About this Framework
The FFIEC Cybersecurity Assessment Tool (CAT) helps U.S. financial institutions identify cybersecurity risks and determine the maturity of their cybersecurity programs. Mapped to the NIST Cybersecurity Framework and the FFIEC Information Security Booklet, the CAT uses an Inherent Risk Profile (connectivity, delivery channels, external threats) to determine the appropriate Cybersecurity Maturity level across five domains. Results are widely expected by OCC, FDIC and Federal Reserve examiners during safety and soundness examinations.
Key Control Domains
Cyber Risk Management & Oversight
Threat Intelligence & Collaboration
Cybersecurity Controls
External Dependency Management
Cyber Incident Management & Resilience
Who Needs This?
- U.S. banks and credit unions of all sizes
- Savings associations and thrift institutions
- Mortgage banking and finance companies
- Financial institutions examined by OCC, FDIC or Federal Reserve
- IT service providers to federally regulated financial institutions
Compliance Benefits
- Alignment with FFIEC examiner expectations reduces examination findings
- Maps to NIST CSF enabling dual-framework efficiency
- Structured maturity measurement across five domains
- Widely accepted benchmark by federal banking regulators
Official Reference
FFIEC Cybersecurity Assessment Tool
https://www.ffiec.gov/cyberassessmenttool.htm
Assessment Details
Share this Assessment
Share this permanent link with your team, clients or auditors.
https://grcopilot.app/frameworks/ffiec-cybersecurity-assessment-tool-cat