Under the interagency guidelines for safeguarding customer information, financial institutions must conduct which activity to identify risks to customer data?
-
A
An annual external penetration test only
-
B
A risk assessment to identify reasonably foreseeable risks
-
C
A customer survey on data handling preferences
-
D
A quarterly review of employee social media accounts