To address the growing cyber threat against financial institutions, the Federal Financial Institutions Examination Council (FFIEC), an interagency body comprising five banking regulators (FRB, FDIC, NCUA, OCC, CFPB), conducts examinations to ensure these institutions are protected against cyber-attacks. The FFIEC guides financial institutions and assists regulators in enforcing, leading, and auditing cybersecurity measures.
The FFIEC’s Cybersecurity Assessment Tool (CAT) and IT Security Handbook mandate the enforcement of comprehensive configuration hardening baselines for servers. Additionally, the FFIEC Examiner Education Office releases IT Examination Handbooks for field examiners representing its member agencies.
The FFIEC CAT presents a set of challenging server configuration hardening requirements:
CHS offers pre-configured policies aligned with CIS, ISO, or NIST baselines, as well as customizable organizational policies that can be uploaded to our Policy Center and enforced. While implementing broad baselines like CIS or NIST may potentially disrupt applications and OS services, CHS’s predictive “Learning” mode helps mitigate this risk by indicating the potential impact of policy changes on the production environment. This feature saves time and resources typically required for extensive policy testing before deployment to production servers.
CHS integrates into organizational penetration testing and vulnerability scanning programs, implementing a robust configuration change management process. Hardened servers are continuously monitored, with authorized changes logged and unauthorized changes prevented in real-time. All configuration changes are audited, saved, and presented in a dashboard, ensuring comprehensive oversight and control of server environments.