12 CFR 609.905
§ 609.905 In general.
United States · 12 CFR — Banks and Banking · Status: effective
Cite this
- Citation
- 12 CFR 609.905, § 609.905 In general, United States, version 1 as recorded 2026-07-09, yourstate.us, https://yourstate.us/provision/47579
- Permanent ID
ys:prov:47579@1- SHA-256
c388ae38bc6aab62686b6898d13ef1c10f4db6b93fc034a5e34bf2f61c93449a
The hash is SHA-256 of this version's text, with every run of whitespace collapsed to a single space and the ends trimmed. The ID always leads back here, and checking it says whether the text you cited is still the current version.
Full text
Farm Credit System (System) institutions must engage in appropriate risk management practices to ensure safety and soundness of their operations. A System institution's board and management must maintain and document effective policies, procedures, and controls to mitigate cyber risks. This includes establishing an appropriate vulnerability management program to monitor cyber threats, mitigate any known vulnerabilities, and establish appropriate reporting mechanisms to the institution's board and the Farm Credit Administration (FCA). The vulnerability management programs should be commensurate with the size, risk profile, and complexity of the institution and based on sound industry standards and practices.
Legislative history
This is a federal regulation, adopted through agency rulemaking under the Administrative Procedure Act — not enacted by a recorded vote of Congress.