Cyber Insurance Subjectivity Tracker
Controls

The controls a cyber schedule reads

Each control is what an applicant reports: in place, partly, not in place or not sure. Each page sets out the rule behind it in Australia, the United States and the United Kingdom, and the evidence an assessor asks for.

Multi-factor authentication

Backups

Patching

Administrator accounts

Application control and hardening

Logging and incident response

Other controls proposal forms ask about

Sector rules (add-ons)

Privacy Act (Australia)