September 18, 2015
On September 15, 2015, the Office of Compliance Inspections and Examinations (OCIE) of the Securities and Exchange Commission (SEC) issued a Risk Alert announcing a second round of examinations of registered investment advisers and broker-dealers under its cybersecurity examination initiative. The Risk Alert’s purpose is to provide additional information on the areas of focus for the OCIE’s examinations, which will involve more testing to assess implementation of firm procedures and controls.
Registered investment advisers should review their current cybersecurity practices, policies and procedures to ensure that they have addressed the matters referred to in the sample request for information which is included as an Appendix to the Risk Alert and consult with their IT service providers, as appropriate. They will likely be asked to provide this information on an SEC examination.
In summary, the OCIE is planning to assess the following key areas:
For additional information on the cybersecurity focus by the SEC see our earlier Foley Adviser updates, which can be found here: SEC Issues Risk Alert on Cybersecurity Initiative for Investment Advisers and SEC Office of Compliance Inspections and Examinations Releases Cybersecurity Examination Sweep Summary of Investment Advisers and Broker-Dealers.