Jon Waldman

Jon WaldmanSupportBusiness
Summary: SBS CyberSecurity supports the FFIEC's goals of improving transparency and consistency in the CAMELS rating system but expresses concern that removing special consideration for the Management component could reduce oversight of cybersecurity and technology governance. They argue that technology risk is a core safety-and-soundness issue and recommend adding a distinct Technology & Operational Resilience component to the rating framework.
SBS CyberSecurity appreciates the opportunity to comment on the Federal Financial Institutions Examination Council's proposed revisions to the Uniform Financial Institutions Rating System, commonly known as CAMELS. SBS supports the FFIEC's goals of improving transparency, consistency, and predictability in the examination process. Financial institutions should understand how supervisory ratings are determined, and ratings should be tied to meaningful risk rather than examiner discretion or documentation requirements that are not indicative of material risk. SBS is concerned that removing the special consideration historically given to the Management component may unintentionally reduce supervisory emphasis on technology governance, cybersecurity governance, third-party risk management, operational resilience, independent testing, and a well-managed Information Security Program. Those areas are not secondary concerns in modern banking. They are core safety-and-soundness issues, as well as critical elements to the resilience and continued operations of the financial sector as a whole. While SBS supports the FFIEC's effort to focus ratings on material financial risk, we believe technology governance, cybersecurity, and independent testing should be viewed as leading indicators of material risk rather than process-oriented considerations. Attached is a detailed letter breaking down our concerns and offering our support to a previous comment left by Vincent J. Buono, CISA, CISM, retired OCC Bank IT Analyst, recommending that the FFIEC consider adding a distinct Technology & Operational Resilience component to the rating framework. His proposed CAMELTS structure recognizes that technology failures, cyber events, operational outages, third-party dependencies, and data integrity issues can directly affect safety and soundness. Our suggestion builds upon Mr. Buono's recommendation with a few additional important elements SBS sees as critically important to a modern Information Security Program, and uses language that should be familiar to financial institutions, examiners, auditors, and cybersecurity practitioners. Thank you for the consideration. Jon Waldman President and Co-Founder SBS CyberSecurity

View on Regulations.gov