01/10/2022
Risks and supervisory expectations listed out by The Comptroller of the Currency:
The Comptroller of the Currency notes that examiners are assessing banks’ capabilities to recover from destructive malware attacks. Examinations should emphasize threat vulnerability and detection, authentication and access controls, network management, data management, and managing third-party access.
Examiners should perform assessments of internal controls and operational processes that changed during the pandemic.