← Back to Library
OCC 2023-22

OCC Cybersecurity Supervision Work Program (2023)

Full Name:
Attachment to OCC Bulletin 2023-22 - Cybersecurity Supervision Work Program
Acronym:
OCC Bulletin
Type:
US Federal Standard
Organization:
Office of the Comptroller of the Currency
Version:
2023-22
Year Published:
2023
Popularity:
Low

Overview of OCC Bulletin 2023-22

OCC Bulletin 2023-22, issued in September 2023, outlines the Office of the Comptroller of the Currency's (OCC) approach for evaluating cybersecurity resilience and control maturity across supervised financial institutions. The bulletin introduces the Cybersecurity Supervision Work Program, which provides OCC examiners with a structured framework for assessing banks' cybersecurity programs, identifying vulnerabilities, and evaluating cybersecurity risk management practices. The work program reflects the OCC's recognition that cybersecurity threats pose significant risks to the safety and soundness of the banking system and require comprehensive supervisory oversight.

The Cybersecurity Supervision Work Program emerged in response to growing cybersecurity threats facing financial institutions, increased sophistication of cyber attacks, and recognition that traditional examination approaches needed enhancement to effectively assess cybersecurity programs. The OCC developed the work program to provide examiners with consistent, comprehensive guidance for evaluating banks' cybersecurity resilience, enabling more effective identification of cybersecurity weaknesses and assessment of cybersecurity risk management effectiveness. The work program addresses the OCC's supervisory responsibilities for ensuring that banks implement robust cybersecurity programs that protect customer information and financial systems.

OCC Bulletin 2023-22 applies to all national banks, federal savings associations, and federal branches and agencies of foreign banking organizations supervised by the OCC. The work program guides OCC examiners in assessing banks' cybersecurity programs during regular examinations, special examinations, and targeted cybersecurity assessments. Understanding the work program enables banks to prepare for OCC examinations, identify cybersecurity program gaps, and implement cybersecurity practices that meet OCC expectations. The work program complements other OCC guidance on cybersecurity, third-party risk management, and operational risk.

Framework Applicability and Adoption

OCC Bulletin 2023-22 applies to all OCC-supervised institutions, including national banks, federal savings associations, and federal branches and agencies of foreign banking organizations. The Cybersecurity Supervision Work Program guides OCC examiners in assessing banks' cybersecurity programs, but banks should understand the work program to prepare for examinations and ensure their cybersecurity programs meet OCC expectations. Banks should align their cybersecurity programs with the work program's assessment criteria to demonstrate effective cybersecurity risk management.

Adoption of cybersecurity practices aligned with the work program is driven by OCC examination expectations and banks' need to demonstrate effective cybersecurity risk management. Banks that align their cybersecurity programs with the work program's assessment criteria are better positioned to demonstrate cybersecurity resilience during OCC examinations. The work program's focus on cybersecurity resilience and control maturity enables banks to understand OCC expectations and implement cybersecurity practices that meet supervisory standards.

Key Framework Components and Assessment Areas

The OCC Cybersecurity Supervision Work Program organizes cybersecurity assessment into structured areas that address cybersecurity governance, risk management, technical controls, and operational resilience. OCC examiners use the work program to assess banks' cybersecurity programs across multiple domains:

Cybersecurity Governance and Oversight

Effective cybersecurity programs begin with strong governance structures and board and senior management oversight. The work program assesses banks' cybersecurity governance including board and senior management oversight, cybersecurity policies and procedures, cybersecurity roles and responsibilities, and cybersecurity reporting mechanisms. Banks must establish clear accountability for cybersecurity outcomes, typically through designated leadership roles such as Chief Information Security Officers (CISOs) or equivalent positions. Governance frameworks should include board oversight, documented policies and procedures, and regular reporting that provides visibility into cybersecurity posture and emerging threats.

OCC examiners assess whether banks' boards and senior management understand cybersecurity risks, provide appropriate oversight, and allocate adequate resources for cybersecurity programs. Examiners evaluate cybersecurity policies and procedures for completeness, currency, and effectiveness. Banks must demonstrate that governance structures enable effective cybersecurity risk management and that boards and senior management receive regular cybersecurity reporting. Strong cybersecurity governance enables banks to implement effective cybersecurity programs and respond to cybersecurity threats.

Cybersecurity Risk Assessment and Management

Cybersecurity risk assessment and management enable banks to identify, assess, and manage cybersecurity risks effectively. The work program assesses banks' risk assessment processes including threat identification, vulnerability assessment, risk analysis, and risk mitigation strategies. Banks must conduct regular cybersecurity risk assessments that identify threats, vulnerabilities, and potential business impacts, enabling prioritization of security investments and control implementations based on actual risk exposure.

OCC examiners evaluate whether banks' risk assessments are comprehensive, current, and inform cybersecurity program decisions. Examiners assess risk management processes including risk identification, risk analysis, risk prioritization, and risk mitigation. Banks must demonstrate that risk assessments address current threats, identify vulnerabilities effectively, and inform cybersecurity program improvements. Effective risk assessment and management enable banks to prioritize cybersecurity investments and implement controls that address actual risks.

Cybersecurity Controls and Technical Safeguards

Cybersecurity controls and technical safeguards protect banks' information systems and data from cyber threats. The work program assesses banks' implementation of technical controls including access controls, encryption, network security, endpoint security, and security monitoring. Banks must implement technical controls that protect information systems, prevent unauthorized access, detect security events, and respond to threats effectively.

OCC examiners evaluate whether banks' technical controls are implemented effectively, configured appropriately, and monitored continuously. Examiners assess access controls including authentication, authorization, and access management processes. Banks must demonstrate that technical controls address identified risks, are implemented consistently, and are monitored for effectiveness. Effective technical controls enable banks to protect information systems and data from cyber threats.

Cybersecurity Monitoring and Detection

Cybersecurity monitoring and detection enable banks to identify security events, detect threats, and respond to incidents promptly. The work program assesses banks' security monitoring capabilities including security information and event management (SIEM) systems, intrusion detection systems, endpoint detection and response tools, and security analytics. Banks must implement continuous monitoring that identifies anomalous activities, potential security events, and active compromises.

OCC examiners evaluate whether banks' monitoring capabilities provide comprehensive visibility, detect threats effectively, and enable rapid response. Examiners assess monitoring coverage, alert quality, and response capabilities. Banks must demonstrate that monitoring capabilities address identified risks, detect threats effectively, and enable prompt incident response. Effective monitoring and detection enable banks to identify and respond to cybersecurity threats quickly.

Incident Response and Business Continuity

Incident response and business continuity enable banks to respond effectively to cybersecurity incidents and maintain operations during disruptions. The work program assesses banks' incident response plans including incident detection, containment, eradication, recovery, and post-incident analysis procedures. Banks must develop incident response plans that address cybersecurity incidents, define roles and responsibilities, and establish communication procedures.

OCC examiners evaluate whether banks' incident response plans are comprehensive, tested regularly, and integrated with business continuity plans. Examiners assess incident response capabilities including detection, containment, and recovery procedures. Banks must demonstrate that incident response plans address identified risks, are tested regularly, and enable effective incident management. Effective incident response and business continuity enable banks to respond to cybersecurity incidents and maintain operations.

Third-Party Cybersecurity Risk Management

Third-party cybersecurity risk management addresses cybersecurity risks from third-party service providers that banks rely on for critical services. The work program assesses banks' third-party risk management processes including due diligence, contract requirements, ongoing monitoring, and incident notification. Banks must assess third-party cybersecurity practices, establish contract requirements, and monitor third-party compliance.

OCC examiners evaluate whether banks' third-party risk management processes identify cybersecurity risks, establish appropriate contract requirements, and monitor third-party compliance effectively. Examiners assess due diligence processes, contract requirements, and monitoring procedures. Banks must demonstrate that third-party risk management addresses cybersecurity risks from third-party service providers and enables effective risk management. Effective third-party risk management enables banks to manage cybersecurity risks from third-party relationships.

Implementation Strategies and Best Practices

Banks preparing for OCC examinations should align their cybersecurity programs with the Cybersecurity Supervision Work Program assessment criteria. Banks should begin with self-assessments that evaluate their cybersecurity programs against the work program's assessment areas, identifying gaps and prioritizing improvements.

Conduct Self-Assessment Against Work Program: Banks should conduct comprehensive self-assessments that evaluate their cybersecurity programs against the work program's assessment areas including governance, risk management, technical controls, monitoring, incident response, and third-party risk management. Self-assessments should identify cybersecurity program strengths and weaknesses, prioritize improvement opportunities, and inform cybersecurity program enhancements. Banks should conduct self-assessments regularly to prepare for OCC examinations and identify cybersecurity program gaps proactively.

Strengthen Cybersecurity Governance: Banks must establish strong cybersecurity governance including board and senior management oversight, cybersecurity policies and procedures, and cybersecurity reporting mechanisms. Governance structures should ensure that boards and senior management understand cybersecurity risks, provide appropriate oversight, and allocate adequate resources. Banks should establish cybersecurity committees, designate cybersecurity officers, and implement governance processes that enable effective cybersecurity risk management. Strong governance enables banks to implement effective cybersecurity programs and demonstrate cybersecurity resilience.

Enhance Cybersecurity Risk Assessment: Banks must conduct comprehensive cybersecurity risk assessments that identify threats, vulnerabilities, and potential business impacts. Risk assessments should be conducted regularly, updated based on threat intelligence, and inform cybersecurity program decisions. Banks should establish risk management processes that identify risks, analyze risks, prioritize risks, and implement risk mitigation strategies. Effective risk assessment enables banks to prioritize cybersecurity investments and implement controls that address actual risks.

Implement Comprehensive Technical Controls: Banks must implement technical controls including access controls, encryption, network security, endpoint security, and security monitoring that protect information systems and data. Technical controls must be based on risk assessments, implemented consistently, and monitored for effectiveness. Banks should ensure that technical controls address identified risks, protect information systems effectively, and enable security operations. Comprehensive technical controls enable banks to protect information systems and data from cyber threats.

Establish Security Monitoring Capabilities: Banks must implement security monitoring capabilities that provide visibility into security activities, detect threats, and enable rapid response. Monitoring capabilities should include SIEM systems, intrusion detection systems, endpoint detection and response tools, and security analytics. Banks should ensure that monitoring capabilities provide comprehensive visibility, detect threats effectively, and enable prompt incident response. Effective monitoring enables banks to identify and respond to cybersecurity threats quickly.

Develop Incident Response Capabilities: Banks must develop incident response capabilities that address cybersecurity incidents, including incident detection, containment, and recovery procedures. Incident response plans must be tested regularly, updated based on lessons learned, and integrated with business continuity plans. Banks should ensure that incident response capabilities enable prompt detection, response, and recovery from cybersecurity incidents. Effective incident response enables banks to respond to cybersecurity incidents and minimize impact.

Implement Third-Party Risk Management: Banks must implement third-party risk management processes that assess, monitor, and manage cybersecurity risks from third-party service providers. Third-party risk management must include due diligence assessments, contract requirements, ongoing monitoring, and incident notification. Banks should ensure that third-party risk management addresses cybersecurity risks from third-party relationships and enables effective risk management. Effective third-party risk management enables banks to manage cybersecurity risks from third-party service providers.

Relationship to Other Frameworks and Standards

The OCC Cybersecurity Supervision Work Program complements and aligns with other OCC guidance and federal banking regulations, providing examiners with structured assessment criteria while enabling banks to understand OCC expectations.

FFIEC Cybersecurity Assessment Tool: The work program aligns with the FFIEC Cybersecurity Assessment Tool, providing complementary assessment criteria for evaluating banks' cybersecurity programs. Banks implementing the FFIEC Assessment Tool can align their cybersecurity programs with the work program's assessment criteria. The frameworks work together, with the FFIEC Assessment Tool providing self-assessment guidance and the work program providing OCC examination criteria.

NIST Cybersecurity Framework: The work program aligns with NIST Cybersecurity Framework functions including Identify, Protect, Detect, Respond, and Recover, providing assessment criteria that support framework implementation. Banks implementing the Cybersecurity Framework can align their cybersecurity programs with the work program's assessment criteria. The frameworks complement each other, with the Cybersecurity Framework providing strategic guidance and the work program providing OCC examination criteria.

OCC Third-Party Risk Management Guidance: The work program aligns with OCC guidance on third-party risk management, providing assessment criteria for evaluating banks' third-party cybersecurity risk management. Banks implementing OCC third-party risk management guidance can align their programs with the work program's assessment criteria. The guidance works together, with third-party risk management guidance providing requirements and the work program providing assessment criteria.

Federal Banking Regulations: The work program supports OCC examination of banks' compliance with federal banking regulations including cybersecurity requirements. Banks must comply with federal banking regulations while aligning their cybersecurity programs with the work program's assessment criteria. The work program enables OCC examiners to assess banks' compliance with regulatory requirements and cybersecurity program effectiveness.

Common Challenges and Solutions

Banks preparing for OCC examinations frequently encounter similar challenges related to cybersecurity program alignment, resource constraints, technical implementation, and examination preparation. Understanding these common challenges helps banks plan proactively and prepare for examinations effectively.

Aligning Cybersecurity Programs with Work Program: Banks may struggle to align their cybersecurity programs with the work program's assessment criteria, making it difficult to demonstrate cybersecurity resilience during examinations. Banks may have cybersecurity programs that don't address all assessment areas, lack documentation that demonstrates program effectiveness, or have gaps that examiners may identify. Alignment challenges may require significant program enhancements and documentation improvements.

Solutions include conducting comprehensive self-assessments against the work program, identifying alignment gaps, and implementing enhancements that address assessment criteria. Banks should ensure that cybersecurity programs address all assessment areas, maintain documentation that demonstrates program effectiveness, and conduct regular self-assessments that identify gaps proactively. Alignment with the work program enables banks to demonstrate cybersecurity resilience during examinations.

Resource Constraints: Implementing cybersecurity programs that meet OCC expectations requires significant resources including personnel, technology, and time that may be limited, particularly for smaller banks. Banks may struggle to allocate resources for cybersecurity, particularly when resources are already committed to other priorities. Resource constraints may force banks to prioritize some cybersecurity areas over others.

Solutions include prioritizing cybersecurity investments based on risk, leveraging automation and tools to improve efficiency, and engaging third-party service providers. Banks should implement cybersecurity programs progressively, achieve incremental progress, and demonstrate ongoing cybersecurity improvements. Risk-based prioritization enables banks to allocate limited resources effectively, addressing the most significant cybersecurity risks first.

Technical Implementation Challenges: Implementing technical controls including access controls, encryption, and security monitoring may be technically challenging, particularly for banks with legacy systems or limited technical expertise. Banks may struggle to implement technical controls, integrate controls with existing systems, or maintain controls over time. Technical implementation challenges may require specialized expertise and significant resources.

Solutions include engaging technical experts, implementing technical controls progressively, and leveraging managed security services. Banks should ensure that technical controls address identified risks, integrate with existing systems, and are maintained effectively. Technical expertise enables banks to implement technical controls effectively and demonstrate cybersecurity resilience.

Examination Preparation: Preparing for OCC examinations requires comprehensive documentation, program alignment, and demonstration of cybersecurity program effectiveness. Banks may struggle to prepare documentation that demonstrates program effectiveness, align programs with assessment criteria, or demonstrate cybersecurity resilience during examinations. Examination preparation may require significant time and resources.

Solutions include conducting regular self-assessments, maintaining comprehensive documentation, and preparing examination materials proactively. Banks should ensure that documentation addresses assessment criteria, demonstrates program effectiveness, and supports examination discussions. Examination preparation enables banks to demonstrate cybersecurity resilience and address examination findings effectively.

Third-Party Risk Management: Managing cybersecurity risks from third-party service providers may be challenging, particularly for banks that rely extensively on third-party services. Banks may struggle to assess third-party cybersecurity practices, establish contract requirements, or monitor third-party compliance. Third-party risk management challenges may require significant resources and expertise.

Solutions include developing third-party risk management processes, implementing due diligence assessments, and establishing ongoing monitoring procedures. Banks should ensure that third-party risk management addresses cybersecurity risks from third-party relationships and enables effective risk management. Effective third-party risk management enables banks to manage cybersecurity risks from third-party service providers.

Maintaining Program Currency: Maintaining cybersecurity programs that remain current with evolving threats, technologies, and regulatory expectations may be challenging. Banks may struggle to update programs regularly, address emerging threats, or incorporate new technologies. Maintaining program currency requires ongoing attention and resources.

Solutions include establishing processes for monitoring threats and technologies, conducting regular program reviews, and updating programs based on threat intelligence and lessons learned. Banks should ensure that cybersecurity programs remain current with evolving threats and technologies, addressing emerging risks proactively. Maintaining program currency enables banks to demonstrate cybersecurity resilience and address evolving threats effectively.

OCC Examination Process

OCC examiners use the Cybersecurity Supervision Work Program to assess banks' cybersecurity programs during regular examinations, special examinations, and targeted cybersecurity assessments. Examinations evaluate banks' cybersecurity governance, risk management, technical controls, monitoring capabilities, incident response, and third-party risk management. Banks should prepare for examinations by conducting self-assessments, maintaining comprehensive documentation, and aligning cybersecurity programs with the work program's assessment criteria.

Examination findings may identify cybersecurity program weaknesses, control deficiencies, or risk management gaps that require remediation. Banks must address examination findings promptly, develop remediation plans, and implement improvements that address identified deficiencies. OCC examiners may conduct follow-up examinations to verify that banks have addressed examination findings and improved their cybersecurity programs. Banks should view examinations as opportunities to improve cybersecurity programs and demonstrate cybersecurity resilience.

Frequently Asked Questions

What is OCC Bulletin 2023-22?

OCC Bulletin 2023-22 introduces the Cybersecurity Supervision Work Program, which provides OCC examiners with a structured framework for assessing banks' cybersecurity programs. The work program guides examiners in evaluating cybersecurity governance, risk management, technical controls, monitoring capabilities, incident response, and third-party risk management. The bulletin applies to all OCC-supervised institutions and enables banks to understand OCC examination expectations.

Who is subject to OCC Bulletin 2023-22?

OCC Bulletin 2023-22 applies to all national banks, federal savings associations, and federal branches and agencies of foreign banking organizations supervised by the OCC. The Cybersecurity Supervision Work Program guides OCC examiners in assessing these institutions' cybersecurity programs during examinations. Banks should align their cybersecurity programs with the work program's assessment criteria to demonstrate cybersecurity resilience.

What are the key assessment areas in the work program?

Key assessment areas include cybersecurity governance and oversight, cybersecurity risk assessment and management, cybersecurity controls and technical safeguards, cybersecurity monitoring and detection, incident response and business continuity, and third-party cybersecurity risk management. Each area provides assessment criteria that examiners use to evaluate banks' cybersecurity programs and identify cybersecurity program strengths and weaknesses.

How should banks prepare for OCC examinations?

Banks should prepare for OCC examinations by conducting self-assessments against the work program, aligning cybersecurity programs with assessment criteria, maintaining comprehensive documentation, and addressing cybersecurity program gaps proactively. Banks should ensure that cybersecurity programs address all assessment areas, demonstrate program effectiveness, and enable banks to respond to examination questions effectively. Preparation enables banks to demonstrate cybersecurity resilience during examinations.

What happens if OCC examiners identify cybersecurity weaknesses?

If OCC examiners identify cybersecurity weaknesses, banks must address examination findings promptly, develop remediation plans, and implement improvements that address identified deficiencies. Examiners may conduct follow-up examinations to verify that banks have addressed findings and improved their cybersecurity programs. Banks should view examination findings as opportunities to improve cybersecurity programs and demonstrate cybersecurity resilience.

How does the work program relate to other OCC guidance?

The work program complements other OCC guidance on cybersecurity, third-party risk management, and operational risk, providing examiners with structured assessment criteria. Banks implementing other OCC guidance can align their cybersecurity programs with the work program's assessment criteria. The work program enables examiners to assess banks' compliance with OCC guidance and cybersecurity program effectiveness.

Conclusion

The OCC Cybersecurity Supervision Work Program provides essential guidance for OCC examiners assessing banks' cybersecurity programs and enables banks to understand OCC examination expectations. The work program's focus on cybersecurity resilience and control maturity enables banks to align their cybersecurity programs with OCC expectations and demonstrate cybersecurity resilience during examinations. Understanding the work program enables banks to prepare for examinations effectively and implement cybersecurity practices that meet OCC supervisory standards.

Successful alignment with the work program requires executive support, adequate resources, qualified personnel, and sustained commitment to maintaining cybersecurity programs. Banks should approach the work program as a framework for continuous improvement, using assessment criteria as opportunities to strengthen cybersecurity postures and build resilience against evolving cyber threats. Banks should conduct regular self-assessments, maintain comprehensive documentation, and address cybersecurity program gaps proactively.

By aligning cybersecurity programs with the work program's assessment criteria, maintaining comprehensive documentation, and preparing for examinations proactively, banks can demonstrate cybersecurity resilience and address examination findings effectively. The investment in cybersecurity maturity pays dividends through reduced cybersecurity risk, enhanced supervisory confidence, and improved ability to protect customer information and financial systems from cyber threats.