Important Notice: Our web hosting provider recently started charging us for additional visits, which was unexpected. In response, we're seeking donations. Depending on the situation, we may explore different monetization options for our Community and Expert Contributors. It's crucial to provide more returns for their expertise and offer more Expert Validated Answers or AI Validated Answers. Learn more about our hosting issue here.

Does the Department require that credit monitoring be offered in the event of an information security incident?

0
Posted

Does the Department require that credit monitoring be offered in the event of an information security incident?

0

It looks like the Department may require credit monitoring in some circumstances. The Bulletin states that: Depending on the type of incident and information involved, the Department will also want to have discussions regarding the level of credit monitoring and insurance protection which the Department will require to be offered to affected consumers and for what period of time. In addition, the Department wants to review the draft letters informing individuals of the information security incident. Will the Department impose penalties? The Bulletin states that the Department will evaluate each incident independently based on the applicable circumstances, and notes that some situations may warrant imposition of administrative penalties. The Department urges licenses and registrants to follow these procedures in order to minimize the possibility for penalties. Licenses and registrants surely will need to review this guidance and incorporate it into their information security programs. O

Related Questions

What is your question?

*Sadly, we had to bring back ads too. Hopefully more targeted.

Experts123