Training – Are You Doing Enough To Meet Regulatory Expectations?
The Division of Investment Management’s recent cybersecurity guidance suggested that firms consider implementing training to provide guidance to officers and employees “concerning applicable threats and measures to prevent, detect, and respond to… threats and that monitor compliance with cybersecurity policies and procedures.” In addition, the Division suggested that firms “may wish [...]
Is Risk Assessment Mandatory Via Recent SEC and FINRA Guidance?
This may be one of those cases where regulatory expectation is just as important as the written Rule. The Division of Investment Management's April 28 guidance used the following language: “In the staff’s view, there are a number of measures that funds and advisers may wish to consider in addressing cybersecurity [...]
Security Through Data Classification Part III – Administration
The regulatory expectation from both the SEC and the DOJ is that your firm will implement some form of a data classification system that will allow you to adequately protect your business’s sensitive information. We have previously discussed the creation and implementation of such a program. In this post we will [...]
Security Through Data Classification Part II – Defining a Schema
As we discussed in Part I of our data classification series, the regulatory expectation from both the SEC and the DOJ is that your firm will implement some form of a data classification system that will allow you to adequately protect your business’s sensitive information. In addition, a thoughtfully executed data classification system [...]
Fraud, Breach, and Insider Activity
Just weeks ago, SEC Commissioner Aguilar’s Chief of Staff noted that the SEC is about to enter “a time of great change” regarding regulation for breach disclosure. Just weeks later, the guidance from the Division of Investment Management reinforced this notion by commenting that “in the staff’s view, funds and advisers [...]
Security Through Data Classification
Data Classification, Retention, and Security Part 1: What Do We Have Here? Recent SEC and DOJ guidance has placed great emphasis on Data Security through Data Classification. Regulators are expecting you to classify your information based upon criticality and sensitivity, but where do you begin? Take a minute and think about all [...]