Updates to conform with standards and evolving risks were made to the national bank regulator’s Cybersecurity Supervision Work Program (CSW), but none of the changes affect banks’ regulatory compliance responsibilities, according to an announcement Monday.
“The CSW does not establish new regulatory expectations, and banks are not expected to use this work program to assess cybersecurity preparedness,” the Office of the Comptroller of the Currency (OCC) said in its Bulletin 2026-48, issued Monday. “The OCC continues to encourage, but does not require, the use of a standardized approach to assess and improve cybersecurity preparedness, and banks may choose from a variety of tools and frameworks available.”
The OCC’s website says the CSW is a component of the agency’s risk-based bank information technology supervision process. It says the CSW provides high-level examination objectives and procedures that are aligned with existing supervisory guidance and the National Institute of Standards and Technology (NIST) Cybersecurity Framework (CSF). Monday’s announced updates maintain that alignment. Monday’s announcement says the program maps to the Federal Financial Institutions Examination Council (FFIEC) Information Technology (IT) Examination Handbook and common cybersecurity frameworks.
Monday’s bulletin rescinds OCC Bulletin 2023-22, “Cybersecurity: Cybersecurity Supervision Work Program,” issued June 26, 2023, the agency said.
Leave a Reply