The FR 2231 covers the information
collections included in a final rule (Final Rule) promulgated by
the Board, Office of the Comptroller of the Currency (OCC), and
Federal Deposit Insurance Corporation (FDIC) (collectively, the
agencies) on November 23, 2021. The Final Rule requires a banking
organization to notify its primary Federal banking regulator of any
“computer-security incident” that rises to the level of a
“notification incident,” as soon as possible and no later than 36
hours after the banking organization determines that a notification
incident has occurred. The banking organizations for which the
Board serves as primary Federal banking regulator for the purposes
of the Final Rule are U.S. bank holding companies, U.S. savings and
loan holding companies, state member banks, U.S. operations of
foreign banking organizations, and Edge or agreement corporations.
The Final Rule also requires a bank service provider to notify each
affected banking organization customer as soon as possible when the
bank service provider determines that it has experienced an
unplanned computer-security incident that has caused, or is
reasonably likely to cause, a material service disruption or
degradation for four or more hours.
US Code:
12
USC 321-338a Name of Law: Federal Reserve Act
US Code: 12
USC 1844(b) Name of Law: Bank Holding Company Act of 1956
US Code: 12
USC 1467a(g) Name of Law: Home Owners’ Loan Act
US Code:
12 USC 1861-1867 Name of Law: Bank Service Company Act
US Code:
12 USC 3101 et seq. Name of Law: International Banking Act of
1978
This is a new collection. The
estimated total annual burden for the FR 2231 is 2,502 hours. For
both the reporting and the disclosure requirement, the agencies
estimate it will take up to 3 hours to comply with the reporting
and disclosure requirements.
On behalf of this Federal agency, I certify that
the collection of information encompassed by this request complies
with 5 CFR 1320.9 and the related provisions of 5 CFR
1320.8(b)(3).
The following is a summary of the topics, regarding
the proposed collection of information, that the certification
covers:
(i) Why the information is being collected;
(ii) Use of information;
(iii) Burden estimate;
(iv) Nature of response (voluntary, required for a
benefit, or mandatory);
(v) Nature and extent of confidentiality; and
(vi) Need to display currently valid OMB control
number;
If you are unable to certify compliance with any of
these provisions, identify the item by leaving the box unchecked
and explain the reason in the Supporting Statement.