Department Of Labor Provides Cybersecurity Guidance For Stakeholders Of ERISA-Covered Plans - Technology
Have a formal, well-documented cybersecurity program Conduct prudent annual risk assessments Obtain reliable annual third-party audits of security controls Clearly define and assign information security roles and responsibilities Create and maintain strong access control procedures Ensure assets or data stored in a cloud or managed by a service provider are subject to appropriate security reviews and independent security assessments Conduct annual cybersecurity awareness training for all personnel and updated as necessary to reflect risks identified in the most recent risk assessment Implemen...