What's Happening?
The Office of the Comptroller of the Currency (OCC) has updated its Cybersecurity Supervision Work Program (CSW) used by examiners for national banks, federal savings associations, and federal branches and agencies. This update primarily focuses on aligning
the CSW's structure and references with the evolving National Institute of Standards and Technology (NIST) Cybersecurity Framework (CSF). The OCC emphasized that no new procedures were added, nor were any existing procedures changed in this update. The CSW continues to provide high-level examination objectives and procedures that are consistent with current supervisory guidance. The OCC encourages, but does not mandate, the use of standardized tools and frameworks for assessing cybersecurity preparedness, allowing banks to choose from various available options. This revision rescinds OCC Bulletin 2023-22, which was issued on June 26, 2023. The updated CSW is designed to be scalable for banks of different sizes and complexities, including community banks, enabling risk-based examination scoping.
Why It's Important?
This update is important because it reflects the continuous evolution of cyber threats and the banking sector's adoption of standardized cybersecurity assessment tools. By aligning its supervisory program with the NIST CSF, the OCC aims to ensure that its examination procedures remain relevant and effective in evaluating banks' cybersecurity risks. This alignment provides clarity and consistency for financial institutions, as the NIST CSF is a widely recognized and adopted framework for managing cybersecurity risk. While the OCC does not impose new regulatory expectations or require banks to use the CSW for self-assessment, its updated structure will guide examiners in their evaluations. This helps maintain the resilience of the U.S. financial system against cyberattacks, protecting both institutions and their customers from potential data breaches and financial losses. The scalability of the CSW ensures that even smaller community banks receive appropriate cybersecurity oversight, contributing to overall financial stability.
What's Next?
The updated CSW will be utilized by OCC examiners during their assessments of banks' cybersecurity preparedness. Financial institutions, particularly national banks, federal savings associations, and federal branches and agencies, should continue to monitor OCC guidance and ensure their cybersecurity programs are robust and adaptable to evolving threats. While not mandatory, banks may find it beneficial to review their own cybersecurity frameworks in light of the CSW's alignment with the NIST CSF to anticipate examination focus areas. The OCC will continue to make future changes to the CSW References page available through its official website, indicating an ongoing commitment to adapting its supervisory approach as the cybersecurity landscape changes. This iterative process suggests that banks should expect continuous updates and refinements in regulatory expectations regarding cybersecurity.
Beyond the Headlines
The OCC's decision to align its cybersecurity supervision with the NIST CSF underscores a broader trend towards standardization and best practices in critical infrastructure protection. This move highlights the increasing recognition that cybersecurity is not merely an IT issue but a fundamental component of operational resilience and risk management for financial institutions. The emphasis on a framework like NIST CSF promotes a common language and approach to cybersecurity, facilitating better communication and collaboration between regulators and regulated entities. This also implicitly encourages a culture of continuous improvement in cybersecurity, as the NIST CSF itself is designed to be adaptable and evolve with new threats and technologies. The long-term implication is a more harmonized and robust cybersecurity posture across the U.S. banking sector, potentially setting a precedent for other regulated industries.













