Entity requires that all staff members with access to any critical system is protected with a secure login mechanism such as Multifactor-authentication
Entity maintains and periodically reviews the inventory of systems which are critical to security commitments and requirements
Entity requires that all staff members complete Information Security Awareness training annually
Entity requires that new staff members complete Information Security Awareness training upon hire
Entity maintains a list of legal, statutory, and regulatory requirements relevant to information security
Entity requires that all company-owned endpoints to be protected from access to external websites using web filtering technologies to reduce exposure to malicious content