Skip to main content
OCC Flag

An official website of the United States government

Cybersecurity Supervision Work Program References

The Cybersecurity Supervision Work Program (CSW) provides high-level examination procedures that are aligned with existing supervisory guidance and the National Institute of Standards and Technology (NIST) Cybersecurity Framework (CSF). Within the CSW Cross-References table on this page, users can filter and search for CSW procedures. The procedures are cross-referenced to common industry cybersecurity frameworks, OCC publications, and the FFIEC IT Examination Handbook. Learn more about the OCC’s cybersecurity supervision.

The CSW is a component of the OCC’s risk-based bank information technology supervision process. The CSW sets no new regulatory expectations, and national banks and federal savings associations are not expected to use this work program to assess cybersecurity preparedness.


CSW Cross-References

Use the filters below to see a table of CSW procedures and the cross-references or click search without applying filters to view all data. Learn more about CSW Cross-References.


More Information About CSW Cross-References 

The CSW Cross-References table above offers several columns of information. Select the sections below to learn more about what is displayed under each column.

The CSW is structured to align with the NIST CSF functions and categories. The table below shows how NIST aligns the categories under each function.

The CSW does not include NIST CSF categories and/or subcategories that are addressed as part of other examination programs or that do not apply to the OCC bank information technology supervision process.

The unique ID identifies the procedure and its hierarchy. Unique IDs are structured using a hierarchy of NIST CSF functions, categories, and subcategories. The OCC added two characters at the end of the unique ID to designate the specific procedure. See the figure pictured below.

Unique ID

During supervisory activities, examiners use the procedures to guide their reviews and evaluation of cybersecurity preparedness.

OCC Resources, FFIEC IT Examination Handbook InfoBase, Industry Frameworks

The table provides cross-references that map CSW procedures to existing supervisory guidance, examiner guidance, and industry frameworks. The cross-references are provided for informational purposes only; inclusion of products, processes, services, manufacturers, or companies in the CSW is not indicative of an OCC endorsement.

  • OCC Resources
    • OCC Bulletins
      • Each bulletin listed in the table will have a hyperlink to the applicable attachment or bulletin transmittal. If necessary, scroll to the page indicated or search for the applicable text.
    • OCC Comptroller’s Handbook: Community Bank Supervision
      • To find the associated procedures in the “Community Bank Supervision” booklet of the Comptroller’s Handbook, navigate to Core Assessment > Information Technology > Other Assessment Objectives. Then search for the Objective and Procedure listed in the table.
  • FFIEC IT Examination Handbook InfoBase
    • There may be multiple booklets listed. Each booklet listed will have bullets with hyperlinks, that address the booklet narrative and examination procedures.
      • Narrative: The linked text (e.g., II.C.5) refers to a section in the identified booklet’s table of contents. The hyperlink will lead to the specific section of the narrative.
      • Examination Procedures: The linked Appendix A connects to examination procedures for the corresponding booklet. The objective, procedure, and sub-procedure (e.g., Appendix A (6-10b) refers to Objective 6, Procedure 10, sub-procedure b) will be listed – click the link and scroll to the identified objective and procedure.
  • Industry Frameworks NIST Special Publication 800-53, Revision 5
    • The hyperlink goes to a PDF version of the controls catalog. The associated text can be found by searching for the identifier listed in the table.

1 NIST CSF uses the term “Asset Management,” while the CSW uses the term “IT Asset Management” to differentiate it from financial asset management.