Cyber Insurance Application Scannermap an application to controls

Tokio Marine HCC cyber policy application, held

The questions of the NetGuard Plus Cyber Liability Insurance Application (US), held and mapped to the ISO 27001:2022 controls, the SOC 2 criteria and the NIST CSF 2.0 outcomes each one reaches. The source document (read 2026-10-11). The date shown is the date this copy was read, not a version the form itself states. This page quotes only the question each mapped row needs and states its source; it does not publish the carrier's form. A complete form would be held only under a stated policy for copyrighted forms. Tokio Marine HCC is a source document, never a customer.

This document's questions reach 55 of 290 held controls. Whether an applicant is offered cover is the carrier’s underwriting decision. 8 questions here are flagged knockout (a "no" is a common decline point) and 8 flagged warranty (an answer the carrier relies on, that can affect cover if wrong).

An answer about an existing state of affairs can be relied on by the carrier, but in Australia and the United Kingdom a statement by the insured is a representation, not a warranty (the Insurance Contracts Act and the Insurance Act), and the position varies by US state.

Application question Do you collect, store, host, process, control, use or share any private or sensitive information* in either paper or electronic form?
Tokio Marine HCC held application question

This is a scoping question, not a control requirement. It reaches no held control.

No held control answers this line.

Application question Do you collect, store, host, process, control, use or share any biometric information or data, such as fingerprints, voiceprints, facial, hand, iris or retinal scans, DNA, or any other biological, physical or behavioral characteristics that can be used to uniquely identify a person?
Tokio Marine HCC held application question

This is a scoping question, not a control requirement. It reaches no held control.

No held control answers this line.

Application question If "Yes", have you reviewed your policies relating to the collection, storage and destruction of such information or data with a qualified attorney and confirmed compliance with applicable federal, state, local and foreign laws?
Tokio Marine HCC held application question
ISO 27001:2022 A.5.34 Privacy and protection of personal identifiable information (PII)
Evidence to have on file (guidance, our wording)
  • The topic-specific privacy and PII protection policy and its communication to relevant parties
  • Privacy procedures communicated to everyone who processes PII
ISO 27001:2022 A.5.31 Legal, statutory, regulatory and contractual requirements
Evidence to have on file (guidance, our wording)
  • A register of applicable laws, regulations and contractual obligations for information security, with the countries covered, the approach to meeting each and a named responsible owner
  • Records of periodic review of the register and of new or changed legislation identified
SOC 2 P1.1 Privacy notice to data subjects
Evidence to have on file (guidance, our wording)
  • Published privacy notice with effective date and version history
  • Evidence notice is presented at collection points (forms, apps)
SOC 2 P3.1 Collecting personal information consistent with objectives
Evidence to have on file (guidance, our wording)
  • Data inventory showing purpose for each personal data field
  • Privacy review of new collection forms or features
NIST CSF 2.0 GV.OC-03 Legal, regulatory, and contractual requirements regarding cybersecurity - including privacy and civil liberties obligations - are understood and managed
Evidence to have on file (guidance, our wording)
  • Legal and regulatory obligations register with owners
  • Contractual security clauses summary across customer base
NIST CSF 2.0 PR.DS-01 The confidentiality, integrity, and availability of data-at-rest are protected
Evidence to have on file (guidance, our wording)
  • Data at rest encryption inventory by store type
  • Storage configuration baselines with attestation
Application question Do you use anti-virus software and a firewall to protect your network?
Tokio Marine HCC held application question

Flagged knockout: the wording of this question makes a "no" a common point at which a cyber application is declined or referred.

Flagged warranty: where the carrier declares its answers to be the basis of the contract, this is an answer the carrier relies on and that can affect cover if it is wrong.

ISO 27001:2022 A.8.7 Protection against malware
Evidence to have on file (guidance, our wording)
  • Anti-malware deployment and update status reports across endpoints, servers and gateways
  • Application allowlisting and malicious website blocking configurations
ISO 27001:2022 A.8.1 User end point devices
Evidence to have on file (guidance, our wording)
  • The topic-specific endpoint policy covering classification limits, registration, software restrictions, updates, network connection rules, encryption, malware protection, remote wipe, backup and port control
  • Device management (MDM or endpoint management) reports showing enrolment, encryption, patch level, firewall and anti-malware status
ISO 27001:2022 A.8.20 Networks security
Evidence to have on file (guidance, our wording)
  • Current network diagrams and device configuration backups for routers, switches, firewalls and wireless controllers
  • Defined responsibilities and procedures for network device management, separated from system operations where appropriate
SOC 2 CC6.8 Preventing and detecting unauthorised or malicious software
Evidence to have on file (guidance, our wording)
  • Endpoint protection coverage report across servers and workstations
  • Local administrator and software installation restrictions
SOC 2 CC6.6 Protection against threats from outside the system boundary
Evidence to have on file (guidance, our wording)
  • Firewall and security group rule sets with review evidence
  • MFA enforced on VPN, remote and administrative access
NIST CSF 2.0 PR.PS-05 Installation and execution of unauthorized software are prevented
Evidence to have on file (guidance, our wording)
  • Application allowlist policy and tooling configuration
  • Endpoint protection deployment reports
NIST CSF 2.0 DE.CM-09 Computing hardware and software, runtime environments, and their data are monitored to find potentially adverse events
Evidence to have on file (guidance, our wording)
  • EDR coverage report by asset class
  • File integrity monitoring baseline and drift alerts
Application question Do you use a cloud provider to store data or host applications?
Tokio Marine HCC held application question

Answer options on this form: No / Yes.

ISO 27001:2022 A.5.19 Information security in supplier relationships
Evidence to have on file (guidance, our wording)
  • The topic-specific supplier relationship policy and its communication record
  • A supplier inventory categorized by type and by the information, services and infrastructure each can access
ISO 27001:2022 A.5.20 Addressing information security within supplier agreements
Evidence to have on file (guidance, our wording)
  • Supplier agreements containing security clauses proportionate to the relationship, such as classification mapping, agreed controls, incident notification, subcontracting, right to audit and termination terms
  • A register of contracts, memoranda and information-sharing arrangements with outside parties showing what information each covers and when it was last reviewed
ISO 27001:2022 A.5.21 Managing information security in the information and communication technology (ICT) supply chain
Evidence to have on file (guidance, our wording)
  • Security requirements included in ICT acquisition specifications and contracts, including flow-down to sub-suppliers
  • Software component information such as SBOMs and descriptions of security functions and secure configuration obtained from product suppliers
SOC 2 CC9.2 Assessing and managing vendor and business partner risk
Evidence to have on file (guidance, our wording)
  • Vendor inventory with risk tiers and the review frequency set for each tier
  • Due diligence records, for example vendor SOC reports reviewed with complementary controls noted
SOC 2 P6.4 Privacy commitments from vendors and third parties
Evidence to have on file (guidance, our wording)
  • Data processing agreements with privacy clauses
  • Periodic assessments of vendors' privacy compliance
NIST CSF 2.0 GV.SC-01 A cybersecurity supply chain risk management program, strategy, objectives, policies, and processes are established and agreed to by organizational stakeholders
Evidence to have on file (guidance, our wording)
  • Third party risk management program charter
  • Supplier risk policy with tiering criteria
NIST CSF 2.0 GV.SC-05 Requirements to address cybersecurity risks in supply chains are established, prioritized, and integrated into contracts and other types of agreements with suppliers and other relevant third parties
Evidence to have on file (guidance, our wording)
  • Standard supplier security requirements catalog
  • Contract clause library with cyber obligations
Application question Amazon Web Services (AWS), Microsoft Azure, Google Cloud?
Tokio Marine HCC held application question

This is a scoping question, not a control requirement. It reaches no held control.

No held control answers this line.

Application question Do you encrypt all sensitive and confidential information stored on your organization's systems and networks?
Tokio Marine HCC held application question
ISO 27001:2022 A.8.24 Use of cryptography
Evidence to have on file (guidance, our wording)
  • The topic-specific cryptography policy with approved algorithms, key lengths, protocols and usage by information classification
  • Evidence of encryption on endpoints, removable media and data in transit, aligned with the policy
ISO 27001:2022 A.7.10 Storage media
Evidence to have on file (guidance, our wording)
  • The topic-specific removable media policy and evidence it was communicated to users
  • Endpoint configuration showing USB and SD ports disabled unless a business reason is approved, and monitoring of transfers to removable media
ISO 27001:2022 A.8.1 User end point devices
Evidence to have on file (guidance, our wording)
  • The topic-specific endpoint policy covering classification limits, registration, software restrictions, updates, network connection rules, encryption, malware protection, remote wipe, backup and port control
  • Device management (MDM or endpoint management) reports showing enrolment, encryption, patch level, firewall and anti-malware status
SOC 2 CC6.1 Logical access security over protected information assets
Evidence to have on file (guidance, our wording)
  • Asset inventory with classification for in-scope systems
  • Identity provider configuration showing MFA and password policy
SOC 2 CC6.7 Restricting and protecting information in transmission, movement and removal
Evidence to have on file (guidance, our wording)
  • TLS and encryption standards for data in transit
  • Removable media policy and technical enforcement
NIST CSF 2.0 PR.DS-01 The confidentiality, integrity, and availability of data-at-rest are protected
Evidence to have on file (guidance, our wording)
  • Data at rest encryption inventory by store type
  • Storage configuration baselines with attestation
NIST CSF 2.0 PR.DS-02 The confidentiality, integrity, and availability of data-in-transit are protected
Evidence to have on file (guidance, our wording)
  • TLS configuration standards and scan results
  • VPN and zero trust network access policy
Application question If "No", are the following compensating controls in place: (1) Segregation of servers that store sensitive and confidential information?
Tokio Marine HCC held application question

No held control answers this line.

Application question (2) Access control with role-based assignments?
Tokio Marine HCC held application question
ISO 27001:2022 A.5.15 Access control
Evidence to have on file (guidance, our wording)
  • The topic-specific access control policy, approved and communicated, reflecting owner-defined business and security requirements
  • Access control rules or role models mapping entities (users, services, devices) to rights, consistent with classification
ISO 27001:2022 A.5.16 Identity management
Evidence to have on file (guidance, our wording)
  • Identity management procedure covering creation, verification, activation, change, disablement and removal
  • Evidence that identities are verified against trusted documents before issue
ISO 27001:2022 A.5.18 Access rights
Evidence to have on file (guidance, our wording)
  • Access request records showing owner authorization, and management approval where required, before rights were activated
  • A central record of access rights per user identifier across logical and physical access
SOC 2 CC6.1 Logical access security over protected information assets
Evidence to have on file (guidance, our wording)
  • Asset inventory with classification for in-scope systems
  • Identity provider configuration showing MFA and password policy
SOC 2 CC6.2 Registering and authorising users before issuing credentials
Evidence to have on file (guidance, our wording)
  • Access request tickets with owner approval for a sample of new users, service accounts and API credentials
  • Termination records reconciled to account disablement dates
NIST CSF 2.0 PR.AA-01 Identities and credentials for authorized users, services, and hardware are managed by the organization
Evidence to have on file (guidance, our wording)
  • Identity management platform configuration baseline
  • Joiner mover leaver workflow with timing SLAs
NIST CSF 2.0 PR.AA-05 Access permissions, entitlements, and authorizations are defined in a policy, managed, enforced, and reviewed, and incorporate the principles of least privilege and separation of duties
Evidence to have on file (guidance, our wording)
  • Access policy framework with role definitions
  • Privileged access management deployment evidence
Application question Do you process, store, or handle credit card transactions?
Tokio Marine HCC held application question
ISO 27001:2022 A.8.24 Use of cryptography
Evidence to have on file (guidance, our wording)
  • The topic-specific cryptography policy with approved algorithms, key lengths, protocols and usage by information classification
  • Evidence of encryption on endpoints, removable media and data in transit, aligned with the policy
ISO 27001:2022 A.5.15 Access control
Evidence to have on file (guidance, our wording)
  • The topic-specific access control policy, approved and communicated, reflecting owner-defined business and security requirements
  • Access control rules or role models mapping entities (users, services, devices) to rights, consistent with classification
SOC 2 CC6.1 Logical access security over protected information assets
Evidence to have on file (guidance, our wording)
  • Asset inventory with classification for in-scope systems
  • Identity provider configuration showing MFA and password policy
SOC 2 CC6.7 Restricting and protecting information in transmission, movement and removal
Evidence to have on file (guidance, our wording)
  • TLS and encryption standards for data in transit
  • Removable media policy and technical enforcement
NIST CSF 2.0 PR.DS-01 The confidentiality, integrity, and availability of data-at-rest are protected
Evidence to have on file (guidance, our wording)
  • Data at rest encryption inventory by store type
  • Storage configuration baselines with attestation
Application question If "Yes", are you PCI-DSS Compliant?
Tokio Marine HCC held application question

This is an attestation question, not a control requirement. It reaches no held control.

No held control answers this line.

Application question Do you allow remote access to your network?
Tokio Marine HCC held application question
ISO 27001:2022 A.6.7 Remote working
Evidence to have on file (guidance, our wording)
  • The topic-specific remote working policy defining conditions, permitted work, information classifications allowed and systems accessible
  • Remote access configuration showing multi-factor authentication, secure channels or virtual desktops
ISO 27001:2022 A.8.20 Networks security
Evidence to have on file (guidance, our wording)
  • Current network diagrams and device configuration backups for routers, switches, firewalls and wireless controllers
  • Defined responsibilities and procedures for network device management, separated from system operations where appropriate
ISO 27001:2022 A.8.22 Segregation of networks
Evidence to have on file (guidance, our wording)
  • Network segmentation design defining domains by trust, criticality, sensitivity or organizational unit, with the assessment that justified it
  • Firewall or filtering router rules controlling traffic between domains, with rule review records
SOC 2 CC6.6 Protection against threats from outside the system boundary
Evidence to have on file (guidance, our wording)
  • Firewall and security group rule sets with review evidence
  • MFA enforced on VPN, remote and administrative access
NIST CSF 2.0 PR.IR-01 Networks and environments are protected from unauthorized logical access and usage
Evidence to have on file (guidance, our wording)
  • Network segmentation design with zones and trust levels
  • Firewall and access control list governance
Application question If "Yes": (1) Do you use 2-factor authentication to secure all remote access to your network?
Tokio Marine HCC held application question

Flagged knockout: the wording of this question makes a "no" a common point at which a cyber application is declined or referred.

Flagged warranty: where the carrier declares its answers to be the basis of the contract, this is an answer the carrier relies on and that can affect cover if it is wrong.

ISO 27001:2022 A.8.5 Secure authentication
Evidence to have on file (guidance, our wording)
  • An authentication standard linking required authentication strength to information classification and system criticality
  • MFA configuration and coverage reports for critical systems, remote access and privileged access, including conditional or risk-based rules
ISO 27001:2022 A.5.17 Authentication information
Evidence to have on file (guidance, our wording)
  • Credential issuance procedure requiring identity verification before new, replacement or temporary credentials are provided
  • Evidence that initial credentials are unique, delivered over protected channels and changed at first use
ISO 27001:2022 A.6.7 Remote working
Evidence to have on file (guidance, our wording)
  • The topic-specific remote working policy defining conditions, permitted work, information classifications allowed and systems accessible
  • Remote access configuration showing multi-factor authentication, secure channels or virtual desktops
SOC 2 CC6.1 Logical access security over protected information assets
Evidence to have on file (guidance, our wording)
  • Asset inventory with classification for in-scope systems
  • Identity provider configuration showing MFA and password policy
SOC 2 CC6.6 Protection against threats from outside the system boundary
Evidence to have on file (guidance, our wording)
  • Firewall and security group rule sets with review evidence
  • MFA enforced on VPN, remote and administrative access
NIST CSF 2.0 PR.AA-03 Users, services, and hardware are authenticated
Evidence to have on file (guidance, our wording)
  • Multi factor authentication coverage report
  • Phishing resistant authentication rollout plan
NIST CSF 2.0 PR.IR-01 Networks and environments are protected from unauthorized logical access and usage
Evidence to have on file (guidance, our wording)
  • Network segmentation design with zones and trust levels
  • Firewall and access control list governance
Application question (2) Do you utilize IP whitelisting to further protect remote access connections?
Tokio Marine HCC held application question
ISO 27001:2022 A.6.7 Remote working
Evidence to have on file (guidance, our wording)
  • The topic-specific remote working policy defining conditions, permitted work, information classifications allowed and systems accessible
  • Remote access configuration showing multi-factor authentication, secure channels or virtual desktops
ISO 27001:2022 A.8.20 Networks security
Evidence to have on file (guidance, our wording)
  • Current network diagrams and device configuration backups for routers, switches, firewalls and wireless controllers
  • Defined responsibilities and procedures for network device management, separated from system operations where appropriate
ISO 27001:2022 A.8.22 Segregation of networks
Evidence to have on file (guidance, our wording)
  • Network segmentation design defining domains by trust, criticality, sensitivity or organizational unit, with the assessment that justified it
  • Firewall or filtering router rules controlling traffic between domains, with rule review records
SOC 2 CC6.6 Protection against threats from outside the system boundary
Evidence to have on file (guidance, our wording)
  • Firewall and security group rule sets with review evidence
  • MFA enforced on VPN, remote and administrative access
NIST CSF 2.0 PR.IR-01 Networks and environments are protected from unauthorized logical access and usage
Evidence to have on file (guidance, our wording)
  • Network segmentation design with zones and trust levels
  • Firewall and access control list governance
NIST CSF 2.0 DE.CM-01 Networks and network services are monitored to find potentially adverse events
Evidence to have on file (guidance, our wording)
  • Network flow telemetry coverage map by segment
  • IDS or NDR sensor inventory with placement diagram
Application question Have you disabled the Remote Desktop Protocol (RDP) and/or Remote Desktop Gateway (RDG) on all system endpoints and servers?
Tokio Marine HCC held application question
ISO 27001:2022 A.6.7 Remote working
Evidence to have on file (guidance, our wording)
  • The topic-specific remote working policy defining conditions, permitted work, information classifications allowed and systems accessible
  • Remote access configuration showing multi-factor authentication, secure channels or virtual desktops
ISO 27001:2022 A.8.20 Networks security
Evidence to have on file (guidance, our wording)
  • Current network diagrams and device configuration backups for routers, switches, firewalls and wireless controllers
  • Defined responsibilities and procedures for network device management, separated from system operations where appropriate
ISO 27001:2022 A.8.22 Segregation of networks
Evidence to have on file (guidance, our wording)
  • Network segmentation design defining domains by trust, criticality, sensitivity or organizational unit, with the assessment that justified it
  • Firewall or filtering router rules controlling traffic between domains, with rule review records
SOC 2 CC6.6 Protection against threats from outside the system boundary
Evidence to have on file (guidance, our wording)
  • Firewall and security group rule sets with review evidence
  • MFA enforced on VPN, remote and administrative access
NIST CSF 2.0 PR.IR-01 Networks and environments are protected from unauthorized logical access and usage
Evidence to have on file (guidance, our wording)
  • Network segmentation design with zones and trust levels
  • Firewall and access control list governance
Application question If "No", is RDP and/or RDG protected by two-factor authentication?
Tokio Marine HCC held application question

Flagged knockout: the wording of this question makes a "no" a common point at which a cyber application is declined or referred.

Flagged warranty: where the carrier declares its answers to be the basis of the contract, this is an answer the carrier relies on and that can affect cover if it is wrong.

ISO 27001:2022 A.8.5 Secure authentication
Evidence to have on file (guidance, our wording)
  • An authentication standard linking required authentication strength to information classification and system criticality
  • MFA configuration and coverage reports for critical systems, remote access and privileged access, including conditional or risk-based rules
ISO 27001:2022 A.5.17 Authentication information
Evidence to have on file (guidance, our wording)
  • Credential issuance procedure requiring identity verification before new, replacement or temporary credentials are provided
  • Evidence that initial credentials are unique, delivered over protected channels and changed at first use
ISO 27001:2022 A.6.7 Remote working
Evidence to have on file (guidance, our wording)
  • The topic-specific remote working policy defining conditions, permitted work, information classifications allowed and systems accessible
  • Remote access configuration showing multi-factor authentication, secure channels or virtual desktops
SOC 2 CC6.1 Logical access security over protected information assets
Evidence to have on file (guidance, our wording)
  • Asset inventory with classification for in-scope systems
  • Identity provider configuration showing MFA and password policy
SOC 2 CC6.6 Protection against threats from outside the system boundary
Evidence to have on file (guidance, our wording)
  • Firewall and security group rule sets with review evidence
  • MFA enforced on VPN, remote and administrative access
NIST CSF 2.0 PR.AA-03 Users, services, and hardware are authenticated
Evidence to have on file (guidance, our wording)
  • Multi factor authentication coverage report
  • Phishing resistant authentication rollout plan
NIST CSF 2.0 PR.IR-01 Networks and environments are protected from unauthorized logical access and usage
Evidence to have on file (guidance, our wording)
  • Network segmentation design with zones and trust levels
  • Firewall and access control list governance
Application question Do you use 2-factor authentication to secure all domain or network administrator accounts?
Tokio Marine HCC held application question

Flagged knockout: the wording of this question makes a "no" a common point at which a cyber application is declined or referred.

Flagged warranty: where the carrier declares its answers to be the basis of the contract, this is an answer the carrier relies on and that can affect cover if it is wrong.

ISO 27001:2022 A.8.5 Secure authentication
Evidence to have on file (guidance, our wording)
  • An authentication standard linking required authentication strength to information classification and system criticality
  • MFA configuration and coverage reports for critical systems, remote access and privileged access, including conditional or risk-based rules
ISO 27001:2022 A.5.17 Authentication information
Evidence to have on file (guidance, our wording)
  • Credential issuance procedure requiring identity verification before new, replacement or temporary credentials are provided
  • Evidence that initial credentials are unique, delivered over protected channels and changed at first use
ISO 27001:2022 A.8.2 Privileged access rights
Evidence to have on file (guidance, our wording)
  • An inventory of privileged accounts per system (operating systems, databases, applications, cloud consoles) mapped to named individuals
  • Authorization records for each privileged grant with approver, justification and expiry
SOC 2 CC6.1 Logical access security over protected information assets
Evidence to have on file (guidance, our wording)
  • Asset inventory with classification for in-scope systems
  • Identity provider configuration showing MFA and password policy
SOC 2 CC6.3 Role-based access, least privilege and segregation of duties
Evidence to have on file (guidance, our wording)
  • the bank or treasury platform dual-authorisation setup and the payment approval workflow, showing a second approver on a different device above the threshold
  • the callback or out-of-band verification procedure for a change to payee bank details, with a dated example
NIST CSF 2.0 PR.AA-03 Users, services, and hardware are authenticated
Evidence to have on file (guidance, our wording)
  • Multi factor authentication coverage report
  • Phishing resistant authentication rollout plan
NIST CSF 2.0 PR.AA-05 Access permissions, entitlements, and authorizations are defined in a policy, managed, enforced, and reviewed, and incorporate the principles of least privilege and separation of duties
Evidence to have on file (guidance, our wording)
  • Access policy framework with role definitions
  • Privileged access management deployment evidence
Application question Do you use 2-factor authentication to secure remote access to your email accounts?
Tokio Marine HCC held application question

Flagged knockout: the wording of this question makes a "no" a common point at which a cyber application is declined or referred.

Flagged warranty: where the carrier declares its answers to be the basis of the contract, this is an answer the carrier relies on and that can affect cover if it is wrong.

ISO 27001:2022 A.8.5 Secure authentication
Evidence to have on file (guidance, our wording)
  • An authentication standard linking required authentication strength to information classification and system criticality
  • MFA configuration and coverage reports for critical systems, remote access and privileged access, including conditional or risk-based rules
ISO 27001:2022 A.5.17 Authentication information
Evidence to have on file (guidance, our wording)
  • Credential issuance procedure requiring identity verification before new, replacement or temporary credentials are provided
  • Evidence that initial credentials are unique, delivered over protected channels and changed at first use
ISO 27001:2022 A.6.7 Remote working
Evidence to have on file (guidance, our wording)
  • The topic-specific remote working policy defining conditions, permitted work, information classifications allowed and systems accessible
  • Remote access configuration showing multi-factor authentication, secure channels or virtual desktops
SOC 2 CC6.1 Logical access security over protected information assets
Evidence to have on file (guidance, our wording)
  • Asset inventory with classification for in-scope systems
  • Identity provider configuration showing MFA and password policy
SOC 2 CC6.6 Protection against threats from outside the system boundary
Evidence to have on file (guidance, our wording)
  • Firewall and security group rule sets with review evidence
  • MFA enforced on VPN, remote and administrative access
NIST CSF 2.0 PR.AA-03 Users, services, and hardware are authenticated
Evidence to have on file (guidance, our wording)
  • Multi factor authentication coverage report
  • Phishing resistant authentication rollout plan
NIST CSF 2.0 PR.IR-01 Networks and environments are protected from unauthorized logical access and usage
Evidence to have on file (guidance, our wording)
  • Network segmentation design with zones and trust levels
  • Firewall and access control list governance
Application question Do you use Endpoint Detection and Response (EDR) or a Next-Generation Antivirus (NGAV) software (e.g., CrowdStrike, Cylance, Carbon Black) to secure all system endpoints?
Tokio Marine HCC held application question

Flagged knockout: the wording of this question makes a "no" a common point at which a cyber application is declined or referred.

Flagged warranty: where the carrier declares its answers to be the basis of the contract, this is an answer the carrier relies on and that can affect cover if it is wrong.

ISO 27001:2022 A.8.7 Protection against malware
Evidence to have on file (guidance, our wording)
  • Anti-malware deployment and update status reports across endpoints, servers and gateways
  • Application allowlisting and malicious website blocking configurations
ISO 27001:2022 A.8.1 User end point devices
Evidence to have on file (guidance, our wording)
  • The topic-specific endpoint policy covering classification limits, registration, software restrictions, updates, network connection rules, encryption, malware protection, remote wipe, backup and port control
  • Device management (MDM or endpoint management) reports showing enrolment, encryption, patch level, firewall and anti-malware status
SOC 2 CC6.8 Preventing and detecting unauthorised or malicious software
Evidence to have on file (guidance, our wording)
  • Endpoint protection coverage report across servers and workstations
  • Local administrator and software installation restrictions
NIST CSF 2.0 PR.PS-05 Installation and execution of unauthorized software are prevented
Evidence to have on file (guidance, our wording)
  • Application allowlist policy and tooling configuration
  • Endpoint protection deployment reports
NIST CSF 2.0 DE.CM-09 Computing hardware and software, runtime environments, and their data are monitored to find potentially adverse events
Evidence to have on file (guidance, our wording)
  • EDR coverage report by asset class
  • File integrity monitoring baseline and drift alerts
Application question Do you use an email filtering solution designed to prevent phishing or ransomware attacks (in addition to any filtering solution(s) provided by your email provider?
Tokio Marine HCC held application question
ISO 27001:2022 A.8.23 Web filtering
Evidence to have on file (guidance, our wording)
  • Current rules on safe, proper use of online resources
  • Web filtering or secure web gateway configuration showing blocked categories such as malicious, phishing, command and control, illegal content and upload sites
ISO 27001:2022 A.8.7 Protection against malware
Evidence to have on file (guidance, our wording)
  • Anti-malware deployment and update status reports across endpoints, servers and gateways
  • Application allowlisting and malicious website blocking configurations
ISO 27001:2022 A.5.14 Information transfer
Evidence to have on file (guidance, our wording)
  • The topic-specific information transfer policy and its communication record
  • Transfer agreements with third parties covering recipient authentication, protection levels, incident liability and labelling
SOC 2 CC6.8 Preventing and detecting unauthorised or malicious software
Evidence to have on file (guidance, our wording)
  • Endpoint protection coverage report across servers and workstations
  • Local administrator and software installation restrictions
NIST CSF 2.0 PR.PS-05 Installation and execution of unauthorized software are prevented
Evidence to have on file (guidance, our wording)
  • Application allowlist policy and tooling configuration
  • Endpoint protection deployment reports
Application question Do you use a data backup solution for all critical data?
Tokio Marine HCC held application question
ISO 27001:2022 A.8.13 Information backup
Evidence to have on file (guidance, our wording)
  • The topic-specific backup policy and backup plans stating scope, extent, frequency and retention per system aligned with RPO
  • Backup job monitoring reports with evidence that failed jobs were investigated and rerun
ISO 27001:2022 A.8.14 Redundancy of information processing facilities
Evidence to have on file (guidance, our wording)
  • Documented availability requirements for business services and systems
  • Architecture diagrams showing redundancy such as dual providers, redundant networks, separate data centres, redundant power and load-balanced instances
SOC 2 A1.2 Environmental protection, backup and recovery infrastructure
Evidence to have on file (guidance, our wording)
  • Backup policy defining scope, frequency and retention
  • Backup job monitoring and failure remediation records
SOC 2 A1.3 Testing recovery plan procedures
Evidence to have on file (guidance, our wording)
  • Disaster recovery or continuity test plan and results in the period
  • Backup restore test records with verification of completeness
NIST CSF 2.0 PR.DS-11 Backups of data are created, protected, maintained, and tested
Evidence to have on file (guidance, our wording)
  • Backup policy with frequency and retention
  • Backup integrity test reports
Application question If "Yes": (1) How frequently does it run?
Tokio Marine HCC held application question

No held control answers this line.

Application question Daily Weekly Monthly (2) Which of the following best describes your data backup solution?
Tokio Marine HCC held application question
ISO 27001:2022 A.8.13 Information backup
Evidence to have on file (guidance, our wording)
  • The topic-specific backup policy and backup plans stating scope, extent, frequency and retention per system aligned with RPO
  • Backup job monitoring reports with evidence that failed jobs were investigated and rerun
ISO 27001:2022 A.8.14 Redundancy of information processing facilities
Evidence to have on file (guidance, our wording)
  • Documented availability requirements for business services and systems
  • Architecture diagrams showing redundancy such as dual providers, redundant networks, separate data centres, redundant power and load-balanced instances
SOC 2 A1.2 Environmental protection, backup and recovery infrastructure
Evidence to have on file (guidance, our wording)
  • Backup policy defining scope, frequency and retention
  • Backup job monitoring and failure remediation records
SOC 2 A1.3 Testing recovery plan procedures
Evidence to have on file (guidance, our wording)
  • Disaster recovery or continuity test plan and results in the period
  • Backup restore test records with verification of completeness
NIST CSF 2.0 PR.DS-11 Backups of data are created, protected, maintained, and tested
Evidence to have on file (guidance, our wording)
  • Backup policy with frequency and retention
  • Backup integrity test reports
Application question Local backup Network drive Tape backup Off-site storage Cloud backup Other: (3) Please list your data backup provider: (4) Is your data backup solution: (a) physically disconnected from your network?
Tokio Marine HCC held application question

Flagged knockout: the wording of this question makes a "no" a common point at which a cyber application is declined or referred.

Flagged warranty: where the carrier declares its answers to be the basis of the contract, this is an answer the carrier relies on and that can affect cover if it is wrong.

ISO 27001:2022 A.8.13 Information backup
Evidence to have on file (guidance, our wording)
  • The topic-specific backup policy and backup plans stating scope, extent, frequency and retention per system aligned with RPO
  • Backup job monitoring reports with evidence that failed jobs were investigated and rerun
ISO 27001:2022 A.8.14 Redundancy of information processing facilities
Evidence to have on file (guidance, our wording)
  • Documented availability requirements for business services and systems
  • Architecture diagrams showing redundancy such as dual providers, redundant networks, separate data centres, redundant power and load-balanced instances
ISO 27001:2022 A.7.1 Physical security perimeters
Evidence to have on file (guidance, our wording)
  • Site plans showing defined security perimeters and their strength relative to the assets inside
  • Physical security surveys or assessments of walls, roofs, floors, doors, windows and vents
SOC 2 A1.2 Environmental protection, backup and recovery infrastructure
Evidence to have on file (guidance, our wording)
  • Backup policy defining scope, frequency and retention
  • Backup job monitoring and failure remediation records
SOC 2 A1.3 Testing recovery plan procedures
Evidence to have on file (guidance, our wording)
  • Disaster recovery or continuity test plan and results in the period
  • Backup restore test records with verification of completeness
NIST CSF 2.0 PR.DS-11 Backups of data are created, protected, maintained, and tested
Evidence to have on file (guidance, our wording)
  • Backup policy with frequency and retention
  • Backup integrity test reports
NIST CSF 2.0 PR.AA-06 Physical access to assets is managed, monitored, and enforced commensurate with risk
Evidence to have on file (guidance, our wording)
  • Physical access control system inventory
  • Badge issuance and revocation records
Application question (b) segregated with 2-factor authentication access control?
Tokio Marine HCC held application question

Flagged knockout: the wording of this question makes a "no" a common point at which a cyber application is declined or referred.

Flagged warranty: where the carrier declares its answers to be the basis of the contract, this is an answer the carrier relies on and that can affect cover if it is wrong.

ISO 27001:2022 A.8.5 Secure authentication
Evidence to have on file (guidance, our wording)
  • An authentication standard linking required authentication strength to information classification and system criticality
  • MFA configuration and coverage reports for critical systems, remote access and privileged access, including conditional or risk-based rules
ISO 27001:2022 A.5.17 Authentication information
Evidence to have on file (guidance, our wording)
  • Credential issuance procedure requiring identity verification before new, replacement or temporary credentials are provided
  • Evidence that initial credentials are unique, delivered over protected channels and changed at first use
ISO 27001:2022 A.5.15 Access control
Evidence to have on file (guidance, our wording)
  • The topic-specific access control policy, approved and communicated, reflecting owner-defined business and security requirements
  • Access control rules or role models mapping entities (users, services, devices) to rights, consistent with classification
SOC 2 CC6.1 Logical access security over protected information assets
Evidence to have on file (guidance, our wording)
  • Asset inventory with classification for in-scope systems
  • Identity provider configuration showing MFA and password policy
SOC 2 CC6.2 Registering and authorising users before issuing credentials
Evidence to have on file (guidance, our wording)
  • Access request tickets with owner approval for a sample of new users, service accounts and API credentials
  • Termination records reconciled to account disablement dates
NIST CSF 2.0 PR.AA-03 Users, services, and hardware are authenticated
Evidence to have on file (guidance, our wording)
  • Multi factor authentication coverage report
  • Phishing resistant authentication rollout plan
NIST CSF 2.0 PR.AA-01 Identities and credentials for authorized users, services, and hardware are managed by the organization
Evidence to have on file (guidance, our wording)
  • Identity management platform configuration baseline
  • Joiner mover leaver workflow with timing SLAs
Application question (5) How long do you expect it to take to recover from backups in the event of a widespread malware or ransomware attack within your network?
Tokio Marine HCC held application question
ISO 27001:2022 A.8.13 Information backup
Evidence to have on file (guidance, our wording)
  • The topic-specific backup policy and backup plans stating scope, extent, frequency and retention per system aligned with RPO
  • Backup job monitoring reports with evidence that failed jobs were investigated and rerun
ISO 27001:2022 A.8.14 Redundancy of information processing facilities
Evidence to have on file (guidance, our wording)
  • Documented availability requirements for business services and systems
  • Architecture diagrams showing redundancy such as dual providers, redundant networks, separate data centres, redundant power and load-balanced instances
SOC 2 A1.2 Environmental protection, backup and recovery infrastructure
Evidence to have on file (guidance, our wording)
  • Backup policy defining scope, frequency and retention
  • Backup job monitoring and failure remediation records
SOC 2 A1.3 Testing recovery plan procedures
Evidence to have on file (guidance, our wording)
  • Disaster recovery or continuity test plan and results in the period
  • Backup restore test records with verification of completeness
NIST CSF 2.0 PR.DS-11 Backups of data are created, protected, maintained, and tested
Evidence to have on file (guidance, our wording)
  • Backup policy with frequency and retention
  • Backup integrity test reports
Application question Do any of the following employees at your company complete social engineering training: (1) Employees with financial or accounting responsibilities?
Tokio Marine HCC held application question
ISO 27001:2022 A.6.3 Information security awareness, education and training
Evidence to have on file (guidance, our wording)
  • A documented awareness, education and training programme aligned with the policies and planned by role, including external personnel
  • Completion records for initial training of new starters and role changers and for periodic refreshers
SOC 2 CC1.4 Attracting, developing and retaining competent people (COSO principle 4)
Evidence to have on file (guidance, our wording)
  • Background check policy and completed checks for a sample of new hires and contractors
  • Role competency requirements and performance review records
SOC 2 CC2.2 Internal communication of objectives and control responsibilities (COSO principle 14)
Evidence to have on file (guidance, our wording)
  • Security awareness training content and completion records
  • Published information security policies accessible to staff with change notices
NIST CSF 2.0 PR.AT-01 Personnel are provided with awareness and training so that they possess the knowledge and skills to perform general tasks with cybersecurity risks in mind
Evidence to have on file (guidance, our wording)
  • Security awareness program curriculum
  • Completion records by population
Application question (2) Employees without financial or accounting responsibilities?
Tokio Marine HCC held application question

No held control answers this line.

Application question If "Yes" to question 7.a.(1) or 7.a.(2) above, does your social engineering training include phishing simulation?
Tokio Marine HCC held application question
ISO 27001:2022 A.8.23 Web filtering
Evidence to have on file (guidance, our wording)
  • Current rules on safe, proper use of online resources
  • Web filtering or secure web gateway configuration showing blocked categories such as malicious, phishing, command and control, illegal content and upload sites
ISO 27001:2022 A.8.7 Protection against malware
Evidence to have on file (guidance, our wording)
  • Anti-malware deployment and update status reports across endpoints, servers and gateways
  • Application allowlisting and malicious website blocking configurations
ISO 27001:2022 A.5.14 Information transfer
Evidence to have on file (guidance, our wording)
  • The topic-specific information transfer policy and its communication record
  • Transfer agreements with third parties covering recipient authentication, protection levels, incident liability and labelling
SOC 2 CC6.8 Preventing and detecting unauthorised or malicious software
Evidence to have on file (guidance, our wording)
  • Endpoint protection coverage report across servers and workstations
  • Local administrator and software installation restrictions
SOC 2 CC1.4 Attracting, developing and retaining competent people (COSO principle 4)
Evidence to have on file (guidance, our wording)
  • Background check policy and completed checks for a sample of new hires and contractors
  • Role competency requirements and performance review records
NIST CSF 2.0 PR.PS-05 Installation and execution of unauthorized software are prevented
Evidence to have on file (guidance, our wording)
  • Application allowlist policy and tooling configuration
  • Endpoint protection deployment reports
NIST CSF 2.0 PR.AT-01 Personnel are provided with awareness and training so that they possess the knowledge and skills to perform general tasks with cybersecurity risks in mind
Evidence to have on file (guidance, our wording)
  • Security awareness program curriculum
  • Completion records by population
Application question Does your organization send and/or receive wire transfers?
Tokio Marine HCC held application question
ISO 27001:2022 A.5.3 Segregation of duties
Evidence to have on file (guidance, our wording)
  • the bank or treasury platform dual-authorisation setup and the payment approval workflow, showing a second approver on a different device above the threshold
  • the callback or out-of-band verification procedure for a change to payee bank details, with a dated example
ISO 27001:2022 A.6.3 Information security awareness, education and training
Evidence to have on file (guidance, our wording)
  • A documented awareness, education and training programme aligned with the policies and planned by role, including external personnel
  • Completion records for initial training of new starters and role changers and for periodic refreshers
ISO 27001:2022 A.8.5 Secure authentication
Evidence to have on file (guidance, our wording)
  • An authentication standard linking required authentication strength to information classification and system criticality
  • MFA configuration and coverage reports for critical systems, remote access and privileged access, including conditional or risk-based rules
SOC 2 CC6.3 Role-based access, least privilege and segregation of duties
Evidence to have on file (guidance, our wording)
  • the bank or treasury platform dual-authorisation setup and the payment approval workflow, showing a second approver on a different device above the threshold
  • the callback or out-of-band verification procedure for a change to payee bank details, with a dated example
SOC 2 CC3.3 Considering fraud risk (COSO principle 8)
Evidence to have on file (guidance, our wording)
  • Fraud risk assessment or fraud section of the enterprise risk assessment
  • Analysis of privileged access and data misuse scenarios
NIST CSF 2.0 PR.AA-05 Access permissions, entitlements, and authorizations are defined in a policy, managed, enforced, and reviewed, and incorporate the principles of least privilege and separation of duties
Evidence to have on file (guidance, our wording)
  • Access policy framework with role definitions
  • Privileged access management deployment evidence
Application question If "Yes", does your wire transfer authorization process include the following: (1) A wire request documentation form?
Tokio Marine HCC held application question
ISO 27001:2022 A.5.3 Segregation of duties
Evidence to have on file (guidance, our wording)
  • the bank or treasury platform dual-authorisation setup and the payment approval workflow, showing a second approver on a different device above the threshold
  • the callback or out-of-band verification procedure for a change to payee bank details, with a dated example
ISO 27001:2022 A.6.3 Information security awareness, education and training
Evidence to have on file (guidance, our wording)
  • A documented awareness, education and training programme aligned with the policies and planned by role, including external personnel
  • Completion records for initial training of new starters and role changers and for periodic refreshers
ISO 27001:2022 A.8.5 Secure authentication
Evidence to have on file (guidance, our wording)
  • An authentication standard linking required authentication strength to information classification and system criticality
  • MFA configuration and coverage reports for critical systems, remote access and privileged access, including conditional or risk-based rules
SOC 2 CC6.3 Role-based access, least privilege and segregation of duties
Evidence to have on file (guidance, our wording)
  • the bank or treasury platform dual-authorisation setup and the payment approval workflow, showing a second approver on a different device above the threshold
  • the callback or out-of-band verification procedure for a change to payee bank details, with a dated example
SOC 2 CC3.3 Considering fraud risk (COSO principle 8)
Evidence to have on file (guidance, our wording)
  • Fraud risk assessment or fraud section of the enterprise risk assessment
  • Analysis of privileged access and data misuse scenarios
NIST CSF 2.0 PR.AA-05 Access permissions, entitlements, and authorizations are defined in a policy, managed, enforced, and reviewed, and incorporate the principles of least privilege and separation of duties
Evidence to have on file (guidance, our wording)
  • Access policy framework with role definitions
  • Privileged access management deployment evidence
Application question (2) A protocol for obtaining proper written authorization for wire transfers?
Tokio Marine HCC held application question
ISO 27001:2022 A.5.3 Segregation of duties
Evidence to have on file (guidance, our wording)
  • the bank or treasury platform dual-authorisation setup and the payment approval workflow, showing a second approver on a different device above the threshold
  • the callback or out-of-band verification procedure for a change to payee bank details, with a dated example
ISO 27001:2022 A.6.3 Information security awareness, education and training
Evidence to have on file (guidance, our wording)
  • A documented awareness, education and training programme aligned with the policies and planned by role, including external personnel
  • Completion records for initial training of new starters and role changers and for periodic refreshers
ISO 27001:2022 A.8.5 Secure authentication
Evidence to have on file (guidance, our wording)
  • An authentication standard linking required authentication strength to information classification and system criticality
  • MFA configuration and coverage reports for critical systems, remote access and privileged access, including conditional or risk-based rules
SOC 2 CC6.3 Role-based access, least privilege and segregation of duties
Evidence to have on file (guidance, our wording)
  • the bank or treasury platform dual-authorisation setup and the payment approval workflow, showing a second approver on a different device above the threshold
  • the callback or out-of-band verification procedure for a change to payee bank details, with a dated example
SOC 2 CC3.3 Considering fraud risk (COSO principle 8)
Evidence to have on file (guidance, our wording)
  • Fraud risk assessment or fraud section of the enterprise risk assessment
  • Analysis of privileged access and data misuse scenarios
NIST CSF 2.0 PR.AA-05 Access permissions, entitlements, and authorizations are defined in a policy, managed, enforced, and reviewed, and incorporate the principles of least privilege and separation of duties
Evidence to have on file (guidance, our wording)
  • Access policy framework with role definitions
  • Privileged access management deployment evidence
Application question (3) A separation of authority protocol?
Tokio Marine HCC held application question
ISO 27001:2022 A.5.15 Access control
Evidence to have on file (guidance, our wording)
  • The topic-specific access control policy, approved and communicated, reflecting owner-defined business and security requirements
  • Access control rules or role models mapping entities (users, services, devices) to rights, consistent with classification
ISO 27001:2022 A.5.16 Identity management
Evidence to have on file (guidance, our wording)
  • Identity management procedure covering creation, verification, activation, change, disablement and removal
  • Evidence that identities are verified against trusted documents before issue
ISO 27001:2022 A.5.18 Access rights
Evidence to have on file (guidance, our wording)
  • Access request records showing owner authorization, and management approval where required, before rights were activated
  • A central record of access rights per user identifier across logical and physical access
SOC 2 CC6.1 Logical access security over protected information assets
Evidence to have on file (guidance, our wording)
  • Asset inventory with classification for in-scope systems
  • Identity provider configuration showing MFA and password policy
SOC 2 CC6.2 Registering and authorising users before issuing credentials
Evidence to have on file (guidance, our wording)
  • Access request tickets with owner approval for a sample of new users, service accounts and API credentials
  • Termination records reconciled to account disablement dates
NIST CSF 2.0 PR.AA-01 Identities and credentials for authorized users, services, and hardware are managed by the organization
Evidence to have on file (guidance, our wording)
  • Identity management platform configuration baseline
  • Joiner mover leaver workflow with timing SLAs
NIST CSF 2.0 PR.AA-05 Access permissions, entitlements, and authorizations are defined in a policy, managed, enforced, and reviewed, and incorporate the principles of least privilege and separation of duties
Evidence to have on file (guidance, our wording)
  • Access policy framework with role definitions
  • Privileged access management deployment evidence
Application question (4) A protocol for confirming all payment or funds transfer instructions/requests from a new vendor, client or customer via direct call to that vendor, client or customer using only the telephone number provided by the vendor, client or customer before the payment or funds transfer instruction/request was received?
Tokio Marine HCC held application question
ISO 27001:2022 A.5.19 Information security in supplier relationships
Evidence to have on file (guidance, our wording)
  • The topic-specific supplier relationship policy and its communication record
  • A supplier inventory categorized by type and by the information, services and infrastructure each can access
ISO 27001:2022 A.5.20 Addressing information security within supplier agreements
Evidence to have on file (guidance, our wording)
  • Supplier agreements containing security clauses proportionate to the relationship, such as classification mapping, agreed controls, incident notification, subcontracting, right to audit and termination terms
  • A register of contracts, memoranda and information-sharing arrangements with outside parties showing what information each covers and when it was last reviewed
ISO 27001:2022 A.5.21 Managing information security in the information and communication technology (ICT) supply chain
Evidence to have on file (guidance, our wording)
  • Security requirements included in ICT acquisition specifications and contracts, including flow-down to sub-suppliers
  • Software component information such as SBOMs and descriptions of security functions and secure configuration obtained from product suppliers
SOC 2 CC9.2 Assessing and managing vendor and business partner risk
Evidence to have on file (guidance, our wording)
  • Vendor inventory with risk tiers and the review frequency set for each tier
  • Due diligence records, for example vendor SOC reports reviewed with complementary controls noted
SOC 2 P6.4 Privacy commitments from vendors and third parties
Evidence to have on file (guidance, our wording)
  • Data processing agreements with privacy clauses
  • Periodic assessments of vendors' privacy compliance
NIST CSF 2.0 GV.SC-01 A cybersecurity supply chain risk management program, strategy, objectives, policies, and processes are established and agreed to by organizational stakeholders
Evidence to have on file (guidance, our wording)
  • Third party risk management program charter
  • Supplier risk policy with tiering criteria
NIST CSF 2.0 GV.SC-05 Requirements to address cybersecurity risks in supply chains are established, prioritized, and integrated into contracts and other types of agreements with suppliers and other relevant third parties
Evidence to have on file (guidance, our wording)
  • Standard supplier security requirements catalog
  • Contract clause library with cyber obligations
Application question (5) A protocol for confirming any vendor, client or customer account information change requests (including requests to change bank account numbers, contact information or mailing addresses) via direct call to that vendor, client or customer using only the telephone number provided by the vendor, client or customer before the change request was received?
Tokio Marine HCC held application question
ISO 27001:2022 A.5.19 Information security in supplier relationships
Evidence to have on file (guidance, our wording)
  • The topic-specific supplier relationship policy and its communication record
  • A supplier inventory categorized by type and by the information, services and infrastructure each can access
ISO 27001:2022 A.5.20 Addressing information security within supplier agreements
Evidence to have on file (guidance, our wording)
  • Supplier agreements containing security clauses proportionate to the relationship, such as classification mapping, agreed controls, incident notification, subcontracting, right to audit and termination terms
  • A register of contracts, memoranda and information-sharing arrangements with outside parties showing what information each covers and when it was last reviewed
ISO 27001:2022 A.5.21 Managing information security in the information and communication technology (ICT) supply chain
Evidence to have on file (guidance, our wording)
  • Security requirements included in ICT acquisition specifications and contracts, including flow-down to sub-suppliers
  • Software component information such as SBOMs and descriptions of security functions and secure configuration obtained from product suppliers
SOC 2 CC9.2 Assessing and managing vendor and business partner risk
Evidence to have on file (guidance, our wording)
  • Vendor inventory with risk tiers and the review frequency set for each tier
  • Due diligence records, for example vendor SOC reports reviewed with complementary controls noted
SOC 2 P6.4 Privacy commitments from vendors and third parties
Evidence to have on file (guidance, our wording)
  • Data processing agreements with privacy clauses
  • Periodic assessments of vendors' privacy compliance
NIST CSF 2.0 GV.SC-01 A cybersecurity supply chain risk management program, strategy, objectives, policies, and processes are established and agreed to by organizational stakeholders
Evidence to have on file (guidance, our wording)
  • Third party risk management program charter
  • Supplier risk policy with tiering criteria
NIST CSF 2.0 GV.SC-05 Requirements to address cybersecurity risks in supply chains are established, prioritized, and integrated into contracts and other types of agreements with suppliers and other relevant third parties
Evidence to have on file (guidance, our wording)
  • Standard supplier security requirements catalog
  • Contract clause library with cyber obligations
Application question In the past 3 years, has the Applicant or any other person or organization proposed for this insurance: (1) Received any complaints or written demands or been a subject in litigation involving matters of privacy injury, breach of private information, network security, defamation, content infringement, identity theft, denial of service attacks, computer virus infections, theft of information, damage to third party networks or the ability of third parties to rely on the Applicant's network?
Tokio Marine HCC held application question

This is a loss history question, not a control requirement. It reaches no held control.

No held control answers this line.

Application question (2) Been the subject of any government action, investigation or other proceedings regarding any alleged violation of privacy law or regulation?
Tokio Marine HCC held application question

This is a loss history question, not a control requirement. It reaches no held control.

No held control answers this line.

Application question (3) Notified customers, clients or any third party of any security breach or privacy breach?
Tokio Marine HCC held application question

This is a loss history question, not a control requirement. It reaches no held control.

No held control answers this line.

Application question (4) Received any cyber extortion demand or threat?
Tokio Marine HCC held application question

This is a loss history question, not a control requirement. It reaches no held control.

No held control answers this line.

Application question (5) Sustained any unscheduled network outage or interruption for any reason?
Tokio Marine HCC held application question

This is a loss history question, not a control requirement. It reaches no held control.

No held control answers this line.

Application question (6) Sustained any property damage or business interruption losses as a result of a cyber-attack?
Tokio Marine HCC held application question

This is a loss history question, not a control requirement. It reaches no held control.

No held control answers this line.

Application question (7) Sustained any losses due to wire transfer fraud, telecommunications fraud or phishing fraud?
Tokio Marine HCC held application question

This is a loss history question, not a control requirement. It reaches no held control.

No held control answers this line.

Application question Do you or any other person or organization proposed for this insurance have knowledge of any security breach, privacy breach, privacy-related event or incident or allegations of breach of privacy that may give rise to a claim?
Tokio Marine HCC held application question

Prior-knowledge question. This asks whether the applicant knows of any circumstance that could give rise to a claim. A wrong answer here is the classic route to a prior-knowledge exclusion or rescission, so it is the highest-consequence line on the form, not a line to leave unread. It reaches no control by itself: it is about what the applicant knows, not a control to hold.

No held control answers this line.

Application question In the past 3 years, has any service provider with access to the Applicant's network or computer system(s) sustained an unscheduled network outage or interruption lasting longer than 4 hours?
Tokio Marine HCC held application question

This is a loss history question, not a control requirement. It reaches no held control.

No held control answers this line.

Application question If "Yes", did the Applicant experience an interruption in business as a result of such outage or interruption?
Tokio Marine HCC held application question

No held control answers this line.

Controls not asked in this held document (235)

None of this held document's questions reach 235 of the 290 held controls (for example A.5.1, A.5.2, A.5.4, A.5.5, A.5.6, A.5.7, A.5.8, A.5.9). That is a fact about this held document, not about what the carrier underwrites on: a carrier's fuller forms and supplements ask controls this summary does not, multi-factor authentication, offline backups and patching among them. A control here is not asserted as required, and not asserted as not required.