Thread Options
|
Tools
|
#128214 - 11/04/03 04:56 PM
Basic Security.....They Just Don't Get It
|
Anonymous
Unregistered
|
I am so frustrated that I can't answer this question when I know its prudent business practice, but I need more narrative than that.
I am recommending that the bank I work for change the combinations on its vaults and ATMs since they have not been changed in over 4 years. Key personnel have left in that time, including a President and Cashier, among others. Knowing this managment (I am preparing a draft report not yet presented), they would say their alarm systems would take care of this need. I keep reading in audit literature over the many years that combinations need changing when key personnel leave.
Help!
|
Return to Top
|
|
|
|
#128215 - 11/04/03 05:10 PM
Re: Basic Security.....They Just Don't Get It
|
Platinum Poster
Joined: Apr 2003
Posts: 672
New England
|
You are, IMHO, right on the money with this request. It is part of the process when key personnel leave to change combo's, entry codes, and other security based procedures based on the personnel's access and usage rights. It should be done right away! The alarm system won't help if the whole system is flawed.
_________________________
May you be in Heaven a half hour before the Devil knows you're gone!!
|
Return to Top
|
|
|
|
#128216 - 11/04/03 06:40 PM
Re: Basic Security.....They Just Don't Get It
|
Platinum Poster
Joined: Jan 2003
Posts: 921
Down South, USA
|
It's a no-brainer, why would they not change the codes?
I would have said that, like computer passwords, they should be changed at least every ninety days, and whenever anybody who knows the codes leaves even the department/ branch (as they no longer have a need to know), and much more so if they leave the bank.
_________________________
This is my opinion; it is not legal advice, nor the view of my employer, and it may change tomorrow.
|
Return to Top
|
|
|
|
#128217 - 11/04/03 06:49 PM
Re: Basic Security.....They Just Don't Get It
|
100 Club
Joined: Sep 2003
Posts: 196
I have fallen down the rabbit ...
|
Definately you are not nuts! In a recent internal audit review- one branch was written up for failure to change ATM combo's. Your regulators should help your case - give them a call- they will assist- maybe an audit finding will wake them up? But that is what you are trying to keep them from....
_________________________
Some days, it is all a mystery to me.
|
Return to Top
|
|
|
|
#128218 - 11/04/03 08:28 PM
Re: Basic Security.....They Just Don't Get It
|
Anonymous
Unregistered
|
Here's another one of similar magnitude of ????? Combinations to the vault are on paper and stored in the Cashiers brief case for one facility. A second facility its stored on paper in the top drawer to the branch managers desk. Again, accept my appologies for asking such silly no-brainer questions, but I'm dealing with managment that will think there's nothing wrong with that. So....other than making a pudent business descision reqarding proper safekeeping, what can I recommend regarding procedures over the storage of combinations on paper?
Hope these two posts have made you day. Should be safed in the BOL Hall of Fame.
Thank you.
|
Return to Top
|
|
|
|
#128220 - 11/04/03 09:03 PM
Re: Basic Security.....They Just Don't Get It
|
Platinum Poster
Joined: Apr 2003
Posts: 672
New England
|
Um, WOW this is as you have stated "a no brainer". These codes should be maintained under dual control as Wild Turkey suggested. Other institutions even have divided codes to prevent such a complete security nightmare. If both codes need to be maintained together for some unknown reason(other than because it's easier that way ), they should, for the code holders sake if nothing else, be maintained in dual control(I wouldn't want to hold a complete combo with no control in place ).
_________________________
May you be in Heaven a half hour before the Devil knows you're gone!!
|
Return to Top
|
|
|
|
#128222 - 11/04/03 10:12 PM
Re: Basic Security.....They Just Don't Get It
|
Platinum Poster
Joined: Jan 2003
Posts: 921
Down South, USA
|
Depending on the location of the bank, if I wanted to raid the vault and had the codes to open the vault door I wouldn't necessarily care about the alarms, so long as I could get in, out, and away quickly enough. If you really still need something to persuade your management, ask them what they are planning to tell the insurance company if the vault is raided? ... Under the current procedures I wouldn't want to be in their shoes if the worst happened.
_________________________
This is my opinion; it is not legal advice, nor the view of my employer, and it may change tomorrow.
|
Return to Top
|
|
|
|
#128223 - 07/30/04 07:47 PM
Re: Basic Security.....They Just Don't Get It
|
Anonymous
Unregistered
|
If they won't change the combo, keys, codes reccomend they remove the locks as the locks are usless when you do not control the combo, keys, codes. The response should be "thats crazy" If they give this recomendation consideration you are lost!
|
Return to Top
|
|
|
|
#128224 - 07/30/04 09:39 PM
Re: Basic Security.....They Just Don't Get It
|
10K Club
Joined: Jun 2004
Posts: 19,961
Pulling people out of the ditc...
|
Do you have an internal auditor? Subtely suggest that they perform an audit on bank security, and have them write this up as a comment. Internal audits must be presented to your banks Audit Committee, which is comprised Board members and reprots to the Board of Directors. Next time the regulators come through and ask to review your Board minutes, I bet these get changed.
_________________________
Providing alternative truths since the invention of time
|
Return to Top
|
|
|
|
|
|