat investigations lack documented procedures
- Privileged user behavior is not analyzed separately from standard users
- Integration with HR signals such as termination notice is missing
- Analyst feedback loops to improve UBA models are not established
Incident response program defines roles, escalation paths, communication protocols, and regulatory notification requirements.
- IR plan
- Playbooks
- Contact lists
- Regulatory notification matrix
- Incident response plan has not been reviewed within the last 12 months
- Severity classification criteria are inconsistently applied across teams
- Legal and communications roles in the plan are not pre identified
- Contact lists for response teams are stale
- Integration with crisis management and BCP plans is unclear
Incidents are detected, classified by severity, and triaged with timely engagement of incident response team.
- Incident records
- Severity classification matrix
- Triage records
- Detection coverage for ransomware and business email compromise is limited
- Triage playbooks exist for only a subset of common incident types
- Mean time to detect is not measured or trended
- Classification criteria do not address material impact for regulatory reporting
- Cross domain incidents lack a single accountable incident commander
IR plan is tested at least annually through tabletop or full-scale exercises with lessons learned and plan updates.
- Exercise plans
- After-action reports
- Lessons learned tracker
- Tabletop exercises are conducted annually but do not include executives or board
- Technical simulation exercises such as purple team drills are not performed
- Lessons learned actions from exercises are not tracked to completion
- Exercise scenarios do not reflect current threat landscape
- Third party participation in exercises is missing for critical vendors
Customer, regulator, and law enforcement notification follows applicable rules including the 36-hour incident notification requirement.
- Notification procedures
- Notification logs
- Regulatory contacts
- Notification templates for customers and regulators are not pre approved by legal
- Timelines for notification do not reflect the most stringent applicable jurisdiction
- Law enforcement contacts and procedures are not documented
- Notification decisions lack a documented materiality assessment
- Post notification follow up communications are not planned
Backups are encrypted, isolated from production credentials, tested for restorability, and protected against ransomware.
- Backup policy
- Restoration test reports
- Immutability configuration
- Immutable or offline backups are not maintained for ransomware resilience
- Restoration testing is not performed at the required frequency for critical systems
- Backup encryption keys and credentials are not segregated from production
- Backup coverage gaps exist for cloud services and SaaS applications
- Backup integrity monitoring does not detect silent corruption
All personnel complete annual security awareness training with role-based content and phishing simulations.
- Training curriculum
- Completion records
- Phishing simulation reports
- Annual awareness training completion rates fall short of policy thresholds
- Phishing simulation campaigns lack progressive difficulty and targeting
- Role based training for high risk roles such as finance is not provided
- Awareness content is not refreshed to reflect current threats
- Effectiveness of training is not measured beyond completion
Management
Overall IT and information security governance aligns with the Management booklet expectations for risk management, strategy, and accountability.
- IT governance framework
- Strategy documents
- Board reports
- Mapping between internal policies and FFIEC Management Booklet expectations is incomplete
- Governance forums do not explicitly reference Management Booklet principles
- IT steering committee charters are not aligned with handbook guidance
- Three lines model responsibilities are not clearly delineated
- Periodic gap assessment against the Management Booklet is not performed
Outsourcing
Third party service providers are subject to due diligence, contractual security requirements, and ongoing monitoring.
- TPRM policy
- Vendor inventory
- Due diligence files
- SOC 2 reports
- Third party inventory is incomplete and excludes fourth party dependencies
- Due diligence is performed at onboarding but not refreshed periodically
- Vendor risk tiering criteria are subjective and not consistently applied
- Right to audit clauses are present but not exercised
- Termination and exit planning for critical vendors is undocumented
Cloud service providers are governed with attention to shared responsibility, data residency, and exit strategies.
- Cloud governance policy
- Shared responsibility matrix
- Exit plans
- Shared responsibility model is not documented for each cloud service in use
- SOC 2 and equivalent reports are not reviewed for material exceptions
- Cloud configuration baselines are not benchmarked against CIS or vendor guidance
- Concentration risk across cloud providers is not assessed
- Cloud event logs are not ingested into the central monitoring platform
Assembled from the framework’s own control set, so this list is regenerated rather than written and stays current as the graph does. See the FFIEC IT Examination Handbook framework page.