{"data":{"id":"us/12-cfr-609.935","jurisdiction":"us","citation":"12 CFR 609.935","heading":"Business planning.","body":"The annually approved business plan required under subpart J of part 618 of this chapter, and § 652.60 of this chapter for System institutions and the Federal Agricultural Mortgage Corporation, respectively, must include a technology plan that, at a minimum:\n(a) Describes the institution's intended technology goals, performance measures, and objectives;\n(b) Details the technology budget;\n(c) Identifies and assesses the adequacy of the institution's entire cyber risk management program, including proposed technology changes;\n(d) Describes how the institution's technology and security support the current and planned business operations; and\n(e) Reviews internal and external technology factors likely to affect the institution during the planning period.","path":["Title 12—Banks and Banking","CHAPTER VI—FARM CREDIT ADMINISTRATION","SUBCHAPTER B—FARM CREDIT SYSTEM","PART 609—CYBER RISK MANAGEMENT","Subpart B—Standards for Boards and Management"],"source_url":"https://www.ecfr.gov/api/versioner/v1/full/2026-08-25/title-12.xml","current_through":"2026-08-25","vintage":"","retrieved_at":"2026-08-27T02:24:16Z","sha256":"3f9a2392340ecd637ae295fba776b3a2863694190883b84db722b98d1cc593fb","source_id":"us-cfr","stale":true,"prev":"us/12-cfr-609.930","next":"us/12-cfr-609.945"},"notice":"GroundRules: Original legal text. Not legal advice."}
