27.2 Information Security Programs and Incident Investigation

Key Takeaways

  • A bank information-security program addresses risk assessment, safeguards, testing and service providers.

  • Incident investigation determines affected information and the likelihood of misuse.

  • The banking agencies’ safeguards requirements differ from the FTC rule for entities within FTC jurisdiction.

Last updated: October 2026

1. Statutory Mandate and Core Safeguard Objectives

Section 501(b) of the GLBA mandates that each federal functional banking regulator establish administrative, technical, and physical standards for financial institutions under its supervisory jurisdiction. Under Section II of the Interagency Guidelines, an institution's information security program must be designed to achieve three foundational statutory objectives:

  1. Ensure the Security and Confidentiality of Customer Information: Maintaining the privacy and integrity of customer records across all paper, electronic, and voice systems;
  2. Protect Against Anticipated Threats or Hazards: Defending customer records and systems against reasonably foreseeable internal and external cyber threats, environmental hazards, and operational failures;
  3. Protect Against Unauthorized Access or Use: Preventing unauthorized access to or use of customer information that could result in substantial harm or inconvenience to any customer.

2. Information Security Program Architecture

Every depository institution must establish, implement, and maintain a comprehensive Written Information Security Program (WISP) scaled to the bank's size, operational complexity, and the nature and scope of its activities.

Board of Directors and Executive Governance

Governance under the Interagency Guidelines is anchored directly in the Board of Directors:

  • Board Approval: The Board of Directors (or a designated Board committee, such as the Board Risk Committee or Audit Committee) must approve the written information security program and oversee its development, implementation and maintenance. The guidelines separately require management’s status report at least annually.
  • Oversight Accountability: The Board oversees the development, implementation, and maintenance of the program, assigning specific management responsibility for coordinating information security across business lines.
  • Mandatory Annual Board Report: Senior executive management must report to the Board or its designated committee at least annually on the overall status of the information security program. Under Section III.F of the Guidelines, the report must address:
    1. The overall status of the program and compliance with the Interagency Guidelines;
    2. The results of the enterprise-wide information security risk assessment;
    3. Risk management and control decisions (including resource allocation and control investments);
    4. Service provider arrangements and third-party oversight reviews;
    5. Results of independent testing (vulnerability assessments and penetration testing);
    6. Security incidents or violations, management's remediation responses, and regulatory communications; and
    7. Recommendations for changes to the information security program.

Enterprise Risk Assessment Process

The information security program must be grounded in an ongoing risk assessment methodology under which the institution:

  • Identifies reasonably foreseeable internal and external threats that could result in unauthorized disclosure, misuse, alteration, or destruction of customer information or customer information systems;
  • Assesses the likelihood and potential damage of these threats, taking into consideration the sensitivity of customer records;
  • Assesses the sufficiency of existing policies, procedures, customer information systems, and operational safeguards to mitigate identified risks.

Comprehensive Safeguard Controls

Depository institutions must implement layered administrative, technical, and physical safeguards across the information lifecycle:

  • Technical safeguards: Select controls based on the risk assessment, including access restrictions, authentication, encryption, monitoring, vulnerability management and testing. TLS 1.3, AES-256, SIEM and EDR are possible implementations; the bank guidelines do not mandate these product choices or an annual external penetration test for every institution.

Third-Party Service Provider Oversight

Under the Interagency Guidelines, financial institutions maintain non-delegable legal accountability for safeguarding customer information entrusted to third-party vendors. The bank must implement a structured third-party risk management framework encompassing:

  1. Due Diligence: Conducting comprehensive pre-contract due diligence to evaluate the adequacy of a prospective service provider's information security architecture, operational resilience, and compliance history;
  2. Contractual Mandates: Requiring service providers by contract to implement appropriate security measures designed to meet the objectives of the Interagency Guidelines, restrict data redisclosure, and mandate prompt incident notification;
  3. Ongoing Monitoring: Conducting ongoing vendor oversight through risk-appropriate reviews of independent control reports, testing and other evidence; an annual SOC 2 Type II report is not universally required.

3. Incident Response & Customer Notice (Supplement A to Appendix B)

Promulgated by the federal banking agencies as Supplement A to Appendix B, the Interagency Guidance on Response Programs for Unauthorized Access to Customer Information and Customer Notice establishes explicit requirements for responding to security breaches involving customer data.

Mandatory Incident Response Program Components

Every depository institution must implement a written incident response program that includes procedures for:

  • Assessing the nature and scope of an incident and identifying what customer information systems and customer information have been accessed or compromised;
  • Notifying the bank's primary federal banking regulator as soon as possible once the bank becomes aware of unauthorized access to sensitive customer information;
  • Notifying appropriate law enforcement agencies (e.g., local police, FBI, U.S. Secret Service) and filing a timely Suspicious Activity Report (SAR) in compliance with FinCEN regulations;
  • Taking immediate containment and control measures (such as isolating compromised servers, revoking credentials, or applying firewall blocks) to prevent further unauthorized access; and
  • Delivering customer notice when legally required.

Customer notice standard: Investigate unauthorized access to sensitive customer information. If the bank determines that misuse has occurred or is reasonably possible, notify affected customers as soon as possible, subject to an authorized law-enforcement delay. The investigation trigger and the notice conclusion are distinct.

Test Your Knowledge

Under the Interagency Guidelines Establishing Information Security Standards (12 CFR Part 30, Appendix B / Part 364, Appendix B), which of the following duties is specifically established as a mandatory governance responsibility of the bank's Board of Directors or an authorized Board committee?

A

Directly supervising the configuration of multi-factor authentication policies for frontline teller workstations.

B

Executing semi-annual vulnerability penetration tests against internal wire transfer production servers.

C

Conducting daily intrusion detection log reviews and managing automated endpoint threat quarantines.

D

Approving the written information security program and receiving an annual report on program status, risk assessments, and incidents.

Sections you finish are checked off in the contents.