A banking organization is required to notify its primary Federal banking regulator of any âcomputer-security incidentâ that rises to the level of a ânotification incident,â as soon as possible and no later than 36 hours after the banking organization determines that a notification incident has occurred. A bank service provider is required to notify each affected banking organization customer as soon as possible when the bank service provider determines that it has experienced a computer-security incident, that has caused, or is reasonably likely to cause, a material service disruption or degradation for four or more hours.
On behalf of this Federal agency, I certify that the collection of information encompassed by this request complies with 5 CFR 1320.9 and the related provisions of 5 CFR 1320.8(b)(3).
The following is a summary of the topics, regarding the proposed collection of information, that the certification covers:
(i) Why the information is being collected;
(ii) Use of information;
(iii) Burden estimate;
(iv) Nature of response (voluntary, required for a benefit, or mandatory);
(v) Nature and extent of confidentiality; and
(vi) Need to display currently valid OMB control number;
If you are unable to certify compliance with any of these provisions, identify the item by leaving the box unchecked and explain the reason in the Supporting Statement.