I had dinner with a few CSO friends of mine the other night and heard a lot of grumbling about the “Red Flag Rules”. “Red Flag Rules” are provisions covered under Sections 114 and 315 of FACTA (the Fair and Accurate Credit Transactions Act of 2003) that require financial institutions to implement an identity theft prevention program to help stave off identity theft.Specifically, FACTA amended the Fair Credit Reporting Act to require the federal banking agencies and the National Credit Union Administration jointly: establish and maintain guidelines for use by each financial institution and each creditor regarding identity theft; prescribe regulations requiring each financial institution and each creditor to establish reasonable policies and procedures for implementing these guidelines in order to identify possible risks to account holders or customers or to the safety and soundness of the institution or customers; and, prescribe regulations applicable to card issuers to ensure that will flag typical indicators of fraud notify consumers about significant address discrepancies on their credit reports which may indicate fraudThese rules went into effect this past January 1st and require full compliance by November 1, 2008. Interestingly enough, they don’t seem to have gotten much attention so it begs the question, “are financial institutions going to meet the deadline?” If you are a financial institution as determined by the Equal Credit Opportunity Act (anyone who arranges for the extension, renewal, or continuation of credit, including third-party debt collectors) you have a little less than seven months to get this all together. Better get going.For more on CSO’s coverage of identity theft, check out Sarah Scalet’s article on “Five Ways to Fight Identity Theft“. Related content opinion Don’t let social media get you in trouble As social media has become more pervasive, it has run headlong into the inevitable intersection between our personal lives and our work lives. How to best manage that intersection is something everyone should understand. By Bob Bragdon Jan 14, 2019 4 mins Privacy Security opinion Remember: It’s not all about the 1s and 0s Don't forget the role of physical security in protecting your assets...even the digital ones By Bob Bragdon Nov 07, 2018 4 mins Physical Security Security opinion The rolling tide that is GDPR … say hello to the CCPA Think you dodged the GDPR bullet because you’re not in Europe? Guess again. California just brought that home for millions of businesses. By Bob Bragdon Aug 01, 2018 4 mins Regulation Compliance Privacy opinion The story of Mary Good information security isn't just about the 1s and 0s By Bob Bragdon Jun 20, 2018 4 mins Data and Information Security Security Podcasts Videos Resources Events SUBSCRIBE TO OUR NEWSLETTER From our editors straight to your inbox Get started by entering your email address below. Please enter a valid email address Subscribe