Where Cybersecurity Talent, Opportunity, and Trust Connect.

U.S. Banking Regulators Strengthen Handling of Highly Sensitive Examination Information

Financial cybersecurity team reviewing encrypted examination records inside a controlled data boundary
Financial regulation

Governance update

The Federal Reserve, FDIC and OCC announced enhanced procedures intended to reduce the cyber risk associated with highly sensitive bank examination information.

At a glance

  • The agencies will prefer reviewing highly sensitive information at a bank's premises rather than transferring it to agency systems when practicable.
  • Covered banks will be notified of a potential or confirmed material breach involving their information no later than 72 hours after discovery unless law restricts notification.
  • The changes focus on reducing concentration and transfer risk around sensitive supervisory data.
  • The announcement applies to the agencies' examination-information handling, not a replacement for banks' own incident-notification duties.

Copyright

© SecurityTalent.com — original summary and analysis

  13 Hits

Mozilla Root Store Policy 3.1 Takes Effect for Certificate Authorities

Security operations team reviewing Mozilla Root Store Policy 3.1 Takes Effect for Certificate Authorities
Trust policy update

Review certificate governance

Mozilla Root Store Policy version 3.1 became effective July 1, changing the governance baseline for certificate authorities trusted by Mozilla products.

At a glance

  • The policy governs root-store participation and certificate-authority obligations.
  • PKI, trust-service and compliance teams should compare current controls with the effective policy.

Copyright

© SecurityTalent.com — original summary and analysis

  13 Hits