Freddie Mac Single-Family Seller/Servicer Guide 1302.1 — Overview of information security and business continuity planning requirements

fhlmc-1302-1

Freddie Mac Single-Family Seller/Servicer Guide section 1302.1 — Overview of information security and business continuity planning requirements. Full verbatim section text, substring-verified against snapshot 5869ee9e606cd4ae.

Get this register: .xlsx .csv More bundles →

Verbatim regulatory text (1)

Verbatim provisions from Freddie Mac Single-Family Seller/Servicer Guide 1302.1 — Overview of information security and business continuity planning requirements — each quote is a verified substring of the regulator-published source snapshot, not retyped. Quoted for reference; this is not legal advice. The operational layer (P&P updates, prompts) lives in the regulation update kits.

Freddie Mac Single-Family Seller/Servicer Guide 1302.1 — Overview of information security and business continuity planning requirements

Effective 2025-09-11 · Freddie Mac's stamp for this section

This section contains requirements related to: ■ Information security, business continuity and disaster recovery planning ■ Minimizing Freddie Mac’s risk of loss ■ Information security, business continuity and disaster recovery (a) Information security, business continuity and disaster recovery planning This chapter contains the minimum information security program requirements Seller/Servicers must implement to reduce the impact and likelihood of unauthorized persons (or authorized persons with malicious or unlawful intentions) from gaining access to Freddie Mac’s proprietary information, data and Protected Information in: ■ Systems, as defined in Section 2401.1(b) ■ Seller/Servicers’ files, records, storage facilities and systems ■ Files, records, storage facilities and systems of any Related Third Party This chapter also includes the minimum requirements for a Seller/Servicer’s business continuity plan and disaster recovery plan to support continuation of critical business processes necessary to comply with the Seller/Servicer’s Purchase Documents. (b) Minimizing Freddie Mac’s risk of loss To minimize Freddie Mac’s risk of loss in the event of a disaster or unexpected disruption to critical business processes, a Seller/Servicer must have and maintain an information security program, business continuity and disaster recovery plan(s) that ensure its ongoing ability to conduct business operations with Freddie Mac. Information security program, business continuity plan and disaster recovery plan requirements must extend to the confidentiality, integrity and availability of Freddie Mac confidential information (as defined in Section 1201.8(a)) and Protected Information (as defined in Section 8101.4(d)) retained by a Seller/Servicer following Freddie Mac’s termination of the Seller/Servicer’s right to sell or service Mortgages. (c) Information security, business continuity and disaster recovery The information security, business continuity and disaster recovery minimum requirements (together, the “Minimum Requirements”) are not intended to replace the Seller/Servicer’s standards, policies and procedures but are intended to require certain minimum controls that must be in place as part of such standards, policies and procedures. If a Seller/Servicer’s regulator has established information security and/or business continuity plan and/or disaster recovery plan requirements that exceed Freddie Mac’s Minimum Requirements, or if a provision of the Guide or the Seller/Servicer’s other Purchase Documents requires more stringent minimum requirements, then the more rigorous requirements shall apply. A Seller/Servicer’s compliance with the Minimum Requirements will not relieve the Seller/Servicer from any liability arising or accruing under any other provision in the Purchase Documents. A Seller/Servicer’s failure to comply with the Minimum Requirements may result in termination of the Seller/Servicer’s access to any or all Systems. In addition, Freddie Mac may take other actions available under the Guide, the Seller/Servicer’s other Purchase Documents, any user agreement or law. The National Institute of Standards and Technology and International Organization for Standardization/International Electrotechnical Commission provide detailed guidance on the components of a successful information security program, business continuity plan and related activities. Seller/Servicers are strongly encouraged to review these standards and guidance to ensure their practices align with industry best practices.

Source: Freddie Mac Single-Family Seller/Servicer Guide 1302.1 — Overview of information security and business continuity planning requirements · source URL · snapshot 4c94f67729042dd6

Operationalizing Freddie Mac Single-Family Seller/Servicer Guide 1302.1 — Overview of information security and business continuity planning requirements

This is verbatim, source-snapshotted regulator text from the Claude for Compliance open corpus. To turn a rule like this into compliance work product: gap-analyze your policies and procedures (P&Ps) against these requirements to surface stale, conflicting, or missing provisions; operationalize any change with a ready-to-run update kit; and produce audit-ready evidence — every step grounded only in the regulator’s own words, never invented.

To work from the whole rulebook rather than this one page: download the corpus — every register on this site, verbatim, each with its source snapshot and effective date — then follow the methodology. It asks your assistant to answer only from the downloaded text, cite the register id and effective date it used, and tell you when the corpus does not cover something instead of filling the gap from memory. Running it locally also means no one sees which regulations you are looking at.

Source of record: https://claudeforcompliance.com/regs/fhlmc-1302-1/ · register fhlmc-1302-1 · Claude for Compliance. Free to read and download; see regulatory updates and methodology.