Security terms in outside counsel guidelines address encryption, access control, multi-factor authentication, breach notification timing, subcontractor approval, data location, and audit rights. Requirements vary substantially by client.
Some clients conduct on-site or remote security assessments.
Alternative Names:
OCG Security Requirements, Client Security Requirements
Why it Matters?
Requirements now vary enough between clients that a firm may face conflicting obligations, particularly on data location and retention. Notification timelines are the provision most often missed, since several clients require notice within twenty-four hours of discovering an incident, which is faster than most firms' internal escalation produces. Mapping requirements across the client base identifies where the firm's actual capability falls short of what it has agreed.
Frequently Confused with
Related terms
Frequently asked questions
What provision is most often missed?
Can requirements conflict?





