Pennsylvania Statutes
§ 4514 — Corporate oversight
(a)Duties.--If a licensee has a board of directors, the board or an appropriate committee of the board shall, at a minimum:
(1)Require the licensee's executive management or delegates to develop, implement and maintain the licensee's information security program.
(2)Require the licensee's executive management or delegates to report in writing at least annually, the following information:
(i)The overall status of the information security program and the licensee's compliance with this chapter.
(ii)Material matters related to the information security program, addressing issues such as:
(A)Risk assessment, risk management and control decisions.
(B)Third-party service provider arrangements.
(C)The results of testing.
(D)Cybersecurity events.
(E)Any violation of this chapter
Free access — add to your briefcase to read the full text and ask questions with AI
Pennsylvania § 4514 (Corporate oversight) — published by Counsel Stack Legal Research, free access to 12M+ legal documents.
Legislative History
Cross References.Section 4514 is referred to in sections 4516, 4521, 4532, 4536 of this title.
Nearby Sections
15
§ 4501
Scope of chapter§ 4502
Definitions§ 4512
Risk assessment§ 4514
Corporate oversight§ 4516
Certification§ 4522
Penalties§ 4531
Confidentiality§ 4532
Exemptions§ 4533
Rules and regulations