| Home > Banking > Supervision and Regulation |
| Circular |
|
Guidance Issued on Response Programs for Unauthorized Access to Customer Information and Customer Notice
|
|
December 7, 2005
|
|
| Circular No. 11752 | |
|
To All Depository Institutions and Others Concerned A joint Supervision and Regulation and Consumer Affairs Letter from the Board of Governors of the Federal Reserve System establishes the Federal Reserve’s expectations for financial institutions and supervisory personnel with respect to the Interagency Guidance on Response Programs for Unauthorized Access to Customer Information and Customer Notice (Guidance). The Guidance, which has been effective since March 29, 2005, interprets the Interagency Guidelines Establishing Information Security Standards (Security Guidelines) and states that each financial institution should implement a response program to address unauthorized access to customer information maintained by the institution or its service providers. The Guidance describes the components of a response program, including procedures to notify customers about incidents that involve unauthorized access to sensitive customer information. When evaluating the adequacy of a financial institution’s information security program required by the Security Guidelines, the Federal Reserve will consider whether the bank has developed and implemented a response program including notification procedures as described in the Guidance. An institution’s response program should contain procedures for the following:
Read the SR/CA letter and interagency guidance below for complete details. SR 05-23/CA 05-10 ››Interagency guidance ›› Contacts: John Ricketti
Contact: |

