Cyber Insurance Subjectivity Tracker

Controls / Sector rules (add-ons)

A written information security program exists, owned by a named qualified individual or officer

What the applicant reports, the rules behind it in each jurisdiction, and the evidence an assessor asks for. In the applicant's words: write the information security program your rule asks for, and name the person who owns it.

In the United States

FTC Safeguards Rule, when it applies

Financial institutions under FTC jurisdiction, for example tax preparers, mortgage brokers and auto dealers that arrange financing.

ClauseThe held text, and the evidence an assessor asks for
314.3(a)
FTC Safeguards Rule (add-on)
314.3(a) Comprehensive written information security program

The institution develops, implements and maintains a comprehensive information security program, written in one or more readily accessible parts, containing administrative, technical and physical safeguards appropriate to its size and complexity, the nature and scope of its activities and the sensitivity of the customer information at issue, including the elements of 314.4 and reasonably designed to meet the rule's objectives: the security and confidentiality of customer information, protection against anticipated threats or hazards to its security or integrity, and protection against unauthorised access or use that could result in substantial harm or inconvenience to a customer.

evidence an assessor asks for Written information security program covering administrative, technical and physical safeguards; Mapping of the program to the 314.4 elements; Evidence of proportionality to size, complexity and data sensitivity

314.4(a)
FTC Safeguards Rule (add-on)
314.4(a) Qualified Individual

The institution designates a Qualified Individual responsible for overseeing, implementing and enforcing the information security program; the individual may be employed by the institution, an affiliate or a service provider, and where a service provider or affiliate fills the role the institution retains responsibility for compliance, designates a senior member of its own personnel to direct and oversee the Qualified Individual, and requires the provider or affiliate to maintain an information security program that protects the institution to the rule's requirements.

evidence an assessor asks for Designation of the Qualified Individual with responsibilities; Where outsourced: the named senior overseer and the provider's contractual program obligation

HIPAA Security Rule, when it applies

HIPAA covered entities (health plans, health care clearinghouses, health care providers that transmit health information electronically) and their business associates.

ClauseThe held text, and the evidence an assessor asks for
164.308(a)(1)(i)
HIPAA Security Rule (add-on)
Security Management Process (Standard)

Implement policies and procedures to prevent, detect, contain, and correct security violations. NIST recommends establishing an enterprise security governance program with defined roles and risk-based decision making.

evidence an assessor asks for Information security policy; Security program charter; Governance committee minutes; Risk management framework documentation

23 NYCRR 500, when it applies

Entities licensed by the New York Department of Financial Services. Section 500.19 sets limited exemptions for smaller covered entities: whether one applies is a question for the business, and this page never decides it.

ClauseThe held text, and the evidence an assessor asks for
500.2
23 NYCRR 500 (add-on)
Cybersecurity Program

Maintain a written cybersecurity program based on the Risk Assessment that performs the core functions: identify, protect, detect, respond, recover, and fulfill reporting obligations.

evidence an assessor asks for Written cybersecurity program document; Mapping of program elements to identify/protect/detect/respond/recover functions; Risk Assessment linkage matrix; Board or Senior Governing Body approval record; Annual program review minutes; Program scope statement including affiliates; Evidence of integration with enterprise risk

500.4
23 NYCRR 500 (add-on)
Cybersecurity Governance (CISO)

Designate a qualified CISO responsible for overseeing and implementing the program and enforcing policy. CISO reports in writing at least annually to Senior Governing Body on program status, risks, and material events. Senior Governing Body must exercise oversight and have sufficient cybersecurity expertise.

evidence an assessor asks for CISO appointment letter with qualifications; Annual CISO written report to Senior Governing Body; Board or committee minutes evidencing oversight; Material event notifications to governing body; Evidence of cybersecurity expertise on governing body (training, advisors); CISO independence and reporting line diagram; Third-party CISO arrangement and oversight if applicable

Questions

What does the applicant report for this control?
Whether it is in place, partly in place, not in place or not sure. Partly, not in place and not sure are gaps; not sure reads as a question.
When is it due on the 90-day schedule?
Day 90 by the default rule: a sector add-on line. The underwriter or broker can move it.
Does this page check the control?
No. The applicant reports a closure with a date and a note; the schedule records it as reported and never checks it.

Put this control on a schedule