FINANCE, POLICY & MARKETSPublished by Paul Ivinskas
fc.The Financial CurrentDAILY INTELLIGENCEWhat matters across finance
Back to newsfeed
Supervisory update

OCC updates cyber examination mapping without new procedures

The OCC’s September 21 cybersecurity bulletin updates the structure and references of its examiner work program to align with the evolving NIST framework. The agency explicitly says examination procedures are unchanged and no new regulatory expectations are created.

1 min read · estimatedAI-generated analysis · Methodology
Related research, policy & entities ↓
0% through article

Tap a dotted-underlined term for a definition. Use Aa in the navigation for reading preferences.

Analysis

Analysis: update control crosswalks and evidence ownership before treating the release as a new remediation mandate. The useful test is whether existing incident response, recovery and third-party evidence can be retrieved and explained under the revised mapping.

What remains uncertain

Banks are not required to use the OCC work program as their own assessment tool. A mapping change does not establish that a particular bank’s controls are sufficient.

Sources

Flag an error or suggest a correction →Public corrections log →