Oregon Administrative Rules
Chapter 836 - DEPARTMENT OF CONSUMER AND BUSINESS SERVICES, INSURANCE REGULATION
Division 81 - TRADE PRACTICES - GENERAL PROVISIONS
Section 836-081-0121 - Examples of Methods of Development and Implementation
Current through Register Vol. 63, No. 9, September 1, 2024
The actions and procedures described in this rule are examples of methods of implementation of the requirements of OAR 836-081-0111 and 836-081-0116. These examples are nonexclusive illustrations of actions and procedures that licensees may follow to implement 836-081-0111 and 836-081-0116. The examples are as follows:
(1) Assessing risk. The licensee:
(2) Managing and controlling risk. The licensee:
(3) Overseeing service provider arrangements. The licensee:
(4) Adjusting the program. The licensee monitors, evaluates and adjusts, as appropriate, the information security program in light of any relevant changes in technology, the sensitivity of its customer information, internal or external threats to information, and the licensee's own changing business arrangements, such as mergers and acquisitions, alliances and joint ventures, outsourcing arrangements and changes to customer information systems.
Stat. Auth.: ORS 731.244
Stats. Implemented: ORS 746.240, ORS 746.670