Information security program required elements

Miss. Code Ann. § 75-14-7, under Data Security for Money Transmitters Act.

Miss. Code Ann. § 75-14-7

(1) (a) A licensee shall designate a qualified individual to be responsible for implementing, overseeing and enforcing the licensee’s information security program.(b) The qualified individual may be employed by the licensee, an affiliate or a service provider. If a licensee designates an individual employed by an affiliate or service provider to oversee the information security program, the licensee:(i) Remains responsible for compliance with this article;(ii) Must designate a senior member of the licensee’s personnel to be responsible for the direction and oversight of the qualified individual; and(iii) Must require the service provider or affiliate to maintain an information security program that protects the licensee as required by this article.

(a) A licensee shall designate a qualified individual to be responsible for implementing, overseeing and enforcing the licensee’s information security program.

(b) The qualified individual may be employed by the licensee, an affiliate or a service provider. If a licensee designates an individual employed by an affiliate or service provider to oversee the information security program, the licensee:(i) Remains responsible for compliance with this article;(ii) Must designate a senior member of the licensee’s personnel to be responsible for the direction and oversight of the qualified individual; and(iii) Must require the service provider or affiliate to maintain an information security program that protects the licensee as required by this article.

(i) Remains responsible for compliance with this article;

(ii) Must designate a senior member of the licensee’s personnel to be responsible for the direction and oversight of the qualified individual; and

(iii) Must require the service provider or affiliate to maintain an information security program that protects the licensee as required by this article.

(2) (a) A licensee shall base the information security program on a risk assessment that:(i) Identifies reasonably foreseeable internal and external risks to the security, confidentiality and integrity of customer information that could result in the unauthorized disclosure, misuse, alteration, destruction or other compromise of the information; and(ii) Assesses the sufficiency of any safeguards in place to control these risks.(b) The risk assessment shall be written and include:(i) Criteria for the evaluation and categorization of identified security risks or threats the licensee faces;(ii) Criteria for the assessment of the confidentiality, integrity and availability of the licensee’s information systems and customer information, including the adequacy of the existing controls in the context of the identified risks or threats the licensee faces; and(iii) Requirements for mitigating or accepting identified risks based on the risk assessment and a description of how the information security program will address identified risks.

(a) A licensee shall base the information security program on a risk assessment that:(i) Identifies reasonably foreseeable internal and external risks to the security, confidentiality and integrity of customer information that could result in the unauthorized disclosure, misuse, alteration, destruction or other compromise of the information; and(ii) Assesses the sufficiency of any safeguards in place to control these risks.

(i) Identifies reasonably foreseeable internal and external risks to the security, confidentiality and integrity of customer information that could result in the unauthorized disclosure, misuse, alteration, destruction or other compromise of the information; and

(ii) Assesses the sufficiency of any safeguards in place to control these risks.

(b) The risk assessment shall be written and include:(i) Criteria for the evaluation and categorization of identified security risks or threats the licensee faces;(ii) Criteria for the assessment of the confidentiality, integrity and availability of the licensee’s information systems and customer information, including the adequacy of the existing controls in the context of the identified risks or threats the licensee faces; and(iii) Requirements for mitigating or accepting identified risks based on the risk assessment and a description of how the information security program will address identified risks.

(i) Criteria for the evaluation and categorization of identified security risks or threats the licensee faces;

(ii) Criteria for the assessment of the confidentiality, integrity and availability of the licensee’s information systems and customer information, including the adequacy of the existing controls in the context of the identified risks or threats the licensee faces; and

(iii) Requirements for mitigating or accepting identified risks based on the risk assessment and a description of how the information security program will address identified risks.

(3) A licensee shall periodically perform additional risk assessments that:(a) Reexamine the reasonably foreseeable internal and external risks to the security, confidentiality and integrity of customer information that could result in the unauthorized disclosure, misuse, alteration, destruction or other compromise of customer information; and(b) Reassess the sufficiency of any safeguards in place to control these risks.

(a) Reexamine the reasonably foreseeable internal and external risks to the security, confidentiality and integrity of customer information that could result in the unauthorized disclosure, misuse, alteration, destruction or other compromise of customer information; and

(b) Reassess the sufficiency of any safeguards in place to control these risks.

(4) A licensee shall design and implement safeguards to control the risks the financial institution identifies through the risk assessment as required under subsection (2) of this section, including, but not limited to:(a) Implementing and periodically reviewing access controls, including technical and, as appropriate, physical controls, to:(i) Authenticate and permit access only to authorized users to protect against the unauthorized acquisition of customer information; and(ii) Limit authorized users’ access only to customer information that the authorized user needs to perform the authorized user’s duties and functions, or in the case of customers, to access the customer’s own customer information;(b) Identifying and managing the data, personnel, devices, systems and facilities that enable the licensee to achieve business purposes according to the licensee’s relative importance to business objectives and the licensee’s risk strategy;(c) Protecting by encryption all customer information held or transmitted by the licensee both in transit over external networks and at rest. To the extent the licensee determines that encryption of customer information, either in transit over external networks or at rest, is infeasible, the licensee may instead secure the customer information using effective alternative compensating controls reviewed and approved by the licensee’s qualified individual;(d) Adopting secure development practices for in-house developed applications used by the licensee for transmitting, accessing or storing customer information and procedures for evaluating, assessing or testing the security of externally developed applications the licensee uses to transmit, access or store customer information;(e) Implementing multi-factor authentication for an individual accessing an information system, unless the licensee’s qualified individual has approved in writing the use of reasonably equivalent or more secure access controls;(f) Developing, implementing and maintaining procedures for the secure disposal of customer information in any format no later than two (2) years after the last date the customer information was used in connection with the provision of a financial product or service to the customer, unless the customer information is:(i) Necessary for business operations or for other legitimate business purposes;(ii) Otherwise required to be retained by state or federal law or regulation; or(iii) Where targeted disposal is not reasonably feasible due to the manner in which the information is maintained;(g) Periodically reviewing the licensee’s data retention policy to minimize the unnecessary retention of data;(h) Adopting procedures for change management; and(i) Implementing policies, procedures and controls designed to monitor and log the activity of authorized users and detect unauthorized access or use of, or tampering with, customer information by these users.

(a) Implementing and periodically reviewing access controls, including technical and, as appropriate, physical controls, to:(i) Authenticate and permit access only to authorized users to protect against the unauthorized acquisition of customer information; and(ii) Limit authorized users’ access only to customer information that the authorized user needs to perform the authorized user’s duties and functions, or in the case of customers, to access the customer’s own customer information;

(i) Authenticate and permit access only to authorized users to protect against the unauthorized acquisition of customer information; and

(ii) Limit authorized users’ access only to customer information that the authorized user needs to perform the authorized user’s duties and functions, or in the case of customers, to access the customer’s own customer information;

(b) Identifying and managing the data, personnel, devices, systems and facilities that enable the licensee to achieve business purposes according to the licensee’s relative importance to business objectives and the licensee’s risk strategy;

(c) Protecting by encryption all customer information held or transmitted by the licensee both in transit over external networks and at rest. To the extent the licensee determines that encryption of customer information, either in transit over external networks or at rest, is infeasible, the licensee may instead secure the customer information using effective alternative compensating controls reviewed and approved by the licensee’s qualified individual;

(d) Adopting secure development practices for in-house developed applications used by the licensee for transmitting, accessing or storing customer information and procedures for evaluating, assessing or testing the security of externally developed applications the licensee uses to transmit, access or store customer information;

(e) Implementing multi-factor authentication for an individual accessing an information system, unless the licensee’s qualified individual has approved in writing the use of reasonably equivalent or more secure access controls;

(f) Developing, implementing and maintaining procedures for the secure disposal of customer information in any format no later than two (2) years after the last date the customer information was used in connection with the provision of a financial product or service to the customer, unless the customer information is:(i) Necessary for business operations or for other legitimate business purposes;(ii) Otherwise required to be retained by state or federal law or regulation; or(iii) Where targeted disposal is not reasonably feasible due to the manner in which the information is maintained;

(i) Necessary for business operations or for other legitimate business purposes;

(ii) Otherwise required to be retained by state or federal law or regulation; or

(iii) Where targeted disposal is not reasonably feasible due to the manner in which the information is maintained;

(g) Periodically reviewing the licensee’s data retention policy to minimize the unnecessary retention of data;

(h) Adopting procedures for change management; and

(i) Implementing policies, procedures and controls designed to monitor and log the activity of authorized users and detect unauthorized access or use of, or tampering with, customer information by these users.

(5) (a) A licensee shall regularly test or otherwise monitor the effectiveness of the safeguards’ key controls, systems and procedures, including those to detect actual and attempted attacks on or intrusions into information systems.(b) For information systems, monitoring and testing shall include continuous monitoring or periodic penetration testing and vulnerability assessments. Absent effective continuous monitoring or other systems to detect, on an ongoing basis, changes in information systems that may create vulnerabilities, the licensee shall conduct:(i) Annual penetration testing of a licensee’s information systems determined each given year based on relevant identified risks according to the risk assessment; and(ii) Vulnerability assessments, including a systemic scan or review of an information system reasonably designed to identify publicly known security vulnerabilities in the licensee’s information systems based on the risk assessment, at least every six (6) months, and whenever there are:1. Material changes to the licensee’s operations or business arrangements; and2. Circumstances the licensee knows or has reason to know may have a material impact on the licensee’s information security program.

(a) A licensee shall regularly test or otherwise monitor the effectiveness of the safeguards’ key controls, systems and procedures, including those to detect actual and attempted attacks on or intrusions into information systems.

(b) For information systems, monitoring and testing shall include continuous monitoring or periodic penetration testing and vulnerability assessments. Absent effective continuous monitoring or other systems to detect, on an ongoing basis, changes in information systems that may create vulnerabilities, the licensee shall conduct:(i) Annual penetration testing of a licensee’s information systems determined each given year based on relevant identified risks according to the risk assessment; and(ii) Vulnerability assessments, including a systemic scan or review of an information system reasonably designed to identify publicly known security vulnerabilities in the licensee’s information systems based on the risk assessment, at least every six (6) months, and whenever there are:1. Material changes to the licensee’s operations or business arrangements; and2. Circumstances the licensee knows or has reason to know may have a material impact on the licensee’s information security program.

(i) Annual penetration testing of a licensee’s information systems determined each given year based on relevant identified risks according to the risk assessment; and

(ii) Vulnerability assessments, including a systemic scan or review of an information system reasonably designed to identify publicly known security vulnerabilities in the licensee’s information systems based on the risk assessment, at least every six (6) months, and whenever there are:1. Material changes to the licensee’s operations or business arrangements; and2. Circumstances the licensee knows or has reason to know may have a material impact on the licensee’s information security program.

1. Material changes to the licensee’s operations or business arrangements; and

2. Circumstances the licensee knows or has reason to know may have a material impact on the licensee’s information security program.

(6) A licensee shall implement policies and procedures to ensure that personnel are able to enact the licensee’s information security program by:(a) Providing the licensee’s personnel with security awareness training that is updated as necessary to reflect risks identified by the risk assessment;(b) Using qualified information security personnel employed by the licensee or an affiliate or service provider sufficient to manage the licensee’s information security risks and to perform or oversee the information security program;(c) Providing information security personnel with security updates and training sufficient to address relevant security risks; and(d) Verifying that key information security personnel take steps to maintain current knowledge of changing information, security threats and countermeasures.

(a) Providing the licensee’s personnel with security awareness training that is updated as necessary to reflect risks identified by the risk assessment;

(b) Using qualified information security personnel employed by the licensee or an affiliate or service provider sufficient to manage the licensee’s information security risks and to perform or oversee the information security program;

(c) Providing information security personnel with security updates and training sufficient to address relevant security risks; and

(d) Verifying that key information security personnel take steps to maintain current knowledge of changing information, security threats and countermeasures.

(7) (a) A licensee shall take reasonable steps to select and retain service providers that are capable of maintaining appropriate safeguards for the customer information at issue. As a provision of the contract between a licensee and a service provider, the service provider shall be required to implement and maintain such safeguards.(b) A licensee shall periodically assess its service providers based on the risk they present and the continued adequacy of their safeguards.

(a) A licensee shall take reasonable steps to select and retain service providers that are capable of maintaining appropriate safeguards for the customer information at issue. As a provision of the contract between a licensee and a service provider, the service provider shall be required to implement and maintain such safeguards.

(b) A licensee shall periodically assess its service providers based on the risk they present and the continued adequacy of their safeguards.

(8) A licensee shall evaluate and adjust the licensee’s information security program to reflect:(a) The results of the testing and monitoring required by subsection (5) of this section;(b) A material change to the licensee’s operations or business arrangements or other circumstances;(c) The results of risk assessments performed under subsection (2) of this section; and(d) Any other circumstances that the licensee knows or has reason to know may have a material impact on the licensee’s information security program.

(a) The results of the testing and monitoring required by subsection (5) of this section;

(b) A material change to the licensee’s operations or business arrangements or other circumstances;

(c) The results of risk assessments performed under subsection (2) of this section; and

(d) Any other circumstances that the licensee knows or has reason to know may have a material impact on the licensee’s information security program.

(9) A licensee shall establish a written incident response plan designed to promptly respond to, and recover from, any security event materially affecting the confidentiality, integrity or availability of customer information in the licensee’s control. The incident response plan shall address:(a) The goals of the incident response plan;(b) The internal processes for responding to a security event;(c) The definition of clear roles, responsibilities and levels of decision-making authority;(d) External and internal communications and information sharing;(e) Identification of requirements for the remediation of any identified weaknesses in information systems and associated controls;(f) Documentation and reporting regarding security events and related incident response activities; and(g) The evaluation and revision as necessary of the incident response plan following a security event.

(a) The goals of the incident response plan;

(b) The internal processes for responding to a security event;

(c) The definition of clear roles, responsibilities and levels of decision-making authority;

(d) External and internal communications and information sharing;

(e) Identification of requirements for the remediation of any identified weaknesses in information systems and associated controls;

(f) Documentation and reporting regarding security events and related incident response activities; and

(g) The evaluation and revision as necessary of the incident response plan following a security event.

(10) (a) The licensee’s qualified individual shall report in writing, at least annually, to the licensee’s board of directors or equivalent governing body. If a board of directors or equivalent governing body does not exist, the report required under this subsection (10) shall be timely presented to a senior officer responsible for the licensee’s information security program.(b) The report shall include:(i) The overall status of the information security program and the licensee’s compliance with this article and associated rules; and(ii) Material matters related to the information security program, addressing issues such as risk assessment, risk management and control decisions, service provider arrangements, results of testing, security events or violations and management’s responses to security events or violations, and recommendations for changes in the information security program.

(a) The licensee’s qualified individual shall report in writing, at least annually, to the licensee’s board of directors or equivalent governing body. If a board of directors or equivalent governing body does not exist, the report required under this subsection (10) shall be timely presented to a senior officer responsible for the licensee’s information security program.

(b) The report shall include:(i) The overall status of the information security program and the licensee’s compliance with this article and associated rules; and(ii) Material matters related to the information security program, addressing issues such as risk assessment, risk management and control decisions, service provider arrangements, results of testing, security events or violations and management’s responses to security events or violations, and recommendations for changes in the information security program.

(i) The overall status of the information security program and the licensee’s compliance with this article and associated rules; and

(ii) Material matters related to the information security program, addressing issues such as risk assessment, risk management and control decisions, service provider arrangements, results of testing, security events or violations and management’s responses to security events or violations, and recommendations for changes in the information security program.

(11) A licensee shall establish a written plan addressing business continuity and disaster recovery.