American Bankers Association
OCCRulemakingOCC-2020-0038

Computer Security Incident Notification

RIN
Last modified
Jan 27, 2022
Comment window
closed 1933d ago
American Bankers Association filings
1

Activity

American Bankers Association filed 1 comment on this docket between Apr 14, 2021 and Apr 14, 2021. 1 other organizations filed here. The comment window closed 1933d ago.

What American Bankers Association filed (1)

Apr 14, 2021· OCC-2020-0038-0023

The American Bankers Association (ABA) appreciates the opportunity to respond to the January 2021 notice of proposed rulemaking, "Computer-Security Incident Notification Requirements for Banking Organizations and Their Bank Service Providers," jointly issued by the Federal Reserve Board of Governors, the Federal Deposit Insurance Corporation, and the Office of the Comptroller of the Currency.

Abstract

The OCC, Board, and FDIC are issuing a final rule that requires a banking organization to notify its primary Federal regulator of any ‘‘computer-security incident’’ that rises to the level of a ‘‘notification incident,’’ as soon as possible and no later than 36 hours after the banking organization determines that a notification incident has occurred. The final rule also requires a bank service provider to notify each affected banking organization customer as soon as possible when the bank service provider determines that it has experienced a computer-security incident that has caused, or is reasonably likely to cause, a material service disruption or degradation for four or more hours.

View on regulations.gov →