Would the regulators expect to see a log of detected activity and resulting mitigation?
The Rule does not require you to maintain a log, nor do the Guidelines suggest that a log should be maintained. You are, however, required to prepare regular reports on the effectiveness of your Program, and you also are required to incorporate your own experiences with identity theft when you review and update your Program.
Related Questions
- I submitted a request and have reviewed the Request Details, Activity Log, and Process View from the Request Entry console. How do I get more information regarding my request?
- Would the regulators expect to see a log of detected activity and resulting mitigation?
- New to Activity Adventure Holidays in Spain - or not sure what to expect?