Freddie Mac Single-Family Seller/Servicer Guide 1302.2 — Information security

fhlmc-1302-2

Freddie Mac Guide §1302.2 (Information security). Gap-fill (verbatim, ID-diff).

Get this register: .xlsx .csv More bundles →

Verbatim regulatory text (2)

Verbatim provisions from Freddie Mac Single-Family Seller/Servicer Guide 1302.2 — Information security — each quote is a verified substring of the regulator-published source snapshot, not retyped. Quoted for reference; this is not legal advice. The operational layer (P&P updates, prompts) lives in the regulation update kits.

Freddie Mac Single-Family Seller/Servicer Guide 1302.2 — Information security (part 1 of 2)

Effective 2026-07-01 · Freddie Mac's stamp for this section

This section contains: ■ Defined terms ■ Information security minimum requirements (a) Defined terms Seller/Servicers should be familiar with the following defined terms as they relate to the requirements of Section 1302.2: Information security defined terms A Authentication The process in which a system verifies the identity and role of an individual, usually based on some form of credential(s) (password/ID, token, etc.). E Encryption The process of encoding or obfuscating messages or information in such a way that only authorized parties can read it. F Freddie Mac Critical Data All information necessary for the Seller/Servicer to perform its obligations under the Seller/Servicer’s Purchase Documents, including, but not limited to, Freddie Mac confidential information and Protected Information. V Vulnerability Management The process of identifying and testing known software vulnerabilities within a system and prioritizing remediation according to each vulnerability’s likelihood of occurrence and how the exploitation of the vulnerability would impact the system. (b) Information security minimum requirements (i) Information security program Seller/Servicers must define an individual or group of individuals responsible for the development of information security requirements, including the adoption, implementation, maintenance and administration of written minimum-security standards, policies and procedures that responsibly address critical issues such as user responsibilities (e.g., “Acceptable Use”); ownership of and access to information; baseline security practices; physical, administrative and technical security protection mechanisms and other requirements. Not less than annually, Seller/Servicers must review and assess the adequacy of their information security policies and procedures used in connection with the selling and Servicing of Freddie Mac Mortgages to ensure compliance with the Guide, their other Purchase Documents and industry best practices (including as set forth by the National Institute of Standards and Technology (NIST) and International Organization for Standardization (ISO)/International Electrotechnical Commission (IEC) standards). Upon request of Freddie Mac, Seller/Servicers must make their information security program policies and procedures available; further, upon request of Freddie Mac, Seller/Servicers must provide an attestation executed by a duly authorized corporate officer of the adequacy of these policies and procedures, including following the termination of a Seller/Servicer’s right to sell or service Mortgages, or the occurrence of an Incident (as defined in Section 1302.5). (ii) Human resources security The following are requirements related to human resources security: ■ Pre-employment screening: Seller/Servicers must conduct, or retain a qualified third party to conduct, thorough background verification checks (screening) for all candidates for employment or contractor status who will have access to Freddie Mac confidential information, Protected Information or Systems (as defined in Section 2401.1(b)) ■ Code of conduct or non-disclosure agreement: Prior to being granted access to Freddie Mac confidential information, Protected Information or Systems, Seller/Servicers must require all employees, contractors and third parties to (i) sign a non-disclosure agreement or (ii) be subject to a code of conduct, which in either case includes obligations to restrict the use or disclosure of and to maintain as confidential all Freddie Mac confidential information ■ Protected Information and information related to or contained in Systems: The code of conduct must be acknowledged by the employee, contractor or third party, and must address at least the following subjects: ❑ Appropriate use of company assets ❑ Information protection, including non-disclosure and confidentiality ❑ Records management ❑ Information security and privacy ❑ Business courtesies ❑ Personal investments and insider trading ❑ Conflicts of interest ■ Information security awareness, education and training: At least annually, Seller/Servicers must provide information security awareness training to all employees and contractors who have access to Freddie Mac confidential information, Protected Information and/or Systems. The training should incorporate current cybersecurity threats, including phishing, social engineering, supply chain attacks, malware/ransomware, credential compromise via weak password hygiene, insider threats, artificial intelligence (AI)- powered tactics (e.g., deepfakes, targeted phishing content) and threats to AI systems (e.g., model inversion, data poisoning, prompt injection). When necessary, the organization personnel and partners must receive AI risk management training to enable them to perform their duties and responsibilities consistent with related policies, procedures and agreements. At a minimum, the training must address the importance of data security, provide details on roles and responsibilities for all users in protecting information at the Seller/Servicer (along with practical ways to incorporate information security into daily routines) and include the specific processes in place for protecting Freddie Mac confidential information and Protected Information. (iii)Physical and environmental security controls Seller/Servicers must create and maintain: ■ A physical security control program of the organization’s buildings and facilities that contain information systems, designed to detect, monitor and prevent unauthorized access and to respond to physical security incidents using real-time physical intrusion alarms and surveillance equipment ■ An updated list of personnel with authorized access to facilities where information systems reside, including an access privilege review performed not less than annually and upon the departure of any authorized personnel ■ Environmental controls to monitor, mitigate and protect the organization with regards to a loss of connectivity, access to or integrity of information and damage caused by natural disasters or man-made incidents such as fire, earthquake, flood, hurricane, tornado or weather-related adverse conditions ■ A clean desk policy that ensures that Freddie Mac confidential information and Protected Information are stored securely (iv) Communications and operations management Seller/Servicers must implement technical security measures designed to monitor for, mitigate against and prevent malicious software, stop unwanted spam and traffic and to protect against unauthorized use of wireless connections. Measures must include those provided in the remainder of this section or meet industry best practices, whichever is more stringent. (v) Data transmission and data loss prevention Seller/Servicers must: ■ Maintain a data loss prevention/transmission protection mechanism and related written policy establishing requirements to protect the confidentiality and integrity of information exchange using technology applications or information systems ■ Ensure adequate and up-to-date data loss prevention software is used and a corresponding management process is in place to scan for sensitive information stored on media and outgoing transmissions over public communication paths as well as to restrict the transfer of data to USB and other removable media devices at the desktop level ■ Not transmit to System(s) or the Uniform Collateral Data Portal®, through an application programming interface or otherwise, any Malicious Code. “Malicious Code” means software or firmware intended to perform an unauthorized process that may have adverse impacts on the confidentiality, integrity, or availability of an information system (including, without limitation, data in transit), such as a “virus,” “time bomb,” “worm,” “trojan horse,” or other code-based entity that infects a host; ransomware, spyware and certain forms of adware are also examples of Malicious Code. ■ Conduct regular audits to ensure compliance with data loss prevention policies and procedures and verify that data loss prevention software is functioning as intended ■ For data loss prevention policies, implement a data classification scheme to identify and categorize Freddie Mac confidential information and personal information ■ Ensure adequate and up-to-date data loss prevention software is used and a corresponding management process is in place to scan all inbound files and e-mails for malware ■ Establish an incident response plan for data loss prevention policy violations. Ensure staff are trained to respond to potential data loss incidents. (vi) Anti-virus program/updates Seller/Servicers must install anti-virus software to protect servers and end user systems and must keep all such software up to date with the latest anti-virus software and definitions. (vii) Network security Seller/Servicers must: ■ Implement information technology controls such as stateful firewalls to block all traffic inbound from, and outbound to, public networks that have not been expressly permitted by policy (i.e., “deny by default”) ■ Manage and restrict ports, protocols and services to only those that are required and approved for business operations ■ Formally recertify and authorize firewall rules upon each significant change (including, but not limited to, physical appliance updates, firmware updates and other changes to firewall technology) in infrastructure and otherwise not less than annually ■ Define a network segmentation strategy, commensurate with the Seller/Servicer’s risk profile, that is documented in policies and procedures and requires physical and logical segmentation from the user environment ■ Establish a comprehensive strategy and process for endpoint detection and response that includes continuous monitoring of endpoint detection and response and remote access technologies to detect any misuse or abuse ■ At least annually, review and update the endpoint detection and response strategy and processes to adapt to evolving threats and technologies ■ Define criteria and indicators to identify when privileged credentials are compromised or used maliciously ■ Develop procedures for prompt response and mitigation of identified threats, ensuring that all incidents involving compromised credentials are thoroughly investigated and remediated (viii) Privacy policy Seller/Servicers must maintain a written privacy policy that has been approved by management and communicated to all appropriate personnel. The policy must meet industry best practices and require the Seller/Servicer to have an easily accessible online privacy notice that complies with applicable laws. (ix) Mobile computing Seller/Servicers must maintain a written mobile device/computing management (MDM) policy that has been approved by management and communicated to all appropriate personnel. This policy must reflect current and best practices, specifying parameters including but not limited to: ■ Approved and prohibited applications ■ Cryptographic mechanisms to ensure data security ■ Identity and access management requirements ■ Software updates (x) Wireless networks Seller/Servicers must control, secure, and monitor wireless access points. In addition, Seller/Servicers that offer wireless networks for network users must: ■ Implement and keep up to date a strong Wireless Local Area Network (WLAN) Authentication method that meets or exceeds the current industry standard Encryption strength and technology ■ Prohibit use of outdated wireless technologies such as Wired Equivalent Privacy (WEP) ■ At least annually, perform reviews of approved wireless networks to validate and verify authorized users and access points ■ Password protect and control administrative access to the router (xi) Vulnerability management and penetration testing Seller/Servicers must conduct vulnerability testing on a regular basis and have a process in place to analyze and remediate identified vulnerabilities. To accomplish this, the Seller/Servicer must: ■ Not less than annually, employ a qualified and independent third party to conduct penetration testing on systems or system components used to store, access, process and/or transmit Freddie Mac confidential information or Protected Information or connect to System(s). At a minimum, the executive summary of the penetration report on Freddie Mac-related services and data should be made available to Freddie Mac for review. ■ Maintain a written vulnerability assessment process and policy that has been approved by Senior Management, including, at a minimum, the Chief Information Officer, Chief Technology Officer, Chief Information Security Office or Chief Risk Officer (or the equivalents thereof), communicated to appropriate personnel and has an owner that implements, maintains and reviews the policy at least annually to ensure that it consistently reflects industry best practices ■ As needed, document a remediation plan and remediate all identified vulnerabilities per defined service level agreements ■ Maintain a record of all identified vulnerabilities and their remediation status (xii) Configuration and patch management Seller/Servicers must: ■ Implement and maintain a written patch management process and a policy that has been approved by management, communicated to all appropriate personnel and has a designated owner that reviews, implements and maintains the policy to ensure that it consistently reflects industry best practices ■ Develop and execute a process for developing and maintaining secure configuration baselines (also known as hardening guides, baseline secure configurations) of infrastructure components ■ Deploy intrusion detection and/or prevention systems (IDS and/or IPS) with generated events fed into centralized systems for analysis ■ Define, implement and maintain preventive controls designed to block malicious messages and attachments from entering the environment ■ Designate qualified personnel responsible for performing timely software updates and patches and maintain a process for testing and installing software updates as they become available (xiii) Auditing, logging and monitoring Seller/Servicers must: ■ Develop, implement and maintain written guidelines and requirements for the logging and monitoring of activities and action within information systems. If the Seller/Servicer uses an enterprise log management function, the subject requirements must be integrated with such log management function. The Seller/Servicer may elect to use an external vendor for information security monitoring, subject to the provisions of this Chapter 1302. ■ Develop, implement and maintain written log retention and handling requirements to ensure logs retain relevant, useable and timely information sufficient to identify user access and/or system activities ■ Perform an independent security assessment of the control environment not less than annually and upon the occurrence of any Incident (as defined in Section 1302.5) (xiv) Software and application development life cycle (SDLC) If a Seller/Servicer develops or acquires any application or software that stores, accesses, processes or transmits Freddie Mac confidential information or Protected Information or connects to Systems, the Seller/Servicer must develop, implement and maintain a written SDLC process and policy that have been approved by management. This process and policy and all associated procedures collectively must incorporate current industry best practices, and specifically: ■ Establish roles and responsibilities defining who is responsible and accountable for each phase and step of the development process ■ Standardize the stages (e.g., planning, analysis, design, development, testing, deployment, maintenance) for all projects and adhere to separation of nonproduction, testing and production environments ■ Integrate security practices throughout the process of development (e.g., DevSecOps) as follows: ❑ Adherence to formal and industry recognized standards must be included. Where applicable, these standards may include (among others): ■ Open Web Application Security Project Top 10, ■ The NIST Secure Software Development Framework, ■ ISO and IEC 27034, ■ Computer Emergency Response Team Secure Coding, and ■ Computer Information Systems Controls ❑ When incorporating open-source code, a dependency inventory Software Bill of Materials must be documented and maintained ❑ Vulnerability testing during all phases prior to moving code into production must be conducted ■ Establish formal quality assurance practices, including rigorous testing during all phases. At a minimum, Seller/Servicer must perform Dynamic Application Security Testing and/or Static Application Security Testing scans on code and document results. ■ Establish a formal, documented and accountable change management process ■ Create and maintain documentation sufficient to ensure compliance with all relevant statutory, regulatory and internal policies, including all sections of the Guide (xv) Data Encryption Seller/Servicers must: ■ Maintain a formal Encryption and cryptography use policy that has been approved by Senior Management, including, at a minimum, the Chief Information Officer, Chief Technology Officer, Chief Information Security Office or Chief Risk Officer (or the equivalents thereof), and which has been communicated to appropriate personnel and has an owner that implements, maintains and reviews the policy to ensure it consistently reflects industry best practices ■ Maintain an encryption solution that enables the recovery of a compromised database administrator account ■ Maintain encryption solutions that allow privileged administrators to complete required actions without the ability to decrypt data ■ Ensure the protection, integrity and confidentiality of Freddie Mac confidential information and Protected Information using encryption methods while in transit and at rest ■ Deploy cryptography standards that meet or exceed the then-current industry standard Encryption strength and technology and prohibit use of outdated technologies ■ Generate, exchange, store, use, replace and delete cryptographic keys in a timely manner to prevent unauthorized access to those keys ■ Use Encryption mechanisms on portable end-user devices to protect data if the hardware (laptop, mobile device, etc.) is lost or stolen (xvi) Incident management Seller/Servicers must: ■ Develop and maintain, and implement when triggered, an incident response plan that provides a roadmap for implementing incident response capabilities and defines the resources and management support needed. The plan must: ❑ Be approved by Senior Management, including, at a minimum, the Chief Information Officer, Chief Technology Officer, Chief Information Security Office or Chief Risk Officer (or the equivalents thereof); ❑ Include a plan, with a clearly defined process, to shut off access to Freddie Mac Systems when an Incident occurs; ❑ As specified in Section 1302.5, address any security breaches or incidents involving Freddie Mac confidential information or Protected Information promptly and effectively; ❑ Be tested at a pre-defined periodic frequency, or more frequently, if prudent, given the circumstances; ❑ Be reviewed and updated at least annually ■ Document a process to identify and respond to malicious domains, taking immediate action to block access to these domains across all network and endpoint security systems ■ Notify relevant stakeholders and provide detailed reports on the identified threats and actions taken ■ Coordinate with Related Third Parties on Incident detection and remediation ■ Regularly review and update the response processes to adapt to evolving threats and technologies, incorporating lessons learned from past incidents to enhance the overall effectiveness of the response strategy ■ Annually, unless formally activated, test the effectiveness of the incident response plan and capabilities ■ Annually, unless formally activated, audit the incident response plan. The audit may be performed by (i) an internal independent function within the organization, or (ii) an external entity who is qualified to do such audits; ■ Evaluate lessons learned from all Incidents; ■ Implement or identify an existing classification scale for Incidents to quantify the severity of the Incident; ■ Have documented action plans for remediation of Incidents, including playbooks for Incidents related to AI/ML (as defined in Section 1302.8) (xvii) Access control A. Access management policy A Seller/Servicer must: ■ Establish, implement and maintain an access management policy that aligns with industry best practices, including a process for granting and removing system access, requirements for Authentication and rules of behavior. The access management policy must be reviewed and updated at least annually. ■ Define a process for securing administrative user and other privileged accounts, which must be reviewed and updated at least annually, and enforce access and Authentication requirements, including establishing and maintaining multifactor authentication procedures for system administrators and other privileged accounts ■ Define and enforce remote access requirements, including acceptable use, approvals and recertification processes ■ Define and enforce requirements around locked accounts after multiple failed login attempts and timeout requirements ■ Establish and enforce access control methods that limit access to systems, physical or virtual resources and grant access to users, including third parties, on a need-to-know basis ■ Define and enforce requirements for multifactor authentication where applicable (privileged sessions, remote connectivity, applications housing Freddie Mac confidential information or Protected Information, etc.) ■ Manage user accounts for System(s), in accordance with the Guide and the other Purchase Documents. Seller/Servicers must monitor account access for users who transfer roles or are terminated or no longer need access to their accounts. Seller/Servicers must notify Freddie Mac (see Directory 8) within one Business Day after any transfer or termination. Refer to and comply with the instructions to update systems access for relevant applications at https://sf.freddiemac.com/tools-learning/technology-login B. Granting, removing and reviewing access Seller/Servicers must maintain and enforce written procedures to ensure that only necessary personnel are granted access to Freddie Mac Systems. Access should be granted based on the principle of least privilege, ensuring that individuals have only the access necessary for their roles. Access to sensitive information is limited to authorized users only, commensurate with their roles and responsibilities, on a need-to-know basis. The procedures must specifically address: ■ Approval of access requests ■ Removal of access for terminations and transfers ■ Analysis of user access and removal of access that is inactive or no longer needed ■ At least annual review of all user access privileges and certification of access according to the minimum information necessary to access permission rules ■ At least twice annual review of all administrator roles and responsibilities and certification of access according to the minimum necessary to access permission rules ■ Timely compliance with Freddie Mac requests pertaining to recertification of user access privileges and/or administrator roles for Systems ■ Prohibit or prevent using the same service account identifiers and passwords in both production and non-production environments C. Authentication requirements and guidelines Seller/Servicers must authenticate employee identity with a multifactor authentication method or process that includes, but is not limited to, user identification codes, passwords, personal identification numbers, a smart card and/or a token device. Ensure that this process is fatigue resistant. Ensure that all access to Freddie Mac data requires multifactor authentication. Seller/Servicers should establish comprehensive procedures to monitor all enterprise Authentication services and processes. This includes defining criteria and indicators for detecting credential compromise or anomalous activity. Regular monitoring and analysis should be conducted to identify and respond to potential threats promptly. Additionally, third-party access should be continuously reviewed and updated to ensure compliance with security policies and to mitigate risks. If passwords are used, the Authentication policy must mandate, and Seller/Servicers must enforce, minimum guidelines for password complexity, reuse timelines and password change timelines. Seller/Servicers must utilize password vaults with multifactor authentication and ensure that no passwords are stored in unsecured files. D. Asset management Seller/Servicers must implement security measures to protect Freddie Mac confidential information and Protected Information, including encryption, secure storage solutions and regular security assessments. Seller/Servicers must ensure compliance with all relevant regulations and standards for data protection and confidentiality. Seller/Servicers must maintain an inventory management system to track physical and software assets, such as end-user technology, servers, network devices, and corresponding asset ownership. The inventory management system must be reconciled to actual inventory at least annually to verify all assets are included. Seller/Servicers must develop procedures for continuous monitoring of access and usage of Freddie Mac confidential information and Protected Information to detect and respond to any unauthorized access or anomalies. Documented procedures must be in place detailing guidelines and requirements for tracking the removal of assets from a facility. E. Cloud computing When a Seller/Servicer consumes or provides cloud services that store, process, access or transmit Freddie Mac confidential information or Protected Information or connect to any System, the Seller/Servicer must maintain and comply with policies and standards for managing cloud computing risks. The policy should address: ■ Due Diligence: Specify appropriate due diligence responsibilities, governance, ongoing oversight and monitoring of the cloud service providers’ security ■ System vulnerabilities: Articulate processes and responsibilities to securely configure cloud systems, provision access, and log and monitor the FM information assets residing in or being processed in the cloud environment. Create and maintain a process for determining the criteria for replacing or remediating the services provided by a cloud service provider when it has suffered an incident. ■ Identity and access management: Define roles for cloud access management, limiting account privileges, implementing multifactor authentication, frequently updating and reviewing account access, monitoring activity, and requiring privileged users to have separate usernames and passwords ■ Security controls for sensitive data: Define responsibilities for implementing controls to safeguard sensitive data limit a malicious actor’s ability to exploit data during a breach The cloud policy should be approved by management and communicated to appropriate personnel, and the Seller/Servicer must designate an owner to maintain and review the policy to ensure it consistently reflects industry best practices. F. Vendor risk management program Seller/Servicers must implement a vendor risk management program to formally evaluate, track and measure third-party risk; to assess its impact on all aspects of the organization’s business; and to develop compensating controls or other forms of mitigation to safeguard and protect Freddie Mac confidential information, Protected Information and Systems from unauthorized persons, malicious software or other harmful computer information, commands, codes or programs. The risk management program must include: I. Criteria for determining when to replace a Related Third Party that has experienced or is experiencing an incident and II. A process to replace the Related Third Party when such criteria are met Seller/Servicers must maintain with all Related Third Parties that store, process, access or transmit Freddie Mac confidential information or Protected Information a written agreement that obligates them to comply with Minimum Requirements similar to what is outlined within this chapter.

Source: Freddie Mac Single-Family Seller/Servicer Guide 1302.2 — Information security · source URL · snapshot 4c94f67729042dd6

Freddie Mac Single-Family Seller/Servicer Guide 1302.2 — Information security (part 2 of 2)

Effective 2026-07-01 · Freddie Mac's stamp for this section

01/01/27) This section contains: ■ Defined terms ■ Information security minimum requirements (a) Defined terms Seller/Servicers should be familiar with the following defined terms as they relate to the requirements of Section 1302.2: Information security defined terms A Authentication The process in which a system verifies the identity and role of an individual, usually based on some form of credential(s) (password/ID, token, etc.). E Encryption The process of encoding or obfuscating messages or information in such a way that only authorized parties can read it. Information security defined terms F Freddie Mac Critical Data All information necessary for the Seller/Servicer to perform its obligations under the Seller/Servicer’s Purchase Documents, including, but not limited to, Freddie Mac confidential information and Protected Information. V Vulnerability Management The process of identifying and testing known software vulnerabilities within a system and prioritizing remediation according to each vulnerability’s likelihood of occurrence and how the exploitation of the vulnerability would impact the system. (b) Information security minimum requirements (i) Information security program Seller/Servicers must define an individual or group of individuals responsible for the development of information security requirements, including the adoption, implementation, maintenance and administration of written minimum-security standards, policies and procedures that responsibly address critical issues such as user responsibilities (e.g., “Acceptable Use”); ownership of and access to information; baseline security practices; physical, administrative and technical security protection mechanisms and other requirements. Not less than annually, Seller/Servicers must review and assess the adequacy of their information security policies and procedures used in connection with the selling and Servicing of Freddie Mac Mortgages to ensure compliance with the Guide, their other Purchase Documents and industry best practices (including as set forth by the National Institute of Standards and Technology (NIST) and International Organization for Standardization (ISO)/International Electrotechnical Commission (IEC) standards). Upon request of Freddie Mac, Seller/Servicers must make their information security program policies and procedures available; further, upon request of Freddie Mac, Seller/Servicers must provide an attestation executed by a duly authorized corporate officer of the adequacy of these policies and procedures, including following the termination of a Seller/Servicer’s right to sell or service Mortgages, or the occurrence of an Incident (as defined in Section 1302.5). (ii) Human resources security The following are requirements related to human resources security: ■ Pre-employment screening: Seller/Servicers must conduct, or retain a qualified third party to conduct, thorough background verification checks (screening) for all candidates for employment or contractor status who will have access to Freddie Mac confidential information, Protected Information or Systems (as defined in Section 2401.1(b)) ■ Code of conduct or non-disclosure agreement: Prior to being granted access to Freddie Mac confidential information, Protected Information or Systems, Seller/Servicers must require all employees, contractors and third parties to (i) sign a non-disclosure agreement or (ii) be subject to a code of conduct, which in either case includes obligations to restrict the use or disclosure of and to maintain as confidential all Freddie Mac confidential information ■ Protected Information and information related to or contained in Systems: The code of conduct must be acknowledged by the employee, contractor or third party, and must address at least the following subjects: ❑ Appropriate use of company assets ❑ Information protection, including non-disclosure and confidentiality ❑ Records management ❑ Information security and privacy ❑ Business courtesies ❑ Personal investments and insider trading ❑ Conflicts of interest ■ Information security awareness, education and training: At least annually, Seller/Servicers must provide information security awareness training to all employees and contractors who have access to Freddie Mac confidential information, Protected Information and/or Systems. The training should incorporate current cybersecurity threats, including phishing, social engineering, supply chain attacks, malware/ransomware, credential compromise via weak password hygiene, insider threats, artificial intelligence (AI)- powered tactics (e.g., deepfakes, targeted phishing content) and threats to AI systems (e.g., model inversion, data poisoning, prompt injection). When necessary, the organization personnel and partners must receive AI risk management training to enable them to perform their duties and responsibilities consistent with related policies, procedures and agreements. At a minimum, the training must address the importance of data security, provide details on roles and responsibilities for all users in protecting information at the Seller/Servicer (along with practical ways to incorporate information security into daily routines) and include the specific processes in place for protecting Freddie Mac confidential information and Protected Information. (iii)Physical and environmental security controls Seller/Servicers must create and maintain: ■ A physical security control program of the organization’s buildings and facilities that contain information systems, designed to detect, monitor and prevent unauthorized access and to respond to physical security incidents using real-time physical intrusion alarms and surveillance equipment ■ An updated list of personnel with authorized access to facilities where information systems reside, including an access privilege review performed not less than annually and upon the departure of any authorized personnel ■ Environmental controls to monitor, mitigate and protect the organization with regards to a loss of connectivity, access to or integrity of information and damage caused by natural disasters or man-made incidents such as fire, earthquake, flood, hurricane, tornado or weather-related adverse conditions ■ A clean desk policy that ensures that Freddie Mac confidential information and Protected Information are stored securely (iv) Communications and operations management Seller/Servicers must implement technical security measures designed to monitor for, mitigate against and prevent malicious software, stop unwanted spam and traffic and to protect against unauthorized use of wireless connections. Measures must include those provided in the remainder of this section or meet industry best practices, whichever is more stringent. (v) Data transmission and data loss prevention Seller/Servicers must: ■ Maintain a data loss prevention/transmission protection mechanism and related written policy establishing requirements to protect the confidentiality and integrity of information exchange using technology applications or information systems ■ Ensure adequate and up-to-date data loss prevention software is used and a corresponding management process is in place to scan for sensitive information stored on media and outgoing transmissions over public communication paths as well as to restrict the transfer of data to USB and other removable media devices at the desktop level ■ Not transmit to System(s) or the Uniform Collateral Data Portal®, through an application programming interface or otherwise, any Malicious Code. “Malicious Code” means software or firmware intended to perform an unauthorized process that may have adverse impacts on the confidentiality, integrity, or availability of an information system (including, without limitation, data in transit), such as a “virus,” “time bomb,” “worm,” “trojan horse,” or other code-based entity that infects a host; ransomware, spyware and certain forms of adware are also examples of Malicious Code. ■ Conduct regular audits to ensure compliance with data loss prevention policies and procedures and verify that data loss prevention software is functioning as intended ■ For data loss prevention policies, implement a data classification scheme to identify and categorize Freddie Mac confidential information and personal information ■ Ensure adequate and up-to-date data loss prevention software is used and a corresponding management process is in place to scan all inbound files and e-mails for malware ■ Establish an incident response plan for data loss prevention policy violations. Ensure staff are trained to respond to potential data loss incidents. (vi) Anti-virus program/updates Seller/Servicers must install anti-virus software to protect servers and end user systems and must keep all such software up to date with the latest anti-virus software and definitions. (vii) Network security Seller/Servicers must: ■ Implement information technology controls such as stateful firewalls to block all traffic inbound from, and outbound to, public networks that have not been expressly permitted by policy (i.e., “deny by default”) ■ Manage and restrict ports, protocols and services to only those that are required and approved for business operations ■ Formally recertify and authorize firewall rules upon each significant change (including, but not limited to, physical appliance updates, firmware updates and other changes to firewall technology) in infrastructure and otherwise not less than annually ■ Define a network segmentation strategy, commensurate with the Seller/Servicer’s risk profile, that is documented in policies and procedures and requires physical and logical segmentation from the user environment ■ Establish a comprehensive strategy and process for endpoint detection and response that includes continuous monitoring of endpoint detection and response and remote access technologies to detect any misuse or abuse ■ At least annually, review and update the endpoint detection and response strategy and processes to adapt to evolving threats and technologies ■ Define criteria and indicators to identify when privileged credentials are compromised or used maliciously ■ Develop procedures for prompt response and mitigation of identified threats, ensuring that all incidents involving compromised credentials are thoroughly investigated and remediated (viii) Privacy policy Seller/Servicers must maintain a written privacy policy that has been approved by management and communicated to all appropriate personnel. The policy must meet industry best practices and require the Seller/Servicer to have an easily accessible online privacy notice that complies with applicable laws. (ix) Mobile computing Seller/Servicers must maintain a written mobile device/computing management (MDM) policy that has been approved by management and communicated to all appropriate personnel. This policy must reflect current and best practices, specifying parameters including but not limited to: ■ Approved and prohibited applications ■ Cryptographic mechanisms to ensure data security ■ Identity and access management requirements ■ Software updates (x) Wireless networks Seller/Servicers must control, secure and monitor wireless access points. In addition, Seller/Servicers that offer wireless networks for network users must: ■ Implement and keep up to date a strong Wireless Local Area Network (WLAN) Authentication method that meets or exceeds the current industry standard Encryption strength and technology ■ Prohibit use of outdated wireless technologies such as Wired Equivalent Privacy (WEP) ■ At least annually, perform reviews of approved wireless networks to validate and verify authorized users and access points ■ Password protect and control administrative access to the router (xi) Vulnerability management and penetration testing Seller/Servicers must conduct vulnerability testing on a regular basis and have a process in place to analyze and remediate identified vulnerabilities. To accomplish this, the Seller/Servicer must: ■ Not less than annually, employ a qualified and independent third party to conduct penetration testing on systems or system components used to store, access, process and/or transmit Freddie Mac confidential information or Protected Information or connect to System(s). At a minimum, the executive summary of the penetration report on Freddie Mac-related services and data should be made available to Freddie Mac for review. ■ Maintain a written vulnerability assessment process and policy that has been approved by Senior Management, including, at a minimum, the Chief Information Officer, Chief Technology Officer, Chief Information Security Office or Chief Risk Officer (or the equivalents thereof), communicated to appropriate personnel and has an owner that implements, maintains and reviews the policy at least annually to ensure that it consistently reflects industry best practices ■ As needed, document a remediation plan and remediate all identified vulnerabilities per defined service level agreements ■ Maintain a record of all identified vulnerabilities and their remediation status (xii) Configuration and patch management Seller/Servicers must: ■ Implement and maintain a written patch management process and a policy that has been approved by management, communicated to all appropriate personnel and has a designated owner that reviews, implements and maintains the policy to ensure that it consistently reflects industry best practices ■ Develop and execute a process for developing and maintaining secure configuration baselines (also known as hardening guides, baseline secure configurations) of infrastructure components ■ Deploy intrusion detection and/or prevention systems (IDS and/or IPS) with generated events fed into centralized systems for analysis ■ Define, implement and maintain preventive controls designed to block malicious messages and attachments from entering the environment ■ Designate qualified personnel responsible for performing timely software updates and patches and maintain a process for testing and installing software updates as they become available (xiii) Auditing, logging and monitoring Seller/Servicers must: ■ Develop, implement and maintain written guidelines and requirements for the logging and monitoring of activities and action within information systems. If the Seller/Servicer uses an enterprise log management function, the subject requirements must be integrated with such log management function. The Seller/Servicer may elect to use an external vendor for information security monitoring, subject to the provisions of this Chapter 1302. ■ Develop, implement and maintain written log retention and handling requirements to ensure logs retain relevant, useable and timely information sufficient to identify user access and/or system activities ■ Perform an independent security assessment of the control environment not less than annually and upon the occurrence of any Incident (as defined in Section 1302.5) (xiv) Software and application development life cycle (SDLC) If a Seller/Servicer develops or acquires any application or software that stores, accesses, processes or transmits Freddie Mac confidential information or Protected Information or connects to Systems, the Seller/Servicer must develop, implement and maintain a written SDLC process and policy that have been approved by management. This process and policy and all associated procedures collectively must incorporate current industry best practices, and specifically: ■ Establish roles and responsibilities defining who is responsible and accountable for each phase and step of the development process ■ Standardize the stages (e.g., planning, analysis, design, development, testing, deployment, maintenance) for all projects and adhere to separation of nonproduction, testing and production environments ■ Integrate security practices throughout the process of development (e.g., DevSecOps) as follows: ❑ Adherence to formal and industry recognized standards must be included. Where applicable, these standards may include (among others): ■ Open Web Application Security Project Top 10, ■ The NIST Secure Software Development Framework, ■ ISO and IEC 27034, ■ Computer Emergency Response Team Secure Coding, and ■ Computer Information Systems Controls ❑ When incorporating open-source code, a dependency inventory Software Bill of Materials must be documented and maintained ❑ Vulnerability testing during all phases prior to moving code into production must be conducted ■ Establish formal quality assurance practices, including rigorous testing during all phases. At a minimum, Seller/Servicer must perform Dynamic Application Security Testing and/or Static Application Security Testing scans on code and document results. ■ Establish a formal, documented and accountable change management process ■ Create and maintain documentation sufficient to ensure compliance with all relevant statutory, regulatory and internal policies, including all sections of the Guide (xv) Data Encryption Seller/Servicers must: ■ Maintain a formal Encryption and cryptography use policy that has been approved by Senior Management, including, at a minimum, the Chief Information Officer, Chief Technology Officer, Chief Information Security Office or Chief Risk Officer (or the equivalents thereof), and which has been communicated to appropriate personnel and has an owner that implements, maintains and reviews the policy to ensure it consistently reflects industry best practices ■ Maintain an encryption solution that enables the recovery of a compromised database administrator account ■ Maintain encryption solutions that allow privileged administrators to complete required actions without the ability to decrypt data ■ Ensure the protection, integrity and confidentiality of Freddie Mac confidential information and Protected Information using encryption methods while in transit and at rest ■ Deploy cryptography standards that meet or exceed the then-current industry standard Encryption strength and technology and prohibit use of outdated technologies ■ Generate, exchange, store, use, replace and delete cryptographic keys in a timely manner to prevent unauthorized access to those keys ■ Use Encryption mechanisms on portable end-user devices to protect data if the hardware (laptop, mobile device, etc.) is lost or stolen (xvi) Incident management Seller/Servicers must: ■ Develop and maintain, and implement when triggered, an incident response plan that provides a roadmap for implementing incident response capabilities and defines the resources and management support needed. The plan must: ❑ Be approved by Senior Management, including, at a minimum, the Chief Information Officer, Chief Technology Officer, Chief Information Security Office or Chief Risk Officer (or the equivalents thereof); ❑ Include a plan, with a clearly defined process, to shut off access to Freddie Mac Systems when an Incident occurs; ❑ As specified in Section 1302.5, address any security breaches or incidents involving Freddie Mac confidential information or Protected Information promptly and effectively; ❑ Be tested at a pre-defined periodic frequency, or more frequently, if prudent, given the circumstances; ❑ Be reviewed and updated at least annually ■ Document a process to identify and respond to malicious domains, taking immediate action to block access to these domains across all network and endpoint security systems ■ Notify relevant stakeholders and provide detailed reports on the identified threats and actions taken ■ Coordinate with Related Third Parties on Incident detection and remediation ■ Regularly review and update the response processes to adapt to evolving threats and technologies, incorporating lessons learned from past incidents to enhance the overall effectiveness of the response strategy ■ Annually, unless formally activated, test the effectiveness of the incident response plan and capabilities ■ Annually, unless formally activated, audit the incident response plan. The audit may be performed by (i) an internal independent function within the organization, or (ii) an external entity who is qualified to do such audits; ■ Evaluate lessons learned from all Incidents; ■ Implement or identify an existing classification scale for Incidents to quantify the severity of the Incident; ■ Have documented action plans for remediation of Incidents, including playbooks for Incidents related to AI/ML (as defined in Section 1302.8) (xvii) Access control A. Access management policy A Seller/Servicer must: ■ Establish, implement and maintain an access management policy that aligns with industry best practices, including a process for granting and removing system access, requirements for Authentication and rules of behavior. The access management policy must be reviewed and updated at least annually. ■ Define a process for securing administrative user and other privileged accounts, which must be reviewed and updated at least annually, and enforce access and Authentication requirements, including establishing and maintaining multifactor authentication procedures for system administrators and other privileged accounts ■ Define and enforce remote access requirements, including acceptable use, approvals and recertification processes ■ Define and enforce requirements around locked accounts after multiple failed login attempts and timeout requirements ■ Establish and enforce access control methods that limit access to systems, physical or virtual resources and grant access to users, including third parties, on a need-to-know basis ■ Define and enforce requirements for multifactor authentication where applicable (privileged sessions, remote connectivity, applications housing Freddie Mac confidential information or Protected Information, etc.) ■ Manage user accounts for System(s), in accordance with the Guide and the other Purchase Documents. Seller/Servicers must monitor account access for users who transfer roles or are terminated or no longer need access to their accounts. Seller/Servicers must notify Freddie Mac (see Directory 8) within one Business Day after any transfer or termination. Refer to and comply with the instructions to update systems access for relevant applications at https://sf.freddiemac.com/tools-learning/technology-login B. Granting, removing and reviewing access Seller/Servicers must maintain and enforce written procedures to ensure that only necessary personnel are granted access to Freddie Mac Systems. Access should be granted based on the principle of least privilege, ensuring that individuals have only the access necessary for their roles. Access to sensitive information is limited to authorized users only, commensurate with their roles and responsibilities, on a need-to-know basis. The procedures must specifically address: ■ Approval of access requests ■ Removal of access for terminations and transfers ■ Analysis of user access and removal of access that is inactive or no longer needed ■ At least annual review of all user access privileges and certification of access according to the minimum information necessary to access permission rules ■ At least twice annual review of all administrator roles and responsibilities and certification of access according to the minimum necessary to access permission rules ■ Timely compliance with Freddie Mac requests pertaining to recertification of user access privileges and/or administrator roles for Systems ■ Prohibit or prevent using the same service account identifiers and passwords in both production and non-production environments C. Authentication requirements and guidelines Seller/Servicers must authenticate employee identity with a multifactor authentication method or process that includes, but is not limited to, user identification codes, passwords, personal identification numbers, a smart card and/or a token device. Ensure that this process is fatigue resistant. Ensure that all access to Freddie Mac data requires multifactor authentication. Seller/Servicers should establish comprehensive procedures to monitor all enterprise Authentication services and processes. This includes defining criteria and indicators for detecting credential compromise or anomalous activity. Regular monitoring and analysis should be conducted to identify and respond to potential threats promptly. Additionally, third-party access should be continuously reviewed and updated to ensure compliance with security policies and to mitigate risks. If passwords are used, the Authentication policy must mandate, and Seller/Servicers must enforce, minimum guidelines for password complexity, reuse timelines and password change timelines. Seller/Servicers must utilize password vaults with multifactor authentication and ensure that no passwords are stored in unsecured files. D. Asset management Seller/Servicers must implement security measures to protect Freddie Mac confidential information and Protected Information, including encryption, secure storage solutions and regular security assessments. Seller/Servicers must ensure compliance with all relevant regulations and standards for data protection and confidentiality. Seller/Servicers must maintain an inventory management system to track physical and software assets, such as end-user technology, servers, network devices, and corresponding asset ownership. The inventory management system must be reconciled to actual inventory at least annually to verify all assets are included. Seller/Servicers must develop procedures for continuous monitoring of access and usage of Freddie Mac confidential information and Protected Information to detect and respond to any unauthorized access or anomalies. Documented procedures must be in place detailing guidelines and requirements for tracking the removal of assets from a facility. E. Cloud computing When a Seller/Servicer consumes or provides cloud services that store, process, access or transmit Freddie Mac confidential information or Protected Information or connect to any System, the Seller/Servicer must maintain and comply with policies and standards for managing cloud computing risks. The policy should address: ■ Due Diligence: Specify appropriate due diligence responsibilities, governance, ongoing oversight and monitoring of the cloud service providers’ security ■ System vulnerabilities: Articulate processes and responsibilities to securely configure cloud systems, provision access, and log and monitor the FM information assets residing in or being processed in the cloud environment. Create and maintain a process for determining the criteria for replacing or remediating the services provided by a cloud service provider when it has suffered an incident. ■ Identity and access management: Define roles for cloud access management, limiting account privileges, implementing multifactor authentication, frequently updating and reviewing account access, monitoring activity, and requiring privileged users to have separate usernames and passwords ■ Security controls for sensitive data: Define responsibilities for implementing controls to safeguard sensitive data limit a malicious actor’s ability to exploit data during a breach The cloud policy should be approved by management and communicated to appropriate personnel, and the Seller/Servicer must designate an owner to maintain and review the policy to ensure it consistently reflects industry best practices. F. Vendor risk management program Seller/Servicers must implement a vendor risk management program to formally evaluate, track and measure third-party risk; to assess its impact on all aspects of the organization’s business; and to develop compensating controls or other forms of mitigation to safeguard and protect Freddie Mac confidential information, Protected Information and Systems from unauthorized persons, malicious software or other harmful computer information, commands, codes or programs. The risk management program must include: I. Criteria for determining when to replace a Related Third Party that has experienced or is experiencing an incident and II. A process to replace the Related Third Party when such criteria are met Seller/Servicers must maintain with all Related Third Parties that store, process, access or transmit Freddie Mac confidential information or Protected Information a written agreement that obligates them to comply with Minimum Requirements similar to what is outlined within this chapter. (xviii) Third-party security assurance – service organization controls (SOC) 2 Type 2 compliance requirement A. SOC 2 Type 2 audit requirement Servicers whose total annual Mortgage Servicing portfolio equals or exceeds $150 billion shall, at their own expense, engage an independent, qualified auditing firm to conduct a SOC 2 Type 2 examination in accordance with the standards established by the American Institute of Certified Public Accountants (AICPA). The audit shall be performed at least annually and assess the design and operating effectiveness of Servicer’s internal controls over a reporting period of no less than six (6) consecutive months. Servicers whose total annual Mortgage Servicing portfolio is less than $150 billion should, at their own expense, engage an independent, qualified auditing firm to conduct a SOC 2 Type 2 examination in accordance with the standards established by the AICPA. The audit should be performed at least annually and assess the design and operating effectiveness of Servicer’s internal controls over a reporting period of no less than six (6) consecutive months. B. Scope of trust services criteria (TSC) Given the sensitive nature of financial services and applicable regulatory obligations, the SOC 2 Type 2 assessment shall, at a minimum, include all systems and networks that store, process or transmit Freddie Mac data and cover the following: ■ Security (Required): Controls to safeguard against unauthorized access, use or modification of systems and data ■ Availability: Controls to ensure reliable and timely access to financial systems and services ■ Confidentiality: Controls to restrict access to and protect the confidentiality of non-public financial information and other sensitive data ■ Processing Integrity: Controls to ensure that financial data processing is accurate, complete, timely and authorized ■ Privacy: If Vendor collects, processes or stores personally identifiable information, controls to ensure compliance with applicable privacy laws and commitments Freddie Mac reserves the right to require specific TSC based on the nature of services provided, risk tiering or regulatory guidance (e.g., Federal Financial Institutions Examination Council, the Gramm-Leach-Bliley Act, New York Department of Financial Services Part 500). C. Delivery and review of reports Servicer shall provide Freddie Mac with a full and unredacted copy of the final SOC 2 Type 2 report, management response and any relevant remediation plans within thirty (30) days of report issuance. Reports must be made available, upon Freddie Mac request, on at least an annual basis or upon material changes to a Servicer’s control environment. Upon Freddie Mac request, Servicers shall also provide supporting documentation evidencing control performance relevant to the services rendered. D. Submission process Freddie Mac will contact Servicers to schedule their annual risk assessment. Servicers will receive a message from Freddie Mac with instructions to upload Servicer’s required documentation to the secure portal. Servicers must use the link provided in the message to access the secure portal and follow the instructions to upload their SOC 2 Type 2 report, completed questionnaire and any additional documentation for controls not covered by the report. After submission, Servicers will receive a confirmation notification. E. Remediation of deficiencies Servicer must remediate, in a timely manner, all control exceptions or deficiencies identified in the SOC 2 Type 2 report that could impact the confidentiality, integrity or availability of Freddie Mac’s data or systems. Servicer shall provide Freddie Mac with a written remediation plan and periodic updates on remediation progress, including evidence of issue closure. F. Regulatory cooperation and oversight Servicer acknowledges that Freddie Mac is subject to oversight by financial regulators and may be required to disclose or validate the security and compliance posture of Related Third Parties. Servicer agrees to reasonably cooperate with Freddie Mac in responding to regulatory inquiries, examinations and audits and to provide relevant documentation or assurances upon request. G. Subcontractor compliance Servicers required to conduct an annual SOC2 Type 2 assessment must ensure any Related Third Party that processes, stores or transmits Freddie Mac’s proprietary information, data and Protected Information or supports critical services, also maintains SOC 2 Type 2 compliance (or equivalent audit frameworks, such as International Organization for Standards 27001 or Payment Card Industry Data Security Standards, where applicable). Servicer shall provide such reports to Freddie Mac upon request and maintain adequate oversight of such parties. H. Right to audit In addition to the SOC 2 Type 2 report, Freddie Mac reserves the right to perform its own assessment or to designate a third-party assessor to evaluate a Servicer’s security and compliance practices, including data handling, financial transaction controls and Servicer’s business operations.

Source: Freddie Mac Single-Family Seller/Servicer Guide 1302.2 — Information security · source URL · snapshot 4c94f67729042dd6

Operationalizing Freddie Mac Single-Family Seller/Servicer Guide 1302.2 — Information security

This is verbatim, source-snapshotted regulator text from the Claude for Compliance open corpus. To turn a rule like this into compliance work product: gap-analyze your policies and procedures (P&Ps) against these requirements to surface stale, conflicting, or missing provisions; operationalize any change with a ready-to-run update kit; and produce audit-ready evidence — every step grounded only in the regulator’s own words, never invented.

To work from the whole rulebook rather than this one page: download the corpus — every register on this site, verbatim, each with its source snapshot and effective date — then follow the methodology. It asks your assistant to answer only from the downloaded text, cite the register id and effective date it used, and tell you when the corpus does not cover something instead of filling the gap from memory. Running it locally also means no one sees which regulations you are looking at.

Source of record: https://claudeforcompliance.com/regs/fhlmc-1302-2/ · register fhlmc-1302-2 · Claude for Compliance. Free to read and download; see regulatory updates and methodology.