
This is a community paste of different cybersecurity and IT related questions we have seen the SEC, FINRA, and SSBs send firms before showing up for an onsite interview or examination We have found the best way to prepare for a SEC cybersecurity audit is to study and prepare for the requests that will be coming your way. We hope this document helps Good Luck.
For each of the following practices employed by the Firm for management of information security assets, please provide the month and year in which the noted action was last taken; the frequency with which such practices are conducted; the group with responsibility for conducting the practice; and, if not conducted firm wide, the areas that are included within the practice. Please also provide a copy of any relevant policies and procedures.
• Physical devices and systems within the Firm are inventoried and assessed for risks.
• Software platforms and applications within the Firm are inventoried and audited.
• Maps of network resources, connections, and data flows (including locations where customer data is housed) are created or updated.
Continue reading “The SEC Cybersecurity Compliance Documentation Request List”