BreachExchange mailing list archives

Re: Banking and state regulations regarding the transmission of banking routing/account information


From: "Mark Simon" <MarkSimon () eclipsecurity com>
Date: Fri, 17 Apr 2009 13:04:46 -0500

You're on the right track to question the practice of sending
routing/account number information over the internet without protection
of that data.

 

FEDERAL RESERVE SYSTEM PART 216--PRIVACY OF CONSUMER FINANCIAL
INFORMATION (REGULATION P), 12 CFR 216.3, defines nonpublic information
that a financial institution is obligated to protect.  Security and
confidentiality of nonpublic personal information of consumers with whom
an institution has a customer relationship is protected by GLBA
interagency regulations establishing customer safeguards.  See 88 FR
8616 (Feb. 1, 2001).

 

You may want to check your institution's privacy notice, too. Financial
institutions are required, as part of their initial privacy notices, to
describe their policies and

practices with respect to protecting the confidentiality and security of
nonpublic personal information (12 CFR 216.6).

 

 

--
Mark S. Simon, JD, CISSP

Director of Regulatory Compliance Consulting 

 
Mobile: (224) 612-3101

Office: (847) 850-5088

Toll Free: (877) 369-5331

 

www.eclipsecurity.com

Lock-in success.  Because information travels...

From: dataloss-bounces () datalossdb org
[mailto:dataloss-bounces () datalossdb org] On Behalf Of Pia
Sachs-Donerkiel
Sent: Friday, April 17, 2009 8:56 AM
To: 'dataloss () datalossdb org'
Subject: Re: [Dataloss] Banking and state regulations regarding the
transmission of banking routing/account information

 

Well, it's not Banking Reg, but I am sure FDIC has something similar to
BCUA:

 

 Credit Union member  information security requirements, for federal
credit unions, is spelled out in section 748 of NCUA's Rules and
Regulations.

 

Section iii  Development and implementation of member information
security program; part C ;Manage and control risk  paragraph (c) of part
748 states:

Each Credit Union shall employ encryption of electronic member
information, including while in transit or in storage on networks or
systems to which unauthorized individuals may have access.

 

 

Pia Sachs-Donerkiel

Payment Services Supervisor

New England Federal Credit Union

802-879-8773

802-764-6589 Fax

From: dataloss-bounces () datalossdb org
[mailto:dataloss-bounces () datalossdb org] On Behalf Of fzbrick
Sent: Thursday, April 16, 2009 4:02 PM
To: dataloss () datalossdb org
Subject: [Dataloss] Banking and state regulations regarding the
transmission of banking routing/account information

 

Hi,

Is anyone aware of written regulations regarding how bank routing and
account information should be transmitted over the internet?

Intuitively, it needs to be encrypted, however what seems clear to
others isn't to others.  I need a banking regulation, federal law, or
banking requirement that says

"Bank Routing and Account information shall be encrypted".

Sorry, I am dealing with difficult people, who will not believe me, and
need it spelled out to them in near comic book form.

Thanks

 

________________________________

Confidentiality Notice: This email message, including any attachments,
is for the sole use of the intended recipient(s) and may contain
confidential & privileged information. Any unauthorized review, use,
disclosure, or distribution is prohibited. If you are not the intended
recipient, please contact sender by reply email & destroy all copies of
the original message. To protect your privacy, we have removed personal
and account information (such as member number, etc.) from the email
being returned to you, and we advise you not to include confidential
information if you respond to this email.


********************
This message and any accompanying attachments are intended
only for the addressees(s) named above, and may contain information 
that is privileged or confidential.  If you have received 
this email in error, please notify the sender and delete this 
message and any accompanying attachments immediately 
thereafter.  To the extent the contents of this message or any 
accompanying attachments are original works of authorship, the 
right to copy, prepare derivative works, distribute, or display publicly
such work without the permission of Eclipsecurity, LLC, is strictly 
prohibited under U.S. Copyright law.
********************

_______________________________________________
Dataloss Mailing List (dataloss () datalossdb org)

CREDANT Technologies, a leader in data security, offers advanced data encryption solutions.
Protect sensitive data on desktops, laptops, smartphones and USB sticks transparently 
across your enterprise to ensure regulatory compliance.
http://www.credant.com/stopdataloss

Current thread: