Controls / Sector rules (add-ons)
A written risk assessment of the information systems is done and repeated periodically
What the applicant reports, the rules behind it in each jurisdiction, and the evidence an assessor asks for. In the applicant's words: write a risk assessment of your information systems, and repeat it on a schedule.
In the United States
FTC Safeguards Rule, when it applies
Financial institutions under FTC jurisdiction, for example tax preparers, mortgage brokers and auto dealers that arrange financing.
| Clause | The held text, and the evidence an assessor asks for |
|---|---|
| 314.4(b)(1) FTC Safeguards Rule (add-on) | 314.4(b)(1) Written risk assessment The risk assessment is written and includes criteria for evaluating and categorising the identified security risks and threats, criteria for assessing the confidentiality, integrity and availability of the institution's information systems and customer information including the adequacy of existing controls against the identified risks, and requirements describing how identified risks will be mitigated or accepted and how the program will address them. Not required of institutions holding information on fewer than 5,000 consumers (314.6). evidence an assessor asks for Written risk assessment with categorisation criteria, CIA assessment criteria and mitigation or acceptance requirements; Inventory of identified internal and external risks |
HIPAA Security Rule, when it applies
HIPAA covered entities (health plans, health care clearinghouses, health care providers that transmit health information electronically) and their business associates.
| Clause | The held text, and the evidence an assessor asks for |
|---|---|
| 164.308(a)(1)(ii)(A) HIPAA Security Rule (add-on) | Risk Analysis (Required) Conduct accurate and thorough assessment of potential risks and vulnerabilities to ePHI. NIST recommends the nine-step risk analysis methodology and integration with NIST SP 800-30 and the NIST RMF. evidence an assessor asks for Documented risk analysis report; Risk analysis methodology aligned to NIST SP 800-30; Periodic refresh schedule; Evidence of ePHI scoping |
23 NYCRR 500, when it applies
Entities licensed by the New York Department of Financial Services. Section 500.19 sets limited exemptions for smaller covered entities: whether one applies is a question for the business, and this page never decides it.
| Clause | The held text, and the evidence an assessor asks for |
|---|---|
| 500.9 23 NYCRR 500 (add-on) | Risk Assessment Conduct a written Risk Assessment of the Covered Entity's information systems, reviewed and updated at least annually and whenever a change in business or technology causes material change to risk. Assessment must follow written policies and procedures and account for emerging technologies and changes in nonpublic information. evidence an assessor asks for Written Risk Assessment methodology; Current annual Risk Assessment report; Risk register with treatments and owners; Change-triggered reassessments log; Inventory of information systems and data flows feeding the assessment; Linkage of Risk Assessment to controls in ยง500.2 program; Board or governing body briefing on top risks |
Questions
- What does the applicant report for this control?
- Whether it is in place, partly in place, not in place or not sure. Partly, not in place and not sure are gaps; not sure reads as a question.
- When is it due on the 90-day schedule?
- Day 90 by the default rule: a sector add-on line. The underwriter or broker can move it.
- Does this page check the control?
- No. The applicant reports a closure with a date and a note; the schedule records it as reported and never checks it.