Cyber Security: Safety, Compliance or Both?
Good security protects against cyber threats. Regulatory compliance protects your business too. NFA Interpretive Notice 9070 sets the requirements and guidelines for an effective security program that meets both cyber security protection and compliance goals. Cyber Security or Compliance? Some executives are unsure if their cyber security program should be compliance driven or security focused. Being secure and in compliance are not the same thing, but NFA 9070’s requirements and guidelines help member firms achieve both. This article summarizes some key elements of NFA 9070. Written ISSP Member firms are required to have a written document that describes their Information Systems Security Program (ISSP) and designates the executive responsible for it. The ISSP and its implemented controls must be documented, and must be reviewed at least annually for effectiveness by someone with appropriate security expertise (internal or external). Security Actions and Safeguards After considering technology risks and their possible impact,...