Cyber Insurance Application Scannermap an application to controls

Chubb cyber policy application, held

The questions of the Chubb Cyber Enterprise Risk Management / Cyber and Privacy Insurance Short Form Application, held and mapped to the ISO 27001:2022 controls, the SOC 2 criteria and the NIST CSF 2.0 outcomes each one reaches. The source document (read 2026-10-11). The date shown is the date this copy was read, not a version the form itself states. This page quotes only the question each mapped row needs and states its source; it does not publish the carrier's form. A complete form would be held only under a stated policy for copyrighted forms. Chubb is a source document, never a customer.

This document's questions reach 32 of 290 held controls. Whether an applicant is offered cover is the carrier’s underwriting decision. 2 questions here are flagged knockout (a "no" is a common decline point) and 2 flagged warranty (an answer the carrier relies on, that can affect cover if wrong).

An answer about an existing state of affairs can be relied on by the carrier, but in Australia and the United Kingdom a statement by the insured is a representation, not a warranty (the Insurance Contracts Act and the Insurance Act), and the position varies by US state.

Application question What is the maximum total number of unique individual persons or organizations whose Protected Information could be compromised in a not-yet-discovered Cyber Incident, or will be stored or transmitted during the Policy Period on the Applicant's Computer System or any Shared Computer System combined that relate to the Applicant's business?
Chubb held application question

This is a scoping question, not a control requirement. It reaches no held control.

No held control answers this line.

Application question Does the Applicant have any products or services entering new markets or territories within the next year that are substantially different in scope or end use than current products or services, including as a result of recent or planned merger or acquisition?
Chubb held application question

This is a scoping question, not a control requirement. It reaches no held control.

No held control answers this line.

Application question Does the Applicant currently or will the Applicant potentially operate as a financial institution, cryptocurrency exchange, third-party claims administrator, accreditation service, surveillance, manufacturer of life safety products/software, media production company, payment processor, data aggregator/broker/warehouse, credit bureau, direct marketer, social media, peer-to-peer file sharing, adult content provider or gambling services provider?
Chubb held application question

This is a scoping question, not a control requirement. It reaches no held control.

No held control answers this line.

Application question does the Applicant derive more than 50% of its revenue from technology products and services (e.g. software, electronics, telecom?
Chubb held application question

This is a scoping question, not a control requirement. It reaches no held control.

No held control answers this line.

Application question Within the past three years, has the Applicant had any actual or potential professional, E&O, Technology, Media or Cyber Incidents or Claims?
Chubb held application question

This is a loss history question, not a control requirement. It reaches no held control.

No held control answers this line.

Application question Is the Applicant aware of any notices, facts, circumstances or situations that could reasonably be expected to give rise to a professional, E&O, Technology, Media or Cyber Incident or Claim?
Chubb held application question

Prior-knowledge question. This asks whether the applicant knows of any circumstance that could give rise to a claim. A wrong answer here is the classic route to a prior-knowledge exclusion or rescission, so it is the highest-consequence line on the form, not a line to leave unread. It reaches no control by itself: it is about what the applicant knows, not a control to hold.

No held control answers this line.

Application question Does the Applicant have third party software protecting its network (e.g. antivirus, encryption, firewalls, etc.?
Chubb held application question

Flagged knockout: the wording of this question makes a "no" a common point at which a cyber application is declined or referred.

Flagged warranty: where the carrier declares its answers to be the basis of the contract, this is an answer the carrier relies on and that can affect cover if it is wrong.

ISO 27001:2022 A.8.24 Use of cryptography
Evidence to have on file (guidance, our wording)
  • The topic-specific cryptography policy with approved algorithms, key lengths, protocols and usage by information classification
  • Evidence of encryption on endpoints, removable media and data in transit, aligned with the policy
ISO 27001:2022 A.8.7 Protection against malware
Evidence to have on file (guidance, our wording)
  • Anti-malware deployment and update status reports across endpoints, servers and gateways
  • Application allowlisting and malicious website blocking configurations
ISO 27001:2022 A.8.1 User end point devices
Evidence to have on file (guidance, our wording)
  • The topic-specific endpoint policy covering classification limits, registration, software restrictions, updates, network connection rules, encryption, malware protection, remote wipe, backup and port control
  • Device management (MDM or endpoint management) reports showing enrolment, encryption, patch level, firewall and anti-malware status
SOC 2 CC6.1 Logical access security over protected information assets
Evidence to have on file (guidance, our wording)
  • Asset inventory with classification for in-scope systems
  • Identity provider configuration showing MFA and password policy
SOC 2 CC6.8 Preventing and detecting unauthorised or malicious software
Evidence to have on file (guidance, our wording)
  • Endpoint protection coverage report across servers and workstations
  • Local administrator and software installation restrictions
NIST CSF 2.0 PR.DS-01 The confidentiality, integrity, and availability of data-at-rest are protected
Evidence to have on file (guidance, our wording)
  • Data at rest encryption inventory by store type
  • Storage configuration baselines with attestation
NIST CSF 2.0 PR.DS-02 The confidentiality, integrity, and availability of data-in-transit are protected
Evidence to have on file (guidance, our wording)
  • TLS configuration standards and scan results
  • VPN and zero trust network access policy
Application question Does the Applicant's Website, Computer System, or Telephone System request and capture any Payment Card information?
Chubb held application question

This is a scoping question, not a control requirement. It reaches no held control.

No held control answers this line.

Application question If Yes, do all of the Applicant's point-of-sale terminals accept chip-enabled cards?
Chubb held application question
ISO 27001:2022 A.8.24 Use of cryptography
Evidence to have on file (guidance, our wording)
  • The topic-specific cryptography policy with approved algorithms, key lengths, protocols and usage by information classification
  • Evidence of encryption on endpoints, removable media and data in transit, aligned with the policy
ISO 27001:2022 A.5.15 Access control
Evidence to have on file (guidance, our wording)
  • The topic-specific access control policy, approved and communicated, reflecting owner-defined business and security requirements
  • Access control rules or role models mapping entities (users, services, devices) to rights, consistent with classification
SOC 2 CC6.1 Logical access security over protected information assets
Evidence to have on file (guidance, our wording)
  • Asset inventory with classification for in-scope systems
  • Identity provider configuration showing MFA and password policy
SOC 2 CC6.7 Restricting and protecting information in transmission, movement and removal
Evidence to have on file (guidance, our wording)
  • TLS and encryption standards for data in transit
  • Removable media policy and technical enforcement
NIST CSF 2.0 PR.DS-01 The confidentiality, integrity, and availability of data-at-rest are protected
Evidence to have on file (guidance, our wording)
  • Data at rest encryption inventory by store type
  • Storage configuration baselines with attestation
Application question 2) Has the Applicant self-attested to be PCI-compliant in the past 12 months?
Chubb held application question

This is a loss history question, not a control requirement. It reaches no held control.

No held control answers this line.

Application question Does the Applicant's Website, Computer System, or Telephone System request and capture medical records or personal health information?
Chubb held application question

This is a scoping question, not a control requirement. It reaches no held control.

No held control answers this line.

Application question If Yes, is Applicant compliant with HIPAA and the HITECH ACT?
Chubb held application question

This is an attestation question, not a control requirement. It reaches no held control.

No held control answers this line.

Application question 2) Does the Applicant have operations or customers in California, or any responsibilities under the California Confidentiality of Medical Information Act?
Chubb held application question

This is a scoping question, not a control requirement. It reaches no held control.

No held control answers this line.

Application question Does the Applicant provide consumer products or services?
Chubb held application question

This is a scoping question, not a control requirement. It reaches no held control.

No held control answers this line.

Application question 1) If Yes, is the Applicant compliant with the Fair Credit Reporting Act?
Chubb held application question

This is an attestation question, not a control requirement. It reaches no held control.

No held control answers this line.

Application question Media (Only if applying for this coverage) Has legal counsel screened the Applicant's use of all trademarks and service marks, including Applicant's use of domain names and metatags, to ensure they do not infringe on the intellectual property of others?
Chubb held application question

This is a media liability question, not a control requirement. It reaches no held control.

No held control answers this line.

Application question Does the Applicant obtain written permission or releases from third party content providers and contributors, including freelancers, independent contractors, and other talent?
Chubb held application question

This is a media liability question, not a control requirement. It reaches no held control.

No held control answers this line.

Application question Does the Applicant involve legal counsel in reviewing content prior to publication or in evaluating whether it should be removed when notified that content is defamatory, infringing, in violation of a third party's privacy rights or otherwise improper?
Chubb held application question

This is a media liability question, not a control requirement. It reaches no held control.

No held control answers this line.

Application question Business Interruption (Only if applying for this coverage) Are system backup and recovery procedures implemented, documented and tested at least annually for all mission-critical systems?
Chubb held application question

Flagged knockout: the wording of this question makes a "no" a common point at which a cyber application is declined or referred.

Flagged warranty: where the carrier declares its answers to be the basis of the contract, this is an answer the carrier relies on and that can affect cover if it is wrong.

ISO 27001:2022 A.8.13 Information backup
Evidence to have on file (guidance, our wording)
  • The topic-specific backup policy and backup plans stating scope, extent, frequency and retention per system aligned with RPO
  • Backup job monitoring reports with evidence that failed jobs were investigated and rerun
ISO 27001:2022 A.8.14 Redundancy of information processing facilities
Evidence to have on file (guidance, our wording)
  • Documented availability requirements for business services and systems
  • Architecture diagrams showing redundancy such as dual providers, redundant networks, separate data centres, redundant power and load-balanced instances
SOC 2 A1.2 Environmental protection, backup and recovery infrastructure
Evidence to have on file (guidance, our wording)
  • Backup policy defining scope, frequency and retention
  • Backup job monitoring and failure remediation records
SOC 2 A1.3 Testing recovery plan procedures
Evidence to have on file (guidance, our wording)
  • Disaster recovery or continuity test plan and results in the period
  • Backup restore test records with verification of completeness
NIST CSF 2.0 PR.DS-11 Backups of data are created, protected, maintained, and tested
Evidence to have on file (guidance, our wording)
  • Backup policy with frequency and retention
  • Backup integrity test reports
Application question If the Applicant's customer is primarily dependent on the product or service provided by the Applicant, does the Applicant have a contingency plan in place to address this exposure?
Chubb held application question
ISO 27001:2022 A.5.29 Information security during disruption
Evidence to have on file (guidance, our wording)
  • Business continuity plans that contain information security requirements and the controls, systems and tools needed during disruption
  • A documented analysis of which security controls must be adapted during disruption and how
ISO 27001:2022 A.5.30 ICT readiness for business continuity
Evidence to have on file (guidance, our wording)
  • The business impact analysis with prioritized activities, supporting ICT services and their RTOs, and RPOs for required information
  • Selected ICT continuity strategies covering before, during and after disruption
ISO 27001:2022 A.8.14 Redundancy of information processing facilities
Evidence to have on file (guidance, our wording)
  • Documented availability requirements for business services and systems
  • Architecture diagrams showing redundancy such as dual providers, redundant networks, separate data centres, redundant power and load-balanced instances
SOC 2 CC9.1 Mitigating risks of business disruption
Evidence to have on file (guidance, our wording)
  • Business continuity and disaster recovery plans covering the in-scope service
  • Business impact analysis
SOC 2 A1.2 Environmental protection, backup and recovery infrastructure
Evidence to have on file (guidance, our wording)
  • Backup policy defining scope, frequency and retention
  • Backup job monitoring and failure remediation records
NIST CSF 2.0 PR.IR-03 Mechanisms are implemented to achieve resilience requirements in normal and adverse situations
Evidence to have on file (guidance, our wording)
  • Resilience architecture patterns for critical services
  • Failover and failback tested with evidence
NIST CSF 2.0 RC.RP-01 The recovery portion of the incident response plan is executed once initiated from the incident response process
Evidence to have on file (guidance, our wording)
  • Recovery plan with triggers and decision rights
  • Execution log of recovery activities
Application question Cyber Crime (Only if applying for this coverage) Does the Applicant accept funds transfer information from clients over the telephone, email, text message or similar method of communication?
Chubb held application question
ISO 27001:2022 A.5.3 Segregation of duties
Evidence to have on file (guidance, our wording)
  • the bank or treasury platform dual-authorisation setup and the payment approval workflow, showing a second approver on a different device above the threshold
  • the callback or out-of-band verification procedure for a change to payee bank details, with a dated example
ISO 27001:2022 A.6.3 Information security awareness, education and training
Evidence to have on file (guidance, our wording)
  • A documented awareness, education and training programme aligned with the policies and planned by role, including external personnel
  • Completion records for initial training of new starters and role changers and for periodic refreshers
ISO 27001:2022 A.8.5 Secure authentication
Evidence to have on file (guidance, our wording)
  • An authentication standard linking required authentication strength to information classification and system criticality
  • MFA configuration and coverage reports for critical systems, remote access and privileged access, including conditional or risk-based rules
SOC 2 CC6.3 Role-based access, least privilege and segregation of duties
Evidence to have on file (guidance, our wording)
  • the bank or treasury platform dual-authorisation setup and the payment approval workflow, showing a second approver on a different device above the threshold
  • the callback or out-of-band verification procedure for a change to payee bank details, with a dated example
SOC 2 CC3.3 Considering fraud risk (COSO principle 8)
Evidence to have on file (guidance, our wording)
  • Fraud risk assessment or fraud section of the enterprise risk assessment
  • Analysis of privileged access and data misuse scenarios
NIST CSF 2.0 PR.AA-05 Access permissions, entitlements, and authorizations are defined in a policy, managed, enforced, and reviewed, and incorporate the principles of least privilege and separation of duties
Evidence to have on file (guidance, our wording)
  • Access policy framework with role definitions
  • Privileged access management deployment evidence
Application question Does the Applicant authenticate instructions by calling the customer at a predetermined phone number or require receipt of a customer identity code?
Chubb held application question
ISO 27001:2022 A.5.3 Segregation of duties
Evidence to have on file (guidance, our wording)
  • the bank or treasury platform dual-authorisation setup and the payment approval workflow, showing a second approver on a different device above the threshold
  • the callback or out-of-band verification procedure for a change to payee bank details, with a dated example
ISO 27001:2022 A.6.3 Information security awareness, education and training
Evidence to have on file (guidance, our wording)
  • A documented awareness, education and training programme aligned with the policies and planned by role, including external personnel
  • Completion records for initial training of new starters and role changers and for periodic refreshers
ISO 27001:2022 A.8.5 Secure authentication
Evidence to have on file (guidance, our wording)
  • An authentication standard linking required authentication strength to information classification and system criticality
  • MFA configuration and coverage reports for critical systems, remote access and privileged access, including conditional or risk-based rules
SOC 2 CC6.3 Role-based access, least privilege and segregation of duties
Evidence to have on file (guidance, our wording)
  • the bank or treasury platform dual-authorisation setup and the payment approval workflow, showing a second approver on a different device above the threshold
  • the callback or out-of-band verification procedure for a change to payee bank details, with a dated example
SOC 2 CC3.3 Considering fraud risk (COSO principle 8)
Evidence to have on file (guidance, our wording)
  • Fraud risk assessment or fraud section of the enterprise risk assessment
  • Analysis of privileged access and data misuse scenarios
NIST CSF 2.0 PR.AA-05 Access permissions, entitlements, and authorizations are defined in a policy, managed, enforced, and reviewed, and incorporate the principles of least privilege and separation of duties
Evidence to have on file (guidance, our wording)
  • Access policy framework with role definitions
  • Privileged access management deployment evidence
Application question Is approval by more than one person required to initiate a wire transfer?
Chubb held application question
ISO 27001:2022 A.5.3 Segregation of duties
Evidence to have on file (guidance, our wording)
  • the bank or treasury platform dual-authorisation setup and the payment approval workflow, showing a second approver on a different device above the threshold
  • the callback or out-of-band verification procedure for a change to payee bank details, with a dated example
ISO 27001:2022 A.6.3 Information security awareness, education and training
Evidence to have on file (guidance, our wording)
  • A documented awareness, education and training programme aligned with the policies and planned by role, including external personnel
  • Completion records for initial training of new starters and role changers and for periodic refreshers
ISO 27001:2022 A.8.5 Secure authentication
Evidence to have on file (guidance, our wording)
  • An authentication standard linking required authentication strength to information classification and system criticality
  • MFA configuration and coverage reports for critical systems, remote access and privileged access, including conditional or risk-based rules
SOC 2 CC6.3 Role-based access, least privilege and segregation of duties
Evidence to have on file (guidance, our wording)
  • the bank or treasury platform dual-authorisation setup and the payment approval workflow, showing a second approver on a different device above the threshold
  • the callback or out-of-band verification procedure for a change to payee bank details, with a dated example
SOC 2 CC3.3 Considering fraud risk (COSO principle 8)
Evidence to have on file (guidance, our wording)
  • Fraud risk assessment or fraud section of the enterprise risk assessment
  • Analysis of privileged access and data misuse scenarios
NIST CSF 2.0 PR.AA-05 Access permissions, entitlements, and authorizations are defined in a policy, managed, enforced, and reviewed, and incorporate the principles of least privilege and separation of duties
Evidence to have on file (guidance, our wording)
  • Access policy framework with role definitions
  • Privileged access management deployment evidence
Application question Does the Applicant verify all vendor and supplier bank accounts by a direct call to the receiving bank, prior to accounts being established in the accounts payable system?
Chubb held application question
ISO 27001:2022 A.5.19 Information security in supplier relationships
Evidence to have on file (guidance, our wording)
  • The topic-specific supplier relationship policy and its communication record
  • A supplier inventory categorized by type and by the information, services and infrastructure each can access
ISO 27001:2022 A.5.20 Addressing information security within supplier agreements
Evidence to have on file (guidance, our wording)
  • Supplier agreements containing security clauses proportionate to the relationship, such as classification mapping, agreed controls, incident notification, subcontracting, right to audit and termination terms
  • A register of contracts, memoranda and information-sharing arrangements with outside parties showing what information each covers and when it was last reviewed
ISO 27001:2022 A.5.21 Managing information security in the information and communication technology (ICT) supply chain
Evidence to have on file (guidance, our wording)
  • Security requirements included in ICT acquisition specifications and contracts, including flow-down to sub-suppliers
  • Software component information such as SBOMs and descriptions of security functions and secure configuration obtained from product suppliers
SOC 2 CC9.2 Assessing and managing vendor and business partner risk
Evidence to have on file (guidance, our wording)
  • Vendor inventory with risk tiers and the review frequency set for each tier
  • Due diligence records, for example vendor SOC reports reviewed with complementary controls noted
SOC 2 P6.4 Privacy commitments from vendors and third parties
Evidence to have on file (guidance, our wording)
  • Data processing agreements with privacy clauses
  • Periodic assessments of vendors' privacy compliance
NIST CSF 2.0 GV.SC-01 A cybersecurity supply chain risk management program, strategy, objectives, policies, and processes are established and agreed to by organizational stakeholders
Evidence to have on file (guidance, our wording)
  • Third party risk management program charter
  • Supplier risk policy with tiering criteria
NIST CSF 2.0 GV.SC-05 Requirements to address cybersecurity risks in supply chains are established, prioritized, and integrated into contracts and other types of agreements with suppliers and other relevant third parties
Evidence to have on file (guidance, our wording)
  • Standard supplier security requirements catalog
  • Contract clause library with cyber obligations
Application question Does the Applicant currently purchase E&O insurance to address the failure of their product or service If Yes, what is the Retro Date?
Chubb held application question

This is an attestation question, not a control requirement. It reaches no held control.

No held control answers this line.

Application question Does the Applicant currently purchase Cyber or Privacy Liability insurance?
Chubb held application question

This is an attestation question, not a control requirement. It reaches no held control.

No held control answers this line.

Application question If Yes, what is the Retro Date?
Chubb held application question

This is an attestation question, not a control requirement. It reaches no held control.

No held control answers this line.

Application question Does the Applicant currently purchase Media Liability Insurance?
Chubb held application question

This is an attestation question, not a control requirement. It reaches no held control.

No held control answers this line.

Controls not asked in this held document (258)

None of this held document's questions reach 258 of the 290 held controls (for example A.5.1, A.5.2, A.5.4, A.5.5, A.5.6, A.5.7, A.5.8, A.5.9). That is a fact about this held document, not about what the carrier underwrites on: a carrier's fuller forms and supplements ask controls this summary does not, multi-factor authentication, offline backups and patching among them. A control here is not asserted as required, and not asserted as not required.