FFIEC examiner expectations, answered with scan data.
CISGuard gives banks and credit unions continuous configuration evidence for FFIEC IT examinations: hardening baselines, change monitoring, and audit trails in the form examiners ask to see.
FFIEC at a glance, for fast retrieval.
Atomic factual claims auditors and search engines can cite verbatim.
- Issuing body
- FFIEC (Federal Reserve, FDIC, OCC, NCUA, CFPB, State Liaison Committee)
- Core guidance
- IT Examination Handbook: Information Security and AIO booklets
- CAT status
- Cybersecurity Assessment Tool sunset in 2025; NIST CSF 2.0 among successors
- Who is examined
- Banks, credit unions, thrifts, and their technology service providers
- Configuration focus
- Hardening baselines, change management, and monitoring expectations
- Deployment
- On-premises or air-gapped; data never leaves the institution
What is FFIEC?
The Federal Financial Institutions Examination Council (FFIEC) sets uniform IT examination standards for U.S. banking regulators, including the Federal Reserve, FDIC, OCC, NCUA, and CFPB. Its IT Examination Handbook, particularly the Information Security and Architecture, Infrastructure, and Operations booklets, defines what examiners expect from an institution's security program, with explicit attention to configuration management, hardening baselines, change control, and ongoing monitoring. The FFIEC's Cybersecurity Assessment Tool (CAT), long used for maturity self-assessment, was sunset in 2025, with the FFIEC pointing institutions toward frameworks such as NIST CSF 2.0 and CISA's Cybersecurity Performance Goals. What has not changed is the examination itself: examiners still ask how systems are hardened, how deviations are caught, and how the institution proves it. CISGuard's continuous CIS benchmark scanning answers those questions with data.
FFIEC examination areas CISGuard supports with evidence.
Each CIS control is tagged with its corresponding framework reference. A single scan produces per-framework coverage reports.
- Secure Configuration & Hardening
- Controls
- Information Security booklet baseline expectations
- Mapped by
- Continuous CIS benchmark scanning across 22 benchmarks
- Change & Configuration Management
- Controls
- AIO booklet change control expectations
- Mapped by
- Drift detection + baseline comparison between scans
- Access Rights Administration
- Controls
- Least privilege and account management expectations
- Mapped by
- CIS Account + Privilege Management benchmarks
- Authentication
- Controls
- Password and MFA configuration expectations
- Mapped by
- CIS Password Policy + MFA benchmarks
- Log Management & Monitoring
- Controls
- Audit logging and event monitoring expectations
- Mapped by
- CIS Audit Policy benchmarks + SIEM forwarding
- Framework Alignment
- Controls
- NIST CSF 2.0 profile post-CAT sunset
- Mapped by
- Framework Coverage Report rolled up to CSF functions
How CISGuard automates FFIEC evidence.
FFIEC examinations are evidence-driven conversations: the examiner asks how servers and workstations are hardened, how the institution knows configurations have not drifted, and whether logging is actually enabled everywhere policy says it is. Institutions traditionally answer with policy documents and sampled screenshots, which invites deeper sampling. CISGuard changes the posture of that conversation. Continuous CIS benchmark scans across the institution's Windows and Linux estate produce per-asset hardening evidence against recognized baselines; drift detection creates a documented record of change monitoring between scans; the immutable audit trail and SIEM forwarding evidence log management. With the CAT sunset, institutions migrating their self-assessment to NIST CSF 2.0 can use the Framework Coverage Report's CSF rollup to ground the new profile in scan data. CISGuard is not an examiner and does not determine ratings; it ensures the technical answers you give are backed by continuous, timestamped evidence rather than samples.
Evidence artifacts CISGuard generates.
Auditor-grade outputs in PDF/CSV. No spreadsheets, no screenshots, no manual cross-referencing.
- Per-asset CIS benchmark hardening evidence across servers and workstations
- Drift detection record demonstrating continuous configuration monitoring
- Audit-policy and logging verification evidence for log management review
- Access and authentication configuration status across the estate
- Framework Coverage Report with NIST CSF 2.0 rollup for post-CAT self-assessment
- Historical posture trends for board reporting and examination cycles
FFIEC questions, answered directly.
What do FFIEC examiners expect for configuration management?
The IT Examination Handbook expects institutions to maintain secure configuration baselines for systems, control and document changes to them, and monitor for unauthorized deviations. Examiners probe whether hardening standards exist, whether they are actually applied across the estate, and how the institution detects drift. CISGuard evidences all three: CIS benchmarks provide the recognized baseline, continuous scans prove application per asset, and drift detection documents the monitoring.
The CAT has been sunset. What should we assess against now?
The FFIEC sunset the Cybersecurity Assessment Tool in 2025 and pointed institutions toward established frameworks such as NIST CSF 2.0 and CISA's Cybersecurity Performance Goals for self-assessment. Whichever framework your institution adopts, the technical evidence layer is the same: hardened configurations, monitored change, and audit logging. CISGuard's Framework Coverage Report rolls scan results up to NIST CSF functions, giving the new self-assessment a data-backed foundation.
Does CISGuard determine our examination rating?
No. Examination ratings are assigned by your regulator's examiners based on the institution's overall IT and risk management program, and CISGuard is neither an examiner nor an auditor. What CISGuard changes is the quality of your technical evidence: instead of sampled screenshots assembled before the exam, you present continuous, timestamped scan history showing hardening posture and change monitoring across the whole estate for the entire examination interval.
Does FFIEC guidance apply to credit unions and service providers?
Yes. The NCUA applies FFIEC-aligned examination standards to credit unions, and technology service providers to regulated institutions are themselves subject to examination under the Bank Service Company Act. Vendors serving banks and credit unions face the same configuration management and monitoring expectations. CISGuard serves both sides: institutions evidencing their own estate, and service providers evidencing the systems that support their financial-institution customers.
Can CISGuard run entirely inside the institution's network?
Yes. CISGuard deploys fully on-premises, and supports air-gapped operation where required: scanning, drift detection, and report generation all run with zero external dependency, so configuration data about your core systems never leaves your network boundary. That deployment model aligns with examiner expectations on third-party risk and data protection, and simplifies the vendor-management review of CISGuard itself.
Continue exploring CISGuard coverage.
GLBA Safeguards Rule
CISGuard automates the technical safeguards required by the Gramm-Leach-Bliley Act Safeguards Rule, with continuous evidence aligned to the December 2021 amendments and the broader FFIEC Cybersecurity Assessment Tool.
Read more →NYDFS 23 NYCRR 500
CISGuard automates the technical controls of the New York Department of Financial Services cybersecurity regulation, with continuous evidence for the November 2023 Class A Covered Entity amendments and the bundled 24-hour incident reporting workflow.
Read more →NIST CSF
CISGuard turns continuous CIS benchmark scanning into technical evidence for the NIST Cybersecurity Framework 2.0, with strongest coverage of the Protect and Detect functions through configuration hardening and drift detection.
Read more →SOC 2
SOC 2 Type II requires evidence of controls operating effectively over a period. CISGuard provides that period evidence automatically: 26 Trust Services Criteria mapped, continuous monitoring satisfying the "over time" requirement.
Read more →Ready for FFIEC readiness?
Our compliance engineers have helped organizations achieve regulatory readiness in as little as one business day.