(1) A licensee may permit mortgage loan originators to perform origination activities at a remote location under the supervision and in compliance with the licensee’s written policies and procedures subject to the conditions provided in this subsection.The licensee shall establish appropriate standards relating to administrative, technical, and physical safeguards to ensure the security and confidentiality of customer information; protect against anticipated threats or hazards to the security or integrity of such records; and protect against unauthorized access to or use of such records or information which could result in substantial harm or inconvenience to any customer. Appropriate safeguards shall include, but are not limited to, the following: (a) Customer interactions and conversations about consumers will be in compliance with federal and state information security requirements, including applicable provisions under the Gramm-Leach-Bliley Act and the Safeguards Rule established under the Federal Trade Commission, set forth at 16 CFR Part 314;(b) Mortgage loan originators performing origination activities from a remote location must access the licensee’s secure systems (including cloud-based systems) directly from any out-of-office device such individual uses (laptop, phone, desktop computer, tablet, etc.) via a virtual private network (VPN) or comparable system that ensures secure connectivity and requires passwords or other forms of authentication to access;(c) The licensee shall ensure that appropriate security updates, patches, or other alterations to the security of all devices used at remote locations are installed and maintained;(d) The licensee must have an ability to remotely lock or erase company-related contents of any device or otherwise remotely limit all access to a company’s secure systems;(e) The licensee shall employ appropriate risk-based monitoring and oversight processes and any mortgage loan originator that performs origination activities from a remote location agrees to comply with the licensee’s established processes;(f) The licensee shall at least once annually certify that all mortgage loan originators engaging in remote activity meet the appropriate standards and safeguards to continue such activity; and(g) The NMLS record of a mortgage loan originator that performs origination activities from a remote location shall designate the licensee’s licensed main office as their registered location unless such mortgage loan originator elects to choose a licensed branch as a registered location.
The licensee shall establish appropriate standards relating to administrative, technical, and physical safeguards to ensure the security and confidentiality of customer information; protect against anticipated threats or hazards to the security or integrity of such records; and protect against unauthorized access to or use of such records or information which could result in substantial harm or inconvenience to any customer. Appropriate safeguards shall include, but are not limited to, the following: (a) Customer interactions and conversations about consumers will be in compliance with federal and state information security requirements, including applicable provisions under the Gramm-Leach-Bliley Act and the Safeguards Rule established under the Federal Trade Commission, set forth at 16 CFR Part 314;
(b) Mortgage loan originators performing origination activities from a remote location must access the licensee’s secure systems (including cloud-based systems) directly from any out-of-office device such individual uses (laptop, phone, desktop computer, tablet, etc.) via a virtual private network (VPN) or comparable system that ensures secure connectivity and requires passwords or other forms of authentication to access;
(c) The licensee shall ensure that appropriate security updates, patches, or other alterations to the security of all devices used at remote locations are installed and maintained;
(d) The licensee must have an ability to remotely lock or erase company-related contents of any device or otherwise remotely limit all access to a company’s secure systems;
(e) The licensee shall employ appropriate risk-based monitoring and oversight processes and any mortgage loan originator that performs origination activities from a remote location agrees to comply with the licensee’s established processes;
(f) The licensee shall at least once annually certify that all mortgage loan originators engaging in remote activity meet the appropriate standards and safeguards to continue such activity; and
(g) The NMLS record of a mortgage loan originator that performs origination activities from a remote location shall designate the licensee’s licensed main office as their registered location unless such mortgage loan originator elects to choose a licensed branch as a registered location.
(2) A licensee shall notify the commissioner as promptly as possible but in no event later than three (3) business days from a determination that an unauthorized access to or disruption or misuse of consumer information has occurred.
(3) (a) A licensee must regularly audit or otherwise monitor the effectiveness of its information security requirements.(b) The audit must include continuous monitoring or periodic penetration testing and vulnerability assessments. Penetration testing means a test methodology in which assessors attempt to circumvent or defeat the security features of licensee’s information systems by attempting penetration of databases or controls from outside or inside the licensee’s system.(c) Absent effective continuous monitoring or other systems to detect, on an ongoing basis, changes in information systems that may create vulnerabilities, the nonbank licensee shall conduct annual penetration testing of the licensee’s information systems determined each given year based on relevant identified risks in assessment, and biannual vulnerability assessments, including any systemic scans or reviews of information systems reasonably designed to identify publicly known security vulnerabilities in the licensee’s information systems based on a risk assessment.
(a) A licensee must regularly audit or otherwise monitor the effectiveness of its information security requirements.
(b) The audit must include continuous monitoring or periodic penetration testing and vulnerability assessments. Penetration testing means a test methodology in which assessors attempt to circumvent or defeat the security features of licensee’s information systems by attempting penetration of databases or controls from outside or inside the licensee’s system.
(c) Absent effective continuous monitoring or other systems to detect, on an ongoing basis, changes in information systems that may create vulnerabilities, the nonbank licensee shall conduct annual penetration testing of the licensee’s information systems determined each given year based on relevant identified risks in assessment, and biannual vulnerability assessments, including any systemic scans or reviews of information systems reasonably designed to identify publicly known security vulnerabilities in the licensee’s information systems based on a risk assessment.