FFIEC-01 | Information security program management | 0 |
FFIEC-02 | Board and management oversight | 0 |
FFIEC-03 | Risk appetite and tolerance for IT risk | 83 |
FFIEC-04 | Security policy framework | 0 |
FFIEC-05 | Roles and responsibilities definition | 147 |
FFIEC-06 | Network security and segmentation | 59 |
FFIEC-07 | Endpoint protection and detection | 17 |
FFIEC-08 | Application security controls | 57 |
FFIEC-09 | Encryption and key management | 123 |
FFIEC-10 | Secure configuration standards | 50 |
FFIEC-11 | Business continuity planning and testing | 63 |
FFIEC-12 | Disaster recovery procedures | 107 |
FFIEC-13 | Third-party dependency management | 0 |
FFIEC-14 | Critical service identification | 49 |
FFIEC-15 | Communication and escalation procedures | 13 |
FFIEC-16 | Due diligence and onboarding | 1 |
FFIEC-17 | Contractual security requirements | 0 |
FFIEC-18 | Ongoing monitoring and assessment | 83 |
FFIEC-19 | Concentration risk management | 0 |
FFIEC-20 | Exit strategy and transition planning | 83 |
FFIEC-21 | Incident detection and classification | 0 |
FFIEC-22 | Incident response and containment | 0 |
FFIEC-23 | Regulatory reporting requirements | 122 |
FFIEC-24 | Customer notification procedures | 122 |
FFIEC-25 | Post-incident review and improvement | 122 |
IS-II.A.1 | Board Oversight of Information Security | 0 |
IS-II.A.2 | Senior Management Responsibilities | 0 |
IS-II.B.1 | Information Security Culture | 0 |
IS-II.C.1 | Information Security Roles and Responsibilities | 2 |
IS-III.A.1 | Information Security Risk Management Framework | 0 |
IS-III.B.1 | Risk Identification | 2 |
IS-III.B.2 | Risk Measurement and Analysis | 0 |
IS-III.B.3 | Risk Mitigation Strategy | 0 |
IS-III.C.1 | Risk Monitoring and Reporting | 0 |
IS-III.D.1 | Information Security Strategy | 0 |
IS-IV.A.1 | Inventory and Classification of Information Assets | 0 |
IS-IV.A.2 | Data Flow Diagrams | 0 |
IS-IV.B.1 | Identity and Access Management Program | 0 |
IS-IV.B.2 | Authentication Controls | 0 |
IS-IV.B.3 | Privileged Access Management | 1 |
IS-IV.B.4 | Access Reviews and Recertification | 0 |
IS-IV.B.5 | Joiner Mover Leaver Process | 0 |
IS-IV.C.1 | Network Security Architecture | 0 |
IS-IV.C.2 | Firewall Configuration and Review | 0 |
IS-IV.C.3 | Wireless Network Security | 0 |
IS-IV.C.4 | Remote Access Security | 0 |
IS-IV.D.1 | Endpoint Security Controls | 0 |
IS-IV.D.2 | Mobile Device Management | 0 |
IS-IV.D.3 | Removable Media Controls | 0 |
IS-IV.E.1 | Secure Software Development Lifecycle | 0 |
IS-IV.E.2 | Application Security Testing | 0 |
IS-IV.E.3 | Application Change Management | 0 |
IS-IV.F.1 | Encryption Standards and Key Management | 0 |
IS-IV.F.2 | Data in Transit Encryption | 0 |
IS-IV.F.3 | Data at Rest Encryption | 0 |
IS-IX.A.1 | Third Party Risk Management | 0 |
IS-IX.A.2 | Cloud Service Provider Oversight | 0 |
IS-V.A.1 | IT Operations Management | 0 |
IS-V.A.2 | Configuration Management | 2 |
IS-V.A.3 | Patch Management | 0 |
IS-V.B.1 | Vulnerability Management Program | 0 |
IS-V.B.2 | Penetration Testing | 0 |
IS-V.C.1 | Physical and Environmental Security | 1 |
IS-VI.A.1 | Security Logging Standards | 0 |
IS-VI.A.2 | Security Monitoring and SIEM | 0 |
IS-VI.A.3 | Threat Intelligence | 1 |
IS-VI.B.1 | User Behavior Analytics | 0 |
IS-VII.A.1 | Incident Response Program | 0 |
IS-VII.A.2 | Incident Detection and Classification | 0 |
IS-VII.A.3 | Incident Response Testing and Exercises | 0 |
IS-VII.A.4 | Notification of Customers Regulators and Law Enforcement | 0 |
IS-VIII.A.1 | Business Continuity Integration | 0 |
IS-VIII.A.2 | Backup and Recovery | 0 |
IS-X.A.1 | Security Awareness Training | 0 |
IS-X.B.1 | Independent Information Security Audit | 0 |
IS-X.B.2 | Cybersecurity Assessment and Maturity | 0 |
IS-XI.A.1 | Architecture and Operations Alignment | 0 |
IS-XI.A.2 | Management Booklet Governance Alignment | 0 |
AIO | Architecture, Infrastructure, and Operations booklet (June 2021) | 0 |
AIO-I | I ARCHITECTURE, INFRASTRUCTURE, AND (Architecture, Infrastructure, and Operations) | 0 |
AIO-II | II ARCHITECTURE, INFRASTRUCTURE, AND (Architecture, Infrastructure, and Operations) | 0 |
AIO-II.A | II.A Board and Senior Management Responsibilities (Architecture, Infrastructure, and Operations) | 0 |
AIO-II.A.1 | II.A.1 Strategic Planning (Architecture, Infrastructure, and Operations) | 0 |
AIO-II.A.2 | II.A.2 Enterprise Risk Management (Architecture, Infrastructure, and Operations) | 0 |
AIO-II.B | II.B Other Roles and Responsibilities (Architecture, Infrastructure, and Operations) | 0 |
AIO-II.B.1 | II.B.1 IT Management Responsibilities (Architecture, Infrastructure, and Operations) | 0 |
AIO-II.B.1(a) | II.B.1(a) Chief Architect (Architecture, Infrastructure, and Operations) | 0 |
AIO-II.B.1(b) | II.B.1(b) Chief Data Officer (Architecture, Infrastructure, and Operations) | 0 |
AIO-II.B.1(c) | II.B.1(c) IT Operations Management (Architecture, Infrastructure, and Operations) | 0 |
AIO-II.B.2 | II.B.2 IT Operations Personnel Responsibilities (Architecture, Infrastructure, and Operations) | 0 |
AIO-II.C | II.C Policies, Standards, and Procedures (Architecture, Infrastructure, and Operations) | 0 |
AIO-II.D | II.D Internal Audit, Independent Reviews, and (Architecture, Infrastructure, and Operations) | 0 |
AIO-II.E | II.E Communication (Architecture, Infrastructure, and Operations) | 0 |
AIO-II.F | II.F Board and Senior Management Reporting (Architecture, Infrastructure, and Operations) | 0 |
AIO-III | III COMMON AIO RISK MANAGEMENT TOPICS (Architecture, Infrastructure, and Operations) | 0 |
AIO-III.A | III.A Data Governance and Data Management (Architecture, Infrastructure, and Operations) | 0 |
AIO-III.A.1 | III.A.1 Data Identification and Classification (Architecture, Infrastructure, and Operations) | 0 |
AIO-III.A.2 | III.A.2 Database Management (Architecture, Infrastructure, and Operations) | 0 |
AIO-III.A.2(a) | III.A.2(a) Database Security (Architecture, Infrastructure, and Operations) | 0 |
AIO-III.A.3 | III.A.3 Non-Production Environments (Architecture, Infrastructure, and Operations) | 0 |
AIO-III.A.4 | III.A.4 Data Analytics (Architecture, Infrastructure, and Operations) | 0 |
AIO-III.B | III.B IT Asset Management (Architecture, Infrastructure, and Operations) | 0 |
AIO-III.B.1 | III.B.1 Technology Asset Inventory (Architecture, Infrastructure, and Operations) | 0 |
AIO-III.B.1(a) | III.B.1(a) Hardware Inventory (Architecture, Infrastructure, and Operations) | 0 |
AIO-III.B.1(b) | III.B.1(b) Software Inventory (Architecture, Infrastructure, and Operations) | 0 |
AIO-III.B.2 | III.B.2 IT Asset End-of-Life (Architecture, Infrastructure, and Operations) | 0 |
AIO-III.B.3 | III.B.3 Shadow IT (Architecture, Infrastructure, and Operations) | 0 |
AIO-III.C | III.C IT and Business Environment Representations (Architecture, Infrastructure, and Operations) | 0 |
AIO-III.C.1 | III.C.1 Network Diagrams (Architecture, Infrastructure, and Operations) | 0 |
AIO-III.C.2 | III.C.2 Data Flow Diagrams (Architecture, Infrastructure, and Operations) | 0 |
AIO-III.C.3 | III.C.3 Business Process Diagrams and Narratives (Architecture, Infrastructure, and Operations) | 0 |
AIO-III.D | III.D Managing Change in AIO (Architecture, Infrastructure, and Operations) | 0 |
AIO-III.D.1 | III.D.1 Change Management (Architecture, Infrastructure, and Operations) | 0 |
AIO-III.D.2 | III.D.2 Transitioning From Strategic Change Management (Architecture, Infrastructure, and Operations) | 0 |
AIO-III.E | III.E Oversight of Third-Party Service Providers (Architecture, Infrastructure, and Operations) | 0 |
AIO-III.F | III.F Resilience (Architecture, Infrastructure, and Operations) | 0 |
AIO-III.G | III.G Remote Access (Architecture, Infrastructure, and Operations) | 0 |
AIO-III.H | III.H Personally Owned Devices (Architecture, Infrastructure, and Operations) | 0 |
AIO-III.I | III.I File Exchange (Architecture, Infrastructure, and Operations) | 0 |
AIO-IV | IV ARCHITECTURE (Architecture, Infrastructure, and Operations) | 0 |
AIO-IV.A | IV.A Architecture Plan (Architecture, Infrastructure, and Operations) | 0 |
AIO-IV.B | IV.B Design Objectives (Architecture, Infrastructure, and Operations) | 0 |
AIO-IV.C | IV.C IT Architecture Design (Architecture, Infrastructure, and Operations) | 0 |
AIO-IV.D | IV.D Enterprise Architecture (Architecture, Infrastructure, and Operations) | 0 |
AIO-V | V INFRASTRUCTURE (Architecture, Infrastructure, and Operations) | 0 |
AIO-V.A | V.A Hardware (Architecture, Infrastructure, and Operations) | 0 |
AIO-V.B | V.B Network and Telecommunications (Architecture, Infrastructure, and Operations) | 0 |
AIO-V.B.1 | V.B.1 Network (Architecture, Infrastructure, and Operations) | 0 |
AIO-V.B.2 | V.B.2 Telecommunications (Architecture, Infrastructure, and Operations) | 0 |
AIO-V.B.2(a) | V.B.2(a) Voice Communications (Architecture, Infrastructure, and Operations) | 0 |
AIO-V.B.2(b) | V.B.2(b) Data Communications (Architecture, Infrastructure, and Operations) | 0 |
AIO-V.C | V.C Software (Architecture, Infrastructure, and Operations) | 0 |
AIO-V.C.1 | V.C.1 Internally and Externally Developed Software (Architecture, Infrastructure, and Operations) | 0 |
AIO-V.C.2 | V.C.2 Software Types (Architecture, Infrastructure, and Operations) | 0 |
AIO-V.C.2(a) | V.C.2(a) Open Source Software (Architecture, Infrastructure, and Operations) | 0 |
AIO-V.C.2(b) | V.C.2(b) Mainframe Security Software (Architecture, Infrastructure, and Operations) | 0 |
AIO-V.C.2(c) | V.C.2(c) Application Programming Interfaces (Architecture, Infrastructure, and Operations) | 0 |
AIO-V.C.3 | V.C.3 Software Hosting (Architecture, Infrastructure, and Operations) | 0 |
AIO-V.D | V.D Environmental Controls (Architecture, Infrastructure, and Operations) | 0 |
AIO-V.D.1 | V.D.1 Heating, Ventilation, and Air Conditioning (Architecture, Infrastructure, and Operations) | 0 |
AIO-V.D.2 | V.D.2 Smoke and Fire (Architecture, Infrastructure, and Operations) | 0 |
AIO-V.D.3 | V.D.3 Water (Architecture, Infrastructure, and Operations) | 0 |
AIO-V.D.4 | V.D.4 Power (Architecture, Infrastructure, and Operations) | 0 |
AIO-V.E | V.E Physical Access Controls (Architecture, Infrastructure, and Operations) | 0 |
AIO-VI | VI OPERATIONS (Architecture, Infrastructure, and Operations) | 0 |
AIO-VI.A | VI.A Operational Controls (Architecture, Infrastructure, and Operations) | 0 |
AIO-VI.A.1 | VI.A.1 Operating Centers (Architecture, Infrastructure, and Operations) | 0 |
AIO-VI.A.2 | VI.A.2 Authorization Boundary (Architecture, Infrastructure, and Operations) | 0 |
AIO-VI.A.3 | VI.A.3 Identity and Access Management (Architecture, Infrastructure, and Operations) | 0 |
AIO-VI.A.4 | VI.A.4 Personnel Controls (Architecture, Infrastructure, and Operations) | 0 |
AIO-VI.B | VI.B IT Operational Processes (Architecture, Infrastructure, and Operations) | 0 |
AIO-VI.B.1 | VI.B.1 Maintenance (Architecture, Infrastructure, and Operations) | 0 |
AIO-VI.B.2 | VI.B.2 Configuration Management (Architecture, Infrastructure, and Operations) | 0 |
AIO-VI.B.3 | VI.B.3 Vulnerability and Patch Management (Architecture, Infrastructure, and Operations) | 0 |
AIO-VI.B.3(a) | VI.B.3(a) Vulnerability Management (Architecture, Infrastructure, and Operations) | 0 |
AIO-VI.B.3(b) | VI.B.3(b) Patch Management (Architecture, Infrastructure, and Operations) | 0 |
AIO-VI.B.4 | VI.B.4 Backup and Replication Processes (Architecture, Infrastructure, and Operations) | 0 |
AIO-VI.B.5 | VI.B.5 Scheduling (Architecture, Infrastructure, and Operations) | 0 |
AIO-VI.B.6 | VI.B.6 Capacity Management (Architecture, Infrastructure, and Operations) | 0 |
AIO-VI.B.7 | VI.B.7 Log Management (Architecture, Infrastructure, and Operations) | 0 |
AIO-VI.B.8 | VI.B.8 Disposal of Data and Media (Architecture, Infrastructure, and Operations) | 0 |
AIO-VI.C | VI.C Service and Support Processes (Architecture, Infrastructure, and Operations) | 0 |
AIO-VI.C.1 | VI.C.1 Service Management (Architecture, Infrastructure, and Operations) | 0 |
AIO-VI.C.2 | VI.C.2 Operational Support (Architecture, Infrastructure, and Operations) | 0 |
AIO-VI.C.3 | VI.C.3 IT Support (Architecture, Infrastructure, and Operations) | 0 |
AIO-VI.C.4 | VI.C.4 Event, Incident, and Problem Management (Architecture, Infrastructure, and Operations) | 0 |
AIO-VI.D | VI.D Ongoing Monitoring and Evaluation Processes (Architecture, Infrastructure, and Operations) | 0 |
AIO-VI.D.1 | VI.D.1 Monitoring and Reporting (Architecture, Infrastructure, and Operations) | 0 |
AIO-VI.D.2 | VI.D.2 IT and Operations Key Performance Indicators (Architecture, Infrastructure, and Operations) | 0 |
AIO-VI.D.3 | VI.D.3 Control Self-Assessments (Architecture, Infrastructure, and Operations) | 0 |
AIO-VI.D.4 | VI.D.4 Continuous Improvement (Architecture, Infrastructure, and Operations) | 0 |
AIO-VII | VII EVOLVING TECHNOLOGIES (Architecture, Infrastructure, and Operations) | 0 |
AIO-VII.A | VII.A Cloud Computing (Architecture, Infrastructure, and Operations) | 0 |
AIO-VII.A.1 | VII.A.1 Essential Characteristics (Architecture, Infrastructure, and Operations) | 0 |
AIO-VII.A.2 | VII.A.2 Cloud Service Models (Architecture, Infrastructure, and Operations) | 0 |
AIO-VII.A.3 | VII.A.3 Cloud Deployment Models (Architecture, Infrastructure, and Operations) | 0 |
AIO-VII.A.4 | VII.A.4 Shared Responsibilities (Architecture, Infrastructure, and Operations) | 0 |
AIO-VII.A.5 | VII.A.5 Risk Considerations for Cloud Computing (Architecture, Infrastructure, and Operations) | 0 |
AIO-VII.A.5(a) | VII.A.5(a) Access Control Considerations (Architecture, Infrastructure, and Operations) | 0 |
AIO-VII.B | VII.B Zero Trust Architecture (Architecture, Infrastructure, and Operations) | 0 |
AIO-VII.C | VII.C Microservices (Architecture, Infrastructure, and Operations) | 0 |
AIO-VII.D | VII.D Artificial Intelligence and Machine Learning (Architecture, Infrastructure, and Operations) | 0 |
AIO-VII.E | VII.E Internet of Things (Architecture, Infrastructure, and Operations) | 0 |
AUD | Audit booklet (April 2012) | 0 |
AUD-01 | IT Audit Roles and Responsibilities (Audit) | 0 |
AUD-02 | Board of Directors and Senior Management (Audit) | 0 |
AUD-03 | Audit Management (Audit) | 0 |
AUD-04 | Internal IT Audit Staff (Audit) | 0 |
AUD-05 | Operating Management (Audit) | 0 |
AUD-06 | External Auditors (Audit) | 0 |
AUD-07 | Independence and Staffing of Internal IT Audit (Audit) | 0 |
AUD-08 | Independence (Audit) | 0 |
AUD-09 | Staffing (Audit) | 0 |
AUD-10 | Internal Audit Program (Audit) | 0 |
AUD-11 | Risk Assessment and Risk-Based Auditing (Audit) | 0 |
AUD-12 | Program Elements (Audit) | 0 |
AUD-13 | Risk Scoring System (Audit) | 0 |
AUD-14 | Audit Participation in Application Development, Acquisition, Conversions, and Testing (Audit) | 0 |
AUD-15 | Outsourcing Internal IT Audit (Audit) | 0 |
AUD-16 | Independence of the External Auditor Providing Internal Audit Services (Audit) | 0 |
AUD-17 | Examples of Arrangements (Audit) | 0 |
AUD-18 | Third-Party Reviews of Technology Service Providers (Audit) | 0 |
BCM | Business Continuity Management booklet (November 2019) | 0 |
BCM-I | I Business Continuity Management (Business Continuity Management) | 0 |
BCM-II | II Business Continuity Management Governance (Business Continuity Management) | 0 |
BCM-II.A | II.A Board and Senior Management Responsibilities (Business Continuity Management) | 0 |
BCM-II.B | II.B Audit (Business Continuity Management) | 0 |
BCM-III | III Risk Management (Business Continuity Management) | 0 |
BCM-III.A | III.A Business Impact Analysis (Business Continuity Management) | 0 |
BCM-III.B | III.B Risk Assessment (Business Continuity Management) | 0 |
BCM-IV | IV Business Continuity Strategies (Business Continuity Management) | 0 |
BCM-IV.A | IV.A Resilience (Business Continuity Management) | 0 |
BCM-IV.B | IV.B Communications (Business Continuity Management) | 0 |
BCM-IX | IX Board Reporting (Business Continuity Management) | 0 |
BCM-V | V Business Continuity Plan (Business Continuity Management) | 0 |
BCM-V.A | V.A Event Management (Business Continuity Management) | 0 |
BCM-V.B | V.B Continuity and Recovery (Business Continuity Management) | 0 |
BCM-V.C | V.C Facilities and Infrastructure (Business Continuity Management) | 0 |
BCM-V.D | V.D Payment Systems (Business Continuity Management) | 0 |
BCM-V.E | V.E Liquidity Considerations (Business Continuity Management) | 0 |
BCM-V.F | V.F Other Components (Business Continuity Management) | 0 |
BCM-VI | VI Training (Business Continuity Management) | 0 |
BCM-VII | VII Exercises and Tests (Business Continuity Management) | 0 |
BCM-VII.A | VII.A Exercise and Test Program (Business Continuity Management) | 0 |
BCM-VII.B | VII.B Exercise and Test Policy (Business Continuity Management) | 0 |
BCM-VII.C | VII.C Exercise and Test Strategies (Business Continuity Management) | 0 |
BCM-VII.D | VII.D Exercise and Test Objectives (Business Continuity Management) | 0 |
BCM-VII.E | VII.E Exercise and Test Plans (Business Continuity Management) | 0 |
BCM-VII.F | VII.F Exercise and Test Scenarios (Business Continuity Management) | 0 |
BCM-VII.G | VII.G Exercise and Test Methods (Business Continuity Management) | 0 |
BCM-VII.H | VII.H Industry Exercises and Resilience (Business Continuity Management) | 0 |
BCM-VII.I | VII.I Third-Party Service Provider Testing (Business Continuity Management) | 0 |
BCM-VII.J | VII.J Testing for Core and Significant Firms (Business Continuity Management) | 0 |
BCM-VII.K | VII.K Post-Exercise and Post-Test Actions (Business Continuity Management) | 0 |
BCM-VIII | VIII Maintenance and Improvement (Business Continuity Management) | 0 |
DAM | Development, Acquisition, and Maintenance booklet (August 2024) | 0 |
DAM-I | I OVERVIEW OF DEVELOPMENT, ACQUISITION, AND (Development, Acquisition, and Maintenance) | 0 |
DAM-II | II GOVERNANCE OF DEVELOPMENT, ACQUISITION, AND (Development, Acquisition, and Maintenance) | 0 |
DAM-II.A | II.A Policies, Standards, and Procedures (Development, Acquisition, and Maintenance) | 0 |
DAM-II.B | II.B Roles and Responsibilities (Development, Acquisition, and Maintenance) | 0 |
DAM-II.B.1 | II.B.1 Board, Senior Management, and Other Common Roles (Development, Acquisition, and Maintenance) | 0 |
DAM-II.B.2 | II.B.2 IT Project Management Roles (Development, Acquisition, and Maintenance) | 0 |
DAM-II.B.3 | II.B.3 Development Roles (Development, Acquisition, and Maintenance) | 0 |
DAM-II.B.4 | II.B.4 Acquisition Roles (Development, Acquisition, and Maintenance) | 0 |
DAM-II.B.5 | II.B.5 Maintenance Roles (Development, Acquisition, and Maintenance) | 0 |
DAM-II.B.6 | II.B.6 Other Common Development, Acquisition, and (Development, Acquisition, and Maintenance) | 0 |
DAM-II.B.7 | II.B.7 Supply Chain Roles (Development, Acquisition, and Maintenance) | 0 |
DAM-II.B.8 | II.B.8 Other Support Functions (Development, Acquisition, and Maintenance) | 0 |
DAM-II.B.9 | II.B.9 Audit’s Role (Development, Acquisition, and Maintenance) | 0 |
DAM-III | III RISK MANAGEMENT OF DEVELOPMENT, ACQUISITION, (Development, Acquisition, and Maintenance) | 0 |
DAM-III.A | III.A Risk Identification (Development, Acquisition, and Maintenance) | 0 |
DAM-III.B | III.B Risk Measurement (Development, Acquisition, and Maintenance) | 0 |
DAM-III.C | III.C Risk Monitoring and Reporting (Development, Acquisition, and Maintenance) | 0 |
DAM-III.D | III.D Controlling or Mitigating Risk (Development, Acquisition, and Maintenance) | 0 |
DAM-IV | IV COMMON DEVELOPMENT, ACQUISITION, AND (Development, Acquisition, and Maintenance) | 0 |
DAM-IV.A | IV.A Open-Source (Development, Acquisition, and Maintenance) | 0 |
DAM-IV.B | IV.B Commercial-off-the-Shelf (Development, Acquisition, and Maintenance) | 0 |
DAM-IV.C | IV.C Licenses, Agreements, and Copyright Protection (Development, Acquisition, and Maintenance) | 0 |
DAM-IV.C.1 | IV.C.1 Software Licenses (Development, Acquisition, and Maintenance) | 0 |
DAM-IV.C.1(a) | IV.C.1(a) Free and Open-Source Software Licenses (Development, Acquisition, and Maintenance) | 0 |
DAM-IV.C.1(b) | IV.C.1(b) Proprietary Software Licenses (Development, Acquisition, and Maintenance) | 0 |
DAM-IV.C.2 | IV.C.2 Hardware Licenses (Development, Acquisition, and Maintenance) | 0 |
DAM-IV.C.3 | IV.C.3 Copyright Protection (Development, Acquisition, and Maintenance) | 0 |
DAM-IV.D | IV.D Secure Development (Development, Acquisition, and Maintenance) | 0 |
DAM-IV.E | IV.E Data (Development, Acquisition, and Maintenance) | 0 |
DAM-IV.F | IV.F Secure Operating Environments (Development, Acquisition, and Maintenance) | 0 |
DAM-IV.G | IV.G Microservices (Development, Acquisition, and Maintenance) | 0 |
DAM-IV.H | IV.H Containers (Development, Acquisition, and Maintenance) | 0 |
DAM-IV.I | IV.I Application Programming Interfaces (Development, Acquisition, and Maintenance) | 0 |
DAM-IV.I.1 | IV.I.1 API Gateway (Development, Acquisition, and Maintenance) | 0 |
DAM-IV.I.2 | IV.I.2 API Risk Mitigation (Development, Acquisition, and Maintenance) | 0 |
DAM-IV.J | IV.J Methodologies (Development, Acquisition, and Maintenance) | 0 |
DAM-IV.J.1 | IV.J.1 Waterfall (Development, Acquisition, and Maintenance) | 0 |
DAM-IV.J.2 | IV.J.2 Agile (Development, Acquisition, and Maintenance) | 0 |
DAM-IV.K | IV.K Quality Management (Development, Acquisition, and Maintenance) | 0 |
DAM-IV.L | IV.L Documentation Standards (Development, Acquisition, and Maintenance) | 0 |
DAM-IV.M | IV.M Post-Implementation Review (Development, Acquisition, and Maintenance) | 0 |
DAM-IV.N | IV.N IT Project Management (Development, Acquisition, and Maintenance) | 0 |
DAM-IV.N.1 | IV.N.1 IT Project Phases (Development, Acquisition, and Maintenance) | 0 |
DAM-IV.N.1(a) | IV.N.1(a) Initiation (Development, Acquisition, and Maintenance) | 0 |
DAM-IV.N.1(b) | IV.N.1(b) Planning (Development, Acquisition, and Maintenance) | 0 |
DAM-IV.N.1(c) | IV.N.1(c) Execution (Development, Acquisition, and Maintenance) | 0 |
DAM-IV.N.1(d) | IV.N.1(d) Closeout (Development, Acquisition, and Maintenance) | 0 |
DAM-IV.N.2 | IV.N.2 Monitoring and Controlling (Development, Acquisition, and Maintenance) | 0 |
DAM-IV.N.3 | IV.N.3 IT Project Documentation (Development, Acquisition, and Maintenance) | 0 |
DAM-IV.N.3(a) | IV.N.3(a) IT Project Request (Development, Acquisition, and Maintenance) | 0 |
DAM-IV.N.3(b) | IV.N.3(b) Business Case (Development, Acquisition, and Maintenance) | 0 |
DAM-IV.N.3(c) | IV.N.3(c) Feasibility Study (Development, Acquisition, and Maintenance) | 0 |
DAM-IV.N.3(d) | IV.N.3(d) IT Project Plans (Development, Acquisition, and Maintenance) | 0 |
DAM-IV.N.3(e) | IV.N.3(e) Closeout Documentation (Development, Acquisition, and Maintenance) | 0 |
DAM-IV.O | IV.O System Development Life Cycle (Development, Acquisition, and Maintenance) | 0 |
DAM-IV.O.1 | IV.O.1 SDLC Phases (Development, Acquisition, and Maintenance) | 0 |
DAM-IV.O.1(a) | IV.O.1(a) Initiation (Development, Acquisition, and Maintenance) | 0 |
DAM-IV.O.1(b) | IV.O.1(b) Development or Acquisition (Development, Acquisition, and Maintenance) | 0 |
DAM-IV.O.1(c) | IV.O.1(c) Implementation and Assessment (Development, Acquisition, and Maintenance) | 0 |
DAM-IV.O.1(d) | IV.O.1(d) Operations and Maintenance (Development, Acquisition, and Maintenance) | 0 |
DAM-IV.O.1(e) | IV.O.1(e) Sunset and Disposal (Development, Acquisition, and Maintenance) | 0 |
DAM-IV.P | IV.P Third-Party Relationship Risk Management (Development, Acquisition, and Maintenance) | 0 |
DAM-IV.P.1 | IV.P.1 Planning (Development, Acquisition, and Maintenance) | 0 |
DAM-IV.P.2 | IV.P.2 Due Diligence and Third-Party Selection (Development, Acquisition, and Maintenance) | 0 |
DAM-IV.P.3 | IV.P.3 Contract Negotiation (Development, Acquisition, and Maintenance) | 0 |
DAM-IV.Q | IV.Q Supply Chain Considerations (Development, Acquisition, and Maintenance) | 0 |
DAM-IV.Q.1 | IV.Q.1 Supply Chain Risk Management (Development, Acquisition, and Maintenance) | 0 |
DAM-IV.Q.2 | IV.Q.2 Software Bill of Material (Development, Acquisition, and Maintenance) | 0 |
DAM-IV.Q.3 | IV.Q.3 Enterprise Risk Management and Supply Chain Risks (Development, Acquisition, and Maintenance) | 0 |
DAM-V | V DEVELOPMENT (Development, Acquisition, and Maintenance) | 0 |
DAM-V.A | V.A Development Standards and Controls (Development, Acquisition, and Maintenance) | 0 |
DAM-V.B | V.B Testing (Development, Acquisition, and Maintenance) | 0 |
DAM-V.C | V.C DevOps and DevSecOps (Development, Acquisition, and Maintenance) | 0 |
DAM-V.C.1 | V.C.1 DevOps (Development, Acquisition, and Maintenance) | 0 |
DAM-V.C.2 | V.C.2 DevSecOps (Development, Acquisition, and Maintenance) | 0 |
DAM-V.D | V.D Functional Development Types (Development, Acquisition, and Maintenance) | 0 |
DAM-V.D.1 | V.D.1 Model Development (Development, Acquisition, and Maintenance) | 0 |
DAM-V.D.2 | V.D.2 Database Development (Development, Acquisition, and Maintenance) | 0 |
DAM-VI | VI ACQUISITION (Development, Acquisition, and Maintenance) | 0 |
DAM-VI.A | VI.A Acquisition Policies, Standards, and Procedures (Development, Acquisition, and Maintenance) | 0 |
DAM-VI.B | VI.B Acquisition Projects (Development, Acquisition, and Maintenance) | 0 |
DAM-VI.C | VI.C Solicitation (Development, Acquisition, and Maintenance) | 0 |
DAM-VI.D | VI.D Evaluation (Development, Acquisition, and Maintenance) | 0 |
DAM-VI.E | VI.E Contracts and Other Agreements (Development, Acquisition, and Maintenance) | 0 |
DAM-VI.E.1 | VI.E.1 Statement of Work (Development, Acquisition, and Maintenance) | 0 |
DAM-VI.E.2 | VI.E.2 Master Services Agreement (Development, Acquisition, and Maintenance) | 0 |
DAM-VI.E.3 | VI.E.3 Service Level Agreement (Development, Acquisition, and Maintenance) | 0 |
DAM-VI.E.4 | VI.E.4 Contracts (Development, Acquisition, and Maintenance) | 0 |
DAM-VI.E.5 | VI.E.5 Escrowed Source Code Agreements and Documentation (Development, Acquisition, and Maintenance) | 0 |
DAM-VI.E.6 | VI.E.6 Exit Strategy (Development, Acquisition, and Maintenance) | 0 |
DAM-VII | VII MAINTENANCE (Development, Acquisition, and Maintenance) | 0 |
DAM-VII.A | VII.A Preventive Maintenance (Development, Acquisition, and Maintenance) | 0 |
DAM-VII.B | VII.B Change Management (Development, Acquisition, and Maintenance) | 0 |
DAM-VII.B.1 | VII.B.1 Implementing Changes (Development, Acquisition, and Maintenance) | 0 |
DAM-VII.B.2 | VII.B.2 Additional Control Considerations in Change Management (Development, Acquisition, and Maintenance) | 0 |
DAM-VII.B.2(a) | VII.B.2(a) Data Controls in the Testing Environment (Development, Acquisition, and Maintenance) | 0 |
DAM-VII.B.2(b) | VII.B.2(b) Library Controls (Development, Acquisition, and Maintenance) | 0 |
DAM-VII.B.2(c) | VII.B.2(c) Code Repository Controls (Development, Acquisition, and Maintenance) | 0 |
DAM-VII.B.3 | VII.B.3 Change Types (Development, Acquisition, and Maintenance) | 0 |
DAM-VII.B.3(a) | VII.B.3(a) Routine Modifications (Development, Acquisition, and Maintenance) | 0 |
DAM-VII.B.3(b) | VII.B.3(b) Major Modifications (Development, Acquisition, and Maintenance) | 0 |
DAM-VII.B.3(c) | VII.B.3(c) Emergency Modifications (Development, Acquisition, and Maintenance) | 0 |
DAM-VII.B.4 | VII.B.4 Change Management Documentation (Development, Acquisition, and Maintenance) | 0 |
DAM-VII.B.4(a) | VII.B.4(a) Change Request Form (Development, Acquisition, and Maintenance) | 0 |
DAM-VII.B.4(b) | VII.B.4(b) Impact Analysis (Development, Acquisition, and Maintenance) | 0 |
DAM-VII.B.4(c) | VII.B.4(c) Rollback or Back-Out Plan (Development, Acquisition, and Maintenance) | 0 |
DAM-VII.C | VII.C End-of-Life (Development, Acquisition, and Maintenance) | 0 |
DAM-VII.D | VII.D Termination and Disposal (Development, Acquisition, and Maintenance) | 0 |
DAM-VII.E | VII.E Maintenance Documentation (Development, Acquisition, and Maintenance) | 0 |
EXAM | Appendix A examination procedures, the URSIT rating and the relationship between the booklets | 0 |
HANDBOOK | The FFIEC IT Examination Handbook: the ten booklets, their editions, and what is held | 0 |
IS | Information Security booklet (September 2016) | 0 |
IS-I | I Governance of the Information Security Program (Information Security) | 0 |
IS-I.A | I.A Security Culture (Information Security) | 0 |
IS-I.B | I.B Responsibility and Accountability (Information Security) | 0 |
IS-I.C | I.C Resources (Information Security) | 0 |
IS-II | II Information Security Program Management (Information Security) | 0 |
IS-II.A | II.A Risk Identification (Information Security) | 0 |
IS-II.A.1 | II.A.1 Threats (Information Security) | 0 |
IS-II.A.2 | II.A.2 Vulnerabilities (Information Security) | 0 |
IS-II.A.3 | II.A.3 Supervision of Cybersecurity Risk and Resources for (Information Security) | 0 |
IS-II.A.3(a) | II.A.3(a) Supervision of Cybersecurity Risk (Information Security) | 0 |
IS-II.A.3(b) | II.A.3(b) Resources for Cybersecurity Preparedness (Information Security) | 0 |
IS-II.B | II.B Risk Measurement (Information Security) | 0 |
IS-II.C | II.C Risk Mitigation (Information Security) | 0 |
IS-II.C.1 | II.C.1 Policies, Standards, and Procedures (Information Security) | 0 |
IS-II.C.10 | II.C.10 Change Management Within the IT Environment (Information Security) | 0 |
IS-II.C.10(a) | II.C.10(a) Configuration Management (Information Security) | 0 |
IS-II.C.10(b) | II.C.10(b) Hardening (Information Security) | 0 |
IS-II.C.10(c) | II.C.10(c) Standard Builds (Information Security) | 0 |
IS-II.C.10(d) | II.C.10(d) Patch Management (Information Security) | 0 |
IS-II.C.11 | II.C.11 End-of-Life Management (Information Security) | 0 |
IS-II.C.12 | II.C.12 Malware Mitigation (Information Security) | 0 |
IS-II.C.13 | II.C.13 Control of Information (Information Security) | 0 |
IS-II.C.13(a) | II.C.13(a) Storage (Information Security) | 0 |
IS-II.C.13(b) | II.C.13(b) Electronic Transmission of Information (Information Security) | 0 |
IS-II.C.13(c) | II.C.13(c) Disposal of Information (Information Security) | 0 |
IS-II.C.13(d) | II.C.13(d) Transit of Physical Media (Information Security) | 0 |
IS-II.C.13(e) | II.C.13(e) Rogue or Shadow IT (Information Security) | 0 |
IS-II.C.14 | II.C.14 Supply Chain (Information Security) | 0 |
IS-II.C.15 | II.C.15 Logical Security (Information Security) | 0 |
IS-II.C.15(a) | II.C.15(a) Operating System Access (Information Security) | 0 |
IS-II.C.15(b) | II.C.15(b) Application Access (Information Security) | 0 |
IS-II.C.15(c) | II.C.15(c) Remote Access (Information Security) | 0 |
IS-II.C.15(d) | II.C.15(d) Use of Remote Devices (Information Security) | 0 |
IS-II.C.16 | II.C.16 Customer Remote Access to Financial Services (Information Security) | 0 |
IS-II.C.16(a) | II.C.16(a) Customer Awareness (Information Security) | 0 |
IS-II.C.17 | II.C.17 Application Security (Information Security) | 0 |
IS-II.C.18 | II.C.18 Database Security (Information Security) | 0 |
IS-II.C.19 | II.C.19 Encryption (Information Security) | 0 |
IS-II.C.2 | II.C.2 Technology Design (Information Security) | 0 |
IS-II.C.20 | II.C.20 Oversight of Third-Party Service Providers (Information Security) | 0 |
IS-II.C.20(a) | II.C.20(a) Outsourced Cloud Computing (Information Security) | 0 |
IS-II.C.20(b) | II.C.20(b) Managed Security Service Providers (Information Security) | 0 |
IS-II.C.21 | II.C.21 Business Continuity Considerations (Information Security) | 0 |
IS-II.C.22 | II.C.22 Log Management (Information Security) | 0 |
IS-II.C.3 | II.C.3 Control Types (Information Security) | 0 |
IS-II.C.4 | II.C.4 Control Implementation (Information Security) | 0 |
IS-II.C.5 | II.C.5 Inventory and Classification of Assets (Information Security) | 0 |
IS-II.C.6 | II.C.6 Mitigating Interconnectivity Risk (Information Security) | 0 |
IS-II.C.7 | II.C.7 User Security Controls (Information Security) | 0 |
IS-II.C.7(a) | II.C.7(a) Security Screening in Hiring Practices (Information Security) | 0 |
IS-II.C.7(b) | II.C.7(b) User Access Program (Information Security) | 0 |
IS-II.C.7(c) | II.C.7(c) Segregation of Duties (Information Security) | 0 |