609.930(c)(3)—609.930(c)(3)
>Control Description
Maintain an incident response plan that contains procedures the institution must implement when it suspects or detects unauthorized access to current, former, or potential customer, employee, or other sensitive or confidential information. An institution's incident response plan must be reviewed and updated periodically, but at least annually, to address new threats, concerns, and evolving technology. The incident response plan must contain procedures for:
>Cross-Framework Mappings
Ask AI
Configure your API key to use AI features.