{"data":{"id":"us/12-cfr-225.300","jurisdiction":"us","citation":"12 CFR 225.300","heading":"Authority, purpose, and scope.","body":"(a) Authority. This subpart is issued under the authority of 12 U.S.C. 1, 321-338a, 1467a(g), 1818(b), 1844(b), 1861-1867, and 3101 et seq.\n(b) Purpose. This subpart promotes the timely notification of computer-security incidents that may materially and adversely affect Board-supervised entities.\n(c) Scope. This subpart applies to all U.S. bank holding companies and savings and loan holding companies; state member banks; the U.S. operations of foreign banking organizations; and Edge and agreement corporations. This subpart also applies to their bank service providers, as defined in § 225.301(b)(2).","path":["Title 12—Banks and Banking","CHAPTER II—FEDERAL RESERVE SYSTEM","SUBCHAPTER A—BOARD OF GOVERNORS OF THE FEDERAL RESERVE SYSTEM","PART 225—BANK HOLDING COMPANIES AND CHANGE IN BANK CONTROL (REGULATION Y)","Subpart N—Computer-Security Incident Notification"],"source_url":"https://www.ecfr.gov/api/versioner/v1/full/2026-08-25/title-12.xml","current_through":"2026-08-25","vintage":"","retrieved_at":"2026-08-27T02:24:16Z","sha256":"98529e2213e5ee864b22009c9b45f8ecda1b33ace550361cde52a1d768743b4c","source_id":"us-cfr","stale":true,"prev":"us/12-cfr-225.196","next":"us/12-cfr-225.301"},"notice":"GroundRules: Original legal text. Not legal advice."}
