The institution maintains an accessible written information security program scaled to its circumstances and covering the required elements.
CRITICALeCFRFTC Safeguards Rule
16 CFR Part 314 · Federal Trade Commission
Checks a written information security program against the administrative, technical and physical safeguard requirements in 16 CFR Part 314.
Requirements
Showing 8 of 55 · official summariesThe program expressly treats security and confidentiality of customer information as an objective.
HIGHeCFRThe program addresses anticipated threats and hazards affecting customer information.
HIGHeCFRThe program addresses unauthorized access or use that could harm customers.
HIGHeCFRA specific Qualified Individual is designated with responsibility for oversight, implementation, and enforcement.
CRITICALeCFRUsing an affiliate or service provider as Qualified Individual does not transfer the institution's responsibility.
HIGHeCFRA senior internal person directs and oversees an external Qualified Individual.
HIGHeCFRThe external Qualified Individual's organization is required to maintain a protective information security program.
HIGHeCFR