RLI cyber policy application, held
The questions of the RT Connector Cyber Application, held and mapped to the ISO 27001:2022 controls, the SOC 2 criteria and the NIST CSF 2.0 outcomes each one reaches. The source document (read 2026-10-11). The date shown is the date this copy was read, not a version the form itself states. This page quotes only the question each mapped row needs and states its source; it does not publish the carrier's form. A complete form would be held only under a stated policy for copyrighted forms. RLI is a source document, never a customer.
This document's questions reach 26 of 290 held controls. Whether an applicant is offered cover is the carrier’s underwriting decision. 0 questions here are flagged knockout (a "no" is a common decline point) and 0 flagged warranty (an answer the carrier relies on, that can affect cover if wrong).
This is an attestation question, not a control requirement. It reaches no held control.
No held control answers this line.
This is a scoping question, not a control requirement. It reaches no held control.
No held control answers this line.
This is a scoping question, not a control requirement. It reaches no held control.
No held control answers this line.
This is a scoping question, not a control requirement. It reaches no held control.
No held control answers this line.
This is a loss history question, not a control requirement. It reaches no held control.
No held control answers this line.
This is a loss history question, not a control requirement. It reaches no held control.
No held control answers this line.
- The topic-specific supplier relationship policy and its communication record
- A supplier inventory categorized by type and by the information, services and infrastructure each can access
- Supplier agreements containing security clauses proportionate to the relationship, such as classification mapping, agreed controls, incident notification, subcontracting, right to audit and termination terms
- A register of contracts, memoranda and information-sharing arrangements with outside parties showing what information each covers and when it was last reviewed
- Security requirements included in ICT acquisition specifications and contracts, including flow-down to sub-suppliers
- Software component information such as SBOMs and descriptions of security functions and secure configuration obtained from product suppliers
- Vendor inventory with risk tiers and the review frequency set for each tier
- Due diligence records, for example vendor SOC reports reviewed with complementary controls noted
- Data processing agreements with privacy clauses
- Periodic assessments of vendors' privacy compliance
- Third party risk management program charter
- Supplier risk policy with tiering criteria
- Standard supplier security requirements catalog
- Contract clause library with cyber obligations
- the bank or treasury platform dual-authorisation setup and the payment approval workflow, showing a second approver on a different device above the threshold
- the callback or out-of-band verification procedure for a change to payee bank details, with a dated example
- A documented awareness, education and training programme aligned with the policies and planned by role, including external personnel
- Completion records for initial training of new starters and role changers and for periodic refreshers
- An authentication standard linking required authentication strength to information classification and system criticality
- MFA configuration and coverage reports for critical systems, remote access and privileged access, including conditional or risk-based rules
- the bank or treasury platform dual-authorisation setup and the payment approval workflow, showing a second approver on a different device above the threshold
- the callback or out-of-band verification procedure for a change to payee bank details, with a dated example
- Fraud risk assessment or fraud section of the enterprise risk assessment
- Analysis of privileged access and data misuse scenarios
- Access policy framework with role definitions
- Privileged access management deployment evidence
- Cybersecurity risk management policy approved by leadership
- Policy linkage matrix to standards and procedures
- the bank or treasury platform dual-authorisation setup and the payment approval workflow, showing a second approver on a different device above the threshold
- the callback or out-of-band verification procedure for a change to payee bank details, with a dated example
- A documented awareness, education and training programme aligned with the policies and planned by role, including external personnel
- Completion records for initial training of new starters and role changers and for periodic refreshers
- An authentication standard linking required authentication strength to information classification and system criticality
- MFA configuration and coverage reports for critical systems, remote access and privileged access, including conditional or risk-based rules
- the bank or treasury platform dual-authorisation setup and the payment approval workflow, showing a second approver on a different device above the threshold
- the callback or out-of-band verification procedure for a change to payee bank details, with a dated example
- Fraud risk assessment or fraud section of the enterprise risk assessment
- Analysis of privileged access and data misuse scenarios
- Access policy framework with role definitions
- Privileged access management deployment evidence
- The topic-specific cryptography policy with approved algorithms, key lengths, protocols and usage by information classification
- Evidence of encryption on endpoints, removable media and data in transit, aligned with the policy
- The topic-specific removable media policy and evidence it was communicated to users
- Endpoint configuration showing USB and SD ports disabled unless a business reason is approved, and monitoring of transfers to removable media
- The topic-specific endpoint policy covering classification limits, registration, software restrictions, updates, network connection rules, encryption, malware protection, remote wipe, backup and port control
- Device management (MDM or endpoint management) reports showing enrolment, encryption, patch level, firewall and anti-malware status
- Asset inventory with classification for in-scope systems
- Identity provider configuration showing MFA and password policy
- TLS and encryption standards for data in transit
- Removable media policy and technical enforcement
- Data at rest encryption inventory by store type
- Storage configuration baselines with attestation
- TLS configuration standards and scan results
- VPN and zero trust network access policy
This is a media liability question, not a control requirement. It reaches no held control.
No held control answers this line.
This is a loss history question, not a control requirement. It reaches no held control.
No held control answers this line.
This is a media liability question, not a control requirement. It reaches no held control.
No held control answers this line.
- The topic-specific supplier relationship policy and its communication record
- A supplier inventory categorized by type and by the information, services and infrastructure each can access
- Supplier agreements containing security clauses proportionate to the relationship, such as classification mapping, agreed controls, incident notification, subcontracting, right to audit and termination terms
- A register of contracts, memoranda and information-sharing arrangements with outside parties showing what information each covers and when it was last reviewed
- Security requirements included in ICT acquisition specifications and contracts, including flow-down to sub-suppliers
- Software component information such as SBOMs and descriptions of security functions and secure configuration obtained from product suppliers
- Vendor inventory with risk tiers and the review frequency set for each tier
- Due diligence records, for example vendor SOC reports reviewed with complementary controls noted
- Data processing agreements with privacy clauses
- Periodic assessments of vendors' privacy compliance
- Third party risk management program charter
- Supplier risk policy with tiering criteria
- Standard supplier security requirements catalog
- Contract clause library with cyber obligations
This is a scoping question, not a control requirement. It reaches no held control.
No held control answers this line.
No held control answers this line.
- Current rules on safe, proper use of online resources
- Web filtering or secure web gateway configuration showing blocked categories such as malicious, phishing, command and control, illegal content and upload sites
- Anti-malware deployment and update status reports across endpoints, servers and gateways
- Application allowlisting and malicious website blocking configurations
- The topic-specific information transfer policy and its communication record
- Transfer agreements with third parties covering recipient authentication, protection levels, incident liability and labelling
- Endpoint protection coverage report across servers and workstations
- Local administrator and software installation restrictions
- Application allowlist policy and tooling configuration
- Endpoint protection deployment reports
This is a loss history question, not a control requirement. It reaches no held control.
No held control answers this line.
Controls not asked in this held document (264)
None of this held document's questions reach 264 of the 290 held controls (for example A.5.1, A.5.2, A.5.4, A.5.5, A.5.6, A.5.7, A.5.8, A.5.9). That is a fact about this held document, not about what the carrier underwrites on: a carrier's fuller forms and supplements ask controls this summary does not, multi-factor authentication, offline backups and patching among them. A control here is not asserted as required, and not asserted as not required.