Security Program, 12 CFR 748

ICR 202209-3133-002

OMB: 3133-0033

Federal Form Document

Forms and Documents
Document
Name
Status
Supplementary Document
2022-10-11
Supporting Statement A
2022-10-04
IC Document Collections
IC ID
Document
Title
Status
32685
Modified
ICR Details
3133-0033 202209-3133-002
Received in OIRA 202001-3133-002
NCUA NPRM
Security Program, 12 CFR 748
Revision of a currently approved collection   No
Regular 10/11/2022
  Requested Previously Approved
36 Months From Approved 06/30/2023
93,307 159,240
240,397 382,176
0 0

Respondents are all federally insured credit unions, which are required by 12 CFR Part 748 to develop a written security program to safeguard sensitive member information. This information collection requires that such programs be designed to respond to incidents of unauthorized access or use, in order to prevent substantial harm or serious inconvenience to members.

US Code: 15 USC 6801 Name of Law: Title V of the Gramm-Leach-Bliley Act
  
None

3133-AF47 Proposed rulemaking 87 FR 45029 07/27/2022

No

1
IC Title Form No. Form Name
Security Program

  Total Request Previously Approved Change Due to New Statute Change Due to Agency Discretion Change Due to Adjustment in Estimate Change Due to Potential Violation of the PRA
Annual Number of Responses 93,307 159,240 0 4,903 -70,836 0
Annual Time Burden (Hours) 240,397 382,176 0 4,903 -146,682 0
Annual Cost Burden (Dollars) 0 0 0 0 0 0
Yes
Changing Regulations
No
The proposed rule would require FICUs to notify the appropriate NCUA-designated point of contact of the occurrence of a reportable cyber incident via email, telephone, or other similar methods that the NCUA may prescribe. The information collection requirements associated with 12 CFR part 748 are cleared under OMB control number 3133-0033 and provide for catastrophic act reporting and GLBA incident reporting guidance under Appendix B to part 748. The proposed rule adds a cyber incident reporting under § 748.1(c) where FICUs would be required to report these incidents, as defined. The burden associated with the reporting requirements identified under Appendix B will be removed because most reporting will now fall under the new cyber incident requirement. The NCUA estimates a one-hour annual reporting burden on each FICU, for a total of 4,903 hours. An adjustment is being made to reflect the current number of FICUs and to provide for a more accurate response rate per respondent. A total reduction of 146,682 burden hours is due to this adjustment.

$0
No
    No
    No
No
No
No
No
Gira Bose 703 518-6562 [email protected]

  No

On behalf of this Federal agency, I certify that the collection of information encompassed by this request complies with 5 CFR 1320.9 and the related provisions of 5 CFR 1320.8(b)(3).
The following is a summary of the topics, regarding the proposed collection of information, that the certification covers:
 
 
 
 
 
 
 
    (i) Why the information is being collected;
    (ii) Use of information;
    (iii) Burden estimate;
    (iv) Nature of response (voluntary, required for a benefit, or mandatory);
    (v) Nature and extent of confidentiality; and
    (vi) Need to display currently valid OMB control number;
 
 
 
If you are unable to certify compliance with any of these provisions, identify the item by leaving the box unchecked and explain the reason in the Supporting Statement.
10/11/2022


© 2024 OMB.report | Privacy Policy