On September 29, 2023, the FDIC released a Financial Institution Letter announcing updates to the Information Technology Risk Examination (InTREx). This update aims to “improve the Audit module‘s usability, specify compliance review steps relative to the Computer Security Incident Notification Rule (Part 304 Subpart C), provide more specificity regarding examiner review of service provider reports of examination, and update links to references.”
BankOnIT has examined the modifications made to the InTREx and noted that these changes mainly pertain to adjustments in how examiners conduct their assessments. These alterations also involve updates to terminology to include the newly created Computer Security Incident Notification Rule and some superficial adjustments to the overall procedure.
Regulators are looking for institutions to review their service provider's TSP exam reports. As a result, institutions should check to make sure requests for those reports are regularly being driven by someone in their institution. In addition, with the inclusion of the Computer Security Incident Notification Rule, we recommend that our clients review the modifications to ensure an established and approved policy is in place.
Have questions? Contact us at insights@bankonitusa.com.
--
Links:
Financial Institution Letter - Information Technology Risk Examination (InTREx) Procedures
Financial Institution Letter - Computer-Security Incident Notification