Develop, implement, and maintain a comprehensive written Information Security Program (ISP) based on the licensees risk assessment that includes administrative, technical, and physical safeguards for protecting Nonpublic Information and the licensees information systems. Scale the ISP commensurate with size + complexity + nature + scope of activities + sensitivity of Nonpublic Information used + handled. Address Section 4(D) requirements covering nine specific controls: access controls + identification + authentication + change management + system monitoring + protective controls + physical security + business continuity + vendor oversight.
The graph holds this control, the 0 it maps to, and the evidence behind each claim, over MCP and REST.