NASAA Series 65, Uniform Investment Adviser Law ExaminationLaws, Regulations, and Guidelines, including Prohibition on Unethical Business PracticesEasy
An investment adviser representative (IAR) is assisting a client with opening a new investment account. The client provides the IAR with their social security number, birth date, and bank account information. Which of the following best describes the IAR's obligation regarding this client information under cybersecurity best practices?
- AThe IAR should share the information with third-party marketing firms to offer additional services.
- BThe IAR must ensure the information is transmitted and stored using secure, encrypted methods.
- CThe IAR should ensure the information is only stored on a personal, unencrypted laptop for easy access.
- DThe IAR is only responsible for protecting the information while it is in their direct possession.
Show answer & explanationAnswer & explanation
Correct answer: B. The IAR must ensure the information is transmitted and stored using secure, encrypted methods.
Cybersecurity best practices and regulatory requirements mandate that sensitive client information be transmitted and stored using secure, encrypted methods to protect against unauthorized access and data breaches.
Why the other options are wrong
- A. Sharing client information with unauthorized third parties is a clear violation of privacy and cybersecurity rules.
- C. Storing sensitive data on an unencrypted device is a severe cybersecurity risk and a violation of best practices.
- D. The responsibility extends beyond direct possession to the entire lifecycle of the data within the firm's control.
Cybersecurity - Data Protection
Investment advisers and their representatives have a responsibility to protect sensitive client information from unauthorized access, use, or disclosure through robust cybersecurity measures, including encryption and secure storage.
- Mandated by regulatory bodies (SEC, state Administrators).
- Applies to all personally identifiable information (PII).
- Requires secure transmission, storage, and access controls.
- Includes employee training and incident response plans.
Memory trick: Client Data: Encrypt, Protect, Never Neglect!