| 16 CFR 314.3; 314.4Written information security program | Maintain a written program with administrative, technical, and physical safeguards appropriate to the firm's size, complexity, and the sensitivity of customer information. | 17.1 Designate Incident-Handling Personnel · program governance across Controls 3, 5, 6, 8 |
|---|
| 16 CFR 314.4(a)Qualified individual | Designate a single qualified individual responsible for overseeing, implementing, and enforcing the program. | 17.1 Designate Incident-Handling Personnel · 14.9 Role-Specific Security Training |
|---|
| 16 CFR 314.4(b)Written risk assessment | Conduct and document a written risk assessment that identifies reasonably foreseeable internal and external risks, and base the program's safeguards on it. | 3.1 Data Management Process · 3.7 Data Classification Scheme · 1.1 Enterprise Asset Inventory · 2.1 Software Inventory · 3.2 Data Inventory |
|---|
| 16 CFR 314.4(c)(1)Access controls | Place access controls on information systems to authenticate and permit access only to authorized users, and limit access to customer information to those who need it. | 6.1 Access Granting Process · 6.2 Access Revoking Process · 6.8 Role-Based Access Control · 3.3 Data Access Control Lists |
|---|
| 16 CFR 314.4(c)(2)Encryption | Encrypt customer information at rest and in transit, or document a qualified-individual-approved compensating control where encryption is infeasible. | 3.10 Encrypt Sensitive Data in Transit · 3.11 Encrypt Sensitive Data at Rest |
|---|
| 16 CFR 314.4(c)(5)Multi-factor authentication | Require multi-factor authentication for any individual accessing any information system, unless the qualified individual approves an equivalent control in writing. | 6.3 MFA for Externally-Exposed Applications · 6.4 MFA for Remote Network Access · 6.5 MFA for Administrative Access |
|---|
| 16 CFR 314.4(e)Security awareness training | Provide security awareness training to personnel and verify that key personnel maintain current knowledge of changing threats and countermeasures. | 14.1 Security Awareness Program · 14.3 Train on Authentication Best Practices · 14.9 Role-Specific Security Training |
|---|
| 16 CFR 314.4(f)Service-provider oversight | Select and retain service providers capable of maintaining appropriate safeguards, and require those safeguards by contract; periodically assess providers based on the risk they present. | 15.1 Inventory of Service Providers · 15.2 Service Provider Management Policy · 15.4 Service Provider Contracts Include Security Requirements |
|---|
| 16 CFR 314.4(h)Incident response | Establish a written incident-response plan addressing roles, internal processes, communication, remediation, and post-incident evaluation. | 17.1 Designate Incident-Handling Personnel · 17.4 Incident Response Process · 17.7 Routine Incident Response Exercises |
|---|
| 16 CFR 314.4(i)Reporting to the board | Have the qualified individual report in writing, at least annually, to the board or a senior officer on the program's status and material matters. | 17.1 Designate Incident-Handling Personnel · governance reporting across the program |
|---|