Munich Re cyber policy application, held
The questions of the Insurance Application - Cyber Risk (UK), held and mapped to the ISO 27001:2022 controls, the SOC 2 criteria and the NIST CSF 2.0 outcomes each one reaches. The source document (read 2026-10-11). The date shown is the date this copy was read, not a version the form itself states. This page quotes only the question each mapped row needs and states its source; it does not publish the carrier's form. A complete form would be held only under a stated policy for copyrighted forms. Munich Re is a source document, never a customer.
This document's questions reach 112 of 290 held controls. Whether an applicant is offered cover is the carrier’s underwriting decision. 12 questions here are flagged knockout (a "no" is a common decline point) and 0 flagged warranty (an answer the carrier relies on, that can affect cover if wrong).
- The top-level information security policy with top management approval, covering the definition, objectives or objective-setting framework, principles, commitments to requirements and continual improvement, role assignments and the exceptions procedure
- The register of topic-specific policies with an owner, approving manager and version for each
- A documented roles and responsibilities matrix covering asset protection, specific security processes, risk management and residual risk acceptance, and user duties
- Named risk owners with evidence that they accepted residual risks
- Evidence that security briefings on roles and responsibilities occur before access is granted, such as onboarding checklists tied to access provisioning
- Role-specific guidance documents setting out security expectations
- Current organisation chart including security, IT operations, compliance and privacy functions
- Job descriptions or RACI naming security and privacy responsibilities
- Approved information security policy set with owners and review dates
- Evidence of annual policy review and approval
- Cybersecurity risk management policy approved by leadership
- Policy linkage matrix to standards and procedures
- Board cyber accountability charter
- Executive cyber scorecard with named owners
- The topic-specific privacy and PII protection policy and its communication to relevant parties
- Privacy procedures communicated to everyone who processes PII
- A register of applicable laws, regulations and contractual obligations for information security, with the countries covered, the approach to meeting each and a named responsible owner
- Records of periodic review of the register and of new or changed legislation identified
- The top-level information security policy with top management approval, covering the definition, objectives or objective-setting framework, principles, commitments to requirements and continual improvement, role assignments and the exceptions procedure
- The register of topic-specific policies with an owner, approving manager and version for each
- Published privacy notice with effective date and version history
- Evidence notice is presented at collection points (forms, apps)
- Data inventory showing purpose for each personal data field
- Privacy review of new collection forms or features
- Legal and regulatory obligations register with owners
- Contractual security clauses summary across customer base
- Data at rest encryption inventory by store type
- Storage configuration baselines with attestation
- The topic-specific privacy and PII protection policy and its communication to relevant parties
- Privacy procedures communicated to everyone who processes PII
- A register of applicable laws, regulations and contractual obligations for information security, with the countries covered, the approach to meeting each and a named responsible owner
- Records of periodic review of the register and of new or changed legislation identified
- The topic-specific supplier relationship policy and its communication record
- A supplier inventory categorized by type and by the information, services and infrastructure each can access
- Published privacy notice with effective date and version history
- Evidence notice is presented at collection points (forms, apps)
- Data inventory showing purpose for each personal data field
- Privacy review of new collection forms or features
- Legal and regulatory obligations register with owners
- Contractual security clauses summary across customer base
- Data at rest encryption inventory by store type
- Storage configuration baselines with attestation
- The topic-specific privacy and PII protection policy and its communication to relevant parties
- Privacy procedures communicated to everyone who processes PII
- A register of applicable laws, regulations and contractual obligations for information security, with the countries covered, the approach to meeting each and a named responsible owner
- Records of periodic review of the register and of new or changed legislation identified
- The topic-specific supplier relationship policy and its communication record
- A supplier inventory categorized by type and by the information, services and infrastructure each can access
- Published privacy notice with effective date and version history
- Evidence notice is presented at collection points (forms, apps)
- Data inventory showing purpose for each personal data field
- Privacy review of new collection forms or features
- Legal and regulatory obligations register with owners
- Contractual security clauses summary across customer base
- Data at rest encryption inventory by store type
- Storage configuration baselines with attestation
- The topic-specific supplier relationship policy and its communication record
- A supplier inventory categorized by type and by the information, services and infrastructure each can access
- Supplier agreements containing security clauses proportionate to the relationship, such as classification mapping, agreed controls, incident notification, subcontracting, right to audit and termination terms
- A register of contracts, memoranda and information-sharing arrangements with outside parties showing what information each covers and when it was last reviewed
- Security requirements included in ICT acquisition specifications and contracts, including flow-down to sub-suppliers
- Software component information such as SBOMs and descriptions of security functions and secure configuration obtained from product suppliers
- Vendor inventory with risk tiers and the review frequency set for each tier
- Due diligence records, for example vendor SOC reports reviewed with complementary controls noted
- Data processing agreements with privacy clauses
- Periodic assessments of vendors' privacy compliance
- Third party risk management program charter
- Supplier risk policy with tiering criteria
- Standard supplier security requirements catalog
- Contract clause library with cyber obligations
- The topic-specific privacy and PII protection policy and its communication to relevant parties
- Privacy procedures communicated to everyone who processes PII
- A register of applicable laws, regulations and contractual obligations for information security, with the countries covered, the approach to meeting each and a named responsible owner
- Records of periodic review of the register and of new or changed legislation identified
- The topic-specific supplier relationship policy and its communication record
- A supplier inventory categorized by type and by the information, services and infrastructure each can access
- Published privacy notice with effective date and version history
- Evidence notice is presented at collection points (forms, apps)
- Data inventory showing purpose for each personal data field
- Privacy review of new collection forms or features
- Legal and regulatory obligations register with owners
- Contractual security clauses summary across customer base
- Data at rest encryption inventory by store type
- Storage configuration baselines with attestation
- The topic-specific privacy and PII protection policy and its communication to relevant parties
- Privacy procedures communicated to everyone who processes PII
- A register of applicable laws, regulations and contractual obligations for information security, with the countries covered, the approach to meeting each and a named responsible owner
- Records of periodic review of the register and of new or changed legislation identified
- Published privacy notice with effective date and version history
- Evidence notice is presented at collection points (forms, apps)
- Data inventory showing purpose for each personal data field
- Privacy review of new collection forms or features
- Legal and regulatory obligations register with owners
- Contractual security clauses summary across customer base
- Data at rest encryption inventory by store type
- Storage configuration baselines with attestation
No held control answers this line.
- The top-level information security policy with top management approval, covering the definition, objectives or objective-setting framework, principles, commitments to requirements and continual improvement, role assignments and the exceptions procedure
- The register of topic-specific policies with an owner, approving manager and version for each
- A documented roles and responsibilities matrix covering asset protection, specific security processes, risk management and residual risk acceptance, and user duties
- Named risk owners with evidence that they accepted residual risks
- Evidence that security briefings on roles and responsibilities occur before access is granted, such as onboarding checklists tied to access provisioning
- Role-specific guidance documents setting out security expectations
- Current organisation chart including security, IT operations, compliance and privacy functions
- Job descriptions or RACI naming security and privacy responsibilities
- Approved information security policy set with owners and review dates
- Evidence of annual policy review and approval
- Cybersecurity risk management policy approved by leadership
- Policy linkage matrix to standards and procedures
- Board cyber accountability charter
- Executive cyber scorecard with named owners
- The top-level information security policy with top management approval, covering the definition, objectives or objective-setting framework, principles, commitments to requirements and continual improvement, role assignments and the exceptions procedure
- The register of topic-specific policies with an owner, approving manager and version for each
- A documented roles and responsibilities matrix covering asset protection, specific security processes, risk management and residual risk acceptance, and user duties
- Named risk owners with evidence that they accepted residual risks
- Evidence that security briefings on roles and responsibilities occur before access is granted, such as onboarding checklists tied to access provisioning
- Role-specific guidance documents setting out security expectations
- Current organisation chart including security, IT operations, compliance and privacy functions
- Job descriptions or RACI naming security and privacy responsibilities
- Approved information security policy set with owners and review dates
- Evidence of annual policy review and approval
- Cybersecurity risk management policy approved by leadership
- Policy linkage matrix to standards and procedures
- Board cyber accountability charter
- Executive cyber scorecard with named owners
- The top-level information security policy with top management approval, covering the definition, objectives or objective-setting framework, principles, commitments to requirements and continual improvement, role assignments and the exceptions procedure
- The register of topic-specific policies with an owner, approving manager and version for each
- A documented roles and responsibilities matrix covering asset protection, specific security processes, risk management and residual risk acceptance, and user duties
- Named risk owners with evidence that they accepted residual risks
- Evidence that security briefings on roles and responsibilities occur before access is granted, such as onboarding checklists tied to access provisioning
- Role-specific guidance documents setting out security expectations
- Current organisation chart including security, IT operations, compliance and privacy functions
- Job descriptions or RACI naming security and privacy responsibilities
- Approved information security policy set with owners and review dates
- Evidence of annual policy review and approval
- Cybersecurity risk management policy approved by leadership
- Policy linkage matrix to standards and procedures
- Board cyber accountability charter
- Executive cyber scorecard with named owners
- A documented awareness, education and training programme aligned with the policies and planned by role, including external personnel
- Completion records for initial training of new starters and role changers and for periodic refreshers
- Background check policy and completed checks for a sample of new hires and contractors
- Role competency requirements and performance review records
- Security awareness training content and completion records
- Published information security policies accessible to staff with change notices
- Security awareness program curriculum
- Completion records by population
- Current rules on safe, proper use of online resources
- Web filtering or secure web gateway configuration showing blocked categories such as malicious, phishing, command and control, illegal content and upload sites
- Anti-malware deployment and update status reports across endpoints, servers and gateways
- Application allowlisting and malicious website blocking configurations
- The topic-specific information transfer policy and its communication record
- Transfer agreements with third parties covering recipient authentication, protection levels, incident liability and labelling
- Endpoint protection coverage report across servers and workstations
- Local administrator and software installation restrictions
- Background check policy and completed checks for a sample of new hires and contractors
- Role competency requirements and performance review records
- Application allowlist policy and tooling configuration
- Endpoint protection deployment reports
- Security awareness program curriculum
- Completion records by population
No held control answers this line.
- Current rules on safe, proper use of online resources
- Web filtering or secure web gateway configuration showing blocked categories such as malicious, phishing, command and control, illegal content and upload sites
- Anti-malware deployment and update status reports across endpoints, servers and gateways
- Application allowlisting and malicious website blocking configurations
- The topic-specific information transfer policy and its communication record
- Transfer agreements with third parties covering recipient authentication, protection levels, incident liability and labelling
- Endpoint protection coverage report across servers and workstations
- Local administrator and software installation restrictions
- Background check policy and completed checks for a sample of new hires and contractors
- Role competency requirements and performance review records
- Application allowlist policy and tooling configuration
- Endpoint protection deployment reports
- Security awareness program curriculum
- Completion records by population
- Current rules on safe, proper use of online resources
- Web filtering or secure web gateway configuration showing blocked categories such as malicious, phishing, command and control, illegal content and upload sites
- Anti-malware deployment and update status reports across endpoints, servers and gateways
- Application allowlisting and malicious website blocking configurations
- The topic-specific information transfer policy and its communication record
- Transfer agreements with third parties covering recipient authentication, protection levels, incident liability and labelling
- Endpoint protection coverage report across servers and workstations
- Local administrator and software installation restrictions
- Background check policy and completed checks for a sample of new hires and contractors
- Role competency requirements and performance review records
- Application allowlist policy and tooling configuration
- Endpoint protection deployment reports
- Security awareness program curriculum
- Completion records by population
No held control answers this line.
- The topic-specific access control policy, approved and communicated, reflecting owner-defined business and security requirements
- Access control rules or role models mapping entities (users, services, devices) to rights, consistent with classification
- Identity management procedure covering creation, verification, activation, change, disablement and removal
- Evidence that identities are verified against trusted documents before issue
- Access request records showing owner authorization, and management approval where required, before rights were activated
- A central record of access rights per user identifier across logical and physical access
- Asset inventory with classification for in-scope systems
- Identity provider configuration showing MFA and password policy
- Access request tickets with owner approval for a sample of new users, service accounts and API credentials
- Termination records reconciled to account disablement dates
- Identity management platform configuration baseline
- Joiner mover leaver workflow with timing SLAs
- Access policy framework with role definitions
- Privileged access management deployment evidence
- The topic-specific access control policy, approved and communicated, reflecting owner-defined business and security requirements
- Access control rules or role models mapping entities (users, services, devices) to rights, consistent with classification
- Identity management procedure covering creation, verification, activation, change, disablement and removal
- Evidence that identities are verified against trusted documents before issue
- Access request records showing owner authorization, and management approval where required, before rights were activated
- A central record of access rights per user identifier across logical and physical access
- Asset inventory with classification for in-scope systems
- Identity provider configuration showing MFA and password policy
- Access request tickets with owner approval for a sample of new users, service accounts and API credentials
- Termination records reconciled to account disablement dates
- Identity management platform configuration baseline
- Joiner mover leaver workflow with timing SLAs
- Access policy framework with role definitions
- Privileged access management deployment evidence
This is a scoping question, not a control requirement. It reaches no held control.
No held control answers this line.
- The asset inventories (information, hardware, software, virtual, facilities and others) with owner, classification and location fields populated
- Reconciliation records between inventories and discovery tooling, or evidence that installs, changes and removals update the inventory automatically
- The topic-specific classification policy with named levels, criteria based on impact, and conventions covering confidentiality, integrity and availability
- Evidence the scheme was communicated to relevant interested parties and built into procedures
- Labelling procedures covering all formats, with rules on placement, exemptions and cases where labelling is not possible
- Examples of labelled documents, emails, reports and media showing the chosen techniques such as headers, watermarks or metadata
- Asset inventory with classification for in-scope systems
- Identity provider configuration showing MFA and password policy
- Hardware inventory with last seen and owner fields
- Automated discovery feeds reconciled against CMDB
- Software inventory with licensing and version data
- SaaS application register with owner and data class
- The topic-specific endpoint policy covering classification limits, registration, software restrictions, updates, network connection rules, encryption, malware protection, remote wipe, backup and port control
- Device management (MDM or endpoint management) reports showing enrolment, encryption, patch level, firewall and anti-malware status
- The topic-specific removable media policy and evidence it was communicated to users
- Endpoint configuration showing USB and SD ports disabled unless a business reason is approved, and monitoring of transfers to removable media
- The topic-specific remote working policy defining conditions, permitted work, information classifications allowed and systems accessible
- Remote access configuration showing multi-factor authentication, secure channels or virtual desktops
- Asset inventory with classification for in-scope systems
- Identity provider configuration showing MFA and password policy
- TLS and encryption standards for data in transit
- Removable media policy and technical enforcement
- Physical access control system inventory
- Badge issuance and revocation records
- Data at rest encryption inventory by store type
- Storage configuration baselines with attestation
- The topic-specific cryptography policy with approved algorithms, key lengths, protocols and usage by information classification
- Evidence of encryption on endpoints, removable media and data in transit, aligned with the policy
- The topic-specific removable media policy and evidence it was communicated to users
- Endpoint configuration showing USB and SD ports disabled unless a business reason is approved, and monitoring of transfers to removable media
- The topic-specific endpoint policy covering classification limits, registration, software restrictions, updates, network connection rules, encryption, malware protection, remote wipe, backup and port control
- Device management (MDM or endpoint management) reports showing enrolment, encryption, patch level, firewall and anti-malware status
- Asset inventory with classification for in-scope systems
- Identity provider configuration showing MFA and password policy
- TLS and encryption standards for data in transit
- Removable media policy and technical enforcement
- Data at rest encryption inventory by store type
- Storage configuration baselines with attestation
- TLS configuration standards and scan results
- VPN and zero trust network access policy
- The topic-specific endpoint policy covering classification limits, registration, software restrictions, updates, network connection rules, encryption, malware protection, remote wipe, backup and port control
- Device management (MDM or endpoint management) reports showing enrolment, encryption, patch level, firewall and anti-malware status
- The topic-specific removable media policy and evidence it was communicated to users
- Endpoint configuration showing USB and SD ports disabled unless a business reason is approved, and monitoring of transfers to removable media
- The topic-specific remote working policy defining conditions, permitted work, information classifications allowed and systems accessible
- Remote access configuration showing multi-factor authentication, secure channels or virtual desktops
- Asset inventory with classification for in-scope systems
- Identity provider configuration showing MFA and password policy
- TLS and encryption standards for data in transit
- Removable media policy and technical enforcement
- Physical access control system inventory
- Badge issuance and revocation records
- Data at rest encryption inventory by store type
- Storage configuration baselines with attestation
- The topic-specific endpoint policy covering classification limits, registration, software restrictions, updates, network connection rules, encryption, malware protection, remote wipe, backup and port control
- Device management (MDM or endpoint management) reports showing enrolment, encryption, patch level, firewall and anti-malware status
- The topic-specific removable media policy and evidence it was communicated to users
- Endpoint configuration showing USB and SD ports disabled unless a business reason is approved, and monitoring of transfers to removable media
- The topic-specific remote working policy defining conditions, permitted work, information classifications allowed and systems accessible
- Remote access configuration showing multi-factor authentication, secure channels or virtual desktops
- Asset inventory with classification for in-scope systems
- Identity provider configuration showing MFA and password policy
- TLS and encryption standards for data in transit
- Removable media policy and technical enforcement
- Physical access control system inventory
- Badge issuance and revocation records
- Data at rest encryption inventory by store type
- Storage configuration baselines with attestation
- Current network diagrams and device configuration backups for routers, switches, firewalls and wireless controllers
- Defined responsibilities and procedures for network device management, separated from system operations where appropriate
- Service agreements with internal and external network providers specifying security features, service levels and requirements
- Right-to-audit clauses and third-party attestations from network and managed security service providers, with records of review
- Network segmentation design defining domains by trust, criticality, sensitivity or organizational unit, with the assessment that justified it
- Firewall or filtering router rules controlling traffic between domains, with rule review records
- Firewall and security group rule sets with review evidence
- MFA enforced on VPN, remote and administrative access
- Network segmentation design with zones and trust levels
- Firewall and access control list governance
- Network flow telemetry coverage map by segment
- IDS or NDR sensor inventory with placement diagram
- Current network diagrams and device configuration backups for routers, switches, firewalls and wireless controllers
- Defined responsibilities and procedures for network device management, separated from system operations where appropriate
- Service agreements with internal and external network providers specifying security features, service levels and requirements
- Right-to-audit clauses and third-party attestations from network and managed security service providers, with records of review
- Network segmentation design defining domains by trust, criticality, sensitivity or organizational unit, with the assessment that justified it
- Firewall or filtering router rules controlling traffic between domains, with rule review records
- Firewall and security group rule sets with review evidence
- MFA enforced on VPN, remote and administrative access
- Network segmentation design with zones and trust levels
- Firewall and access control list governance
- Network flow telemetry coverage map by segment
- IDS or NDR sensor inventory with placement diagram
- Current network diagrams and device configuration backups for routers, switches, firewalls and wireless controllers
- Defined responsibilities and procedures for network device management, separated from system operations where appropriate
- Service agreements with internal and external network providers specifying security features, service levels and requirements
- Right-to-audit clauses and third-party attestations from network and managed security service providers, with records of review
- Network segmentation design defining domains by trust, criticality, sensitivity or organizational unit, with the assessment that justified it
- Firewall or filtering router rules controlling traffic between domains, with rule review records
- Firewall and security group rule sets with review evidence
- MFA enforced on VPN, remote and administrative access
- Badge access provisioning and removal records
- Periodic physical access review for sensitive areas
- Network segmentation design with zones and trust levels
- Firewall and access control list governance
- Network flow telemetry coverage map by segment
- IDS or NDR sensor inventory with placement diagram
Flagged knockout: the wording of this question makes a "no" a common point at which a cyber application is declined or referred.
- An inventory of privileged accounts per system (operating systems, databases, applications, cloud consoles) mapped to named individuals
- Authorization records for each privileged grant with approver, justification and expiry
- System, application and cloud storage configurations restricting access by identity or group, with granular permissions per action
- Evidence that anonymous or public access is limited to locations holding no sensitive information, for example storage bucket access reviews
- The topic-specific access control policy, approved and communicated, reflecting owner-defined business and security requirements
- Access control rules or role models mapping entities (users, services, devices) to rights, consistent with classification
- the bank or treasury platform dual-authorisation setup and the payment approval workflow, showing a second approver on a different device above the threshold
- the callback or out-of-band verification procedure for a change to payee bank details, with a dated example
- Asset inventory with classification for in-scope systems
- Identity provider configuration showing MFA and password policy
- Access policy framework with role definitions
- Privileged access management deployment evidence
- Identity management platform configuration baseline
- Joiner mover leaver workflow with timing SLAs
- The topic-specific access control policy, approved and communicated, reflecting owner-defined business and security requirements
- Access control rules or role models mapping entities (users, services, devices) to rights, consistent with classification
- Identity management procedure covering creation, verification, activation, change, disablement and removal
- Evidence that identities are verified against trusted documents before issue
- Access request records showing owner authorization, and management approval where required, before rights were activated
- A central record of access rights per user identifier across logical and physical access
- Asset inventory with classification for in-scope systems
- Identity provider configuration showing MFA and password policy
- Access request tickets with owner approval for a sample of new users, service accounts and API credentials
- Termination records reconciled to account disablement dates
- Identity management platform configuration baseline
- Joiner mover leaver workflow with timing SLAs
- Access policy framework with role definitions
- Privileged access management deployment evidence
- The topic-specific access control policy, approved and communicated, reflecting owner-defined business and security requirements
- Access control rules or role models mapping entities (users, services, devices) to rights, consistent with classification
- Identity management procedure covering creation, verification, activation, change, disablement and removal
- Evidence that identities are verified against trusted documents before issue
- Access request records showing owner authorization, and management approval where required, before rights were activated
- A central record of access rights per user identifier across logical and physical access
- Asset inventory with classification for in-scope systems
- Identity provider configuration showing MFA and password policy
- Access request tickets with owner approval for a sample of new users, service accounts and API credentials
- Termination records reconciled to account disablement dates
- Identity management platform configuration baseline
- Joiner mover leaver workflow with timing SLAs
- Access policy framework with role definitions
- Privileged access management deployment evidence
- The topic-specific access control policy, approved and communicated, reflecting owner-defined business and security requirements
- Access control rules or role models mapping entities (users, services, devices) to rights, consistent with classification
- Identity management procedure covering creation, verification, activation, change, disablement and removal
- Evidence that identities are verified against trusted documents before issue
- Access request records showing owner authorization, and management approval where required, before rights were activated
- A central record of access rights per user identifier across logical and physical access
- Asset inventory with classification for in-scope systems
- Identity provider configuration showing MFA and password policy
- Access request tickets with owner approval for a sample of new users, service accounts and API credentials
- Termination records reconciled to account disablement dates
- Identity management platform configuration baseline
- Joiner mover leaver workflow with timing SLAs
- Access policy framework with role definitions
- Privileged access management deployment evidence
- The topic-specific remote working policy defining conditions, permitted work, information classifications allowed and systems accessible
- Remote access configuration showing multi-factor authentication, secure channels or virtual desktops
- Current network diagrams and device configuration backups for routers, switches, firewalls and wireless controllers
- Defined responsibilities and procedures for network device management, separated from system operations where appropriate
- Network segmentation design defining domains by trust, criticality, sensitivity or organizational unit, with the assessment that justified it
- Firewall or filtering router rules controlling traffic between domains, with rule review records
- Firewall and security group rule sets with review evidence
- MFA enforced on VPN, remote and administrative access
- Network segmentation design with zones and trust levels
- Firewall and access control list governance
No held control answers this line.
Flagged knockout: the wording of this question makes a "no" a common point at which a cyber application is declined or referred.
- An inventory of privileged accounts per system (operating systems, databases, applications, cloud consoles) mapped to named individuals
- Authorization records for each privileged grant with approver, justification and expiry
- System, application and cloud storage configurations restricting access by identity or group, with granular permissions per action
- Evidence that anonymous or public access is limited to locations holding no sensitive information, for example storage bucket access reviews
- The topic-specific access control policy, approved and communicated, reflecting owner-defined business and security requirements
- Access control rules or role models mapping entities (users, services, devices) to rights, consistent with classification
- the bank or treasury platform dual-authorisation setup and the payment approval workflow, showing a second approver on a different device above the threshold
- the callback or out-of-band verification procedure for a change to payee bank details, with a dated example
- Asset inventory with classification for in-scope systems
- Identity provider configuration showing MFA and password policy
- Access policy framework with role definitions
- Privileged access management deployment evidence
Flagged knockout: the wording of this question makes a "no" a common point at which a cyber application is declined or referred.
- An inventory of privileged accounts per system (operating systems, databases, applications, cloud consoles) mapped to named individuals
- Authorization records for each privileged grant with approver, justification and expiry
- System, application and cloud storage configurations restricting access by identity or group, with granular permissions per action
- Evidence that anonymous or public access is limited to locations holding no sensitive information, for example storage bucket access reviews
- The topic-specific access control policy, approved and communicated, reflecting owner-defined business and security requirements
- Access control rules or role models mapping entities (users, services, devices) to rights, consistent with classification
- the bank or treasury platform dual-authorisation setup and the payment approval workflow, showing a second approver on a different device above the threshold
- the callback or out-of-band verification procedure for a change to payee bank details, with a dated example
- Asset inventory with classification for in-scope systems
- Identity provider configuration showing MFA and password policy
- Access policy framework with role definitions
- Privileged access management deployment evidence
Flagged knockout: the wording of this question makes a "no" a common point at which a cyber application is declined or referred.
- An inventory of privileged accounts per system (operating systems, databases, applications, cloud consoles) mapped to named individuals
- Authorization records for each privileged grant with approver, justification and expiry
- System, application and cloud storage configurations restricting access by identity or group, with granular permissions per action
- Evidence that anonymous or public access is limited to locations holding no sensitive information, for example storage bucket access reviews
- The topic-specific access control policy, approved and communicated, reflecting owner-defined business and security requirements
- Access control rules or role models mapping entities (users, services, devices) to rights, consistent with classification
- the bank or treasury platform dual-authorisation setup and the payment approval workflow, showing a second approver on a different device above the threshold
- the callback or out-of-band verification procedure for a change to payee bank details, with a dated example
- Asset inventory with classification for in-scope systems
- Identity provider configuration showing MFA and password policy
- Access policy framework with role definitions
- Privileged access management deployment evidence
- Network flow telemetry coverage map by segment
- IDS or NDR sensor inventory with placement diagram
Flagged knockout: the wording of this question makes a "no" a common point at which a cyber application is declined or referred.
- An inventory of privileged accounts per system (operating systems, databases, applications, cloud consoles) mapped to named individuals
- Authorization records for each privileged grant with approver, justification and expiry
- System, application and cloud storage configurations restricting access by identity or group, with granular permissions per action
- Evidence that anonymous or public access is limited to locations holding no sensitive information, for example storage bucket access reviews
- The topic-specific access control policy, approved and communicated, reflecting owner-defined business and security requirements
- Access control rules or role models mapping entities (users, services, devices) to rights, consistent with classification
- the bank or treasury platform dual-authorisation setup and the payment approval workflow, showing a second approver on a different device above the threshold
- the callback or out-of-band verification procedure for a change to payee bank details, with a dated example
- Asset inventory with classification for in-scope systems
- Identity provider configuration showing MFA and password policy
- Access policy framework with role definitions
- Privileged access management deployment evidence
Flagged knockout: the wording of this question makes a "no" a common point at which a cyber application is declined or referred.
- An inventory of privileged accounts per system (operating systems, databases, applications, cloud consoles) mapped to named individuals
- Authorization records for each privileged grant with approver, justification and expiry
- System, application and cloud storage configurations restricting access by identity or group, with granular permissions per action
- Evidence that anonymous or public access is limited to locations holding no sensitive information, for example storage bucket access reviews
- The topic-specific access control policy, approved and communicated, reflecting owner-defined business and security requirements
- Access control rules or role models mapping entities (users, services, devices) to rights, consistent with classification
- the bank or treasury platform dual-authorisation setup and the payment approval workflow, showing a second approver on a different device above the threshold
- the callback or out-of-band verification procedure for a change to payee bank details, with a dated example
- Asset inventory with classification for in-scope systems
- Identity provider configuration showing MFA and password policy
- Access policy framework with role definitions
- Privileged access management deployment evidence
Flagged knockout: the wording of this question makes a "no" a common point at which a cyber application is declined or referred.
- An inventory of privileged accounts per system (operating systems, databases, applications, cloud consoles) mapped to named individuals
- Authorization records for each privileged grant with approver, justification and expiry
- System, application and cloud storage configurations restricting access by identity or group, with granular permissions per action
- Evidence that anonymous or public access is limited to locations holding no sensitive information, for example storage bucket access reviews
- The topic-specific access control policy, approved and communicated, reflecting owner-defined business and security requirements
- Access control rules or role models mapping entities (users, services, devices) to rights, consistent with classification
- the bank or treasury platform dual-authorisation setup and the payment approval workflow, showing a second approver on a different device above the threshold
- the callback or out-of-band verification procedure for a change to payee bank details, with a dated example
- Asset inventory with classification for in-scope systems
- Identity provider configuration showing MFA and password policy
- Access policy framework with role definitions
- Privileged access management deployment evidence
- Identity management platform configuration baseline
- Joiner mover leaver workflow with timing SLAs
- An inventory of privileged accounts per system (operating systems, databases, applications, cloud consoles) mapped to named individuals
- Authorization records for each privileged grant with approver, justification and expiry
- System, application and cloud storage configurations restricting access by identity or group, with granular permissions per action
- Evidence that anonymous or public access is limited to locations holding no sensitive information, for example storage bucket access reviews
- The topic-specific access control policy, approved and communicated, reflecting owner-defined business and security requirements
- Access control rules or role models mapping entities (users, services, devices) to rights, consistent with classification
- the bank or treasury platform dual-authorisation setup and the payment approval workflow, showing a second approver on a different device above the threshold
- the callback or out-of-band verification procedure for a change to payee bank details, with a dated example
- Asset inventory with classification for in-scope systems
- Identity provider configuration showing MFA and password policy
- Access policy framework with role definitions
- Privileged access management deployment evidence
- Network flow telemetry coverage map by segment
- IDS or NDR sensor inventory with placement diagram
Flagged knockout: the wording of this question makes a "no" a common point at which a cyber application is declined or referred.
- An inventory of privileged accounts per system (operating systems, databases, applications, cloud consoles) mapped to named individuals
- Authorization records for each privileged grant with approver, justification and expiry
- System, application and cloud storage configurations restricting access by identity or group, with granular permissions per action
- Evidence that anonymous or public access is limited to locations holding no sensitive information, for example storage bucket access reviews
- The topic-specific access control policy, approved and communicated, reflecting owner-defined business and security requirements
- Access control rules or role models mapping entities (users, services, devices) to rights, consistent with classification
- the bank or treasury platform dual-authorisation setup and the payment approval workflow, showing a second approver on a different device above the threshold
- the callback or out-of-band verification procedure for a change to payee bank details, with a dated example
- Asset inventory with classification for in-scope systems
- Identity provider configuration showing MFA and password policy
- Access policy framework with role definitions
- Privileged access management deployment evidence
- Network flow telemetry coverage map by segment
- IDS or NDR sensor inventory with placement diagram
Flagged knockout: the wording of this question makes a "no" a common point at which a cyber application is declined or referred.
- An inventory of privileged accounts per system (operating systems, databases, applications, cloud consoles) mapped to named individuals
- Authorization records for each privileged grant with approver, justification and expiry
- System, application and cloud storage configurations restricting access by identity or group, with granular permissions per action
- Evidence that anonymous or public access is limited to locations holding no sensitive information, for example storage bucket access reviews
- The topic-specific access control policy, approved and communicated, reflecting owner-defined business and security requirements
- Access control rules or role models mapping entities (users, services, devices) to rights, consistent with classification
- the bank or treasury platform dual-authorisation setup and the payment approval workflow, showing a second approver on a different device above the threshold
- the callback or out-of-band verification procedure for a change to payee bank details, with a dated example
- Asset inventory with classification for in-scope systems
- Identity provider configuration showing MFA and password policy
- Access policy framework with role definitions
- Privileged access management deployment evidence
- The topic-specific cryptography policy with approved algorithms, key lengths, protocols and usage by information classification
- Evidence of encryption on endpoints, removable media and data in transit, aligned with the policy
- The topic-specific information transfer policy and its communication record
- Transfer agreements with third parties covering recipient authentication, protection levels, incident liability and labelling
- TLS and encryption standards for data in transit
- Removable media policy and technical enforcement
- Asset inventory with classification for in-scope systems
- Identity provider configuration showing MFA and password policy
- TLS configuration standards and scan results
- VPN and zero trust network access policy
- Data at rest encryption inventory by store type
- Storage configuration baselines with attestation
- The topic-specific cryptography policy with approved algorithms, key lengths, protocols and usage by information classification
- Evidence of encryption on endpoints, removable media and data in transit, aligned with the policy
- The topic-specific removable media policy and evidence it was communicated to users
- Endpoint configuration showing USB and SD ports disabled unless a business reason is approved, and monitoring of transfers to removable media
- The topic-specific endpoint policy covering classification limits, registration, software restrictions, updates, network connection rules, encryption, malware protection, remote wipe, backup and port control
- Device management (MDM or endpoint management) reports showing enrolment, encryption, patch level, firewall and anti-malware status
- Asset inventory with classification for in-scope systems
- Identity provider configuration showing MFA and password policy
- TLS and encryption standards for data in transit
- Removable media policy and technical enforcement
- Data at rest encryption inventory by store type
- Storage configuration baselines with attestation
- TLS configuration standards and scan results
- VPN and zero trust network access policy
- Site plans showing defined security perimeters and their strength relative to the assets inside
- Physical security surveys or assessments of walls, roofs, floors, doors, windows and vents
- Physical access rights records with provisioning, periodic review and revocation evidence
- Electronic access control logs or physical logbooks, protected and monitored
- Facility security design documentation showing critical facilities sited away from public access
- Photographs or survey records confirming the absence of signage revealing processing facilities
- Badge access provisioning and removal records
- Periodic physical access review for sensitive areas
- Media sanitisation and disposal procedure
- Certificates of destruction or wipe logs for disposed devices
- Physical access control system inventory
- Badge issuance and revocation records
- Environmental controls inventory (HVAC, power, fire)
- Site risk assessments with mitigation status
This is a scoping question, not a control requirement. It reaches no held control.
No held control answers this line.
No held control answers this line.
- The topic-specific backup policy and backup plans stating scope, extent, frequency and retention per system aligned with RPO
- Backup job monitoring reports with evidence that failed jobs were investigated and rerun
- Documented availability requirements for business services and systems
- Architecture diagrams showing redundancy such as dual providers, redundant networks, separate data centres, redundant power and load-balanced instances
- Backup policy defining scope, frequency and retention
- Backup job monitoring and failure remediation records
- Disaster recovery or continuity test plan and results in the period
- Backup restore test records with verification of completeness
- Backup policy with frequency and retention
- Backup integrity test reports
Flagged knockout: the wording of this question makes a "no" a common point at which a cyber application is declined or referred.
- Credential issuance procedure requiring identity verification before new, replacement or temporary credentials are provided
- Evidence that initial credentials are unique, delivered over protected channels and changed at first use
- An authentication standard linking required authentication strength to information classification and system criticality
- MFA configuration and coverage reports for critical systems, remote access and privileged access, including conditional or risk-based rules
- The topic-specific backup policy and backup plans stating scope, extent, frequency and retention per system aligned with RPO
- Backup job monitoring reports with evidence that failed jobs were investigated and rerun
- Asset inventory with classification for in-scope systems
- Identity provider configuration showing MFA and password policy
- Backup policy defining scope, frequency and retention
- Backup job monitoring and failure remediation records
- Identity management platform configuration baseline
- Joiner mover leaver workflow with timing SLAs
- Backup policy with frequency and retention
- Backup integrity test reports
Flagged knockout: the wording of this question makes a "no" a common point at which a cyber application is declined or referred.
- The topic-specific backup policy and backup plans stating scope, extent, frequency and retention per system aligned with RPO
- Backup job monitoring reports with evidence that failed jobs were investigated and rerun
- Documented availability requirements for business services and systems
- Architecture diagrams showing redundancy such as dual providers, redundant networks, separate data centres, redundant power and load-balanced instances
- Backup policy defining scope, frequency and retention
- Backup job monitoring and failure remediation records
- Disaster recovery or continuity test plan and results in the period
- Backup restore test records with verification of completeness
- Backup policy with frequency and retention
- Backup integrity test reports
- The topic-specific logging policy defining purposes, events to be logged, fields captured, retention and protection
- A documented monitoring scope covering network traffic, system access, configuration files, security tool logs, code integrity and resource use, with retention periods
- Baselines of normal behaviour for systems and user groups, and the detection rules built on them
- Hardening standards or benchmarks for in-scope platforms
- Configuration compliance scan results
- Alert rules and sample of triaged alerts
- Threat intelligence sources in use
- Network flow telemetry coverage map by segment
- IDS or NDR sensor inventory with placement diagram
- Logging policy by data class and system tier
- Centralized log collection architecture
- A software asset inventory with vendor, product, version, deployment location and responsible owner
- Defined vulnerability management roles and a list of monitored vulnerability information sources
- Procedures for installing and updating operational software, including authorization, testing and rollback planning
- Change and deployment records showing management authorization, successful testing and the administrator who performed the installation
- Security test plans with schedules, inputs, expected outputs, evaluation criteria and decisions, scaled to the system's importance and change impact
- Security test results covering authentication, access restriction, cryptography, secure coding and configuration
- Hardening standards or benchmarks for in-scope platforms
- Configuration compliance scan results
- Vulnerability scanning coverage report
- Vulnerability triage workflow with severity SLAs
- Software lifecycle policy with end of support tracking
- Patch management cadence and exception register
No held control answers this line.
No held control answers this line.
No held control answers this line.
- An authentication standard linking required authentication strength to information classification and system criticality
- MFA configuration and coverage reports for critical systems, remote access and privileged access, including conditional or risk-based rules
- The topic-specific access control policy, approved and communicated, reflecting owner-defined business and security requirements
- Access control rules or role models mapping entities (users, services, devices) to rights, consistent with classification
- Asset inventory with classification for in-scope systems
- Identity provider configuration showing MFA and password policy
- Multi factor authentication coverage report
- Phishing resistant authentication rollout plan
- The topic-specific logging policy defining purposes, events to be logged, fields captured, retention and protection
- A documented monitoring scope covering network traffic, system access, configuration files, security tool logs, code integrity and resource use, with retention periods
- Baselines of normal behaviour for systems and user groups, and the detection rules built on them
- An authentication standard linking required authentication strength to information classification and system criticality
- MFA configuration and coverage reports for critical systems, remote access and privileged access, including conditional or risk-based rules
- Hardening standards or benchmarks for in-scope platforms
- Configuration compliance scan results
- Alert rules and sample of triaged alerts
- Threat intelligence sources in use
- Network flow telemetry coverage map by segment
- IDS or NDR sensor inventory with placement diagram
- Logging policy by data class and system tier
- Centralized log collection architecture
Flagged knockout: the wording of this question makes a "no" a common point at which a cyber application is declined or referred.
- An authentication standard linking required authentication strength to information classification and system criticality
- MFA configuration and coverage reports for critical systems, remote access and privileged access, including conditional or risk-based rules
- Credential issuance procedure requiring identity verification before new, replacement or temporary credentials are provided
- Evidence that initial credentials are unique, delivered over protected channels and changed at first use
- The topic-specific access control policy, approved and communicated, reflecting owner-defined business and security requirements
- Access control rules or role models mapping entities (users, services, devices) to rights, consistent with classification
- Asset inventory with classification for in-scope systems
- Identity provider configuration showing MFA and password policy
- Multi factor authentication coverage report
- Phishing resistant authentication rollout plan
This is a scoping question, not a control requirement. It reaches no held control.
No held control answers this line.
- Current rules on safe, proper use of online resources
- Web filtering or secure web gateway configuration showing blocked categories such as malicious, phishing, command and control, illegal content and upload sites
- Anti-malware deployment and update status reports across endpoints, servers and gateways
- Application allowlisting and malicious website blocking configurations
- The topic-specific information transfer policy and its communication record
- Transfer agreements with third parties covering recipient authentication, protection levels, incident liability and labelling
- Endpoint protection coverage report across servers and workstations
- Local administrator and software installation restrictions
- Application allowlist policy and tooling configuration
- Endpoint protection deployment reports
- An inventory of information types and classifications in scope for leakage protection
- DLP policies and rules covering email, web uploads, file transfer, endpoints and removable storage, with the actions taken (alert, quarantine, block)
- The topic-specific cryptography policy with approved algorithms, key lengths, protocols and usage by information classification
- Evidence of encryption on endpoints, removable media and data in transit, aligned with the policy
- TLS and encryption standards for data in transit
- Removable media policy and technical enforcement
- Data classification policy defining confidential information
- Data inventory tagging confidential data and its retention period
- Data at rest encryption inventory by store type
- Storage configuration baselines with attestation
- TLS configuration standards and scan results
- VPN and zero trust network access policy
- An inventory of information types and classifications in scope for leakage protection
- DLP policies and rules covering email, web uploads, file transfer, endpoints and removable storage, with the actions taken (alert, quarantine, block)
- The topic-specific cryptography policy with approved algorithms, key lengths, protocols and usage by information classification
- Evidence of encryption on endpoints, removable media and data in transit, aligned with the policy
- TLS and encryption standards for data in transit
- Removable media policy and technical enforcement
- Data classification policy defining confidential information
- Data inventory tagging confidential data and its retention period
- Data at rest encryption inventory by store type
- Storage configuration baselines with attestation
- TLS configuration standards and scan results
- VPN and zero trust network access policy
- Current rules on safe, proper use of online resources
- Web filtering or secure web gateway configuration showing blocked categories such as malicious, phishing, command and control, illegal content and upload sites
- Anti-malware deployment and update status reports across endpoints, servers and gateways
- Application allowlisting and malicious website blocking configurations
- The topic-specific information transfer policy and its communication record
- Transfer agreements with third parties covering recipient authentication, protection levels, incident liability and labelling
- Endpoint protection coverage report across servers and workstations
- Local administrator and software installation restrictions
- Application allowlist policy and tooling configuration
- Endpoint protection deployment reports
- Current rules on safe, proper use of online resources
- Web filtering or secure web gateway configuration showing blocked categories such as malicious, phishing, command and control, illegal content and upload sites
- Anti-malware deployment and update status reports across endpoints, servers and gateways
- Application allowlisting and malicious website blocking configurations
- The topic-specific information transfer policy and its communication record
- Transfer agreements with third parties covering recipient authentication, protection levels, incident liability and labelling
- Endpoint protection coverage report across servers and workstations
- Local administrator and software installation restrictions
- Application allowlist policy and tooling configuration
- Endpoint protection deployment reports
- Current rules on safe, proper use of online resources
- Web filtering or secure web gateway configuration showing blocked categories such as malicious, phishing, command and control, illegal content and upload sites
- Anti-malware deployment and update status reports across endpoints, servers and gateways
- Application allowlisting and malicious website blocking configurations
- The topic-specific information transfer policy and its communication record
- Transfer agreements with third parties covering recipient authentication, protection levels, incident liability and labelling
- Endpoint protection coverage report across servers and workstations
- Local administrator and software installation restrictions
- Badge access provisioning and removal records
- Periodic physical access review for sensitive areas
- Application allowlist policy and tooling configuration
- Endpoint protection deployment reports
- Physical access control system inventory
- Badge issuance and revocation records
- The topic-specific logging policy defining purposes, events to be logged, fields captured, retention and protection
- A documented monitoring scope covering network traffic, system access, configuration files, security tool logs, code integrity and resource use, with retention periods
- Baselines of normal behaviour for systems and user groups, and the detection rules built on them
- Current rules on safe, proper use of online resources
- Web filtering or secure web gateway configuration showing blocked categories such as malicious, phishing, command and control, illegal content and upload sites
- Hardening standards or benchmarks for in-scope platforms
- Configuration compliance scan results
- Alert rules and sample of triaged alerts
- Threat intelligence sources in use
- Network flow telemetry coverage map by segment
- IDS or NDR sensor inventory with placement diagram
- Logging policy by data class and system tier
- Centralized log collection architecture
- Current network diagrams and device configuration backups for routers, switches, firewalls and wireless controllers
- Defined responsibilities and procedures for network device management, separated from system operations where appropriate
- Service agreements with internal and external network providers specifying security features, service levels and requirements
- Right-to-audit clauses and third-party attestations from network and managed security service providers, with records of review
- Network segmentation design defining domains by trust, criticality, sensitivity or organizational unit, with the assessment that justified it
- Firewall or filtering router rules controlling traffic between domains, with rule review records
- Firewall and security group rule sets with review evidence
- MFA enforced on VPN, remote and administrative access
- Network segmentation design with zones and trust levels
- Firewall and access control list governance
- Network flow telemetry coverage map by segment
- IDS or NDR sensor inventory with placement diagram
This is a media liability question, not a control requirement. It reaches no held control.
No held control answers this line.
No held control answers this line.
No held control answers this line.
No held control answers this line.
- Current network diagrams and device configuration backups for routers, switches, firewalls and wireless controllers
- Defined responsibilities and procedures for network device management, separated from system operations where appropriate
- Service agreements with internal and external network providers specifying security features, service levels and requirements
- Right-to-audit clauses and third-party attestations from network and managed security service providers, with records of review
- Network segmentation design defining domains by trust, criticality, sensitivity or organizational unit, with the assessment that justified it
- Firewall or filtering router rules controlling traffic between domains, with rule review records
- Firewall and security group rule sets with review evidence
- MFA enforced on VPN, remote and administrative access
- Network segmentation design with zones and trust levels
- Firewall and access control list governance
- Network flow telemetry coverage map by segment
- IDS or NDR sensor inventory with placement diagram
This is a scoping question, not a control requirement. It reaches no held control.
No held control answers this line.
- Current network diagrams and device configuration backups for routers, switches, firewalls and wireless controllers
- Defined responsibilities and procedures for network device management, separated from system operations where appropriate
- Service agreements with internal and external network providers specifying security features, service levels and requirements
- Right-to-audit clauses and third-party attestations from network and managed security service providers, with records of review
- Network segmentation design defining domains by trust, criticality, sensitivity or organizational unit, with the assessment that justified it
- Firewall or filtering router rules controlling traffic between domains, with rule review records
- Firewall and security group rule sets with review evidence
- MFA enforced on VPN, remote and administrative access
- Change management policy covering normal, standard and emergency changes
- Sample of change tickets with approval, testing evidence and deployer different from author
- Network segmentation design with zones and trust levels
- Firewall and access control list governance
- Network flow telemetry coverage map by segment
- IDS or NDR sensor inventory with placement diagram
- Current network diagrams and device configuration backups for routers, switches, firewalls and wireless controllers
- Defined responsibilities and procedures for network device management, separated from system operations where appropriate
- Service agreements with internal and external network providers specifying security features, service levels and requirements
- Right-to-audit clauses and third-party attestations from network and managed security service providers, with records of review
- Network segmentation design defining domains by trust, criticality, sensitivity or organizational unit, with the assessment that justified it
- Firewall or filtering router rules controlling traffic between domains, with rule review records
- Firewall and security group rule sets with review evidence
- MFA enforced on VPN, remote and administrative access
- Network segmentation design with zones and trust levels
- Firewall and access control list governance
- Network flow telemetry coverage map by segment
- IDS or NDR sensor inventory with placement diagram
- Approved secure configuration templates or baselines for each platform, derived from vendor or independent guidance, with review dates
- Configuration records or a CMDB showing owner, last change date, template version and relationships between assets
- Change management policy covering normal, standard and emergency changes
- Sample of change tickets with approval, testing evidence and deployer different from author
- Configuration management standards by platform
- Hardening baselines and compliance reports
- Documented secure development rules or SDLC standard covering environments, methodology, coding guidelines, security requirements, checkpoints, testing, repositories and version control
- Secure coding guidelines for each language in use
- Approved application security requirements documents for new or acquired applications, derived from risk assessment with security specialist input
- Requirement checklists covering authentication, classification, access segregation, attack resilience, legal and privacy needs, data protection, encryption, input and output controls, logging and error handling
- Secure coding standards and a minimum baseline applying to in-house and outsourced development, updated from current threat and vulnerability information
- IDE and pipeline configuration enforcing secure coding checks, including SAST results and remediation records
- Change management policy covering normal, standard and emergency changes
- Sample of change tickets with approval, testing evidence and deployer different from author
- Job scheduling and processing monitoring with failure alerts
- Error queues and evidence of correction
- Secure SDLC standard with control gates
- Threat modeling outputs per project
- Quality assurance procedure for risk assessments
- Peer review records on assessment outputs
- A documented awareness, education and training programme aligned with the policies and planned by role, including external personnel
- Completion records for initial training of new starters and role changers and for periodic refreshers
- Documented secure development rules or SDLC standard covering environments, methodology, coding guidelines, security requirements, checkpoints, testing, repositories and version control
- Secure coding guidelines for each language in use
- Approved application security requirements documents for new or acquired applications, derived from risk assessment with security specialist input
- Requirement checklists covering authentication, classification, access segregation, attack resilience, legal and privacy needs, data protection, encryption, input and output controls, logging and error handling
- Background check policy and completed checks for a sample of new hires and contractors
- Role competency requirements and performance review records
- Security awareness training content and completion records
- Published information security policies accessible to staff with change notices
- Security awareness program curriculum
- Completion records by population
- Secure SDLC standard with control gates
- Threat modeling outputs per project
- A software asset inventory with vendor, product, version, deployment location and responsible owner
- Defined vulnerability management roles and a list of monitored vulnerability information sources
- Procedures for installing and updating operational software, including authorization, testing and rollback planning
- Change and deployment records showing management authorization, successful testing and the administrator who performed the installation
- Security test plans with schedules, inputs, expected outputs, evaluation criteria and decisions, scaled to the system's importance and change impact
- Security test results covering authentication, access restriction, cryptography, secure coding and configuration
- Hardening standards or benchmarks for in-scope platforms
- Configuration compliance scan results
- Change management policy covering normal, standard and emergency changes
- Sample of change tickets with approval, testing evidence and deployer different from author
- Vulnerability scanning coverage report
- Vulnerability triage workflow with severity SLAs
- Software lifecycle policy with end of support tracking
- Patch management cadence and exception register
No held control answers this line.
- A software asset inventory with vendor, product, version, deployment location and responsible owner
- Defined vulnerability management roles and a list of monitored vulnerability information sources
- Procedures for installing and updating operational software, including authorization, testing and rollback planning
- Change and deployment records showing management authorization, successful testing and the administrator who performed the installation
- Security test plans with schedules, inputs, expected outputs, evaluation criteria and decisions, scaled to the system's importance and change impact
- Security test results covering authentication, access restriction, cryptography, secure coding and configuration
- Hardening standards or benchmarks for in-scope platforms
- Configuration compliance scan results
- Change management policy covering normal, standard and emergency changes
- Sample of change tickets with approval, testing evidence and deployer different from author
- Vulnerability scanning coverage report
- Vulnerability triage workflow with severity SLAs
- Software lifecycle policy with end of support tracking
- Patch management cadence and exception register
- The topic-specific classification policy with named levels, criteria based on impact, and conventions covering confidentiality, integrity and availability
- Evidence the scheme was communicated to relevant interested parties and built into procedures
- Labelling procedures covering all formats, with rules on placement, exemptions and cases where labelling is not possible
- Examples of labelled documents, emails, reports and media showing the chosen techniques such as headers, watermarks or metadata
- The topic-specific supplier relationship policy and its communication record
- A supplier inventory categorized by type and by the information, services and infrastructure each can access
- Asset inventory with classification for in-scope systems
- Identity provider configuration showing MFA and password policy
- Vendor inventory with risk tiers and the review frequency set for each tier
- Due diligence records, for example vendor SOC reports reviewed with complementary controls noted
- Asset prioritization scoring model
- Criticality ratings stored in CMDB
- Data inventory with classification and location
- Metadata tagging policy enforced in storage
- The topic-specific supplier relationship policy and its communication record
- A supplier inventory categorized by type and by the information, services and infrastructure each can access
- Supplier agreements containing security clauses proportionate to the relationship, such as classification mapping, agreed controls, incident notification, subcontracting, right to audit and termination terms
- A register of contracts, memoranda and information-sharing arrangements with outside parties showing what information each covers and when it was last reviewed
- Security requirements included in ICT acquisition specifications and contracts, including flow-down to sub-suppliers
- Software component information such as SBOMs and descriptions of security functions and secure configuration obtained from product suppliers
- Vendor inventory with risk tiers and the review frequency set for each tier
- Due diligence records, for example vendor SOC reports reviewed with complementary controls noted
- Data processing agreements with privacy clauses
- Periodic assessments of vendors' privacy compliance
- Third party risk management program charter
- Supplier risk policy with tiering criteria
- Standard supplier security requirements catalog
- Contract clause library with cyber obligations
- The topic-specific supplier relationship policy and its communication record
- A supplier inventory categorized by type and by the information, services and infrastructure each can access
- Supplier agreements containing security clauses proportionate to the relationship, such as classification mapping, agreed controls, incident notification, subcontracting, right to audit and termination terms
- A register of contracts, memoranda and information-sharing arrangements with outside parties showing what information each covers and when it was last reviewed
- Security requirements included in ICT acquisition specifications and contracts, including flow-down to sub-suppliers
- Software component information such as SBOMs and descriptions of security functions and secure configuration obtained from product suppliers
- Vendor inventory with risk tiers and the review frequency set for each tier
- Due diligence records, for example vendor SOC reports reviewed with complementary controls noted
- Data processing agreements with privacy clauses
- Periodic assessments of vendors' privacy compliance
- Third party risk management program charter
- Supplier risk policy with tiering criteria
- Standard supplier security requirements catalog
- Contract clause library with cyber obligations
- The topic-specific supplier relationship policy and its communication record
- A supplier inventory categorized by type and by the information, services and infrastructure each can access
- Supplier agreements containing security clauses proportionate to the relationship, such as classification mapping, agreed controls, incident notification, subcontracting, right to audit and termination terms
- A register of contracts, memoranda and information-sharing arrangements with outside parties showing what information each covers and when it was last reviewed
- Security requirements included in ICT acquisition specifications and contracts, including flow-down to sub-suppliers
- Software component information such as SBOMs and descriptions of security functions and secure configuration obtained from product suppliers
- Vendor inventory with risk tiers and the review frequency set for each tier
- Due diligence records, for example vendor SOC reports reviewed with complementary controls noted
- Data processing agreements with privacy clauses
- Periodic assessments of vendors' privacy compliance
- Third party risk management program charter
- Supplier risk policy with tiering criteria
- Standard supplier security requirements catalog
- Contract clause library with cyber obligations
- The topic-specific access control policy, approved and communicated, reflecting owner-defined business and security requirements
- Access control rules or role models mapping entities (users, services, devices) to rights, consistent with classification
- Identity management procedure covering creation, verification, activation, change, disablement and removal
- Evidence that identities are verified against trusted documents before issue
- Access request records showing owner authorization, and management approval where required, before rights were activated
- A central record of access rights per user identifier across logical and physical access
- Asset inventory with classification for in-scope systems
- Identity provider configuration showing MFA and password policy
- Access request tickets with owner approval for a sample of new users, service accounts and API credentials
- Termination records reconciled to account disablement dates
- Identity management platform configuration baseline
- Joiner mover leaver workflow with timing SLAs
- Access policy framework with role definitions
- Privileged access management deployment evidence
- The topic-specific logging policy defining purposes, events to be logged, fields captured, retention and protection
- A documented monitoring scope covering network traffic, system access, configuration files, security tool logs, code integrity and resource use, with retention periods
- Baselines of normal behaviour for systems and user groups, and the detection rules built on them
- The topic-specific access control policy, approved and communicated, reflecting owner-defined business and security requirements
- Access control rules or role models mapping entities (users, services, devices) to rights, consistent with classification
- Hardening standards or benchmarks for in-scope platforms
- Configuration compliance scan results
- Alert rules and sample of triaged alerts
- Threat intelligence sources in use
- Network flow telemetry coverage map by segment
- IDS or NDR sensor inventory with placement diagram
- Logging policy by data class and system tier
- Centralized log collection architecture
- An approved incident management plan and procedures covering evaluation, detection, classification, escalation, recovery, communication, evidence handling and post-incident review
- Incident management objectives and priorities agreed with management, including resolution time frames by severity
- The agreed incident categorization and prioritization scheme with criteria for declaring an incident and consequence levels
- Triage records showing each reported event assessed against the scheme
- Documented incident response procedures or playbooks communicated to relevant parties
- Incident records showing containment, evidence collection, escalation, communication and formal closure
- Incident classification and severity criteria
- Security event log showing triage decisions
- Incident response plan with roles and contact lists
- Incident tickets showing containment, eradication, recovery and communication
- Incident response plan with third party invocation
- Retainer contract evidence for IR vendor
- Incident notification policy and timing matrix
- Internal stakeholder communication templates
- An approved incident management plan and procedures covering evaluation, detection, classification, escalation, recovery, communication, evidence handling and post-incident review
- Incident management objectives and priorities agreed with management, including resolution time frames by severity
- The agreed incident categorization and prioritization scheme with criteria for declaring an incident and consequence levels
- Triage records showing each reported event assessed against the scheme
- Documented incident response procedures or playbooks communicated to relevant parties
- Incident records showing containment, evidence collection, escalation, communication and formal closure
- Incident classification and severity criteria
- Security event log showing triage decisions
- Incident response plan with roles and contact lists
- Incident tickets showing containment, eradication, recovery and communication
- Incident response plan with third party invocation
- Retainer contract evidence for IR vendor
- Incident notification policy and timing matrix
- Internal stakeholder communication templates
- The topic-specific logging policy defining purposes, events to be logged, fields captured, retention and protection
- A documented monitoring scope covering network traffic, system access, configuration files, security tool logs, code integrity and resource use, with retention periods
- Baselines of normal behaviour for systems and user groups, and the detection rules built on them
- Hardening standards or benchmarks for in-scope platforms
- Configuration compliance scan results
- Alert rules and sample of triaged alerts
- Threat intelligence sources in use
- Network flow telemetry coverage map by segment
- IDS or NDR sensor inventory with placement diagram
- Logging policy by data class and system tier
- Centralized log collection architecture
- The topic-specific logging policy defining purposes, events to be logged, fields captured, retention and protection
- A documented monitoring scope covering network traffic, system access, configuration files, security tool logs, code integrity and resource use, with retention periods
- Baselines of normal behaviour for systems and user groups, and the detection rules built on them
- Hardening standards or benchmarks for in-scope platforms
- Configuration compliance scan results
- Alert rules and sample of triaged alerts
- Threat intelligence sources in use
- Network flow telemetry coverage map by segment
- IDS or NDR sensor inventory with placement diagram
- Logging policy by data class and system tier
- Centralized log collection architecture
- The topic-specific logging policy defining purposes, events to be logged, fields captured, retention and protection
- A documented monitoring scope covering network traffic, system access, configuration files, security tool logs, code integrity and resource use, with retention periods
- Baselines of normal behaviour for systems and user groups, and the detection rules built on them
- Hardening standards or benchmarks for in-scope platforms
- Configuration compliance scan results
- Alert rules and sample of triaged alerts
- Threat intelligence sources in use
- Network flow telemetry coverage map by segment
- IDS or NDR sensor inventory with placement diagram
- Logging policy by data class and system tier
- Centralized log collection architecture
- The topic-specific logging policy defining purposes, events to be logged, fields captured, retention and protection
- A documented monitoring scope covering network traffic, system access, configuration files, security tool logs, code integrity and resource use, with retention periods
- Baselines of normal behaviour for systems and user groups, and the detection rules built on them
- Hardening standards or benchmarks for in-scope platforms
- Configuration compliance scan results
- Alert rules and sample of triaged alerts
- Threat intelligence sources in use
- Network flow telemetry coverage map by segment
- IDS or NDR sensor inventory with placement diagram
- Logging policy by data class and system tier
- Centralized log collection architecture
- Business continuity plans that contain information security requirements and the controls, systems and tools needed during disruption
- A documented analysis of which security controls must be adapted during disruption and how
- The business impact analysis with prioritized activities, supporting ICT services and their RTOs, and RPOs for required information
- Selected ICT continuity strategies covering before, during and after disruption
- Documented availability requirements for business services and systems
- Architecture diagrams showing redundancy such as dual providers, redundant networks, separate data centres, redundant power and load-balanced instances
- Business continuity and disaster recovery plans covering the in-scope service
- Business impact analysis
- Backup policy defining scope, frequency and retention
- Backup job monitoring and failure remediation records
- Resilience architecture patterns for critical services
- Failover and failback tested with evidence
- Recovery plan with triggers and decision rights
- Execution log of recovery activities
No held control answers this line.
- Business continuity plans that contain information security requirements and the controls, systems and tools needed during disruption
- A documented analysis of which security controls must be adapted during disruption and how
- The business impact analysis with prioritized activities, supporting ICT services and their RTOs, and RPOs for required information
- Selected ICT continuity strategies covering before, during and after disruption
- Documented availability requirements for business services and systems
- Architecture diagrams showing redundancy such as dual providers, redundant networks, separate data centres, redundant power and load-balanced instances
- Business continuity and disaster recovery plans covering the in-scope service
- Business impact analysis
- Backup policy defining scope, frequency and retention
- Backup job monitoring and failure remediation records
- Resilience architecture patterns for critical services
- Failover and failback tested with evidence
- Recovery plan with triggers and decision rights
- Execution log of recovery activities
- Business continuity plans that contain information security requirements and the controls, systems and tools needed during disruption
- A documented analysis of which security controls must be adapted during disruption and how
- The business impact analysis with prioritized activities, supporting ICT services and their RTOs, and RPOs for required information
- Selected ICT continuity strategies covering before, during and after disruption
- Documented availability requirements for business services and systems
- Architecture diagrams showing redundancy such as dual providers, redundant networks, separate data centres, redundant power and load-balanced instances
- Business continuity and disaster recovery plans covering the in-scope service
- Business impact analysis
- Backup policy defining scope, frequency and retention
- Backup job monitoring and failure remediation records
- Resilience architecture patterns for critical services
- Failover and failback tested with evidence
- Recovery plan with triggers and decision rights
- Execution log of recovery activities
- Business continuity plans that contain information security requirements and the controls, systems and tools needed during disruption
- A documented analysis of which security controls must be adapted during disruption and how
- The business impact analysis with prioritized activities, supporting ICT services and their RTOs, and RPOs for required information
- Selected ICT continuity strategies covering before, during and after disruption
- Documented availability requirements for business services and systems
- Architecture diagrams showing redundancy such as dual providers, redundant networks, separate data centres, redundant power and load-balanced instances
- Business continuity and disaster recovery plans covering the in-scope service
- Business impact analysis
- Backup policy defining scope, frequency and retention
- Backup job monitoring and failure remediation records
- Resilience architecture patterns for critical services
- Failover and failback tested with evidence
- Recovery plan with triggers and decision rights
- Execution log of recovery activities
- Business continuity plans that contain information security requirements and the controls, systems and tools needed during disruption
- A documented analysis of which security controls must be adapted during disruption and how
- The business impact analysis with prioritized activities, supporting ICT services and their RTOs, and RPOs for required information
- Selected ICT continuity strategies covering before, during and after disruption
- Documented availability requirements for business services and systems
- Architecture diagrams showing redundancy such as dual providers, redundant networks, separate data centres, redundant power and load-balanced instances
- Business continuity and disaster recovery plans covering the in-scope service
- Business impact analysis
- Backup policy defining scope, frequency and retention
- Backup job monitoring and failure remediation records
- Resilience architecture patterns for critical services
- Failover and failback tested with evidence
- Recovery plan with triggers and decision rights
- Execution log of recovery activities
No held control answers this line.
This is a media liability question, not a control requirement. It reaches no held control.
No held control answers this line.
This is a media liability question, not a control requirement. It reaches no held control.
No held control answers this line.
This is a media liability question, not a control requirement. It reaches no held control.
No held control answers this line.
- The topic-specific cryptography policy with approved algorithms, key lengths, protocols and usage by information classification
- Evidence of encryption on endpoints, removable media and data in transit, aligned with the policy
- The topic-specific access control policy, approved and communicated, reflecting owner-defined business and security requirements
- Access control rules or role models mapping entities (users, services, devices) to rights, consistent with classification
- Asset inventory with classification for in-scope systems
- Identity provider configuration showing MFA and password policy
- TLS and encryption standards for data in transit
- Removable media policy and technical enforcement
- Data at rest encryption inventory by store type
- Storage configuration baselines with attestation
This is a scoping question, not a control requirement. It reaches no held control.
No held control answers this line.
- The topic-specific cryptography policy with approved algorithms, key lengths, protocols and usage by information classification
- Evidence of encryption on endpoints, removable media and data in transit, aligned with the policy
- The topic-specific access control policy, approved and communicated, reflecting owner-defined business and security requirements
- Access control rules or role models mapping entities (users, services, devices) to rights, consistent with classification
- Asset inventory with classification for in-scope systems
- Identity provider configuration showing MFA and password policy
- TLS and encryption standards for data in transit
- Removable media policy and technical enforcement
- Data at rest encryption inventory by store type
- Storage configuration baselines with attestation
- The topic-specific cryptography policy with approved algorithms, key lengths, protocols and usage by information classification
- Evidence of encryption on endpoints, removable media and data in transit, aligned with the policy
- The topic-specific access control policy, approved and communicated, reflecting owner-defined business and security requirements
- Access control rules or role models mapping entities (users, services, devices) to rights, consistent with classification
- Asset inventory with classification for in-scope systems
- Identity provider configuration showing MFA and password policy
- TLS and encryption standards for data in transit
- Removable media policy and technical enforcement
- Data at rest encryption inventory by store type
- Storage configuration baselines with attestation
- The topic-specific cryptography policy with approved algorithms, key lengths, protocols and usage by information classification
- Evidence of encryption on endpoints, removable media and data in transit, aligned with the policy
- Policy or standard specifying where masking, pseudonymization or anonymization is required, based on access control policy, business needs and law
- Masking configurations in applications, databases and reports showing minimum necessary data displayed per role
- The topic-specific access control policy, approved and communicated, reflecting owner-defined business and security requirements
- Access control rules or role models mapping entities (users, services, devices) to rights, consistent with classification
- Asset inventory with classification for in-scope systems
- Identity provider configuration showing MFA and password policy
- TLS and encryption standards for data in transit
- Removable media policy and technical enforcement
- Data at rest encryption inventory by store type
- Storage configuration baselines with attestation
- TLS configuration standards and scan results
- VPN and zero trust network access policy
- The topic-specific cryptography policy with approved algorithms, key lengths, protocols and usage by information classification
- Evidence of encryption on endpoints, removable media and data in transit, aligned with the policy
- The topic-specific access control policy, approved and communicated, reflecting owner-defined business and security requirements
- Access control rules or role models mapping entities (users, services, devices) to rights, consistent with classification
- Asset inventory with classification for in-scope systems
- Identity provider configuration showing MFA and password policy
- TLS and encryption standards for data in transit
- Removable media policy and technical enforcement
- Data at rest encryption inventory by store type
- Storage configuration baselines with attestation
No held control answers this line.
- The topic-specific cryptography policy with approved algorithms, key lengths, protocols and usage by information classification
- Evidence of encryption on endpoints, removable media and data in transit, aligned with the policy
- The topic-specific access control policy, approved and communicated, reflecting owner-defined business and security requirements
- Access control rules or role models mapping entities (users, services, devices) to rights, consistent with classification
- Asset inventory with classification for in-scope systems
- Identity provider configuration showing MFA and password policy
- TLS and encryption standards for data in transit
- Removable media policy and technical enforcement
- Data at rest encryption inventory by store type
- Storage configuration baselines with attestation
- The topic-specific privacy and PII protection policy and its communication to relevant parties
- Privacy procedures communicated to everyone who processes PII
- A register of applicable laws, regulations and contractual obligations for information security, with the countries covered, the approach to meeting each and a named responsible owner
- Records of periodic review of the register and of new or changed legislation identified
- Published privacy notice with effective date and version history
- Evidence notice is presented at collection points (forms, apps)
- Data inventory showing purpose for each personal data field
- Privacy review of new collection forms or features
- Legal and regulatory obligations register with owners
- Contractual security clauses summary across customer base
- Data at rest encryption inventory by store type
- Storage configuration baselines with attestation
- Records handling guidelines covering storage, chain of custody, tamper prevention and disposal, aligned with the records management policy
- A retention schedule listing record types, retention periods, legal basis and permitted storage media
- The data retention topic-specific policy with deletion triggers per information type
- Configuration of automated deletion after retention periods or on data subject requests
- A disposal and reuse procedure requiring verification that equipment is checked for storage media and sanitized
- Sanitization or destruction certificates identifying each device, method used and verifier
- Retention schedule for personal information categories
- Evidence of automated retention enforcement
- Deletion request log with completion evidence
- Anonymisation or destruction procedure
- Data at rest encryption inventory by store type
- Storage configuration baselines with attestation
- Legal and regulatory obligations register with owners
- Contractual security clauses summary across customer base
- Records handling guidelines covering storage, chain of custody, tamper prevention and disposal, aligned with the records management policy
- A retention schedule listing record types, retention periods, legal basis and permitted storage media
- The data retention topic-specific policy with deletion triggers per information type
- Configuration of automated deletion after retention periods or on data subject requests
- A disposal and reuse procedure requiring verification that equipment is checked for storage media and sanitized
- Sanitization or destruction certificates identifying each device, method used and verifier
- Retention schedule for personal information categories
- Evidence of automated retention enforcement
- Deletion request log with completion evidence
- Anonymisation or destruction procedure
- Data at rest encryption inventory by store type
- Storage configuration baselines with attestation
- Legal and regulatory obligations register with owners
- Contractual security clauses summary across customer base
- The topic-specific privacy and PII protection policy and its communication to relevant parties
- Privacy procedures communicated to everyone who processes PII
- A register of applicable laws, regulations and contractual obligations for information security, with the countries covered, the approach to meeting each and a named responsible owner
- Records of periodic review of the register and of new or changed legislation identified
- Published privacy notice with effective date and version history
- Evidence notice is presented at collection points (forms, apps)
- Data inventory showing purpose for each personal data field
- Privacy review of new collection forms or features
- Legal and regulatory obligations register with owners
- Contractual security clauses summary across customer base
- Data at rest encryption inventory by store type
- Storage configuration baselines with attestation
- The topic-specific privacy and PII protection policy and its communication to relevant parties
- Privacy procedures communicated to everyone who processes PII
- A register of applicable laws, regulations and contractual obligations for information security, with the countries covered, the approach to meeting each and a named responsible owner
- Records of periodic review of the register and of new or changed legislation identified
- Published privacy notice with effective date and version history
- Evidence notice is presented at collection points (forms, apps)
- Data inventory showing purpose for each personal data field
- Privacy review of new collection forms or features
- Legal and regulatory obligations register with owners
- Contractual security clauses summary across customer base
- Data at rest encryption inventory by store type
- Storage configuration baselines with attestation
No held control answers this line.
This is a loss history question, not a control requirement. It reaches no held control.
No held control answers this line.
This is a loss history question, not a control requirement. It reaches no held control.
No held control answers this line.
Prior-knowledge question. This asks whether the applicant knows of any circumstance that could give rise to a claim. A wrong answer here is the classic route to a prior-knowledge exclusion or rescission, so it is the highest-consequence line on the form, not a line to leave unread. It reaches no control by itself: it is about what the applicant knows, not a control to hold.
No held control answers this line.
Controls not asked in this held document (178)
None of this held document's questions reach 178 of the 290 held controls (for example A.5.3, A.5.5, A.5.6, A.5.7, A.5.8, A.5.10, A.5.11, A.5.22). That is a fact about this held document, not about what the carrier underwrites on: a carrier's fuller forms and supplements ask controls this summary does not, multi-factor authentication, offline backups and patching among them. A control here is not asserted as required, and not asserted as not required.