May 18, 2013   
Share |
             


Amy K: InfoSight Highlight
Story ID: 2715  Print Friendly and PDF
Date Posted: January 15, 2013 

FFIEC Cloud Computing FAQs

In July 2012 the Federal Financial Institutions Examination Council (FFIEC) issued a statement on Outsourced Cloud Computing. The statement discusses key risk considerations associated with using third-party vendors to implement cloud computing solutions. The guidance from the FFIEC cautions credit unions to undertake a thorough due diligence and risk assessment process for outsourced cloud computing arrangements. It is important for credit unions who are considering storing information on a cloud to understand the possible risks that are associated with this type of information technology.

To help your credit union remain in compliance, the FFIEC Cloud Computing FAQs topic on the Security channel of InfoSight provides answers to these questions:

  • Why should we follow the guidance of the FFIEC?
  • What is cloud computing?
  • Why would a credit union want to consider cloud computing?
  • What services are currently offered through a cloud and how am I exposed to them?
  • Should my credit union be concerned with the safety of data stored on a cloud?
  • Does the FFIEC guidance help credit unions understand what due diligence issues we may face with cloud computing providers?
  • Is the cloud service provider responsible for changes in regulatory requirements?
  • How would a credit union monitor cloud computing activity?
  • What legal considerations should we review before enter into a contract for cloud computing services?
  • Will the credit unions current policies and procedures be adequate if we want to join a cloud?
  • How will cloud computing affect business continuity planning?


Compliance Video
- Expedited Funds Availability Act

The Expedited Funds Availability Act provides credit union employees with important information on requirements for making deposited items available to members in a timely manner.  This CUBE TV video provides an overview of check holds and member notification.

These topics can be found under the “Security” and “Home” channels in your InfoSight account. The “channels” are listed on the right hand of the screen. To access your account, or to request account, visit this link: http://dakotas.leagueinfosight.com/

Source: InfoSight Compliance eNewsletter, January 11, 2013 Vol. 7, Issue 2

Should you have any questions or concerns on this or any other compliance topic, please do not hesitate to contact Amy Kleinschmit at akleinschmit@cuad.coop or 701.214.9721.