Federal Banking Regulators Institute New Protocols for Protecting Highly Sensitive Supervisory Information
The FDIC, Federal Reserve, and OCC issued a joint statement announcing a coordinated approach for handling banks’ highly sensitive supervisory information, including protocols to minimize the risk of exposure.
Highly sensitive information can include, but is not limited to, documents and data containing detailed information about a supervised bank’s technology/network diagrams and schematics; detailed penetration test results; technical details of specific information technology control weaknesses; and succession planning. Banks that have concerns about their highly sensitive information should discuss the issue with their examiners, including what methods of protection to employ. Protocols to minimize the collection and storage of this information may include on-site review, direct digital review via access to the bank’s systems, or allowing submission of redacted or summarized versions of the information.
The agencies have also committed to notifying banks of potential or confirmed material compromises of confidential supervisory information as soon as practicable—and within no more than 72 hours—after the agency forms a reasonable basis to believe a compromise has occurred and determines which banks are affected (subject to applicable legal considerations).
The agencies will provide bank examiners with additional written guidance and training on the new information handling protocols. Examiners will also notify banks at the start of examinations that they may flag information as highly sensitive, as well as the process for banks to escalate concerns regarding examiner determinations on the identification and handling such information.
