United States
The FTC Safeguards Rule and cyber insurance
For a financial institution under FTC jurisdiction, such as a tax preparer, a mortgage broker or an auto dealer that arranges financing, the Safeguards Rule adds its own lines to the schedule: the written program and its qualified individual, the risk assessment, multi-factor authentication, encryption, and notice to the FTC no later than 30 days after discovering a notification event involving 500 or more consumers.
The controls
- A written information security program exists, owned by a named qualified individual or officer
- A written risk assessment of the information systems is done and repeated periodically
- Staff sign in to email and the online services that hold business data (office suite, accounting, practice or client software) with multi-factor authentication
- Laptops, phones and removable media that hold sensitive data are encrypted
- The business knows the notice its rule requires after an incident or a data breach, to whom and by when
- Staff are trained to recognise phishing and other social engineering, and to report a suspected incident
Start from the template, or mark the controls in the control list. How the schedule works.
Questions
- Does this page say the business can be covered?
- No. It shows the gaps and the rule behind each; cover is the insurer's decision.
- What does it cost?
- One applicant on screen is free in any jurisdiction. Saving clocks and the applicant link are on Solo.