|
All active domains are required to complete scans of public databases. |
If you collect PII or PHI, how many payment card numbers (credit cards, debit cards, etc.) does company store, process, transmit, or have access to: |
We are looking for the actual number of individual credit cards processed annually or store in your files, not the $ amount of transactions. |
How many customer PII* or PHI** records does the company have: |
|
Within the last 3 years has company been subject to any complaints concerning the content of its website, advertising materials, social media, or other publications: |
|
Does company have procedures to remove content (including third party content) that is libelous, infringing, or otherwise controversial: |
|
Does company require dual control when transferring funds in excess of $25,000: |
Examples of Dual Control procedures:
(1) Calling the recipient of the wire transfer to verify the transaction details.
(2) Verifying the transaction with another executive at the company (preferably in writing).
(3) Setting up internal controls within your financial institution. One administrator or user enters or creates a payment (ACH batch, wire transfer), and a second administrator or user is then required to review the payment and approve/release the transaction. |