OCC Heightened Standards (12 CFR Part 30, Appendix D)
Scope and Applicability
OCC Heightened Standards (12 CFR Part 30, Appendix D) OCCHS-1: Scope, Applicability, and Definitions of Heightened Standards
Determine scope and applicability of the OCC Heightened Standards per 12 CFR Part 30 Appendix D Section I and the OCC Heightened Standards for Large Banks final rule (effective November 2014 + revisions). The standards apply to (a) insured national banks + insured Federal savings associations + insured Federal branches of foreign banks with average total consolidated assets of USD 50 billion or more (a covered bank), (b) any insured national bank or Federal savings association the OCC notifies must comply, (c) banks below the 50 billion threshold may be voluntarily covered by their own decision or by OCC direction based on risk profile + complexity. Definitions in Section I.E apply throughout including covered bank + parent company + business line + front line unit + independent risk management + internal audit + risk + compliance risk + credit risk + interest rate risk + liquidity risk + market risk + operational risk + reputation risk + strategic risk + risk appetite + risk limit + risk profile + risk taxonomy + significant change. Communication and implementation of Standards must be documented per Section IV with phased implementation appropriate to covered bank size + complexity.
What else in your programme already covers this
This control maps to 164 controls across 92 other frameworks. If you already hold one of them, the evidence you collected for it is the starting point here rather than new work.
2.2.2 Vendor default accounts are managed as follows: • If the vendor default account(s) will be used, the default password is changed per Requirement 8.3.6. • If the vendor default account(s) will not be used,