OCCRulemakingOCC-2020-0038

Who commented on this docket

Computer Security Incident Notification

2 organizations filed 2 public comments on Computer Security Incident Notification, at the Office of the Comptroller of the Currency. The comment window closed 1933d ago.

Organizations
2
Comments
2
RIN
Comment window
closed 1933d ago

Abstract

The OCC, Board, and FDIC are issuing a final rule that requires a banking organization to notify its primary Federal regulator of any ‘‘computer-security incident’’ that rises to the level of a ‘‘notification incident,’’ as soon as possible and no later than 36 hours after the banking organization determines that a notification incident has occurred. The final rule also requires a bank service provider to notify each affected banking organization customer as soon as possible when the bank service provider determines that it has experienced a computer-security incident that has caused, or is reasonably likely to cause, a material service disruption or degradation for four or more hours.

Commenters (2)

View this docket on regulations.gov →

Attribution is name-based and imperfect. regulations.gov data is public record.