← Independent regulator rules (SEC/Fed/FDIC/SBA/FTC/NCUA/CPSC/FHFA/EEOC/NLRB)

Cyber Incident Notification Requirements for Federally Insured Credit Unions

NCUA · final-rule · Published 2023-03-01 · Effective 2023-09-01 · 88 FR 12811

Document

Document number
2023-03682
Federal Register citation
88 FR 12811
CFR reference
12 CFR 748
Type
Rule
Action
Final rule.
Category
final-rule
Agency
US National Credit Union Administration
Publication date
2023-03-01
Effective date
2023-09-01

Abstract

The National Credit Union Administration (NCUA or agency) is amending Part 748 of its regulations to require a federally insured credit union (FICU) that experiences a reportable cyber incident to report the incident to the NCUA as soon as possible and no later than 72 hours after the FICU reasonably believes that it has experienced a reportable cyber incident. This notification requirement provides an early alert to the NCUA and does not require a FICU to provide a detailed incident assessment to the NCUA within the 72-hour time frame.

Source

Authoritative
Federal Register document
Machine
JSON-LD · Markdown