From: CU Insight
The Credit Union National Association (CUNA) submitted comments to the National Credit Union Administration (NCUA) regarding the Office of General Counsel’s list of regulations scheduled for review this year. Additionally, CUNA pushed for reducing the creeping complexity of credit union regulatory burden by: 1) urging NCUA to go beyond clarifications and reduce regulatory requirements substantially to provide meaningful regulatory relief for credit unions; and 2) urging NCUA to add new or expand existing rules only if required to do so by law, or doing so is clearly warranted based on a compelling safety and soundness reason that can be satisfactorily addressed in no other manner.
See full letter below:
August 4, 2014
Office of the General Counsel
National Credit Union Administration
1775 Duke Street
Alexandria, VA 22314
Re: 2014 Regulatory Review
***
Data Security and Cybersecurity
In February of this year, NCUA launched a new webpage that provides links to cybersecurity and data security resources for credit union staff, including, regulations, guidance, and best practices. We understand the agency is also working on better understanding the evolving cyber threat environment with other financial regulators, law enforcement, and intelligence communities. NCUA previously issued a risk alert (13-Risk-01) to credit unions on cybersecurity, focusing on Distributed Denial-of-Service (DDoS) attacks. These are positive steps but credit unions remain very concerned about cybersecurity issues. Of course, credit unions have no control about when cyber attackers will strike. NCUA should continue to provide cybersecurity resources and assistance to credit unions.
While credit unions are seriously concerned about cybersecurity, they are equally concerned about the potential for the development of complex, overlapping new rules in this area. In that connection, we urge NCUA to continue to coordinate closely with the Department of Homeland Security, the National Institute for Standards and Technology (NIST), the Financial Services Sector Coordinating Council for Critical Infrastructure (FSSCC), and others on the implementation of the President’s Executive Order on “critical infrastructure” cybersecurity and the voluntary NIST framework finalized this February. We also urge NCUA to ensure that the U.S. cybersecurity framework will recognize that credit unions and financial institutions are already subject to robust data security requirements and standards, such as NCUA and FFIEC rules, and should not be subject to additional regulations.
Further, we urge the agency to establish a credit union cybersecurity council or working group to help identify and address data security concerns in a manner that recognizes the unique nature and needs of credit unions, without imposing a new layer of regulatory compliance.
Leave a Reply