8/31/2021 - By Jason Keith, CIA, CISA
On June 30, 2021, the Federal Financial Institutions Examination Council (FFIEC) published the new Architecture Infrastructure and Operations (AIO) booklet, replacing the Operations booklet from July 2004. While this new booklet resembles its predecessor, there are significant new themes to evaluate.
After reading Appendix A Examination Procedures, a few guiding themes began to surface. Three of these themes are considered below:
I found it helpful to visualize the booklet by considering the number of times selected topics appear within the booklet, and saw some interesting perspectives come out below.
In many cases, it makes sense that new terminology is needed when replacing a booklet originally authored 17 years ago. If around for another 17 years, this booklet may be one our best tools to forecast regulatory priorities now and into the future. Make time to digest the booklet and be prepared for some new questions in your next exam!
Contact our IT team for any questions regarding this new FFIEC booklet!
About the Author | Jason Keith, CIA, CISA
Jason is a senior technology risk consultant at Saltmarsh, Cleaveland and Gund. He specializes in consulting highly-regulated industries such as financial institutions, healthcare organizations and the defense industrial base, providing information security assessments, vulnerability and penetration testing and other related information security compliance services. Jason has over 20 years of professional experience and has held several technology-focused leadership roles with previous organizations, including Vice President of Risk, Chief Information Officer, and Chief Operations Officer.