SR 11-9 Interagency Supplement to Authentication in an Internet Banking Environment

July 20, 2011

The Federal Reserve Board, together with the other members of the Federal Financial Institution Examination Council (FFIEC) (collectively, the agencies) have issued the attached guidance titled “Supplement to Authentication in an Internet Banking Environment” (Supplement), which supplements the similarly titled guidance issued by the FFIEC in 2005. Given heightened and evolving cyber threats in the online environment, the supplement reinforces the original risk-management framework guidance and updates the agencies’ expectations for supervised financial organizations regarding customer authentication, layered security, and other controls. Going forward, organizations supervised by the agencies should look to both the 2005 FFIEC authentication guidance and this Supplement to understand the agencies’ risk-management expectations for controls within Internet and other electronic banking environments.