50 Ill. Adm. Code 4003.80
Manage and Control Risk
Section 4003.80 Manage and Control Risk
The licensee:
a) Designs
its information security program to control the identified risks, commensurate
with the sensitivity of the information, as well as the complexity and scope of
the licensee's activities;
b) Trains
staff, as appropriate, to implement the licensee'’s information security
program; and
c) Regularly
tests or otherwise regularly monitors the key controls, systems and procedures
of the information security program. The frequency and nature of these tests or
other monitoring practices are determined by the licensee’s risk assessment.