FCA Examination Manual 31.7 (2025)
Overview of FCA Examination Manual 31.7 - Information Security
The Farm Credit Administration (FCA) Examination Manual Section 31.7, updated in 2025, provides detailed examination guidance specifically focused on information security programs at Farm Credit System (FCS) institutions. This manual section complements Section 31.6 (IT Risk Management) by drilling deeper into cybersecurity-specific requirements, controls, and examination procedures. Section 31.7 establishes FCA supervisory expectations for comprehensive information security programs protecting FCS institutions from cyber threats, ensuring borrower data confidentiality and integrity, and maintaining operational resilience against cyberattacks. FCA examiners use Manual 31.7 to evaluate cybersecurity program maturity, technical control effectiveness, and institutions' capabilities to prevent, detect, and respond to cyber incidents.
The 2025 update incorporates lessons from significant cybersecurity incidents affecting agricultural financial institutions, including ransomware attacks disrupting lending operations during critical agricultural seasons, data breaches exposing borrower financial and operational information, and business email compromise schemes targeting agricultural lending relationships. Manual 31.7 emphasizes defense-in-depth security architectures, continuous monitoring, rapid incident response, and cyber resilience enabling institutions to maintain critical lending services even during active cyberattacks. The manual recognizes that FCS institutions support America's agricultural economy and food supply chain—compromises affecting agricultural lending can have ripple effects through the agricultural sector requiring robust cybersecurity at FCS institutions.
Key Information Security Examination Areas
FCA Manual 31.7 examines information security across multiple domains, evaluating both technical controls and programmatic capabilities.
Information Security Program Structure
Examiners assess whether institutions maintain comprehensive information security programs with documented policies covering all security domains, risk-based security strategies aligned with threat environments and institution risk profiles, qualified information security leadership (CISO or equivalent) with appropriate authority and resources, regular security assessments identifying vulnerabilities and control gaps, metrics and reporting providing management and boards with security posture visibility, and continuous improvement processes incorporating lessons learned and emerging threats. Security programs should be proportionate to institution size and risk—small associations may have simpler programs while large institutions require sophisticated capabilities.
Access Control and Authentication
Access control receives detailed examination attention. Examiners evaluate user identification and authentication mechanisms including unique user IDs and strong passwords, multi-factor authentication for remote access and privileged accounts, role-based access control limiting users to necessary permissions, privileged access management with approval workflows and monitoring, automated provisioning and deprovisioning tied to HR processes, and regular access reviews validating appropriate authorizations. Institutions should demonstrate least privilege principles throughout access management, with particular scrutiny of administrative and database access permissions.
Network Security and Boundary Protection
Network security controls protect institution networks from unauthorized access and malicious activities. Examiners assess firewall configurations implementing principle of least privilege for network traffic, intrusion detection and prevention systems (IDS/IPS) monitoring for attack patterns, network segmentation separating sensitive systems from general networks, secure remote access through VPNs with multi-factor authentication, DMZ architectures isolating internet-facing systems, and network monitoring capabilities detecting anomalous traffic patterns. Institutions should maintain network diagrams, document firewall rules with business justifications, and regularly review network access permissions.
Malware Protection and Endpoint Security
Endpoint security controls prevent and detect malware on workstations and servers. Examiners evaluate anti-malware deployment on all endpoints with automatic signature updates, centralized management and reporting of endpoint security status, endpoint detection and response (EDR) for advanced threat detection, email security filtering blocking phishing and malicious attachments, web filtering preventing access to malicious sites, and application control preventing unauthorized software execution. Institutions should track endpoint security metrics including percentage of protected devices, malware detection incidents, and remediation timeframes.
Vulnerability and Patch Management
Timely vulnerability remediation prevents exploitation by threat actors. Examiners assess vulnerability scanning frequency and coverage across all systems, patch management processes with prioritization of critical vulnerabilities, testing procedures validating patches before production deployment, tracking and metrics demonstrating timely patching, and compensating controls for systems that cannot be patched promptly. Institutions should demonstrate that critical vulnerabilities in internet-facing systems are patched within two weeks, with documented exceptions and risk acceptance for delayed patching.
Encryption and Data Protection
Data protection controls safeguard sensitive borrower information. Examiners evaluate encryption of data at rest on mobile devices and portable media, encryption of data in transit over public networks or untrusted connections, encryption key management with secure key storage and rotation, data classification identifying sensitive information requiring protection, and data loss prevention technologies preventing unauthorized exfiltration. Financial institutions handling agricultural borrowers' financial statements, land ownership records, and production data must protect this sensitive information through appropriate encryption and access restrictions.
Security Monitoring and Incident Detection
Continuous monitoring enables prompt incident detection. Examiners assess security information and event management (SIEM) or equivalent log aggregation and analysis, logging of security-relevant events from all critical systems, log retention meeting regulatory requirements (typically 90 days online, one year archived), automated alerting for suspicious activities or policy violations, and security operations procedures for alert triage and investigation. Smaller institutions may use managed security service providers (MSSPs) for monitoring capabilities, while larger institutions typically maintain internal security operations.
Incident Response and Cyber Resilience
Incident response capabilities minimize damage from security incidents. Examiners evaluate documented incident response plans with defined roles and procedures, incident detection capabilities identifying security events promptly, containment procedures limiting incident scope and damage, recovery procedures restoring normal operations, regulatory notification processes ensuring timely FCA notification of significant incidents, and post-incident reviews identifying root causes and improvements. Institutions should test incident response plans through tabletop exercises or simulations at least annually.
Relationship to Other FCA Examination Manual Sections
Manual 31.7 (Information Security) works in conjunction with Manual 31.6 (IT Risk Management) and other IT sections. Section 31.6 addresses broader IT risk management including governance, while 31.7 focuses specifically on cybersecurity technical controls and programs. Institutions should review both sections together for comprehensive understanding of FCA IT examination expectations. The manual also references NIST Cybersecurity Framework and FFIEC resources as implementation guidance.
Frequently Asked Questions
What is FCA Examination Manual Section 31.7?
FCA Examination Manual 31.7 provides detailed examination guidance for information security programs at Farm Credit System institutions. While Manual 31.6 addresses broad IT risk management, 31.7 focuses specifically on cybersecurity including access controls, network security, malware protection, encryption, monitoring, and incident response. Examiners use 31.7 to evaluate technical security control effectiveness and cybersecurity program maturity during safety and soundness examinations. Institutions should implement controls meeting 31.7 expectations and maintain documentation demonstrating control operation.
How does Section 31.7 differ from Section 31.6?
Manual 31.6 addresses broad IT risk management including governance, strategic planning, business continuity, and vendor management. Manual 31.7 focuses specifically on information security technical controls and cybersecurity programs. Organizations should view 31.6 as strategic/governance guidance and 31.7 as tactical/technical guidance. Together, these sections provide comprehensive IT examination framework—31.6 for "what to do" at governance level and 31.7 for "how to do it" at technical control level. FCA examinations typically address both sections, evaluating governance under 31.6 and technical controls under 31.7.
What cybersecurity frameworks does FCA recognize?
FCA examination manual references NIST Cybersecurity Framework, FFIEC Cybersecurity Assessment Tool, and ISO 27001 as acceptable frameworks for structuring information security programs. FCS institutions can adopt any of these frameworks to satisfy FCA expectations. Many institutions use NIST CSF as their primary framework given federal government endorsement and financial sector adoption. Some institutions use the Cyber Risk Institute Profile which harmonizes NIST CSF with FFIEC expectations. Institutions should select frameworks appropriate to their size and complexity, then implement comprehensively rather than cherry-picking convenient requirements.
How often are FCA IT examinations conducted?
FCA conducts safety and soundness examinations of FCS institutions on risk-based schedules, typically annually for most institutions. IT risk management examination under Manuals 31.6 and 31.7 occurs as part of these safety and soundness examinations. High-risk institutions or those with previous IT findings may face more frequent IT-focused examinations or targeted reviews. FCA also conducts follow-up reviews validating that institutions remediate examination findings within committed timeframes. Institutions with strong IT risk management and clean examination histories may receive less intensive IT reviews, while those with weaknesses face enhanced examination scrutiny.
What happens if institutions don't satisfy Manual 31.7 expectations?
Examiners issue findings documenting deficiencies, ranging from matters requiring attention (MRAs) to significant supervisory concerns for material weaknesses. Institutions must develop corrective action plans with specific remediation steps and completion dates. FCA monitors remediation progress through follow-up reviews. Persistent information security weaknesses can result in formal enforcement actions including consent orders requiring specific corrective actions and timelines, civil money penalties for serious violations or delayed remediation, removal of officers/directors responsible for security program failures, and restrictions on business activities until deficiencies are corrected. Strong information security helps institutions avoid findings and maintain positive supervisory relationships.
Key Framework Components and Control Domains
The FCA Examination Manual 31.7 (2025) organizes cybersecurity requirements into structured domains that address the full spectrum of information security concerns. Organizations implementing FCA EM 31.7 must address controls across multiple areas:
Governance and Risk Management
Effective cybersecurity programs begin with strong governance structures and risk-based decision making. FCA EM 31.7 requires organizations to establish clear accountability for security outcomes, typically through designated leadership roles such as Chief Information Security Officers (CISOs) or equivalent positions. Risk assessments must identify threats, vulnerabilities, and potential business impacts, enabling organizations to prioritize security investments and control implementations based on actual risk exposure.
Governance frameworks should include board or senior management oversight, documented policies and procedures, and regular reporting mechanisms that provide visibility into the security posture and emerging threats. Organizations must maintain awareness of the evolving threat landscape and adjust security strategies accordingly.
Access Control and Identity Management
Controlling who can access information systems and data represents a foundational security principle emphasized throughout FCA EM 31.7. Organizations must implement strong authentication mechanisms, including multi-factor authentication for high-risk access scenarios. The principle of least privilege should govern access grants, ensuring users receive only the minimum permissions necessary to perform legitimate job functions.
Access control implementations should address both human users and system accounts, with particular attention to privileged accounts that possess elevated permissions. Regular access reviews help ensure authorization remains appropriate as roles change and employment relationships end.
Data Protection and Encryption
FCA EM 31.7 mandates protection of sensitive information through technical and procedural controls. Encryption requirements typically cover data both at rest (stored on devices and systems) and in transit (moving across networks). Organizations must classify information based on sensitivity and apply protection measures commensurate with risk.
Data protection programs should address the full information lifecycle, from creation through disposal. Secure deletion procedures, backup protection, and data loss prevention technologies help ensure sensitive information remains confidential and available when needed.
Security Monitoring and Incident Response
Detecting and responding to security incidents quickly minimizes potential damage and supports rapid recovery. FCA EM 31.7 requires organizations to implement continuous monitoring capabilities that identify anomalous activities, potential security events, and active compromises. Security information and event management (SIEM) systems, intrusion detection systems, and endpoint detection and response tools provide visibility into security-relevant activities.
Incident response plans must be documented, tested regularly, and include clear procedures for containment, eradication, recovery, and post-incident analysis. Organizations should maintain relationships with law enforcement, external cybersecurity experts, and communication teams to support effective incident management.
Vulnerability and Patch Management
Unpatched vulnerabilities represent a primary attack vector exploited by threat actors. FCA EM 31.7 emphasizes timely identification and remediation of security vulnerabilities across all information systems. Organizations should conduct regular vulnerability assessments, maintain inventories of assets and software, and implement processes for rapid patch deployment.
Patch management programs must balance security needs with operational stability, often requiring testing before deployment to production environments. For vulnerabilities that cannot be immediately patched, compensating controls provide interim risk reduction.
Implementation Strategies and Best Practices
Successfully implementing FCA EM 31.7 requires structured planning, stakeholder engagement, and sustained commitment. Organizations should begin with a comprehensive gap assessment that compares current security practices against framework requirements. This assessment identifies priorities and informs resource allocation decisions.
Develop a Phased Implementation Roadmap: Rather than attempting to address all requirements simultaneously, organizations should prioritize based on risk and create a multi-phase implementation plan. Early phases should focus on foundational controls that reduce the most significant risks or address the most critical compliance gaps.
Secure Executive Support and Resources: Cybersecurity transformation requires investment in technology, personnel, and processes. Executive sponsorship helps secure necessary resources and ensures cybersecurity remains a strategic priority rather than merely an IT concern.
Build or Acquire Necessary Expertise: Implementing comprehensive security frameworks demands specialized knowledge. Organizations must invest in training existing staff, hiring qualified security professionals, or engaging external consultants to supplement internal capabilities.
Maintain Comprehensive Documentation: Regulatory compliance requires extensive documentation of policies, procedures, risk assessments, and control implementations. Documentation should be maintained in accessible formats and updated regularly to reflect changes in technology, threats, and business processes.
Implement Continuous Monitoring and Improvement: Cybersecurity is not a one-time project but an ongoing program. Organizations should establish metrics that measure security effectiveness, conduct regular assessments to identify new gaps, and continuously enhance controls based on lessons learned and emerging threats.
Relationship to Other Frameworks and Standards
FCA EM 31.7 exists within a broader ecosystem of cybersecurity frameworks, standards, and regulations. Understanding relationships and alignments helps organizations manage multiple compliance obligations efficiently and avoid duplicative efforts.
Many federal frameworks such as NIST SP 800-53, NIST Cybersecurity Framework, and FedRAMP share common control foundations with FCA EM 31.7. Organizations can often map controls across frameworks, implementing once and satisfying multiple requirements.
Organizations managing multiple compliance obligations should consider developing integrated frameworks that address all applicable requirements through unified control sets, avoiding fragmented implementations that increase complexity and cost.
Common Challenges and Solutions
Organizations implementing FCA EM 31.7 frequently encounter similar challenges. Understanding common pitfalls helps organizations plan proactively and avoid costly mistakes.
Resource Constraints: Cybersecurity programs require sustained investment in technology, personnel, and operations. Organizations should prioritize based on risk, leverage automation where possible, and consider managed security services to extend internal capabilities cost-effectively.
Complexity and Scope: Comprehensive frameworks can feel overwhelming, particularly for smaller organizations with limited security expertise. Breaking implementation into manageable phases, focusing on fundamentals first, and leveraging external expertise helps organizations maintain momentum and achieve incremental progress.
Maintaining Currency: Threat landscapes, technologies, and regulatory requirements evolve continuously. Organizations must establish processes for monitoring changes, assessing impacts, and updating controls to remain effective and compliant over time.
Cultural Resistance: Cybersecurity controls sometimes conflict with convenience or established workflows, creating resistance from users and business units. Effective security programs balance protection with usability, involve stakeholders in design decisions, and communicate the business value of security investments.
Audit and Compliance Validation
Organizations subject to FCA EM 31.7 must demonstrate compliance through various assessment and audit mechanisms. Federal agencies conduct regular audits, and contractors may face assessments as conditions of contract awards or renewals.
Successful audits require organizations to maintain evidence of control implementations, document security processes and procedures, and demonstrate consistent application of security practices. Audit preparation should be continuous rather than episodic, with evidence collection and documentation integrated into normal operations.
Organizations should conduct internal self-assessments regularly to identify gaps before external auditors discover them. Self-assessment findings provide opportunities for remediation and demonstrate proactive commitment to compliance.
Future Outlook and Emerging Considerations
The cybersecurity landscape continues evolving rapidly, with emerging technologies, threat techniques, and regulatory expectations reshaping security requirements. Organizations implementing FCA EM 31.7 should anticipate future trends and position security programs for adaptability.
Cloud computing, artificial intelligence, remote work, and operational technology integration create new attack surfaces and require security controls to evolve beyond traditional paradigms. Framework updates and amendments will likely address these emerging areas, requiring organizations to stay informed and adjust implementations accordingly.
Supply chain security, zero trust architecture, and privacy-enhancing technologies represent growing focus areas across cybersecurity frameworks. Organizations should consider how these concepts apply to their environments and proactively incorporate relevant principles into security programs.
Conclusion
The FCA Examination Manual 31.7 (2025) provides essential guidance for organizations seeking to establish or enhance cybersecurity programs that protect against modern threats. Compliance is mandatory for covered entities, and organizations must view adherence as a continuous obligation rather than a one-time achievement.
Successful implementation requires executive support, adequate resources, qualified personnel, and sustained commitment. Organizations should approach FCA EM 31.7 as a framework for continuous improvement rather than a checkbox exercise, using requirements as opportunities to strengthen security postures and build resilience against evolving cyber threats.
By following structured implementation approaches, maintaining comprehensive documentation, and fostering security-aware cultures, organizations can achieve FCA EM 31.7 compliance or alignment while building security programs that genuinely reduce risk and protect critical assets. The investment in cybersecurity maturity pays dividends through reduced incident likelihood and impact, enhanced customer trust, and improved operational resilience.