Iowa Admin. Code r. 191-90.37

Current through Register Vol. 46, No. 20, April 3, 2024
Rule 191-90.37 - [Effective until 4/24/2024] Information security program
(1) Each licensee shall implement a comprehensive written information security program that includes administrative, technical and physical safeguards for the protection of customer information. The administrative, technical and physical safeguards included in the information security program shall be appropriate to the size and complexity of the licensee and the nature and scope of the licensee's activities.
(2) A licensee's information security program shall be designed to:
a. Ensure the security and confidentiality of customer information;
b. Protect against any anticipated threats or hazards to the security or integrity of the information; and
c. Protect against unauthorized access to or use of the information that could result in substantial harm or inconvenience to any customer

Iowa Admin. Code r. 191-90.37