Acrobat PDF

Letter;

Click to download
Reviews
Shared by: 837dc4f1ea930e97
Categories
Tags
Stats
views:
16
rating:
not rated
reviews:
0
posted:
6/11/2009
language:
English
pages:
0
NCUA LETTER TO CREDIT UNIONS NATIONAL CREDIT UNION ADMINISTRATION 1775 Duke Street, Alexandria, VA 22314 DATE: TO: SUBJ: ENCL: September 2003 LETTER NO.: 03-CU-14 Federally Insured Credit Unions Computer Software Patch Management Guidance on Developing an Information System Patch Management Program to Address Software Vulnerabilities Dear Manager and Board of Directors: The National Credit Union Administration (NCUA) is providing credit unions with the enclosed guidance, recently issued by the Federal Deposit Insurance Corporation (FDIC), in an effort to assist credit unions in the development of an effective computer software patch management program encompassing appropriate policies, procedures, and practices in order to mitigate risks associated with commercial software vulnerabilities. During the past year, many companies and some credit unions have experienced security breaches that could have been prevented through the timely identification and patching of software vulnerabilities. This guidance provides information about the importance of maintaining an effective computer software patch management program and information technology (IT) infrastructure. In addition, the guidance provides credit unions with background information on the risks associated with software vulnerabilities and how they can be mitigated through an effective patch management program. Many credit unions rely on commercially developed software to support business processes and an IT infrastructure. Common types of software include operating systems, core processing systems, business applications (e.g., word processing, spreadsheet, and database programs), and system services (e.g., anti-virus programs, firewalls, etc.). Commercially developed software may contain flaws that create security and performance vulnerabilities. These vulnerabilities may cause system unavailability or corrupt critical system components or data. Although software vendors often develop updates, or "patches," to correct identified weaknesses, it is the software user's responsibility to update systems or install patches in a timely manner. If you have any questions or concerns, please contact your NCUA regional office or State Supervisory Authority. Sincerely, /S/ Dennis Dollar Chairman Enclosure

Related docs
The letter
Views: 31  |  Downloads: 0
Letter to the
Views: 8  |  Downloads: 0
the letter
Views: 9  |  Downloads: 0
a letter
Views: 36  |  Downloads: 0
private letter
Views: 304  |  Downloads: 7
Letter
Views: 43  |  Downloads: 1
Letter
Views: 18  |  Downloads: 1
Letter-in
Views: 12  |  Downloads: 1
Letter
Views: 11  |  Downloads: 0
Letter
Views: 21  |  Downloads: 1
Letter
Views: 0  |  Downloads: 0
Letter
Views: 20  |  Downloads: 0
Letter
Views: 1  |  Downloads: 0
letter
Views: 2  |  Downloads: 0
premium docs
Other docs by 837dc4f1ea930e...
Provisions in deed made pursuant to receiver
Views: 216  |  Downloads: 2
Midgett Schrader Briefs
Views: 179  |  Downloads: 0
Physics Formulary
Views: 3059  |  Downloads: 190
Form 202-General Information
Views: 413  |  Downloads: 1
de172
Views: 79  |  Downloads: 0
de305
Views: 74  |  Downloads: 0
Pavel Enterprises v Johnson
Views: 414  |  Downloads: 6
National Chemistry Week Experiments: Bubbles
Views: 496  |  Downloads: 12
Hess v Pawloski
Views: 883  |  Downloads: 7
Surround Us
Views: 214  |  Downloads: 1
Jesus Name Above All Names
Views: 589  |  Downloads: 2
Christ We Do All Adore Thee
Views: 169  |  Downloads: 1
dv100k
Views: 134  |  Downloads: 0
cr120
Views: 92  |  Downloads: 0
Harms v Sprague
Views: 196  |  Downloads: 2