Cyber Insurance Subjectivity Tracker

Controls / Other controls proposal forms ask about

Staff are trained to recognise phishing and other social engineering, and to report a suspected incident

What the applicant reports, the rules behind it in each jurisdiction, and the evidence an assessor asks for. In the applicant's words: train staff to spot phishing and to report a suspected incident.

In Australia

No Essential Eight requirement covers this control; in Australia it is on the schedule as a condition beyond the core list.

PCI DSS v4.0.1, when it applies

Any business that stores, processes or transmits payment card data, in any of the three jurisdictions.

ClauseThe held text, and the evidence an assessor asks for
PCI DSS 12.6.1
PCI DSS v4.0.1 (add-on)
Formal security awareness program

A formal security awareness program must be in place so that all personnel know the entity's security policy and its procedures, and understand their own part in protecting cardholder data. The guidance notes that without such education, safeguards may be undermined by accidental mistakes or deliberate acts. Customized approach objective: personnel understand the threat landscape and their duties in operating relevant security controls, and can obtain help and guidance when they need it.

evidence an assessor asks for Security awareness program document with scope and owner; Training curriculum mapped to policy and procedures; Population coverage list showing all personnel groups; Help channel or contact point for security guidance

PCI DSS 12.6.3.1
PCI DSS v4.0.1 (add-on)
Awareness training covers phishing and social engineering

Security awareness training must address threats and vulnerabilities that could affect cardholder data or sensitive authentication data, covering at minimum phishing (and attacks related to it) plus social engineering. Applicability: technical and automated anti-phishing controls under Requirement 5.4.1 are a separate and distinct requirement; meeting one does not satisfy the other. Objective under the customized approach: personnel understand their own human weaknesses and how attackers try to exploit them, and can obtain help and guidance when needed. Future-dated: treated as a best practice up to 31 March 2025 and mandatory since then.

evidence an assessor asks for Training module content on phishing and social engineering; Phishing simulation campaign results; Reporting procedure for suspected phishing; Completion records for the module

In the United States

ClauseThe held text, and the evidence an assessor asks for
CIS 14.1
CIS Controls v8.1
Establish and Maintain a Security Awareness Program

Set up and keep a security awareness programme whose aim is to teach the workforce how to use enterprise assets and data securely. Train people when they are hired and at least yearly after that. Revisit the content each year, or sooner when a major change in the enterprise could affect this Safeguard.

evidence an assessor asks for Security awareness programme document with content, audience, delivery methods and the annual review date; Training completion records showing new hires trained at onboarding and all staff trained at least annually; Management-approved awareness policy stating mandatory training, the target workforce population and consequences for non-completion; Learning management system export listing each worker's completion date, with contractors and temporary staff included; Annual content review record showing topics updated for new threats, systems or enterprise changes, with approver

CIS 14.2
CIS Controls v8.1
Train Workforce Members to Recognize Social Engineering Attacks

Teach the workforce to spot social engineering, for example phishing, pretexting and tailgating.

evidence an assessor asks for Social engineering training module content covering phishing, pretexting and tailgating, with completion records; Phishing simulation campaign results showing click and report rates and the follow-up training for repeat clickers; Phishing simulation programme plan covering frequency, templates of increasing difficulty and target groups including executives; Tailgating and pretext awareness materials such as posters, briefings or physical social engineering test results; Report or dashboard of suspicious email reports through the report-phishing button, with time to report

CIS 14.6
CIS Controls v8.1
Train Workforce Members on Recognizing and Reporting Security Incidents

Teach the workforce to recognise a possible incident and to report it.

evidence an assessor asks for Training content showing how to recognise a potential incident and the reporting channel to use; Completion records, plus a sample of workforce-originated incident reports showing the channel is being used; Incident reporting instructions issued to staff: examples of incidents, the report channel, hotline and expected response; Metrics on time from event to staff report for recent incidents, used to measure training effect; Tabletop or awareness exercise records where staff practised recognising and reporting an incident

PR.AT-01
NIST CSF 2.0

Personnel are provided with awareness and training so that they possess the knowledge and skills to perform general tasks with cybersecurity risks in mind

evidence an assessor asks for Security awareness program curriculum; Completion records by population; Phishing simulation results and trends; Awareness campaign artefacts (posters, emails); Annual program effectiveness review

FTC Safeguards Rule, when it applies

Financial institutions under FTC jurisdiction, for example tax preparers, mortgage brokers and auto dealers that arrange financing.

ClauseThe held text, and the evidence an assessor asks for
314.4(e)(1)
FTC Safeguards Rule (add-on)
314.4(e)(1) Security awareness training

Personnel receive security awareness training that is updated as necessary to reflect the risks identified by the risk assessment.

evidence an assessor asks for Security awareness training records; Evidence the content was updated for identified risks

HIPAA Security Rule, when it applies

HIPAA covered entities (health plans, health care clearinghouses, health care providers that transmit health information electronically) and their business associates.

ClauseThe held text, and the evidence an assessor asks for
164.308(a)(5)(i)
HIPAA Security Rule (add-on)
Security Awareness and Training (Standard)

Implement a security awareness and training program for all workforce members. NIST recommends role-based content, onboarding plus annual refresh, and reinforcement reminders.

evidence an assessor asks for Training curriculum; Completion records by workforce member; Role-based modules; Awareness campaigns calendar

23 NYCRR 500, when it applies

Entities licensed by the New York Department of Financial Services. Section 500.19 sets limited exemptions for smaller covered entities: whether one applies is a question for the business, and this page never decides it.

ClauseThe held text, and the evidence an assessor asks for
500.14
23 NYCRR 500 (add-on)
Monitoring and Training

Implement risk-based controls including monitoring of authorized user activity and detection of unauthorized access or tampering, malware protection, annual cybersecurity awareness training including social engineering. Class A must implement endpoint detection and response solution and centralized logging.

evidence an assessor asks for UEBA or user activity monitoring outputs; Anti-malware deployment coverage report; Annual training completion records with phishing simulation results; Class A EDR coverage dashboard; Class A centralized SIEM logging design and coverage; CISO-approved compensating control register if EDR/SIEM not implemented (Class A); Training content review covering social engineering

PCI DSS v4.0.1, when it applies

Any business that stores, processes or transmits payment card data, in any of the three jurisdictions.

ClauseThe held text, and the evidence an assessor asks for
PCI DSS 12.6.1
PCI DSS v4.0.1 (add-on)
Formal security awareness program

A formal security awareness program must be in place so that all personnel know the entity's security policy and its procedures, and understand their own part in protecting cardholder data. The guidance notes that without such education, safeguards may be undermined by accidental mistakes or deliberate acts. Customized approach objective: personnel understand the threat landscape and their duties in operating relevant security controls, and can obtain help and guidance when they need it.

evidence an assessor asks for Security awareness program document with scope and owner; Training curriculum mapped to policy and procedures; Population coverage list showing all personnel groups; Help channel or contact point for security guidance

PCI DSS 12.6.3.1
PCI DSS v4.0.1 (add-on)
Awareness training covers phishing and social engineering

Security awareness training must address threats and vulnerabilities that could affect cardholder data or sensitive authentication data, covering at minimum phishing (and attacks related to it) plus social engineering. Applicability: technical and automated anti-phishing controls under Requirement 5.4.1 are a separate and distinct requirement; meeting one does not satisfy the other. Objective under the customized approach: personnel understand their own human weaknesses and how attackers try to exploit them, and can obtain help and guidance when needed. Future-dated: treated as a best practice up to 31 March 2025 and mandatory since then.

evidence an assessor asks for Training module content on phishing and social engineering; Phishing simulation campaign results; Reporting procedure for suspected phishing; Completion records for the module

In United Kingdom

ClauseThe held text, and the evidence an assessor asks for
CE-SC.7
Cyber Essentials
Educate Users on Strong Passwords

Educate users to avoid common, predictable, or compromised passwords and on the importance of unique passwords per account.

evidence an assessor asks for password guidance document; training attendance log; phishing/password module evidence

PCI DSS v4.0.1, when it applies

Any business that stores, processes or transmits payment card data, in any of the three jurisdictions.

ClauseThe held text, and the evidence an assessor asks for
PCI DSS 12.6.1
PCI DSS v4.0.1 (add-on)
Formal security awareness program

A formal security awareness program must be in place so that all personnel know the entity's security policy and its procedures, and understand their own part in protecting cardholder data. The guidance notes that without such education, safeguards may be undermined by accidental mistakes or deliberate acts. Customized approach objective: personnel understand the threat landscape and their duties in operating relevant security controls, and can obtain help and guidance when they need it.

evidence an assessor asks for Security awareness program document with scope and owner; Training curriculum mapped to policy and procedures; Population coverage list showing all personnel groups; Help channel or contact point for security guidance

PCI DSS 12.6.3.1
PCI DSS v4.0.1 (add-on)
Awareness training covers phishing and social engineering

Security awareness training must address threats and vulnerabilities that could affect cardholder data or sensitive authentication data, covering at minimum phishing (and attacks related to it) plus social engineering. Applicability: technical and automated anti-phishing controls under Requirement 5.4.1 are a separate and distinct requirement; meeting one does not satisfy the other. Objective under the customized approach: personnel understand their own human weaknesses and how attackers try to exploit them, and can obtain help and guidance when needed. Future-dated: treated as a best practice up to 31 March 2025 and mandatory since then.

evidence an assessor asks for Training module content on phishing and social engineering; Phishing simulation campaign results; Reporting procedure for suspected phishing; Completion records for the module

Also cited: ISO/IEC 27001:2022 Annex A

A lens in any jurisdiction, never a gap on its own.

ClauseThe held text, and the evidence an assessor asks for
A.6.3
ISO/IEC 27001:2022 (lens)
Information security awareness, education and training

The organization's personnel and relevant interested parties are to receive information security awareness, education and training suited to their jobs, together with regular updates on the policy, topic-specific policies and procedures. Purpose (stated in ISO/IEC 27002:2022): makes staff and relevant outside parties know and carry out their security duties. As an Annex A reference control, it is compared with the controls determined in risk treatment (6.1.3 c) and recorded in the Statement of Applicability as included or excluded, with the justification and implementation status (6.1.3 d); implementation guidance is ISO/IEC 27002:2022 6.3.

evidence an assessor asks for Statement of Applicability entry for control A.6.3, showing inclusion or justified exclusion, implementation status and the risks it treats; A documented awareness, education and training programme aligned with the policies and planned by role, including external personnel; Completion records for initial training of new starters and role changers and for periodic refreshers; Assessment results testing understanding at the end of training activities; Awareness materials across channels covering management commitment, obligations, accountability, event reporting and baseline controls

Questions

What does the applicant report for this control?
Whether it is in place, partly in place, not in place or not sure. Partly, not in place and not sure are gaps; not sure reads as a question.
When is it due on the 90-day schedule?
Day 60 by the default rule for a core line, day 90 when it is beyond the core list for the jurisdiction or marked not sure. The underwriter or broker can move it.
Does this page check the control?
No. The applicant reports a closure with a date and a note; the schedule records it as reported and never checks it.

Put this control on a schedule