Leela
Incident Response
IR-04

Report a material computer-security incident to the bank as soon as possible

Policy reference

Incident Response policy, §5.2, §7.2

Computer-Security Incident Notification Rule, bank service provider notice, 12 CFR 53.4; 12 CFR 225.303; 12 CFR 304.24
Computer-Security Incident Notification Rule, bank notice to regulator, 12 CFR 53.3; 12 CFR 225.302; 12 CFR 304.23
Requirement

When the Company determines it has experienced a computer-security incident, with or without unauthorized access, that has materially disrupted or degraded, or is reasonably likely to materially disrupt or degrade, the services it provides to the sponsor bank for four hours or more, it notifies the bank as soon as possible. The notice is not held for a completed investigation, because it feeds the bank’s own 36-hour notice to its regulator.

Trigger

Event-driven

As soon as possible after determining a disruption of 4 hours or more has occurred or is reasonably likely

Action

Make the four-hour determination on confirmation, send the notice to the bank’s security contacts with what is known, log the time, and supply the details the bank needs for its regulatory notice.

Evidence
  • Determination record

    Time the four-hour threshold was judged met or likely, and by whom

  • Bank notice

    Notice sent with the time, against the determination time

Owner

Compliance Officer

Leela can
Prepare for review

Leela can prepare the artifact and hand it to a person for review.

Leela can draft the notice from the outage record the moment the four-hour threshold is judged met and route it to the Compliance Officer to send.

Applies

Tell Leela about your company to see whether this applies.

Status
Setup needed

Tell Leela how you handle it today, or hand it over: see what’s next.

What’s next?