USA Law and Practice Contributed by: Brock Dahl, Beth George, Timothy Howard and Megan Kayo, Freshfields
3.2 ICT Service Provider Contractual Requirements
The Interagency Guidelines Establishing Information Security Standards (the “Security Guidelines”) that derive from this statutory mandate require all financial institutions to have information security programmes that further the objectives of the Safeguards Rule. In 2020, the OCC and the FDIC published a Joint State - ment on Heightened Cybersecurity Risk (the “Joint Statement”), which elaborated on the Security Guide - lines. Cybersecurity risks are also addressed in the Intera - gency Guidelines Establishing Standards for Safety and Soundness (the “Safety and Soundness Guide - lines”), which set out broad safety and soundness standards against which financial institutions are eval - uated. As with other components of risk management, the prudential regulators expect a financial institution to tailor its cybersecurity risk management system to be proportionate to: • the institution’s size and complexity; and • to its risk profile. In 2020, the prudential regulators published intera - gency guidance on Sound Practices to Strengthen Operational Resilience (the “Sound Practices”), which brought together existing regulations, guidance, state - ments and common industry standards for operational resilience. Acknowledging cybersecurity risk as “one of the most important types of operational risk”, the Sound Practices include an appendix with sound practices for managing cyber-risk. The Federal Financial Institutions Examination Coun - cil (FFIEC) – an interagency body that promotes uni - formity in the supervision of financial institutions – has also published examination manuals and guidance on cybersecurity risk management, including the FFIEC IT Examination Handbook. Taken together, these rules, statements and guide - lines, as well as the FFIEC examination manuals and supplements, provide the prudential regulators’ most current standards regarding managing cybersecurity risk.
The Bank Service Company Act grants the prudential regulators statutory authority to supervise certain third parties that provide services to financial institutions. In the case of IT, these third-party service providers include core application processors, electronic funds transfer switches, internet banking providers, item processors, managed security service providers and data storage service providers. In October 2012, concurrently with the release of the Supervision of Technology Service Providers Book - let (the “TSP Booklet”) of the FFIEC’s IT Examination Handbook (described in 3.1 Scope of Financial Sec- tor Operational Resilience Regulation ), the prudential regulators also released the Administrative Guidelines on the Implementation of Interagency Programs for the Supervision of Technology Service Providers. The guidelines describe how technology service providers (TSPs) are assessed for risk using the Uniform Rat - ing System for Information Technology (URSIT). The URSIT score is used to determine the priority, frequen - cy and extent of the examinations of TSPs. TSPs are considered either significant service providers (SSPs), serving a large number of banks and posing a higher risk or regional service providers (RSPs), serving fewer banks and posing a lower risk. The multi-regional data processing servicer (MDPS) programme is a programme that specifically desig - nates for special monitoring and interagency supervi - sion TSPs that are considered “mission-critical” (vital to the successful continuance of a core business activity) for a large number of financial institutions that are regulated by more than one prudential regulator or provide services through a number of technology service centres located in diverse geographic regions. The prudential regulators also conduct shared appli - cation software reviews (SASRs) to review major software packages used by a significant number of financial institutions or for higher-risk applications in larger financial institutions (such as software pack - ages for use in wire transfer, capital markets or securi - ties transfer).
468 CHAMBERS.COM
Powered by FlippingBook