FDIC, Federal Deposit Insurance Corporation, Office of Inspector General, core values: communication, objectivity, responsibility, excellence
FDIC.GOV Office of Inspector General core values: communication, objectivity, responsibility, excellence
Search | Accessibility | Privacy | Information Quality | Contact Us | Site Map | Home

Controls Over the Risk-Related Premium System

September 2005
Audit Report 05-037


DATE:  September 13, 2005

MEMORANDUM TO:  Stephen M. Beard
 Deputy Assistant Inspector General for Audits
 Office of the Inspector General

FROM: Arthur J. Murton
 Director

SUBJECT:  Draft Report Entitled, Audit of Controls Over the Risk-Related Premium System
 (Assignment No. 2005-029)

Thank you for the opportunity to respond to the draft audit report, Audit of Controls Over the Risk-Related Premium System. The Division of Insurance and Research (DIR) agrees with the overall assessment that the management, operational, and technical controls for the Risk-Related Premium System (RRPS) provide reasonable assurance of adequate security.

The draft report contains three recommendations to maintain strong controls over RRPS. The Division is responsible for taking corrective action to address the deficiencies noted in the Recommendations One (1) and Three (3) of the draft report. The Division of Information Technology (DIT) is responsible for Recommendation Two (2) and will provide a response to the draft audit report under separate cover. The recommendations for which DIR has primary responsibility are listed below with the Division’s responses and actions taken to correct noted deficiencies.

FDIC OIG Recommendations:

  1. We recommend that the Director, DIR, correct identified deficiencies in and approve the updated RRPS security plan.

DIR Response:

DIR concurs with the finding. All items listed in the condition have been documented in the RRPS security plan and a copy of the revised plan has been provided to the OIG. DIR will continue to modify the security plan when: (1) NIST/OMB updates requirements for major application security plans, (2) RRPS applications controls or procedures are modified, and/or (3) internal reviews or external security audits require modifications.

  1. We recommend that the Director, DIR, develop and implement an SCM plan for RRPS that incorporates the appropriate features of StarTeam.

DIT will respond to this finding under separate cover.

  1. We recommend that the Director. DIR, establish roles, responsibilities, and procedures for conducting periodic reviews of all RRPS user access rights as required by FDIC Directive 1360.15 and the RRPS security plan.

DIR Response:

DIR concurs with the finding. Roles, responsibilities, and procedures for conducting periodic reviews of all RRPS users access rights have been developed and are documented in the security plan.

Search | Accessibility | Privacy | Information Quality | Contact Us | Site Map | Home
Last updated 10/12/2005