Cal. Code Regs. Tit. 10, § 2689.17 - Manage and Control Risk
Current through Register 2021 Notice Reg. No. 52, December 24, 2021
The licensee:
(a)
Designs its information security program to control the identified risks,
commensurate with the sensitivity of the information as well as the complexity
and scope of the licensee's activities.
(b) Trains staff, as appropriate, to
implement the licensee's information security program; and
(c) Regularly tests or otherwise regularly
monitors the key controls, systems and procedures of the information security
program. The frequency and nature of the tests are determined by the licensee's
risk assessment.
The following state regulations pages link to this page.
State regulations are updated quarterly; we currently have two versions available. Below is a comparison between our most recent version and the prior quarterly release. More comparison features will be added as we have more versions to compare.