Cyber Insurance Subjectivity Tracker

Controls / Sector rules (add-ons)

A written risk assessment of the information systems is done and repeated periodically

What the applicant reports, the rules behind it in each jurisdiction, and the evidence an assessor asks for. In the applicant's words: write a risk assessment of your information systems, and repeat it on a schedule.

In the United States

FTC Safeguards Rule, when it applies

Financial institutions under FTC jurisdiction, for example tax preparers, mortgage brokers and auto dealers that arrange financing.

ClauseThe held text, and the evidence an assessor asks for
314.4(b)(1)
FTC Safeguards Rule (add-on)
314.4(b)(1) Written risk assessment

The risk assessment is written and includes criteria for evaluating and categorising the identified security risks and threats, criteria for assessing the confidentiality, integrity and availability of the institution's information systems and customer information including the adequacy of existing controls against the identified risks, and requirements describing how identified risks will be mitigated or accepted and how the program will address them. Not required of institutions holding information on fewer than 5,000 consumers (314.6).

evidence an assessor asks for Written risk assessment with categorisation criteria, CIA assessment criteria and mitigation or acceptance requirements; Inventory of identified internal and external risks

HIPAA Security Rule, when it applies

HIPAA covered entities (health plans, health care clearinghouses, health care providers that transmit health information electronically) and their business associates.

ClauseThe held text, and the evidence an assessor asks for
164.308(a)(1)(ii)(A)
HIPAA Security Rule (add-on)
Risk Analysis (Required)

Conduct accurate and thorough assessment of potential risks and vulnerabilities to ePHI. NIST recommends the nine-step risk analysis methodology and integration with NIST SP 800-30 and the NIST RMF.

evidence an assessor asks for Documented risk analysis report; Risk analysis methodology aligned to NIST SP 800-30; Periodic refresh schedule; Evidence of ePHI scoping

23 NYCRR 500, when it applies

Entities licensed by the New York Department of Financial Services. Section 500.19 sets limited exemptions for smaller covered entities: whether one applies is a question for the business, and this page never decides it.

ClauseThe held text, and the evidence an assessor asks for
500.9
23 NYCRR 500 (add-on)
Risk Assessment

Conduct a written Risk Assessment of the Covered Entity's information systems, reviewed and updated at least annually and whenever a change in business or technology causes material change to risk. Assessment must follow written policies and procedures and account for emerging technologies and changes in nonpublic information.

evidence an assessor asks for Written Risk Assessment methodology; Current annual Risk Assessment report; Risk register with treatments and owners; Change-triggered reassessments log; Inventory of information systems and data flows feeding the assessment; Linkage of Risk Assessment to controls in ยง500.2 program; Board or governing body briefing on top risks

Questions

What does the applicant report for this control?
Whether it is in place, partly in place, not in place or not sure. Partly, not in place and not sure are gaps; not sure reads as a question.
When is it due on the 90-day schedule?
Day 90 by the default rule: a sector add-on line. The underwriter or broker can move it.
Does this page check the control?
No. The applicant reports a closure with a date and a note; the schedule records it as reported and never checks it.

Put this control on a schedule