Your information security program, reported to the board and recorded incident by incident.
Generate the annual information security program report to the board, and record each security incident with the notices it owes and the evidence that they were sent.
| Regime | Citation | Notice |
|---|---|---|
| Primary federal regulator | 12 CFR 304.23 | Sent after 19 hours |
| Customer notice | 12 CFR 364 App. B Supp. A | Marked by hand |
| Suspicious activity report | 31 CFR 1020.320 | Considered |
| Cyber insurer | Your policy | Due |
The annual report to the board
Section III.F of the Interagency Guidelines Establishing Information Security Standards asks for a report to the board on the information security program at least annually. Zovos generates that report from the Cybersecurity landing. Its seven sections follow III.F in order. They cover overall status and compliance, the risk assessment, risk management and control decisions, service provider arrangements, results of testing, security breaches or violations and management’s responses, and recommendations for changes in the program.
- 01Sections one to six are computed from your registers, and every figure is cited to the records it counts.
- 02An empty register reports zero, never an estimate.
- 03Your information security officer writes the recommendations in a shared draft, and that draft is sealed into the report when it is generated.
- 04The report is filed as a sealed PDF with your other board reports and reaches directors through the board portal.
- 05After the report is generated, you can record the annual board report obligation as met on the Obligations calendar.
A security incident register with the notices each incident owes
The Security incidents register records each incident with its severity, its detection time, the systems affected, the service provider where it occurred, the kinds of information involved and the number of customers affected. A named person at your institution records the determination of what the incident is, with its time and its basis. Zovos never makes that determination. Once it is recorded, each incident lists the notification regimes, whether each one applies and why, the deadline it sets, the citation it comes from, and the evidence that each notice was sent.
- 01A bank’s primary federal regulator is owed notice no later than 36 hours after the determination, under 12 CFR 53.3, 225.302 or 304.23.
- 02A credit union owes NCUA notice no later than 72 hours after the determination, under 12 CFR 748.1(c).
- 03When an incident at an entity the FTC Safeguards Rule covers involves the information of 500 or more consumers, FTC notice is due no later than 30 days after discovery.
- 04Customer notice, the cyber insurer and state breach laws are marked by hand, because their terms rest on your judgment, your policy or each statute.
- 05For a suspicious activity report, the register records only that the question was considered and by whom.
- 06No deadline appears before a determination is recorded, and a recorded determination changes only with a reason that stays in the audit trail.
Incidents linked to the rest of the program
An incident connects to the records it touches. It can be promoted to a finding, linked to a loss event or used to create one in the loss event register, tied to the service provider where it occurred, and given tasks and evidence documents. An incident closes only with a root cause and the lessons learned.
- 01Loss amounts stay in the loss event register, so a loss is never counted twice.
- 02The board report reads the incident register, and it still reports incident-class loss events that no incident links.
- 03Only members who hold the security read permission open the register, and examiner access does not reach it.
The Cybersecurity landing
The Cybersecurity landing shows the program at a glance. It lists the security and continuity frameworks your institution has enrolled and keeps in scope, with their coverage. Those can be the FFIEC IT and business continuity booklets, GLBA, NCUA Chapter VII, NIST CSF 2.0, the CRI Profile, NIST SP 800-53, the CIS Controls, ISO/IEC 27001, NYDFS Part 500 and PCI DSS. The landing also carries the board report, the open security incidents with the notices still due, the open findings tagged to those frameworks, and the controls crosswalked to them with their test status.
- 01A framework appears on the landing only while its enrollment is in scope.
- 02Open incidents are listed with the earliest notice deadline first.
Automated tests on the tools you already run
Automated control tests read the security tools your institution already owns, such as Tenable, Qualys, CrowdStrike and Jamf. A test can be set up only on a connection whose provider can answer its check, so a vulnerability check cannot be placed on an identity provider. A check that cannot be read records an error and never a silent pass.
- 01In the board report, tests whose latest run errored are reported on their own and left out of every pass rate.
- 02The security evidence connectors read summary figures such as counts, rates and remediation aging, not the vulnerability inventory or detection detail.
Governance and evidence, not detection
Zovos records how your institution governs its information security program and keeps the evidence behind it. It does not detect threats, respond to incidents or send notices for you. Your security tools detect, your team responds, and Zovos holds the record of what was decided, by whom, and when.
- 01Notices are sent by your team, and Zovos records when, to whom and by whom each one was sent.
- 02Every write to an incident is recorded in the audit trail.
Grounded in shipped behaviour.
- The board report has seven sections that follow section III.F of the Interagency Guidelines one to one.
- Every figure in the board report is bound to the record ids it counts in a sealed lineage manifest.
- Each incident lists seven notification regimes, from the primary federal regulator to state breach law, with whether each one applies and why.
- A security incident cannot close without a root cause and lessons learned.
Counts come from the platform's regulatory corpus, connector registry, and seed template library at release. See the documentation for the current values.
Questions, answered first.
- Does Zovos decide whether an incident must be reported?
- No. A named person at your institution records the determination, with its time and its basis. Zovos shows the deadlines that follow from it, the regime and citation each one comes from, and the evidence that each notice was sent.
- What is in the annual report to the board?
- Seven sections that follow section III.F of the Interagency Guidelines. Six are computed from your registers with a citation on every figure, and the seventh holds the recommendations your information security officer writes.
- Does Zovos detect or respond to security incidents?
- No. Your security tools detect incidents and your team responds to them. Zovos records each incident, its determination, its notices and its closure, and links it to findings, loss events and vendors.
- Who can see the incident register?
- Members who hold the security read permission can see it. Examiner access does not reach the register.
See information security program on your library.
Bring your controls, a policy, and one regulator paragraph that gives you trouble. We target two-week onboarding.