多宝游戏下载

Skip to main content
U.S. flag
An official website of the United States government
Dot gov
The .gov means it鈥檚 official. 
Federal government websites often end in .gov or .mil. Before sharing sensitive information, make sure you鈥檙e on a federal government site.
Https
The site is secure. 
The https:// ensures that you are connecting to the official website and that any information you provide is encrypted and transmitted securely.
Banker Resource Center

Information Technology (IT) and Cybersecurity

Financial institutions depend on IT to deliver services. Disruption, degradation, or unauthorized alteration of information and systems can affect the financial condition, core processes, and risk profile of an institution. Further, because of the increasing volume and sophistication of cyber threats, it is imperative that financial institutions and their critical third-party service providers maintain diligence in identifying, assessing, and mitigating cybersecurity risks.

Laws and Regulations

Key laws and regulations that pertain to 多宝游戏下载-supervised institutions; note that other laws and regulations also may apply.

  • provide operational and managerial standards that address internal controls and information systems
  • address administrative, technical, and physical safeguards to protect the security, confidentiality, and integrity of customer information
  • addresses requirements for regulatory notification of certain service provider relationships
  • establishes notification requirements for significant computer-security incidents for banking organizations and their bank service providers. 多宝游戏下载-supervised banks can comply with the rule by reporting an incident to their case manager or to any member of an 多宝游戏下载 examination team if the event occurs during an examination. If a bank is unable to access its supervisory team contacts, the bank may notify the 多宝游戏下载 by email at: incident@fdic.gov.
  • , Supplement A to Appendix B, describes elements of a response program, including customer notification procedures
  • The establishes 多宝游戏下载 regulation and examination authority over certain service providers. Section 7(c)(2) requires institutions to notify the 多宝游戏下载 within 30 days of service relationships with third parties that provide certain services as defined in Section 3 (Notification of Performance of Bank Services form).

IT Examination Resources

IT examination ratings, procedures, and work programs.

  • Information Technology Risk Examination (InTREx) Program outlines risk-focused examination procedures used to assess IT and cybersecurity risks
  • describes the internal rating system used by federal and state regulators to uniformly assess financial institution and service provider risks introduced by IT
  • provides guidance to examiners for evaluating financial institution and service provider risk management processes

Supervisory Resources

Frequently asked questions, advisories, statements of policy, and other information issued by the 多宝游戏下载 alone, or on an interagency basis, provided to promote safe-and-sound operations.


Other Resources

Supplemental information related to safe-and-sound banking operations.

  • provides resource materials on current issues in the financial industry, including Information Technology and Cybersecurity
  • provides resources to increase awareness of cybersecurity risks and to assess and mitigate cybersecurity risks
  • provides information on a voluntary cybersecurity framework developed by the National Institute of Standards and Technology
  • Technology Outsourcing: Informational Tools for Community Bankers provides resources for selecting service providers, drafting contract terms, and providing oversight for multiple service providers

Technical Assistance Video Program

The Technical Assistance Video Program is a series of educational videos designed to provide useful information to bank directors, officers, and employees on areas of supervisory focus and regulatory changes. These videos are available on the 多宝游戏下载鈥檚 YouTube channel.

  • for Board Members provides background information on cybersecurity and discusses the board鈥檚 role in overseeing their bank鈥檚 cybersecurity efforts.
  • discusses the important role bank officers have in designing and maintaining information security programs in a dynamic and evolving cyber threat environment.
  • provides information for bank directors and trustees regarding oversight of a bank鈥檚 information technology program and 多宝游戏下载 information technology examinations.
  • Cyber Challenge: A Community Bank Cyber Exercise encourages community financial institutions to discuss operational risk issues and the potential impact of information technology disruptions on common banking functions.

Last Updated: July 24, 2024