The proposed amendments are designed to ensure that covered institutions maintain a reasonable information security program that includes safeguarding policies and procedures that are more specific than those currently required, including policies and procedures for responding to data security breach incidents, for notifying individuals for whom the incidents pose a risk of identity theft, and for