FTC settlement shows key compliance area
A settlement between the Federal Trade Commission (FTC) and computer vendor Asus shows employers one way to stay on the feds’ good side – act quickly when you receive vulnerability reports.
According to the complaint, Asus misrepresented its security policies, and failed to act on vulnerability reports quickly.
Delayed notification
Specifically, the FTC alleges that Asus took too long to address reported vulnerabilities and notify its customers that the flaws could lead to cyberattacks.
That delay was a key factor in the company’s poor security practices, the FTC said. To settle the suit, Asus has agreed to implement a more thorough security program that fixes these issues, along with other steps.
To keep out of federal regulator’s crosshairs, be sure you have solid procedures to address vulnerabilities and notify consumers if those flaws could endanger their data security.
Free Training & Resources
Further Reading
Can a company’s cybersecurity weakness equate to “ineffective accounting controls?” The Securities & Exchange Commiss...
You can now file Form 1099 series information returns using the Information Returns Intake System (IRIS) online portal. Step one is enrolli...
If you’ve used Excel to create a database table with fixed formulas, and that table will be used by multiple people, there’s a ...
Effectively handling multi-sheet Excel workbooks is crucial for organizing and analyzing complex data. By mastering worksheet management, y...
For finance leaders, not many responsibilities are as stressful (or as important) as closing the books. The financial close aims to make su...
Finance teams have always known expense fraud is a problem. What’s changed is the scale, the motivation, and the profile of who’...