31 Pa. Code § 146c.6 - Assess risk
The licensee:
(1)
Identifies reasonably foreseeable internal or external threats that could
result in unauthorized disclosure, misuse, alteration or destruction of
customer information or customer information systems.
(2) Assesses the likelihood and potential
damage of these threats, taking into consideration the sensitivity of customer
information.
(3) Assesses the
sufficiency of policies, procedures, customer information systems and other
safeguards in place to control risks.
Notes
This section cited in 31 Pa. Code § 146c.5 (relating to examples of methods of development and implementation).
State regulations are updated quarterly; we currently have two versions available. Below is a comparison between our most recent version and the prior quarterly release. More comparison features will be added as we have more versions to compare.
No prior version found.