12 CFR 225.300
§ 225.300 Authority, purpose, and scope.
United States · 12 CFR — Banks and Banking · Status: effective
Cite this
- Citation
- 12 CFR 225.300, § 225.300 Authority, purpose, and scope, United States, version 1 as recorded 2026-07-09, yourstate.us, https://yourstate.us/provision/44769
- Permanent ID
ys:prov:44769@1- SHA-256
828b7c78e8ba2572d76229b37ea09feb44593be8297937cd91f6e42bd0cd6159
The hash is SHA-256 of this version's text, with every run of whitespace collapsed to a single space and the ends trimmed. The ID always leads back here, and checking it says whether the text you cited is still the current version.
Full text
(a) Authority. This subpart is issued under the authority of 12 U.S.C. 1, 321-338a, 1467a(g), 1818(b), 1844(b), 1861-1867, and 3101 et seq.
(b) Purpose. This subpart promotes the timely notification of computer-security incidents that may materially and adversely affect Board-supervised entities.
(c) Scope. This subpart applies to all U.S. bank holding companies and savings and loan holding companies; state member banks; the U.S. operations of foreign banking organizations; and Edge and agreement corporations. This subpart also applies to their bank service providers, as defined in § 225.301(b)(2).
Legislative history
This is a federal regulation, adopted through agency rulemaking under the Administrative Procedure Act — not enacted by a recorded vote of Congress.