To All Depository Institutions and Others Concerned in the Second Federal Reserve District:
The Federal Financial Institutions Examination Council (FFIEC) has issued revised guidance for examiners, financial institutions, and technology service providers on the development, acquisition, and maintenance of information systems.
The Development and Acquisition booklet provides guidance on development, acquisition, and maintenance projects, project risks, and project management techniques. The booklet emphasizes the use of standardized policies, detailed plans, and well-structured project management techniques when directing project activities and controlling project risks. Effective development and acquisition should result in sound information systems that provide specific functionality, consistent reliability, and strong security.
The booklet represents the latest in a series of updates to the 1996 FFIEC Information Systems Examination Handbook (Handbook). The FFIEC is updating the Handbook to address changes in technology since 1996 and to incorporate a risk-based examination approach. The new booklets will replace the Handbook, becoming the FFIEC Information Technology Examination Handbook. The booklets are distributed electronically through the FFIEC website.
Press release
FFIEC Information Technology Examination Handbook
Contact:
Jeanmarie Davis
Assistant Vice President
Operational Risk Department
jeanmarie.davis@ny.frb.org