AuditNet Discussion Forum Forum Index AuditNet Discussion Forum
Auditors Helping Auditors
 
 FAQFAQ   SearchSearch   MemberlistMemberlist   UsergroupsUsergroups   RegisterRegister 
 ProfileProfile   Log in to check your private messagesLog in to check your private messages   Log inLog in 

Information Security (Customer Response Programs)

 
Post new topic   Reply to topic    AuditNet Discussion Forum Forum Index -> IT Auditing
View previous topic :: View next topic  
Author Message
Mr. Jones



Joined: 21 Oct 2005
Posts: 1

PostPosted: Mon Oct 24, 2005 4:06 pm    Post subject: Information Security (Customer Response Programs) Reply with quote

For those auditors that review the information security customer response programs for national banks (OCC regulated), has anyone performed a risk assessment if the bank decided not to give notice to the customer (regulatory guidance applies only to information that is within the control of the institution and its service providers). An example would be where VISA had a breach and is not a direct third party of the national bank using VISA debit cards. Excluding monetary issues (fraud costs), I see the biggest issue as reputation risk. If you disclose, the uniformed customer may think it is your bank and not a service provider you have no control over (VISA). If you don’t disclose and the customer(s) find out you knew of the breach before hand, there could be potential legal and ethical issues.

Obviously, regulatory guidance is very grey. I am looking for other people’s thoughts and guidance they may have received from their regulators.
Back to top
View user's profile Send private message
Display posts from previous:   
Post new topic   Reply to topic    AuditNet Discussion Forum Forum Index -> IT Auditing All times are GMT - 5 Hours
Page 1 of 1

 
Jump to:  
You cannot post new topics in this forum
You cannot reply to topics in this forum
You cannot edit your posts in this forum
You cannot delete your posts in this forum
You cannot vote in polls in this forum




Powered by phpBB © 2001, 2005 phpBB Group

Abuse - Report Abuse
Powered by forumup.org free forum, create your free forum!
Created by Raulken of Hyarbor S.r.l.
TOS & Privacy.

Page generation time: 0.048