ARTICLE
7 June 2019

OCIE Identifies Security Risks To Cloud-Based Records Storage

HL
Hogan Lovells Cadwalader

Contributor

Hogan Lovells Cadwalader is a global law firm trusted by clients to deliver on complex, high-stakes matters.

Operating at the intersection of business, finance, and government, we bring an unwavering commitment to client service and the decisive counsel that helps clients achieve exceptional results.

Consistently recognized for innovation across legal services, we combine sharp judgment with deep commercial perspective and intellectual rigor to address critical, cutting-edge challenges.

With 3,100 lawyers worldwide, we offer global scale with strong local insight in the markets that matter most. Our commitment extends beyond client work through pro bono activities, community investment, and responsible business practices.

In a Risk Alert, the SEC Office of Compliance Inspections and Examinations ("OCIE") urged broker-dealers and investment advisers to review ...
United States Corporate/Commercial Law
Hogan Lovells Cadwalader are most popular:
  • within Intellectual Property, Government, Public Sector, Food, Drugs, Healthcare and Life Sciences topic(s)
  • with readers working within the Consumer Industries industries

In a Risk Alert, the SEC Office of Compliance Inspections and Examinations ("OCIE") urged broker-dealers and investment advisers to review their practices and policies governing the storage of electronic information, particularly as to customer information maintained in the cloud.

During examinations, the OCIE staff observed firms:

  • that store electronic records using third-party services (e.g., cloud-based storage) failed to use the data protection tools that the service provider made available to them;
  • were not sufficiently configuring the security settings to safeguard against unauthorized access;
  • lacked adequate policies, procedures or contractual provisions to ensure that the security settings or vendor-provided network storage solutions were configured in alignment with the firm's policies; and
  • had policies and procedures that failed to identify the types of data stored electronically by the firm and the appropriate controls for each type of data.

The OCIE staff noted that these failures raised serious issues under Regulations S-P and S-ID (Privacy of consumer financial information, safeguarding private information and identity theft red flags).

The content of this article is intended to provide a general guide to the subject matter. Specialist advice should be sought about your specific circumstances.

[View Source]

Mondaq uses cookies on this website. By using our website you agree to our use of cookies as set out in our Privacy Policy.

Learn More