Organizations must have a written security policy.
Organizations must establish a baseline - risk assessment - vulnerability scan
Organizations must monitor and report on access to any files, folders, or databases
that contain consumer financial information.
Organizations must notify any consumer if you believe their information has been
compromised.
Organizations must designate a security program coordinator.
Organizations must establish and employee security awareness and training program.
Organizations must establish policies for information processing, transmission,
storage and disposal; and must review and revise following material changes.
Organizations must have appropriate measures to detect, prevent, and respond, to
attacks and intrusions.
Organizations will provide a procedure for FTC reviews or audits.
Organizations will provide oversight for contracted service provider organizations.