Bidda Sovereign Intelligence · 10,090 Verified Nodes · 39 Sovereign Pillars

Report on Selected Cybersecurity Practices - 2018

This report continues FINRA’s efforts to share information that can help broker-dealer firms further develop their cybersecurity programs. Firms routinely…

What Report on Selected Cybersecurity Practices - 2018 requires

This report continues FINRA’s efforts to share information that can help broker-dealer firms further develop their cybersecurity programs. Firms routinely identify cybersecurity as one of their primary operational risks, and this report presents FINRA’s observations regarding effective practices that firms have implemented to address selected cybersecurity risks, recognizing that there is no one-size-fits-all approach. The topics covered include strengthening cybersecurity controls in branch offices, limiting phishing attacks, identifying and mitigating insider threats, the elements of a strong penetration testing program, and establishing controls on mobile devices. The report highlights practices that should be evaluated in the context of a holistic firm-level cybersecurity program. It is intended for broker-dealer firms, with specific guidance for small firms provided in an appendix titled “Core Cybersecurity Controls for Small Firms.” The core obligations involve implementing robust controls across various domains, such as developing written supervisory procedures (WSPs) for branches, conducting regular training, maintaining asset inventories, establishing technical controls like multi-factor authentication and encryption, conducting penetration tests, and managing mobile device security.

Pillar: Operations & CX · Authority: FINANCIAL INDUSTRY REGULATORY AUTHORITY · Version: 1.0.0 · Last updated:

Primary source: https://www.finra.org/sites/default/files/Cybersecurity_Report_2018.pdf

SHA-256 integrity: dbce7e2050a18924abb5ac579fcfba67e0df14b02ed45b5bd503bc1f0e163d14

Primary Citations — 8 traced to source

  • Branch-Level WSPs: Mandating that registered representatives complete an annual attestation to comply with the firm's WSP requirements, including its cybersecurity policies.
  • Technical Controls: Prohibiting the sharing of passwords among firm staff;

+ 6 more citations (full bibliography, deterministic workflow, actionable schema and crosswalks) included in the vault unlock — $0.01 via Skyfire / L402 / Direct Base USDC.

Access

⚠ Important: Human Verification Required

Bidda compliance nodes are reference intelligence, not legal advice. Every node must be reviewed by a qualified compliance professional or legal counsel before implementation in any enterprise workflow, regulated system, or compliance programme. See bidda.com/disclaimer for full terms.