---
kind: "section"
citation: "12 C.F.R. § 225.300"
title: "12"
number: "225.300"
heading: "Authority, purpose, and scope."
url: "https://uscodex.org/cfr/12/225.300"
---

# §225.300. Authority, purpose, and scope.

- (a) **Authority.** This subpart is issued under the authority of 12 U.S.C. [1](/usc/12/1.md), [321-338a](/usc/12/321-338a.md), [1467a(g)](/usc/12/1467a.md?p=g), [1818(b)](/usc/12/1818.md?p=b), [1844(b)](/usc/12/1844.md?p=b), [1861-1867](/usc/12/1861-1867.md), and [3101](/usc/12/3101.md) et seq.
- (b) **Purpose.** This subpart promotes the timely notification of computer-security incidents that may materially and adversely affect Board-supervised entities.
- (c) **Scope.** This subpart applies to all U.S. bank holding companies and savings and loan holding companies; state member banks; the U.S. operations of foreign banking organizations; and Edge and agreement corporations. This subpart also applies to their bank service providers, as defined in [§ 225.301(b)(2)](/cfr/12/225.301.md?p=b-2).

## Notes

### Source

Source: 86 FR 66442, Nov. 23, 2021, unless otherwise noted.

### Authority

Authority: 12 U.S.C. 1817(j)(13), 1818, 1828(o), 1831i, 1831p-1, 1843(c)(8), 1844(b), 1972(1), 3106, 3108, 3310, 3331-3351, 3354, 3906, 3907, and 3909; 15 U.S.C. 1681s, 1681w, 6801 and 6805.

### Source

Source: Reg. Y, 49 FR 818, Jan. 5, 1984, unless otherwise noted.
