IH - Laws and Regulations - Module 2 Powerpoint Presentation.pptx
trevor501353
10 views
18 slides
Mar 05, 2025
Slide 1 of 18
1
2
3
4
5
6
7
8
9
10
11
12
13
14
15
16
17
18
About This Presentation
IH - Laws and Regulations - Module 2 Powerpoint Presentation.pptx
Size: 3.57 MB
Language: en
Added: Mar 05, 2025
Slides: 18 pages
Slide Content
Dr. Kevin F. Streff Founder and Managing Partner 1 Incident Handler Certification
Dr. Kevin Streff American Security and Privacy, LLC Founder & Managing Partner www.americansecurityandprivacy.com [email protected] 605.270.4427 2
Agenda 3 Module 1 Incident Response Overview Module 2 Incident Response Laws and Regulations Module 3 The Fit of Incident Response in Information Security and Privacy Programs Module 4 Privacy Incidents Module 5 Security Incidents Module 6 Incident Response Program Overview Module 7 Step 1 - Preparation Module 8 Step 2 - Detection and Analysis Module 9 Step 3 - Contain, Eradicate, and Recover Module 10 Step 4 - Post Incident Activity Module 11 Incident Response Testing Module 12 Third Party Incident Response Requirements Module 13 Incident Response Auditing Module 14 Incident Response Metrics
Module 2 Incident Management law and regulation 4
Glass-Steagall of 1933 Legislation that includes four provisions of the United States Banking Act of 1933 separating commercial and investment banking Forced commercial banks to refrain from investment banking activities to protect depositors from potential losses through stock speculation. Glass-Steagall aimed to prevent a repeat of the 1929 stock market crash and the wave of commercial bank failures. Signed into law by President Franklin Delano Roosevelt was part of the New Deal 5
Gramm-Leach-Bliley Act of 1999 Repealed Glass-Stegall Increased need for information sharing Increased need for security and privacy Required an Information Security Program (ISP) Began laying down early privacy requirements 6
Banking Regulatory Framework by Dr. Kevin Streff 7 FEDERAL LAW: Gramm-Leach-Bliley Act, PCI, SOX, etc. FEDERAL UNIVERSAL REGULATION: FFIEC Booklets & Rules CONSUMER PROTECTION RULES: CFPB Rules STATE RULES: CSBS Rules FDIC NCUA FRB OCC CFPB
8
Incident Handling Resource 9
FFIEC Booklets 10
IT Workprograms 11
12
Incident Response The Federal Financial Institutions Examination Council (FFIEC) requires every FI to develop and implement a response program designed to address incidents of unauthorized access to sensitive customer information maintained by the financial institution or its service provider. 13
Dr. Kevin Streff American Security and Privacy, LLC Founder & Managing Partner www.americansecurityandprivacy.com [email protected] 605.270.4427 18 American Security and Privacy, LLC