Cyber Insurance Subjectivity Tracker

Controls / Other controls proposal forms ask about

Laptops, phones and removable media that hold sensitive data are encrypted

What the applicant reports, the rules behind it in each jurisdiction, and the evidence an assessor asks for. In the applicant's words: encrypt laptops, phones and removable media that hold sensitive data.

In Australia

No Essential Eight requirement covers this control; in Australia it is on the schedule as a condition beyond the core list.

In the United States

ClauseThe held text, and the evidence an assessor asks for
CIS 3.6
CIS Controls v8.1
Encrypt Data on End-User Devices

Encrypt the data held on end-user devices that store sensitive data. (The held text goes on to give examples that name commercial products; they are left out here.)

evidence an assessor asks for Endpoint encryption policy for the built-in disk encryption of each operating system; Encryption compliance report listing unencrypted end-user devices and remediation; MDM or endpoint management encryption status report for laptops and desktops holding sensitive data; Recovery key escrow records showing keys stored centrally for each encrypted device; Build standard showing encryption enabled before a device is issued

CIS 3.9
CIS Controls v8.1

Encrypt data on removable media.

evidence an assessor asks for Inventory of approved encrypted USB devices issued to staff, with serial numbers, holders and the encryption algorithm used; Data protection standard requiring encryption of any enterprise data written to removable media, with the approved tools and exemption process; Endpoint or device management policy forcing encryption before writes to USB drives; Device control logs showing unencrypted removable media blocked or set to read-only

PR.DS-01
NIST CSF 2.0

The confidentiality, integrity, and availability of data-at-rest are protected. Control from NIST Cybersecurity Framework 2.0 framework, domain: PR - Protect.

evidence an assessor asks for Data at rest encryption inventory by store type; Key management standards and rotation evidence; Storage configuration baselines with attestation; Sensitive data discovery findings remediated; Audit findings on data at rest protection

FTC Safeguards Rule, when it applies

Financial institutions under FTC jurisdiction, for example tax preparers, mortgage brokers and auto dealers that arrange financing.

ClauseThe held text, and the evidence an assessor asks for
314.4(c)(3)
FTC Safeguards Rule (add-on)
314.4(c)(3) Encryption in transit and at rest

All customer information held or transmitted by the institution is protected by encryption both in transit over external networks and at rest; where the institution determines encryption is infeasible in either case, it may instead secure the information by effective alternative compensating controls reviewed and approved by the Qualified Individual.

evidence an assessor asks for Encryption standards and coverage for data at rest and in transit over external networks; Qualified Individual's written approval of any compensating control with the infeasibility determination

HIPAA Security Rule, when it applies

HIPAA covered entities (health plans, health care clearinghouses, health care providers that transmit health information electronically) and their business associates.

ClauseThe held text, and the evidence an assessor asks for
164.312(a)(2)(iv)
HIPAA Security Rule (add-on)
Encryption and Decryption (Addressable)

Implement a mechanism to encrypt and decrypt ePHI. NIST recommends FIPS 140-validated cryptography, encryption at rest for all ePHI stores, and key management aligned to SP 800-57.

evidence an assessor asks for Encryption standard; FIPS 140 validation references; Key management procedures; Database, file, and endpoint encryption coverage report

23 NYCRR 500, when it applies

Entities licensed by the New York Department of Financial Services. Section 500.19 sets limited exemptions for smaller covered entities: whether one applies is a question for the business, and this page never decides it.

ClauseThe held text, and the evidence an assessor asks for
500.15
23 NYCRR 500 (add-on)
Encryption of Nonpublic Information

Implement controls including encryption to protect Nonpublic Information held or transmitted by the Covered Entity in transit over external networks and at rest. Where encryption at rest is infeasible, CISO may approve effective alternative compensating controls, reviewed at least annually.

evidence an assessor asks for Encryption standards and approved algorithms list; TLS configuration scans for external endpoints; At-rest encryption coverage report by data store; Key management procedures and HSM evidence; CISO-approved compensating control register for at-rest exceptions with annual review; Discovery scans for unencrypted Nonpublic Information; Email and file transfer encryption configuration

In United Kingdom

No requirement in the core list for the United Kingdom covers this control; it is on the schedule as a condition beyond the core list.

Also cited: ISO/IEC 27001:2022 Annex A

A lens in any jurisdiction, never a gap on its own.

ClauseThe held text, and the evidence an assessor asks for
A.8.24
ISO/IEC 27001:2022 (lens)
Use of cryptography

The organization is to define and apply rules for using cryptography effectively, key management included. Purpose (stated in ISO/IEC 27002:2022): makes cryptography work correctly to keep information confidential, genuine or unaltered as business, security and legal needs require. As an Annex A reference control, it is compared with the controls determined in risk treatment (6.1.3 c) and recorded in the Statement of Applicability as included or excluded, with the justification and implementation status (6.1.3 d); implementation guidance is ISO/IEC 27002:2022 8.24.

evidence an assessor asks for Statement of Applicability entry for control A.8.24, showing inclusion or justified exclusion, implementation status and the risks it treats; The topic-specific cryptography policy with approved algorithms, key lengths, protocols and usage by information classification; Key management procedures covering generation, distribution, storage, rotation, revocation, recovery, backup, destruction and activation periods; Key inventory or HSM and key management service records with logs of key management activity; Evidence of encryption on endpoints, removable media and data in transit, aligned with the policy

Questions

What does the applicant report for this control?
Whether it is in place, partly in place, not in place or not sure. Partly, not in place and not sure are gaps; not sure reads as a question.
When is it due on the 90-day schedule?
Day 60 by the default rule for a core line, day 90 when it is beyond the core list for the jurisdiction or marked not sure. The underwriter or broker can move it.
Does this page check the control?
No. The applicant reports a closure with a date and a note; the schedule records it as reported and never checks it.

Put this control on a schedule