ConceptioArchiveCode of Federal Regulations (eCFR)
Code of Federal Regulations (eCFR)public full text

12 CFR Part 748 — Security Program, Suspicious Transactions, Catastrophic Acts, Cyber Incidents, and Bank Secrecy Act Compliance

Office of the Federal Register (NARA) · Code of Federal Regulations (eCFR, Office of the Federal Register)
Code of Federal Regulations (eCFR) · Legal · License: Public Domain
Open Source ↗
united states, us regulation, us federal regulation, code of federal regulations, cfr, federal regulation, 12, 748, part 748, 12 cfr 748, 12 cfr part 748, banks, and, banking, national credit union administration, regulations affecting credit unions

PART 748—SECURITY PROGRAM, SUSPICIOUS TRANSACTIONS, CATASTROPHIC ACTS, CYBER INCIDENTS, AND BANK SECRECY ACT COMPLIANCE Authority: 12 U.S.C. 1766(a), 1786(b)(1), 1786(q), 1789(a)(11); 15 U.S.C. 6801-6809; 31 U.S.C. 5311 and 5318. Editorial Note: Nomenclature changes to part 748 appear at 84 FR 1609, Feb. 5, 2019. § 748.0 Security program. (a) Each federally insured credit union will develop a written security program within 90 days of the effective date of insurance. (b) The security program will be designed to: (1) Protect each credit union office from robberies, burglaries, larcenies, and embezzlement; (2) Ensure the security and confidentiality of member records, protect against the anticipated threats or hazards to the security or integrity of such records, and protect against unauthorized access to or use of such records that could result in substantial harm or serious inconvenience to a member; (3) Respond to incidents of unauthorized access to or use of member information that could result in substantial harm or serious inconvenience to a member; (4) Assist in the identification of persons who commit or attempt such actions and crimes, and (5) Prevent destruction of vital records, as defined in 12 CFR part 749. (c) Each Federal credit union, as part of its information security program, must properly dispose of any consumer information the Federal credit union maintains or otherwise possesses, as required under § 717.83 of this chapter. [50 FR 53295, Dec. 31, 1985, as amended at 53 FR 4845, Feb. 18, 1988; 66 FR 8161, Jan. 30, 2001; 69 FR 69274, Nov. 29, 2004; 70 FR 22778, May 2, 2005] § 748.1 Filing of reports. (a) The president or managing official of each federally insured credit union must certify compliance with the requirements of this part in its Credit Union Profile annually through NCUA's online information management system. (b) Catastrophic act report. (c) Cyber incident report. reportable cyber incident (1) Reportable cyber incident. (A) A substantial loss of confidentiality, integrity, or availability of a network or member information system as defined in appendix A, section I.B.2. e., of this part that results from the unauthorized access to or exposure of sensitive data, disrupts vital member services as defined in § 749.1 of this chapter, or has a serious impact on the safety and resiliency of operational systems and processes. (B) A disruption of business operations, vital member services, or a member information system resulting from a cyberattack or exploitation of vulnerabilities. (C) A disruption of business operations or unauthorized access to sensitive data facilitated through, or caused by, a compromise of a credit union service organization, cloud service provider, or other third-party data hosting provider or by a supply chain compromise. (ii) A reportable cyber incident (2) Definitions. Compromise Confidentiality Cyber incident Cyberattack Disruption Integrity Sensitive data (d) Suspicious Activity Report. credit union official (1) Reportable activity. Transaction (i) Insider abuse involving any amount. (ii) Transactions aggregating $5,000 or more where a suspect can be identified. (iii) Transactions aggregating $25,000 or more regardless of potential suspects. (iv) Transactions aggregating $5,000 or more that involve potential money laundering or violations of the Bank Secrecy Act. (A) The transaction involves funds derived from illegal activities or is intended or conducted in order to hide or disguise funds or assets derived from illegal activities (including, without limitation, the ownership, nature, source, location, or control of such funds or assets) as part of a plan to violate or evade any Federal law or regulation or to avoid any transaction reporting requirement under Federal law; (B) The transaction is designed to evade any regulations promulgated under the Bank Secrecy Act; or (C) The transaction has no business or apparent lawful purpose or is not the sort of transaction in which the particular member would normally be expected to engage, and the credit union knows of no reasonable explanation for the transaction after examining the available facts, including the background and possible purpose of the transaction. (v) Exceptions. (2) Filing procedures Timing. (ii) Content. http://www.ncua.gov, http://www.fincen.gov. (iii) Compliance. (3) Retention of Records. (4) Notification to board of directors Generally. (ii) Suspect is a director or committee member. (5) Confidentiality of reports. (6) Safe Harbor. [50 FR 53295, Dec. 31, 1985, as amended at 53 FR 26232, July 12, 1988; 58 FR 17492, Apr. 5, 1993; 61 FR 11527, Mar. 21, 1996; 71 FR 62878, Oct. 27, 2006; 72 FR 42273, Aug. 2, 2007; 74 FR 35769, July 21, 2009; 76 FR 18366, Apr. 4, 2011; 78 FR 64885, Oct. 30, 2013; 88 FR 12816, Mar. 1, 2023] § 748.2 Procedures for monitoring Bank Secrecy Act (BSA) compliance. (a) Purpose. (b) Establishment of a BSA compliance program Program requirement. (2) Customer identification program. (c) Contents of compliance program. (1) Provide for a system of internal controls to assure ongoing compliance; (2) Provide for independent testing for compliance to be conducted by credit union personnel or outside parties; (3) Designate an individual responsible for coordinating and monitoring day-to-day compliance; and (4) Provide training for appropriate personnel. (Approved by the Office of Management and Budget under control number 3133-0094) [52 FR 2861, Jan. 27, 1987, as amended at 52 FR 8062, Mar. 16, 1987; 68 FR 25112, May 9, 2003; 76 FR 18366, Apr. 4, 2011] Appendix A to Part 748—Guidelines for Safeguarding Member Information Table of Contents I. Introduction A. Scope B. Definitions II. Guidelines for Safeguarding Member Information A. Information Security Program B. Objectives III. Development and Implementation of Member Information Security Program A. Involve the Board of Directors B. Assess Risk C. Manage and Control Risk D. Oversee Service Provider Arrangements E. Adjust the Program F. Report to the Board I. Introduction The Guidelines for Safeguarding Member Information (Guidelines) set forth standards pursuant to sections 501 and 505(b), codified at 15 U.S.C. 6801 and 6805(b), of the Gramm-Leach-Bliley Act. These Guidelines provide guidance standards for developing and implementing administrative, technical, and physical safeguards to protect the security, confidentiality, and integrity of member information. These Guidelines also address standards with respect to the proper disposal of consumer information pursuant to sections 621(b) and 628 of the Fair Credit Reporting Act (15 U.S.C. 1681s(b) and 1681w). A. Scope. B. Definitions. In general. 2. For purposes of the Guidelines, the following definitions apply: a. Consumer information b. Consumer report c. Member d. Member information e. Member information system f. Service provider II. Standards for Safeguarding Member Information A. Information Security Program. B. Objectives. III. Development and Implementation of Member Information Security Program A. Involve the Board of Directors. 1. Approve the credit union's written information security policy and program; and 2. Oversee the development, implementation, and maintenance of the credit union's information security program, including assigning specific responsibility for its implementation and reviewing reports from management. B. Assess Risk. 1. Identify reasonably foreseeable internal and external threats that could result in unauthorized disclosure, misuse, alteration, or destruction of member information or member information systems; 2. Assess the likelihood and potential damage of these threats, taking into consideration the sensitivity of member information; and 3. Assess the sufficiency of policies, procedures, member information systems, and other arrangements in place to control risks. C. Manage and Control Risk. 1. Design its information security program to control the identified risks, commensurate with the sensitivity of the information as well as the complexity and scope of the credit union's activities. Each credit union must consider whether the following security measures are appropriate for the credit union and, if so, adopt those measures the credit union concludes are appropriate: a. Access controls on member information systems, including controls to authenticate and permit access only to authorized individuals and controls to prevent employees from providing member information to unauthorized individuals who may seek to obtain this information through fraudulent means; b. Access restrictions at physical locations containing member information, such as buildings, computer facilities, and records storage facilities to permit access only to authorized individuals; c. Encryption of electronic member information, including while in transit or in storage on networks or systems to which unauthorized individuals may have access; d. Procedures designed to ensure that member information system modifications are consistent with the credit union's information security program; e. Dual controls procedures, segregation of duties, and employee background checks for employees with responsibilities for or access to member information; f. Monitoring systems and procedures to detect actual and attempted attacks on or intrusions into member information systems; g. Response programs that specify actions to be taken when the credit union suspects or detects that unauthorized individuals have gained access to member information systems, including appropriate reports to regulatory and law enforcement agencies; and h. Measures to protect against destruction, loss, or damage of member information due to potential environmental hazards, such as fire and water damage or technical failures. 2. Train staff to implement the credit union's information security program. 3. Regularly test the key controls, systems and procedures of the information security program. The frequency and nature of such tests should be determined by the credit union's risk assessment. Tests should be conducted or reviewed by independent third parties or staff independent of those that develop or maintain the security programs. 4. Develop, implement, and maintain, as part of its information security program, appropriate measures to properly dispose of member information and consumer information in accordance with the provisions in paragraph III. D. Oversee Service Provider Arrangements. 1. Exercise appropriate due diligence in selecting its service providers; 2. Require its service providers by contract to implement appropriate measures designed to meet the objectives of these guidelines; and 3. Where indicated by the credit union's risk assessment, monitor its service providers to confirm that they have satisfied their obligations as required by paragraph D.2. As part of this monitoring, a credit union should review audits, summaries of test results, or other equivalent evaluations of its service providers. E. Adjust the Program. F. Report to the Board. [66 FR 8161, Jan. 30, 2001, as amended at 69 FR 69274, Nov. 29, 2004; 77 FR 71085, Nov. 29, 2012; 78 FR 32545, May 31, 2013; 84 FR 1609, Feb. 5, 2019] Appendix B to Part 748—Guidance on Response Programs for Unauthorized Access to Member Information and Member Notice I. Background This appendix provides guidance on NCUA's Security Program, Suspicious Transactions, Catastrophic Acts, Cyber Incidents, and Bank Secrecy Act Compliance regulation, 1 1 A. Security Guidelines Section 501(b) of the GLBA required the NCUA to establish appropriate standards for credit unions subject to its jurisdiction that include administrative, technical, and physical safeguards to protect the security and confidentiality of member information. Accordingly, the NCUA amended Part 748 of its rules to require credit unions to develop appropriate security programs, and issued appendix A, reflecting its expectation that every federally insured credit union would develop an information security program designed to: 1. Ensure the security and confidentiality of member information; 2. Protect against any anticipated threats or hazards to the security or integrity of such information; and 3. Protect against unauthorized access to or use of such information that could result in substantial harm or inconvenience to any member. B. Risk Assessment and Controls 1. Appendix A directs every credit union to assess the following risks, among others, when developing its information security program: a. Reasonably foreseeable internal and external threats that could result in unauthorized disclosure, misuse, alteration, or destruction of member information or member information systems; b. The likelihood and potential damage of threats, taking into consideration the sensitivity of member information; and c. The sufficiency of policies, procedures, member information systems, and other arrangements in place to control risks. 2 2 See 2. Following the assessment of these risks, appendix A directs a credit union to design a program to address the identified risks. The particular security measures a credit union should adopt will depend upon the risks presented by the complexity and scope of its business. At a minimum, the credit union should consider the specific security measures enumerated in appendix A, 3 3 See a. Access controls on member information systems, including controls to authenticate and permit access only to authorized individuals and controls to prevent employees from providing member information to unauthorized individuals who may seek to obtain this information through fraudulent means; b. Background checks for employees with responsibilities for access to member information; and c. Response programs that specify actions to be taken when the credit union suspects or detects that unauthorized individuals have gained access to member information systems, including appropriate reports to regulatory and law enforcement agencies. 4 4 See C. Service Providers Appendix A advises every credit union to require its service providers by contract to implement appropriate measures designed to protect against unauthorized access to or use of member information that could result in substantial harm or inconvenience to any member. 5 5 See II. Response Program i. Millions of Americans, throughout the country, have been victims of identity theft. 6 7 8 9 6 See Identity Theft Survey Report, http://www.ftc.gov/os/2003/09synovatereport.pdf. 7 8 member information systems See 9 See http://www.ffiec.gov/ffiecinfobase/html_pages/it_01.htm1#infosec, ii. In addition, each credit union should be able to address incidents of unauthorized access to member information in member information systems maintained by its domestic and foreign service providers. Therefore, consistent with the obligations in this Guidance that relate to these arrangements, and with existing guidance on this topic issued by the NCUA, 10 10 See http://www.ffiec.gov/ffiecinfobase/html_pages/it_01.htm1#outscouring A. Components of a Response Program 1. At a minimum, a credit union's response program should contain procedures for the following: a. Assessing the nature and scope of an incident, and identifying what member information systems and types of member information have been accessed or misused; b. Notifying the appropriate NCUA Regional Director, and, in the case of state-chartered credit unions, its applicable state supervisory authority, as soon as possible when the credit union becomes aware of an incident involving unauthorized access to or use of sensitive member information as defined below. c. Consistent with the NCUA's Suspicious Activity Report (“SAR”) regulations, 11 11 d. Taking appropriate steps to contain and control the incident to prevent further unauthorized access to or use of member information, for example, by monitoring, freezing, or closing affected accounts, while preserving records and other evidence; 12 12 See e. Notifying members when warranted. 2. Where an incident of unauthorized access to member information involves member information systems maintained by a credit union's service providers, it is the responsibility of the credit union to notify the credit union's members and regulator. However, a credit union may authorize or contract with its service provider to notify the credit union's members or regulators on its behalf. III. Member Notice i. Credit unions have an affirmative duty to protect their members' information against unauthorized access or use. Notifying members of a security incident involving the unauthorized access or use of the member's information in accordance with the standard set forth below is a key part of that duty. ii. Timely notification of members is important to manage a credit union's reputation risk. Effective notice also may reduce a credit union's legal risk, assist in maintaining good member relations, and enable the credit union's members to take steps to protect themselves against the consequences of identity theft. When member notification is warranted, a credit union may not forgo notifying its customers of an incident because the credit union believes that it may be potentially embarrassed or inconvenienced by doing so. A. Standard for Providing Notice When a credit union becomes aware of an incident of unauthorized access to sensitive member information, the credit union should conduct a reasonable investigation to promptly determine the likelihood that the information has been or will be misused. If the credit union determines that misuse of its information about a member has occurred or is reasonably possible, it should notify the affected member as soon as possible. Member notice may be delayed if an appropriate law enforcement agency determines that notification will interfere with a criminal investigation and provides the credit union with a written request for the delay. However, the credit union should notify its members as soon as notification will no longer interfere with the investigation. 1. Sensitive Member Information Under Part 748.0, a credit union must protect against unauthorized access to or use of member information that could result in substantial harm or inconvenience to any member. Substantial harm or inconvenience is most likely to result from improper access to sensitive member information For purposes of this Guidance, sensitive member information means a member's name, address, or telephone number, in conjunction with the member's social security number, driver's license number, account number, credit or debit card number, or a personal identification number or password that would permit access to the member's account. Sensitive member information 2. Affected Members If a credit union, based upon its investigation, can determine from its logs or other data precisely which members' information has been improperly accessed, it may limit notification to those members with regard to whom the credit union determines that misuse of their information has occurred or is reasonably possible. However, there may be situations where the credit union determines that a group of files has been accessed improperly, but is unable to identify which specific member's information has been accessed. If the circumstances of the unauthorized access lead the credit union to determine that misuse of the information is reasonably possible, it should notify all members in the group. B. Content of Member Notice 1. Member notice should be given in a clear and conspicuous manner. The notice should describe the incident in general terms and the type of member information that was the subject of unauthorized access or use. It also should generally describe what the credit union has done to protect the members' information from further unauthorized access. In addition, it should include a telephone number that members can call for further information and assistance. 13 13 a. A recommendation that the member review account statements and immediately report any suspicious activity to the credit union; b. A description of fraud alerts and an explanation of how the member may place a fraud alert in the member's consumer reports to put the member's creditors on notice that the member may be a victim of fraud; c. A recommendation that the member periodically obtain credit reports from each nationwide credit reporting agency and have information relating to fraudulent transactions deleted; d. An explanation of how the member may obtain a credit report free of charge; and e. Information about the availability of the FTC's online guidance regarding steps a consumer can take to protect against identity theft. The notice should encourage the member to report any incidents of identity theft to the FTC, and should provide the FTC's Web site address and toll-free telephone number that members may use to obtain the identity theft guidance and report suspected incidents of identity theft. 14 14 http://www.ftc.gov/idtheft 2. NCUA encourages credit unions to notify the nationwide consumer reporting agencies prior to sending notices to a large number of members that include contact information for the reporting agencies. C. Delivery of Member Notice Member notice should be delivered in any manner designed to ensure that a member can reasonably be expected to receive it. For example, the credit union may choose to contact all members affected by telephone or by mail, or by electronic mail for those members for whom it has a valid e-mail address and who have agreed to receive communications electronically. [70 FR 22778, May 2, 2005, as amended at 85 FR 62214, Oct. 2, 2020; 88 FR 12817, Mar. 1, 2023; 89 FR 79393, Sept. 30, 2024]

Related documents

Record · ID 505491 · SHA-256 04acdb22dd03d902
Retrieved via Conceptio — every document is proof-bundled with source, license, and retrieval metadata.