Cyber Insurance Application Scannermap an application to controls

Munich Re cyber policy application, held

The questions of the Insurance Application - Cyber Risk (UK), held and mapped to the ISO 27001:2022 controls, the SOC 2 criteria and the NIST CSF 2.0 outcomes each one reaches. The source document (read 2026-10-11). The date shown is the date this copy was read, not a version the form itself states. This page quotes only the question each mapped row needs and states its source; it does not publish the carrier's form. A complete form would be held only under a stated policy for copyrighted forms. Munich Re is a source document, never a customer.

This document's questions reach 112 of 290 held controls. Whether an applicant is offered cover is the carrier’s underwriting decision. 12 questions here are flagged knockout (a "no" is a common decline point) and 0 flagged warranty (an answer the carrier relies on, that can affect cover if wrong).

Application question Do you have a Chief Privacy Officer, Data Protection Officer or function equivalent?
Munich Re held application question
ISO 27001:2022 A.5.1 Policies for information security
Evidence to have on file (guidance, our wording)
  • The top-level information security policy with top management approval, covering the definition, objectives or objective-setting framework, principles, commitments to requirements and continual improvement, role assignments and the exceptions procedure
  • The register of topic-specific policies with an owner, approving manager and version for each
ISO 27001:2022 A.5.2 Information security roles and responsibilities
Evidence to have on file (guidance, our wording)
  • A documented roles and responsibilities matrix covering asset protection, specific security processes, risk management and residual risk acceptance, and user duties
  • Named risk owners with evidence that they accepted residual risks
ISO 27001:2022 A.5.4 Management responsibilities
Evidence to have on file (guidance, our wording)
  • Evidence that security briefings on roles and responsibilities occur before access is granted, such as onboarding checklists tied to access provisioning
  • Role-specific guidance documents setting out security expectations
SOC 2 CC1.3 Structures, reporting lines, authorities and responsibilities (COSO principle 3)
Evidence to have on file (guidance, our wording)
  • Current organisation chart including security, IT operations, compliance and privacy functions
  • Job descriptions or RACI naming security and privacy responsibilities
SOC 2 CC5.3 Deploying controls through policies and procedures (COSO principle 12)
Evidence to have on file (guidance, our wording)
  • Approved information security policy set with owners and review dates
  • Evidence of annual policy review and approval
NIST CSF 2.0 GV.PO-01 Policy for managing cybersecurity risks is established based on organizational context, cybersecurity strategy, and priorities and is communicated and enforced
Evidence to have on file (guidance, our wording)
  • Cybersecurity risk management policy approved by leadership
  • Policy linkage matrix to standards and procedures
NIST CSF 2.0 GV.RR-01 Organizational leadership is responsible and accountable for cybersecurity risk and fosters a culture that is risk-aware, ethical, and continually improving
Evidence to have on file (guidance, our wording)
  • Board cyber accountability charter
  • Executive cyber scorecard with named owners
Application question Do you have a written privacy policy that is reviewed (at least annually) by qualified legal counsel?
Munich Re held application question
ISO 27001:2022 A.5.34 Privacy and protection of personal identifiable information (PII)
Evidence to have on file (guidance, our wording)
  • The topic-specific privacy and PII protection policy and its communication to relevant parties
  • Privacy procedures communicated to everyone who processes PII
ISO 27001:2022 A.5.31 Legal, statutory, regulatory and contractual requirements
Evidence to have on file (guidance, our wording)
  • A register of applicable laws, regulations and contractual obligations for information security, with the countries covered, the approach to meeting each and a named responsible owner
  • Records of periodic review of the register and of new or changed legislation identified
ISO 27001:2022 A.5.1 Policies for information security
Evidence to have on file (guidance, our wording)
  • The top-level information security policy with top management approval, covering the definition, objectives or objective-setting framework, principles, commitments to requirements and continual improvement, role assignments and the exceptions procedure
  • The register of topic-specific policies with an owner, approving manager and version for each
SOC 2 P1.1 Privacy notice to data subjects
Evidence to have on file (guidance, our wording)
  • Published privacy notice with effective date and version history
  • Evidence notice is presented at collection points (forms, apps)
SOC 2 P3.1 Collecting personal information consistent with objectives
Evidence to have on file (guidance, our wording)
  • Data inventory showing purpose for each personal data field
  • Privacy review of new collection forms or features
NIST CSF 2.0 GV.OC-03 Legal, regulatory, and contractual requirements regarding cybersecurity - including privacy and civil liberties obligations - are understood and managed
Evidence to have on file (guidance, our wording)
  • Legal and regulatory obligations register with owners
  • Contractual security clauses summary across customer base
NIST CSF 2.0 PR.DS-01 The confidentiality, integrity, and availability of data-at-rest are protected
Evidence to have on file (guidance, our wording)
  • Data at rest encryption inventory by store type
  • Storage configuration baselines with attestation
Application question Do you share any personal data with third parties?
Munich Re held application question
ISO 27001:2022 A.5.34 Privacy and protection of personal identifiable information (PII)
Evidence to have on file (guidance, our wording)
  • The topic-specific privacy and PII protection policy and its communication to relevant parties
  • Privacy procedures communicated to everyone who processes PII
ISO 27001:2022 A.5.31 Legal, statutory, regulatory and contractual requirements
Evidence to have on file (guidance, our wording)
  • A register of applicable laws, regulations and contractual obligations for information security, with the countries covered, the approach to meeting each and a named responsible owner
  • Records of periodic review of the register and of new or changed legislation identified
ISO 27001:2022 A.5.19 Information security in supplier relationships
Evidence to have on file (guidance, our wording)
  • The topic-specific supplier relationship policy and its communication record
  • A supplier inventory categorized by type and by the information, services and infrastructure each can access
SOC 2 P1.1 Privacy notice to data subjects
Evidence to have on file (guidance, our wording)
  • Published privacy notice with effective date and version history
  • Evidence notice is presented at collection points (forms, apps)
SOC 2 P3.1 Collecting personal information consistent with objectives
Evidence to have on file (guidance, our wording)
  • Data inventory showing purpose for each personal data field
  • Privacy review of new collection forms or features
NIST CSF 2.0 GV.OC-03 Legal, regulatory, and contractual requirements regarding cybersecurity - including privacy and civil liberties obligations - are understood and managed
Evidence to have on file (guidance, our wording)
  • Legal and regulatory obligations register with owners
  • Contractual security clauses summary across customer base
NIST CSF 2.0 PR.DS-01 The confidentiality, integrity, and availability of data-at-rest are protected
Evidence to have on file (guidance, our wording)
  • Data at rest encryption inventory by store type
  • Storage configuration baselines with attestation
Application question If Yes, do you have data sharing agreements in place with all third parties where personal data is shared?
Munich Re held application question
ISO 27001:2022 A.5.34 Privacy and protection of personal identifiable information (PII)
Evidence to have on file (guidance, our wording)
  • The topic-specific privacy and PII protection policy and its communication to relevant parties
  • Privacy procedures communicated to everyone who processes PII
ISO 27001:2022 A.5.31 Legal, statutory, regulatory and contractual requirements
Evidence to have on file (guidance, our wording)
  • A register of applicable laws, regulations and contractual obligations for information security, with the countries covered, the approach to meeting each and a named responsible owner
  • Records of periodic review of the register and of new or changed legislation identified
ISO 27001:2022 A.5.19 Information security in supplier relationships
Evidence to have on file (guidance, our wording)
  • The topic-specific supplier relationship policy and its communication record
  • A supplier inventory categorized by type and by the information, services and infrastructure each can access
SOC 2 P1.1 Privacy notice to data subjects
Evidence to have on file (guidance, our wording)
  • Published privacy notice with effective date and version history
  • Evidence notice is presented at collection points (forms, apps)
SOC 2 P3.1 Collecting personal information consistent with objectives
Evidence to have on file (guidance, our wording)
  • Data inventory showing purpose for each personal data field
  • Privacy review of new collection forms or features
NIST CSF 2.0 GV.OC-03 Legal, regulatory, and contractual requirements regarding cybersecurity - including privacy and civil liberties obligations - are understood and managed
Evidence to have on file (guidance, our wording)
  • Legal and regulatory obligations register with owners
  • Contractual security clauses summary across customer base
NIST CSF 2.0 PR.DS-01 The confidentiality, integrity, and availability of data-at-rest are protected
Evidence to have on file (guidance, our wording)
  • Data at rest encryption inventory by store type
  • Storage configuration baselines with attestation
Application question Do you obtain authorization prior to sharing customer data with third parties?
Munich Re held application question
ISO 27001:2022 A.5.19 Information security in supplier relationships
Evidence to have on file (guidance, our wording)
  • The topic-specific supplier relationship policy and its communication record
  • A supplier inventory categorized by type and by the information, services and infrastructure each can access
ISO 27001:2022 A.5.20 Addressing information security within supplier agreements
Evidence to have on file (guidance, our wording)
  • Supplier agreements containing security clauses proportionate to the relationship, such as classification mapping, agreed controls, incident notification, subcontracting, right to audit and termination terms
  • A register of contracts, memoranda and information-sharing arrangements with outside parties showing what information each covers and when it was last reviewed
ISO 27001:2022 A.5.21 Managing information security in the information and communication technology (ICT) supply chain
Evidence to have on file (guidance, our wording)
  • Security requirements included in ICT acquisition specifications and contracts, including flow-down to sub-suppliers
  • Software component information such as SBOMs and descriptions of security functions and secure configuration obtained from product suppliers
SOC 2 CC9.2 Assessing and managing vendor and business partner risk
Evidence to have on file (guidance, our wording)
  • Vendor inventory with risk tiers and the review frequency set for each tier
  • Due diligence records, for example vendor SOC reports reviewed with complementary controls noted
SOC 2 P6.4 Privacy commitments from vendors and third parties
Evidence to have on file (guidance, our wording)
  • Data processing agreements with privacy clauses
  • Periodic assessments of vendors' privacy compliance
NIST CSF 2.0 GV.SC-01 A cybersecurity supply chain risk management program, strategy, objectives, policies, and processes are established and agreed to by organizational stakeholders
Evidence to have on file (guidance, our wording)
  • Third party risk management program charter
  • Supplier risk policy with tiering criteria
NIST CSF 2.0 GV.SC-05 Requirements to address cybersecurity risks in supply chains are established, prioritized, and integrated into contracts and other types of agreements with suppliers and other relevant third parties
Evidence to have on file (guidance, our wording)
  • Standard supplier security requirements catalog
  • Contract clause library with cyber obligations
Application question Do you give data subjects the ability to opt-out of allowing personal data to be shared with third parties?
Munich Re held application question
ISO 27001:2022 A.5.34 Privacy and protection of personal identifiable information (PII)
Evidence to have on file (guidance, our wording)
  • The topic-specific privacy and PII protection policy and its communication to relevant parties
  • Privacy procedures communicated to everyone who processes PII
ISO 27001:2022 A.5.31 Legal, statutory, regulatory and contractual requirements
Evidence to have on file (guidance, our wording)
  • A register of applicable laws, regulations and contractual obligations for information security, with the countries covered, the approach to meeting each and a named responsible owner
  • Records of periodic review of the register and of new or changed legislation identified
ISO 27001:2022 A.5.19 Information security in supplier relationships
Evidence to have on file (guidance, our wording)
  • The topic-specific supplier relationship policy and its communication record
  • A supplier inventory categorized by type and by the information, services and infrastructure each can access
SOC 2 P1.1 Privacy notice to data subjects
Evidence to have on file (guidance, our wording)
  • Published privacy notice with effective date and version history
  • Evidence notice is presented at collection points (forms, apps)
SOC 2 P3.1 Collecting personal information consistent with objectives
Evidence to have on file (guidance, our wording)
  • Data inventory showing purpose for each personal data field
  • Privacy review of new collection forms or features
NIST CSF 2.0 GV.OC-03 Legal, regulatory, and contractual requirements regarding cybersecurity - including privacy and civil liberties obligations - are understood and managed
Evidence to have on file (guidance, our wording)
  • Legal and regulatory obligations register with owners
  • Contractual security clauses summary across customer base
NIST CSF 2.0 PR.DS-01 The confidentiality, integrity, and availability of data-at-rest are protected
Evidence to have on file (guidance, our wording)
  • Data at rest encryption inventory by store type
  • Storage configuration baselines with attestation
Application question Do you have a process in place to respond to data subject requests (e.g. access requests, right to erasure) and  Yes  No complaints based on applicable data privacy regulations?
Munich Re held application question
ISO 27001:2022 A.5.34 Privacy and protection of personal identifiable information (PII)
Evidence to have on file (guidance, our wording)
  • The topic-specific privacy and PII protection policy and its communication to relevant parties
  • Privacy procedures communicated to everyone who processes PII
ISO 27001:2022 A.5.31 Legal, statutory, regulatory and contractual requirements
Evidence to have on file (guidance, our wording)
  • A register of applicable laws, regulations and contractual obligations for information security, with the countries covered, the approach to meeting each and a named responsible owner
  • Records of periodic review of the register and of new or changed legislation identified
SOC 2 P1.1 Privacy notice to data subjects
Evidence to have on file (guidance, our wording)
  • Published privacy notice with effective date and version history
  • Evidence notice is presented at collection points (forms, apps)
SOC 2 P3.1 Collecting personal information consistent with objectives
Evidence to have on file (guidance, our wording)
  • Data inventory showing purpose for each personal data field
  • Privacy review of new collection forms or features
NIST CSF 2.0 GV.OC-03 Legal, regulatory, and contractual requirements regarding cybersecurity - including privacy and civil liberties obligations - are understood and managed
Evidence to have on file (guidance, our wording)
  • Legal and regulatory obligations register with owners
  • Contractual security clauses summary across customer base
NIST CSF 2.0 PR.DS-01 The confidentiality, integrity, and availability of data-at-rest are protected
Evidence to have on file (guidance, our wording)
  • Data at rest encryption inventory by store type
  • Storage configuration baselines with attestation
Application question Do you have a documented corporate-wide policy governing information security?
Munich Re held application question

No held control answers this line.

Application question Is your information security policy reviewed (at least annually) and approved by senior management?
Munich Re held application question
ISO 27001:2022 A.5.1 Policies for information security
Evidence to have on file (guidance, our wording)
  • The top-level information security policy with top management approval, covering the definition, objectives or objective-setting framework, principles, commitments to requirements and continual improvement, role assignments and the exceptions procedure
  • The register of topic-specific policies with an owner, approving manager and version for each
ISO 27001:2022 A.5.2 Information security roles and responsibilities
Evidence to have on file (guidance, our wording)
  • A documented roles and responsibilities matrix covering asset protection, specific security processes, risk management and residual risk acceptance, and user duties
  • Named risk owners with evidence that they accepted residual risks
ISO 27001:2022 A.5.4 Management responsibilities
Evidence to have on file (guidance, our wording)
  • Evidence that security briefings on roles and responsibilities occur before access is granted, such as onboarding checklists tied to access provisioning
  • Role-specific guidance documents setting out security expectations
SOC 2 CC1.3 Structures, reporting lines, authorities and responsibilities (COSO principle 3)
Evidence to have on file (guidance, our wording)
  • Current organisation chart including security, IT operations, compliance and privacy functions
  • Job descriptions or RACI naming security and privacy responsibilities
SOC 2 CC5.3 Deploying controls through policies and procedures (COSO principle 12)
Evidence to have on file (guidance, our wording)
  • Approved information security policy set with owners and review dates
  • Evidence of annual policy review and approval
NIST CSF 2.0 GV.PO-01 Policy for managing cybersecurity risks is established based on organizational context, cybersecurity strategy, and priorities and is communicated and enforced
Evidence to have on file (guidance, our wording)
  • Cybersecurity risk management policy approved by leadership
  • Policy linkage matrix to standards and procedures
NIST CSF 2.0 GV.RR-01 Organizational leadership is responsible and accountable for cybersecurity risk and fosters a culture that is risk-aware, ethical, and continually improving
Evidence to have on file (guidance, our wording)
  • Board cyber accountability charter
  • Executive cyber scorecard with named owners
Application question Chief Information Security Officer?
Munich Re held application question
ISO 27001:2022 A.5.1 Policies for information security
Evidence to have on file (guidance, our wording)
  • The top-level information security policy with top management approval, covering the definition, objectives or objective-setting framework, principles, commitments to requirements and continual improvement, role assignments and the exceptions procedure
  • The register of topic-specific policies with an owner, approving manager and version for each
ISO 27001:2022 A.5.2 Information security roles and responsibilities
Evidence to have on file (guidance, our wording)
  • A documented roles and responsibilities matrix covering asset protection, specific security processes, risk management and residual risk acceptance, and user duties
  • Named risk owners with evidence that they accepted residual risks
ISO 27001:2022 A.5.4 Management responsibilities
Evidence to have on file (guidance, our wording)
  • Evidence that security briefings on roles and responsibilities occur before access is granted, such as onboarding checklists tied to access provisioning
  • Role-specific guidance documents setting out security expectations
SOC 2 CC1.3 Structures, reporting lines, authorities and responsibilities (COSO principle 3)
Evidence to have on file (guidance, our wording)
  • Current organisation chart including security, IT operations, compliance and privacy functions
  • Job descriptions or RACI naming security and privacy responsibilities
SOC 2 CC5.3 Deploying controls through policies and procedures (COSO principle 12)
Evidence to have on file (guidance, our wording)
  • Approved information security policy set with owners and review dates
  • Evidence of annual policy review and approval
NIST CSF 2.0 GV.PO-01 Policy for managing cybersecurity risks is established based on organizational context, cybersecurity strategy, and priorities and is communicated and enforced
Evidence to have on file (guidance, our wording)
  • Cybersecurity risk management policy approved by leadership
  • Policy linkage matrix to standards and procedures
NIST CSF 2.0 GV.RR-01 Organizational leadership is responsible and accountable for cybersecurity risk and fosters a culture that is risk-aware, ethical, and continually improving
Evidence to have on file (guidance, our wording)
  • Board cyber accountability charter
  • Executive cyber scorecard with named owners
Application question If Yes, does this person regularly report to senior level management?
Munich Re held application question
ISO 27001:2022 A.5.1 Policies for information security
Evidence to have on file (guidance, our wording)
  • The top-level information security policy with top management approval, covering the definition, objectives or objective-setting framework, principles, commitments to requirements and continual improvement, role assignments and the exceptions procedure
  • The register of topic-specific policies with an owner, approving manager and version for each
ISO 27001:2022 A.5.2 Information security roles and responsibilities
Evidence to have on file (guidance, our wording)
  • A documented roles and responsibilities matrix covering asset protection, specific security processes, risk management and residual risk acceptance, and user duties
  • Named risk owners with evidence that they accepted residual risks
ISO 27001:2022 A.5.4 Management responsibilities
Evidence to have on file (guidance, our wording)
  • Evidence that security briefings on roles and responsibilities occur before access is granted, such as onboarding checklists tied to access provisioning
  • Role-specific guidance documents setting out security expectations
SOC 2 CC1.3 Structures, reporting lines, authorities and responsibilities (COSO principle 3)
Evidence to have on file (guidance, our wording)
  • Current organisation chart including security, IT operations, compliance and privacy functions
  • Job descriptions or RACI naming security and privacy responsibilities
SOC 2 CC5.3 Deploying controls through policies and procedures (COSO principle 12)
Evidence to have on file (guidance, our wording)
  • Approved information security policy set with owners and review dates
  • Evidence of annual policy review and approval
NIST CSF 2.0 GV.PO-01 Policy for managing cybersecurity risks is established based on organizational context, cybersecurity strategy, and priorities and is communicated and enforced
Evidence to have on file (guidance, our wording)
  • Cybersecurity risk management policy approved by leadership
  • Policy linkage matrix to standards and procedures
NIST CSF 2.0 GV.RR-01 Organizational leadership is responsible and accountable for cybersecurity risk and fosters a culture that is risk-aware, ethical, and continually improving
Evidence to have on file (guidance, our wording)
  • Board cyber accountability charter
  • Executive cyber scorecard with named owners
Application question Which of the following information security and privacy trainings are conducted?
Munich Re held application question
ISO 27001:2022 A.6.3 Information security awareness, education and training
Evidence to have on file (guidance, our wording)
  • A documented awareness, education and training programme aligned with the policies and planned by role, including external personnel
  • Completion records for initial training of new starters and role changers and for periodic refreshers
SOC 2 CC1.4 Attracting, developing and retaining competent people (COSO principle 4)
Evidence to have on file (guidance, our wording)
  • Background check policy and completed checks for a sample of new hires and contractors
  • Role competency requirements and performance review records
SOC 2 CC2.2 Internal communication of objectives and control responsibilities (COSO principle 14)
Evidence to have on file (guidance, our wording)
  • Security awareness training content and completion records
  • Published information security policies accessible to staff with change notices
NIST CSF 2.0 PR.AT-01 Personnel are provided with awareness and training so that they possess the knowledge and skills to perform general tasks with cybersecurity risks in mind
Evidence to have on file (guidance, our wording)
  • Security awareness program curriculum
  • Completion records by population
Application question Do you conduct employee phishing campaigns?
Munich Re held application question
ISO 27001:2022 A.8.23 Web filtering
Evidence to have on file (guidance, our wording)
  • Current rules on safe, proper use of online resources
  • Web filtering or secure web gateway configuration showing blocked categories such as malicious, phishing, command and control, illegal content and upload sites
ISO 27001:2022 A.8.7 Protection against malware
Evidence to have on file (guidance, our wording)
  • Anti-malware deployment and update status reports across endpoints, servers and gateways
  • Application allowlisting and malicious website blocking configurations
ISO 27001:2022 A.5.14 Information transfer
Evidence to have on file (guidance, our wording)
  • The topic-specific information transfer policy and its communication record
  • Transfer agreements with third parties covering recipient authentication, protection levels, incident liability and labelling
SOC 2 CC6.8 Preventing and detecting unauthorised or malicious software
Evidence to have on file (guidance, our wording)
  • Endpoint protection coverage report across servers and workstations
  • Local administrator and software installation restrictions
SOC 2 CC1.4 Attracting, developing and retaining competent people (COSO principle 4)
Evidence to have on file (guidance, our wording)
  • Background check policy and completed checks for a sample of new hires and contractors
  • Role competency requirements and performance review records
NIST CSF 2.0 PR.PS-05 Installation and execution of unauthorized software are prevented
Evidence to have on file (guidance, our wording)
  • Application allowlist policy and tooling configuration
  • Endpoint protection deployment reports
NIST CSF 2.0 PR.AT-01 Personnel are provided with awareness and training so that they possess the knowledge and skills to perform general tasks with cybersecurity risks in mind
Evidence to have on file (guidance, our wording)
  • Security awareness program curriculum
  • Completion records by population
Application question If Yes, what is the click through failure rate on the latest test?
Munich Re held application question

No held control answers this line.

Application question How often are phishing campaigns conducted?
Munich Re held application question
ISO 27001:2022 A.8.23 Web filtering
Evidence to have on file (guidance, our wording)
  • Current rules on safe, proper use of online resources
  • Web filtering or secure web gateway configuration showing blocked categories such as malicious, phishing, command and control, illegal content and upload sites
ISO 27001:2022 A.8.7 Protection against malware
Evidence to have on file (guidance, our wording)
  • Anti-malware deployment and update status reports across endpoints, servers and gateways
  • Application allowlisting and malicious website blocking configurations
ISO 27001:2022 A.5.14 Information transfer
Evidence to have on file (guidance, our wording)
  • The topic-specific information transfer policy and its communication record
  • Transfer agreements with third parties covering recipient authentication, protection levels, incident liability and labelling
SOC 2 CC6.8 Preventing and detecting unauthorised or malicious software
Evidence to have on file (guidance, our wording)
  • Endpoint protection coverage report across servers and workstations
  • Local administrator and software installation restrictions
SOC 2 CC1.4 Attracting, developing and retaining competent people (COSO principle 4)
Evidence to have on file (guidance, our wording)
  • Background check policy and completed checks for a sample of new hires and contractors
  • Role competency requirements and performance review records
NIST CSF 2.0 PR.PS-05 Installation and execution of unauthorized software are prevented
Evidence to have on file (guidance, our wording)
  • Application allowlist policy and tooling configuration
  • Endpoint protection deployment reports
NIST CSF 2.0 PR.AT-01 Personnel are provided with awareness and training so that they possess the knowledge and skills to perform general tasks with cybersecurity risks in mind
Evidence to have on file (guidance, our wording)
  • Security awareness program curriculum
  • Completion records by population
Application question Do you mandate additional training to those employees who fail to acknowledge phishing emails?
Munich Re held application question
ISO 27001:2022 A.8.23 Web filtering
Evidence to have on file (guidance, our wording)
  • Current rules on safe, proper use of online resources
  • Web filtering or secure web gateway configuration showing blocked categories such as malicious, phishing, command and control, illegal content and upload sites
ISO 27001:2022 A.8.7 Protection against malware
Evidence to have on file (guidance, our wording)
  • Anti-malware deployment and update status reports across endpoints, servers and gateways
  • Application allowlisting and malicious website blocking configurations
ISO 27001:2022 A.5.14 Information transfer
Evidence to have on file (guidance, our wording)
  • The topic-specific information transfer policy and its communication record
  • Transfer agreements with third parties covering recipient authentication, protection levels, incident liability and labelling
SOC 2 CC6.8 Preventing and detecting unauthorised or malicious software
Evidence to have on file (guidance, our wording)
  • Endpoint protection coverage report across servers and workstations
  • Local administrator and software installation restrictions
SOC 2 CC1.4 Attracting, developing and retaining competent people (COSO principle 4)
Evidence to have on file (guidance, our wording)
  • Background check policy and completed checks for a sample of new hires and contractors
  • Role competency requirements and performance review records
NIST CSF 2.0 PR.PS-05 Installation and execution of unauthorized software are prevented
Evidence to have on file (guidance, our wording)
  • Application allowlist policy and tooling configuration
  • Endpoint protection deployment reports
NIST CSF 2.0 PR.AT-01 Personnel are provided with awareness and training so that they possess the knowledge and skills to perform general tasks with cybersecurity risks in mind
Evidence to have on file (guidance, our wording)
  • Security awareness program curriculum
  • Completion records by population
Application question Do you have a corporate employee social media policy?
Munich Re held application question

No held control answers this line.

Application question Do you perform background checks on employees & contractors who have access to sensitive information?
Munich Re held application question
ISO 27001:2022 A.5.15 Access control
Evidence to have on file (guidance, our wording)
  • The topic-specific access control policy, approved and communicated, reflecting owner-defined business and security requirements
  • Access control rules or role models mapping entities (users, services, devices) to rights, consistent with classification
ISO 27001:2022 A.5.16 Identity management
Evidence to have on file (guidance, our wording)
  • Identity management procedure covering creation, verification, activation, change, disablement and removal
  • Evidence that identities are verified against trusted documents before issue
ISO 27001:2022 A.5.18 Access rights
Evidence to have on file (guidance, our wording)
  • Access request records showing owner authorization, and management approval where required, before rights were activated
  • A central record of access rights per user identifier across logical and physical access
SOC 2 CC6.1 Logical access security over protected information assets
Evidence to have on file (guidance, our wording)
  • Asset inventory with classification for in-scope systems
  • Identity provider configuration showing MFA and password policy
SOC 2 CC6.2 Registering and authorising users before issuing credentials
Evidence to have on file (guidance, our wording)
  • Access request tickets with owner approval for a sample of new users, service accounts and API credentials
  • Termination records reconciled to account disablement dates
NIST CSF 2.0 PR.AA-01 Identities and credentials for authorized users, services, and hardware are managed by the organization
Evidence to have on file (guidance, our wording)
  • Identity management platform configuration baseline
  • Joiner mover leaver workflow with timing SLAs
NIST CSF 2.0 PR.AA-05 Access permissions, entitlements, and authorizations are defined in a policy, managed, enforced, and reviewed, and incorporate the principles of least privilege and separation of duties
Evidence to have on file (guidance, our wording)
  • Access policy framework with role definitions
  • Privileged access management deployment evidence
Application question Do you terminate user access rights as part of the employee exit process?
Munich Re held application question
ISO 27001:2022 A.5.15 Access control
Evidence to have on file (guidance, our wording)
  • The topic-specific access control policy, approved and communicated, reflecting owner-defined business and security requirements
  • Access control rules or role models mapping entities (users, services, devices) to rights, consistent with classification
ISO 27001:2022 A.5.16 Identity management
Evidence to have on file (guidance, our wording)
  • Identity management procedure covering creation, verification, activation, change, disablement and removal
  • Evidence that identities are verified against trusted documents before issue
ISO 27001:2022 A.5.18 Access rights
Evidence to have on file (guidance, our wording)
  • Access request records showing owner authorization, and management approval where required, before rights were activated
  • A central record of access rights per user identifier across logical and physical access
SOC 2 CC6.1 Logical access security over protected information assets
Evidence to have on file (guidance, our wording)
  • Asset inventory with classification for in-scope systems
  • Identity provider configuration showing MFA and password policy
SOC 2 CC6.2 Registering and authorising users before issuing credentials
Evidence to have on file (guidance, our wording)
  • Access request tickets with owner approval for a sample of new users, service accounts and API credentials
  • Termination records reconciled to account disablement dates
NIST CSF 2.0 PR.AA-01 Identities and credentials for authorized users, services, and hardware are managed by the organization
Evidence to have on file (guidance, our wording)
  • Identity management platform configuration baseline
  • Joiner mover leaver workflow with timing SLAs
NIST CSF 2.0 PR.AA-05 Access permissions, entitlements, and authorizations are defined in a policy, managed, enforced, and reviewed, and incorporate the principles of least privilege and separation of duties
Evidence to have on file (guidance, our wording)
  • Access policy framework with role definitions
  • Privileged access management deployment evidence
Application question What percentage of your hardware is inventoried?
Munich Re held application question

This is a scoping question, not a control requirement. It reaches no held control.

No held control answers this line.

Application question If you inventory hardware and/or software assets, do you have an asset classification policy that is enforced?
Munich Re held application question
ISO 27001:2022 A.5.9 Inventory of information and other associated assets
Evidence to have on file (guidance, our wording)
  • The asset inventories (information, hardware, software, virtual, facilities and others) with owner, classification and location fields populated
  • Reconciliation records between inventories and discovery tooling, or evidence that installs, changes and removals update the inventory automatically
ISO 27001:2022 A.5.12 Classification of information
Evidence to have on file (guidance, our wording)
  • The topic-specific classification policy with named levels, criteria based on impact, and conventions covering confidentiality, integrity and availability
  • Evidence the scheme was communicated to relevant interested parties and built into procedures
ISO 27001:2022 A.5.13 Labelling of information
Evidence to have on file (guidance, our wording)
  • Labelling procedures covering all formats, with rules on placement, exemptions and cases where labelling is not possible
  • Examples of labelled documents, emails, reports and media showing the chosen techniques such as headers, watermarks or metadata
SOC 2 CC6.1 Logical access security over protected information assets
Evidence to have on file (guidance, our wording)
  • Asset inventory with classification for in-scope systems
  • Identity provider configuration showing MFA and password policy
NIST CSF 2.0 ID.AM-01 Inventories of hardware managed by the organization are maintained
Evidence to have on file (guidance, our wording)
  • Hardware inventory with last seen and owner fields
  • Automated discovery feeds reconciled against CMDB
NIST CSF 2.0 ID.AM-02 Inventories of software, services, and systems managed by the organization are maintained
Evidence to have on file (guidance, our wording)
  • Software inventory with licensing and version data
  • SaaS application register with owner and data class
Application question Are all mobile devices managed using a Mobile Device Management (MDM) solution?
Munich Re held application question
ISO 27001:2022 A.8.1 User end point devices
Evidence to have on file (guidance, our wording)
  • The topic-specific endpoint policy covering classification limits, registration, software restrictions, updates, network connection rules, encryption, malware protection, remote wipe, backup and port control
  • Device management (MDM or endpoint management) reports showing enrolment, encryption, patch level, firewall and anti-malware status
ISO 27001:2022 A.7.10 Storage media
Evidence to have on file (guidance, our wording)
  • The topic-specific removable media policy and evidence it was communicated to users
  • Endpoint configuration showing USB and SD ports disabled unless a business reason is approved, and monitoring of transfers to removable media
ISO 27001:2022 A.6.7 Remote working
Evidence to have on file (guidance, our wording)
  • The topic-specific remote working policy defining conditions, permitted work, information classifications allowed and systems accessible
  • Remote access configuration showing multi-factor authentication, secure channels or virtual desktops
SOC 2 CC6.1 Logical access security over protected information assets
Evidence to have on file (guidance, our wording)
  • Asset inventory with classification for in-scope systems
  • Identity provider configuration showing MFA and password policy
SOC 2 CC6.7 Restricting and protecting information in transmission, movement and removal
Evidence to have on file (guidance, our wording)
  • TLS and encryption standards for data in transit
  • Removable media policy and technical enforcement
NIST CSF 2.0 PR.AA-06 Physical access to assets is managed, monitored, and enforced commensurate with risk
Evidence to have on file (guidance, our wording)
  • Physical access control system inventory
  • Badge issuance and revocation records
NIST CSF 2.0 PR.DS-01 The confidentiality, integrity, and availability of data-at-rest are protected
Evidence to have on file (guidance, our wording)
  • Data at rest encryption inventory by store type
  • Storage configuration baselines with attestation
Application question Do you disable media ports or restrict usage to only encrypted removable storage devices?
Munich Re held application question
ISO 27001:2022 A.8.24 Use of cryptography
Evidence to have on file (guidance, our wording)
  • The topic-specific cryptography policy with approved algorithms, key lengths, protocols and usage by information classification
  • Evidence of encryption on endpoints, removable media and data in transit, aligned with the policy
ISO 27001:2022 A.7.10 Storage media
Evidence to have on file (guidance, our wording)
  • The topic-specific removable media policy and evidence it was communicated to users
  • Endpoint configuration showing USB and SD ports disabled unless a business reason is approved, and monitoring of transfers to removable media
ISO 27001:2022 A.8.1 User end point devices
Evidence to have on file (guidance, our wording)
  • The topic-specific endpoint policy covering classification limits, registration, software restrictions, updates, network connection rules, encryption, malware protection, remote wipe, backup and port control
  • Device management (MDM or endpoint management) reports showing enrolment, encryption, patch level, firewall and anti-malware status
SOC 2 CC6.1 Logical access security over protected information assets
Evidence to have on file (guidance, our wording)
  • Asset inventory with classification for in-scope systems
  • Identity provider configuration showing MFA and password policy
SOC 2 CC6.7 Restricting and protecting information in transmission, movement and removal
Evidence to have on file (guidance, our wording)
  • TLS and encryption standards for data in transit
  • Removable media policy and technical enforcement
NIST CSF 2.0 PR.DS-01 The confidentiality, integrity, and availability of data-at-rest are protected
Evidence to have on file (guidance, our wording)
  • Data at rest encryption inventory by store type
  • Storage configuration baselines with attestation
NIST CSF 2.0 PR.DS-02 The confidentiality, integrity, and availability of data-in-transit are protected
Evidence to have on file (guidance, our wording)
  • TLS configuration standards and scan results
  • VPN and zero trust network access policy
Application question Do you allow employees to use personal mobile devices to access company data (e.g. email?
Munich Re held application question
ISO 27001:2022 A.8.1 User end point devices
Evidence to have on file (guidance, our wording)
  • The topic-specific endpoint policy covering classification limits, registration, software restrictions, updates, network connection rules, encryption, malware protection, remote wipe, backup and port control
  • Device management (MDM or endpoint management) reports showing enrolment, encryption, patch level, firewall and anti-malware status
ISO 27001:2022 A.7.10 Storage media
Evidence to have on file (guidance, our wording)
  • The topic-specific removable media policy and evidence it was communicated to users
  • Endpoint configuration showing USB and SD ports disabled unless a business reason is approved, and monitoring of transfers to removable media
ISO 27001:2022 A.6.7 Remote working
Evidence to have on file (guidance, our wording)
  • The topic-specific remote working policy defining conditions, permitted work, information classifications allowed and systems accessible
  • Remote access configuration showing multi-factor authentication, secure channels or virtual desktops
SOC 2 CC6.1 Logical access security over protected information assets
Evidence to have on file (guidance, our wording)
  • Asset inventory with classification for in-scope systems
  • Identity provider configuration showing MFA and password policy
SOC 2 CC6.7 Restricting and protecting information in transmission, movement and removal
Evidence to have on file (guidance, our wording)
  • TLS and encryption standards for data in transit
  • Removable media policy and technical enforcement
NIST CSF 2.0 PR.AA-06 Physical access to assets is managed, monitored, and enforced commensurate with risk
Evidence to have on file (guidance, our wording)
  • Physical access control system inventory
  • Badge issuance and revocation records
NIST CSF 2.0 PR.DS-01 The confidentiality, integrity, and availability of data-at-rest are protected
Evidence to have on file (guidance, our wording)
  • Data at rest encryption inventory by store type
  • Storage configuration baselines with attestation
Application question If Yes, do you have a Bring Your Own Device (BYOD) policy in place that governs usage and controls?
Munich Re held application question
ISO 27001:2022 A.8.1 User end point devices
Evidence to have on file (guidance, our wording)
  • The topic-specific endpoint policy covering classification limits, registration, software restrictions, updates, network connection rules, encryption, malware protection, remote wipe, backup and port control
  • Device management (MDM or endpoint management) reports showing enrolment, encryption, patch level, firewall and anti-malware status
ISO 27001:2022 A.7.10 Storage media
Evidence to have on file (guidance, our wording)
  • The topic-specific removable media policy and evidence it was communicated to users
  • Endpoint configuration showing USB and SD ports disabled unless a business reason is approved, and monitoring of transfers to removable media
ISO 27001:2022 A.6.7 Remote working
Evidence to have on file (guidance, our wording)
  • The topic-specific remote working policy defining conditions, permitted work, information classifications allowed and systems accessible
  • Remote access configuration showing multi-factor authentication, secure channels or virtual desktops
SOC 2 CC6.1 Logical access security over protected information assets
Evidence to have on file (guidance, our wording)
  • Asset inventory with classification for in-scope systems
  • Identity provider configuration showing MFA and password policy
SOC 2 CC6.7 Restricting and protecting information in transmission, movement and removal
Evidence to have on file (guidance, our wording)
  • TLS and encryption standards for data in transit
  • Removable media policy and technical enforcement
NIST CSF 2.0 PR.AA-06 Physical access to assets is managed, monitored, and enforced commensurate with risk
Evidence to have on file (guidance, our wording)
  • Physical access control system inventory
  • Badge issuance and revocation records
NIST CSF 2.0 PR.DS-01 The confidentiality, integrity, and availability of data-at-rest are protected
Evidence to have on file (guidance, our wording)
  • Data at rest encryption inventory by store type
  • Storage configuration baselines with attestation
Application question Is a Web Application Firewall (WAF) used to protect publicly exposed web application?
Munich Re held application question
ISO 27001:2022 A.8.20 Networks security
Evidence to have on file (guidance, our wording)
  • Current network diagrams and device configuration backups for routers, switches, firewalls and wireless controllers
  • Defined responsibilities and procedures for network device management, separated from system operations where appropriate
ISO 27001:2022 A.8.21 Security of network services
Evidence to have on file (guidance, our wording)
  • Service agreements with internal and external network providers specifying security features, service levels and requirements
  • Right-to-audit clauses and third-party attestations from network and managed security service providers, with records of review
ISO 27001:2022 A.8.22 Segregation of networks
Evidence to have on file (guidance, our wording)
  • Network segmentation design defining domains by trust, criticality, sensitivity or organizational unit, with the assessment that justified it
  • Firewall or filtering router rules controlling traffic between domains, with rule review records
SOC 2 CC6.6 Protection against threats from outside the system boundary
Evidence to have on file (guidance, our wording)
  • Firewall and security group rule sets with review evidence
  • MFA enforced on VPN, remote and administrative access
NIST CSF 2.0 PR.IR-01 Networks and environments are protected from unauthorized logical access and usage
Evidence to have on file (guidance, our wording)
  • Network segmentation design with zones and trust levels
  • Firewall and access control list governance
NIST CSF 2.0 DE.CM-01 Networks and network services are monitored to find potentially adverse events
Evidence to have on file (guidance, our wording)
  • Network flow telemetry coverage map by segment
  • IDS or NDR sensor inventory with placement diagram
Application question Do you ensure that all publicly facing ports are protected by a pre-configured firewall that blocks unauthorised  Yes  No network traffic?
Munich Re held application question
ISO 27001:2022 A.8.20 Networks security
Evidence to have on file (guidance, our wording)
  • Current network diagrams and device configuration backups for routers, switches, firewalls and wireless controllers
  • Defined responsibilities and procedures for network device management, separated from system operations where appropriate
ISO 27001:2022 A.8.21 Security of network services
Evidence to have on file (guidance, our wording)
  • Service agreements with internal and external network providers specifying security features, service levels and requirements
  • Right-to-audit clauses and third-party attestations from network and managed security service providers, with records of review
ISO 27001:2022 A.8.22 Segregation of networks
Evidence to have on file (guidance, our wording)
  • Network segmentation design defining domains by trust, criticality, sensitivity or organizational unit, with the assessment that justified it
  • Firewall or filtering router rules controlling traffic between domains, with rule review records
SOC 2 CC6.6 Protection against threats from outside the system boundary
Evidence to have on file (guidance, our wording)
  • Firewall and security group rule sets with review evidence
  • MFA enforced on VPN, remote and administrative access
NIST CSF 2.0 PR.IR-01 Networks and environments are protected from unauthorized logical access and usage
Evidence to have on file (guidance, our wording)
  • Network segmentation design with zones and trust levels
  • Firewall and access control list governance
NIST CSF 2.0 DE.CM-01 Networks and network services are monitored to find potentially adverse events
Evidence to have on file (guidance, our wording)
  • Network flow telemetry coverage map by segment
  • IDS or NDR sensor inventory with placement diagram
Application question Do you regularly scan publicly accessible ports and ensure unnecessary ones are locked down?
Munich Re held application question
ISO 27001:2022 A.8.20 Networks security
Evidence to have on file (guidance, our wording)
  • Current network diagrams and device configuration backups for routers, switches, firewalls and wireless controllers
  • Defined responsibilities and procedures for network device management, separated from system operations where appropriate
ISO 27001:2022 A.8.21 Security of network services
Evidence to have on file (guidance, our wording)
  • Service agreements with internal and external network providers specifying security features, service levels and requirements
  • Right-to-audit clauses and third-party attestations from network and managed security service providers, with records of review
ISO 27001:2022 A.8.22 Segregation of networks
Evidence to have on file (guidance, our wording)
  • Network segmentation design defining domains by trust, criticality, sensitivity or organizational unit, with the assessment that justified it
  • Firewall or filtering router rules controlling traffic between domains, with rule review records
SOC 2 CC6.6 Protection against threats from outside the system boundary
Evidence to have on file (guidance, our wording)
  • Firewall and security group rule sets with review evidence
  • MFA enforced on VPN, remote and administrative access
SOC 2 CC6.4 Restricting physical access to facilities and assets
Evidence to have on file (guidance, our wording)
  • Badge access provisioning and removal records
  • Periodic physical access review for sensitive areas
NIST CSF 2.0 PR.IR-01 Networks and environments are protected from unauthorized logical access and usage
Evidence to have on file (guidance, our wording)
  • Network segmentation design with zones and trust levels
  • Firewall and access control list governance
NIST CSF 2.0 DE.CM-01 Networks and network services are monitored to find potentially adverse events
Evidence to have on file (guidance, our wording)
  • Network flow telemetry coverage map by segment
  • IDS or NDR sensor inventory with placement diagram
Application question Do you restrict user access (employees, contractors etc.) on a business need-to-know & least-privilege basis?
Munich Re held application question

Flagged knockout: the wording of this question makes a "no" a common point at which a cyber application is declined or referred.

ISO 27001:2022 A.8.2 Privileged access rights
Evidence to have on file (guidance, our wording)
  • An inventory of privileged accounts per system (operating systems, databases, applications, cloud consoles) mapped to named individuals
  • Authorization records for each privileged grant with approver, justification and expiry
ISO 27001:2022 A.8.3 Information access restriction
Evidence to have on file (guidance, our wording)
  • System, application and cloud storage configurations restricting access by identity or group, with granular permissions per action
  • Evidence that anonymous or public access is limited to locations holding no sensitive information, for example storage bucket access reviews
ISO 27001:2022 A.5.15 Access control
Evidence to have on file (guidance, our wording)
  • The topic-specific access control policy, approved and communicated, reflecting owner-defined business and security requirements
  • Access control rules or role models mapping entities (users, services, devices) to rights, consistent with classification
SOC 2 CC6.3 Role-based access, least privilege and segregation of duties
Evidence to have on file (guidance, our wording)
  • the bank or treasury platform dual-authorisation setup and the payment approval workflow, showing a second approver on a different device above the threshold
  • the callback or out-of-band verification procedure for a change to payee bank details, with a dated example
SOC 2 CC6.1 Logical access security over protected information assets
Evidence to have on file (guidance, our wording)
  • Asset inventory with classification for in-scope systems
  • Identity provider configuration showing MFA and password policy
NIST CSF 2.0 PR.AA-05 Access permissions, entitlements, and authorizations are defined in a policy, managed, enforced, and reviewed, and incorporate the principles of least privilege and separation of duties
Evidence to have on file (guidance, our wording)
  • Access policy framework with role definitions
  • Privileged access management deployment evidence
NIST CSF 2.0 PR.AA-01 Identities and credentials for authorized users, services, and hardware are managed by the organization
Evidence to have on file (guidance, our wording)
  • Identity management platform configuration baseline
  • Joiner mover leaver workflow with timing SLAs
Application question Do you have a central Identity & Access Management ("IAM") system for assigning and revoking access rights?
Munich Re held application question
ISO 27001:2022 A.5.15 Access control
Evidence to have on file (guidance, our wording)
  • The topic-specific access control policy, approved and communicated, reflecting owner-defined business and security requirements
  • Access control rules or role models mapping entities (users, services, devices) to rights, consistent with classification
ISO 27001:2022 A.5.16 Identity management
Evidence to have on file (guidance, our wording)
  • Identity management procedure covering creation, verification, activation, change, disablement and removal
  • Evidence that identities are verified against trusted documents before issue
ISO 27001:2022 A.5.18 Access rights
Evidence to have on file (guidance, our wording)
  • Access request records showing owner authorization, and management approval where required, before rights were activated
  • A central record of access rights per user identifier across logical and physical access
SOC 2 CC6.1 Logical access security over protected information assets
Evidence to have on file (guidance, our wording)
  • Asset inventory with classification for in-scope systems
  • Identity provider configuration showing MFA and password policy
SOC 2 CC6.2 Registering and authorising users before issuing credentials
Evidence to have on file (guidance, our wording)
  • Access request tickets with owner approval for a sample of new users, service accounts and API credentials
  • Termination records reconciled to account disablement dates
NIST CSF 2.0 PR.AA-01 Identities and credentials for authorized users, services, and hardware are managed by the organization
Evidence to have on file (guidance, our wording)
  • Identity management platform configuration baseline
  • Joiner mover leaver workflow with timing SLAs
NIST CSF 2.0 PR.AA-05 Access permissions, entitlements, and authorizations are defined in a policy, managed, enforced, and reviewed, and incorporate the principles of least privilege and separation of duties
Evidence to have on file (guidance, our wording)
  • Access policy framework with role definitions
  • Privileged access management deployment evidence
Application question Do you have a formal process in place for assigning and revoking user accounts and access rights?
Munich Re held application question
ISO 27001:2022 A.5.15 Access control
Evidence to have on file (guidance, our wording)
  • The topic-specific access control policy, approved and communicated, reflecting owner-defined business and security requirements
  • Access control rules or role models mapping entities (users, services, devices) to rights, consistent with classification
ISO 27001:2022 A.5.16 Identity management
Evidence to have on file (guidance, our wording)
  • Identity management procedure covering creation, verification, activation, change, disablement and removal
  • Evidence that identities are verified against trusted documents before issue
ISO 27001:2022 A.5.18 Access rights
Evidence to have on file (guidance, our wording)
  • Access request records showing owner authorization, and management approval where required, before rights were activated
  • A central record of access rights per user identifier across logical and physical access
SOC 2 CC6.1 Logical access security over protected information assets
Evidence to have on file (guidance, our wording)
  • Asset inventory with classification for in-scope systems
  • Identity provider configuration showing MFA and password policy
SOC 2 CC6.2 Registering and authorising users before issuing credentials
Evidence to have on file (guidance, our wording)
  • Access request tickets with owner approval for a sample of new users, service accounts and API credentials
  • Termination records reconciled to account disablement dates
NIST CSF 2.0 PR.AA-01 Identities and credentials for authorized users, services, and hardware are managed by the organization
Evidence to have on file (guidance, our wording)
  • Identity management platform configuration baseline
  • Joiner mover leaver workflow with timing SLAs
NIST CSF 2.0 PR.AA-05 Access permissions, entitlements, and authorizations are defined in a policy, managed, enforced, and reviewed, and incorporate the principles of least privilege and separation of duties
Evidence to have on file (guidance, our wording)
  • Access policy framework with role definitions
  • Privileged access management deployment evidence
Application question Do assets owners review access rights at least annually?
Munich Re held application question
ISO 27001:2022 A.5.15 Access control
Evidence to have on file (guidance, our wording)
  • The topic-specific access control policy, approved and communicated, reflecting owner-defined business and security requirements
  • Access control rules or role models mapping entities (users, services, devices) to rights, consistent with classification
ISO 27001:2022 A.5.16 Identity management
Evidence to have on file (guidance, our wording)
  • Identity management procedure covering creation, verification, activation, change, disablement and removal
  • Evidence that identities are verified against trusted documents before issue
ISO 27001:2022 A.5.18 Access rights
Evidence to have on file (guidance, our wording)
  • Access request records showing owner authorization, and management approval where required, before rights were activated
  • A central record of access rights per user identifier across logical and physical access
SOC 2 CC6.1 Logical access security over protected information assets
Evidence to have on file (guidance, our wording)
  • Asset inventory with classification for in-scope systems
  • Identity provider configuration showing MFA and password policy
SOC 2 CC6.2 Registering and authorising users before issuing credentials
Evidence to have on file (guidance, our wording)
  • Access request tickets with owner approval for a sample of new users, service accounts and API credentials
  • Termination records reconciled to account disablement dates
NIST CSF 2.0 PR.AA-01 Identities and credentials for authorized users, services, and hardware are managed by the organization
Evidence to have on file (guidance, our wording)
  • Identity management platform configuration baseline
  • Joiner mover leaver workflow with timing SLAs
NIST CSF 2.0 PR.AA-05 Access permissions, entitlements, and authorizations are defined in a policy, managed, enforced, and reviewed, and incorporate the principles of least privilege and separation of duties
Evidence to have on file (guidance, our wording)
  • Access policy framework with role definitions
  • Privileged access management deployment evidence
Application question Do you allow Remote Desktop Protocol (RDP) connections?
Munich Re held application question
ISO 27001:2022 A.6.7 Remote working
Evidence to have on file (guidance, our wording)
  • The topic-specific remote working policy defining conditions, permitted work, information classifications allowed and systems accessible
  • Remote access configuration showing multi-factor authentication, secure channels or virtual desktops
ISO 27001:2022 A.8.20 Networks security
Evidence to have on file (guidance, our wording)
  • Current network diagrams and device configuration backups for routers, switches, firewalls and wireless controllers
  • Defined responsibilities and procedures for network device management, separated from system operations where appropriate
ISO 27001:2022 A.8.22 Segregation of networks
Evidence to have on file (guidance, our wording)
  • Network segmentation design defining domains by trust, criticality, sensitivity or organizational unit, with the assessment that justified it
  • Firewall or filtering router rules controlling traffic between domains, with rule review records
SOC 2 CC6.6 Protection against threats from outside the system boundary
Evidence to have on file (guidance, our wording)
  • Firewall and security group rule sets with review evidence
  • MFA enforced on VPN, remote and administrative access
NIST CSF 2.0 PR.IR-01 Networks and environments are protected from unauthorized logical access and usage
Evidence to have on file (guidance, our wording)
  • Network segmentation design with zones and trust levels
  • Firewall and access control list governance
Application question CyberArk, Delinea, BeyondTrust?
Munich Re held application question

No held control answers this line.

Application question If Yes, which of the following accounts are enrolled into the PAM tool?
Munich Re held application question

Flagged knockout: the wording of this question makes a "no" a common point at which a cyber application is declined or referred.

ISO 27001:2022 A.8.2 Privileged access rights
Evidence to have on file (guidance, our wording)
  • An inventory of privileged accounts per system (operating systems, databases, applications, cloud consoles) mapped to named individuals
  • Authorization records for each privileged grant with approver, justification and expiry
ISO 27001:2022 A.8.3 Information access restriction
Evidence to have on file (guidance, our wording)
  • System, application and cloud storage configurations restricting access by identity or group, with granular permissions per action
  • Evidence that anonymous or public access is limited to locations holding no sensitive information, for example storage bucket access reviews
ISO 27001:2022 A.5.15 Access control
Evidence to have on file (guidance, our wording)
  • The topic-specific access control policy, approved and communicated, reflecting owner-defined business and security requirements
  • Access control rules or role models mapping entities (users, services, devices) to rights, consistent with classification
SOC 2 CC6.3 Role-based access, least privilege and segregation of duties
Evidence to have on file (guidance, our wording)
  • the bank or treasury platform dual-authorisation setup and the payment approval workflow, showing a second approver on a different device above the threshold
  • the callback or out-of-band verification procedure for a change to payee bank details, with a dated example
SOC 2 CC6.1 Logical access security over protected information assets
Evidence to have on file (guidance, our wording)
  • Asset inventory with classification for in-scope systems
  • Identity provider configuration showing MFA and password policy
NIST CSF 2.0 PR.AA-05 Access permissions, entitlements, and authorizations are defined in a policy, managed, enforced, and reviewed, and incorporate the principles of least privilege and separation of duties
Evidence to have on file (guidance, our wording)
  • Access policy framework with role definitions
  • Privileged access management deployment evidence
Application question Which of the following features are enabled on the PAM tool?
Munich Re held application question

Flagged knockout: the wording of this question makes a "no" a common point at which a cyber application is declined or referred.

ISO 27001:2022 A.8.2 Privileged access rights
Evidence to have on file (guidance, our wording)
  • An inventory of privileged accounts per system (operating systems, databases, applications, cloud consoles) mapped to named individuals
  • Authorization records for each privileged grant with approver, justification and expiry
ISO 27001:2022 A.8.3 Information access restriction
Evidence to have on file (guidance, our wording)
  • System, application and cloud storage configurations restricting access by identity or group, with granular permissions per action
  • Evidence that anonymous or public access is limited to locations holding no sensitive information, for example storage bucket access reviews
ISO 27001:2022 A.5.15 Access control
Evidence to have on file (guidance, our wording)
  • The topic-specific access control policy, approved and communicated, reflecting owner-defined business and security requirements
  • Access control rules or role models mapping entities (users, services, devices) to rights, consistent with classification
SOC 2 CC6.3 Role-based access, least privilege and segregation of duties
Evidence to have on file (guidance, our wording)
  • the bank or treasury platform dual-authorisation setup and the payment approval workflow, showing a second approver on a different device above the threshold
  • the callback or out-of-band verification procedure for a change to payee bank details, with a dated example
SOC 2 CC6.1 Logical access security over protected information assets
Evidence to have on file (guidance, our wording)
  • Asset inventory with classification for in-scope systems
  • Identity provider configuration showing MFA and password policy
NIST CSF 2.0 PR.AA-05 Access permissions, entitlements, and authorizations are defined in a policy, managed, enforced, and reviewed, and incorporate the principles of least privilege and separation of duties
Evidence to have on file (guidance, our wording)
  • Access policy framework with role definitions
  • Privileged access management deployment evidence
Application question Is logging and alerting configured for all privileged account activity?
Munich Re held application question

Flagged knockout: the wording of this question makes a "no" a common point at which a cyber application is declined or referred.

ISO 27001:2022 A.8.2 Privileged access rights
Evidence to have on file (guidance, our wording)
  • An inventory of privileged accounts per system (operating systems, databases, applications, cloud consoles) mapped to named individuals
  • Authorization records for each privileged grant with approver, justification and expiry
ISO 27001:2022 A.8.3 Information access restriction
Evidence to have on file (guidance, our wording)
  • System, application and cloud storage configurations restricting access by identity or group, with granular permissions per action
  • Evidence that anonymous or public access is limited to locations holding no sensitive information, for example storage bucket access reviews
ISO 27001:2022 A.5.15 Access control
Evidence to have on file (guidance, our wording)
  • The topic-specific access control policy, approved and communicated, reflecting owner-defined business and security requirements
  • Access control rules or role models mapping entities (users, services, devices) to rights, consistent with classification
SOC 2 CC6.3 Role-based access, least privilege and segregation of duties
Evidence to have on file (guidance, our wording)
  • the bank or treasury platform dual-authorisation setup and the payment approval workflow, showing a second approver on a different device above the threshold
  • the callback or out-of-band verification procedure for a change to payee bank details, with a dated example
SOC 2 CC6.1 Logical access security over protected information assets
Evidence to have on file (guidance, our wording)
  • Asset inventory with classification for in-scope systems
  • Identity provider configuration showing MFA and password policy
NIST CSF 2.0 PR.AA-05 Access permissions, entitlements, and authorizations are defined in a policy, managed, enforced, and reviewed, and incorporate the principles of least privilege and separation of duties
Evidence to have on file (guidance, our wording)
  • Access policy framework with role definitions
  • Privileged access management deployment evidence
NIST CSF 2.0 DE.CM-01 Networks and network services are monitored to find potentially adverse events
Evidence to have on file (guidance, our wording)
  • Network flow telemetry coverage map by segment
  • IDS or NDR sensor inventory with placement diagram
Application question Are domain admin accounts limited to administrative functions only?
Munich Re held application question

Flagged knockout: the wording of this question makes a "no" a common point at which a cyber application is declined or referred.

ISO 27001:2022 A.8.2 Privileged access rights
Evidence to have on file (guidance, our wording)
  • An inventory of privileged accounts per system (operating systems, databases, applications, cloud consoles) mapped to named individuals
  • Authorization records for each privileged grant with approver, justification and expiry
ISO 27001:2022 A.8.3 Information access restriction
Evidence to have on file (guidance, our wording)
  • System, application and cloud storage configurations restricting access by identity or group, with granular permissions per action
  • Evidence that anonymous or public access is limited to locations holding no sensitive information, for example storage bucket access reviews
ISO 27001:2022 A.5.15 Access control
Evidence to have on file (guidance, our wording)
  • The topic-specific access control policy, approved and communicated, reflecting owner-defined business and security requirements
  • Access control rules or role models mapping entities (users, services, devices) to rights, consistent with classification
SOC 2 CC6.3 Role-based access, least privilege and segregation of duties
Evidence to have on file (guidance, our wording)
  • the bank or treasury platform dual-authorisation setup and the payment approval workflow, showing a second approver on a different device above the threshold
  • the callback or out-of-band verification procedure for a change to payee bank details, with a dated example
SOC 2 CC6.1 Logical access security over protected information assets
Evidence to have on file (guidance, our wording)
  • Asset inventory with classification for in-scope systems
  • Identity provider configuration showing MFA and password policy
NIST CSF 2.0 PR.AA-05 Access permissions, entitlements, and authorizations are defined in a policy, managed, enforced, and reviewed, and incorporate the principles of least privilege and separation of duties
Evidence to have on file (guidance, our wording)
  • Access policy framework with role definitions
  • Privileged access management deployment evidence
Application question Please provide the number of service accounts in the domain admin group?
Munich Re held application question

Flagged knockout: the wording of this question makes a "no" a common point at which a cyber application is declined or referred.

ISO 27001:2022 A.8.2 Privileged access rights
Evidence to have on file (guidance, our wording)
  • An inventory of privileged accounts per system (operating systems, databases, applications, cloud consoles) mapped to named individuals
  • Authorization records for each privileged grant with approver, justification and expiry
ISO 27001:2022 A.8.3 Information access restriction
Evidence to have on file (guidance, our wording)
  • System, application and cloud storage configurations restricting access by identity or group, with granular permissions per action
  • Evidence that anonymous or public access is limited to locations holding no sensitive information, for example storage bucket access reviews
ISO 27001:2022 A.5.15 Access control
Evidence to have on file (guidance, our wording)
  • The topic-specific access control policy, approved and communicated, reflecting owner-defined business and security requirements
  • Access control rules or role models mapping entities (users, services, devices) to rights, consistent with classification
SOC 2 CC6.3 Role-based access, least privilege and segregation of duties
Evidence to have on file (guidance, our wording)
  • the bank or treasury platform dual-authorisation setup and the payment approval workflow, showing a second approver on a different device above the threshold
  • the callback or out-of-band verification procedure for a change to payee bank details, with a dated example
SOC 2 CC6.1 Logical access security over protected information assets
Evidence to have on file (guidance, our wording)
  • Asset inventory with classification for in-scope systems
  • Identity provider configuration showing MFA and password policy
NIST CSF 2.0 PR.AA-05 Access permissions, entitlements, and authorizations are defined in a policy, managed, enforced, and reviewed, and incorporate the principles of least privilege and separation of duties
Evidence to have on file (guidance, our wording)
  • Access policy framework with role definitions
  • Privileged access management deployment evidence
Application question Do you configure service accounts using the principle of least privilege?
Munich Re held application question

Flagged knockout: the wording of this question makes a "no" a common point at which a cyber application is declined or referred.

ISO 27001:2022 A.8.2 Privileged access rights
Evidence to have on file (guidance, our wording)
  • An inventory of privileged accounts per system (operating systems, databases, applications, cloud consoles) mapped to named individuals
  • Authorization records for each privileged grant with approver, justification and expiry
ISO 27001:2022 A.8.3 Information access restriction
Evidence to have on file (guidance, our wording)
  • System, application and cloud storage configurations restricting access by identity or group, with granular permissions per action
  • Evidence that anonymous or public access is limited to locations holding no sensitive information, for example storage bucket access reviews
ISO 27001:2022 A.5.15 Access control
Evidence to have on file (guidance, our wording)
  • The topic-specific access control policy, approved and communicated, reflecting owner-defined business and security requirements
  • Access control rules or role models mapping entities (users, services, devices) to rights, consistent with classification
SOC 2 CC6.3 Role-based access, least privilege and segregation of duties
Evidence to have on file (guidance, our wording)
  • the bank or treasury platform dual-authorisation setup and the payment approval workflow, showing a second approver on a different device above the threshold
  • the callback or out-of-band verification procedure for a change to payee bank details, with a dated example
SOC 2 CC6.1 Logical access security over protected information assets
Evidence to have on file (guidance, our wording)
  • Asset inventory with classification for in-scope systems
  • Identity provider configuration showing MFA and password policy
NIST CSF 2.0 PR.AA-05 Access permissions, entitlements, and authorizations are defined in a policy, managed, enforced, and reviewed, and incorporate the principles of least privilege and separation of duties
Evidence to have on file (guidance, our wording)
  • Access policy framework with role definitions
  • Privileged access management deployment evidence
NIST CSF 2.0 PR.AA-01 Identities and credentials for authorized users, services, and hardware are managed by the organization
Evidence to have on file (guidance, our wording)
  • Identity management platform configuration baseline
  • Joiner mover leaver workflow with timing SLAs
Application question Do you configure service accounts to deny interactive log-ins?
Munich Re held application question
ISO 27001:2022 A.8.2 Privileged access rights
Evidence to have on file (guidance, our wording)
  • An inventory of privileged accounts per system (operating systems, databases, applications, cloud consoles) mapped to named individuals
  • Authorization records for each privileged grant with approver, justification and expiry
ISO 27001:2022 A.8.3 Information access restriction
Evidence to have on file (guidance, our wording)
  • System, application and cloud storage configurations restricting access by identity or group, with granular permissions per action
  • Evidence that anonymous or public access is limited to locations holding no sensitive information, for example storage bucket access reviews
ISO 27001:2022 A.5.15 Access control
Evidence to have on file (guidance, our wording)
  • The topic-specific access control policy, approved and communicated, reflecting owner-defined business and security requirements
  • Access control rules or role models mapping entities (users, services, devices) to rights, consistent with classification
SOC 2 CC6.3 Role-based access, least privilege and segregation of duties
Evidence to have on file (guidance, our wording)
  • the bank or treasury platform dual-authorisation setup and the payment approval workflow, showing a second approver on a different device above the threshold
  • the callback or out-of-band verification procedure for a change to payee bank details, with a dated example
SOC 2 CC6.1 Logical access security over protected information assets
Evidence to have on file (guidance, our wording)
  • Asset inventory with classification for in-scope systems
  • Identity provider configuration showing MFA and password policy
NIST CSF 2.0 PR.AA-05 Access permissions, entitlements, and authorizations are defined in a policy, managed, enforced, and reviewed, and incorporate the principles of least privilege and separation of duties
Evidence to have on file (guidance, our wording)
  • Access policy framework with role definitions
  • Privileged access management deployment evidence
NIST CSF 2.0 DE.CM-01 Networks and network services are monitored to find potentially adverse events
Evidence to have on file (guidance, our wording)
  • Network flow telemetry coverage map by segment
  • IDS or NDR sensor inventory with placement diagram
Application question Do you log the activity of service accounts that are able to override system or application controls (e.g. elevation  Yes  No of privileges, lateral movement etc.?
Munich Re held application question

Flagged knockout: the wording of this question makes a "no" a common point at which a cyber application is declined or referred.

ISO 27001:2022 A.8.2 Privileged access rights
Evidence to have on file (guidance, our wording)
  • An inventory of privileged accounts per system (operating systems, databases, applications, cloud consoles) mapped to named individuals
  • Authorization records for each privileged grant with approver, justification and expiry
ISO 27001:2022 A.8.3 Information access restriction
Evidence to have on file (guidance, our wording)
  • System, application and cloud storage configurations restricting access by identity or group, with granular permissions per action
  • Evidence that anonymous or public access is limited to locations holding no sensitive information, for example storage bucket access reviews
ISO 27001:2022 A.5.15 Access control
Evidence to have on file (guidance, our wording)
  • The topic-specific access control policy, approved and communicated, reflecting owner-defined business and security requirements
  • Access control rules or role models mapping entities (users, services, devices) to rights, consistent with classification
SOC 2 CC6.3 Role-based access, least privilege and segregation of duties
Evidence to have on file (guidance, our wording)
  • the bank or treasury platform dual-authorisation setup and the payment approval workflow, showing a second approver on a different device above the threshold
  • the callback or out-of-band verification procedure for a change to payee bank details, with a dated example
SOC 2 CC6.1 Logical access security over protected information assets
Evidence to have on file (guidance, our wording)
  • Asset inventory with classification for in-scope systems
  • Identity provider configuration showing MFA and password policy
NIST CSF 2.0 PR.AA-05 Access permissions, entitlements, and authorizations are defined in a policy, managed, enforced, and reviewed, and incorporate the principles of least privilege and separation of duties
Evidence to have on file (guidance, our wording)
  • Access policy framework with role definitions
  • Privileged access management deployment evidence
NIST CSF 2.0 DE.CM-01 Networks and network services are monitored to find potentially adverse events
Evidence to have on file (guidance, our wording)
  • Network flow telemetry coverage map by segment
  • IDS or NDR sensor inventory with placement diagram
Application question Do you prohibit local admin rights on workstations for users?
Munich Re held application question

Flagged knockout: the wording of this question makes a "no" a common point at which a cyber application is declined or referred.

ISO 27001:2022 A.8.2 Privileged access rights
Evidence to have on file (guidance, our wording)
  • An inventory of privileged accounts per system (operating systems, databases, applications, cloud consoles) mapped to named individuals
  • Authorization records for each privileged grant with approver, justification and expiry
ISO 27001:2022 A.8.3 Information access restriction
Evidence to have on file (guidance, our wording)
  • System, application and cloud storage configurations restricting access by identity or group, with granular permissions per action
  • Evidence that anonymous or public access is limited to locations holding no sensitive information, for example storage bucket access reviews
ISO 27001:2022 A.5.15 Access control
Evidence to have on file (guidance, our wording)
  • The topic-specific access control policy, approved and communicated, reflecting owner-defined business and security requirements
  • Access control rules or role models mapping entities (users, services, devices) to rights, consistent with classification
SOC 2 CC6.3 Role-based access, least privilege and segregation of duties
Evidence to have on file (guidance, our wording)
  • the bank or treasury platform dual-authorisation setup and the payment approval workflow, showing a second approver on a different device above the threshold
  • the callback or out-of-band verification procedure for a change to payee bank details, with a dated example
SOC 2 CC6.1 Logical access security over protected information assets
Evidence to have on file (guidance, our wording)
  • Asset inventory with classification for in-scope systems
  • Identity provider configuration showing MFA and password policy
NIST CSF 2.0 PR.AA-05 Access permissions, entitlements, and authorizations are defined in a policy, managed, enforced, and reviewed, and incorporate the principles of least privilege and separation of duties
Evidence to have on file (guidance, our wording)
  • Access policy framework with role definitions
  • Privileged access management deployment evidence
Application question Do you enforce the use of encryption over all external communication lines (e.g. website, email, wireless?
Munich Re held application question
ISO 27001:2022 A.8.24 Use of cryptography
Evidence to have on file (guidance, our wording)
  • The topic-specific cryptography policy with approved algorithms, key lengths, protocols and usage by information classification
  • Evidence of encryption on endpoints, removable media and data in transit, aligned with the policy
ISO 27001:2022 A.5.14 Information transfer
Evidence to have on file (guidance, our wording)
  • The topic-specific information transfer policy and its communication record
  • Transfer agreements with third parties covering recipient authentication, protection levels, incident liability and labelling
SOC 2 CC6.7 Restricting and protecting information in transmission, movement and removal
Evidence to have on file (guidance, our wording)
  • TLS and encryption standards for data in transit
  • Removable media policy and technical enforcement
SOC 2 CC6.1 Logical access security over protected information assets
Evidence to have on file (guidance, our wording)
  • Asset inventory with classification for in-scope systems
  • Identity provider configuration showing MFA and password policy
NIST CSF 2.0 PR.DS-02 The confidentiality, integrity, and availability of data-in-transit are protected
Evidence to have on file (guidance, our wording)
  • TLS configuration standards and scan results
  • VPN and zero trust network access policy
NIST CSF 2.0 PR.DS-01 The confidentiality, integrity, and availability of data-at-rest are protected
Evidence to have on file (guidance, our wording)
  • Data at rest encryption inventory by store type
  • Storage configuration baselines with attestation
Application question Do you enforce the use of encryption of sensitive information while at rest (e.g. on premise, mobile device,  Yes  No cloud?
Munich Re held application question
ISO 27001:2022 A.8.24 Use of cryptography
Evidence to have on file (guidance, our wording)
  • The topic-specific cryptography policy with approved algorithms, key lengths, protocols and usage by information classification
  • Evidence of encryption on endpoints, removable media and data in transit, aligned with the policy
ISO 27001:2022 A.7.10 Storage media
Evidence to have on file (guidance, our wording)
  • The topic-specific removable media policy and evidence it was communicated to users
  • Endpoint configuration showing USB and SD ports disabled unless a business reason is approved, and monitoring of transfers to removable media
ISO 27001:2022 A.8.1 User end point devices
Evidence to have on file (guidance, our wording)
  • The topic-specific endpoint policy covering classification limits, registration, software restrictions, updates, network connection rules, encryption, malware protection, remote wipe, backup and port control
  • Device management (MDM or endpoint management) reports showing enrolment, encryption, patch level, firewall and anti-malware status
SOC 2 CC6.1 Logical access security over protected information assets
Evidence to have on file (guidance, our wording)
  • Asset inventory with classification for in-scope systems
  • Identity provider configuration showing MFA and password policy
SOC 2 CC6.7 Restricting and protecting information in transmission, movement and removal
Evidence to have on file (guidance, our wording)
  • TLS and encryption standards for data in transit
  • Removable media policy and technical enforcement
NIST CSF 2.0 PR.DS-01 The confidentiality, integrity, and availability of data-at-rest are protected
Evidence to have on file (guidance, our wording)
  • Data at rest encryption inventory by store type
  • Storage configuration baselines with attestation
NIST CSF 2.0 PR.DS-02 The confidentiality, integrity, and availability of data-in-transit are protected
Evidence to have on file (guidance, our wording)
  • TLS configuration standards and scan results
  • VPN and zero trust network access policy
Application question Does your company operate a clean desk policy at all sites?
Munich Re held application question
ISO 27001:2022 A.7.1 Physical security perimeters
Evidence to have on file (guidance, our wording)
  • Site plans showing defined security perimeters and their strength relative to the assets inside
  • Physical security surveys or assessments of walls, roofs, floors, doors, windows and vents
ISO 27001:2022 A.7.2 Physical entry
Evidence to have on file (guidance, our wording)
  • Physical access rights records with provisioning, periodic review and revocation evidence
  • Electronic access control logs or physical logbooks, protected and monitored
ISO 27001:2022 A.7.3 Securing offices, rooms and facilities
Evidence to have on file (guidance, our wording)
  • Facility security design documentation showing critical facilities sited away from public access
  • Photographs or survey records confirming the absence of signage revealing processing facilities
SOC 2 CC6.4 Restricting physical access to facilities and assets
Evidence to have on file (guidance, our wording)
  • Badge access provisioning and removal records
  • Periodic physical access review for sensitive areas
SOC 2 CC6.5 Protecting data on assets until disposal
Evidence to have on file (guidance, our wording)
  • Media sanitisation and disposal procedure
  • Certificates of destruction or wipe logs for disposed devices
NIST CSF 2.0 PR.AA-06 Physical access to assets is managed, monitored, and enforced commensurate with risk
Evidence to have on file (guidance, our wording)
  • Physical access control system inventory
  • Badge issuance and revocation records
NIST CSF 2.0 PR.IR-02 The organization's technology assets are protected from environmental threats
Evidence to have on file (guidance, our wording)
  • Environmental controls inventory (HVAC, power, fire)
  • Site risk assessments with mitigation status
Application question What type of endpoint protection solution is used?
Munich Re held application question

This is a scoping question, not a control requirement. It reaches no held control.

No held control answers this line.

Application question What is the deployment percentage on the following endpoints?
Munich Re held application question

No held control answers this line.

Application question How are your backups stored?
Munich Re held application question
ISO 27001:2022 A.8.13 Information backup
Evidence to have on file (guidance, our wording)
  • The topic-specific backup policy and backup plans stating scope, extent, frequency and retention per system aligned with RPO
  • Backup job monitoring reports with evidence that failed jobs were investigated and rerun
ISO 27001:2022 A.8.14 Redundancy of information processing facilities
Evidence to have on file (guidance, our wording)
  • Documented availability requirements for business services and systems
  • Architecture diagrams showing redundancy such as dual providers, redundant networks, separate data centres, redundant power and load-balanced instances
SOC 2 A1.2 Environmental protection, backup and recovery infrastructure
Evidence to have on file (guidance, our wording)
  • Backup policy defining scope, frequency and retention
  • Backup job monitoring and failure remediation records
SOC 2 A1.3 Testing recovery plan procedures
Evidence to have on file (guidance, our wording)
  • Disaster recovery or continuity test plan and results in the period
  • Backup restore test records with verification of completeness
NIST CSF 2.0 PR.DS-11 Backups of data are created, protected, maintained, and tested
Evidence to have on file (guidance, our wording)
  • Backup policy with frequency and retention
  • Backup integrity test reports
Application question Are unique backup credentials stored separately from other user credentials?
Munich Re held application question

Flagged knockout: the wording of this question makes a "no" a common point at which a cyber application is declined or referred.

ISO 27001:2022 A.5.17 Authentication information
Evidence to have on file (guidance, our wording)
  • Credential issuance procedure requiring identity verification before new, replacement or temporary credentials are provided
  • Evidence that initial credentials are unique, delivered over protected channels and changed at first use
ISO 27001:2022 A.8.5 Secure authentication
Evidence to have on file (guidance, our wording)
  • An authentication standard linking required authentication strength to information classification and system criticality
  • MFA configuration and coverage reports for critical systems, remote access and privileged access, including conditional or risk-based rules
ISO 27001:2022 A.8.13 Information backup
Evidence to have on file (guidance, our wording)
  • The topic-specific backup policy and backup plans stating scope, extent, frequency and retention per system aligned with RPO
  • Backup job monitoring reports with evidence that failed jobs were investigated and rerun
SOC 2 CC6.1 Logical access security over protected information assets
Evidence to have on file (guidance, our wording)
  • Asset inventory with classification for in-scope systems
  • Identity provider configuration showing MFA and password policy
SOC 2 A1.2 Environmental protection, backup and recovery infrastructure
Evidence to have on file (guidance, our wording)
  • Backup policy defining scope, frequency and retention
  • Backup job monitoring and failure remediation records
NIST CSF 2.0 PR.AA-01 Identities and credentials for authorized users, services, and hardware are managed by the organization
Evidence to have on file (guidance, our wording)
  • Identity management platform configuration baseline
  • Joiner mover leaver workflow with timing SLAs
NIST CSF 2.0 PR.DS-11 Backups of data are created, protected, maintained, and tested
Evidence to have on file (guidance, our wording)
  • Backup policy with frequency and retention
  • Backup integrity test reports
Application question Are backup processes tested to ensure data can be restored with minimal impact to the business?
Munich Re held application question

Flagged knockout: the wording of this question makes a "no" a common point at which a cyber application is declined or referred.

ISO 27001:2022 A.8.13 Information backup
Evidence to have on file (guidance, our wording)
  • The topic-specific backup policy and backup plans stating scope, extent, frequency and retention per system aligned with RPO
  • Backup job monitoring reports with evidence that failed jobs were investigated and rerun
ISO 27001:2022 A.8.14 Redundancy of information processing facilities
Evidence to have on file (guidance, our wording)
  • Documented availability requirements for business services and systems
  • Architecture diagrams showing redundancy such as dual providers, redundant networks, separate data centres, redundant power and load-balanced instances
SOC 2 A1.2 Environmental protection, backup and recovery infrastructure
Evidence to have on file (guidance, our wording)
  • Backup policy defining scope, frequency and retention
  • Backup job monitoring and failure remediation records
SOC 2 A1.3 Testing recovery plan procedures
Evidence to have on file (guidance, our wording)
  • Disaster recovery or continuity test plan and results in the period
  • Backup restore test records with verification of completeness
NIST CSF 2.0 PR.DS-11 Backups of data are created, protected, maintained, and tested
Evidence to have on file (guidance, our wording)
  • Backup policy with frequency and retention
  • Backup integrity test reports
Application question Are your audit logs immutable?
Munich Re held application question
ISO 27001:2022 A.8.15 Logging
Evidence to have on file (guidance, our wording)
  • The topic-specific logging policy defining purposes, events to be logged, fields captured, retention and protection
ISO 27001:2022 A.8.16 Monitoring activities
Evidence to have on file (guidance, our wording)
  • A documented monitoring scope covering network traffic, system access, configuration files, security tool logs, code integrity and resource use, with retention periods
  • Baselines of normal behaviour for systems and user groups, and the detection rules built on them
SOC 2 CC7.1 Detecting configuration changes and new vulnerabilities
Evidence to have on file (guidance, our wording)
  • Hardening standards or benchmarks for in-scope platforms
  • Configuration compliance scan results
SOC 2 CC7.2 Monitoring system components for anomalies
Evidence to have on file (guidance, our wording)
  • Alert rules and sample of triaged alerts
  • Threat intelligence sources in use
NIST CSF 2.0 DE.CM-01 Networks and network services are monitored to find potentially adverse events
Evidence to have on file (guidance, our wording)
  • Network flow telemetry coverage map by segment
  • IDS or NDR sensor inventory with placement diagram
NIST CSF 2.0 PR.PS-04 Log records are generated and made available for continuous monitoring
Evidence to have on file (guidance, our wording)
  • Logging policy by data class and system tier
  • Centralized log collection architecture
Application question Do you regularly conduct vulnerability scanning across your internal and external-facing assets?
Munich Re held application question
ISO 27001:2022 A.8.8 Management of technical vulnerabilities
Evidence to have on file (guidance, our wording)
  • A software asset inventory with vendor, product, version, deployment location and responsible owner
  • Defined vulnerability management roles and a list of monitored vulnerability information sources
ISO 27001:2022 A.8.19 Installation of software on operational systems
Evidence to have on file (guidance, our wording)
  • Procedures for installing and updating operational software, including authorization, testing and rollback planning
  • Change and deployment records showing management authorization, successful testing and the administrator who performed the installation
ISO 27001:2022 A.8.29 Security testing in development and acceptance
Evidence to have on file (guidance, our wording)
  • Security test plans with schedules, inputs, expected outputs, evaluation criteria and decisions, scaled to the system's importance and change impact
  • Security test results covering authentication, access restriction, cryptography, secure coding and configuration
SOC 2 CC7.1 Detecting configuration changes and new vulnerabilities
Evidence to have on file (guidance, our wording)
  • Hardening standards or benchmarks for in-scope platforms
  • Configuration compliance scan results
NIST CSF 2.0 ID.RA-01 Vulnerabilities in assets are identified, validated, and recorded
Evidence to have on file (guidance, our wording)
  • Vulnerability scanning coverage report
  • Vulnerability triage workflow with severity SLAs
NIST CSF 2.0 PR.PS-02 Software is maintained, replaced, and removed commensurate with risk
Evidence to have on file (guidance, our wording)
  • Software lifecycle policy with end of support tracking
  • Patch management cadence and exception register
Application question Do you technically prohibit users from installing unauthorised software on their devices?
Munich Re held application question

No held control answers this line.

Application question Do have a whitelist of software that users and system administrators are permitted to install?
Munich Re held application question

No held control answers this line.

Application question If Yes, does your company implement any of the following?
Munich Re held application question

No held control answers this line.

Application question Is web-based email available to employees?
Munich Re held application question
ISO 27001:2022 A.8.5 Secure authentication
Evidence to have on file (guidance, our wording)
  • An authentication standard linking required authentication strength to information classification and system criticality
  • MFA configuration and coverage reports for critical systems, remote access and privileged access, including conditional or risk-based rules
ISO 27001:2022 A.5.15 Access control
Evidence to have on file (guidance, our wording)
  • The topic-specific access control policy, approved and communicated, reflecting owner-defined business and security requirements
  • Access control rules or role models mapping entities (users, services, devices) to rights, consistent with classification
SOC 2 CC6.1 Logical access security over protected information assets
Evidence to have on file (guidance, our wording)
  • Asset inventory with classification for in-scope systems
  • Identity provider configuration showing MFA and password policy
NIST CSF 2.0 PR.AA-03 Users, services, and hardware are authenticated
Evidence to have on file (guidance, our wording)
  • Multi factor authentication coverage report
  • Phishing resistant authentication rollout plan
Application question Are logins to web-based email monitored with alerts for suspicious activity implemented?
Munich Re held application question
ISO 27001:2022 A.8.15 Logging
Evidence to have on file (guidance, our wording)
  • The topic-specific logging policy defining purposes, events to be logged, fields captured, retention and protection
ISO 27001:2022 A.8.16 Monitoring activities
Evidence to have on file (guidance, our wording)
  • A documented monitoring scope covering network traffic, system access, configuration files, security tool logs, code integrity and resource use, with retention periods
  • Baselines of normal behaviour for systems and user groups, and the detection rules built on them
ISO 27001:2022 A.8.5 Secure authentication
Evidence to have on file (guidance, our wording)
  • An authentication standard linking required authentication strength to information classification and system criticality
  • MFA configuration and coverage reports for critical systems, remote access and privileged access, including conditional or risk-based rules
SOC 2 CC7.1 Detecting configuration changes and new vulnerabilities
Evidence to have on file (guidance, our wording)
  • Hardening standards or benchmarks for in-scope platforms
  • Configuration compliance scan results
SOC 2 CC7.2 Monitoring system components for anomalies
Evidence to have on file (guidance, our wording)
  • Alert rules and sample of triaged alerts
  • Threat intelligence sources in use
NIST CSF 2.0 DE.CM-01 Networks and network services are monitored to find potentially adverse events
Evidence to have on file (guidance, our wording)
  • Network flow telemetry coverage map by segment
  • IDS or NDR sensor inventory with placement diagram
NIST CSF 2.0 PR.PS-04 Log records are generated and made available for continuous monitoring
Evidence to have on file (guidance, our wording)
  • Logging policy by data class and system tier
  • Centralized log collection architecture
Application question Is multi-factor authentication (MFA) in place for web-based email logins?
Munich Re held application question

Flagged knockout: the wording of this question makes a "no" a common point at which a cyber application is declined or referred.

ISO 27001:2022 A.8.5 Secure authentication
Evidence to have on file (guidance, our wording)
  • An authentication standard linking required authentication strength to information classification and system criticality
  • MFA configuration and coverage reports for critical systems, remote access and privileged access, including conditional or risk-based rules
ISO 27001:2022 A.5.17 Authentication information
Evidence to have on file (guidance, our wording)
  • Credential issuance procedure requiring identity verification before new, replacement or temporary credentials are provided
  • Evidence that initial credentials are unique, delivered over protected channels and changed at first use
ISO 27001:2022 A.5.15 Access control
Evidence to have on file (guidance, our wording)
  • The topic-specific access control policy, approved and communicated, reflecting owner-defined business and security requirements
  • Access control rules or role models mapping entities (users, services, devices) to rights, consistent with classification
SOC 2 CC6.1 Logical access security over protected information assets
Evidence to have on file (guidance, our wording)
  • Asset inventory with classification for in-scope systems
  • Identity provider configuration showing MFA and password policy
NIST CSF 2.0 PR.AA-03 Users, services, and hardware are authenticated
Evidence to have on file (guidance, our wording)
  • Multi factor authentication coverage report
  • Phishing resistant authentication rollout plan
Application question What type of email filtering is deployed?
Munich Re held application question

This is a scoping question, not a control requirement. It reaches no held control.

No held control answers this line.

Application question Do you implement any of the following controls to protect against malicious emails?
Munich Re held application question
ISO 27001:2022 A.8.23 Web filtering
Evidence to have on file (guidance, our wording)
  • Current rules on safe, proper use of online resources
  • Web filtering or secure web gateway configuration showing blocked categories such as malicious, phishing, command and control, illegal content and upload sites
ISO 27001:2022 A.8.7 Protection against malware
Evidence to have on file (guidance, our wording)
  • Anti-malware deployment and update status reports across endpoints, servers and gateways
  • Application allowlisting and malicious website blocking configurations
ISO 27001:2022 A.5.14 Information transfer
Evidence to have on file (guidance, our wording)
  • The topic-specific information transfer policy and its communication record
  • Transfer agreements with third parties covering recipient authentication, protection levels, incident liability and labelling
SOC 2 CC6.8 Preventing and detecting unauthorised or malicious software
Evidence to have on file (guidance, our wording)
  • Endpoint protection coverage report across servers and workstations
  • Local administrator and software installation restrictions
NIST CSF 2.0 PR.PS-05 Installation and execution of unauthorized software are prevented
Evidence to have on file (guidance, our wording)
  • Application allowlist policy and tooling configuration
  • Endpoint protection deployment reports
Application question Do you utilize a Data Loss Prevention (DLP) product for email?
Munich Re held application question
ISO 27001:2022 A.8.12 Data leakage prevention
Evidence to have on file (guidance, our wording)
  • An inventory of information types and classifications in scope for leakage protection
  • DLP policies and rules covering email, web uploads, file transfer, endpoints and removable storage, with the actions taken (alert, quarantine, block)
ISO 27001:2022 A.8.24 Use of cryptography
Evidence to have on file (guidance, our wording)
  • The topic-specific cryptography policy with approved algorithms, key lengths, protocols and usage by information classification
  • Evidence of encryption on endpoints, removable media and data in transit, aligned with the policy
SOC 2 CC6.7 Restricting and protecting information in transmission, movement and removal
Evidence to have on file (guidance, our wording)
  • TLS and encryption standards for data in transit
  • Removable media policy and technical enforcement
SOC 2 C1.1 Identifying and maintaining confidential information
Evidence to have on file (guidance, our wording)
  • Data classification policy defining confidential information
  • Data inventory tagging confidential data and its retention period
NIST CSF 2.0 PR.DS-01 The confidentiality, integrity, and availability of data-at-rest are protected
Evidence to have on file (guidance, our wording)
  • Data at rest encryption inventory by store type
  • Storage configuration baselines with attestation
NIST CSF 2.0 PR.DS-02 The confidentiality, integrity, and availability of data-in-transit are protected
Evidence to have on file (guidance, our wording)
  • TLS configuration standards and scan results
  • VPN and zero trust network access policy
Application question Is a DLP solution in use on endpoints, external and internal (including email) servers?
Munich Re held application question
ISO 27001:2022 A.8.12 Data leakage prevention
Evidence to have on file (guidance, our wording)
  • An inventory of information types and classifications in scope for leakage protection
  • DLP policies and rules covering email, web uploads, file transfer, endpoints and removable storage, with the actions taken (alert, quarantine, block)
ISO 27001:2022 A.8.24 Use of cryptography
Evidence to have on file (guidance, our wording)
  • The topic-specific cryptography policy with approved algorithms, key lengths, protocols and usage by information classification
  • Evidence of encryption on endpoints, removable media and data in transit, aligned with the policy
SOC 2 CC6.7 Restricting and protecting information in transmission, movement and removal
Evidence to have on file (guidance, our wording)
  • TLS and encryption standards for data in transit
  • Removable media policy and technical enforcement
SOC 2 C1.1 Identifying and maintaining confidential information
Evidence to have on file (guidance, our wording)
  • Data classification policy defining confidential information
  • Data inventory tagging confidential data and its retention period
NIST CSF 2.0 PR.DS-01 The confidentiality, integrity, and availability of data-at-rest are protected
Evidence to have on file (guidance, our wording)
  • Data at rest encryption inventory by store type
  • Storage configuration baselines with attestation
NIST CSF 2.0 PR.DS-02 The confidentiality, integrity, and availability of data-in-transit are protected
Evidence to have on file (guidance, our wording)
  • TLS configuration standards and scan results
  • VPN and zero trust network access policy
Application question Do you scan incoming emails for malicious attachments and/or links?
Munich Re held application question
ISO 27001:2022 A.8.23 Web filtering
Evidence to have on file (guidance, our wording)
  • Current rules on safe, proper use of online resources
  • Web filtering or secure web gateway configuration showing blocked categories such as malicious, phishing, command and control, illegal content and upload sites
ISO 27001:2022 A.8.7 Protection against malware
Evidence to have on file (guidance, our wording)
  • Anti-malware deployment and update status reports across endpoints, servers and gateways
  • Application allowlisting and malicious website blocking configurations
ISO 27001:2022 A.5.14 Information transfer
Evidence to have on file (guidance, our wording)
  • The topic-specific information transfer policy and its communication record
  • Transfer agreements with third parties covering recipient authentication, protection levels, incident liability and labelling
SOC 2 CC6.8 Preventing and detecting unauthorised or malicious software
Evidence to have on file (guidance, our wording)
  • Endpoint protection coverage report across servers and workstations
  • Local administrator and software installation restrictions
NIST CSF 2.0 PR.PS-05 Installation and execution of unauthorized software are prevented
Evidence to have on file (guidance, our wording)
  • Application allowlist policy and tooling configuration
  • Endpoint protection deployment reports
Application question Do you have the ability to automatically quarantine, detonate and evaluate attachments?
Munich Re held application question
ISO 27001:2022 A.8.23 Web filtering
Evidence to have on file (guidance, our wording)
  • Current rules on safe, proper use of online resources
  • Web filtering or secure web gateway configuration showing blocked categories such as malicious, phishing, command and control, illegal content and upload sites
ISO 27001:2022 A.8.7 Protection against malware
Evidence to have on file (guidance, our wording)
  • Anti-malware deployment and update status reports across endpoints, servers and gateways
  • Application allowlisting and malicious website blocking configurations
ISO 27001:2022 A.5.14 Information transfer
Evidence to have on file (guidance, our wording)
  • The topic-specific information transfer policy and its communication record
  • Transfer agreements with third parties covering recipient authentication, protection levels, incident liability and labelling
SOC 2 CC6.8 Preventing and detecting unauthorised or malicious software
Evidence to have on file (guidance, our wording)
  • Endpoint protection coverage report across servers and workstations
  • Local administrator and software installation restrictions
NIST CSF 2.0 PR.PS-05 Installation and execution of unauthorized software are prevented
Evidence to have on file (guidance, our wording)
  • Application allowlist policy and tooling configuration
  • Endpoint protection deployment reports
Application question Are blocked emails classed as incidents and remediated?
Munich Re held application question
ISO 27001:2022 A.8.23 Web filtering
Evidence to have on file (guidance, our wording)
  • Current rules on safe, proper use of online resources
  • Web filtering or secure web gateway configuration showing blocked categories such as malicious, phishing, command and control, illegal content and upload sites
ISO 27001:2022 A.8.7 Protection against malware
Evidence to have on file (guidance, our wording)
  • Anti-malware deployment and update status reports across endpoints, servers and gateways
  • Application allowlisting and malicious website blocking configurations
ISO 27001:2022 A.5.14 Information transfer
Evidence to have on file (guidance, our wording)
  • The topic-specific information transfer policy and its communication record
  • Transfer agreements with third parties covering recipient authentication, protection levels, incident liability and labelling
SOC 2 CC6.8 Preventing and detecting unauthorised or malicious software
Evidence to have on file (guidance, our wording)
  • Endpoint protection coverage report across servers and workstations
  • Local administrator and software installation restrictions
SOC 2 CC6.4 Restricting physical access to facilities and assets
Evidence to have on file (guidance, our wording)
  • Badge access provisioning and removal records
  • Periodic physical access review for sensitive areas
NIST CSF 2.0 PR.PS-05 Installation and execution of unauthorized software are prevented
Evidence to have on file (guidance, our wording)
  • Application allowlist policy and tooling configuration
  • Endpoint protection deployment reports
NIST CSF 2.0 PR.AA-06 Physical access to assets is managed, monitored, and enforced commensurate with risk
Evidence to have on file (guidance, our wording)
  • Physical access control system inventory
  • Badge issuance and revocation records
Application question Do you tag external emails to alert employees that the message originated from outside the organization?
Munich Re held application question
ISO 27001:2022 A.8.15 Logging
Evidence to have on file (guidance, our wording)
  • The topic-specific logging policy defining purposes, events to be logged, fields captured, retention and protection
ISO 27001:2022 A.8.16 Monitoring activities
Evidence to have on file (guidance, our wording)
  • A documented monitoring scope covering network traffic, system access, configuration files, security tool logs, code integrity and resource use, with retention periods
  • Baselines of normal behaviour for systems and user groups, and the detection rules built on them
ISO 27001:2022 A.8.23 Web filtering
Evidence to have on file (guidance, our wording)
  • Current rules on safe, proper use of online resources
  • Web filtering or secure web gateway configuration showing blocked categories such as malicious, phishing, command and control, illegal content and upload sites
SOC 2 CC7.1 Detecting configuration changes and new vulnerabilities
Evidence to have on file (guidance, our wording)
  • Hardening standards or benchmarks for in-scope platforms
  • Configuration compliance scan results
SOC 2 CC7.2 Monitoring system components for anomalies
Evidence to have on file (guidance, our wording)
  • Alert rules and sample of triaged alerts
  • Threat intelligence sources in use
NIST CSF 2.0 DE.CM-01 Networks and network services are monitored to find potentially adverse events
Evidence to have on file (guidance, our wording)
  • Network flow telemetry coverage map by segment
  • IDS or NDR sensor inventory with placement diagram
NIST CSF 2.0 PR.PS-04 Log records are generated and made available for continuous monitoring
Evidence to have on file (guidance, our wording)
  • Logging policy by data class and system tier
  • Centralized log collection architecture
Application question How is web traffic filtered?
Munich Re held application question
ISO 27001:2022 A.8.20 Networks security
Evidence to have on file (guidance, our wording)
  • Current network diagrams and device configuration backups for routers, switches, firewalls and wireless controllers
  • Defined responsibilities and procedures for network device management, separated from system operations where appropriate
ISO 27001:2022 A.8.21 Security of network services
Evidence to have on file (guidance, our wording)
  • Service agreements with internal and external network providers specifying security features, service levels and requirements
  • Right-to-audit clauses and third-party attestations from network and managed security service providers, with records of review
ISO 27001:2022 A.8.22 Segregation of networks
Evidence to have on file (guidance, our wording)
  • Network segmentation design defining domains by trust, criticality, sensitivity or organizational unit, with the assessment that justified it
  • Firewall or filtering router rules controlling traffic between domains, with rule review records
SOC 2 CC6.6 Protection against threats from outside the system boundary
Evidence to have on file (guidance, our wording)
  • Firewall and security group rule sets with review evidence
  • MFA enforced on VPN, remote and administrative access
NIST CSF 2.0 PR.IR-01 Networks and environments are protected from unauthorized logical access and usage
Evidence to have on file (guidance, our wording)
  • Network segmentation design with zones and trust levels
  • Firewall and access control list governance
NIST CSF 2.0 DE.CM-01 Networks and network services are monitored to find potentially adverse events
Evidence to have on file (guidance, our wording)
  • Network flow telemetry coverage map by segment
  • IDS or NDR sensor inventory with placement diagram
Application question Do you protect your web-servers against "DDoS" attacks (e.g. utilising a content delivery network provider?
Munich Re held application question

This is a media liability question, not a control requirement. It reaches no held control.

No held control answers this line.

Application question Are IP addresses connecting to your non-internet facing servers whitelisted?
Munich Re held application question

No held control answers this line.

Application question Do you blacklist IP addresses on your internet facing servers?
Munich Re held application question

No held control answers this line.

Application question Do you have the capability to block suspicious requests from your network environment?
Munich Re held application question

No held control answers this line.

Application question Have you configured host-based and network firewalls to disallow inbound connections by default?
Munich Re held application question
ISO 27001:2022 A.8.20 Networks security
Evidence to have on file (guidance, our wording)
  • Current network diagrams and device configuration backups for routers, switches, firewalls and wireless controllers
  • Defined responsibilities and procedures for network device management, separated from system operations where appropriate
ISO 27001:2022 A.8.21 Security of network services
Evidence to have on file (guidance, our wording)
  • Service agreements with internal and external network providers specifying security features, service levels and requirements
  • Right-to-audit clauses and third-party attestations from network and managed security service providers, with records of review
ISO 27001:2022 A.8.22 Segregation of networks
Evidence to have on file (guidance, our wording)
  • Network segmentation design defining domains by trust, criticality, sensitivity or organizational unit, with the assessment that justified it
  • Firewall or filtering router rules controlling traffic between domains, with rule review records
SOC 2 CC6.6 Protection against threats from outside the system boundary
Evidence to have on file (guidance, our wording)
  • Firewall and security group rule sets with review evidence
  • MFA enforced on VPN, remote and administrative access
NIST CSF 2.0 PR.IR-01 Networks and environments are protected from unauthorized logical access and usage
Evidence to have on file (guidance, our wording)
  • Network segmentation design with zones and trust levels
  • Firewall and access control list governance
NIST CSF 2.0 DE.CM-01 Networks and network services are monitored to find potentially adverse events
Evidence to have on file (guidance, our wording)
  • Network flow telemetry coverage map by segment
  • IDS or NDR sensor inventory with placement diagram
Application question What percentage of systems have a firewall access control list (inbound & outbound rules) configured?
Munich Re held application question

This is a scoping question, not a control requirement. It reaches no held control.

No held control answers this line.

Application question Do you perform periodic reviews of firewall rules to ensure configurations are on a need-to-have basis?
Munich Re held application question
ISO 27001:2022 A.8.20 Networks security
Evidence to have on file (guidance, our wording)
  • Current network diagrams and device configuration backups for routers, switches, firewalls and wireless controllers
  • Defined responsibilities and procedures for network device management, separated from system operations where appropriate
ISO 27001:2022 A.8.21 Security of network services
Evidence to have on file (guidance, our wording)
  • Service agreements with internal and external network providers specifying security features, service levels and requirements
  • Right-to-audit clauses and third-party attestations from network and managed security service providers, with records of review
ISO 27001:2022 A.8.22 Segregation of networks
Evidence to have on file (guidance, our wording)
  • Network segmentation design defining domains by trust, criticality, sensitivity or organizational unit, with the assessment that justified it
  • Firewall or filtering router rules controlling traffic between domains, with rule review records
SOC 2 CC6.6 Protection against threats from outside the system boundary
Evidence to have on file (guidance, our wording)
  • Firewall and security group rule sets with review evidence
  • MFA enforced on VPN, remote and administrative access
SOC 2 CC8.1 Managing changes to procedures, software, data and infrastructure
Evidence to have on file (guidance, our wording)
  • Change management policy covering normal, standard and emergency changes
  • Sample of change tickets with approval, testing evidence and deployer different from author
NIST CSF 2.0 PR.IR-01 Networks and environments are protected from unauthorized logical access and usage
Evidence to have on file (guidance, our wording)
  • Network segmentation design with zones and trust levels
  • Firewall and access control list governance
NIST CSF 2.0 DE.CM-01 Networks and network services are monitored to find potentially adverse events
Evidence to have on file (guidance, our wording)
  • Network flow telemetry coverage map by segment
  • IDS or NDR sensor inventory with placement diagram
Application question Do you utilize any of the following technologies to physically or logically segregate your network?
Munich Re held application question
ISO 27001:2022 A.8.20 Networks security
Evidence to have on file (guidance, our wording)
  • Current network diagrams and device configuration backups for routers, switches, firewalls and wireless controllers
  • Defined responsibilities and procedures for network device management, separated from system operations where appropriate
ISO 27001:2022 A.8.21 Security of network services
Evidence to have on file (guidance, our wording)
  • Service agreements with internal and external network providers specifying security features, service levels and requirements
  • Right-to-audit clauses and third-party attestations from network and managed security service providers, with records of review
ISO 27001:2022 A.8.22 Segregation of networks
Evidence to have on file (guidance, our wording)
  • Network segmentation design defining domains by trust, criticality, sensitivity or organizational unit, with the assessment that justified it
  • Firewall or filtering router rules controlling traffic between domains, with rule review records
SOC 2 CC6.6 Protection against threats from outside the system boundary
Evidence to have on file (guidance, our wording)
  • Firewall and security group rule sets with review evidence
  • MFA enforced on VPN, remote and administrative access
NIST CSF 2.0 PR.IR-01 Networks and environments are protected from unauthorized logical access and usage
Evidence to have on file (guidance, our wording)
  • Network segmentation design with zones and trust levels
  • Firewall and access control list governance
NIST CSF 2.0 DE.CM-01 Networks and network services are monitored to find potentially adverse events
Evidence to have on file (guidance, our wording)
  • Network flow telemetry coverage map by segment
  • IDS or NDR sensor inventory with placement diagram
Application question Do you implement a hardened baseline configuration materially rolled out across servers and workstations?
Munich Re held application question
ISO 27001:2022 A.8.9 Configuration management
Evidence to have on file (guidance, our wording)
  • Approved secure configuration templates or baselines for each platform, derived from vendor or independent guidance, with review dates
  • Configuration records or a CMDB showing owner, last change date, template version and relationships between assets
SOC 2 CC8.1 Managing changes to procedures, software, data and infrastructure
Evidence to have on file (guidance, our wording)
  • Change management policy covering normal, standard and emergency changes
  • Sample of change tickets with approval, testing evidence and deployer different from author
NIST CSF 2.0 PR.PS-01 Configuration management practices are established and applied
Evidence to have on file (guidance, our wording)
  • Configuration management standards by platform
  • Hardening baselines and compliance reports
Application question Do you have a secure coding baseline in place (e.g. peer reviews & maintenance requirements?
Munich Re held application question
ISO 27001:2022 A.8.25 Secure development life cycle
Evidence to have on file (guidance, our wording)
  • Documented secure development rules or SDLC standard covering environments, methodology, coding guidelines, security requirements, checkpoints, testing, repositories and version control
  • Secure coding guidelines for each language in use
ISO 27001:2022 A.8.26 Application security requirements
Evidence to have on file (guidance, our wording)
  • Approved application security requirements documents for new or acquired applications, derived from risk assessment with security specialist input
  • Requirement checklists covering authentication, classification, access segregation, attack resilience, legal and privacy needs, data protection, encryption, input and output controls, logging and error handling
ISO 27001:2022 A.8.28 Secure coding
Evidence to have on file (guidance, our wording)
  • Secure coding standards and a minimum baseline applying to in-house and outsourced development, updated from current threat and vulnerability information
  • IDE and pipeline configuration enforcing secure coding checks, including SAST results and remediation records
SOC 2 CC8.1 Managing changes to procedures, software, data and infrastructure
Evidence to have on file (guidance, our wording)
  • Change management policy covering normal, standard and emergency changes
  • Sample of change tickets with approval, testing evidence and deployer different from author
SOC 2 PI1.3 Controls over system processing
Evidence to have on file (guidance, our wording)
  • Job scheduling and processing monitoring with failure alerts
  • Error queues and evidence of correction
NIST CSF 2.0 PR.PS-06 Secure software development practices are integrated, and their performance is monitored throughout the software development life cycle
Evidence to have on file (guidance, our wording)
  • Secure SDLC standard with control gates
  • Threat modeling outputs per project
NIST CSF 2.0 ID.RA-09 The authenticity and integrity of hardware and software are assessed prior to acquisition and use
Evidence to have on file (guidance, our wording)
  • Quality assurance procedure for risk assessments
  • Peer review records on assessment outputs
Application question Are your developers regularly trained in secure programming techniques and code reviews?
Munich Re held application question
ISO 27001:2022 A.6.3 Information security awareness, education and training
Evidence to have on file (guidance, our wording)
  • A documented awareness, education and training programme aligned with the policies and planned by role, including external personnel
  • Completion records for initial training of new starters and role changers and for periodic refreshers
ISO 27001:2022 A.8.25 Secure development life cycle
Evidence to have on file (guidance, our wording)
  • Documented secure development rules or SDLC standard covering environments, methodology, coding guidelines, security requirements, checkpoints, testing, repositories and version control
  • Secure coding guidelines for each language in use
ISO 27001:2022 A.8.26 Application security requirements
Evidence to have on file (guidance, our wording)
  • Approved application security requirements documents for new or acquired applications, derived from risk assessment with security specialist input
  • Requirement checklists covering authentication, classification, access segregation, attack resilience, legal and privacy needs, data protection, encryption, input and output controls, logging and error handling
SOC 2 CC1.4 Attracting, developing and retaining competent people (COSO principle 4)
Evidence to have on file (guidance, our wording)
  • Background check policy and completed checks for a sample of new hires and contractors
  • Role competency requirements and performance review records
SOC 2 CC2.2 Internal communication of objectives and control responsibilities (COSO principle 14)
Evidence to have on file (guidance, our wording)
  • Security awareness training content and completion records
  • Published information security policies accessible to staff with change notices
NIST CSF 2.0 PR.AT-01 Personnel are provided with awareness and training so that they possess the knowledge and skills to perform general tasks with cybersecurity risks in mind
Evidence to have on file (guidance, our wording)
  • Security awareness program curriculum
  • Completion records by population
NIST CSF 2.0 PR.PS-06 Secure software development practices are integrated, and their performance is monitored throughout the software development life cycle
Evidence to have on file (guidance, our wording)
  • Secure SDLC standard with control gates
  • Threat modeling outputs per project
Application question Do you conduct security tests or code analysis during system development, before go-live and after  N/A  Yes  No system changes take place?
Munich Re held application question
ISO 27001:2022 A.8.8 Management of technical vulnerabilities
Evidence to have on file (guidance, our wording)
  • A software asset inventory with vendor, product, version, deployment location and responsible owner
  • Defined vulnerability management roles and a list of monitored vulnerability information sources
ISO 27001:2022 A.8.19 Installation of software on operational systems
Evidence to have on file (guidance, our wording)
  • Procedures for installing and updating operational software, including authorization, testing and rollback planning
  • Change and deployment records showing management authorization, successful testing and the administrator who performed the installation
ISO 27001:2022 A.8.29 Security testing in development and acceptance
Evidence to have on file (guidance, our wording)
  • Security test plans with schedules, inputs, expected outputs, evaluation criteria and decisions, scaled to the system's importance and change impact
  • Security test results covering authentication, access restriction, cryptography, secure coding and configuration
SOC 2 CC7.1 Detecting configuration changes and new vulnerabilities
Evidence to have on file (guidance, our wording)
  • Hardening standards or benchmarks for in-scope platforms
  • Configuration compliance scan results
SOC 2 CC8.1 Managing changes to procedures, software, data and infrastructure
Evidence to have on file (guidance, our wording)
  • Change management policy covering normal, standard and emergency changes
  • Sample of change tickets with approval, testing evidence and deployer different from author
NIST CSF 2.0 ID.RA-01 Vulnerabilities in assets are identified, validated, and recorded
Evidence to have on file (guidance, our wording)
  • Vulnerability scanning coverage report
  • Vulnerability triage workflow with severity SLAs
NIST CSF 2.0 PR.PS-02 Software is maintained, replaced, and removed commensurate with risk
Evidence to have on file (guidance, our wording)
  • Software lifecycle policy with end of support tracking
  • Patch management cadence and exception register
Application question Does confidential test data require the same security controls as confidential data on production systems?
Munich Re held application question

No held control answers this line.

Application question Do you ensure that any acquired applications/functions and code is free from known vulnerabilities?
Munich Re held application question
ISO 27001:2022 A.8.8 Management of technical vulnerabilities
Evidence to have on file (guidance, our wording)
  • A software asset inventory with vendor, product, version, deployment location and responsible owner
  • Defined vulnerability management roles and a list of monitored vulnerability information sources
ISO 27001:2022 A.8.19 Installation of software on operational systems
Evidence to have on file (guidance, our wording)
  • Procedures for installing and updating operational software, including authorization, testing and rollback planning
  • Change and deployment records showing management authorization, successful testing and the administrator who performed the installation
ISO 27001:2022 A.8.29 Security testing in development and acceptance
Evidence to have on file (guidance, our wording)
  • Security test plans with schedules, inputs, expected outputs, evaluation criteria and decisions, scaled to the system's importance and change impact
  • Security test results covering authentication, access restriction, cryptography, secure coding and configuration
SOC 2 CC7.1 Detecting configuration changes and new vulnerabilities
Evidence to have on file (guidance, our wording)
  • Hardening standards or benchmarks for in-scope platforms
  • Configuration compliance scan results
SOC 2 CC8.1 Managing changes to procedures, software, data and infrastructure
Evidence to have on file (guidance, our wording)
  • Change management policy covering normal, standard and emergency changes
  • Sample of change tickets with approval, testing evidence and deployer different from author
NIST CSF 2.0 ID.RA-01 Vulnerabilities in assets are identified, validated, and recorded
Evidence to have on file (guidance, our wording)
  • Vulnerability scanning coverage report
  • Vulnerability triage workflow with severity SLAs
NIST CSF 2.0 PR.PS-02 Software is maintained, replaced, and removed commensurate with risk
Evidence to have on file (guidance, our wording)
  • Software lifecycle policy with end of support tracking
  • Patch management cadence and exception register
Application question Do you identify & categorise third party vendors based on their access to company systems and/or data?
Munich Re held application question
ISO 27001:2022 A.5.12 Classification of information
Evidence to have on file (guidance, our wording)
  • The topic-specific classification policy with named levels, criteria based on impact, and conventions covering confidentiality, integrity and availability
  • Evidence the scheme was communicated to relevant interested parties and built into procedures
ISO 27001:2022 A.5.13 Labelling of information
Evidence to have on file (guidance, our wording)
  • Labelling procedures covering all formats, with rules on placement, exemptions and cases where labelling is not possible
  • Examples of labelled documents, emails, reports and media showing the chosen techniques such as headers, watermarks or metadata
ISO 27001:2022 A.5.19 Information security in supplier relationships
Evidence to have on file (guidance, our wording)
  • The topic-specific supplier relationship policy and its communication record
  • A supplier inventory categorized by type and by the information, services and infrastructure each can access
SOC 2 CC6.1 Logical access security over protected information assets
Evidence to have on file (guidance, our wording)
  • Asset inventory with classification for in-scope systems
  • Identity provider configuration showing MFA and password policy
SOC 2 CC9.2 Assessing and managing vendor and business partner risk
Evidence to have on file (guidance, our wording)
  • Vendor inventory with risk tiers and the review frequency set for each tier
  • Due diligence records, for example vendor SOC reports reviewed with complementary controls noted
NIST CSF 2.0 ID.AM-05 Assets are prioritized based on classification, criticality, resources, and impact on the mission
Evidence to have on file (guidance, our wording)
  • Asset prioritization scoring model
  • Criticality ratings stored in CMDB
NIST CSF 2.0 ID.AM-07 Inventories of data and corresponding metadata for designated data types are maintained
Evidence to have on file (guidance, our wording)
  • Data inventory with classification and location
  • Metadata tagging policy enforced in storage
Application question Is an information security assessment performed on vendors at due diligence stage with findings addressed?
Munich Re held application question
ISO 27001:2022 A.5.19 Information security in supplier relationships
Evidence to have on file (guidance, our wording)
  • The topic-specific supplier relationship policy and its communication record
  • A supplier inventory categorized by type and by the information, services and infrastructure each can access
ISO 27001:2022 A.5.20 Addressing information security within supplier agreements
Evidence to have on file (guidance, our wording)
  • Supplier agreements containing security clauses proportionate to the relationship, such as classification mapping, agreed controls, incident notification, subcontracting, right to audit and termination terms
  • A register of contracts, memoranda and information-sharing arrangements with outside parties showing what information each covers and when it was last reviewed
ISO 27001:2022 A.5.21 Managing information security in the information and communication technology (ICT) supply chain
Evidence to have on file (guidance, our wording)
  • Security requirements included in ICT acquisition specifications and contracts, including flow-down to sub-suppliers
  • Software component information such as SBOMs and descriptions of security functions and secure configuration obtained from product suppliers
SOC 2 CC9.2 Assessing and managing vendor and business partner risk
Evidence to have on file (guidance, our wording)
  • Vendor inventory with risk tiers and the review frequency set for each tier
  • Due diligence records, for example vendor SOC reports reviewed with complementary controls noted
SOC 2 P6.4 Privacy commitments from vendors and third parties
Evidence to have on file (guidance, our wording)
  • Data processing agreements with privacy clauses
  • Periodic assessments of vendors' privacy compliance
NIST CSF 2.0 GV.SC-01 A cybersecurity supply chain risk management program, strategy, objectives, policies, and processes are established and agreed to by organizational stakeholders
Evidence to have on file (guidance, our wording)
  • Third party risk management program charter
  • Supplier risk policy with tiering criteria
NIST CSF 2.0 GV.SC-05 Requirements to address cybersecurity risks in supply chains are established, prioritized, and integrated into contracts and other types of agreements with suppliers and other relevant third parties
Evidence to have on file (guidance, our wording)
  • Standard supplier security requirements catalog
  • Contract clause library with cyber obligations
Application question Do you perform periodic audits of vendors and enforce the right to audit in contractual agreement?
Munich Re held application question
ISO 27001:2022 A.5.19 Information security in supplier relationships
Evidence to have on file (guidance, our wording)
  • The topic-specific supplier relationship policy and its communication record
  • A supplier inventory categorized by type and by the information, services and infrastructure each can access
ISO 27001:2022 A.5.20 Addressing information security within supplier agreements
Evidence to have on file (guidance, our wording)
  • Supplier agreements containing security clauses proportionate to the relationship, such as classification mapping, agreed controls, incident notification, subcontracting, right to audit and termination terms
  • A register of contracts, memoranda and information-sharing arrangements with outside parties showing what information each covers and when it was last reviewed
ISO 27001:2022 A.5.21 Managing information security in the information and communication technology (ICT) supply chain
Evidence to have on file (guidance, our wording)
  • Security requirements included in ICT acquisition specifications and contracts, including flow-down to sub-suppliers
  • Software component information such as SBOMs and descriptions of security functions and secure configuration obtained from product suppliers
SOC 2 CC9.2 Assessing and managing vendor and business partner risk
Evidence to have on file (guidance, our wording)
  • Vendor inventory with risk tiers and the review frequency set for each tier
  • Due diligence records, for example vendor SOC reports reviewed with complementary controls noted
SOC 2 P6.4 Privacy commitments from vendors and third parties
Evidence to have on file (guidance, our wording)
  • Data processing agreements with privacy clauses
  • Periodic assessments of vendors' privacy compliance
NIST CSF 2.0 GV.SC-01 A cybersecurity supply chain risk management program, strategy, objectives, policies, and processes are established and agreed to by organizational stakeholders
Evidence to have on file (guidance, our wording)
  • Third party risk management program charter
  • Supplier risk policy with tiering criteria
NIST CSF 2.0 GV.SC-05 Requirements to address cybersecurity risks in supply chains are established, prioritized, and integrated into contracts and other types of agreements with suppliers and other relevant third parties
Evidence to have on file (guidance, our wording)
  • Standard supplier security requirements catalog
  • Contract clause library with cyber obligations
Application question Do vendor agreements require levels of security commensurate with your own information security standards?
Munich Re held application question
ISO 27001:2022 A.5.19 Information security in supplier relationships
Evidence to have on file (guidance, our wording)
  • The topic-specific supplier relationship policy and its communication record
  • A supplier inventory categorized by type and by the information, services and infrastructure each can access
ISO 27001:2022 A.5.20 Addressing information security within supplier agreements
Evidence to have on file (guidance, our wording)
  • Supplier agreements containing security clauses proportionate to the relationship, such as classification mapping, agreed controls, incident notification, subcontracting, right to audit and termination terms
  • A register of contracts, memoranda and information-sharing arrangements with outside parties showing what information each covers and when it was last reviewed
ISO 27001:2022 A.5.21 Managing information security in the information and communication technology (ICT) supply chain
Evidence to have on file (guidance, our wording)
  • Security requirements included in ICT acquisition specifications and contracts, including flow-down to sub-suppliers
  • Software component information such as SBOMs and descriptions of security functions and secure configuration obtained from product suppliers
SOC 2 CC9.2 Assessing and managing vendor and business partner risk
Evidence to have on file (guidance, our wording)
  • Vendor inventory with risk tiers and the review frequency set for each tier
  • Due diligence records, for example vendor SOC reports reviewed with complementary controls noted
SOC 2 P6.4 Privacy commitments from vendors and third parties
Evidence to have on file (guidance, our wording)
  • Data processing agreements with privacy clauses
  • Periodic assessments of vendors' privacy compliance
NIST CSF 2.0 GV.SC-01 A cybersecurity supply chain risk management program, strategy, objectives, policies, and processes are established and agreed to by organizational stakeholders
Evidence to have on file (guidance, our wording)
  • Third party risk management program charter
  • Supplier risk policy with tiering criteria
NIST CSF 2.0 GV.SC-05 Requirements to address cybersecurity risks in supply chains are established, prioritized, and integrated into contracts and other types of agreements with suppliers and other relevant third parties
Evidence to have on file (guidance, our wording)
  • Standard supplier security requirements catalog
  • Contract clause library with cyber obligations
Application question Do you periodically review and update vendor access rights?
Munich Re held application question
ISO 27001:2022 A.5.15 Access control
Evidence to have on file (guidance, our wording)
  • The topic-specific access control policy, approved and communicated, reflecting owner-defined business and security requirements
  • Access control rules or role models mapping entities (users, services, devices) to rights, consistent with classification
ISO 27001:2022 A.5.16 Identity management
Evidence to have on file (guidance, our wording)
  • Identity management procedure covering creation, verification, activation, change, disablement and removal
  • Evidence that identities are verified against trusted documents before issue
ISO 27001:2022 A.5.18 Access rights
Evidence to have on file (guidance, our wording)
  • Access request records showing owner authorization, and management approval where required, before rights were activated
  • A central record of access rights per user identifier across logical and physical access
SOC 2 CC6.1 Logical access security over protected information assets
Evidence to have on file (guidance, our wording)
  • Asset inventory with classification for in-scope systems
  • Identity provider configuration showing MFA and password policy
SOC 2 CC6.2 Registering and authorising users before issuing credentials
Evidence to have on file (guidance, our wording)
  • Access request tickets with owner approval for a sample of new users, service accounts and API credentials
  • Termination records reconciled to account disablement dates
NIST CSF 2.0 PR.AA-01 Identities and credentials for authorized users, services, and hardware are managed by the organization
Evidence to have on file (guidance, our wording)
  • Identity management platform configuration baseline
  • Joiner mover leaver workflow with timing SLAs
NIST CSF 2.0 PR.AA-05 Access permissions, entitlements, and authorizations are defined in a policy, managed, enforced, and reviewed, and incorporate the principles of least privilege and separation of duties
Evidence to have on file (guidance, our wording)
  • Access policy framework with role definitions
  • Privileged access management deployment evidence
Application question Do you restrict vendor access to limited time-windows and monitor their access to your network?
Munich Re held application question
ISO 27001:2022 A.8.15 Logging
Evidence to have on file (guidance, our wording)
  • The topic-specific logging policy defining purposes, events to be logged, fields captured, retention and protection
ISO 27001:2022 A.8.16 Monitoring activities
Evidence to have on file (guidance, our wording)
  • A documented monitoring scope covering network traffic, system access, configuration files, security tool logs, code integrity and resource use, with retention periods
  • Baselines of normal behaviour for systems and user groups, and the detection rules built on them
ISO 27001:2022 A.5.15 Access control
Evidence to have on file (guidance, our wording)
  • The topic-specific access control policy, approved and communicated, reflecting owner-defined business and security requirements
  • Access control rules or role models mapping entities (users, services, devices) to rights, consistent with classification
SOC 2 CC7.1 Detecting configuration changes and new vulnerabilities
Evidence to have on file (guidance, our wording)
  • Hardening standards or benchmarks for in-scope platforms
  • Configuration compliance scan results
SOC 2 CC7.2 Monitoring system components for anomalies
Evidence to have on file (guidance, our wording)
  • Alert rules and sample of triaged alerts
  • Threat intelligence sources in use
NIST CSF 2.0 DE.CM-01 Networks and network services are monitored to find potentially adverse events
Evidence to have on file (guidance, our wording)
  • Network flow telemetry coverage map by segment
  • IDS or NDR sensor inventory with placement diagram
NIST CSF 2.0 PR.PS-04 Log records are generated and made available for continuous monitoring
Evidence to have on file (guidance, our wording)
  • Logging policy by data class and system tier
  • Centralized log collection architecture
Application question Do you have an information security incident response plan?
Munich Re held application question
ISO 27001:2022 A.5.24 Information security incident management planning and preparation
Evidence to have on file (guidance, our wording)
  • An approved incident management plan and procedures covering evaluation, detection, classification, escalation, recovery, communication, evidence handling and post-incident review
  • Incident management objectives and priorities agreed with management, including resolution time frames by severity
ISO 27001:2022 A.5.25 Assessment and decision on information security events
Evidence to have on file (guidance, our wording)
  • The agreed incident categorization and prioritization scheme with criteria for declaring an incident and consequence levels
  • Triage records showing each reported event assessed against the scheme
ISO 27001:2022 A.5.26 Response to information security incidents
Evidence to have on file (guidance, our wording)
  • Documented incident response procedures or playbooks communicated to relevant parties
  • Incident records showing containment, evidence collection, escalation, communication and formal closure
SOC 2 CC7.3 Evaluating security events to identify incidents
Evidence to have on file (guidance, our wording)
  • Incident classification and severity criteria
  • Security event log showing triage decisions
SOC 2 CC7.4 Responding to security incidents
Evidence to have on file (guidance, our wording)
  • Incident response plan with roles and contact lists
  • Incident tickets showing containment, eradication, recovery and communication
NIST CSF 2.0 RS.MA-01 The incident response plan is executed in coordination with relevant third parties once an incident is declared
Evidence to have on file (guidance, our wording)
  • Incident response plan with third party invocation
  • Retainer contract evidence for IR vendor
NIST CSF 2.0 RS.CO-02 Internal and external stakeholders are notified of incidents
Evidence to have on file (guidance, our wording)
  • Incident notification policy and timing matrix
  • Internal stakeholder communication templates
Application question Do you have an incident response or digital forensic outsourcing retainer agreement in place?
Munich Re held application question
ISO 27001:2022 A.5.24 Information security incident management planning and preparation
Evidence to have on file (guidance, our wording)
  • An approved incident management plan and procedures covering evaluation, detection, classification, escalation, recovery, communication, evidence handling and post-incident review
  • Incident management objectives and priorities agreed with management, including resolution time frames by severity
ISO 27001:2022 A.5.25 Assessment and decision on information security events
Evidence to have on file (guidance, our wording)
  • The agreed incident categorization and prioritization scheme with criteria for declaring an incident and consequence levels
  • Triage records showing each reported event assessed against the scheme
ISO 27001:2022 A.5.26 Response to information security incidents
Evidence to have on file (guidance, our wording)
  • Documented incident response procedures or playbooks communicated to relevant parties
  • Incident records showing containment, evidence collection, escalation, communication and formal closure
SOC 2 CC7.3 Evaluating security events to identify incidents
Evidence to have on file (guidance, our wording)
  • Incident classification and severity criteria
  • Security event log showing triage decisions
SOC 2 CC7.4 Responding to security incidents
Evidence to have on file (guidance, our wording)
  • Incident response plan with roles and contact lists
  • Incident tickets showing containment, eradication, recovery and communication
NIST CSF 2.0 RS.MA-01 The incident response plan is executed in coordination with relevant third parties once an incident is declared
Evidence to have on file (guidance, our wording)
  • Incident response plan with third party invocation
  • Retainer contract evidence for IR vendor
NIST CSF 2.0 RS.CO-02 Internal and external stakeholders are notified of incidents
Evidence to have on file (guidance, our wording)
  • Incident notification policy and timing matrix
  • Internal stakeholder communication templates
Application question Are you utilising a Security Incident Event Management (SIEM) solution?
Munich Re held application question
ISO 27001:2022 A.8.15 Logging
Evidence to have on file (guidance, our wording)
  • The topic-specific logging policy defining purposes, events to be logged, fields captured, retention and protection
ISO 27001:2022 A.8.16 Monitoring activities
Evidence to have on file (guidance, our wording)
  • A documented monitoring scope covering network traffic, system access, configuration files, security tool logs, code integrity and resource use, with retention periods
  • Baselines of normal behaviour for systems and user groups, and the detection rules built on them
SOC 2 CC7.1 Detecting configuration changes and new vulnerabilities
Evidence to have on file (guidance, our wording)
  • Hardening standards or benchmarks for in-scope platforms
  • Configuration compliance scan results
SOC 2 CC7.2 Monitoring system components for anomalies
Evidence to have on file (guidance, our wording)
  • Alert rules and sample of triaged alerts
  • Threat intelligence sources in use
NIST CSF 2.0 DE.CM-01 Networks and network services are monitored to find potentially adverse events
Evidence to have on file (guidance, our wording)
  • Network flow telemetry coverage map by segment
  • IDS or NDR sensor inventory with placement diagram
NIST CSF 2.0 PR.PS-04 Log records are generated and made available for continuous monitoring
Evidence to have on file (guidance, our wording)
  • Logging policy by data class and system tier
  • Centralized log collection architecture
Application question How are security incident alerts monitored and responded to?
Munich Re held application question
ISO 27001:2022 A.8.15 Logging
Evidence to have on file (guidance, our wording)
  • The topic-specific logging policy defining purposes, events to be logged, fields captured, retention and protection
ISO 27001:2022 A.8.16 Monitoring activities
Evidence to have on file (guidance, our wording)
  • A documented monitoring scope covering network traffic, system access, configuration files, security tool logs, code integrity and resource use, with retention periods
  • Baselines of normal behaviour for systems and user groups, and the detection rules built on them
SOC 2 CC7.1 Detecting configuration changes and new vulnerabilities
Evidence to have on file (guidance, our wording)
  • Hardening standards or benchmarks for in-scope platforms
  • Configuration compliance scan results
SOC 2 CC7.2 Monitoring system components for anomalies
Evidence to have on file (guidance, our wording)
  • Alert rules and sample of triaged alerts
  • Threat intelligence sources in use
NIST CSF 2.0 DE.CM-01 Networks and network services are monitored to find potentially adverse events
Evidence to have on file (guidance, our wording)
  • Network flow telemetry coverage map by segment
  • IDS or NDR sensor inventory with placement diagram
NIST CSF 2.0 PR.PS-04 Log records are generated and made available for continuous monitoring
Evidence to have on file (guidance, our wording)
  • Logging policy by data class and system tier
  • Centralized log collection architecture
Application question Is the full scope of the SOC operating on a 24/7/365 basis?
Munich Re held application question
ISO 27001:2022 A.8.15 Logging
Evidence to have on file (guidance, our wording)
  • The topic-specific logging policy defining purposes, events to be logged, fields captured, retention and protection
ISO 27001:2022 A.8.16 Monitoring activities
Evidence to have on file (guidance, our wording)
  • A documented monitoring scope covering network traffic, system access, configuration files, security tool logs, code integrity and resource use, with retention periods
  • Baselines of normal behaviour for systems and user groups, and the detection rules built on them
SOC 2 CC7.1 Detecting configuration changes and new vulnerabilities
Evidence to have on file (guidance, our wording)
  • Hardening standards or benchmarks for in-scope platforms
  • Configuration compliance scan results
SOC 2 CC7.2 Monitoring system components for anomalies
Evidence to have on file (guidance, our wording)
  • Alert rules and sample of triaged alerts
  • Threat intelligence sources in use
NIST CSF 2.0 DE.CM-01 Networks and network services are monitored to find potentially adverse events
Evidence to have on file (guidance, our wording)
  • Network flow telemetry coverage map by segment
  • IDS or NDR sensor inventory with placement diagram
NIST CSF 2.0 PR.PS-04 Log records are generated and made available for continuous monitoring
Evidence to have on file (guidance, our wording)
  • Logging policy by data class and system tier
  • Centralized log collection architecture
Application question Does your 24/7/365 service have the authority to contain/isolate systems following a suspicious event?
Munich Re held application question
ISO 27001:2022 A.8.15 Logging
Evidence to have on file (guidance, our wording)
  • The topic-specific logging policy defining purposes, events to be logged, fields captured, retention and protection
ISO 27001:2022 A.8.16 Monitoring activities
Evidence to have on file (guidance, our wording)
  • A documented monitoring scope covering network traffic, system access, configuration files, security tool logs, code integrity and resource use, with retention periods
  • Baselines of normal behaviour for systems and user groups, and the detection rules built on them
SOC 2 CC7.1 Detecting configuration changes and new vulnerabilities
Evidence to have on file (guidance, our wording)
  • Hardening standards or benchmarks for in-scope platforms
  • Configuration compliance scan results
SOC 2 CC7.2 Monitoring system components for anomalies
Evidence to have on file (guidance, our wording)
  • Alert rules and sample of triaged alerts
  • Threat intelligence sources in use
NIST CSF 2.0 DE.CM-01 Networks and network services are monitored to find potentially adverse events
Evidence to have on file (guidance, our wording)
  • Network flow telemetry coverage map by segment
  • IDS or NDR sensor inventory with placement diagram
NIST CSF 2.0 PR.PS-04 Log records are generated and made available for continuous monitoring
Evidence to have on file (guidance, our wording)
  • Logging policy by data class and system tier
  • Centralized log collection architecture
Application question Do you have a written business continuity or disaster recovery plan that addresses network outages & cyber-attacks?
Munich Re held application question
ISO 27001:2022 A.5.29 Information security during disruption
Evidence to have on file (guidance, our wording)
  • Business continuity plans that contain information security requirements and the controls, systems and tools needed during disruption
  • A documented analysis of which security controls must be adapted during disruption and how
ISO 27001:2022 A.5.30 ICT readiness for business continuity
Evidence to have on file (guidance, our wording)
  • The business impact analysis with prioritized activities, supporting ICT services and their RTOs, and RPOs for required information
  • Selected ICT continuity strategies covering before, during and after disruption
ISO 27001:2022 A.8.14 Redundancy of information processing facilities
Evidence to have on file (guidance, our wording)
  • Documented availability requirements for business services and systems
  • Architecture diagrams showing redundancy such as dual providers, redundant networks, separate data centres, redundant power and load-balanced instances
SOC 2 CC9.1 Mitigating risks of business disruption
Evidence to have on file (guidance, our wording)
  • Business continuity and disaster recovery plans covering the in-scope service
  • Business impact analysis
SOC 2 A1.2 Environmental protection, backup and recovery infrastructure
Evidence to have on file (guidance, our wording)
  • Backup policy defining scope, frequency and retention
  • Backup job monitoring and failure remediation records
NIST CSF 2.0 PR.IR-03 Mechanisms are implemented to achieve resilience requirements in normal and adverse situations
Evidence to have on file (guidance, our wording)
  • Resilience architecture patterns for critical services
  • Failover and failback tested with evidence
NIST CSF 2.0 RC.RP-01 The recovery portion of the incident response plan is executed once initiated from the incident response process
Evidence to have on file (guidance, our wording)
  • Recovery plan with triggers and decision rights
  • Execution log of recovery activities
Application question If Yes, is this tested annually with critical deficiencies remediated?
Munich Re held application question

No held control answers this line.

Application question What is your Recovery Time Objective (RTO) for critical systems?
Munich Re held application question
ISO 27001:2022 A.5.29 Information security during disruption
Evidence to have on file (guidance, our wording)
  • Business continuity plans that contain information security requirements and the controls, systems and tools needed during disruption
  • A documented analysis of which security controls must be adapted during disruption and how
ISO 27001:2022 A.5.30 ICT readiness for business continuity
Evidence to have on file (guidance, our wording)
  • The business impact analysis with prioritized activities, supporting ICT services and their RTOs, and RPOs for required information
  • Selected ICT continuity strategies covering before, during and after disruption
ISO 27001:2022 A.8.14 Redundancy of information processing facilities
Evidence to have on file (guidance, our wording)
  • Documented availability requirements for business services and systems
  • Architecture diagrams showing redundancy such as dual providers, redundant networks, separate data centres, redundant power and load-balanced instances
SOC 2 CC9.1 Mitigating risks of business disruption
Evidence to have on file (guidance, our wording)
  • Business continuity and disaster recovery plans covering the in-scope service
  • Business impact analysis
SOC 2 A1.2 Environmental protection, backup and recovery infrastructure
Evidence to have on file (guidance, our wording)
  • Backup policy defining scope, frequency and retention
  • Backup job monitoring and failure remediation records
NIST CSF 2.0 PR.IR-03 Mechanisms are implemented to achieve resilience requirements in normal and adverse situations
Evidence to have on file (guidance, our wording)
  • Resilience architecture patterns for critical services
  • Failover and failback tested with evidence
NIST CSF 2.0 RC.RP-01 The recovery portion of the incident response plan is executed once initiated from the incident response process
Evidence to have on file (guidance, our wording)
  • Recovery plan with triggers and decision rights
  • Execution log of recovery activities
Application question Do you have a defined Recovery Point Objective (RPO) for critical systems?
Munich Re held application question
ISO 27001:2022 A.5.29 Information security during disruption
Evidence to have on file (guidance, our wording)
  • Business continuity plans that contain information security requirements and the controls, systems and tools needed during disruption
  • A documented analysis of which security controls must be adapted during disruption and how
ISO 27001:2022 A.5.30 ICT readiness for business continuity
Evidence to have on file (guidance, our wording)
  • The business impact analysis with prioritized activities, supporting ICT services and their RTOs, and RPOs for required information
  • Selected ICT continuity strategies covering before, during and after disruption
ISO 27001:2022 A.8.14 Redundancy of information processing facilities
Evidence to have on file (guidance, our wording)
  • Documented availability requirements for business services and systems
  • Architecture diagrams showing redundancy such as dual providers, redundant networks, separate data centres, redundant power and load-balanced instances
SOC 2 CC9.1 Mitigating risks of business disruption
Evidence to have on file (guidance, our wording)
  • Business continuity and disaster recovery plans covering the in-scope service
  • Business impact analysis
SOC 2 A1.2 Environmental protection, backup and recovery infrastructure
Evidence to have on file (guidance, our wording)
  • Backup policy defining scope, frequency and retention
  • Backup job monitoring and failure remediation records
NIST CSF 2.0 PR.IR-03 Mechanisms are implemented to achieve resilience requirements in normal and adverse situations
Evidence to have on file (guidance, our wording)
  • Resilience architecture patterns for critical services
  • Failover and failback tested with evidence
NIST CSF 2.0 RC.RP-01 The recovery portion of the incident response plan is executed once initiated from the incident response process
Evidence to have on file (guidance, our wording)
  • Recovery plan with triggers and decision rights
  • Execution log of recovery activities
Application question Have you planned for redundancy for your critical system infrastructure?
Munich Re held application question
ISO 27001:2022 A.5.29 Information security during disruption
Evidence to have on file (guidance, our wording)
  • Business continuity plans that contain information security requirements and the controls, systems and tools needed during disruption
  • A documented analysis of which security controls must be adapted during disruption and how
ISO 27001:2022 A.5.30 ICT readiness for business continuity
Evidence to have on file (guidance, our wording)
  • The business impact analysis with prioritized activities, supporting ICT services and their RTOs, and RPOs for required information
  • Selected ICT continuity strategies covering before, during and after disruption
ISO 27001:2022 A.8.14 Redundancy of information processing facilities
Evidence to have on file (guidance, our wording)
  • Documented availability requirements for business services and systems
  • Architecture diagrams showing redundancy such as dual providers, redundant networks, separate data centres, redundant power and load-balanced instances
SOC 2 CC9.1 Mitigating risks of business disruption
Evidence to have on file (guidance, our wording)
  • Business continuity and disaster recovery plans covering the in-scope service
  • Business impact analysis
SOC 2 A1.2 Environmental protection, backup and recovery infrastructure
Evidence to have on file (guidance, our wording)
  • Backup policy defining scope, frequency and retention
  • Backup job monitoring and failure remediation records
NIST CSF 2.0 PR.IR-03 Mechanisms are implemented to achieve resilience requirements in normal and adverse situations
Evidence to have on file (guidance, our wording)
  • Resilience architecture patterns for critical services
  • Failover and failback tested with evidence
NIST CSF 2.0 RC.RP-01 The recovery portion of the incident response plan is executed once initiated from the incident response process
Evidence to have on file (guidance, our wording)
  • Recovery plan with triggers and decision rights
  • Execution log of recovery activities
Application question Do you conduct redundancy testing at least annually to ensure that failover works as intended?
Munich Re held application question
ISO 27001:2022 A.5.29 Information security during disruption
Evidence to have on file (guidance, our wording)
  • Business continuity plans that contain information security requirements and the controls, systems and tools needed during disruption
  • A documented analysis of which security controls must be adapted during disruption and how
ISO 27001:2022 A.5.30 ICT readiness for business continuity
Evidence to have on file (guidance, our wording)
  • The business impact analysis with prioritized activities, supporting ICT services and their RTOs, and RPOs for required information
  • Selected ICT continuity strategies covering before, during and after disruption
ISO 27001:2022 A.8.14 Redundancy of information processing facilities
Evidence to have on file (guidance, our wording)
  • Documented availability requirements for business services and systems
  • Architecture diagrams showing redundancy such as dual providers, redundant networks, separate data centres, redundant power and load-balanced instances
SOC 2 CC9.1 Mitigating risks of business disruption
Evidence to have on file (guidance, our wording)
  • Business continuity and disaster recovery plans covering the in-scope service
  • Business impact analysis
SOC 2 A1.2 Environmental protection, backup and recovery infrastructure
Evidence to have on file (guidance, our wording)
  • Backup policy defining scope, frequency and retention
  • Backup job monitoring and failure remediation records
NIST CSF 2.0 PR.IR-03 Mechanisms are implemented to achieve resilience requirements in normal and adverse situations
Evidence to have on file (guidance, our wording)
  • Resilience architecture patterns for critical services
  • Failover and failback tested with evidence
NIST CSF 2.0 RC.RP-01 The recovery portion of the incident response plan is executed once initiated from the incident response process
Evidence to have on file (guidance, our wording)
  • Recovery plan with triggers and decision rights
  • Execution log of recovery activities
Application question Do you require reviews to be conducted under the supervision of qualified legal counsel?
Munich Re held application question

No held control answers this line.

Application question For any third party content, do you have procedures in place to secure rights for using such content?
Munich Re held application question

This is a media liability question, not a control requirement. It reaches no held control.

No held control answers this line.

Application question Do you allow third parties to post content directly on to your website(s?
Munich Re held application question

This is a media liability question, not a control requirement. It reaches no held control.

No held control answers this line.

Application question Do you retain the right to remove any such third party content that violates your acceptable terms of use?
Munich Re held application question

This is a media liability question, not a control requirement. It reaches no held control.

No held control answers this line.

Application question Do you accept card payments for goods and/or services?
Munich Re held application question
ISO 27001:2022 A.8.24 Use of cryptography
Evidence to have on file (guidance, our wording)
  • The topic-specific cryptography policy with approved algorithms, key lengths, protocols and usage by information classification
  • Evidence of encryption on endpoints, removable media and data in transit, aligned with the policy
ISO 27001:2022 A.5.15 Access control
Evidence to have on file (guidance, our wording)
  • The topic-specific access control policy, approved and communicated, reflecting owner-defined business and security requirements
  • Access control rules or role models mapping entities (users, services, devices) to rights, consistent with classification
SOC 2 CC6.1 Logical access security over protected information assets
Evidence to have on file (guidance, our wording)
  • Asset inventory with classification for in-scope systems
  • Identity provider configuration showing MFA and password policy
SOC 2 CC6.7 Restricting and protecting information in transmission, movement and removal
Evidence to have on file (guidance, our wording)
  • TLS and encryption standards for data in transit
  • Removable media policy and technical enforcement
NIST CSF 2.0 PR.DS-01 The confidentiality, integrity, and availability of data-at-rest are protected
Evidence to have on file (guidance, our wording)
  • Data at rest encryption inventory by store type
  • Storage configuration baselines with attestation
Application question How many transactions do you process each year?
Munich Re held application question

This is a scoping question, not a control requirement. It reaches no held control.

No held control answers this line.

Application question How do you process payment card transactions?
Munich Re held application question
ISO 27001:2022 A.8.24 Use of cryptography
Evidence to have on file (guidance, our wording)
  • The topic-specific cryptography policy with approved algorithms, key lengths, protocols and usage by information classification
  • Evidence of encryption on endpoints, removable media and data in transit, aligned with the policy
ISO 27001:2022 A.5.15 Access control
Evidence to have on file (guidance, our wording)
  • The topic-specific access control policy, approved and communicated, reflecting owner-defined business and security requirements
  • Access control rules or role models mapping entities (users, services, devices) to rights, consistent with classification
SOC 2 CC6.1 Logical access security over protected information assets
Evidence to have on file (guidance, our wording)
  • Asset inventory with classification for in-scope systems
  • Identity provider configuration showing MFA and password policy
SOC 2 CC6.7 Restricting and protecting information in transmission, movement and removal
Evidence to have on file (guidance, our wording)
  • TLS and encryption standards for data in transit
  • Removable media policy and technical enforcement
NIST CSF 2.0 PR.DS-01 The confidentiality, integrity, and availability of data-at-rest are protected
Evidence to have on file (guidance, our wording)
  • Data at rest encryption inventory by store type
  • Storage configuration baselines with attestation
Application question Do you store payment card data on your network?
Munich Re held application question
ISO 27001:2022 A.8.24 Use of cryptography
Evidence to have on file (guidance, our wording)
  • The topic-specific cryptography policy with approved algorithms, key lengths, protocols and usage by information classification
  • Evidence of encryption on endpoints, removable media and data in transit, aligned with the policy
ISO 27001:2022 A.5.15 Access control
Evidence to have on file (guidance, our wording)
  • The topic-specific access control policy, approved and communicated, reflecting owner-defined business and security requirements
  • Access control rules or role models mapping entities (users, services, devices) to rights, consistent with classification
SOC 2 CC6.1 Logical access security over protected information assets
Evidence to have on file (guidance, our wording)
  • Asset inventory with classification for in-scope systems
  • Identity provider configuration showing MFA and password policy
SOC 2 CC6.7 Restricting and protecting information in transmission, movement and removal
Evidence to have on file (guidance, our wording)
  • TLS and encryption standards for data in transit
  • Removable media policy and technical enforcement
NIST CSF 2.0 PR.DS-01 The confidentiality, integrity, and availability of data-at-rest are protected
Evidence to have on file (guidance, our wording)
  • Data at rest encryption inventory by store type
  • Storage configuration baselines with attestation
Application question If Yes, is payment card data either encrypted or tokenised at all times?
Munich Re held application question
ISO 27001:2022 A.8.24 Use of cryptography
Evidence to have on file (guidance, our wording)
  • The topic-specific cryptography policy with approved algorithms, key lengths, protocols and usage by information classification
  • Evidence of encryption on endpoints, removable media and data in transit, aligned with the policy
ISO 27001:2022 A.8.11 Data masking
Evidence to have on file (guidance, our wording)
  • Policy or standard specifying where masking, pseudonymization or anonymization is required, based on access control policy, business needs and law
  • Masking configurations in applications, databases and reports showing minimum necessary data displayed per role
ISO 27001:2022 A.5.15 Access control
Evidence to have on file (guidance, our wording)
  • The topic-specific access control policy, approved and communicated, reflecting owner-defined business and security requirements
  • Access control rules or role models mapping entities (users, services, devices) to rights, consistent with classification
SOC 2 CC6.1 Logical access security over protected information assets
Evidence to have on file (guidance, our wording)
  • Asset inventory with classification for in-scope systems
  • Identity provider configuration showing MFA and password policy
SOC 2 CC6.7 Restricting and protecting information in transmission, movement and removal
Evidence to have on file (guidance, our wording)
  • TLS and encryption standards for data in transit
  • Removable media policy and technical enforcement
NIST CSF 2.0 PR.DS-01 The confidentiality, integrity, and availability of data-at-rest are protected
Evidence to have on file (guidance, our wording)
  • Data at rest encryption inventory by store type
  • Storage configuration baselines with attestation
NIST CSF 2.0 PR.DS-02 The confidentiality, integrity, and availability of data-in-transit are protected
Evidence to have on file (guidance, our wording)
  • TLS configuration standards and scan results
  • VPN and zero trust network access policy
Application question Do you comply with the relevant Payment Card Industry Data Security Standard?
Munich Re held application question
ISO 27001:2022 A.8.24 Use of cryptography
Evidence to have on file (guidance, our wording)
  • The topic-specific cryptography policy with approved algorithms, key lengths, protocols and usage by information classification
  • Evidence of encryption on endpoints, removable media and data in transit, aligned with the policy
ISO 27001:2022 A.5.15 Access control
Evidence to have on file (guidance, our wording)
  • The topic-specific access control policy, approved and communicated, reflecting owner-defined business and security requirements
  • Access control rules or role models mapping entities (users, services, devices) to rights, consistent with classification
SOC 2 CC6.1 Logical access security over protected information assets
Evidence to have on file (guidance, our wording)
  • Asset inventory with classification for in-scope systems
  • Identity provider configuration showing MFA and password policy
SOC 2 CC6.7 Restricting and protecting information in transmission, movement and removal
Evidence to have on file (guidance, our wording)
  • TLS and encryption standards for data in transit
  • Removable media policy and technical enforcement
NIST CSF 2.0 PR.DS-01 The confidentiality, integrity, and availability of data-at-rest are protected
Evidence to have on file (guidance, our wording)
  • Data at rest encryption inventory by store type
  • Storage configuration baselines with attestation
Application question Do you transact all payments through a payment processor?
Munich Re held application question

No held control answers this line.

Application question Has the payment processor provided you with evidence of its PCI DSS compliance?
Munich Re held application question
ISO 27001:2022 A.8.24 Use of cryptography
Evidence to have on file (guidance, our wording)
  • The topic-specific cryptography policy with approved algorithms, key lengths, protocols and usage by information classification
  • Evidence of encryption on endpoints, removable media and data in transit, aligned with the policy
ISO 27001:2022 A.5.15 Access control
Evidence to have on file (guidance, our wording)
  • The topic-specific access control policy, approved and communicated, reflecting owner-defined business and security requirements
  • Access control rules or role models mapping entities (users, services, devices) to rights, consistent with classification
SOC 2 CC6.1 Logical access security over protected information assets
Evidence to have on file (guidance, our wording)
  • Asset inventory with classification for in-scope systems
  • Identity provider configuration showing MFA and password policy
SOC 2 CC6.7 Restricting and protecting information in transmission, movement and removal
Evidence to have on file (guidance, our wording)
  • TLS and encryption standards for data in transit
  • Removable media policy and technical enforcement
NIST CSF 2.0 PR.DS-01 The confidentiality, integrity, and availability of data-at-rest are protected
Evidence to have on file (guidance, our wording)
  • Data at rest encryption inventory by store type
  • Storage configuration baselines with attestation
Application question Do you clearly outline to individuals how any biometric information will be collected, used and/or destroyed?
Munich Re held application question
ISO 27001:2022 A.5.34 Privacy and protection of personal identifiable information (PII)
Evidence to have on file (guidance, our wording)
  • The topic-specific privacy and PII protection policy and its communication to relevant parties
  • Privacy procedures communicated to everyone who processes PII
ISO 27001:2022 A.5.31 Legal, statutory, regulatory and contractual requirements
Evidence to have on file (guidance, our wording)
  • A register of applicable laws, regulations and contractual obligations for information security, with the countries covered, the approach to meeting each and a named responsible owner
  • Records of periodic review of the register and of new or changed legislation identified
SOC 2 P1.1 Privacy notice to data subjects
Evidence to have on file (guidance, our wording)
  • Published privacy notice with effective date and version history
  • Evidence notice is presented at collection points (forms, apps)
SOC 2 P3.1 Collecting personal information consistent with objectives
Evidence to have on file (guidance, our wording)
  • Data inventory showing purpose for each personal data field
  • Privacy review of new collection forms or features
NIST CSF 2.0 GV.OC-03 Legal, regulatory, and contractual requirements regarding cybersecurity - including privacy and civil liberties obligations - are understood and managed
Evidence to have on file (guidance, our wording)
  • Legal and regulatory obligations register with owners
  • Contractual security clauses summary across customer base
NIST CSF 2.0 PR.DS-01 The confidentiality, integrity, and availability of data-at-rest are protected
Evidence to have on file (guidance, our wording)
  • Data at rest encryption inventory by store type
  • Storage configuration baselines with attestation
Application question Do you obtain written consent from individuals prior to collection, receipt or retention of biometric information?
Munich Re held application question
ISO 27001:2022 A.5.33 Protection of records
Evidence to have on file (guidance, our wording)
  • Records handling guidelines covering storage, chain of custody, tamper prevention and disposal, aligned with the records management policy
  • A retention schedule listing record types, retention periods, legal basis and permitted storage media
ISO 27001:2022 A.8.10 Information deletion
Evidence to have on file (guidance, our wording)
  • The data retention topic-specific policy with deletion triggers per information type
  • Configuration of automated deletion after retention periods or on data subject requests
ISO 27001:2022 A.7.14 Secure disposal or re-use of equipment
Evidence to have on file (guidance, our wording)
  • A disposal and reuse procedure requiring verification that equipment is checked for storage media and sanitized
  • Sanitization or destruction certificates identifying each device, method used and verifier
SOC 2 P4.2 Retaining personal information
Evidence to have on file (guidance, our wording)
  • Retention schedule for personal information categories
  • Evidence of automated retention enforcement
SOC 2 P4.3 Securely disposing of personal information
Evidence to have on file (guidance, our wording)
  • Deletion request log with completion evidence
  • Anonymisation or destruction procedure
NIST CSF 2.0 PR.DS-01 The confidentiality, integrity, and availability of data-at-rest are protected
Evidence to have on file (guidance, our wording)
  • Data at rest encryption inventory by store type
  • Storage configuration baselines with attestation
NIST CSF 2.0 GV.OC-03 Legal, regulatory, and contractual requirements regarding cybersecurity - including privacy and civil liberties obligations - are understood and managed
Evidence to have on file (guidance, our wording)
  • Legal and regulatory obligations register with owners
  • Contractual security clauses summary across customer base
Application question Do you have a retention schedule outlining how long biometric information is retained?
Munich Re held application question
ISO 27001:2022 A.5.33 Protection of records
Evidence to have on file (guidance, our wording)
  • Records handling guidelines covering storage, chain of custody, tamper prevention and disposal, aligned with the records management policy
  • A retention schedule listing record types, retention periods, legal basis and permitted storage media
ISO 27001:2022 A.8.10 Information deletion
Evidence to have on file (guidance, our wording)
  • The data retention topic-specific policy with deletion triggers per information type
  • Configuration of automated deletion after retention periods or on data subject requests
ISO 27001:2022 A.7.14 Secure disposal or re-use of equipment
Evidence to have on file (guidance, our wording)
  • A disposal and reuse procedure requiring verification that equipment is checked for storage media and sanitized
  • Sanitization or destruction certificates identifying each device, method used and verifier
SOC 2 P4.2 Retaining personal information
Evidence to have on file (guidance, our wording)
  • Retention schedule for personal information categories
  • Evidence of automated retention enforcement
SOC 2 P4.3 Securely disposing of personal information
Evidence to have on file (guidance, our wording)
  • Deletion request log with completion evidence
  • Anonymisation or destruction procedure
NIST CSF 2.0 PR.DS-01 The confidentiality, integrity, and availability of data-at-rest are protected
Evidence to have on file (guidance, our wording)
  • Data at rest encryption inventory by store type
  • Storage configuration baselines with attestation
NIST CSF 2.0 GV.OC-03 Legal, regulatory, and contractual requirements regarding cybersecurity - including privacy and civil liberties obligations - are understood and managed
Evidence to have on file (guidance, our wording)
  • Legal and regulatory obligations register with owners
  • Contractual security clauses summary across customer base
Application question Do you sell, lease, trade or otherwise profit from the biometric information of individuals?
Munich Re held application question
ISO 27001:2022 A.5.34 Privacy and protection of personal identifiable information (PII)
Evidence to have on file (guidance, our wording)
  • The topic-specific privacy and PII protection policy and its communication to relevant parties
  • Privacy procedures communicated to everyone who processes PII
ISO 27001:2022 A.5.31 Legal, statutory, regulatory and contractual requirements
Evidence to have on file (guidance, our wording)
  • A register of applicable laws, regulations and contractual obligations for information security, with the countries covered, the approach to meeting each and a named responsible owner
  • Records of periodic review of the register and of new or changed legislation identified
SOC 2 P1.1 Privacy notice to data subjects
Evidence to have on file (guidance, our wording)
  • Published privacy notice with effective date and version history
  • Evidence notice is presented at collection points (forms, apps)
SOC 2 P3.1 Collecting personal information consistent with objectives
Evidence to have on file (guidance, our wording)
  • Data inventory showing purpose for each personal data field
  • Privacy review of new collection forms or features
NIST CSF 2.0 GV.OC-03 Legal, regulatory, and contractual requirements regarding cybersecurity - including privacy and civil liberties obligations - are understood and managed
Evidence to have on file (guidance, our wording)
  • Legal and regulatory obligations register with owners
  • Contractual security clauses summary across customer base
NIST CSF 2.0 PR.DS-01 The confidentiality, integrity, and availability of data-at-rest are protected
Evidence to have on file (guidance, our wording)
  • Data at rest encryption inventory by store type
  • Storage configuration baselines with attestation
Application question Do you subject biometric data to any of the following measures?
Munich Re held application question
ISO 27001:2022 A.5.34 Privacy and protection of personal identifiable information (PII)
Evidence to have on file (guidance, our wording)
  • The topic-specific privacy and PII protection policy and its communication to relevant parties
  • Privacy procedures communicated to everyone who processes PII
ISO 27001:2022 A.5.31 Legal, statutory, regulatory and contractual requirements
Evidence to have on file (guidance, our wording)
  • A register of applicable laws, regulations and contractual obligations for information security, with the countries covered, the approach to meeting each and a named responsible owner
  • Records of periodic review of the register and of new or changed legislation identified
SOC 2 P1.1 Privacy notice to data subjects
Evidence to have on file (guidance, our wording)
  • Published privacy notice with effective date and version history
  • Evidence notice is presented at collection points (forms, apps)
SOC 2 P3.1 Collecting personal information consistent with objectives
Evidence to have on file (guidance, our wording)
  • Data inventory showing purpose for each personal data field
  • Privacy review of new collection forms or features
NIST CSF 2.0 GV.OC-03 Legal, regulatory, and contractual requirements regarding cybersecurity - including privacy and civil liberties obligations - are understood and managed
Evidence to have on file (guidance, our wording)
  • Legal and regulatory obligations register with owners
  • Contractual security clauses summary across customer base
NIST CSF 2.0 PR.DS-01 The confidentiality, integrity, and availability of data-at-rest are protected
Evidence to have on file (guidance, our wording)
  • Data at rest encryption inventory by store type
  • Storage configuration baselines with attestation
Application question Claims & Insurance History Do you hold or have you held insurance providing the same or similar coverage as the insurance being applied for?
Munich Re held application question

No held control answers this line.

Application question Yes  No Has any insurer cancelled or non-renewed a policy that provided the same or similar coverage as the insurance  Yes  No being applied for?
Munich Re held application question

This is a loss history question, not a control requirement. It reaches no held control.

No held control answers this line.

Application question In the last five years has the applicant received or sustained, or are there currently pending, any claims, complaints  Yes  No or incidents which may be covered under the proposed insurance?
Munich Re held application question

This is a loss history question, not a control requirement. It reaches no held control.

No held control answers this line.

Application question Do you have knowledge of any fact, circumstance, situation, event or transaction which may give rise to a claim or  Yes  No loss under the proposed insurance?
Munich Re held application question

Prior-knowledge question. This asks whether the applicant knows of any circumstance that could give rise to a claim. A wrong answer here is the classic route to a prior-knowledge exclusion or rescission, so it is the highest-consequence line on the form, not a line to leave unread. It reaches no control by itself: it is about what the applicant knows, not a control to hold.

No held control answers this line.

Controls not asked in this held document (178)

None of this held document's questions reach 178 of the 290 held controls (for example A.5.3, A.5.5, A.5.6, A.5.7, A.5.8, A.5.10, A.5.11, A.5.22). That is a fact about this held document, not about what the carrier underwrites on: a carrier's fuller forms and supplements ask controls this summary does not, multi-factor authentication, offline backups and patching among them. A control here is not asserted as required, and not asserted as not required.