Cyber Insurance Subjectivity Tracker
United States

Cyber insurance conditions in the United States, on a 90-day clock

In the United States the core list is CIS Controls v8.1 and NIST CSF 2.0. Sector rules are add-ons the applicant ticks, each with its trigger: the FTC Safeguards Rule (financial institutions under FTC jurisdiction, such as tax preparers, mortgage brokers and auto dealers that arrange financing), the HIPAA Security Rule (covered entities and business associates), 23 NYCRR 500 (entities licensed by the New York Department of Financial Services; the section 500.19 limited exemption is a question for the business) and PCI DSS (card data). "Not sure" makes an add-on's lines questions.

Your carrier or broker sets day 0; each gap gets a checkpoint at day 30, 60 or 90 by the default rule, and the applicant reports each fix closed through a private link. Start from the United States template, or mark the controls in the control list.

The controls with a rule in the core list here (28)

Rule sets