
Information Security Officer and Information Security Program Oversight
Your Information Security Officer must fully comprehend the complexity of IT, the Bank’s network, as well as the ever-changing risks of customer information and privacy.
Per the FFIEC IT Examination handbook, your Information Security Officer (ISO) should:
- Report directly to the Board or Senior Management
- Have sufficient authority, stature within the organization, knowledge, background, training, and independence to perform their assigned tasks
- Be independent of the IT Operations Staff; should not report to IT Operations Management
- Be responsible for responding to security events by ordering emergency actions to protect the institution and its customers from imminent loss of information
- Manage the negative effects on the confidentiality, integrity, availability, or value of information
- Minimize the disruption or degradation of critical services
