Under active development Content is continuously updated and improved

609.930(c)(3)609.930(c)(3)

>Control Description

Maintain an incident response plan that contains procedures the institution must implement when it suspects or detects unauthorized access to current, former, or potential customer, employee, or other sensitive or confidential information. An institution's incident response plan must be reviewed and updated periodically, but at least annually, to address new threats, concerns, and evolving technology. The incident response plan must contain procedures for:

>Cross-Framework Mappings

Ask AI

Configure your API key to use AI features.