(1) A licensee shall develop, implement and maintain a comprehensive information security program.
(2) The information security program under subsection (1) of this section shall:(a) Be written in one or more readily accessible parts; and(b) Contain administrative, technical and physical safeguards that are appropriate to the licensee’s size and complexity, the nature and scope of the licensee’s activities, and the sensitivity of any customer information at issue.
(a) Be written in one or more readily accessible parts; and
(b) Contain administrative, technical and physical safeguards that are appropriate to the licensee’s size and complexity, the nature and scope of the licensee’s activities, and the sensitivity of any customer information at issue.