NIST 800-53
Any Investment Company should comply with NIST SP 800-53 Compliance in order to pass SEC review. Company should show sufficient strive in:
- Access control: Ensures only authorized users have access privileges
- Audit and accountability: Involves a system of checks and balances to ensure proper protection
- Awareness and training: Ensures team members are given the pertinent security controls training, including how these controls protect their systems
- Configuration management: Ensures all configurations address the latest needs of the system without compromising security
- Contingency planning: Involves creating a plan that provides different options in case your security controls do not perform as expected
- Identification and authentication: Focuses on ensuring users and devices have valid identification and the rights they need to access systems and data
- Incident response: Orchestrates the steps and tools used when there is a breach
- Maintenance: Necessary for keeping the system up-to-date and functioning as it should
- Media protection: Involves protecting the physical media used to store data, such as hard drives and servers
- Personnel security: Ensures people that manage sensitive systems and data are protected from cybercriminals who may target them
Source: NIST SP 800-53