IT Examiner School eBook May 2025
Credit Card Related Merchant Activities Note: This type of activity relates to credit card payment transactions for merchants. Refer to the Credit Card Related Merchant Activities Examination Documentation (ED) Module and the FFIEC IT Examination Handbook - Retail Payment Systems. If additional procedures are used, enter a summary of findings below. Click here to enter comment End of Management Core Analysis. If applicable, and as needed based on the extent of the institution’s involvement in the following areas, continue to the Expanded Analysis. Cloud Computing User Groups
Vendor Information Security Programs Managed Security Service Providers Foreign-Based Technology Service Providers Vendor Incentive Agreements
Information Technology Risk Examination
Institution Name: Click here to enter institution name Cert# Click here to enter cert number
Preparer: Click here to enter preparer name Start Date: Click here to select a start date
Development and Acquisition
Core Analysis Decision Factors
Note: refer to the FFIEC IT Examination Handbook - Development and Acquisition if additional analysis is necessary to complete this module. Decision Factors – Development and Acquisition DA.1. The level and quality of oversight and support of systems development and acquisition activities by senior management and the Board of Directors. ▼ Procedures #1-4 Click here to enter comment Strong ☐ Satisfactory ☐ Less than satisfactory ☐ Deficient ☐ Critically deficient ☐ DA.2. The quality of project management programs and practices. ▼ Procedure #5 Click here to enter comment Strong ☐ Satisfactory ☐ Less than satisfactory ☐ Deficient ☐ Critically deficient ☐ DA.3. The adequacy of controls over program changes. ▼ Procedure #6 Click here to enter comment Strong ☐ Satisfactory ☐ Less than satisfactory ☐ Deficient ☐ Critically deficient ☐
Made with FlippingBook - Online magazine maker