Access cybersecurity resources related to the financial sector. Additional cybersecurity resources are provided by the DHS, CISA, FBI Infragard, and US-CERT.
Examination
The Examiner's Guide provides guidance and serves as a resource for NCUA staff to use in the supervision of credit unions.
National Supervision Policy Manual
This manual establishes NCUA’s national policies, procedures, and guidelines for effective district management, credit union supervision, and quality assurance.
Awareness
Federal Financial Institutions Examination Council Cybersecurity Awareness
The Federal Financial Institutions Examination Council (FFIEC) Cybersecurity Awareness webpage provides resources to help financial institutions understand supervisory expectations, increase awareness of cybersecurity risks, and assess and mitigate the risks facing their institutions in light of the increasing volume and sophistication of cyber threats.
Cybersecurity & Infrastructure Security Agency
The Cybersecurity and Infrastructure Security Agency (CISA) is the nation’s risk advisor, working with partners to defend against today’s threats and collaborating to build more secure and resilient infrastructure for the future. CISA builds the national capacity to defend against cyber-attacks and works with the federal government to provide cybersecurity tools, incident response services and assessment capabilities that support the essential operations of partner departments and agencies.
InfraGard is a partnership between the FBI and the private sector. It is an association comprised of businesses, academic institutions, state and local law enforcement agencies, and other participants dedicated to sharing information and intelligence to prevent hostile acts against the U.S.
United States Computer Emergency Readiness Team
The Department of Homeland Security's United States Computer Emergency Readiness Team (US-CERT) leads efforts to improve the nation's cybersecurity posture, coordinate cyber information sharing, and proactively manage cyber risks to the Nation while protecting the constitutional rights of Americans. US-CERT strives to be a trusted global leader in cybersecurity—collaborative, agile, and responsive in a dynamic and complex environment.
Common Best Practices
Special Publications in the 800 series present documents of general interest to the computer security community. The Special Publication 800 series was established in 1990 to provide a separate identity for information technology security publications. This Special Publication 800 series reports on Information Technology Laboratory's research, guidelines, and outreach efforts in computer security, and its collaborative activities with industry, government, and academic organizations.
The Framework is voluntary guidance, based on existing standards, guidelines, and practices for organizations to better manage and reduce cybersecurity risk. In addition to helping organizations manage and reduce risks, it was designed to foster risk and cybersecurity management communications amongst both internal and external organizational stakeholders.
Center for Internet Security (CIS) Controls
The CIS is a community-driven nonprofit that created the CIS Controls and CIS Benchmarks™, which are globally recognized best practices for securing IT systems and data. CIS leads a global community of IT professionals to continuously evolve these standards and provide products and services to proactively safeguard against emerging threats. Our CIS Hardened Images provide secure, on-demand, scalable computing environments in the cloud.
ISO/IEC 27001 Information Security Management
ISO/IEC 27001 is widely known and establishes standards for an information security management system, though there are more than a dozen standards in the ISO/IEC 27000 family. Using these standards supports organizations in managing the security of assets like financial information, intellectual property, employee details, or third-party data.
Over the years, best-practice frameworks have been developed and promoted to assist in the process of understanding, designing and implementing enterprise governance of information and technology. COBIT 2019 builds on and integrates more than 25 years of development in this field, not only incorporating new insights from science, but also transforming these insights into practices. From its foundation in the IT audit community, COBIT has developed into a broader and more comprehensive information and technology (I&T) governance and management framework and continues to establish itself as a generally accepted framework for I&T governance.
Information Sharing
National Credit Union Information Sharing Analysis Organization (requires membership)
Following the signing of the Cybersecurity Information Sharing Act into law, the National Credit Union Information Sharing Analysis Organization was established in 2016 to address the unique needs of the nation’s Credit Unions, advancing cyber resilience through information sharing, education, operational guidance, and regulatory compliance.
Financial Services Information Sharing and Analysis Center (requires membership)
Launched in 1999, FS-ISAC was established by the financial services sector in response to 1998's Presidential Directive 63. That directive - later updated by 2003's Homeland Security Presidential Directive 7 - mandated that the public and private sectors share information about physical and cybersecurity threats and vulnerabilities to help protect the U.S. critical infrastructure.
FBI’s Internet Crime Complaint Center (IC3)
The Internet Crime Complaint Center provides the public with a reliable and convenient reporting mechanism to submit information to the FBI concerning suspected internet-facilitated criminal activity and to develop effective alliances with law enforcement and industry partners. Information is analyzed and disseminated for investigative and intelligence purposes to law enforcement and for public awareness.
Additional Cybersecurity Resources
CISA Good Security Habits (Security Tips (ST04-03)
Conference of State Bank Supervisors: Ransomware self-assessment tool (R-SAT)
Department of Treasury: Advisory on Potential Sanctions Risks for Facilitating Ransomware Payments