Cyber Insurance Application Scannermap an application to controls

At-Bay cyber policy application, held

The questions of the Cyber Insurance Short Application, held and mapped to the ISO 27001:2022 controls, the SOC 2 criteria and the NIST CSF 2.0 outcomes each one reaches. The source document (read 2026-10-11). The date shown is the date this copy was read, not a version the form itself states. This page quotes only the question each mapped row needs and states its source; it does not publish the carrier's form. A complete form would be held only under a stated policy for copyrighted forms. At-Bay is a source document, never a customer.

This document's questions reach 18 of 290 held controls. Whether an applicant is offered cover is the carrier’s underwriting decision. 1 question here is flagged knockout (a "no" is a common decline point) and 1 flagged warranty (an answer the carrier relies on, that can affect cover if wrong).

An answer about an existing state of affairs can be relied on by the carrier, but in Australia and the United Kingdom a statement by the insured is a representation, not a warranty (the Insurance Contracts Act and the Insurance Act), and the position varies by US state.

Application question Does the Applicant store or process personal, health or credit card information of more than 500,000 individuals?
At-Bay held application question
ISO 27001:2022 A.8.24 Use of cryptography
Evidence to have on file (guidance, our wording)
  • The topic-specific cryptography policy with approved algorithms, key lengths, protocols and usage by information classification
  • Evidence of encryption on endpoints, removable media and data in transit, aligned with the policy
ISO 27001:2022 A.5.15 Access control
Evidence to have on file (guidance, our wording)
  • The topic-specific access control policy, approved and communicated, reflecting owner-defined business and security requirements
  • Access control rules or role models mapping entities (users, services, devices) to rights, consistent with classification
SOC 2 CC6.1 Logical access security over protected information assets
Evidence to have on file (guidance, our wording)
  • Asset inventory with classification for in-scope systems
  • Identity provider configuration showing MFA and password policy
SOC 2 CC6.7 Restricting and protecting information in transmission, movement and removal
Evidence to have on file (guidance, our wording)
  • TLS and encryption standards for data in transit
  • Removable media policy and technical enforcement
NIST CSF 2.0 PR.DS-01 The confidentiality, integrity, and availability of data-at-rest are protected
Evidence to have on file (guidance, our wording)
  • Data at rest encryption inventory by store type
  • Storage configuration baselines with attestation
Application question Yes [7 we If yes, please approximate the number of individuals Does the Applicant have multi-factor authentication enabled on email access and remote network access?
At-Bay held application question

This is a scoping question, not a control requirement. It reaches no held control.

No held control answers this line.

Application question Does the Applicant keep offline backups that are disconnected from its network or store backups with a cloud service provider?
At-Bay held application question

Flagged knockout: the wording of this question makes a "no" a common point at which a cyber application is declined or referred.

Flagged warranty: where the carrier declares its answers to be the basis of the contract, this is an answer the carrier relies on and that can affect cover if it is wrong.

ISO 27001:2022 A.8.13 Information backup
Evidence to have on file (guidance, our wording)
  • The topic-specific backup policy and backup plans stating scope, extent, frequency and retention per system aligned with RPO
  • Backup job monitoring reports with evidence that failed jobs were investigated and rerun
ISO 27001:2022 A.8.14 Redundancy of information processing facilities
Evidence to have on file (guidance, our wording)
  • Documented availability requirements for business services and systems
  • Architecture diagrams showing redundancy such as dual providers, redundant networks, separate data centres, redundant power and load-balanced instances
ISO 27001:2022 A.5.19 Information security in supplier relationships
Evidence to have on file (guidance, our wording)
  • The topic-specific supplier relationship policy and its communication record
  • A supplier inventory categorized by type and by the information, services and infrastructure each can access
SOC 2 A1.2 Environmental protection, backup and recovery infrastructure
Evidence to have on file (guidance, our wording)
  • Backup policy defining scope, frequency and retention
  • Backup job monitoring and failure remediation records
SOC 2 A1.3 Testing recovery plan procedures
Evidence to have on file (guidance, our wording)
  • Disaster recovery or continuity test plan and results in the period
  • Backup restore test records with verification of completeness
NIST CSF 2.0 PR.DS-11 Backups of data are created, protected, maintained, and tested
Evidence to have on file (guidance, our wording)
  • Backup policy with frequency and retention
  • Backup integrity test reports
NIST CSF 2.0 GV.SC-01 A cybersecurity supply chain risk management program, strategy, objectives, policies, and processes are established and agreed to by organizational stakeholders
Evidence to have on file (guidance, our wording)
  • Third party risk management program charter
  • Supplier risk policy with tiering criteria
Application question ve at SS bay Security Controls Does the Applicant have controls in place which require all fund and wire transfers over $25,000 to be authorized and verified by at least two employees prior to execution?
At-Bay held application question
ISO 27001:2022 A.5.3 Segregation of duties
Evidence to have on file (guidance, our wording)
  • the bank or treasury platform dual-authorisation setup and the payment approval workflow, showing a second approver on a different device above the threshold
  • the callback or out-of-band verification procedure for a change to payee bank details, with a dated example
ISO 27001:2022 A.6.3 Information security awareness, education and training
Evidence to have on file (guidance, our wording)
  • A documented awareness, education and training programme aligned with the policies and planned by role, including external personnel
  • Completion records for initial training of new starters and role changers and for periodic refreshers
ISO 27001:2022 A.8.5 Secure authentication
Evidence to have on file (guidance, our wording)
  • An authentication standard linking required authentication strength to information classification and system criticality
  • MFA configuration and coverage reports for critical systems, remote access and privileged access, including conditional or risk-based rules
SOC 2 CC6.3 Role-based access, least privilege and segregation of duties
Evidence to have on file (guidance, our wording)
  • the bank or treasury platform dual-authorisation setup and the payment approval workflow, showing a second approver on a different device above the threshold
  • the callback or out-of-band verification procedure for a change to payee bank details, with a dated example
SOC 2 CC3.3 Considering fraud risk (COSO principle 8)
Evidence to have on file (guidance, our wording)
  • Fraud risk assessment or fraud section of the enterprise risk assessment
  • Analysis of privileged access and data misuse scenarios
NIST CSF 2.0 PR.AA-05 Access permissions, entitlements, and authorizations are defined in a policy, managed, enforced, and reviewed, and incorporate the principles of least privilege and separation of duties
Evidence to have on file (guidance, our wording)
  • Access policy framework with role definitions
  • Privileged access management deployment evidence
Application question Yes [1 w Insurance In the last three (3) years, has the Applicant experienced in excess of $10,000 any Cyber Event, Loss or been the subject of any Claim made for a Wrongful Act that would fall within the scope of the Policy for which the Applicant is applying?
At-Bay held application question

This is a loss history question, not a control requirement. It reaches no held control.

No held control answers this line.

Application question Yes | n If yes, please provide details Is the Applicant aware of any fact, circumstance, situation, event or Wrongful Act which reasonably could give rise to a Cyber Event, Loss or a Claim being made against them that would fall within the scope of the Policy for which the Applicant is applying?
At-Bay held application question

Prior-knowledge question. This asks whether the applicant knows of any circumstance that could give rise to a claim. A wrong answer here is the classic route to a prior-knowledge exclusion or rescission, so it is the highest-consequence line on the form, not a line to leave unread. It reaches no control by itself: it is about what the applicant knows, not a control to hold.

No held control answers this line.

Application question Yes [x0 If yes, please provide details What are the desired limits?
At-Bay held application question

This is a financials question, not a control requirement. It reaches no held control.

No held control answers this line.

Controls not asked in this held document (272)

None of this held document's questions reach 272 of the 290 held controls (for example A.5.1, A.5.2, A.5.4, A.5.5, A.5.6, A.5.7, A.5.8, A.5.9). That is a fact about this held document, not about what the carrier underwrites on: a carrier's fuller forms and supplements ask controls this summary does not, multi-factor authentication, offline backups and patching among them. A control here is not asserted as required, and not asserted as not required.