The licensee identifies reasonably foreseeable internal or external threats that could result in unauthorized disclosure, misuse, alteration or destruction of customer information or customer information systems; assesses the likelihood and potential damage of these threats, taking into consideration the sensitivity of customer information; and assesses the sufficiency of policies, procedures, customer information systems and other safeguards in place to control risks.
N.J. Admin. Code § 11:1-44.6