From: Metropolitan Corporate Counsel
Kenneth L. Greenberg/Stradley Ronon Stevens & Young, LLP
The Securities and Exchange Commission (SEC) has announced that cybersecurity will be an area of regulatory focus during 2014. The National Exam Program (NEP) run by the SEC’s Office of Compliance Inspections and Examinations (OCIE) has included “information security” as an examination priority for 2014 for each of NEP’s four program areas:
Among items that may be reviewed by the SEC inspection staff during an inspection of an investment company or its investment adviser are the policies and procedures designed to address computer security, identity theft (red flags), privacy and business continuity. Investment advisers and their investment companies will also be expected to have reviewed the computer security policies of their third-party service providers.[2] In addition, the SEC announced that it will host a roundtable at its Washington, DC headquarters on March 26 to discuss “cybersecurity and the issues and challenges it raises for market participants and public companies and how they are addressing those concerns.”[3]
Leave a Reply