Strengthening the Resilience of Outsourced Technology Services
By: Russ Horn (CISA, CISSP, CRISC)
Publication: The Kansas Banker, March 2015
On February 6, 2015, the FFIEC issued a new appendix titled "Strengthening the Resilience of Outsourced Technology Services" to the "Business Continuity Planning" booklet of the FFIEC Information Technology Examination Handbook. This new appendix discusses the following four key elements financial institutions should address related to Technology Service Providers (TSPs).
Third-Party Management
"Establishing a well-defined relationship with TSPs is essential to business resilience. A financial institution's third-party management program should be risk-focused and provide oversight and controls commensurate with the level of risk presented by the outsourcing arrangement."
The guidance focuses on the following third-party management components: