Cyber Insurance Application Scannermap an application to controls

CNA cyber policy application, held

The questions of the Information Security and Cyber Infrastructure Self-Assessment, held and mapped to the ISO 27001:2022 controls, the SOC 2 criteria and the NIST CSF 2.0 outcomes each one reaches. The source document, Information Security and Cyber Infrastructure Self-Assessment (read 2026-10-11). The date shown is the date this copy was read, not a version the form itself states. This page quotes only the question each mapped row needs and states its source; it does not publish the carrier's form. A complete form would be held only under a stated policy for copyrighted forms. CNA is a source document, never a customer.

This document's questions reach 68 of 290 held controls. Whether an applicant is offered cover is the carrier’s underwriting decision. 8 questions here are flagged knockout (a "no" is a common decline point) and 0 flagged warranty (an answer the carrier relies on, that can affect cover if wrong).

Application question Have you identified the level of Risk the Threats (Environmental, Business Resources, and Hostile Actors), Likelihood, and Impact of a data security incident create?
CNA held application question

No held control answers this line.

Application question Have you identified the paper, electronic, and other records, computing systems, and storage media including laptops, mobile phones, and portable devices that contain sensitive information?
CNA held application question
ISO 27001:2022 A.8.1 User end point devices
Evidence to have on file (guidance, our wording)
  • The topic-specific endpoint policy covering classification limits, registration, software restrictions, updates, network connection rules, encryption, malware protection, remote wipe, backup and port control
  • Device management (MDM or endpoint management) reports showing enrolment, encryption, patch level, firewall and anti-malware status
ISO 27001:2022 A.7.10 Storage media
Evidence to have on file (guidance, our wording)
  • The topic-specific removable media policy and evidence it was communicated to users
  • Endpoint configuration showing USB and SD ports disabled unless a business reason is approved, and monitoring of transfers to removable media
ISO 27001:2022 A.6.7 Remote working
Evidence to have on file (guidance, our wording)
  • The topic-specific remote working policy defining conditions, permitted work, information classifications allowed and systems accessible
  • Remote access configuration showing multi-factor authentication, secure channels or virtual desktops
SOC 2 CC6.1 Logical access security over protected information assets
Evidence to have on file (guidance, our wording)
  • Asset inventory with classification for in-scope systems
  • Identity provider configuration showing MFA and password policy
SOC 2 CC6.7 Restricting and protecting information in transmission, movement and removal
Evidence to have on file (guidance, our wording)
  • TLS and encryption standards for data in transit
  • Removable media policy and technical enforcement
NIST CSF 2.0 PR.AA-06 Physical access to assets is managed, monitored, and enforced commensurate with risk
Evidence to have on file (guidance, our wording)
  • Physical access control system inventory
  • Badge issuance and revocation records
NIST CSF 2.0 PR.DS-01 The confidentiality, integrity, and availability of data-at-rest are protected
Evidence to have on file (guidance, our wording)
  • Data at rest encryption inventory by store type
  • Storage configuration baselines with attestation
Application question Do you have a policy in place not to leave your laptops, phones or other devices unattended in public, even locked in a car?
CNA held application question
ISO 27001:2022 A.7.1 Physical security perimeters
Evidence to have on file (guidance, our wording)
  • Site plans showing defined security perimeters and their strength relative to the assets inside
  • Physical security surveys or assessments of walls, roofs, floors, doors, windows and vents
ISO 27001:2022 A.7.2 Physical entry
Evidence to have on file (guidance, our wording)
  • Physical access rights records with provisioning, periodic review and revocation evidence
  • Electronic access control logs or physical logbooks, protected and monitored
ISO 27001:2022 A.7.3 Securing offices, rooms and facilities
Evidence to have on file (guidance, our wording)
  • Facility security design documentation showing critical facilities sited away from public access
  • Photographs or survey records confirming the absence of signage revealing processing facilities
SOC 2 CC6.4 Restricting physical access to facilities and assets
Evidence to have on file (guidance, our wording)
  • Badge access provisioning and removal records
  • Periodic physical access review for sensitive areas
SOC 2 CC6.5 Protecting data on assets until disposal
Evidence to have on file (guidance, our wording)
  • Media sanitisation and disposal procedure
  • Certificates of destruction or wipe logs for disposed devices
NIST CSF 2.0 PR.AA-06 Physical access to assets is managed, monitored, and enforced commensurate with risk
Evidence to have on file (guidance, our wording)
  • Physical access control system inventory
  • Badge issuance and revocation records
NIST CSF 2.0 PR.IR-02 The organization's technology assets are protected from environmental threats
Evidence to have on file (guidance, our wording)
  • Environmental controls inventory (HVAC, power, fire)
  • Site risk assessments with mitigation status
Application question Do you conduct full, nationwide, criminal background check, sexual offender check, and if possible a credit check on all prospective employees?
CNA held application question
ISO 27001:2022 A.6.1 Screening
Evidence to have on file (guidance, our wording)
  • A screening procedure defining criteria, depth by role and classification, who performs checks, and when and why they are done
  • Screening records for a sample of new joiners showing references, CV verification, qualification confirmation and identity checks
SOC 2 CC1.4 Attracting, developing and retaining competent people (COSO principle 4)
Evidence to have on file (guidance, our wording)
  • Background check policy and completed checks for a sample of new hires and contractors
  • Role competency requirements and performance review records
NIST CSF 2.0 GV.RR-04 Cybersecurity is included in human resources practices
Evidence to have on file (guidance, our wording)
  • HR policies covering hiring, transfer, and termination security
  • Background screening standards by role sensitivity
Application question Do you set up a separate account for each user (including any contractors needing access?
CNA held application question
ISO 27001:2022 A.5.15 Access control
Evidence to have on file (guidance, our wording)
  • The topic-specific access control policy, approved and communicated, reflecting owner-defined business and security requirements
  • Access control rules or role models mapping entities (users, services, devices) to rights, consistent with classification
ISO 27001:2022 A.5.16 Identity management
Evidence to have on file (guidance, our wording)
  • Identity management procedure covering creation, verification, activation, change, disablement and removal
  • Evidence that identities are verified against trusted documents before issue
ISO 27001:2022 A.5.18 Access rights
Evidence to have on file (guidance, our wording)
  • Access request records showing owner authorization, and management approval where required, before rights were activated
  • A central record of access rights per user identifier across logical and physical access
SOC 2 CC6.1 Logical access security over protected information assets
Evidence to have on file (guidance, our wording)
  • Asset inventory with classification for in-scope systems
  • Identity provider configuration showing MFA and password policy
SOC 2 CC6.2 Registering and authorising users before issuing credentials
Evidence to have on file (guidance, our wording)
  • Access request tickets with owner approval for a sample of new users, service accounts and API credentials
  • Termination records reconciled to account disablement dates
NIST CSF 2.0 PR.AA-01 Identities and credentials for authorized users, services, and hardware are managed by the organization
Evidence to have on file (guidance, our wording)
  • Identity management platform configuration baseline
  • Joiner mover leaver workflow with timing SLAs
NIST CSF 2.0 PR.AA-05 Access permissions, entitlements, and authorizations are defined in a policy, managed, enforced, and reviewed, and incorporate the principles of least privilege and separation of duties
Evidence to have on file (guidance, our wording)
  • Access policy framework with role definitions
  • Privileged access management deployment evidence
Application question Do you enforce a company policy governing security, privacy and acceptable use of company property that must be followed by anyone who accesses your network or sensitive information in your care?
CNA held application question
ISO 27001:2022 A.5.1 Policies for information security
Evidence to have on file (guidance, our wording)
  • The top-level information security policy with top management approval, covering the definition, objectives or objective-setting framework, principles, commitments to requirements and continual improvement, role assignments and the exceptions procedure
  • The register of topic-specific policies with an owner, approving manager and version for each
ISO 27001:2022 A.5.2 Information security roles and responsibilities
Evidence to have on file (guidance, our wording)
  • A documented roles and responsibilities matrix covering asset protection, specific security processes, risk management and residual risk acceptance, and user duties
  • Named risk owners with evidence that they accepted residual risks
ISO 27001:2022 A.5.4 Management responsibilities
Evidence to have on file (guidance, our wording)
  • Evidence that security briefings on roles and responsibilities occur before access is granted, such as onboarding checklists tied to access provisioning
  • Role-specific guidance documents setting out security expectations
SOC 2 CC1.3 Structures, reporting lines, authorities and responsibilities (COSO principle 3)
Evidence to have on file (guidance, our wording)
  • Current organisation chart including security, IT operations, compliance and privacy functions
  • Job descriptions or RACI naming security and privacy responsibilities
SOC 2 CC5.3 Deploying controls through policies and procedures (COSO principle 12)
Evidence to have on file (guidance, our wording)
  • Approved information security policy set with owners and review dates
  • Evidence of annual policy review and approval
NIST CSF 2.0 GV.PO-01 Policy for managing cybersecurity risks is established based on organizational context, cybersecurity strategy, and priorities and is communicated and enforced
Evidence to have on file (guidance, our wording)
  • Cybersecurity risk management policy approved by leadership
  • Policy linkage matrix to standards and procedures
NIST CSF 2.0 GV.RR-01 Organizational leadership is responsible and accountable for cybersecurity risk and fosters a culture that is risk-aware, ethical, and continually improving
Evidence to have on file (guidance, our wording)
  • Board cyber accountability charter
  • Executive cyber scorecard with named owners
Application question Do you enforce a strong/complex password policy of at least 8-20 characters?
CNA held application question
ISO 27001:2022 A.5.17 Authentication information
Evidence to have on file (guidance, our wording)
  • Credential issuance procedure requiring identity verification before new, replacement or temporary credentials are provided
  • Evidence that initial credentials are unique, delivered over protected channels and changed at first use
ISO 27001:2022 A.8.5 Secure authentication
Evidence to have on file (guidance, our wording)
  • An authentication standard linking required authentication strength to information classification and system criticality
  • MFA configuration and coverage reports for critical systems, remote access and privileged access, including conditional or risk-based rules
SOC 2 CC6.1 Logical access security over protected information assets
Evidence to have on file (guidance, our wording)
  • Asset inventory with classification for in-scope systems
  • Identity provider configuration showing MFA and password policy
NIST CSF 2.0 PR.AA-01 Identities and credentials for authorized users, services, and hardware are managed by the organization
Evidence to have on file (guidance, our wording)
  • Identity management platform configuration baseline
  • Joiner mover leaver workflow with timing SLAs
Application question Do you physically and electronically limit access to sensitive information on a need –to-know basis and revoke access privileges upon a reduction in an individual's need to know?
CNA held application question

Flagged knockout: the wording of this question makes a "no" a common point at which a cyber application is declined or referred.

ISO 27001:2022 A.8.2 Privileged access rights
Evidence to have on file (guidance, our wording)
  • An inventory of privileged accounts per system (operating systems, databases, applications, cloud consoles) mapped to named individuals
  • Authorization records for each privileged grant with approver, justification and expiry
ISO 27001:2022 A.8.3 Information access restriction
Evidence to have on file (guidance, our wording)
  • System, application and cloud storage configurations restricting access by identity or group, with granular permissions per action
  • Evidence that anonymous or public access is limited to locations holding no sensitive information, for example storage bucket access reviews
ISO 27001:2022 A.5.15 Access control
Evidence to have on file (guidance, our wording)
  • The topic-specific access control policy, approved and communicated, reflecting owner-defined business and security requirements
  • Access control rules or role models mapping entities (users, services, devices) to rights, consistent with classification
SOC 2 CC6.3 Role-based access, least privilege and segregation of duties
Evidence to have on file (guidance, our wording)
  • the bank or treasury platform dual-authorisation setup and the payment approval workflow, showing a second approver on a different device above the threshold
  • the callback or out-of-band verification procedure for a change to payee bank details, with a dated example
SOC 2 CC6.1 Logical access security over protected information assets
Evidence to have on file (guidance, our wording)
  • Asset inventory with classification for in-scope systems
  • Identity provider configuration showing MFA and password policy
NIST CSF 2.0 PR.AA-05 Access permissions, entitlements, and authorizations are defined in a policy, managed, enforced, and reviewed, and incorporate the principles of least privilege and separation of duties
Evidence to have on file (guidance, our wording)
  • Access policy framework with role definitions
  • Privileged access management deployment evidence
NIST CSF 2.0 PR.AA-01 Identities and credentials for authorized users, services, and hardware are managed by the organization
Evidence to have on file (guidance, our wording)
  • Identity management platform configuration baseline
  • Joiner mover leaver workflow with timing SLAs
Application question Do you enforce a "clean desk" and "clear screen" policy in which sensitive information must not be accessible or visible when left unattended?
CNA held application question
ISO 27001:2022 A.7.1 Physical security perimeters
Evidence to have on file (guidance, our wording)
  • Site plans showing defined security perimeters and their strength relative to the assets inside
  • Physical security surveys or assessments of walls, roofs, floors, doors, windows and vents
ISO 27001:2022 A.7.2 Physical entry
Evidence to have on file (guidance, our wording)
  • Physical access rights records with provisioning, periodic review and revocation evidence
  • Electronic access control logs or physical logbooks, protected and monitored
ISO 27001:2022 A.7.3 Securing offices, rooms and facilities
Evidence to have on file (guidance, our wording)
  • Facility security design documentation showing critical facilities sited away from public access
  • Photographs or survey records confirming the absence of signage revealing processing facilities
SOC 2 CC6.4 Restricting physical access to facilities and assets
Evidence to have on file (guidance, our wording)
  • Badge access provisioning and removal records
  • Periodic physical access review for sensitive areas
SOC 2 CC6.5 Protecting data on assets until disposal
Evidence to have on file (guidance, our wording)
  • Media sanitisation and disposal procedure
  • Certificates of destruction or wipe logs for disposed devices
NIST CSF 2.0 PR.AA-06 Physical access to assets is managed, monitored, and enforced commensurate with risk
Evidence to have on file (guidance, our wording)
  • Physical access control system inventory
  • Badge issuance and revocation records
NIST CSF 2.0 PR.IR-02 The organization's technology assets are protected from environmental threats
Evidence to have on file (guidance, our wording)
  • Environmental controls inventory (HVAC, power, fire)
  • Site risk assessments with mitigation status
Application question Have you installed electrical surge protectors and UPS (uninterruptible power supply?
CNA held application question
ISO 27001:2022 A.7.1 Physical security perimeters
Evidence to have on file (guidance, our wording)
  • Site plans showing defined security perimeters and their strength relative to the assets inside
  • Physical security surveys or assessments of walls, roofs, floors, doors, windows and vents
ISO 27001:2022 A.7.2 Physical entry
Evidence to have on file (guidance, our wording)
  • Physical access rights records with provisioning, periodic review and revocation evidence
  • Electronic access control logs or physical logbooks, protected and monitored
ISO 27001:2022 A.7.3 Securing offices, rooms and facilities
Evidence to have on file (guidance, our wording)
  • Facility security design documentation showing critical facilities sited away from public access
  • Photographs or survey records confirming the absence of signage revealing processing facilities
SOC 2 CC6.4 Restricting physical access to facilities and assets
Evidence to have on file (guidance, our wording)
  • Badge access provisioning and removal records
  • Periodic physical access review for sensitive areas
SOC 2 CC6.5 Protecting data on assets until disposal
Evidence to have on file (guidance, our wording)
  • Media sanitisation and disposal procedure
  • Certificates of destruction or wipe logs for disposed devices
NIST CSF 2.0 PR.AA-06 Physical access to assets is managed, monitored, and enforced commensurate with risk
Evidence to have on file (guidance, our wording)
  • Physical access control system inventory
  • Badge issuance and revocation records
NIST CSF 2.0 PR.IR-02 The organization's technology assets are protected from environmental threats
Evidence to have on file (guidance, our wording)
  • Environmental controls inventory (HVAC, power, fire)
  • Site risk assessments with mitigation status
Application question Do you check for security patches to your systems at least weekly and implement them within 30 days?
CNA held application question
ISO 27001:2022 A.8.8 Management of technical vulnerabilities
Evidence to have on file (guidance, our wording)
  • A software asset inventory with vendor, product, version, deployment location and responsible owner
  • Defined vulnerability management roles and a list of monitored vulnerability information sources
ISO 27001:2022 A.8.19 Installation of software on operational systems
Evidence to have on file (guidance, our wording)
  • Procedures for installing and updating operational software, including authorization, testing and rollback planning
  • Change and deployment records showing management authorization, successful testing and the administrator who performed the installation
ISO 27001:2022 A.8.29 Security testing in development and acceptance
Evidence to have on file (guidance, our wording)
  • Security test plans with schedules, inputs, expected outputs, evaluation criteria and decisions, scaled to the system's importance and change impact
  • Security test results covering authentication, access restriction, cryptography, secure coding and configuration
SOC 2 CC7.1 Detecting configuration changes and new vulnerabilities
Evidence to have on file (guidance, our wording)
  • Hardening standards or benchmarks for in-scope platforms
  • Configuration compliance scan results
NIST CSF 2.0 ID.RA-01 Vulnerabilities in assets are identified, validated, and recorded
Evidence to have on file (guidance, our wording)
  • Vulnerability scanning coverage report
  • Vulnerability triage workflow with severity SLAs
NIST CSF 2.0 PR.PS-02 Software is maintained, replaced, and removed commensurate with risk
Evidence to have on file (guidance, our wording)
  • Software lifecycle policy with end of support tracking
  • Patch management cadence and exception register
Application question Have you installed firewalls between your internal network and the Internet?
CNA held application question
ISO 27001:2022 A.8.20 Networks security
Evidence to have on file (guidance, our wording)
  • Current network diagrams and device configuration backups for routers, switches, firewalls and wireless controllers
  • Defined responsibilities and procedures for network device management, separated from system operations where appropriate
ISO 27001:2022 A.8.21 Security of network services
Evidence to have on file (guidance, our wording)
  • Service agreements with internal and external network providers specifying security features, service levels and requirements
  • Right-to-audit clauses and third-party attestations from network and managed security service providers, with records of review
ISO 27001:2022 A.8.22 Segregation of networks
Evidence to have on file (guidance, our wording)
  • Network segmentation design defining domains by trust, criticality, sensitivity or organizational unit, with the assessment that justified it
  • Firewall or filtering router rules controlling traffic between domains, with rule review records
SOC 2 CC6.6 Protection against threats from outside the system boundary
Evidence to have on file (guidance, our wording)
  • Firewall and security group rule sets with review evidence
  • MFA enforced on VPN, remote and administrative access
NIST CSF 2.0 PR.IR-01 Networks and environments are protected from unauthorized logical access and usage
Evidence to have on file (guidance, our wording)
  • Network segmentation design with zones and trust levels
  • Firewall and access control list governance
NIST CSF 2.0 DE.CM-01 Networks and network services are monitored to find potentially adverse events
Evidence to have on file (guidance, our wording)
  • Network flow telemetry coverage map by segment
  • IDS or NDR sensor inventory with placement diagram
Application question At least once a year, do you provide security awareness training for everyone who accesses your network or sensitive information in your care?
CNA held application question
ISO 27001:2022 A.6.3 Information security awareness, education and training
Evidence to have on file (guidance, our wording)
  • A documented awareness, education and training programme aligned with the policies and planned by role, including external personnel
  • Completion records for initial training of new starters and role changers and for periodic refreshers
SOC 2 CC1.4 Attracting, developing and retaining competent people (COSO principle 4)
Evidence to have on file (guidance, our wording)
  • Background check policy and completed checks for a sample of new hires and contractors
  • Role competency requirements and performance review records
SOC 2 CC2.2 Internal communication of objectives and control responsibilities (COSO principle 14)
Evidence to have on file (guidance, our wording)
  • Security awareness training content and completion records
  • Published information security policies accessible to staff with change notices
NIST CSF 2.0 PR.AT-01 Personnel are provided with awareness and training so that they possess the knowledge and skills to perform general tasks with cybersecurity risks in mind
Evidence to have on file (guidance, our wording)
  • Security awareness program curriculum
  • Completion records by population
Application question Information Security and Cyber Infrastructure Self-Assessment 14 On your wireless networks; do you use security at least as strong as WPA2 authentication and encryption, and do you require two factor authentication (access token and password/account logon) before allowing wireless connections to your network?
CNA held application question

Flagged knockout: the wording of this question makes a "no" a common point at which a cyber application is declined or referred.

ISO 27001:2022 A.8.5 Secure authentication
Evidence to have on file (guidance, our wording)
  • An authentication standard linking required authentication strength to information classification and system criticality
  • MFA configuration and coverage reports for critical systems, remote access and privileged access, including conditional or risk-based rules
ISO 27001:2022 A.5.17 Authentication information
Evidence to have on file (guidance, our wording)
  • Credential issuance procedure requiring identity verification before new, replacement or temporary credentials are provided
  • Evidence that initial credentials are unique, delivered over protected channels and changed at first use
ISO 27001:2022 A.8.24 Use of cryptography
Evidence to have on file (guidance, our wording)
  • The topic-specific cryptography policy with approved algorithms, key lengths, protocols and usage by information classification
  • Evidence of encryption on endpoints, removable media and data in transit, aligned with the policy
SOC 2 CC6.1 Logical access security over protected information assets
Evidence to have on file (guidance, our wording)
  • Asset inventory with classification for in-scope systems
  • Identity provider configuration showing MFA and password policy
NIST CSF 2.0 PR.AA-03 Users, services, and hardware are authenticated
Evidence to have on file (guidance, our wording)
  • Multi factor authentication coverage report
  • Phishing resistant authentication rollout plan
NIST CSF 2.0 PR.AA-01 Identities and credentials for authorized users, services, and hardware are managed by the organization
Evidence to have on file (guidance, our wording)
  • Identity management platform configuration baseline
  • Joiner mover leaver workflow with timing SLAs
Application question if you do not use wireless networks.) 15 Do you require multi-factor authorization when your network is accessed remotely and/or when cloud resources are utilized?
CNA held application question

Flagged knockout: the wording of this question makes a "no" a common point at which a cyber application is declined or referred.

ISO 27001:2022 A.8.5 Secure authentication
Evidence to have on file (guidance, our wording)
  • An authentication standard linking required authentication strength to information classification and system criticality
  • MFA configuration and coverage reports for critical systems, remote access and privileged access, including conditional or risk-based rules
ISO 27001:2022 A.5.17 Authentication information
Evidence to have on file (guidance, our wording)
  • Credential issuance procedure requiring identity verification before new, replacement or temporary credentials are provided
  • Evidence that initial credentials are unique, delivered over protected channels and changed at first use
SOC 2 CC6.1 Logical access security over protected information assets
Evidence to have on file (guidance, our wording)
  • Asset inventory with classification for in-scope systems
  • Identity provider configuration showing MFA and password policy
NIST CSF 2.0 PR.AA-03 Users, services, and hardware are authenticated
Evidence to have on file (guidance, our wording)
  • Multi factor authentication coverage report
  • Phishing resistant authentication rollout plan
Application question Do you replace factory default settings to ensure your information security systems are securely configured?
CNA held application question
ISO 27001:2022 A.8.9 Configuration management
Evidence to have on file (guidance, our wording)
  • Approved secure configuration templates or baselines for each platform, derived from vendor or independent guidance, with review dates
  • Configuration records or a CMDB showing owner, last change date, template version and relationships between assets
SOC 2 CC8.1 Managing changes to procedures, software, data and infrastructure
Evidence to have on file (guidance, our wording)
  • Change management policy covering normal, standard and emergency changes
  • Sample of change tickets with approval, testing evidence and deployer different from author
NIST CSF 2.0 PR.PS-01 Configuration management practices are established and applied
Evidence to have on file (guidance, our wording)
  • Configuration management standards by platform
  • Hardening baselines and compliance reports
Application question Do you encrypt all sensitive records and files that are held at rest and/or transmitted across public networks, and that are to be transmitted wirelessly?
CNA held application question
ISO 27001:2022 A.8.24 Use of cryptography
Evidence to have on file (guidance, our wording)
  • The topic-specific cryptography policy with approved algorithms, key lengths, protocols and usage by information classification
  • Evidence of encryption on endpoints, removable media and data in transit, aligned with the policy
ISO 27001:2022 A.7.10 Storage media
Evidence to have on file (guidance, our wording)
  • The topic-specific removable media policy and evidence it was communicated to users
  • Endpoint configuration showing USB and SD ports disabled unless a business reason is approved, and monitoring of transfers to removable media
ISO 27001:2022 A.8.1 User end point devices
Evidence to have on file (guidance, our wording)
  • The topic-specific endpoint policy covering classification limits, registration, software restrictions, updates, network connection rules, encryption, malware protection, remote wipe, backup and port control
  • Device management (MDM or endpoint management) reports showing enrolment, encryption, patch level, firewall and anti-malware status
SOC 2 CC6.1 Logical access security over protected information assets
Evidence to have on file (guidance, our wording)
  • Asset inventory with classification for in-scope systems
  • Identity provider configuration showing MFA and password policy
SOC 2 CC6.7 Restricting and protecting information in transmission, movement and removal
Evidence to have on file (guidance, our wording)
  • TLS and encryption standards for data in transit
  • Removable media policy and technical enforcement
NIST CSF 2.0 PR.DS-01 The confidentiality, integrity, and availability of data-at-rest are protected
Evidence to have on file (guidance, our wording)
  • Data at rest encryption inventory by store type
  • Storage configuration baselines with attestation
NIST CSF 2.0 PR.DS-02 The confidentiality, integrity, and availability of data-in-transit are protected
Evidence to have on file (guidance, our wording)
  • TLS configuration standards and scan results
  • VPN and zero trust network access policy
Application question At time of hire and at least once a year, do you provide security awareness training for everyone who accesses your network or sensitive information in your care?
CNA held application question
ISO 27001:2022 A.6.3 Information security awareness, education and training
Evidence to have on file (guidance, our wording)
  • A documented awareness, education and training programme aligned with the policies and planned by role, including external personnel
  • Completion records for initial training of new starters and role changers and for periodic refreshers
SOC 2 CC1.4 Attracting, developing and retaining competent people (COSO principle 4)
Evidence to have on file (guidance, our wording)
  • Background check policy and completed checks for a sample of new hires and contractors
  • Role competency requirements and performance review records
SOC 2 CC2.2 Internal communication of objectives and control responsibilities (COSO principle 14)
Evidence to have on file (guidance, our wording)
  • Security awareness training content and completion records
  • Published information security policies accessible to staff with change notices
NIST CSF 2.0 PR.AT-01 Personnel are provided with awareness and training so that they possess the knowledge and skills to perform general tasks with cybersecurity risks in mind
Evidence to have on file (guidance, our wording)
  • Security awareness program curriculum
  • Completion records by population
Application question Do you have up-to-date versions of system security agent software (including malware, antivirus, and firewall protection) and reasonably up-to-date (within 30 days) security patches and virus definitions?
CNA held application question

Flagged knockout: the wording of this question makes a "no" a common point at which a cyber application is declined or referred.

ISO 27001:2022 A.8.7 Protection against malware
Evidence to have on file (guidance, our wording)
  • Anti-malware deployment and update status reports across endpoints, servers and gateways
  • Application allowlisting and malicious website blocking configurations
ISO 27001:2022 A.8.1 User end point devices
Evidence to have on file (guidance, our wording)
  • The topic-specific endpoint policy covering classification limits, registration, software restrictions, updates, network connection rules, encryption, malware protection, remote wipe, backup and port control
  • Device management (MDM or endpoint management) reports showing enrolment, encryption, patch level, firewall and anti-malware status
ISO 27001:2022 A.8.8 Management of technical vulnerabilities
Evidence to have on file (guidance, our wording)
  • A software asset inventory with vendor, product, version, deployment location and responsible owner
  • Defined vulnerability management roles and a list of monitored vulnerability information sources
SOC 2 CC6.8 Preventing and detecting unauthorised or malicious software
Evidence to have on file (guidance, our wording)
  • Endpoint protection coverage report across servers and workstations
  • Local administrator and software installation restrictions
SOC 2 CC7.1 Detecting configuration changes and new vulnerabilities
Evidence to have on file (guidance, our wording)
  • Hardening standards or benchmarks for in-scope platforms
  • Configuration compliance scan results
NIST CSF 2.0 PR.PS-05 Installation and execution of unauthorized software are prevented
Evidence to have on file (guidance, our wording)
  • Application allowlist policy and tooling configuration
  • Endpoint protection deployment reports
NIST CSF 2.0 DE.CM-09 Computing hardware and software, runtime environments, and their data are monitored to find potentially adverse events
Evidence to have on file (guidance, our wording)
  • EDR coverage report by asset class
  • File integrity monitoring baseline and drift alerts
Application question Do you have monitoring in place to alert you to the occurrence of unauthorized use of or access to sensitive information?
CNA held application question
ISO 27001:2022 A.8.15 Logging
Evidence to have on file (guidance, our wording)
  • The topic-specific logging policy defining purposes, events to be logged, fields captured, retention and protection
ISO 27001:2022 A.8.16 Monitoring activities
Evidence to have on file (guidance, our wording)
  • A documented monitoring scope covering network traffic, system access, configuration files, security tool logs, code integrity and resource use, with retention periods
  • Baselines of normal behaviour for systems and user groups, and the detection rules built on them
ISO 27001:2022 A.5.15 Access control
Evidence to have on file (guidance, our wording)
  • The topic-specific access control policy, approved and communicated, reflecting owner-defined business and security requirements
  • Access control rules or role models mapping entities (users, services, devices) to rights, consistent with classification
SOC 2 CC7.1 Detecting configuration changes and new vulnerabilities
Evidence to have on file (guidance, our wording)
  • Hardening standards or benchmarks for in-scope platforms
  • Configuration compliance scan results
SOC 2 CC7.2 Monitoring system components for anomalies
Evidence to have on file (guidance, our wording)
  • Alert rules and sample of triaged alerts
  • Threat intelligence sources in use
NIST CSF 2.0 DE.CM-01 Networks and network services are monitored to find potentially adverse events
Evidence to have on file (guidance, our wording)
  • Network flow telemetry coverage map by segment
  • IDS or NDR sensor inventory with placement diagram
NIST CSF 2.0 PR.PS-04 Log records are generated and made available for continuous monitoring
Evidence to have on file (guidance, our wording)
  • Logging policy by data class and system tier
  • Centralized log collection architecture
Application question Network attacks and incidents (including: malicious code, hacking, spyware?
CNA held application question

This is a loss history question, not a control requirement. It reaches no held control.

No held control answers this line.

Application question Breaches of privacy/confidentiality?
CNA held application question

This is a loss history question, not a control requirement. It reaches no held control.

No held control answers this line.

Application question Denial of service attacks?
CNA held application question

This is a loss history question, not a control requirement. It reaches no held control.

No held control answers this line.

Application question Do you back-up your network data and configuration files daily and store back-up files in a secure location, and rehearse your procedure for restoring from back-ups at least yearly?
CNA held application question

Flagged knockout: the wording of this question makes a "no" a common point at which a cyber application is declined or referred.

ISO 27001:2022 A.8.13 Information backup
Evidence to have on file (guidance, our wording)
  • The topic-specific backup policy and backup plans stating scope, extent, frequency and retention per system aligned with RPO
  • Backup job monitoring reports with evidence that failed jobs were investigated and rerun
ISO 27001:2022 A.8.14 Redundancy of information processing facilities
Evidence to have on file (guidance, our wording)
  • Documented availability requirements for business services and systems
  • Architecture diagrams showing redundancy such as dual providers, redundant networks, separate data centres, redundant power and load-balanced instances
ISO 27001:2022 A.8.9 Configuration management
Evidence to have on file (guidance, our wording)
  • Approved secure configuration templates or baselines for each platform, derived from vendor or independent guidance, with review dates
  • Configuration records or a CMDB showing owner, last change date, template version and relationships between assets
SOC 2 A1.2 Environmental protection, backup and recovery infrastructure
Evidence to have on file (guidance, our wording)
  • Backup policy defining scope, frequency and retention
  • Backup job monitoring and failure remediation records
SOC 2 A1.3 Testing recovery plan procedures
Evidence to have on file (guidance, our wording)
  • Disaster recovery or continuity test plan and results in the period
  • Backup restore test records with verification of completeness
NIST CSF 2.0 PR.DS-11 Backups of data are created, protected, maintained, and tested
Evidence to have on file (guidance, our wording)
  • Backup policy with frequency and retention
  • Backup integrity test reports
NIST CSF 2.0 PR.PS-01 Configuration management practices are established and applied
Evidence to have on file (guidance, our wording)
  • Configuration management standards by platform
  • Hardening baselines and compliance reports
Application question Do you conduct full, nationwide, criminal background checks, sexual offender checks, and if possible, credit checks on all prospective employees?
CNA held application question
ISO 27001:2022 A.6.1 Screening
Evidence to have on file (guidance, our wording)
  • A screening procedure defining criteria, depth by role and classification, who performs checks, and when and why they are done
  • Screening records for a sample of new joiners showing references, CV verification, qualification confirmation and identity checks
SOC 2 CC1.4 Attracting, developing and retaining competent people (COSO principle 4)
Evidence to have on file (guidance, our wording)
  • Background check policy and completed checks for a sample of new hires and contractors
  • Role competency requirements and performance review records
NIST CSF 2.0 GV.RR-04 Cybersecurity is included in human resources practices
Evidence to have on file (guidance, our wording)
  • HR policies covering hiring, transfer, and termination security
  • Background screening standards by role sensitivity
Application question Do you physically and electronically limit access to sensitive information on a need-to-know basis and revoke access privileges upon a reduction in an individual's need to know?
CNA held application question

Flagged knockout: the wording of this question makes a "no" a common point at which a cyber application is declined or referred.

ISO 27001:2022 A.8.2 Privileged access rights
Evidence to have on file (guidance, our wording)
  • An inventory of privileged accounts per system (operating systems, databases, applications, cloud consoles) mapped to named individuals
  • Authorization records for each privileged grant with approver, justification and expiry
ISO 27001:2022 A.8.3 Information access restriction
Evidence to have on file (guidance, our wording)
  • System, application and cloud storage configurations restricting access by identity or group, with granular permissions per action
  • Evidence that anonymous or public access is limited to locations holding no sensitive information, for example storage bucket access reviews
ISO 27001:2022 A.5.15 Access control
Evidence to have on file (guidance, our wording)
  • The topic-specific access control policy, approved and communicated, reflecting owner-defined business and security requirements
  • Access control rules or role models mapping entities (users, services, devices) to rights, consistent with classification
SOC 2 CC6.3 Role-based access, least privilege and segregation of duties
Evidence to have on file (guidance, our wording)
  • the bank or treasury platform dual-authorisation setup and the payment approval workflow, showing a second approver on a different device above the threshold
  • the callback or out-of-band verification procedure for a change to payee bank details, with a dated example
SOC 2 CC6.1 Logical access security over protected information assets
Evidence to have on file (guidance, our wording)
  • Asset inventory with classification for in-scope systems
  • Identity provider configuration showing MFA and password policy
NIST CSF 2.0 PR.AA-05 Access permissions, entitlements, and authorizations are defined in a policy, managed, enforced, and reviewed, and incorporate the principles of least privilege and separation of duties
Evidence to have on file (guidance, our wording)
  • Access policy framework with role definitions
  • Privileged access management deployment evidence
NIST CSF 2.0 PR.AA-01 Identities and credentials for authorized users, services, and hardware are managed by the organization
Evidence to have on file (guidance, our wording)
  • Identity management platform configuration baseline
  • Joiner mover leaver workflow with timing SLAs
Application question Have you installed electrical surge protectors and uninterruptible power supply (UPS?
CNA held application question
ISO 27001:2022 A.7.1 Physical security perimeters
Evidence to have on file (guidance, our wording)
  • Site plans showing defined security perimeters and their strength relative to the assets inside
  • Physical security surveys or assessments of walls, roofs, floors, doors, windows and vents
ISO 27001:2022 A.7.2 Physical entry
Evidence to have on file (guidance, our wording)
  • Physical access rights records with provisioning, periodic review and revocation evidence
  • Electronic access control logs or physical logbooks, protected and monitored
ISO 27001:2022 A.7.3 Securing offices, rooms and facilities
Evidence to have on file (guidance, our wording)
  • Facility security design documentation showing critical facilities sited away from public access
  • Photographs or survey records confirming the absence of signage revealing processing facilities
SOC 2 CC6.4 Restricting physical access to facilities and assets
Evidence to have on file (guidance, our wording)
  • Badge access provisioning and removal records
  • Periodic physical access review for sensitive areas
SOC 2 CC6.5 Protecting data on assets until disposal
Evidence to have on file (guidance, our wording)
  • Media sanitisation and disposal procedure
  • Certificates of destruction or wipe logs for disposed devices
NIST CSF 2.0 PR.AA-06 Physical access to assets is managed, monitored, and enforced commensurate with risk
Evidence to have on file (guidance, our wording)
  • Physical access control system inventory
  • Badge issuance and revocation records
NIST CSF 2.0 PR.IR-02 The organization's technology assets are protected from environmental threats
Evidence to have on file (guidance, our wording)
  • Environmental controls inventory (HVAC, power, fire)
  • Site risk assessments with mitigation status
Application question On your wireless networks; do you use security at least as strong as WPA2 authentication and encryption, and do you require two factor authentication (access token and password/account logon) before allowing wireless connections to your network?
CNA held application question

Flagged knockout: the wording of this question makes a "no" a common point at which a cyber application is declined or referred.

ISO 27001:2022 A.8.5 Secure authentication
Evidence to have on file (guidance, our wording)
  • An authentication standard linking required authentication strength to information classification and system criticality
  • MFA configuration and coverage reports for critical systems, remote access and privileged access, including conditional or risk-based rules
ISO 27001:2022 A.5.17 Authentication information
Evidence to have on file (guidance, our wording)
  • Credential issuance procedure requiring identity verification before new, replacement or temporary credentials are provided
  • Evidence that initial credentials are unique, delivered over protected channels and changed at first use
ISO 27001:2022 A.8.24 Use of cryptography
Evidence to have on file (guidance, our wording)
  • The topic-specific cryptography policy with approved algorithms, key lengths, protocols and usage by information classification
  • Evidence of encryption on endpoints, removable media and data in transit, aligned with the policy
SOC 2 CC6.1 Logical access security over protected information assets
Evidence to have on file (guidance, our wording)
  • Asset inventory with classification for in-scope systems
  • Identity provider configuration showing MFA and password policy
NIST CSF 2.0 PR.AA-03 Users, services, and hardware are authenticated
Evidence to have on file (guidance, our wording)
  • Multi factor authentication coverage report
  • Phishing resistant authentication rollout plan
NIST CSF 2.0 PR.AA-01 Identities and credentials for authorized users, services, and hardware are managed by the organization
Evidence to have on file (guidance, our wording)
  • Identity management platform configuration baseline
  • Joiner mover leaver workflow with timing SLAs
Application question Do you require multi-factor authorization when your network is accessed remotely and/or when cloud resources are utilized?
CNA held application question

Flagged knockout: the wording of this question makes a "no" a common point at which a cyber application is declined or referred.

ISO 27001:2022 A.8.5 Secure authentication
Evidence to have on file (guidance, our wording)
  • An authentication standard linking required authentication strength to information classification and system criticality
  • MFA configuration and coverage reports for critical systems, remote access and privileged access, including conditional or risk-based rules
ISO 27001:2022 A.5.17 Authentication information
Evidence to have on file (guidance, our wording)
  • Credential issuance procedure requiring identity verification before new, replacement or temporary credentials are provided
  • Evidence that initial credentials are unique, delivered over protected channels and changed at first use
SOC 2 CC6.1 Logical access security over protected information assets
Evidence to have on file (guidance, our wording)
  • Asset inventory with classification for in-scope systems
  • Identity provider configuration showing MFA and password policy
NIST CSF 2.0 PR.AA-03 Users, services, and hardware are authenticated
Evidence to have on file (guidance, our wording)
  • Multi factor authentication coverage report
  • Phishing resistant authentication rollout plan

Controls not asked in this held document (222)

None of this held document's questions reach 222 of the 290 held controls (for example A.5.3, A.5.5, A.5.6, A.5.7, A.5.8, A.5.9, A.5.10, A.5.11). That is a fact about this held document, not about what the carrier underwrites on: a carrier's fuller forms and supplements ask controls this summary does not, multi-factor authentication, offline backups and patching among them. A control here is not asserted as required, and not asserted as not required.