Cyber Insurance Application Scannermap an application to controls

The Hanover Insurance Group cyber policy application, held

The questions of the Cyber Advantage Pro New Business Application, held and mapped to the ISO 27001:2022 controls, the SOC 2 criteria and the NIST CSF 2.0 outcomes each one reaches. The source document (read 2026-10-11). The date shown is the date this copy was read, not a version the form itself states. This page quotes only the question each mapped row needs and states its source; it does not publish the carrier's form. A complete form would be held only under a stated policy for copyrighted forms. The Hanover Insurance Group is a source document, never a customer.

This document's questions reach 45 of 290 held controls. Whether an applicant is offered cover is the carrier’s underwriting decision. 0 questions here are flagged knockout (a "no" is a common decline point) and 0 flagged warranty (an answer the carrier relies on, that can affect cover if wrong).

Application question Does the Applicant have any physical offices, operations or Subsidiaries outside of the United States?
The Hanover Insurance Group held application question

This is a scoping question, not a control requirement. It reaches no held control.

No held control answers this line.

Application question Does the Applicant have any sales outside of the United States?
The Hanover Insurance Group held application question

This is a scoping question, not a control requirement. It reaches no held control.

No held control answers this line.

Application question back-ups of critical Data and Computer Systems If either 2.a. or 2.b. has been selected is one copy stored on-line?
The Hanover Insurance Group held application question
ISO 27001:2022 A.8.13 Information backup
Evidence to have on file (guidance, our wording)
  • The topic-specific backup policy and backup plans stating scope, extent, frequency and retention per system aligned with RPO
  • Backup job monitoring reports with evidence that failed jobs were investigated and rerun
ISO 27001:2022 A.8.14 Redundancy of information processing facilities
Evidence to have on file (guidance, our wording)
  • Documented availability requirements for business services and systems
  • Architecture diagrams showing redundancy such as dual providers, redundant networks, separate data centres, redundant power and load-balanced instances
ISO 27001:2022 A.7.1 Physical security perimeters
Evidence to have on file (guidance, our wording)
  • Site plans showing defined security perimeters and their strength relative to the assets inside
  • Physical security surveys or assessments of walls, roofs, floors, doors, windows and vents
SOC 2 A1.2 Environmental protection, backup and recovery infrastructure
Evidence to have on file (guidance, our wording)
  • Backup policy defining scope, frequency and retention
  • Backup job monitoring and failure remediation records
SOC 2 A1.3 Testing recovery plan procedures
Evidence to have on file (guidance, our wording)
  • Disaster recovery or continuity test plan and results in the period
  • Backup restore test records with verification of completeness
NIST CSF 2.0 PR.DS-11 Backups of data are created, protected, maintained, and tested
Evidence to have on file (guidance, our wording)
  • Backup policy with frequency and retention
  • Backup integrity test reports
NIST CSF 2.0 PR.AA-06 Physical access to assets is managed, monitored, and enforced commensurate with risk
Evidence to have on file (guidance, our wording)
  • Physical access control system inventory
  • Badge issuance and revocation records
Application question If either 2.a. or 2.b. has been selected is one copy stored off-site and off-line?
The Hanover Insurance Group held application question
ISO 27001:2022 A.7.1 Physical security perimeters
Evidence to have on file (guidance, our wording)
  • Site plans showing defined security perimeters and their strength relative to the assets inside
  • Physical security surveys or assessments of walls, roofs, floors, doors, windows and vents
ISO 27001:2022 A.7.2 Physical entry
Evidence to have on file (guidance, our wording)
  • Physical access rights records with provisioning, periodic review and revocation evidence
  • Electronic access control logs or physical logbooks, protected and monitored
ISO 27001:2022 A.7.3 Securing offices, rooms and facilities
Evidence to have on file (guidance, our wording)
  • Facility security design documentation showing critical facilities sited away from public access
  • Photographs or survey records confirming the absence of signage revealing processing facilities
SOC 2 CC6.4 Restricting physical access to facilities and assets
Evidence to have on file (guidance, our wording)
  • Badge access provisioning and removal records
  • Periodic physical access review for sensitive areas
SOC 2 CC6.5 Protecting data on assets until disposal
Evidence to have on file (guidance, our wording)
  • Media sanitisation and disposal procedure
  • Certificates of destruction or wipe logs for disposed devices
NIST CSF 2.0 PR.AA-06 Physical access to assets is managed, monitored, and enforced commensurate with risk
Evidence to have on file (guidance, our wording)
  • Physical access control system inventory
  • Badge issuance and revocation records
NIST CSF 2.0 PR.IR-02 The organization's technology assets are protected from environmental threats
Evidence to have on file (guidance, our wording)
  • Environmental controls inventory (HVAC, power, fire)
  • Site risk assessments with mitigation status
Application question Has traf fic using Remote Desktop Protocol (RDP) TCP ports 3389 and Server Message Block (SMB) TCP ports 445, 135, and 139 been blocked?
The Hanover Insurance Group held application question
ISO 27001:2022 A.6.7 Remote working
Evidence to have on file (guidance, our wording)
  • The topic-specific remote working policy defining conditions, permitted work, information classifications allowed and systems accessible
  • Remote access configuration showing multi-factor authentication, secure channels or virtual desktops
ISO 27001:2022 A.8.20 Networks security
Evidence to have on file (guidance, our wording)
  • Current network diagrams and device configuration backups for routers, switches, firewalls and wireless controllers
  • Defined responsibilities and procedures for network device management, separated from system operations where appropriate
ISO 27001:2022 A.8.22 Segregation of networks
Evidence to have on file (guidance, our wording)
  • Network segmentation design defining domains by trust, criticality, sensitivity or organizational unit, with the assessment that justified it
  • Firewall or filtering router rules controlling traffic between domains, with rule review records
SOC 2 CC6.6 Protection against threats from outside the system boundary
Evidence to have on file (guidance, our wording)
  • Firewall and security group rule sets with review evidence
  • MFA enforced on VPN, remote and administrative access
SOC 2 CC6.4 Restricting physical access to facilities and assets
Evidence to have on file (guidance, our wording)
  • Badge access provisioning and removal records
  • Periodic physical access review for sensitive areas
NIST CSF 2.0 PR.IR-01 Networks and environments are protected from unauthorized logical access and usage
Evidence to have on file (guidance, our wording)
  • Network segmentation design with zones and trust levels
  • Firewall and access control list governance
NIST CSF 2.0 DE.CM-01 Networks and network services are monitored to find potentially adverse events
Evidence to have on file (guidance, our wording)
  • Network flow telemetry coverage map by segment
  • IDS or NDR sensor inventory with placement diagram
Application question All content is reviewed prior to be being posted on the Applicant's website to avoid improper, of fensive or infringing content including intellectual property, trademarks and service marks?
The Hanover Insurance Group held application question

This is a media liability question, not a control requirement. It reaches no held control.

No held control answers this line.

Application question If user inf ormation is collected, the user has the option to opt-in or opt-out of allowing the collection or use of their information?
The Hanover Insurance Group held application question
ISO 27001:2022 A.5.34 Privacy and protection of personal identifiable information (PII)
Evidence to have on file (guidance, our wording)
  • The topic-specific privacy and PII protection policy and its communication to relevant parties
  • Privacy procedures communicated to everyone who processes PII
ISO 27001:2022 A.5.31 Legal, statutory, regulatory and contractual requirements
Evidence to have on file (guidance, our wording)
  • A register of applicable laws, regulations and contractual obligations for information security, with the countries covered, the approach to meeting each and a named responsible owner
  • Records of periodic review of the register and of new or changed legislation identified
SOC 2 P1.1 Privacy notice to data subjects
Evidence to have on file (guidance, our wording)
  • Published privacy notice with effective date and version history
  • Evidence notice is presented at collection points (forms, apps)
SOC 2 P3.1 Collecting personal information consistent with objectives
Evidence to have on file (guidance, our wording)
  • Data inventory showing purpose for each personal data field
  • Privacy review of new collection forms or features
NIST CSF 2.0 GV.OC-03 Legal, regulatory, and contractual requirements regarding cybersecurity - including privacy and civil liberties obligations - are understood and managed
Evidence to have on file (guidance, our wording)
  • Legal and regulatory obligations register with owners
  • Contractual security clauses summary across customer base
NIST CSF 2.0 PR.DS-01 The confidentiality, integrity, and availability of data-at-rest are protected
Evidence to have on file (guidance, our wording)
  • Data at rest encryption inventory by store type
  • Storage configuration baselines with attestation
Application question If Personal Information gathered from customers is sold, the Applicant notifies and obtains consent prior to dissemination of such information?
The Hanover Insurance Group held application question
ISO 27001:2022 A.5.34 Privacy and protection of personal identifiable information (PII)
Evidence to have on file (guidance, our wording)
  • The topic-specific privacy and PII protection policy and its communication to relevant parties
  • Privacy procedures communicated to everyone who processes PII
ISO 27001:2022 A.5.31 Legal, statutory, regulatory and contractual requirements
Evidence to have on file (guidance, our wording)
  • A register of applicable laws, regulations and contractual obligations for information security, with the countries covered, the approach to meeting each and a named responsible owner
  • Records of periodic review of the register and of new or changed legislation identified
SOC 2 P1.1 Privacy notice to data subjects
Evidence to have on file (guidance, our wording)
  • Published privacy notice with effective date and version history
  • Evidence notice is presented at collection points (forms, apps)
SOC 2 P3.1 Collecting personal information consistent with objectives
Evidence to have on file (guidance, our wording)
  • Data inventory showing purpose for each personal data field
  • Privacy review of new collection forms or features
NIST CSF 2.0 GV.OC-03 Legal, regulatory, and contractual requirements regarding cybersecurity - including privacy and civil liberties obligations - are understood and managed
Evidence to have on file (guidance, our wording)
  • Legal and regulatory obligations register with owners
  • Contractual security clauses summary across customer base
NIST CSF 2.0 PR.DS-01 The confidentiality, integrity, and availability of data-at-rest are protected
Evidence to have on file (guidance, our wording)
  • Data at rest encryption inventory by store type
  • Storage configuration baselines with attestation
Application question Does the Applicant consistently monitor & remove offensive, unacceptable or infringing posts from Your website or Social Media site?
The Hanover Insurance Group held application question

This is a media liability question, not a control requirement. It reaches no held control.

No held control answers this line.

Application question Does the Applicant have written and documented procedures in place which are provided to Your Employees and which require Employees to authenticate all requested changes to vendor/supplier 926-1701 APP 10/21 Page 3 of 5 Cyber Advantage Pro New Business Application Or client/customer information (such as changes to bank accounts, routing numbers, contact inf ormation) with a phone call to an authorized representative of the vendor/supplier or client/customer at a pre-determined phone number on file?
The Hanover Insurance Group held application question
ISO 27001:2022 A.5.19 Information security in supplier relationships
Evidence to have on file (guidance, our wording)
  • The topic-specific supplier relationship policy and its communication record
  • A supplier inventory categorized by type and by the information, services and infrastructure each can access
ISO 27001:2022 A.5.20 Addressing information security within supplier agreements
Evidence to have on file (guidance, our wording)
  • Supplier agreements containing security clauses proportionate to the relationship, such as classification mapping, agreed controls, incident notification, subcontracting, right to audit and termination terms
  • A register of contracts, memoranda and information-sharing arrangements with outside parties showing what information each covers and when it was last reviewed
ISO 27001:2022 A.5.21 Managing information security in the information and communication technology (ICT) supply chain
Evidence to have on file (guidance, our wording)
  • Security requirements included in ICT acquisition specifications and contracts, including flow-down to sub-suppliers
  • Software component information such as SBOMs and descriptions of security functions and secure configuration obtained from product suppliers
SOC 2 CC9.2 Assessing and managing vendor and business partner risk
Evidence to have on file (guidance, our wording)
  • Vendor inventory with risk tiers and the review frequency set for each tier
  • Due diligence records, for example vendor SOC reports reviewed with complementary controls noted
SOC 2 P6.4 Privacy commitments from vendors and third parties
Evidence to have on file (guidance, our wording)
  • Data processing agreements with privacy clauses
  • Periodic assessments of vendors' privacy compliance
NIST CSF 2.0 GV.SC-01 A cybersecurity supply chain risk management program, strategy, objectives, policies, and processes are established and agreed to by organizational stakeholders
Evidence to have on file (guidance, our wording)
  • Third party risk management program charter
  • Supplier risk policy with tiering criteria
NIST CSF 2.0 GV.SC-05 Requirements to address cybersecurity risks in supply chains are established, prioritized, and integrated into contracts and other types of agreements with suppliers and other relevant third parties
Evidence to have on file (guidance, our wording)
  • Standard supplier security requirements catalog
  • Contract clause library with cyber obligations
Application question Exec/Employee directed request wire transfer without first validating the request with a call back to the requestor (inclusive of any owner) at a pre-determined work phone number or with a f ace to face confirmation?
The Hanover Insurance Group held application question
ISO 27001:2022 A.5.3 Segregation of duties
Evidence to have on file (guidance, our wording)
  • the bank or treasury platform dual-authorisation setup and the payment approval workflow, showing a second approver on a different device above the threshold
  • the callback or out-of-band verification procedure for a change to payee bank details, with a dated example
ISO 27001:2022 A.6.3 Information security awareness, education and training
Evidence to have on file (guidance, our wording)
  • A documented awareness, education and training programme aligned with the policies and planned by role, including external personnel
  • Completion records for initial training of new starters and role changers and for periodic refreshers
ISO 27001:2022 A.8.5 Secure authentication
Evidence to have on file (guidance, our wording)
  • An authentication standard linking required authentication strength to information classification and system criticality
  • MFA configuration and coverage reports for critical systems, remote access and privileged access, including conditional or risk-based rules
SOC 2 CC6.3 Role-based access, least privilege and segregation of duties
Evidence to have on file (guidance, our wording)
  • the bank or treasury platform dual-authorisation setup and the payment approval workflow, showing a second approver on a different device above the threshold
  • the callback or out-of-band verification procedure for a change to payee bank details, with a dated example
SOC 2 CC3.3 Considering fraud risk (COSO principle 8)
Evidence to have on file (guidance, our wording)
  • Fraud risk assessment or fraud section of the enterprise risk assessment
  • Analysis of privileged access and data misuse scenarios
NIST CSF 2.0 PR.AA-05 Access permissions, entitlements, and authorizations are defined in a policy, managed, enforced, and reviewed, and incorporate the principles of least privilege and separation of duties
Evidence to have on file (guidance, our wording)
  • Access policy framework with role definitions
  • Privileged access management deployment evidence
Application question Detect and identify social engineering/phishing scams where a f raudulent email or phone call f rom purported vendor or client is received, requesting their vendor or client bank account inf ormation be changed?
The Hanover Insurance Group held application question
ISO 27001:2022 A.8.23 Web filtering
Evidence to have on file (guidance, our wording)
  • Current rules on safe, proper use of online resources
  • Web filtering or secure web gateway configuration showing blocked categories such as malicious, phishing, command and control, illegal content and upload sites
ISO 27001:2022 A.8.7 Protection against malware
Evidence to have on file (guidance, our wording)
  • Anti-malware deployment and update status reports across endpoints, servers and gateways
  • Application allowlisting and malicious website blocking configurations
ISO 27001:2022 A.5.14 Information transfer
Evidence to have on file (guidance, our wording)
  • The topic-specific information transfer policy and its communication record
  • Transfer agreements with third parties covering recipient authentication, protection levels, incident liability and labelling
SOC 2 CC6.8 Preventing and detecting unauthorised or malicious software
Evidence to have on file (guidance, our wording)
  • Endpoint protection coverage report across servers and workstations
  • Local administrator and software installation restrictions
SOC 2 CC1.4 Attracting, developing and retaining competent people (COSO principle 4)
Evidence to have on file (guidance, our wording)
  • Background check policy and completed checks for a sample of new hires and contractors
  • Role competency requirements and performance review records
NIST CSF 2.0 PR.PS-05 Installation and execution of unauthorized software are prevented
Evidence to have on file (guidance, our wording)
  • Application allowlist policy and tooling configuration
  • Endpoint protection deployment reports
NIST CSF 2.0 PR.AT-01 Personnel are provided with awareness and training so that they possess the knowledge and skills to perform general tasks with cybersecurity risks in mind
Evidence to have on file (guidance, our wording)
  • Security awareness program curriculum
  • Completion records by population
Application question Detect and identify social engineering/phishing scams where a f raudulent email or phone call f rom a purported owner or employee of the Applicant is received, requesting a wire transfer be made on their behalf?
The Hanover Insurance Group held application question
ISO 27001:2022 A.8.23 Web filtering
Evidence to have on file (guidance, our wording)
  • Current rules on safe, proper use of online resources
  • Web filtering or secure web gateway configuration showing blocked categories such as malicious, phishing, command and control, illegal content and upload sites
ISO 27001:2022 A.8.7 Protection against malware
Evidence to have on file (guidance, our wording)
  • Anti-malware deployment and update status reports across endpoints, servers and gateways
  • Application allowlisting and malicious website blocking configurations
ISO 27001:2022 A.5.14 Information transfer
Evidence to have on file (guidance, our wording)
  • The topic-specific information transfer policy and its communication record
  • Transfer agreements with third parties covering recipient authentication, protection levels, incident liability and labelling
SOC 2 CC6.8 Preventing and detecting unauthorised or malicious software
Evidence to have on file (guidance, our wording)
  • Endpoint protection coverage report across servers and workstations
  • Local administrator and software installation restrictions
SOC 2 CC1.4 Attracting, developing and retaining competent people (COSO principle 4)
Evidence to have on file (guidance, our wording)
  • Background check policy and completed checks for a sample of new hires and contractors
  • Role competency requirements and performance review records
NIST CSF 2.0 PR.PS-05 Installation and execution of unauthorized software are prevented
Evidence to have on file (guidance, our wording)
  • Application allowlist policy and tooling configuration
  • Endpoint protection deployment reports
NIST CSF 2.0 PR.AT-01 Personnel are provided with awareness and training so that they possess the knowledge and skills to perform general tasks with cybersecurity risks in mind
Evidence to have on file (guidance, our wording)
  • Security awareness program curriculum
  • Completion records by population
Application question If "No", what kind of training does the Applicant provide to help combat these types of fraudulent schemes and how often?
The Hanover Insurance Group held application question
ISO 27001:2022 A.6.3 Information security awareness, education and training
Evidence to have on file (guidance, our wording)
  • A documented awareness, education and training programme aligned with the policies and planned by role, including external personnel
  • Completion records for initial training of new starters and role changers and for periodic refreshers
ISO 27001:2022 A.5.3 Segregation of duties
Evidence to have on file (guidance, our wording)
  • the bank or treasury platform dual-authorisation setup and the payment approval workflow, showing a second approver on a different device above the threshold
  • the callback or out-of-band verification procedure for a change to payee bank details, with a dated example
ISO 27001:2022 A.8.5 Secure authentication
Evidence to have on file (guidance, our wording)
  • An authentication standard linking required authentication strength to information classification and system criticality
  • MFA configuration and coverage reports for critical systems, remote access and privileged access, including conditional or risk-based rules
SOC 2 CC1.4 Attracting, developing and retaining competent people (COSO principle 4)
Evidence to have on file (guidance, our wording)
  • Background check policy and completed checks for a sample of new hires and contractors
  • Role competency requirements and performance review records
SOC 2 CC2.2 Internal communication of objectives and control responsibilities (COSO principle 14)
Evidence to have on file (guidance, our wording)
  • Security awareness training content and completion records
  • Published information security policies accessible to staff with change notices
NIST CSF 2.0 PR.AT-01 Personnel are provided with awareness and training so that they possess the knowledge and skills to perform general tasks with cybersecurity risks in mind
Evidence to have on file (guidance, our wording)
  • Security awareness program curriculum
  • Completion records by population
NIST CSF 2.0 PR.AA-05 Access permissions, entitlements, and authorizations are defined in a policy, managed, enforced, and reviewed, and incorporate the principles of least privilege and separation of duties
Evidence to have on file (guidance, our wording)
  • Access policy framework with role definitions
  • Privileged access management deployment evidence
Application question Notif ied consumers or any third party of a data breach incident?
The Hanover Insurance Group held application question

This is a loss history question, not a control requirement. It reaches no held control.

No held control answers this line.

Application question Experienced an actual or attempted extortion demand with respect to Your Computer System?
The Hanover Insurance Group held application question

This is a loss history question, not a control requirement. It reaches no held control.

No held control answers this line.

Application question Experienced an unscheduled network outage lasting over 4 hours?
The Hanover Insurance Group held application question

This is a loss history question, not a control requirement. It reaches no held control.

No held control answers this line.

Application question Received a complaint or cease and desist demand alleging trademark, copyright, invasion of privacy, or defamation with regards to any content published, displayed or distributed by or on behalf of the Applicant?
The Hanover Insurance Group held application question

This is a loss history question, not a control requirement. It reaches no held control.

No held control answers this line.

Application question Is any Applicant proposed for coverage aware of any fact, circumstance, or situation that might reasonably be expected to result in a Claim that would fall within the scope of the proposed coverage?
The Hanover Insurance Group held application question

Prior-knowledge question. This asks whether the applicant knows of any circumstance that could give rise to a claim. A wrong answer here is the classic route to a prior-knowledge exclusion or rescission, so it is the highest-consequence line on the form, not a line to leave unread. It reaches no control by itself: it is about what the applicant knows, not a control to hold.

No held control answers this line.

Controls not asked in this held document (245)

None of this held document's questions reach 245 of the 290 held controls (for example A.5.1, A.5.2, A.5.4, A.5.5, A.5.6, A.5.7, A.5.8, A.5.9). That is a fact about this held document, not about what the carrier underwrites on: a carrier's fuller forms and supplements ask controls this summary does not, multi-factor authentication, offline backups and patching among them. A control here is not asserted as required, and not asserted as not required.