ARSD 20:06:45:23
ARSD 20:06:45:23. Assess risk
Cite as S.D. Admin. R. 20:06:45:23
The licensee:
(A) Identifies reasonably foreseeable internal or external threats that could result in unauthorized disclosure, misuse, alteration, or destruction of customer information or customer information systems;
(B) Assesses the likelihood and potential damage of these threats, taking into consideration the sensitivity of customer information; and
(C) Assesses the sufficiency of policies, procedures, customer information systems and other safeguards in place to control risks.