Chapter 4 - Section 5 - NASAA Investment Adviser Information Security and Privacy Rule Flashcards

1
Q

The policies and procedures must be tailored to the Investment Adviser’s business model, taking into account the ______ of the firm, types of _________ provided, and the number of ____________ of the investment adviser.

A

Size, Services, Locations

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
2
Q

The physical security and cybersecurity policies and procedures must cover at last five functions. What are those functions?

A
  1. Identify
  2. Protect
  3. Detect
  4. Respond
  5. Recover
How well did you know this?
1
Not at all
2
3
4
5
Perfectly
3
Q

The Investment Adviser must review, no less frequently than ____________, and modify, as needed, these policies and procedures to ensure the adequacy of the security measures and the effectiveness of their implementation.

A

Annually

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
4
Q

The IA must deliver, upon the IA’s engagement by a client and on an _____________ basis thereafter, a privacy policy to each client. The IA must ___________ update and deliver to each client an amended privacy policy if any information in the policy becomes inaccurate.

A

Annual; promptly

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
5
Q

What are other considerations for an IA in regard to protecting customer information and privacy?

A
  • train staff to recognize suspicious emails
  • install anti-virus software
  • use cloud-based servers
  • two forms of ID to access systems
  • 3rd party systems to sign confidentiality agreements
How well did you know this?
1
Not at all
2
3
4
5
Perfectly