16 CFR 314.3 standards for safeguarding customer information + 314.4(a) Qualified Individual. STANDARD: financial institution must DEVELOP + IMPLEMENT + MAINTAIN a comprehensive WRITTEN INFORMATION SECURITY PROGRAM (WISP) containing administrative + technical + physical safeguards appropriate to its size + complexity + nature + scope of activities + the sensitivity of any customer information at issue. OBJECTIVES: (a) INSURE the security + confidentiality of customer information; (b) PROTECT against ANY ANTICIPATED THREATS or hazards to security or integrity; (c) PROTECT against UNAUTHORIZED ACCESS or use that could result in substantial harm or inconvenience. QUALIFIED INDIVIDUAL (314.4(a)): the institution MUST DESIGNATE a QUALIFIED INDIVIDUAL responsible for OVERSEEING + IMPLEMENTING + ENFORCING the information security program. The Qualified Individual may be in-house or third-party; if third-party + the institution remains responsible + must designate a member of senior leadership or board to oversee the third-party Qualified Individual. The Qualified Individual must REPORT IN WRITING + at least ANNUALLY to the Board (or, if no Board, to a Senior Officer responsible) + on the program's overall status + risk assessment + 9 safeguard elements + service-provider oversight + program evaluation + any incidents + corrective actions.
The graph holds this control, the 0 it maps to, and the evidence behind each claim, over MCP and REST.