Have you addressed the Computer-Security Incident Notification Requirements for Banking Organizations? Full compliance has been extended to May 1, 2022.
Five questions to ask:
- Have we updated our Incident Response Plan?
- Do we have documentation of who and how we will notify the regulators?
- Do our critical third party vendors have the correct contacts for notification?
- Has our Business Continuity Plan been updated to match the verbiage in the guidance?
- When is your next Incident Response Test and how will you update it?