The federal bank regulatory agencies issued a joint statement describing enhanced security procedures for reviewing sensitive information in the examinations of supervised banks.
The statement discusses a coordinated approach to identifying highly sensitive data and documents and discusses enhanced procedures for the review of such information. This is key to reducing cybersecurity risks and ensures that the agencies have access to such information at all times during an examination.
The agencies recognize the importance of keeping a bank’s highly sensitive information confidential and protecting it against disclosure to or from access by unauthorized persons as a result of cybersecurity vulnerabilities.
“The FBAs (federal banking agencies) acknowledge that certain categories of data and documents have additional levels of sensitivity and heightened risks from disclosure (referenced as highly sensitive information). These may include, but are not limited to, documents and data that contain detailed information on technology/network diagrams and schematics; detailed penetration test results; technical details of specific information technology control weaknesses; and succession planning. The FBAs have used various methods for handling such highly sensitive information in a manner that balances the requirements of effective examination with the need to minimize the risk of exposure. This coordinated approach provides greater alignment of these practices across the FBAs and examination teams,” the statement reads.
The agencies have committed to notify affected banks of any potential or confirmed material data breach involving confidential supervisory information. They will do so as soon as practicable, and no later than 72 hours after discovery, unless legal restrictions apply.
The federal banking agencies include the Board of Governors of the Federal Reserve System, the Federal Deposit Insurance Corporation, and the Office of the Comptroller of the Currency.