Skip to content
BOL Conferences
Thread Options
#870330 - 12/11/07 03:22 PM Gramm, Leach, Bliley
msboo Offline
Gold Star
Joined: May 2006
Posts: 260
Does Gramm, Leach, Bliley state a bank's Information Security Policy & Program should be reviewed annually by the Board of Directors? If so where.

Return to Top
Audit
#870776 - 12/11/07 08:44 PM Re: Gramm, Leach, Bliley msboo
Reads Regs Offline
Diamond Poster
Joined: Nov 2004
Posts: 2,310
Appendix B to part 570 of the OTS regulations contains the "Interagency Guidelines Establishing Information Security Standards." The following text came from this document.

"F. REPORT TO THE BOARD. You shall report to your board or an appropriate committee of the board at least annually. This report should describe the overall status of the information security program and your compliance with these Guidelines. The reports should discuss material matters related to your program, addressing issues such as: risk assessment; risk management and control decisions; service provider arrangements; results of testing; security breaches or violations and management's responses; and recommendations for changes in the information security program."
_________________________
Opinions expressed are my own and not necessarily those of my employer. They are not legal advice.

Return to Top

Moderator:  Andy_Z