Respondents are all federally insured credit unions, which are required by 12 CFR Part 748 to develop a written security program to safeguard sensitive member information. This information collection requires that such programs be designed to respond to incidents of unauthorized access or use, in order to prevent substantial harm or serious inconvenience to members.
US Code:
15 USC 6801
Name of Law: Title V of the Gramm-Leach-Bliley Act
The proposed rule would require FICUs to notify the appropriate NCUA-designated point of contact of the occurrence of a reportable cyber incident via email, telephone, or other similar methods that the NCUA may prescribe. The information collection requirements associated with 12 CFR part 748 are cleared under OMB control number 3133-0033 and provide for catastrophic act reporting and GLBA incident reporting guidance under Appendix B to part 748. The proposed rule adds a cyber incident reporting under § 748.1(c) where FICUs would be required to report these incidents, as defined. The burden associated with the reporting requirements identified under Appendix B will be removed because most reporting will now fall under the new cyber incident requirement. The NCUA estimates a one-hour annual reporting burden on each FICU, for a total of 4,903 hours.
An adjustment is being made to reflect the current number of FICUs and to provide for a more accurate response rate per respondent. A total reduction of 146,682 burden hours is due to this adjustment.
On behalf of this Federal agency, I certify that the collection of information encompassed by this request complies with 5 CFR 1320.9 and the related provisions of 5 CFR 1320.8(b)(3).
The following is a summary of the topics, regarding the proposed collection of information, that the certification covers:
(i) Why the information is being collected;
(ii) Use of information;
(iii) Burden estimate;
(iv) Nature of response (voluntary, required for a benefit, or mandatory);
(v) Nature and extent of confidentiality; and
(vi) Need to display currently valid OMB control number;
If you are unable to certify compliance with any of these provisions, identify the item by leaving the box unchecked and explain the reason in the Supporting Statement.