47 Neb. Admin. Code, ch. 8, § 002

Current through September 17, 2024
Section 47-8-002 - REQUIRED RESPONSE PROGRAM AND NOTICE TO THE DEPARTMENT
002.01 Digital asset depositories shall have in place a written response program detailing the institution's prescribed method of handling unauthorized access of customer information, a data breach, or any other similar event in which the integrity of the ledger or structure of an underlying digital asset that is being custodied by the digital asset depository is at risk.
002.02 At such time as a digital asset depository becomes aware of an incident referenced in this Section 002 of this Rule, the depository must immediately notify the Department of the event, and must also review Neb. Rev. Stat. §§ 87-801 to 87-807 to determine whether the incident may require notification to the Nebraska Attorney General and to impacted customers, if any. In the event that customer notification is required, the Department shall be provided with a copy of the notice sent to affected customers prior to, or simultaneously with, the customers receiving the notice.
002.03 If such an incident would require the filing of any federal required reporting or notification, such as a suspicious activity report, a copy of any such reporting or notification must be timely delivered to the Department.

47 Neb. Admin. Code, ch. 8, § 002

Adopted effective 5/29/2024