210 Neb. Admin. Code, ch. 77, § 008

Current through March 20, 2024
Section 210-77-008 - Manage and Control Risk

The licensee

008.01 Designs its information security program to control the identified risks, commensurate with the sensitivity of the information, as well as the complexity and scope of the licensee's activities;
008.02 Trains staff, as appropriate, to implement the licensee's information security program; and
008.03 Regularly tests or otherwise regularly monitors the key controls, systems and procedures of the information security program. The frequency and nature of these tests or other monitoring practices are determined by the licensee's risk assessment.

210 Neb. Admin. Code, ch. 77, § 008