VerdoCo
Regulation S-P Series · Foundation Suite · Live Sample
0 of 8 fields completed

Organization Details (applies to all documents)

Information Security Program Policy

1. Purpose and Regulatory Authority

This Information Security Program Policy (Version ________) sets out ________’s written policies and procedures to safeguard customer information, adopted pursuant to 17 CFR § 248.30(a)(1). This policy is effective as of ________ and reflects the requirements of SEC Regulation S-P as amended by SEC Release No. 34-100155 (May 16, 2024), issued under the authority of the Gramm-Leach-Bliley Act, 15 U.S.C. § 6801 et seq.

Citation basis: 17 CFR § 248.30(a)(1) — written policies and procedures to safeguard customer information (verified 2026-08-01)

2. Program Ownership and Accountability

________, serving as ________, is designated as the accountable owner of this Information Security Program on behalf of ________. This individual is responsible for the development, implementation, and ongoing maintenance of the written policies and procedures described in this document.

Citation basis: 17 CFR § 248.30(a)(1) — written policies and procedures to safeguard customer information (verified 2026-08-01)

3. Program Objectives

This program’s written policies and procedures are reasonably designed to: (i) ensure the security and confidentiality of customer information; (ii) protect against anticipated threats or hazards to the security or integrity of customer information; and (iii) protect against unauthorized access to or use of customer information that could result in substantial harm or inconvenience to any customer, as required under 17 CFR § 248.30(a)(2).

Citation basis: 17 CFR § 248.30(a)(2) — the three required program objectives (verified 2026-08-01)

4. Relationship to the Response Program

This policy establishes the foundation for ________’s incident response program, including the obligation — where notification is required — to provide notice to affected individuals as soon as practicable, and not later than 30 days, after becoming aware that unauthorized access to or use of customer information has occurred or is reasonably likely to have occurred, in accordance with 17 CFR § 248.30(a)(4)(iii).

Citation basis: 17 CFR § 248.30(a)(4)(iii) — 30-day customer notification timing (verified 2026-08-01)

Customer Record Inventory & CRI Register

1. Inventory Scope

This register inventories ________’s holdings of customer information as defined at 17 CFR § 248.30(d)(5)(i): any record containing nonpublic personal information about a customer, in paper, electronic, or other form, that is in ________’s possession or is handled or maintained by ________ or on its behalf.

Citation basis: 17 CFR § 248.30(d)(5) — definition of customer information (verified 2026-08-01)

2. Primary Record-Keeping System

________’s customer information is primarily maintained within ________. Estimated customer record volume: ________. This entry should be updated whenever the organization’s primary system of record changes.

Citation basis: 17 CFR § 248.30(d)(5) — definition of customer information (verified 2026-08-01)

3. Scope Note for Transfer Agents

If ________ is a transfer agent registered with the Commission or another appropriate regulatory authority, a separate definition applies under 17 CFR § 248.30(d)(5)(ii). Organizations that are not transfer agents should disregard this section.

Citation basis: 17 CFR § 248.30(d)(5) — definition of customer information (verified 2026-08-01)

Regulation S-P Gap Analysis

1. Assessment Basis

This gap analysis assesses ________’s current written policies and procedures against the requirements of 17 CFR § 248.30, Subpart A of Regulation S-P, as amended by SEC Release Nos. 34-100155; IA-6604; IC-35193 (89 Fed. Reg. 47688, June 3, 2024). The assessment was conducted by ________ and reflects ________’s posture as of ________.

Citation basis: 17 CFR Part 248, Subpart A (Regulation S-P) (verified 2026-08-01)

2. Areas of Review

This assessment reviews four required elements of the amended rule: (1) the general written information security program requirement at § 248.30(a)(1)–(2); (2) the incident response program requirement, including the assessment-of-scope obligation at § 248.30(a)(3)(i); (3) service provider oversight, including the 72-hour service-provider notification requirement at § 248.30(a)(5)(i); and (4) the customer notification obligation and its 30-day timing standard at § 248.30(a)(4)(iii).

Citation basis: 17 CFR § 248.30(a)(3)(i) — incident assessment requirement (verified 2026-08-01)

3. Recordkeeping Scope Note

17 CFR § 248.30(c) imposes additional recordkeeping obligations. The precise scope of which covered institutions this subsection applies to has not yet been independently confirmed against primary source text as part of this assessment and should be verified before this gap analysis is treated as complete on that specific point.

Citation: not independently verified — flagged for review, not asserted as fact.

View Full Suite Pricing →