IH - Laws and Regulations - Module 2 Powerpoint Presentation.pptx

trevor501353 10 views 18 slides Mar 05, 2025
Slide 1
Slide 1 of 18
Slide 1
1
Slide 2
2
Slide 3
3
Slide 4
4
Slide 5
5
Slide 6
6
Slide 7
7
Slide 8
8
Slide 9
9
Slide 10
10
Slide 11
11
Slide 12
12
Slide 13
13
Slide 14
14
Slide 15
15
Slide 16
16
Slide 17
17
Slide 18
18

About This Presentation

IH - Laws and Regulations - Module 2 Powerpoint Presentation.pptx


Slide Content

Dr. Kevin F. Streff Founder and Managing Partner 1 Incident Handler Certification

Dr. Kevin Streff American Security and Privacy, LLC Founder & Managing Partner www.americansecurityandprivacy.com [email protected] 605.270.4427 2

Agenda 3 Module 1 Incident Response Overview Module 2 Incident Response Laws and Regulations Module 3 The Fit of Incident Response in Information Security and Privacy Programs Module 4 Privacy Incidents Module 5 Security Incidents Module 6 Incident Response Program Overview Module 7 Step 1 - Preparation Module 8 Step 2 - Detection and Analysis Module 9 Step 3 - Contain, Eradicate, and Recover Module 10 Step 4 - Post Incident Activity Module 11 Incident Response Testing Module 12 Third Party Incident Response Requirements Module 13 Incident Response Auditing Module 14 Incident Response Metrics

Module 2 Incident Management law and regulation 4

Glass-Steagall of 1933 Legislation that includes four provisions of the United States Banking Act of 1933 separating commercial and investment banking Forced commercial banks to refrain from investment banking activities to protect depositors from potential losses through stock speculation. Glass-Steagall aimed to prevent a repeat of the 1929 stock market crash and the wave of commercial bank failures. Signed into law by President Franklin Delano Roosevelt was part of the New Deal  5

Gramm-Leach-Bliley Act of 1999 Repealed Glass-Stegall Increased need for information sharing Increased need for security and privacy Required an Information Security Program (ISP) Began laying down early privacy requirements 6

Banking Regulatory Framework by Dr. Kevin Streff 7 FEDERAL LAW: Gramm-Leach-Bliley Act, PCI, SOX, etc. FEDERAL UNIVERSAL REGULATION: FFIEC Booklets & Rules CONSUMER PROTECTION RULES: CFPB Rules STATE RULES: CSBS Rules FDIC NCUA FRB OCC CFPB

8

Incident Handling Resource 9

FFIEC Booklets 10

IT Workprograms 11

12

Incident Response The Federal Financial Institutions Examination Council (FFIEC) requires every FI to develop and implement a response program designed to address incidents of unauthorized access to sensitive customer information maintained by the financial institution or its service provider. 13

NCUA 14

15

ASFA Cybersecurity Incident Response Procedures 16

Summary 17

Dr. Kevin Streff American Security and Privacy, LLC Founder & Managing Partner www.americansecurityandprivacy.com [email protected] 605.270.4427 18 American Security and Privacy, LLC
Tags