In April 2014, the SEC’s Office of Compliance Inspections and Examinations (OCIE) released a risk alert indicating that the SEC will focus on cybersecurity as a major issue. After reviewing that risk alert, many registered investment advisers were still confused about what steps are required to comply with SEC guidance on the protection of their clients’ confidential information from hackers and data breaches.
The SEC clarified those obligations beginning in September 2015. Registered investment advisers are obligated to: 1) implement robust technical controls to protect clients’ sensitive/confidential information from reasonably foreseeable threats; and 2) adopt written policies and procedures that address administrative, technical and physical safeguards for the protection of that information.
A Brief History of the SEC’s Cybersecurity Initiative
This content has been archived. It is available through our partners, LexisNexis® and Bloomberg Law.
To view this content, please continue to their sites.
Not a Lexis Subscriber?
Subscribe Now
Not a Bloomberg Law Subscriber?
Subscribe Now
LexisNexis® and Bloomberg Law are third party online distributors of the broad collection of current and archived versions of ALM's legal news publications. LexisNexis® and Bloomberg Law customers are able to access and use ALM's content, including content from the National Law Journal, The American Lawyer, Legaltech News, The New York Law Journal, and Corporate Counsel, as well as other sources of legal information.
For questions call 1-877-256-2472 or contact us at [email protected]