16 CFR 314.3 standards for safeguarding customer information + 314.4(a) Qualified Individual. STANDARD: financial institution must DEVELOP + IMPLEMENT + MAINTAIN a comprehensive WRITTEN INFORMATION SECURITY PROGRAM (WISP) containing administrative + technical + physical safeguards appropriate to its size + complexity + nature + scope of activities + the sensitivity of any customer information at issue. OBJECTIVES: (a) INSURE the security + confidentiality of customer information; (b) PROTECT against ANY ANTICIPATED THREATS or hazards to security or integrity; (c) PROTECT against UNAUTHORIZED ACCESS or use that could result in substantial harm or inconvenience. QUALIFIED INDIVIDUAL (314.4(a)): the institution MUST DESIGNATE a QUALIFIED INDIVIDUAL responsible for OVERSEEING + IMPLEMENTING + ENFORCING the information security program. The Qualified Individual may be in-house or third-party; if third-party + the institution remains responsible + must designate a member of senior leadership or board to oversee the third-party Qualified Individual. The Qualified Individual must REPORT IN WRITING + at least ANNUALLY to the Board (or, if no Board, to a Senior Officer responsible) + on the program's overall status + risk assessment + 9 safeguard elements + service-provider oversight + program evaluation + any incidents + corrective actions.
This control maps to 13 controls across 9 other frameworks. If you already hold one of them, the evidence you collected for it is the starting point here rather than new work.
Every mapping shown was judged rather than inferred from wording similarity, and the ones that failed review are published too. See the coverage reports and what was rejected.
The graph holds this control, the 13 it maps to, and the evidence behind each claim, over MCP and REST.