Marriott and Starwood Hotels & Resorts have been ordered to implement a comprehensive information security program.
The program requires appointing a leader, providing regular governance reports, and training employees on safeguarding personal information.
Specific requirements include incident response plans, logging and monitoring systems, multi-factor authentication, and careful vendor selection and management.
The charges were filed by the US Federal Trade Commission after data breaches that impacted millions of customers.