Nebraska Bankers Association
  • About
    • Membership
    • News
    • Boards and Committees
    • Alice Dittman Trailblazer Award
    • NBA Foundation
    • Leadership Program
    • Staff Directory >
      • Contact Us
  • Workforce
    • Careers
    • Post Job Openings
  • Advocacy
    • Legislative Update
    • BankPAC
    • Comment Letters
  • Compliance
    • Handbook
    • Compliance Update
    • Compliance Alliance
  • Education
    • Event Calendar
    • In-person Events/Training
    • Webinars
    • ABA Training
    • Banking Schools
    • CYBERSECURITY TRAINING
    • Sponsorships and Exhibits
    • Young Bankers (YBON)
  • Insurance
    • Agency Services >
      • Commercial Insurance
      • Personal Insurance
      • Livestock, Irrigation and Farm Insurance
      • Surety Bonds
    • Bank Property & Liability
    • Financial Institution Insurance
    • Benefit Plans
  • Bank Resources
    • Preferred Vendors
    • Associate Members
    • Marketing Resources
    • Financial Literacy
    • Single Bank Pooled ​Collateral Program
    • Bank Security
    • Compensation & Benefits Survey
  • About
    • Membership
    • News
    • Boards and Committees
    • Alice Dittman Trailblazer Award
    • NBA Foundation
    • Leadership Program
    • Staff Directory >
      • Contact Us
  • Workforce
    • Careers
    • Post Job Openings
  • Advocacy
    • Legislative Update
    • BankPAC
    • Comment Letters
  • Compliance
    • Handbook
    • Compliance Update
    • Compliance Alliance
  • Education
    • Event Calendar
    • In-person Events/Training
    • Webinars
    • ABA Training
    • Banking Schools
    • CYBERSECURITY TRAINING
    • Sponsorships and Exhibits
    • Young Bankers (YBON)
  • Insurance
    • Agency Services >
      • Commercial Insurance
      • Personal Insurance
      • Livestock, Irrigation and Farm Insurance
      • Surety Bonds
    • Bank Property & Liability
    • Financial Institution Insurance
    • Benefit Plans
  • Bank Resources
    • Preferred Vendors
    • Associate Members
    • Marketing Resources
    • Financial Literacy
    • Single Bank Pooled ​Collateral Program
    • Bank Security
    • Compensation & Benefits Survey

GUIDANCE ON MITIGATING RISK POSED BY INFORMATION STORED ON PHOTOCOPIERS, FAX MACHINES AND PRINTERS

The FDIC has issued guidance, which describes the risk posed by sensitive information stored on certain electronic devices and how institutions should mitigate that risk. 

A.        Risk

Photocopiers, fax machines and printers may contain a hard drive or flash memory that stores digital images ofthe documents that are copied, transmitted or printed by the device. Financial institutions use these devices regularly to process loans and other financial transactions on behalf of their customers. Loan documents and other business documents often contain sensitive and confidential information concerning financial institution customers.

Many financial institutions lease photocopiers, fax machines and printers for a set period of time. At the end of the lease period, the devices are returned to the leasing company and either sold or leased again. Anyone who takes subsequent possession of a device that was used by a financial institution may be able to access the hard drive orflash memory and view digital images of the documents that were processed by the device, thus giving them access to sensitive personal and business information concerning the institution’s customers.

B.        Controls

Financial institutions should be aware of the risks posed by the potential disclosure of sensitive customer information stored on the hard drive or flash memory of photocopiers, fax machines and printers used by the institution. Financial institutions should implement written policies and procedures to identify devices that store digital images of business documents and ensure their hard drive or flash memory is erased, encrypted or destroyed prior to being returned to the leasing company, sold to a third party or otherwise disposed of. If the institution chooses to erase or encrypt the hard drive, the method used should be sufficiently robust to render the information on the disk unrecoverable. Examiners may ask to review such policies and procedures and verify that they have been effectively implemented.

 

Compliance Handbook Search

*
  • Volume I
    • Compliance Management
    • Governance
    • Bank Structure
    • Personnel
    • Record Retention
    • Public Disclosure
    • Privacy
    • Security
    • CFPB
  • Volume II
    • Deposit Accounts
    • Public Funds
    • Bank Promotion
    • Nondeposit Products
    • Unclaimed Property
  • Volume III
    • Secured Transactions
    • Real Estate
    • Lending
    • Environmental Issues
    • Miscellaneous

STAY CONNECTED

Contact Us

Nebraska Bankers Association

233 South 13th Street, Suite 700
Lincoln, NE 68508
​402-474-1555
​Digital Millennium Copyright Act Policy
Member Login