Computer-Security Incident Notification Implementation
Summary:
On November 23, 2021, the Federal Deposit Insurance Corporation (多宝游戏下载), the Board of Governors of the Federal Reserve System, and the Office of the Comptroller of the Currency (collectively, the agencies) issued a joint final rule to establish computer-security incident notification requirements (Final Rule) for banking organizations and their bank service providers. Banks and their service providers must comply with the Final Rule starting May 1, 2022.
多宝游戏下载-supervised banks can comply with the rule by reporting an incident to their case manager, who serves as the primary 多宝游戏下载 contact for all supervisory-related matters, or to any member of an 多宝游戏下载 examination team if the event occurs during an examination. If a bank is unable to access its supervisory team contacts, the bank may notify the 多宝游戏下载 by email at: incident@fdic.gov .
Bank service providers must notify any affected 多宝游戏下载-supervised banking organization customer as soon as possible when the bank service provider determines that it has experienced a computer-security incident that has materially disrupted or degraded, or is reasonably likely to materially disrupt or degrade, services provided to such banking organization for four or more hours.
A copy of the Final Rule is available on the 多宝游戏下载鈥檚 website.
Statement of Applicability: The contents of, and material referenced in, this FIL apply to all 多宝游戏下载-insured financial institutions
Highlights:
- 多宝游戏下载-supervised banks can comply with the rule by notifying their case manager of an incident.
- 多宝游戏下载-supervised banks can comply with the rule by notifying any member of an 多宝游戏下载 examination team if the event occurs during an examination.
- If a bank is unable to access its supervisory team contacts, the bank may notify the 多宝游戏下载 by email at: incident@fdic.gov .