Pennsylvania Statutes
§ 4517 — Investigation of cybersecurity event
(a)Requirement.--If a licensee discovers that a cybersecurity event has or may have occurred regarding the licensee, the licensee or an outside vendor or service provider designated to act on behalf of the licensee shall conduct a prompt investigation.
(b)Determination.--During an investigation under this section, the licensee or an outside vendor or service provider designated to act on behalf of the licensee shall, at a minimum, do as much of the following as possible:
(1)Determine whether a cybersecurity event has occurred.
(2)Assess the nature and scope of the cybersecurity event.
(3)Identify any nonpublic information that may have been involved in the cybersecurity event.
(4)Perform or oversee reasonable measures to restore the security of the information systems compromise
Free access — add to your briefcase to read the full text and ask questions with AI
Pennsylvania § 4517 (Investigation of cybersecurity event) — published by Counsel Stack Legal Research, free access to 12M+ legal documents.
Legislative History
Cross References.Section 4517 is referred to in section 4535 of this title.
Nearby Sections
15
§ 4501
Scope of chapter§ 4502
Definitions§ 4512
Risk assessment§ 4514
Corporate oversight§ 4516
Certification§ 4522
Penalties§ 4531
Confidentiality§ 4532
Exemptions§ 4533
Rules and regulations