Thread Options
|
#557620 - 05/24/06 09:12 PM
Multi-Factor Authentication Prep Poll
|
10K Club
Joined: Oct 2000
Posts: 27,769
On the Net
|
If you have internet banking or telephone banking, the FFIEC multi-factor authentication guidance requires that you be ready by year end. This is an anonymous survey to check on preparations.
_________________________
AndyZ CRCM My opinions are not necessarily my employers. R+R-R=R+R Rules and Regs minus Relationships equals Resentment and Rebellion. John Maxwell
|
Return to Top
|
|
|
|
#557621 - 05/25/06 03:15 PM
Re: Multi-Factor Authentication Prep Poll
|
Power Poster
Joined: Dec 2000
Posts: 5,184
All over the map.
|
May I ask what others are actually using? I'm hoping for the grid card, or "bingo" card (as our provider calls it), but we may end up with the key token.
_________________________
On the road again.....I just can't wait to get on the road again.
|
Return to Top
|
|
|
|
#557624 - 05/30/06 11:58 PM
Re: Multi-Factor Authentication Prep Poll
|
Power Poster
Joined: Mar 2005
Posts: 6,298
San Diego, CA
|
we use Digital Insight as well and their method seems reasonable and less cumbersome than having to change your password every 30 days
_________________________
Dabbling in banking, law, accounting...the life of a trustee.
|
Return to Top
|
|
|
|
#557625 - 06/08/06 03:43 PM
Re: Multi-Factor Authentication Prep Poll
|
Power Poster
Joined: Mar 2004
Posts: 2,514
Up North
|
We will be using a challenge/response question. Has anyone actually done the risk assessment yet?
_________________________
Sometimes you have to burn a few bridges to keep the crazies from following you.
|
Return to Top
|
|
|
|
#557626 - 06/08/06 03:55 PM
Re: Multi-Factor Authentication Prep Poll
|
Power Poster
Joined: Dec 2000
Posts: 5,184
All over the map.
|
Don't you have to use any two of the following 3? 1. Something you know (password, pin#...) 2. Something you are (biometrics ~ fingerprint, retinal scan...) 3. Something you have (grid card, key token...) How can they use a password AND a pin number, and still be in compliance? 
_________________________
On the road again.....I just can't wait to get on the road again.
|
Return to Top
|
|
|
|
#557628 - 06/09/06 03:36 PM
Re: Multi-Factor Authentication Prep Poll
|
Power Poster
Joined: Dec 2000
Posts: 5,184
All over the map.
|
Gurus? Am I overthinking this, or do these companies need to re-read the FIL? 
_________________________
On the road again.....I just can't wait to get on the road again.
|
Return to Top
|
|
|
|
#557629 - 06/09/06 04:32 PM
Re: Multi-Factor Authentication Prep Poll
|
New Poster
Joined: Jun 2006
Posts: 7
|
Both of these seem to be what the customer knows?
|
Return to Top
|
|
|
|
#557630 - 06/09/06 09:03 PM
Re: Multi-Factor Authentication Prep Poll
|
Power Poster
Joined: Mar 2004
Posts: 2,514
Up North
|
Okay, you guys had me questioning our decision as a bank. To clarify, our added security is not simply a challenge question but will monitor IP addresses, transaction patterns and the like. So anyway, I went back and reread the FFIECs guidance and Deppfan, the three things you listed are basic factors in authentication methodologies. From what I can understand of what I read, the level of security you choose is risk based and, according to the Conclusion paragraph, "Where risk assessments indicate that the use of single-factor authentication is inadequate, financial institutions should implement multifactor authentication, layered security, or other controls reasonably calculated to mitigate those risks."
_________________________
Sometimes you have to burn a few bridges to keep the crazies from following you.
|
Return to Top
|
|
|
|
#557631 - 06/09/06 10:32 PM
Re: Multi-Factor Authentication Prep Poll
|
Power Poster
Joined: Mar 2005
Posts: 6,298
San Diego, CA
|
can something you have be a cookie installed on your computer after successfully answering 2 or three questions? if so, then somethgin you knwo if the password, and somethign you have is the cookie. right?
_________________________
Dabbling in banking, law, accounting...the life of a trustee.
|
Return to Top
|
|
|
|
#557632 - 06/12/06 03:04 PM
Re: Multi-Factor Authentication Prep Poll
|
New Poster
Joined: Jun 2006
Posts: 4
Kansas
|
My question...exactly what does the FFIEC Guidance apply too? I am hearing (and reading in your poll) that more than just Internet Access should be considered. How have others interpreted this guidance (does it apply to telephone banking-whether automated or call center)? Thanks in advance!!
|
Return to Top
|
|
|
|
#557633 - 06/12/06 06:58 PM
Re: Multi-Factor Authentication Prep Poll
|
100 Club
Joined: Sep 2005
Posts: 115
|
SarahH - just remember that regulators consider transactional websites to be high risk.
|
Return to Top
|
|
|
|
#557634 - 06/12/06 07:23 PM
Re: Multi-Factor Authentication Prep Poll
|
Power Poster
Joined: Mar 2004
Posts: 2,514
Up North
|
Thanks, I understand that. We actually have an exam next month so I will let you all know if they find our risk assessment and solution acceptable. According to our lead examiner they do not have a lot of guidance themselves yet so it should be interesting.
So then what I got from the guidance is that the reason we do the risk assessment is to determine whether or not single factor authentication is still a viable option. We did ours and determined that no it was not. So, we looked to our internet banking provider to see what options they would be providing. They had two options and we went with the more vigorous of the two. Not that I want the examiners to get here any quicker but I am real curious to hear from them what they find acceptable.
_________________________
Sometimes you have to burn a few bridges to keep the crazies from following you.
|
Return to Top
|
|
|
|
#557635 - 06/12/06 07:35 PM
Re: Multi-Factor Authentication Prep Poll
|
10K Club
Joined: Sep 2002
Posts: 13,965
TN
|
OK - I've been out of banking (in a compliance role) for approximatley 14 months. I am unfamiliar with the m utli-factor authentication. Where can I find out more information, please?
_________________________
My Opinions Only
|
Return to Top
|
|
|
|
#557636 - 06/12/06 07:43 PM
Re: Multi-Factor Authentication Prep Poll
|
Power Poster
Joined: Mar 2004
Posts: 2,514
Up North
|
Skittles, you can get the guidance from the FFIEC website. I don't know how to do the "click here for the link", sorry.
_________________________
Sometimes you have to burn a few bridges to keep the crazies from following you.
|
Return to Top
|
|
|
|
#557638 - 06/12/06 10:18 PM
Re: Multi-Factor Authentication Prep Poll
|
Power Poster
Joined: Mar 2005
Posts: 6,298
San Diego, CA
|
hi guys...we offer bill pay on our website, but customers may add "PEOPLE" to their billpay payees. thsi seems really risky to me...I'm callign it high risk, but has anyone esle heard of banks allowing this? i thought you could only set up companies for bill pay, nto individual people.
your thoughts?
_________________________
Dabbling in banking, law, accounting...the life of a trustee.
|
Return to Top
|
|
|
|
#557639 - 06/15/06 07:10 PM
Re: Multi-Factor Authentication Prep Poll
|
Power Poster
Joined: Dec 2000
Posts: 5,184
All over the map.
|
Do you have your own bill payment service, or do you have another company that actually is the provider?
_________________________
On the road again.....I just can't wait to get on the road again.
|
Return to Top
|
|
|
|
#557642 - 06/26/06 09:03 PM
Re: Multi-Factor Authentication Prep Poll
|
100 Club
Joined: Dec 2004
Posts: 141
Anywhere but here
|
I attended a PBS seminar on Compliance and Internet Banking last week and this issue came up. The instructor indicated that the regulators weren't requiring institutions to have thier multifactor authentication in place by year end, only that they had taken reasonable steps towards getting it in place. His reasonable steps included:
- risk assessment - implementing a customer awareness program
thoughts?
_________________________
I still say Christian Laettner didn't get the shot off in time!!
|
Return to Top
|
|
|
|
#557643 - 06/27/06 02:31 PM
Re: Multi-Factor Authentication Prep Poll
|
100 Club
Joined: Nov 2004
Posts: 107
|
What is everyone doing for the customer awareness program? How are you going about educating the customers?
|
Return to Top
|
|
|
|
|
|