ConceptioArchiveCode of Federal Regulations (eCFR)
Code of Federal Regulations (eCFR)public full text

12 CFR Part 53 — Computer-Security Incident Notification

Office of the Federal Register (NARA) · Code of Federal Regulations (eCFR, Office of the Federal Register)
Code of Federal Regulations (eCFR) · Legal · License: Public Domain
Open Source ↗
departmentofthetreasury
united states, us regulation, us federal regulation, code of federal regulations, cfr, federal regulation, 12, 53, part 53, 12 cfr 53, 12 cfr part 53, banks, and, banking, comptroller of the currency, department of the treasury

PART 53—COMPUTER-SECURITY INCIDENT NOTIFICATION Authority: 12 U.S.C. 1, 93a, 161, 481, 1463, 1464, 1861-1867, and 3102. Source: 86 FR 66442, Nov. 23, 2021, unless otherwise noted. § 53.1 Authority, purpose, and scope. (a) Authority. (b) Purpose. (c) Scope. § 53.2 Definitions. (a) Except as modified in this part, or unless the context otherwise requires, the terms used in this part have the same meanings as set forth in 12 U.S.C. 1813. (b) For purposes of this part, the following definitions apply. (1) Banking organization (2) Bank service provider (3) Business line (4) Computer-security incident (5) Covered services (6) Designated financial market utility (7) Notification incident (i) Ability to carry out banking operations, activities, or processes, or deliver banking products and services to a material portion of its customer base, in the ordinary course of business; (ii) Business line(s), including associated operations, services, functions, and support, that upon failure would result in a material loss of revenue, profit, or franchise value; or (iii) Operations, including associated services, functions and support, as applicable, the failure or discontinuance of which would pose a threat to the financial stability of the United States. (8) Person § 53.3 Notification. A banking organization must notify the appropriate OCC supervisory office, or OCC-designated point of contact, about a notification incident through email, telephone, or other similar methods that the OCC may prescribe. The OCC must receive this notification from the banking organization as soon as possible and no later than 36 hours after the banking organization determines that a notification incident has occurred. § 53.4 Bank service provider notification. (a) A bank service provider is required to notify at least one bank-designated point of contact at each affected banking organization customer as soon as possible when the bank service provider determines that it has experienced a computer-security incident that has materially disrupted or degraded, or is reasonably likely to materially disrupt or degrade, covered services provided to such banking organization for four or more hours. (1) A bank-designated point of contact is an email address, phone number, or any other contact(s), previously provided to the bank service provider by the banking organization customer. (2) If the banking organization customer has not previously provided a bank-designated point of contact, such notification shall be made to the Chief Executive Officer and Chief Information Officer of the banking organization customer, or two individuals of comparable responsibilities, through any reasonable means. (b) The notification requirement in paragraph (a) of this section does not apply to any scheduled maintenance, testing, or software update previously communicated to a banking organization customer.

Related documents

Record · ID 505274 · SHA-256 e30c32b239aae2fb
Retrieved via Conceptio — every document is proof-bundled with source, license, and retrieval metadata.