IT Examiner School eBook

Internal Use Only

IT Management Component Rating  IT management rating is based on FFIEC Uniform Rating System for Information Technology (URSIT)  InTREx process (depository institutions) calls for assigning a Management component rating for IT  Like Safety and Soundness, this component rating plays a key role in the overall URSIT composite rating & is rated on the same criteria, but based solely on IT/operations activities  Additional URSIT information, components & ratings are discussed in other modules

Internal Use Only

IT Management Component Rating – Key Considerations  Level and quality of oversight  Reporting  Policies and Procedures  Compliance  Succession Planning

 Vendor Oversight  Risk Assessments

Made with FlippingBook - Online magazine maker