12 CFR Part 364, Appendix B
For FDIC-supervised institutions, the interagency guidelines require a written program with suitable administrative, technical, and physical safeguards for customer information.
Turn banking-sector cybersecurity expectations into continuous managed security and examiner-ready evidence.
View the control mappingWhere we contribute
FFIEC and FDIC expectations come from laws, regulations, examination handbooks, supervisory procedures, and interagency guidance, rather than one universal control checklist or certification. Network Box can operate and document substantial technical safeguards, while the financial institution remains accountable for its complete, risk-based information-security program.
Incident notification
Reviewed September 2, 2026An FDIC-supervised banking organization must notify the FDIC as soon as possible and no later than 36 hours after it determines that a computer-security incident has risen to the level of a notification incident.
Read the FDIC incident-notification rule summary ↗Regulatory foundation
The applicable agency, charter, activities, technologies, and risk profile determine which requirements and examination procedures apply. These four anchors frame this service mapping.
For FDIC-supervised institutions, the interagency guidelines require a written program with suitable administrative, technical, and physical safeguards for customer information.
The handbook and risk-focused examination procedures help examiners evaluate governance, security, operations, audit, resilience, development, and provider oversight.
FFIEC guidance emphasizes risk assessment, layered security, monitoring, and MFA or controls of equivalent strength when warranted by risk.
The FFIEC Cybersecurity Assessment Tool was sunset on August 31, 2025. This page intentionally maps to current handbook, regulatory, and supervisory expectations instead.
Legal baseline
Appendix B to 12 CFR Part 364 requires an institution's program to include safeguards appropriate to its size, complexity, activities, and customer-information risks. Network Box primarily strengthens the technical and operational portions.
| Framework area | Network Box contribution | Relevant services | Coverage |
|---|---|---|---|
| Management reporting, trends, incidents, findings, and service reviews give leadership evidence for oversight. | Supporting | ||
Detailed mapping2 mapping notes The board or an appropriate committee approves the written information-security program and oversees its development, implementation, and maintenance. Network Box contributionSupportingNetwork Box can provide management-level risk trends, incident summaries, open findings, service performance, and operational reporting for managed safeguards. Financial institution responsibilityClient responsibilityApprove and oversee the program, set accountability and risk appetite, challenge management, and ensure material matters reach the board. | |||
| Technical findings and observed activity provide inputs to the institution's enterprise risk assessment. | Partial | ||
Detailed mapping2 mapping notes Identify foreseeable internal and external threats, assess likelihood and potential damage, and evaluate the sufficiency of safeguards for customer information and supporting systems. Network Box contributionPartialVulnerability findings, attack trends, telemetry, incident history, threat intelligence, and architecture observations identify technical exposure within the managed scope. Financial institution responsibilityClient responsibilityDetermine business impact, inherent and residual risk, risk acceptance, legal obligations, and treatment priorities across the entire institution. | |||
| Managed preventive, detective, and responsive controls turn selected safeguards into repeatable operations. | Strong | ||
Detailed mapping2 mapping notes Select, implement, test, and maintain safeguards appropriate to the institution's risk assessment, systems, and customer information. Network Box contributionStrongNetwork Box configures, operates, monitors, updates, and documents the subscribed security controls and recommends improvements within scope. Financial institution responsibilityClient responsibilitySelect the complete control set, train personnel, protect systems outside the service, remediate weaknesses, test key controls, and accept or treat residual risk. | |||
| Service descriptions, responsibilities, performance records, incident provisions, and assurance information support oversight. | Supporting | ||
Detailed mapping2 mapping notes Exercise due diligence, require providers by contract to implement appropriate safeguards, and monitor provider performance and control effectiveness. Network Box contributionSupportingNetwork Box can document service scope, responsibilities, architecture, security measures, performance, incidents, continuity arrangements, and available assurance information. Financial institution responsibilityClient responsibilityInventory and risk-tier providers, perform due diligence, negotiate and approve contracts, monitor performance and concentration risk, and maintain transition and exit plans. | |||
| Threat, vulnerability, incident, service, and architecture changes provide concrete triggers for program improvement. | Supporting | ||
Detailed mapping2 mapping notes Update the information-security program when technology, threats, business arrangements, customer-information sensitivity, or the institution's risk profile changes. Network Box contributionSupportingNetwork Box supplies current threat information, recurring findings, incident lessons, service changes, and technical recommendations that can inform program adjustments. Financial institution responsibilityClient responsibilityDecide and document changes to policies, safeguards, risk treatment, staffing, provider arrangements, testing, and governance across the enterprise. | |||
| Operational metrics and security evidence can be incorporated into institution-led board reporting. | Supporting | ||
Detailed mapping2 mapping notes Management reports at least annually and as otherwise appropriate on program status, risk assessment, controls, testing, providers, breaches or violations, and responses. Network Box contributionSupportingNetwork Box can provide dashboards, trends, incidents, vulnerabilities, service performance, and unresolved technical findings for managed services. Financial institution responsibilityClient responsibilityDetermine reporting content and cadence, explain enterprise risk and material issues, document board review, and track management commitments to completion. | |||
These mappings are illustrative and depend on deployment, configuration, service scope, the client environment, and evidence requirements. Strong, Partial, and Supporting describe Network Box's potential contribution, not a compliance conclusion.
Control mapping
This detailed matrix connects managed security operations to current FFIEC handbook and FDIC supervisory themes. Each row separates the Network Box contribution from the institution's continuing responsibility.
| Framework area | Network Box contribution | Relevant services | Coverage |
|---|---|---|---|
| Operational reporting, trends, incident summaries, and open findings support informed oversight. | Supporting | ||
Detailed mapping2 mapping notes Leadership should understand technology risk, set direction and accountability, challenge management, and receive timely information about control condition and material issues. Network Box contributionSupportingNetwork Box can furnish risk trends, incident and vulnerability summaries, service performance, dashboards, and unresolved findings for the managed scope. Financial institution responsibilityClient responsibilitySet risk appetite, approve governance and the information-security program, assign accountability, oversee management, and ensure timely remediation and escalation. | |||
| Documented managed services turn selected technical safeguards into repeatable, evidenced operations. | Partial | ||
Detailed mapping2 mapping notes Maintain a comprehensive written program appropriate to the institution's size, complexity, activities, and customer-information risk. Network Box contributionPartialService descriptions, control information, configurations, procedures, monitoring, and operational evidence can document safeguards Network Box manages. Financial institution responsibilityClient responsibilityOwn the complete program, policies, standards, risk basis, roles, approvals, non-technical controls, exceptions, testing, and updates. | |||
| Vulnerability, threat, event, architecture, and incident data provide current technical risk inputs. | Partial | ||
Detailed mapping2 mapping notes Identify threats, vulnerabilities, likelihood, impact, controls, and residual risk across systems, data, products, services, locations, and dependencies. Network Box contributionPartialNetwork Box identifies technical exposures, attack patterns, observed events, architecture concerns, and control gaps within its service visibility. Financial institution responsibilityClient responsibilityDetermine business impact, inherent and residual risk, risk tolerance, legal obligations, treatment priorities, and accepted exceptions across the enterprise. | |||
| Managed inventories and discovery document assets, services, log sources, interfaces, and protected segments in scope. | Partial | ||
Detailed mapping2 mapping notes Maintain accurate inventories and understand customer information, critical services, supporting technologies, data flows, and internal and external dependencies. Network Box contributionPartialNetwork Box can inventory managed devices, services, log sources, external connections, interfaces, and protected network segments. Financial institution responsibilityClient responsibilityMaintain the authoritative enterprise inventory, classify data, map business services and data flows, and identify every critical internal, cloud, and third-party dependency. | |||
| Managed enforcement points reduce attack paths and control traffic across locations and trust zones. | Strong | ||
Detailed mapping2 mapping notes Design resilient, supportable architecture with controlled boundaries, segmentation, secure connectivity, and appropriate monitoring for the institution's risks. Network Box contributionStrongNetwork Box designs and operates managed firewalls, routing policy, segmentation, VPN, SD-WAN, intrusion prevention, and monitored trust boundaries. Financial institution responsibilityClient responsibilityOwn enterprise architecture decisions, complete data-flow and dependency mapping, systems outside scope, acceptance of residual paths, and alignment to business resilience needs. | |||
| Controlled configurations, restricted administration, managed updates, and change records protect subscribed security services. | Partial | ||
Detailed mapping2 mapping notes Establish secure baselines, authorize and test changes, monitor for unauthorized change, and maintain systems throughout their lifecycle. Network Box contributionPartialNetwork Box maintains controlled configurations, policies, updates, administrative restrictions, and relevant change records for the systems and services it manages. Financial institution responsibilityClient responsibilityGovern configuration and change across endpoints, servers, applications, databases, cloud services, identity platforms, and all other technology outside scope. | |||
| Recurring assessment and prioritized findings drive a continuous remediation cycle when subscribed. | Partial | ||
Detailed mapping2 mapping notes Identify, evaluate, prioritize, remediate, and verify vulnerabilities across the technology environment according to risk and exposure. Network Box contributionPartialNetwork Box assesses agreed assets, validates and prioritizes weaknesses, maintains managed security systems, and supplies remediation guidance and trends. Financial institution responsibilityClient responsibilityPatch and remediate client-owned endpoints, servers, applications, databases, network devices, and cloud services; approve treatment; and verify closure. | |||
| Secure remote access, policy enforcement, supported MFA, and access telemetry protect managed entry points. | Partial | ||
Detailed mapping2 mapping notes Apply risk-based authentication, layered security, least privilege, account governance, and monitoring to customers, personnel, administrators, applications, and third parties. Network Box contributionPartialNetwork Box supports VPN controls, directory integration, MFA capabilities, restricted administration, traffic policy, segmentation, and access logging within scope. Financial institution responsibilityClient responsibilityOwn identity proofing, account lifecycle, customer authentication, privileged-access governance, service accounts, access reviews, application access, recovery, and enterprise MFA coverage. | |||
| Centralized telemetry, correlation, alerting, analyst review, and reporting provide continuous visibility. | Strong | ||
Detailed mapping2 mapping notes Collect, protect, analyze, and retain sufficient records to detect unauthorized activity, support accountability, investigate events, and demonstrate control operation. Network Box contributionStrongNetwork Box centralizes connected telemetry, monitors managed services, correlates activity, investigates alerts, identifies interrupted sources, and produces reports. Financial institution responsibilityClient responsibilityDefine required events and retention, connect every necessary source, synchronize clocks, protect records, validate coverage, and meet legal and business evidence needs. | |||
| Layered inspection blocks malicious traffic, exploitation, phishing, harmful content, malware, and command-and-control activity. | Strong | ||
Detailed mapping2 mapping notes Deploy layered preventive and detective controls appropriate to external threats, user channels, data sensitivity, and the institution's attack surface. Network Box contributionStrongManaged network, web, email, endpoint, and threat-intelligence controls inspect, block, detect, and report malicious activity within the subscribed scope. Financial institution responsibilityClient responsibilityEnsure coverage reaches every relevant endpoint, application, cloud service, branch, channel, and user; configure complementary controls; and remediate affected systems. | |||
| WAF, intrusion prevention, monitoring, and vulnerability assessment protect public applications when subscribed. | Strong | ||
Detailed mapping2 mapping notes Identify and manage internet exposure and secure customer-facing and other critical applications throughout acquisition, development, operation, and maintenance. Network Box contributionStrongNetwork Box can protect public applications, detect attacks, monitor telemetry, assess exposure, and identify exploitable weaknesses within scope. Financial institution responsibilityClient responsibilityOwn secure design and development, authentication, authorization, input validation, secrets, dependencies, code testing, remediation, fraud controls, and application resilience. | |||
| The 24/7 SOC converts subscribed tools and telemetry into an operating detection-and-response capability. | Strong | ||
Detailed mapping2 mapping notes Maintain people, processes, technologies, intelligence, and escalation paths capable of identifying and responding to changing threats. Network Box contributionStrongAnalysts continuously monitor, validate, prioritize, investigate, document, and escalate potential incidents and coordinate available response actions. Financial institution responsibilityClient responsibilityEnsure suitable enterprise coverage, integrate business and fraud context, maintain decision authority, staff complementary functions, and govern response beyond the service scope. | |||
| Investigation, escalation, containment assistance, documentation, and continuing updates support institution-led response. | Strong | ||
Detailed mapping2 mapping notes Prepare, test, and operate an enterprise response capability spanning detection, analysis, containment, recovery, communication, evidence, and lessons learned. Network Box contributionStrongNetwork Box can detect, analyze, prioritize, document, escalate, and assist with containment and technical remediation using available controls and telemetry. Financial institution responsibilityClient responsibilityOwn the enterprise plan, exercises, executive decisions, crisis management, legal analysis, evidence preservation, business recovery, public communication, and coordination with other parties. | |||
| Fast technical facts help the bank evaluate material disruption and meet decision-driven notification timelines. | Supporting | ||
Detailed mapping2 mapping notes Determine whether an event meets applicable regulatory definitions and complete accurate, timely notification to the proper authority. Network Box contributionSupportingNetwork Box can provide alerts, investigation findings, timelines, affected assets, impact observations, indicators, logs, and response updates. Financial institution responsibilityClient responsibilityMake and document the legal determination, notify the FDIC or other regulator, manage regulator communication, and address customer, law-enforcement, insurer, and contractual obligations. | |||
| Continuous monitoring, incident support, configuration records, and restoration of managed controls support resilience. | Partial | ||
Detailed mapping2 mapping notes Identify critical services and dependencies, set recovery objectives, maintain resilient operations, and test continuity and disaster-recovery capabilities. Network Box contributionPartialWhere contracted, Network Box supports resilient security architecture, monitors service health, assists during incidents, and restores managed security functions. Financial institution responsibilityClient responsibilityPerform business-impact analysis, own recovery objectives and plans, maintain backups and workarounds, manage crisis communication, test critical dependencies, and remediate gaps. | |||
| Protected configuration and recovery procedures support restoration of Network Box-managed security functions. | Supporting | ||
Detailed mapping2 mapping notes Maintain protected, recoverable, and tested data and system backups consistent with business, resilience, legal, and security requirements. Network Box contributionSupportingNetwork Box can protect relevant managed configurations and restore its managed appliances and services under agreed procedures. Financial institution responsibilityClient responsibilityBack up and restore business data, applications, databases, identity systems, endpoints, cloud workloads, and dependencies; isolate backups; and test recovery. | |||
| Service, security, performance, incident, continuity, and assurance information supports due diligence and monitoring. | Partial | ||
Detailed mapping2 mapping notes Manage third-party relationships through planning, due diligence, contracting, ongoing monitoring, issue management, and termination according to risk. Network Box contributionPartialNetwork Box can document its services, responsibilities, architecture, performance, security measures, incident provisions, continuity, and available independent assurance. Financial institution responsibilityClient responsibilityInventory and risk-tier providers, approve arrangements, negotiate required rights, monitor performance and changes, manage fourth-party and concentration risk, and maintain exit strategies. | |||
| Education, simulations, administration, and metrics improve workforce recognition of social engineering when subscribed. | Strong | ||
Detailed mapping2 mapping notes Maintain an awareness program appropriate to personnel roles, emerging threats, policy responsibilities, and the institution's risk profile. Network Box contributionStrongNetwork Box can deliver awareness content, phishing simulations, campaign administration, participation data, susceptibility metrics, and follow-up reporting. Financial institution responsibilityClient responsibilityDefine the program, assign role-based and leadership training, address non-completion and repeated risk, train new personnel, and integrate awareness with policy and incident reporting. | |||
| Operational records provide evidence for audit and examinations but do not replace independent challenge. | Supporting | ||
Detailed mapping2 mapping notes Use qualified, independent audit and testing to assess control design and operation, report deficiencies, and verify timely corrective action. Network Box contributionSupportingNetwork Box can supply configurations, logs, alerts, findings, tickets, changes, investigations, reports, and available assurance material for the managed scope. Financial institution responsibilityClient responsibilitySet the audit universe and risk-based schedule, preserve independence, commission required testing, assess sufficiency, report results, and govern remediation. | |||
| Segmentation, traffic controls, secure connectivity, inspection, and monitoring protect sensitive data flows. | Partial | ||
Detailed mapping2 mapping notes Protect customer and sensitive information throughout collection, use, transmission, storage, retention, sharing, and disposal according to risk and law. Network Box contributionPartialNetwork Box can control and monitor communications, reduce unauthorized paths, protect traffic in transit, filter content, and detect suspicious transfer activity. Financial institution responsibilityClient responsibilityClassify data, govern use and disclosure, protect data at rest, manage encryption keys, set retention and disposal, validate cryptography, and enforce controls throughout the complete environment. | |||
| Security assessment, WAF, architecture input, controlled service changes, and monitoring support the technology lifecycle. | Partial | ||
Detailed mapping2 mapping notes Govern technology projects and systems from planning and acquisition through secure development, testing, implementation, maintenance, and retirement. Network Box contributionPartialNetwork Box can identify vulnerabilities, protect deployed applications, monitor production activity, manage changes to its services, and contribute security architecture observations. Financial institution responsibilityClient responsibilityOwn project risk, secure development, code and dependency testing, vendor and supply-chain risk, acceptance, patching, data migration, end-of-life planning, and systems outside scope. | |||
These mappings are illustrative and depend on deployment, configuration, service scope, the client environment, and evidence requirements. Strong, Partial, and Supporting describe Network Box's potential contribution, not a compliance conclusion.
Third-party risk
The institution, MSP, Network Box, and other material providers should document systems and data in scope; control ownership; administrative access; telemetry handling; service levels; incident contacts and timing; log ownership and retention; vulnerability remediation; continuity testing; subcontractors; assurance information; regulatory cooperation; and termination or transition duties.
Incident readiness
Regulatory notification is a governance and legal decision supported by technical facts. Detection, decision, escalation, and communication arrangements should be tested instead of improvised under pressure.
Identify who determines whether an event meets the notification-incident definition and who is authorized to contact the regulator.
Maintain tested contacts and redundant escalation paths between the SOC, MSP, institution, counsel, leadership, and service providers.
Document when facts became sufficient for the bank to determine that a qualifying notification incident occurred and preserve the basis for that decision.
Quickly establish affected services, duration, customer impact, business-line impact, continuing activity, and likely operational consequences.
Contracts and playbooks should address the separate four-hour service-disruption threshold applicable to covered bank service providers.
Evaluate customer-information response, customer notice, law-enforcement, insurer, contractual, and other reporting duties independently.
Assessment evidence
Available evidence depends on deployed services, configured log sources, agreed scope, format, and retention period.
Coverage key
Network Box can directly deliver and operate a substantial part of this technical outcome when the relevant services are in scope.
Network Box contributes meaningful controls, but the requirement also depends on the client's systems, configuration, people, or processes.
Network Box provides useful security operations or evidence, but does not satisfy the requirement by itself.
This area primarily remains with the MSP and client, their assessors, or other qualified parties.
Shared responsibility
The institution and its board own governance, the written information-security program, enterprise risk assessment, customer-information protection, identity and data governance, business continuity, independent testing, regulatory decisions and notifications, and oversight of every service provider. Outsourcing security operations does not outsource accountability.
FFIEC / FDIC FAQ
Turn banking-sector cybersecurity expectations into continuous managed security and examiner-ready evidence.
Network Box USA can operate managed technical safeguards, monitor the subscribed environment, investigate and escalate security activity, maintain managed configurations, and produce service evidence that may support applicable FFIEC / FDIC requirements.
No. A managed security service can contribute controls, operations, and evidence, but it cannot guarantee compliance or replace the organization's governance, complete scope, legal interpretation, assessment, or formal certification and attestation work.
Use the mapping as a scoping and evidence-planning aid. Each row explains the requirement, the potential Network Box contribution, available evidence, the coverage level, and the work that remains with the organization.
Depending on the deployed services and agreed retention, evidence may include managed configurations, logs, alerts, incident records, vulnerability findings, change records, service reports, and recurring operational reviews. The assessor determines whether evidence is sufficient.
The institution and its board own governance, the written information-security program, enterprise risk assessment, customer-information protection, identity and data governance, business continuity, independent testing, regulatory decisions and notifications, and oversight of every service provider. Outsourcing security operations does not outsource accountability.
The information in this Compliance Center is provided for general informational purposes and does not constitute legal, regulatory, audit, or certification advice. Requirements vary by organization, jurisdiction, contract, data, and system scope. Network Box services can support selected technical and operational safeguards but do not by themselves establish compliance, certification, or attestation. Each organization remains responsible for determining its obligations, defining scope, implementing governance and non-technical controls, and obtaining advice or assessment from qualified legal, compliance, audit, or certification professionals.
Security stack review