This article was published in the Jan/Feb 2018 edition of the Nebraska Banker magazine.
Over the past few years, as cybersecurity threats have risen, the need for financial institutions to designate an Information Security Officer (ISO) has increased.
What does this ISO role look like? In this article, we will examine what the Federal Financial Institutions Examination Council (FFIEC) handbooks say about an information security officer. For the purposes of this article, we will refer to the Chief Information Security Officer, Information Security Officer, and Corporate Information Security Officer similarly, and use the acronym "ISO" to encompass the collection of job titles.
According to the FFIEC Information Security Booklet, financial institutions should "designate at least one information security officer responsible and accountable for implementing and monitoring the information security program." In the past, many considered the ISO role a technology function; however, the most recent FFIEC Management Booklet suggests, "the role has become a strategic and integral part of the business management team" and the ISO should now be "an enterprise-wide risk manager rather than a production resource devoted to IT operations."
According to the FFIEC Management Booklet, the ISO is typically responsible for:
What qualities should an ISO have?
According to the FFIEC Information Security Booklet, the ISO should have the following qualities:
Yes, the FFIEC Information Security Booklet states "at least one information security officer," implying an institution may have several information security officers.
According to the FFIEC Management Booklet, the ISO should "report directly to the board, a board committee, or senior management and not IT operations management." In general, the reporting structure should ensure the ISO has appropriate authority to carry out his or her responsibilities and should avoid conflicts of interest.
The ISO should have sufficient knowledge and training to perform his or her assigned tasks. There are numerous resources available for ISOs. A few valuable resources include: