An official website of the United States government
Share This Page:
The Cybersecurity Supervision Work Program (CSW) provides high-level examination procedures that are aligned with existing supervisory guidance and the National Institute of Standards and Technology (NIST) Cybersecurity Framework (CSF). Within the CSW Cross-References table on this page, users can filter and search for CSW procedures. The procedures are cross-referenced to common industry cybersecurity frameworks, OCC publications, and the FFIEC IT Examination Handbook. Learn more about the OCC’s cybersecurity supervision.
The CSW is a component of the OCC’s risk-based bank information technology supervision process. The CSW sets no new regulatory expectations, and national banks and federal savings associations are not expected to use this work program to assess cybersecurity preparedness.
Use the filters below to see a table of CSW procedures and the cross-references or click search without applying filters to view all data. Learn more about CSW Cross-References.
Function:
Category:
Procedure:
Unique ID:
OCC Bulletin 2017-7
The CSW Cross-References table above offers several columns of information. Select the sections below to learn more about what is displayed under each column.
The CSW is structured to align with the NIST CSF functions and categories. The table below shows how NIST aligns the categories under each function.
The CSW does not include NIST CSF categories and/or subcategories that are addressed as part of other examination programs or that do not apply to the OCC bank information technology supervision process.
The unique ID identifies the procedure and its hierarchy. Unique IDs are structured using a hierarchy of NIST CSF functions, categories, and subcategories. The OCC added two characters at the end of the unique ID to designate the specific procedure. See the figure pictured below.
During supervisory activities, examiners use the procedures to guide their reviews and evaluation of cybersecurity preparedness.
The table provides cross-references that map CSW procedures to existing supervisory guidance, examiner guidance, and industry frameworks. The cross-references are provided for informational purposes only; inclusion of products, processes, services, manufacturers, or companies in the CSW is not indicative of an OCC endorsement.
1 NIST CSF uses the term “Asset Management,” while the CSW uses the term “IT Asset Management” to differentiate it from financial asset management.