NCUA Disclosed FFIEC DraftRegulator Mistakenly Posted Authentication Guidance
According to representatives of the NCUA's Office of Examination, the draft of the FFIEC's "Interagency Supplement to Authentication in an Internet Banking Environment" was posted on Dec. 30, the day before the formal guidance was expected to be made public.
"FFIEC agencies were originally scheduled to jointly release the document by 12/31/2010," the NCUA said in response to inquiries from Information Security Media Group. "There was, however, a delay with the approval processes at one FFIEC agency. NCUA did not receive notification in time to prevent the public release of the document. As soon as [the] NCUA received notification that one of the other FFIEC agencies had a delay in the approval process, [the] NCUA removed the document from its website as this document was intended as a joint release by FFIEC agencies."
The draft was available on the NCUA site for four to five days over the New Year's holiday, during which time it was downloaded 1,100 times, according to the NCUA. Since then, the draft has circulated widely throughout the banking industry. ISMG published excerpts of this draft on Feb. 22.
ISMG has not been able to confirm which of the FFIEC's member agencies held up the publication of the guidance.
Disclosure's Impact?In short, the FFIEC draft calls for:
- More risk assessments for banks to better understand and respond to emerging threats, such as man-in-the-middle or man-in-the-browser attacks, as well as keyloggers;
- Increased multifactor authentication;
- Layered security controls;
- Improved device identification and protection;
- Improved customer and employee fraud awareness.
This pending supplement - the FFIEC's first statement on authentication since its original 2005 guidance - has been long awaited by industry practitioners, analysts and vendors alike.
Although the disclosure was an "innocent error," Navetta says, it has likely fueled further delays and regulator concerns. "From a public perspective, seeing a draft of what's being proposed helps us know what the regulators are thinking," he says, but it also opens the FFIEC to additional feedback on its proposed guidelines. "It could pose some problems for the actual guidance."
George Tubin, a TowerGroup analyst who focuses on fraud and security, agrees the disclosure likely has contributed to the delay. "I've never seen this happen before, and I think it's caused some problems," he says. "It's been two months now since it went out on the website, and we still don't have anything official. That's a long time."
No high-profile fraud incidents have been reported since the accidental disclosure, but banking and security executives, in particular, anxiously await the final guidance. Not that the guidance alone will prevent fraud incidents, but practitioners are eager for regulators' latest recommendations on hot topics such as multifactor authentication and layered security. As David Shroyer, a former Bank of America executive, said in a recent interview about the drafted guidance, "Financial institutions live and die by this guidance."