0 Comments

Experian's Chris Ryan addressed five major questions about compliance with the Federal Financial Institutions Examination Council's recent guidance on banking authentication. What follows are his responses, summarized:

What does "layered security" actually mean?

Layered security refers to the arrangement of fraud tools in a sequential fashion. A layered approach starts with the most simple, benign and unobtrusive methods of authentication and progresses toward more stringent controls as the activity unfolds and the risk increases.

What does "multi-factor" authentication actually mean?

A simple example of multi-factor authentication is the use of a debit card at an ATM machine. The plastic debit card is an item that you must physically possess to withdraw cash, but the transaction also requires the PIN number to complete the transaction. The card is one factor, the PIN is a second. The two combine to deliver a multi-factor authentication.

Who does this guidance affect? And does it affect each type of credit grantor/ lender differently?

The guidance pertains to all financial institutions in the U.S. that fall under the FFIEC's influence. While the guidance specifically mentions authenticating in an online environment, it's clear that the overall approach advocated by the FFIEC applies to authentication in any environment.

What will the regulation do to help mitigate fraud risk in the near-term and long-term?

The guidance is an important reinforcement of several critical ideas: Fraud losses undermine faith in our financial system. Fraud tactics evolve constantly and the tools that combat them have to evolve as well. The guidance provides a perspective on why it is important to be able to understand the risk and to respond accordingly.

How are organizations responding?

Experian estimates that less than half of the institutions impacted by this guidance are prepared for the examinations. Many of the fraud tools in the marketplace, particularly those that are used to authenticate individuals, were deployed as point-solutions. Few support the need for a feedback loop to identify vulnerabilities, or the ability to employ a risk-based, layered approach that the guidance is seeking.

Robert Siciliano is a personal security expert and blogs regularly for ATMmarketplace.com. Visit his site at www.robertsiciliano.com.

Related Content

Reader Comments

Add a Comment

We welcome your thoughtful comments. All comments will display your real name.

Want to participate in the discussion?

Or log in for complete access.

  • Clear
  • Post
Be the first to post a comment for this story.
Products & Services

ATM Testing On-Demand Worldwide - Web FASTest™

http://global.networldalliance.com/new/images/products/WebFastest_logo100.gif

3710/ATM-Testing-On-Demand-Worldwide-Web-FASTest

Courtesy Telephones

http://global.networldalliance.com/new/images/products/4543.png

4543/Courtesy-Telephones

atmAd Solution

http://global.networldalliance.com/new/images/products/atmAd_logo_100_1108.gif

588/atmAd-Solution

Airis Sunlight Viewable Flat Panel LCD Display Upgrades

http://global.networldalliance.com/new/images/products/SunlightViewable100.gif

477/Airis-Sunlight-Viewable-Flat-Panel-LCD-Display-Upgrades

Convenient Ordering & Industry Best Service

http://global.networldalliance.com/new/images/products/4107.png

4107/Convenient-Ordering-Industry-Best-Service

NCR Managed Services

http://global.networldalliance.com/new/images/products/CD346_129_SERV_CallCenter_150.jpg

3729/NCR-Managed-Services

Traverse™

http://global.networldalliance.com/new/images/products/4148.png

4148/Traverse

VOLTDS® Network Control and Message Delivery System

http://global.networldalliance.com/new/images/products/4260.png

4260/VOLTDS-Network-Control-and-Message-Delivery-System

Robust Rural ATM – AX-821

http://global.networldalliance.com/new/images/products/4930.png

4930/Robust-Rural-ATM-AX-821

KingTeller – A4(08) Standard Lobby ATM

http://global.networldalliance.com/new/images/products/4233.png

4233/KingTeller-A4-08-Standard-Lobby-ATM

Identity Theft and Security

Latest posts by Robert Siciliano
Robert Siciliano
Robert Siciliano is CEO of IDTheftSecurity.com. He is a nationally known speaker on the subject of identity theft.
Customer Experience Technology Buyer
Request Information From Suppliers
Save time looking for suppliers. Complete this form to submit a Request for Information to our entire network of partners.