The Hartford cyber policy application, held
The questions of the CyberChoice Underwriting Application, held and mapped to the ISO 27001:2022 controls, the SOC 2 criteria and the NIST CSF 2.0 outcomes each one reaches. The source document, CyberChoice Underwriting Application (read 2026-10-11). The date shown is the date this copy was read, not a version the form itself states. This page quotes only the question each mapped row needs and states its source; it does not publish the carrier's form. A complete form would be held only under a stated policy for copyrighted forms. The Hartford is a source document, never a customer.
This document's questions reach 48 of 290 held controls. Whether an applicant is offered cover is the carrier’s underwriting decision. 5 questions here are flagged knockout (a "no" is a common decline point) and 5 flagged warranty (an answer the carrier relies on, that can affect cover if wrong).
An answer about an existing state of affairs can be relied on by the carrier, but in Australia and the United Kingdom a statement by the insured is a representation, not a warranty (the Insurance Contracts Act and the Insurance Act), and the position varies by US state.
Answer options on this form: No / Yes.
No held control answers this line.
This is a scoping question, not a control requirement. It reaches no held control.
No held control answers this line.
No held control answers this line.
This is a scoping question, not a control requirement. It reaches no held control.
No held control answers this line.
- The topic-specific logging policy defining purposes, events to be logged, fields captured, retention and protection
- A documented monitoring scope covering network traffic, system access, configuration files, security tool logs, code integrity and resource use, with retention periods
- Baselines of normal behaviour for systems and user groups, and the detection rules built on them
- The top-level information security policy with top management approval, covering the definition, objectives or objective-setting framework, principles, commitments to requirements and continual improvement, role assignments and the exceptions procedure
- The register of topic-specific policies with an owner, approving manager and version for each
- Hardening standards or benchmarks for in-scope platforms
- Configuration compliance scan results
- Alert rules and sample of triaged alerts
- Threat intelligence sources in use
- Network flow telemetry coverage map by segment
- IDS or NDR sensor inventory with placement diagram
- Logging policy by data class and system tier
- Centralized log collection architecture
- The topic-specific supplier relationship policy and its communication record
- A supplier inventory categorized by type and by the information, services and infrastructure each can access
- Supplier agreements containing security clauses proportionate to the relationship, such as classification mapping, agreed controls, incident notification, subcontracting, right to audit and termination terms
- A register of contracts, memoranda and information-sharing arrangements with outside parties showing what information each covers and when it was last reviewed
- Security requirements included in ICT acquisition specifications and contracts, including flow-down to sub-suppliers
- Software component information such as SBOMs and descriptions of security functions and secure configuration obtained from product suppliers
- Vendor inventory with risk tiers and the review frequency set for each tier
- Due diligence records, for example vendor SOC reports reviewed with complementary controls noted
- Data processing agreements with privacy clauses
- Periodic assessments of vendors' privacy compliance
- Third party risk management program charter
- Supplier risk policy with tiering criteria
- Standard supplier security requirements catalog
- Contract clause library with cyber obligations
This is a scoping question, not a control requirement. It reaches no held control.
No held control answers this line.
This is a financials question, not a control requirement. It reaches no held control.
Answer options on this form: No / Yes.
No held control answers this line.
This is a scoping question, not a control requirement. It reaches no held control.
No held control answers this line.
This is a scoping question, not a control requirement. It reaches no held control.
No held control answers this line.
This is a scoping question, not a control requirement. It reaches no held control.
No held control answers this line.
This is a scoping question, not a control requirement. It reaches no held control.
No held control answers this line.
This is a loss history question, not a control requirement. It reaches no held control.
No held control answers this line.
This is a scoping question, not a control requirement. It reaches no held control.
No held control answers this line.
- The topic-specific cryptography policy with approved algorithms, key lengths, protocols and usage by information classification
- Evidence of encryption on endpoints, removable media and data in transit, aligned with the policy
- The topic-specific information transfer policy and its communication record
- Transfer agreements with third parties covering recipient authentication, protection levels, incident liability and labelling
- The topic-specific backup policy and backup plans stating scope, extent, frequency and retention per system aligned with RPO
- Backup job monitoring reports with evidence that failed jobs were investigated and rerun
- TLS and encryption standards for data in transit
- Removable media policy and technical enforcement
- Backup policy defining scope, frequency and retention
- Backup job monitoring and failure remediation records
- TLS configuration standards and scan results
- VPN and zero trust network access policy
- Backup policy with frequency and retention
- Backup integrity test reports
Flagged knockout: the wording of this question makes a "no" a common point at which a cyber application is declined or referred.
Flagged warranty: where the carrier declares its answers to be the basis of the contract, this is an answer the carrier relies on and that can affect cover if it is wrong.
- The topic-specific backup policy and backup plans stating scope, extent, frequency and retention per system aligned with RPO
- Backup job monitoring reports with evidence that failed jobs were investigated and rerun
- Documented availability requirements for business services and systems
- Architecture diagrams showing redundancy such as dual providers, redundant networks, separate data centres, redundant power and load-balanced instances
- Backup policy defining scope, frequency and retention
- Backup job monitoring and failure remediation records
- Disaster recovery or continuity test plan and results in the period
- Backup restore test records with verification of completeness
- Backup policy with frequency and retention
- Backup integrity test reports
Flagged knockout: the wording of this question makes a "no" a common point at which a cyber application is declined or referred.
Flagged warranty: where the carrier declares its answers to be the basis of the contract, this is an answer the carrier relies on and that can affect cover if it is wrong.
- The topic-specific backup policy and backup plans stating scope, extent, frequency and retention per system aligned with RPO
- Backup job monitoring reports with evidence that failed jobs were investigated and rerun
- Documented availability requirements for business services and systems
- Architecture diagrams showing redundancy such as dual providers, redundant networks, separate data centres, redundant power and load-balanced instances
- Backup policy defining scope, frequency and retention
- Backup job monitoring and failure remediation records
- Disaster recovery or continuity test plan and results in the period
- Backup restore test records with verification of completeness
- Backup policy with frequency and retention
- Backup integrity test reports
- Business continuity plans that contain information security requirements and the controls, systems and tools needed during disruption
- A documented analysis of which security controls must be adapted during disruption and how
- The business impact analysis with prioritized activities, supporting ICT services and their RTOs, and RPOs for required information
- Selected ICT continuity strategies covering before, during and after disruption
- Documented availability requirements for business services and systems
- Architecture diagrams showing redundancy such as dual providers, redundant networks, separate data centres, redundant power and load-balanced instances
- Business continuity and disaster recovery plans covering the in-scope service
- Business impact analysis
- Backup policy defining scope, frequency and retention
- Backup job monitoring and failure remediation records
- Resilience architecture patterns for critical services
- Failover and failback tested with evidence
- Recovery plan with triggers and decision rights
- Execution log of recovery activities
- Business continuity plans that contain information security requirements and the controls, systems and tools needed during disruption
- A documented analysis of which security controls must be adapted during disruption and how
- The business impact analysis with prioritized activities, supporting ICT services and their RTOs, and RPOs for required information
- Selected ICT continuity strategies covering before, during and after disruption
- Documented availability requirements for business services and systems
- Architecture diagrams showing redundancy such as dual providers, redundant networks, separate data centres, redundant power and load-balanced instances
- Business continuity and disaster recovery plans covering the in-scope service
- Business impact analysis
- Backup policy defining scope, frequency and retention
- Backup job monitoring and failure remediation records
- Resilience architecture patterns for critical services
- Failover and failback tested with evidence
- Recovery plan with triggers and decision rights
- Execution log of recovery activities
This is a media liability question, not a control requirement. It reaches no held control.
No held control answers this line.
This is a loss history question, not a control requirement. It reaches no held control.
No held control answers this line.
This is a media liability question, not a control requirement. It reaches no held control.
No held control answers this line.
Flagged knockout: the wording of this question makes a "no" a common point at which a cyber application is declined or referred.
Flagged warranty: where the carrier declares its answers to be the basis of the contract, this is an answer the carrier relies on and that can affect cover if it is wrong.
- An authentication standard linking required authentication strength to information classification and system criticality
- MFA configuration and coverage reports for critical systems, remote access and privileged access, including conditional or risk-based rules
- Credential issuance procedure requiring identity verification before new, replacement or temporary credentials are provided
- Evidence that initial credentials are unique, delivered over protected channels and changed at first use
- The topic-specific remote working policy defining conditions, permitted work, information classifications allowed and systems accessible
- Remote access configuration showing multi-factor authentication, secure channels or virtual desktops
- Asset inventory with classification for in-scope systems
- Identity provider configuration showing MFA and password policy
- Firewall and security group rule sets with review evidence
- MFA enforced on VPN, remote and administrative access
- Multi factor authentication coverage report
- Phishing resistant authentication rollout plan
- Network segmentation design with zones and trust levels
- Firewall and access control list governance
- The topic-specific remote working policy defining conditions, permitted work, information classifications allowed and systems accessible
- Remote access configuration showing multi-factor authentication, secure channels or virtual desktops
- Current network diagrams and device configuration backups for routers, switches, firewalls and wireless controllers
- Defined responsibilities and procedures for network device management, separated from system operations where appropriate
- Network segmentation design defining domains by trust, criticality, sensitivity or organizational unit, with the assessment that justified it
- Firewall or filtering router rules controlling traffic between domains, with rule review records
- Firewall and security group rule sets with review evidence
- MFA enforced on VPN, remote and administrative access
- Network segmentation design with zones and trust levels
- Firewall and access control list governance
Flagged knockout: the wording of this question makes a "no" a common point at which a cyber application is declined or referred.
Flagged warranty: where the carrier declares its answers to be the basis of the contract, this is an answer the carrier relies on and that can affect cover if it is wrong.
- An authentication standard linking required authentication strength to information classification and system criticality
- MFA configuration and coverage reports for critical systems, remote access and privileged access, including conditional or risk-based rules
- Credential issuance procedure requiring identity verification before new, replacement or temporary credentials are provided
- Evidence that initial credentials are unique, delivered over protected channels and changed at first use
- Asset inventory with classification for in-scope systems
- Identity provider configuration showing MFA and password policy
- Multi factor authentication coverage report
- Phishing resistant authentication rollout plan
- The topic-specific supplier relationship policy and its communication record
- A supplier inventory categorized by type and by the information, services and infrastructure each can access
- Supplier agreements containing security clauses proportionate to the relationship, such as classification mapping, agreed controls, incident notification, subcontracting, right to audit and termination terms
- A register of contracts, memoranda and information-sharing arrangements with outside parties showing what information each covers and when it was last reviewed
- Security requirements included in ICT acquisition specifications and contracts, including flow-down to sub-suppliers
- Software component information such as SBOMs and descriptions of security functions and secure configuration obtained from product suppliers
- Vendor inventory with risk tiers and the review frequency set for each tier
- Due diligence records, for example vendor SOC reports reviewed with complementary controls noted
- Data processing agreements with privacy clauses
- Periodic assessments of vendors' privacy compliance
- Third party risk management program charter
- Supplier risk policy with tiering criteria
- Standard supplier security requirements catalog
- Contract clause library with cyber obligations
- the bank or treasury platform dual-authorisation setup and the payment approval workflow, showing a second approver on a different device above the threshold
- the callback or out-of-band verification procedure for a change to payee bank details, with a dated example
- A documented awareness, education and training programme aligned with the policies and planned by role, including external personnel
- Completion records for initial training of new starters and role changers and for periodic refreshers
- An authentication standard linking required authentication strength to information classification and system criticality
- MFA configuration and coverage reports for critical systems, remote access and privileged access, including conditional or risk-based rules
- the bank or treasury platform dual-authorisation setup and the payment approval workflow, showing a second approver on a different device above the threshold
- the callback or out-of-band verification procedure for a change to payee bank details, with a dated example
- Fraud risk assessment or fraud section of the enterprise risk assessment
- Analysis of privileged access and data misuse scenarios
- Access policy framework with role definitions
- Privileged access management deployment evidence
- the bank or treasury platform dual-authorisation setup and the payment approval workflow, showing a second approver on a different device above the threshold
- the callback or out-of-band verification procedure for a change to payee bank details, with a dated example
- A documented awareness, education and training programme aligned with the policies and planned by role, including external personnel
- Completion records for initial training of new starters and role changers and for periodic refreshers
- An authentication standard linking required authentication strength to information classification and system criticality
- MFA configuration and coverage reports for critical systems, remote access and privileged access, including conditional or risk-based rules
- the bank or treasury platform dual-authorisation setup and the payment approval workflow, showing a second approver on a different device above the threshold
- the callback or out-of-band verification procedure for a change to payee bank details, with a dated example
- Fraud risk assessment or fraud section of the enterprise risk assessment
- Analysis of privileged access and data misuse scenarios
- Access policy framework with role definitions
- Privileged access management deployment evidence
Flagged knockout: the wording of this question makes a "no" a common point at which a cyber application is declined or referred.
Flagged warranty: where the carrier declares its answers to be the basis of the contract, this is an answer the carrier relies on and that can affect cover if it is wrong.
- The topic-specific logging policy defining purposes, events to be logged, fields captured, retention and protection
- A documented monitoring scope covering network traffic, system access, configuration files, security tool logs, code integrity and resource use, with retention periods
- Baselines of normal behaviour for systems and user groups, and the detection rules built on them
- Anti-malware deployment and update status reports across endpoints, servers and gateways
- Application allowlisting and malicious website blocking configurations
- Hardening standards or benchmarks for in-scope platforms
- Configuration compliance scan results
- Alert rules and sample of triaged alerts
- Threat intelligence sources in use
- Network flow telemetry coverage map by segment
- IDS or NDR sensor inventory with placement diagram
- Logging policy by data class and system tier
- Centralized log collection architecture
- Current rules on safe, proper use of online resources
- Web filtering or secure web gateway configuration showing blocked categories such as malicious, phishing, command and control, illegal content and upload sites
- Anti-malware deployment and update status reports across endpoints, servers and gateways
- Application allowlisting and malicious website blocking configurations
- The topic-specific information transfer policy and its communication record
- Transfer agreements with third parties covering recipient authentication, protection levels, incident liability and labelling
- Endpoint protection coverage report across servers and workstations
- Local administrator and software installation restrictions
- Background check policy and completed checks for a sample of new hires and contractors
- Role competency requirements and performance review records
- Application allowlist policy and tooling configuration
- Endpoint protection deployment reports
- Security awareness program curriculum
- Completion records by population
This is a loss history question, not a control requirement. It reaches no held control.
No held control answers this line.
Prior-knowledge question. This asks whether the applicant knows of any circumstance that could give rise to a claim. A wrong answer here is the classic route to a prior-knowledge exclusion or rescission, so it is the highest-consequence line on the form, not a line to leave unread. It reaches no control by itself: it is about what the applicant knows, not a control to hold.
No held control answers this line.
Prior-knowledge question. This asks whether the applicant knows of any circumstance that could give rise to a claim. A wrong answer here is the classic route to a prior-knowledge exclusion or rescission, so it is the highest-consequence line on the form, not a line to leave unread. It reaches no control by itself: it is about what the applicant knows, not a control to hold.
No held control answers this line.
Controls not asked in this held document (242)
None of this held document's questions reach 242 of the 290 held controls (for example A.5.2, A.5.4, A.5.5, A.5.6, A.5.7, A.5.8, A.5.9, A.5.10). That is a fact about this held document, not about what the carrier underwrites on: a carrier's fuller forms and supplements ask controls this summary does not, multi-factor authentication, offline backups and patching among them. A control here is not asserted as required, and not asserted as not required.