On June 26, 2023, the Office of the Comptroller of the Currency (OCC) published Bulletin 2023-22: Cybersecurity Supervision Work Program. Let's look at five things we think community banks should know about the Cybersecurity Supervision Work Program (CSW) exam procedures.
One of the biggest influencers on the CSW is the NIST Cybersecurity Framework (CSF) Version 1.1.
In short, the NIST CSF v.1.1 and OCC CSW go together like peas and carrots. Learn more about the NIST CSF here: https://www.nist.gov/cyberframework.
There are a lot of direct and indirect references to the FFIEC IT Examination Handbook in the CSW. Specific booklets that get shout-outs include:
Each section begins with a phrase that coaches examiners on where to find more information in the FFIEC booklets about the topic at hand. For example, in the "IT Asset Management" category, examiners are told to refer to the Information Security and Architecture, Infrastructure, and Operations booklets for more info.
The OCC added a "Specialty Areas" section to the end of the CSW with a category called "Secure Software Development" (SA.SD). Since NIST CSF Version 1.1 did not have a category for this topic, the CSW appears to have primarily relied on FFIEC guidance for these statements.
Since 2015, the OCC's cybersecurity examination program was based on the FFIEC Cybersecurity Assessment Tool (CAT). According to the OCC's 2022 Cybersecurity and Financial System Resilience Report to Congress (see PDF page 13), use of the CAT enabled the OCC to:
While the OCC CSW is no longer based on the FFIEC CAT, alignment with the NIST CSF enables the OCC to continue to meet these objectives.
One of my favorite parts about the CSW is that it comes with a Cybersecurity Supervision Work Program References tool. This tool is designed to give banks a way to map the CSW statements to existing guidance and frameworks, such as the CIS Controls and the NIST SP 800-53 controls.
Here's an example of what it looks like when you use the tool.
This is a win-win. It's helpful for OCC examiners who may want to learn more about a certain topic, and it's helpful for banks when preparing for an upcoming examination.
Since the FFIEC CAT sunset, many financial institutions are looking for an alternate framework. Some are even asking, "Can I use the CSW as a cybersecurity framework?"
The short answer is: Maybe. But with caveats.
As the OCC notes, "The CSW does not establish new regulatory expectations, and banks are not required to use this work program to assess cybersecurity preparedness." That said, if you approach it as a framework to help you evaluate your cybersecurity preparedness, it can be a useful tool for self-assessment and exam prep.
Further Reading: Learn more about using cybersecurity frameworks on our blog: What is a Cybersecurity Control Self-Assessment?
The OCC CSW program gives community banks greater flexibility, aligns with current FFIEC guidance, and promotes a consistent cybersecurity supervision framework through its use of the NIST CSF. If you haven't seen the CSW yet:
Tandem Cybersecurity Assessment makes it easy to complete cybersecurity control self-assessments using common frameworks, including the NIST CSF and the OCC CSW. Our web application streamlines the process with intuitive assessment tools, robust reporting, downloadable documents, peer benchmarking, notifications, and more.
Sign up and get started for free at Tandem.App/Cybersecurity.
Update Log: