The coverage island: the controls the held carrier documents ask
Every held carrier question is mapped to the ISO 27001:2022 controls, the SOC 2 criteria and the NIST CSF 2.0 outcomes it reaches. The controls below are ranked by how many held carriers ask them, then by how many questions reach them. Each row carries the source questions that put it there, so no control is shown as asked that a held question does not ask. 23 carriers held (Coalition, Chubb, CFC Underwriting, Beazley, Hiscox, AmTrust, Great American Insurance Group, Tokio Marine HCC, AXIS Insurance, Travelers, RLI, Corvus Insurance, Cowbell Cyber, At-Bay, QBE, The Hanover Insurance Group, The Hartford, CNA, Encore Fiduciary, Everest Insurance, RSA, Munich Re, Hiscox UK); as carriers are added, this ranking is by carrier count. 836 questions held in total, 97 flagged knockout.
| Control | Framework | Carriers | Source questions that ask it |
|---|---|---|---|
| A1.2 Environmental protection, backup and recovery infrastructure | SOC 2 | 21 | "Does Named Insured have procedures to back up, archive, and restore sensitive data and critical business systems?" (Coalition) "Business Interruption (Only if applying for this coverage) Are system backup and recovery procedures implemented, documented and tested at least annually for all mission-critical systems?" (Chubb) "If the Applicant's customer is primarily dependent on the product or service provided by the Applicant, does the Applicant have a contingency plan in place to address this exposure?" (Chubb) "Do you regularly back up your business critical data?" (Beazley) "If you rely on a cloud-based backup service, is it a "syncing service"?" (Beazley) "Do you have a Business Continuity or Disaster Recovery Plan in place that covers cyber event scenarios, such as ransomware attacks?" (Hiscox) "If Yes, is this Plan regularly tested?" (Hiscox) "If you suffer a network disruption, how long would it take to become fully operational?" (Hiscox) "Please specify how often you back-up all of your critical data and systems?" (Hiscox) "please indicate frequency) Never Is the back-up disconnected from your systems?" (Hiscox) "If Yes, is the back-up regularly tested?" (Hiscox) "If you have a back-up of all of your critical data and systems, does that include an offline copy?" (Hiscox) "If Yes, how old is the back-up?" (Hiscox) "Do you utilize cloud back-ups?" (Hiscox) "If Yes, are the cloud back-ups secured via two-factor authentication or other similar means?" (Hiscox) "Are tapes or other portable media containing backup materials encrypted?" (AmTrust) "Do you backup all mission critical systems and data?" (Great American Insurance Group) "How frequently do you back up?" (Great American Insurance Group) "o Daily/nightly o Weekly o Less frequently than weekly Which of the following back-up solutions do you employ?" (Great American Insurance Group) "How quickly can you restore from back-ups?" (Great American Insurance Group) "Are back-up restoration plans tested?" (Great American Insurance Group) "How frequently do you test your ability to restore from back-ups?" (Great American Insurance Group) "Do you use a data backup solution for all critical data?" (Tokio Marine HCC) "Daily Weekly Monthly (2) Which of the following best describes your data backup solution?" (Tokio Marine HCC) "Local backup Network drive Tape backup Off-site storage Cloud backup Other: (3) Please list your data backup provider: (4) Is your data backup solution: (a) physically disconnected from your network?" (Tokio Marine HCC) "(5) How long do you expect it to take to recover from backups in the event of a widespread malware or ransomware attack within your network?" (Tokio Marine HCC) "Does the Applicant have a written business continuity plan?" (AXIS Insurance) "How frequently is this plan tested?" (AXIS Insurance) "Does the Applicant have a written disaster recovery plan?" (AXIS Insurance) "Are copies of the business continuity/disaster recovery and incident response plans stored so that they will be accessible if the Applicant's network became completely unavailable?" (AXIS Insurance) "Does the Applicant conduct regular backup of data?" (AXIS Insurance) "Is Critical Information backed up at least?" (AXIS Insurance) "Which of the following does the Applicant utilize Tapes Disks Cloud for backups?" (AXIS Insurance) "Where are backups stored?" (AXIS Insurance) "Are backups subject to the following measures?" (AXIS Insurance) "Is full recovery from a backup tested at least annually?" (AXIS Insurance) "In the event of an interruption of the Applicant's network, at most how long is the Applicant's recovery time objective (RTO) for critical systems, applications, and processes?" (AXIS Insurance) "Backup and recovery procedures in place for all important business and customer data If Yes, are such procedures automated?" (Travelers) "If Yes, are such procedures tested on an annual basis?" (Travelers) "Are all plans indicated above tested regularly with any critical deficiencies remediated?" (Travelers) "Based upon testing results, how long does it take to restore the Applicant's critical business operations following a network or systems interruption?" (Travelers) "Do you have a backup solution?" (Corvus Insurance) "If "Yes", how frequently do you back up systems and data?" (Corvus Insurance) "Which of the following are in place for your backup solution(s?" (Corvus Insurance) "Do you have a Business Continuity Plan (BCP) or Disaster Recovery Plan (DRP) in place?" (Corvus Insurance) "How often does the organization perform backups of business-critical data?" (Cowbell Cyber) "Does the organization have an incident response plan - tested and in-effect - setting forth specific action items and responsibilities for relevant parties in the event of a cyber incident or data breach matter?" (Cowbell Cyber) "Has the organization tested a full failover of the most critical servers?" (Cowbell Cyber) "Does the Applicant keep offline backups that are disconnected from its network or store backups with a cloud service provider?" (At-Bay) "Does the applicant perform full backups for databases, applications, endpoints, and servers (operating systems?" (QBE) "How often are full backups performed?" (QBE) "Are backups stored offline?" (QBE) "Is all backup data encrypted once replicated?" (QBE) "Where are backups stored?" (QBE) "What is the applicant's target recovery time objective (RTO) for critical systems?" (QBE) "Can backups only be accessed via an authentication mechanism (i.e., MFA/password vault/separate credentials or credential checkout?" (QBE) "If yes, how are the backups accessed and who can access them?" (QBE) "If no, how is the applicant protecting the backups?" (QBE) "Is virus/malware scanning used on the backups?" (QBE) "Are backups tested for vulnerabilities/malware prior to restoration?" (QBE) "How often are full network failover tests conducted?" (QBE) "back-ups of critical Data and Computer Systems If either 2.a. or 2.b. has been selected is one copy stored on-line?" (The Hanover Insurance Group) "at rest While electronically in transit While on mobile devices Backups & Recovery Is your business' critical data regularly backed up?" (The Hartford) "weekly Yes, monthly If yes, are backups stored offline and/or isolated from production systems?" (The Hartford) "And, how often do the applicants test recovering data from the backup?" (The Hartford) "Do all applicants have a Cyber Incident Response Plan or Business Continuity plan in place to respond to a computer system disruption?" (The Hartford) "If yes, how often is the Cyber Incident Response or Business Continuity plan tested?" (The Hartford) "Do you back-up your network data and configuration files daily and store back-up files in a secure location, and rehearse your procedure for restoring from back-ups at least yearly?" (CNA) "Do you use a data backup solution?" (Encore Fiduciary) "Which best describes your data backup solution?" (Encore Fiduciary) "How frequently are backups run?" (Encore Fiduciary) "Does the Applicant have documented business continuity and disaster recovery plans?" (Everest Insurance) "Does the Applicant maintain redundant backups of sensitive and critical system information?" (Everest Insurance) "If "Yes", is there at least one backup destination that is maintained offline?" (Everest Insurance) "on enterprise assets (e.g., databases, file shares, backups?" (Everest Insurance) "You back up Your Critical Data at least weekly to a different location?" (RSA) "The backup of Your Critical Data is stored in a secure locked location with access restricted to authorised personnel only?" (RSA) "have a Business Continuity Plan or Disaster Response plan which includes Cyber perils?" (RSA) "How quickly can you obtain backups of Critical Data?" (RSA) "How long would it take You to fully restore from your backup?" (RSA) "How are your backups stored?" (Munich Re) "Are unique backup credentials stored separately from other user credentials?" (Munich Re) "Are backup processes tested to ensure data can be restored with minimal impact to the business?" (Munich Re) "Do you have a written business continuity or disaster recovery plan that addresses network outages & cyber-attacks?" (Munich Re) "What is your Recovery Time Objective (RTO) for critical systems?" (Munich Re) "Do you have a defined Recovery Point Objective (RPO) for critical systems?" (Munich Re) "Have you planned for redundancy for your critical system infrastructure?" (Munich Re) "Do you conduct redundancy testing at least annually to ensure that failover works as intended?" (Munich Re) "Are full system backups taken at least weekly and stored either off site or disconnected from your network?" (Hiscox UK) |
| A.8.14 Redundancy of information processing facilities | ISO 27001:2022 | 21 | "Does Named Insured have procedures to back up, archive, and restore sensitive data and critical business systems?" (Coalition) "Business Interruption (Only if applying for this coverage) Are system backup and recovery procedures implemented, documented and tested at least annually for all mission-critical systems?" (Chubb) "If the Applicant's customer is primarily dependent on the product or service provided by the Applicant, does the Applicant have a contingency plan in place to address this exposure?" (Chubb) "Do you regularly back up your business critical data?" (Beazley) "If you rely on a cloud-based backup service, is it a "syncing service"?" (Beazley) "Do you have a Business Continuity or Disaster Recovery Plan in place that covers cyber event scenarios, such as ransomware attacks?" (Hiscox) "If Yes, is this Plan regularly tested?" (Hiscox) "If you suffer a network disruption, how long would it take to become fully operational?" (Hiscox) "Please specify how often you back-up all of your critical data and systems?" (Hiscox) "please indicate frequency) Never Is the back-up disconnected from your systems?" (Hiscox) "If Yes, is the back-up regularly tested?" (Hiscox) "If you have a back-up of all of your critical data and systems, does that include an offline copy?" (Hiscox) "If Yes, how old is the back-up?" (Hiscox) "Do you utilize cloud back-ups?" (Hiscox) "Are tapes or other portable media containing backup materials encrypted?" (AmTrust) "Do you backup all mission critical systems and data?" (Great American Insurance Group) "How frequently do you back up?" (Great American Insurance Group) "o Daily/nightly o Weekly o Less frequently than weekly Which of the following back-up solutions do you employ?" (Great American Insurance Group) "How quickly can you restore from back-ups?" (Great American Insurance Group) "Are back-up restoration plans tested?" (Great American Insurance Group) "How frequently do you test your ability to restore from back-ups?" (Great American Insurance Group) "Do you use a data backup solution for all critical data?" (Tokio Marine HCC) "Daily Weekly Monthly (2) Which of the following best describes your data backup solution?" (Tokio Marine HCC) "Local backup Network drive Tape backup Off-site storage Cloud backup Other: (3) Please list your data backup provider: (4) Is your data backup solution: (a) physically disconnected from your network?" (Tokio Marine HCC) "(5) How long do you expect it to take to recover from backups in the event of a widespread malware or ransomware attack within your network?" (Tokio Marine HCC) "Does the Applicant have a written business continuity plan?" (AXIS Insurance) "How frequently is this plan tested?" (AXIS Insurance) "Does the Applicant have a written disaster recovery plan?" (AXIS Insurance) "Are copies of the business continuity/disaster recovery and incident response plans stored so that they will be accessible if the Applicant's network became completely unavailable?" (AXIS Insurance) "Does the Applicant conduct regular backup of data?" (AXIS Insurance) "Is Critical Information backed up at least?" (AXIS Insurance) "Which of the following does the Applicant utilize Tapes Disks Cloud for backups?" (AXIS Insurance) "Where are backups stored?" (AXIS Insurance) "Are backups subject to the following measures?" (AXIS Insurance) "Is full recovery from a backup tested at least annually?" (AXIS Insurance) "In the event of an interruption of the Applicant's network, at most how long is the Applicant's recovery time objective (RTO) for critical systems, applications, and processes?" (AXIS Insurance) "Backup and recovery procedures in place for all important business and customer data If Yes, are such procedures automated?" (Travelers) "If Yes, are such procedures tested on an annual basis?" (Travelers) "Are all plans indicated above tested regularly with any critical deficiencies remediated?" (Travelers) "Based upon testing results, how long does it take to restore the Applicant's critical business operations following a network or systems interruption?" (Travelers) "Do you have a backup solution?" (Corvus Insurance) "If "Yes", how frequently do you back up systems and data?" (Corvus Insurance) "Which of the following are in place for your backup solution(s?" (Corvus Insurance) "Do you have a Business Continuity Plan (BCP) or Disaster Recovery Plan (DRP) in place?" (Corvus Insurance) "How often does the organization perform backups of business-critical data?" (Cowbell Cyber) "Does the organization have an incident response plan - tested and in-effect - setting forth specific action items and responsibilities for relevant parties in the event of a cyber incident or data breach matter?" (Cowbell Cyber) "Has the organization tested a full failover of the most critical servers?" (Cowbell Cyber) "Does the Applicant keep offline backups that are disconnected from its network or store backups with a cloud service provider?" (At-Bay) "Does the applicant perform full backups for databases, applications, endpoints, and servers (operating systems?" (QBE) "How often are full backups performed?" (QBE) "Are backups stored offline?" (QBE) "Is all backup data encrypted once replicated?" (QBE) "Where are backups stored?" (QBE) "What is the applicant's target recovery time objective (RTO) for critical systems?" (QBE) "If yes, how are the backups accessed and who can access them?" (QBE) "If no, how is the applicant protecting the backups?" (QBE) "Is virus/malware scanning used on the backups?" (QBE) "Are backups tested for vulnerabilities/malware prior to restoration?" (QBE) "How often are full network failover tests conducted?" (QBE) "back-ups of critical Data and Computer Systems If either 2.a. or 2.b. has been selected is one copy stored on-line?" (The Hanover Insurance Group) "weekly Yes, monthly If yes, are backups stored offline and/or isolated from production systems?" (The Hartford) "And, how often do the applicants test recovering data from the backup?" (The Hartford) "Do all applicants have a Cyber Incident Response Plan or Business Continuity plan in place to respond to a computer system disruption?" (The Hartford) "If yes, how often is the Cyber Incident Response or Business Continuity plan tested?" (The Hartford) "Do you back-up your network data and configuration files daily and store back-up files in a secure location, and rehearse your procedure for restoring from back-ups at least yearly?" (CNA) "Do you use a data backup solution?" (Encore Fiduciary) "Which best describes your data backup solution?" (Encore Fiduciary) "How frequently are backups run?" (Encore Fiduciary) "Does the Applicant have documented business continuity and disaster recovery plans?" (Everest Insurance) "Does the Applicant maintain redundant backups of sensitive and critical system information?" (Everest Insurance) "If "Yes", is there at least one backup destination that is maintained offline?" (Everest Insurance) "on enterprise assets (e.g., databases, file shares, backups?" (Everest Insurance) "You back up Your Critical Data at least weekly to a different location?" (RSA) "The backup of Your Critical Data is stored in a secure locked location with access restricted to authorised personnel only?" (RSA) "have a Business Continuity Plan or Disaster Response plan which includes Cyber perils?" (RSA) "How quickly can you obtain backups of Critical Data?" (RSA) "How long would it take You to fully restore from your backup?" (RSA) "How are your backups stored?" (Munich Re) "Are backup processes tested to ensure data can be restored with minimal impact to the business?" (Munich Re) "Do you have a written business continuity or disaster recovery plan that addresses network outages & cyber-attacks?" (Munich Re) "What is your Recovery Time Objective (RTO) for critical systems?" (Munich Re) "Do you have a defined Recovery Point Objective (RPO) for critical systems?" (Munich Re) "Have you planned for redundancy for your critical system infrastructure?" (Munich Re) "Do you conduct redundancy testing at least annually to ensure that failover works as intended?" (Munich Re) "Are full system backups taken at least weekly and stored either off site or disconnected from your network?" (Hiscox UK) |
| A.8.13 Information backup | ISO 27001:2022 | 21 | "Does Named Insured have procedures to back up, archive, and restore sensitive data and critical business systems?" (Coalition) "Business Interruption (Only if applying for this coverage) Are system backup and recovery procedures implemented, documented and tested at least annually for all mission-critical systems?" (Chubb) "Do you regularly back up your business critical data?" (Beazley) "If you rely on a cloud-based backup service, is it a "syncing service"?" (Beazley) "Please specify how often you back-up all of your critical data and systems?" (Hiscox) "please indicate frequency) Never Is the back-up disconnected from your systems?" (Hiscox) "If Yes, is the back-up regularly tested?" (Hiscox) "If you have a back-up of all of your critical data and systems, does that include an offline copy?" (Hiscox) "If Yes, how old is the back-up?" (Hiscox) "Do you utilize cloud back-ups?" (Hiscox) "If Yes, are the cloud back-ups secured via two-factor authentication or other similar means?" (Hiscox) "Are tapes or other portable media containing backup materials encrypted?" (AmTrust) "Do you backup all mission critical systems and data?" (Great American Insurance Group) "How frequently do you back up?" (Great American Insurance Group) "o Daily/nightly o Weekly o Less frequently than weekly Which of the following back-up solutions do you employ?" (Great American Insurance Group) "How quickly can you restore from back-ups?" (Great American Insurance Group) "Are back-up restoration plans tested?" (Great American Insurance Group) "How frequently do you test your ability to restore from back-ups?" (Great American Insurance Group) "Do you use a data backup solution for all critical data?" (Tokio Marine HCC) "Daily Weekly Monthly (2) Which of the following best describes your data backup solution?" (Tokio Marine HCC) "Local backup Network drive Tape backup Off-site storage Cloud backup Other: (3) Please list your data backup provider: (4) Is your data backup solution: (a) physically disconnected from your network?" (Tokio Marine HCC) "(5) How long do you expect it to take to recover from backups in the event of a widespread malware or ransomware attack within your network?" (Tokio Marine HCC) "Does the Applicant conduct regular backup of data?" (AXIS Insurance) "Is Critical Information backed up at least?" (AXIS Insurance) "Which of the following does the Applicant utilize Tapes Disks Cloud for backups?" (AXIS Insurance) "Where are backups stored?" (AXIS Insurance) "Are backups subject to the following measures?" (AXIS Insurance) "Is full recovery from a backup tested at least annually?" (AXIS Insurance) "Backup and recovery procedures in place for all important business and customer data If Yes, are such procedures automated?" (Travelers) "Based upon testing results, how long does it take to restore the Applicant's critical business operations following a network or systems interruption?" (Travelers) "Do you have a backup solution?" (Corvus Insurance) "If "Yes", how frequently do you back up systems and data?" (Corvus Insurance) "Which of the following are in place for your backup solution(s?" (Corvus Insurance) "How often does the organization perform backups of business-critical data?" (Cowbell Cyber) "Does the Applicant keep offline backups that are disconnected from its network or store backups with a cloud service provider?" (At-Bay) "Does the applicant perform full backups for databases, applications, endpoints, and servers (operating systems?" (QBE) "How often are full backups performed?" (QBE) "Are backups stored offline?" (QBE) "Is all backup data encrypted once replicated?" (QBE) "Where are backups stored?" (QBE) "Can backups only be accessed via an authentication mechanism (i.e., MFA/password vault/separate credentials or credential checkout?" (QBE) "If yes, how are the backups accessed and who can access them?" (QBE) "If no, how is the applicant protecting the backups?" (QBE) "Is virus/malware scanning used on the backups?" (QBE) "Are backups tested for vulnerabilities/malware prior to restoration?" (QBE) "back-ups of critical Data and Computer Systems If either 2.a. or 2.b. has been selected is one copy stored on-line?" (The Hanover Insurance Group) "at rest While electronically in transit While on mobile devices Backups & Recovery Is your business' critical data regularly backed up?" (The Hartford) "weekly Yes, monthly If yes, are backups stored offline and/or isolated from production systems?" (The Hartford) "And, how often do the applicants test recovering data from the backup?" (The Hartford) "Do you back-up your network data and configuration files daily and store back-up files in a secure location, and rehearse your procedure for restoring from back-ups at least yearly?" (CNA) "Do you use a data backup solution?" (Encore Fiduciary) "Which best describes your data backup solution?" (Encore Fiduciary) "How frequently are backups run?" (Encore Fiduciary) "Does the Applicant maintain redundant backups of sensitive and critical system information?" (Everest Insurance) "If "Yes", is there at least one backup destination that is maintained offline?" (Everest Insurance) "on enterprise assets (e.g., databases, file shares, backups?" (Everest Insurance) "You back up Your Critical Data at least weekly to a different location?" (RSA) "The backup of Your Critical Data is stored in a secure locked location with access restricted to authorised personnel only?" (RSA) "How quickly can you obtain backups of Critical Data?" (RSA) "How long would it take You to fully restore from your backup?" (RSA) "How are your backups stored?" (Munich Re) "Are unique backup credentials stored separately from other user credentials?" (Munich Re) "Are backup processes tested to ensure data can be restored with minimal impact to the business?" (Munich Re) "Are full system backups taken at least weekly and stored either off site or disconnected from your network?" (Hiscox UK) |
| CC6.1 Logical access security over protected information assets | SOC 2 | 20 | "Does Named Insured enable disk encryption on laptops, desktops, and other portable media devices?" (Coalition) "Does the Applicant have third party software protecting its network (e.g. antivirus, encryption, firewalls, etc.?" (Chubb) "If Yes, do all of the Applicant's point-of-sale terminals accept chip-enabled cards?" (Chubb) "Do you require Multi-Factor Authentication (MFA) for remote access to your network (both cloud-hosted and on- premises, including via Virtual Private Networks (VPNs)?" (Beazley) "Do you require MFA for access to web-based email?" (Beazley) "Is this information encrypted while at rest?" (Hiscox) "If No, is such information stored on a segregated server with role-based access controls?" (Hiscox) "Is this information encrypted while in transit?" (Hiscox) "Is this information stored on mobile computing devices, including laptops or smart phones?" (Hiscox) "If Yes, are such devices encrypted?" (Hiscox) "PCI DSS v.3.2 (Payment Card Industry Data Security Standard?" (Hiscox) "in place with all third parties that have access to sensitive information, including business associate agreements?" (Hiscox) "in place that scan both encrypted and unencrypted data to restrict network traffic?" (Hiscox) "A policy that requires strong passwords that should be updated on a regular basis?" (Hiscox) "Employee access to systems and data is limited to only what they need to do their job?" (Hiscox) "Employee access to systems and data is cut when employees leave the organization?" (Hiscox) "Multi-factor authentication in place for remote access by employees?" (Hiscox) "Multi-factor authentication in place for remote access by third parties?" (Hiscox) "If Yes, are the cloud back-ups secured via two-factor authentication or other similar means?" (Hiscox) "If Yes, do you encrypt this data?" (Hiscox) "Do you host sensitive data belonging to your clients' customers?" (Hiscox) "Does the Applicant terminate all computer access and user accounts as part of the regular exit process when an employee leaves the company or when a third party contractor no longer provides the contracted services?" (AmTrust) "Does the Applicant accept credit cards for goods sold or services rendered?" (AmTrust) "Does the Applicant have and enforce policies concerning the encryption of internal and external communication?" (AmTrust) "Are users able to store data to the hard drive of portable computers or portable media devices such as USB drives?" (AmTrust) "Does the Applicant encrypt data stored on laptop computers and portable media?" (AmTrust) "Are tapes or other portable media containing backup materials encrypted?" (AmTrust) "Which controls are in place to protect confidential, sensitive, or otherwise regulated data?" (Great American Insurance Group) "Password/passcode protected Encryption Traditional or next generation firewalls enabled/turned on Traditional or next generation antivirus products on all endpoints Endpoint Detection and Response (EDR) 24/7/365 on all devices If yes to EDR, Who is your provider?" (Great American Insurance Group) "Is multi factor authentication (MFA) to access Email required?" (Great American Insurance Group) "Is multi factor authentication (MFA) for personal devices required?" (Great American Insurance Group) "Is multifactor authentication (MFA) required to remotely connect to the network, all critical internet facing systems and privilege accounts?" (Great American Insurance Group) "Are firewalls configured according to the principles of least privileges?" (Great American Insurance Group) "Do you encrypt all sensitive and confidential information stored on your organization's systems and networks?" (Tokio Marine HCC) "(2) Access control with role-based assignments?" (Tokio Marine HCC) "Do you process, store, or handle credit card transactions?" (Tokio Marine HCC) "If "Yes": (1) Do you use 2-factor authentication to secure all remote access to your network?" (Tokio Marine HCC) "If "No", is RDP and/or RDG protected by two-factor authentication?" (Tokio Marine HCC) "Do you use 2-factor authentication to secure all domain or network administrator accounts?" (Tokio Marine HCC) "Do you use 2-factor authentication to secure remote access to your email accounts?" (Tokio Marine HCC) "(b) segregated with 2-factor authentication access control?" (Tokio Marine HCC) "(3) A separation of authority protocol?" (Tokio Marine HCC) "Which version of PCI-DSS was the Applicant assessed against?" (AXIS Insurance) "Is Multi Factor Authentication used for access?" (AXIS Insurance) "If remote access is available, does the Applicant implement MFA for all remote access?" (AXIS Insurance) "Does the Applicant or its Managed Security Service Provider, if applicable, implement MFA for all administrator access?" (AXIS Insurance) "Does the Applicant employ mandatory encryption to protect the following?" (AXIS Insurance) "Does the applicant encrypt all physical devices, critical data, sensitive emails?" (RLI) "Which of the of the following apply to your Multi-Factor Authentication (MFA) implementation?" (Corvus Insurance) "How are privileged accounts secured and managed?" (Corvus Insurance) "What security controls are in place to protect against unauthorized access to sensitive and confidential data?" (Corvus Insurance) "Do you enforce Multi-Factor Authentication (MFA) for all employees, contractors, and partners on the following?" (Cowbell Cyber) "Does the organization encrypt all external communications containing sensitive information?" (Cowbell Cyber) "Does the organization encrypt sensitive information stored on the cloud?" (Cowbell Cyber) "Does the Applicant store or process personal, health or credit card information of more than 500,000 individuals?" (At-Bay) "a. Do the applicant's privileged users require more extensive training relating to phishing attacks?" (QBE) "Is multifactor authentication (MFA) required for all internal, external, and vendor access to the applicant's network?" (QBE) "Do these users require additional credentials to access?" (QBE) "Does the applicant utilize a Privileged Access Management (PAM) solution?" (QBE) "If not utilizing a PAM solution, what compensating controls exist to protect privileged accounts?" (QBE) "Does the applicant restrict Local Admin rights?" (QBE) "What is the minimum length for passwords?" (QBE) "If yes, does the applicant require strong authentication (e.g., two factor/ MFA?" (QBE) "Is all backup data encrypted once replicated?" (QBE) "Can backups only be accessed via an authentication mechanism (i.e., MFA/password vault/separate credentials or credential checkout?" (QBE) "Does the applicant have a policy that all portable devices use full disk encryption?" (QBE) "Where does the applicant use encryption?" (QBE) "How often does the applicant use encryption?" (QBE) "Security & Controls MFA Is Multi-Factor Authentication (MFA) required for ALL remote access to your business' network?" (The Hartford) "Is MFA required for access to email?" (The Hartford) "Have you identified the paper, electronic, and other records, computing systems, and storage media including laptops, mobile phones, and portable devices that contain sensitive information?" (CNA) "Do you set up a separate account for each user (including any contractors needing access?" (CNA) "Do you enforce a strong/complex password policy of at least 8-20 characters?" (CNA) "Do you physically and electronically limit access to sensitive information on a need –to-know basis and revoke access privileges upon a reduction in an individual's need to know?" (CNA) "Information Security and Cyber Infrastructure Self-Assessment 14 On your wireless networks; do you use security at least as strong as WPA2 authentication and encryption, and do you require two factor authentication (access token and password/account logon) before allowing wireless connections to your network?" (CNA) "if you do not use wireless networks.) 15 Do you require multi-factor authorization when your network is accessed remotely and/or when cloud resources are utilized?" (CNA) "Do you encrypt all sensitive records and files that are held at rest and/or transmitted across public networks, and that are to be transmitted wirelessly?" (CNA) "Do you physically and electronically limit access to sensitive information on a need-to-know basis and revoke access privileges upon a reduction in an individual's need to know?" (CNA) "On your wireless networks; do you use security at least as strong as WPA2 authentication and encryption, and do you require two factor authentication (access token and password/account logon) before allowing wireless connections to your network?" (CNA) "Do you require multi-factor authorization when your network is accessed remotely and/or when cloud resources are utilized?" (CNA) "Do you process, store or handle credit card transactions?" (Encore Fiduciary) "Sender Policy Framework (SPF) Domain Keys Identified Mail (DKIM) Domain-based Message Authentication, Reporting & Conformance (DMARC) None of the above d.Can your users access email through a web application or a non-corporate device?" (Encore Fiduciary) "If "Yes", do you enforce Multi-Factor Authentication (MFA?" (Encore Fiduciary) "Do you encrypt all sensitive and confidential information stored on your organization's systems and networks?" (Encore Fiduciary) "(2) Access control with role-based assignments?" (Encore Fiduciary) "If "Yes", do you use MFA to secure all remote access to your network, including any remote desktop protocol (RDP) connections?" (Encore Fiduciary) "Encore Fiduciary Cyber Liability Application (2.2022) Page 2 of 10 If MFA is used, complete the following: (1) Provide the name of your MFA provider: (2) Describe your MFA type: (3) Does your MFA configuration ensure that the compromise of a single device will only compromise a single authenticator?" (Encore Fiduciary) "If "No", please use the Additional Comments section to outline which assets do not have EDR, and whether any mitigating safeguards are in place for such assets. (4) Can users access the network with their own device ("Bring Your Own Device"?" (Encore Fiduciary) "Do you use MFA to protect all local and remote access to privileged user accounts?" (Encore Fiduciary) "Do you manage privileged accounts using privileged account management software (PAM) (e.g., CyberArk, BeyondTrust, etc.?" (Encore Fiduciary) "If "Yes", complete the following: (1) Provide the name of your PAM software provider: (2) Is access protected by MFA?" (Encore Fiduciary) "Do you actively monitor all administrator access for unusual behavior patterns?" (Encore Fiduciary) "Do you roll out a hardened baseline configuration across servers, laptops, desktops and managed mobile devices?" (Encore Fiduciary) "Do you record and track all software and hardware assets deployed across your organization?" (Encore Fiduciary) "Do non-IT users have local administration rights on their laptop / desktop?" (Encore Fiduciary) "(3) A separation of authority protocol?" (Encore Fiduciary) "Does the Applicant have a continuous monitoring program to detect and maintain an inventory of all hardware and software on to its network?" (Everest Insurance) "Does the Applicant use multi-factor authentication for access to critical applications or databases (including those that contain personally identifiable information, private health information or payment card information?" (Everest Insurance) "Does the Applicant restrict access based on job function and responsibilities?" (Everest Insurance) "Does the Applicant enforce password changes every 8-12 weeks?" (Everest Insurance) "on mobile assets (e.g., laptops, phones, tablets, flash drives?" (Everest Insurance) "Are all terminals EMV enabled?" (Everest Insurance) "Are the POS and corporate networks segregated?" (Everest Insurance) "Is access to the internet from terminals restricted for employees?" (Everest Insurance) "You secure remote access (access control procedures to prevent unauthorised access) to Your network and Your data?" (RSA) "You enforce a policy of auditing of managing computer and user accounts?" (RSA) "Do you perform background checks on employees & contractors who have access to sensitive information?" (Munich Re) "Do you terminate user access rights as part of the employee exit process?" (Munich Re) "If you inventory hardware and/or software assets, do you have an asset classification policy that is enforced?" (Munich Re) "Are all mobile devices managed using a Mobile Device Management (MDM) solution?" (Munich Re) "Do you disable media ports or restrict usage to only encrypted removable storage devices?" (Munich Re) "Do you allow employees to use personal mobile devices to access company data (e.g. email?" (Munich Re) "If Yes, do you have a Bring Your Own Device (BYOD) policy in place that governs usage and controls?" (Munich Re) "Do you restrict user access (employees, contractors etc.) on a business need-to-know & least-privilege basis?" (Munich Re) "Do you have a central Identity & Access Management ("IAM") system for assigning and revoking access rights?" (Munich Re) "Do you have a formal process in place for assigning and revoking user accounts and access rights?" (Munich Re) "Do assets owners review access rights at least annually?" (Munich Re) "If Yes, which of the following accounts are enrolled into the PAM tool?" (Munich Re) "Which of the following features are enabled on the PAM tool?" (Munich Re) "Is logging and alerting configured for all privileged account activity?" (Munich Re) "Are domain admin accounts limited to administrative functions only?" (Munich Re) "Please provide the number of service accounts in the domain admin group?" (Munich Re) "Do you configure service accounts using the principle of least privilege?" (Munich Re) "Do you configure service accounts to deny interactive log-ins?" (Munich Re) "Do you log the activity of service accounts that are able to override system or application controls (e.g. elevation Yes No of privileges, lateral movement etc.?" (Munich Re) "Do you prohibit local admin rights on workstations for users?" (Munich Re) "Do you enforce the use of encryption over all external communication lines (e.g. website, email, wireless?" (Munich Re) "Do you enforce the use of encryption of sensitive information while at rest (e.g. on premise, mobile device, Yes No cloud?" (Munich Re) "Are unique backup credentials stored separately from other user credentials?" (Munich Re) "Is web-based email available to employees?" (Munich Re) "Is multi-factor authentication (MFA) in place for web-based email logins?" (Munich Re) "Do you identify & categorise third party vendors based on their access to company systems and/or data?" (Munich Re) "Do you periodically review and update vendor access rights?" (Munich Re) "Do you accept card payments for goods and/or services?" (Munich Re) "How do you process payment card transactions?" (Munich Re) "Do you store payment card data on your network?" (Munich Re) "If Yes, is payment card data either encrypted or tokenised at all times?" (Munich Re) "Do you comply with the relevant Payment Card Industry Data Security Standard?" (Munich Re) "Has the payment processor provided you with evidence of its PCI DSS compliance?" (Munich Re) "Do you have a formal password policy that explains good password hygiene, such as not using obvious or repeated passwords, for all systems providing access to personal or confidential information?" (Hiscox UK) "Do you have a policy to encrypt mobile computing devices (for example laptops, tablets, mobile telephones, PDAs) and portable data storage media (for example external drives or magnetic tapes) which hold, process, transact or store any of the personal data referred to in 1.7?" (Hiscox UK) "Do all users with remote access provide at least two different forms of identification ('multi-factor authentication') to verify their identity prior to log-in?" (Hiscox UK) "Do you require multi-factor authentication for all online banking logins?" (Hiscox UK) "Do you ensure multi-factor authentication for any fund transfer?" (Hiscox UK) |
| PR.DS-01 The confidentiality, integrity, and availability of data-at-rest are protected | NIST CSF 2.0 | 20 | "Does Named Insured enable disk encryption on laptops, desktops, and other portable media devices?" (Coalition) "Does Named Insured accept credit cards or collect Personally Identifiable Information (PII) or Protected Health Information (PHI) from its customers?" (Coalition) "Does the Applicant have third party software protecting its network (e.g. antivirus, encryption, firewalls, etc.?" (Chubb) "If Yes, do all of the Applicant's point-of-sale terminals accept chip-enabled cards?" (Chubb) "Is this information encrypted while at rest?" (Hiscox) "Is this information encrypted while in transit?" (Hiscox) "Is this information stored on mobile computing devices, including laptops or smart phones?" (Hiscox) "If Yes, are such devices encrypted?" (Hiscox) "PCI DSS v.3.2 (Payment Card Industry Data Security Standard?" (Hiscox) "GDPR (EU General Data Protection Regulation?" (Hiscox) "HIPAA (Health Insurance Portability and Accountability Act?" (Hiscox) "CCPA (California Consumer Privacy Act?" (Hiscox) "BIPA (Biometric Information Privacy Act?" (Hiscox) "A written corporate privacy policy which is reviewed by a qualified lawyer and actively followed?" (Hiscox) "Formal policies and procedures around the retention, destruction, and purging of data?" (Hiscox) "in place that scan both encrypted and unencrypted data to restrict network traffic?" (Hiscox) "Obtaining consent from individuals when collecting Personally Identifiable Information?" (Hiscox) "If Yes, do you encrypt this data?" (Hiscox) "Do you host sensitive data belonging to your clients' customers?" (Hiscox) "Does the Applicant accept credit cards for goods sold or services rendered?" (AmTrust) "Does the Applicant have and enforce policies concerning the encryption of internal and external communication?" (AmTrust) "Are users able to store data to the hard drive of portable computers or portable media devices such as USB drives?" (AmTrust) "Does the Applicant encrypt data stored on laptop computers and portable media?" (AmTrust) "Are tapes or other portable media containing backup materials encrypted?" (AmTrust) "Which controls are in place to protect confidential, sensitive, or otherwise regulated data?" (Great American Insurance Group) "Does the applicant have a privacy policy in place published on the website?" (Great American Insurance Group) "Password/passcode protected Encryption Traditional or next generation firewalls enabled/turned on Traditional or next generation antivirus products on all endpoints Endpoint Detection and Response (EDR) 24/7/365 on all devices If yes to EDR, Who is your provider?" (Great American Insurance Group) "Are trackers, web beacons and/or pixels used on the Applicant's website?" (Great American Insurance Group) "If yes, is the data being collected in compliance with applicable data privacy laws – specific to consent of user?" (Great American Insurance Group) "If yes, is the data being collected limited to the minimum information necessary to accomplish its purpose and not be used or disclosed beyond what is legally permissible?" (Great American Insurance Group) "If "Yes", have you reviewed your policies relating to the collection, storage and destruction of such information or data with a qualified attorney and confirmed compliance with applicable federal, state, local and foreign laws?" (Tokio Marine HCC) "Do you encrypt all sensitive and confidential information stored on your organization's systems and networks?" (Tokio Marine HCC) "Do you process, store, or handle credit card transactions?" (Tokio Marine HCC) "Does the Applicant sell or share Personal Information?" (AXIS Insurance) "Does the Applicant store or process Personal Information on behalf of a third party?" (AXIS Insurance) "Which version of PCI-DSS was the Applicant assessed against?" (AXIS Insurance) "Does the Applicant have a written privacy policy or privacy notice reviewed by an attorney and updated at least annually?" (AXIS Insurance) "Does the Applicant have a written document retention policy?" (AXIS Insurance) "Do these policies enable the Applicant to identify all Personal Information subjected to the following activities during the last 12 months?" (AXIS Insurance) "Do these policies enable the Applicant to identify the source(s) from which Personal Information was collected, sold or shared?" (AXIS Insurance) "Do these policies enable the Applicant to identify the business purpose(s) for which Personal Information was collected, sold or shared?" (AXIS Insurance) "Does the Applicant employ mandatory encryption to protect the following?" (AXIS Insurance) "Are any of the Applicant's products or services used in the collection, use, processing, sharing, sale, profit from, possession, retention and destruction of Biometric Information?" (AXIS Insurance) "Is the Applicant a Healthcare Provider, Business Associate, or Covered Entity under HIPAA?" (Travelers) "If Yes, is the Applicant HIPAA compliant?" (Travelers) "Is the Applicant subject to the General Data Protection Regulation (GDPR?" (Travelers) "Does the applicant encrypt all physical devices, critical data, sensitive emails?" (RLI) "Does the Applicant collect, capture, purchase, receive through trade, or otherwise obtain biometric data (biometric data is data related to body measurements and calculations related to human characteristics and includes, but is not limited to, fingerprints, iris or retina scans, voiceprints, sleep/health/exercise data, DNA or biological markers?" (Corvus Insurance) "What security controls are in place to protect against unauthorized access to sensitive and confidential data?" (Corvus Insurance) "Does the organization encrypt all external communications containing sensitive information?" (Cowbell Cyber) "Does the organization encrypt sensitive information stored on the cloud?" (Cowbell Cyber) "Does the Applicant store or process personal, health or credit card information of more than 500,000 individuals?" (At-Bay) "Is all backup data encrypted once replicated?" (QBE) "Does the applicant have a policy that all portable devices use full disk encryption?" (QBE) "Where does the applicant use encryption?" (QBE) "How often does the applicant use encryption?" (QBE) "If user inf ormation is collected, the user has the option to opt-in or opt-out of allowing the collection or use of their information?" (The Hanover Insurance Group) "If Personal Information gathered from customers is sold, the Applicant notifies and obtains consent prior to dissemination of such information?" (The Hanover Insurance Group) "Have you identified the paper, electronic, and other records, computing systems, and storage media including laptops, mobile phones, and portable devices that contain sensitive information?" (CNA) "Do you encrypt all sensitive records and files that are held at rest and/or transmitted across public networks, and that are to be transmitted wirelessly?" (CNA) "If "Yes", have you reviewed your policies relating to the collection, storage and destruction of such information or data with a qualified attorney and confirmed compliance with applicable federal, state, local and foreign laws?" (Encore Fiduciary) "Do you process, store or handle credit card transactions?" (Encore Fiduciary) "Do you encrypt all sensitive and confidential information stored on your organization's systems and networks?" (Encore Fiduciary) "Does the Applicant's privacy policy allow for the sharing of Confidential Information with third parties?" (Everest Insurance) "Personally Identifiable Information (PII) (non-public information such as social security numbers, driver's licenses, phone numbers, and email addresses?" (Everest Insurance) "Private Health Information (PHI) (e.g., healthcare or medical records?" (Everest Insurance) "Payment Card Information (PCI) (e.g., credit card, debit card numbers or other financial account numbers?" (Everest Insurance) "on mobile assets (e.g., laptops, phones, tablets, flash drives?" (Everest Insurance) "Are all terminals EMV enabled?" (Everest Insurance) "Are the POS and corporate networks segregated?" (Everest Insurance) "Has the Applicant's privacy policy, terms of use, terms of service, and other customer policies been review by an outside counsel?" (Everest Insurance) "Do you have a written Privacy Policy that clearly discloses who You share Personal data with?" (RSA) "Do you have a written privacy policy that is reviewed (at least annually) by qualified legal counsel?" (Munich Re) "Do you share any personal data with third parties?" (Munich Re) "If Yes, do you have data sharing agreements in place with all third parties where personal data is shared?" (Munich Re) "Do you give data subjects the ability to opt-out of allowing personal data to be shared with third parties?" (Munich Re) "Do you have a process in place to respond to data subject requests (e.g. access requests, right to erasure) and Yes No complaints based on applicable data privacy regulations?" (Munich Re) "Are all mobile devices managed using a Mobile Device Management (MDM) solution?" (Munich Re) "Do you disable media ports or restrict usage to only encrypted removable storage devices?" (Munich Re) "Do you allow employees to use personal mobile devices to access company data (e.g. email?" (Munich Re) "If Yes, do you have a Bring Your Own Device (BYOD) policy in place that governs usage and controls?" (Munich Re) "Do you enforce the use of encryption over all external communication lines (e.g. website, email, wireless?" (Munich Re) "Do you enforce the use of encryption of sensitive information while at rest (e.g. on premise, mobile device, Yes No cloud?" (Munich Re) "Do you utilize a Data Loss Prevention (DLP) product for email?" (Munich Re) "Is a DLP solution in use on endpoints, external and internal (including email) servers?" (Munich Re) "Do you accept card payments for goods and/or services?" (Munich Re) "How do you process payment card transactions?" (Munich Re) "Do you store payment card data on your network?" (Munich Re) "If Yes, is payment card data either encrypted or tokenised at all times?" (Munich Re) "Do you comply with the relevant Payment Card Industry Data Security Standard?" (Munich Re) "Has the payment processor provided you with evidence of its PCI DSS compliance?" (Munich Re) "Do you clearly outline to individuals how any biometric information will be collected, used and/or destroyed?" (Munich Re) "Do you obtain written consent from individuals prior to collection, receipt or retention of biometric information?" (Munich Re) "Do you have a retention schedule outlining how long biometric information is retained?" (Munich Re) "Do you sell, lease, trade or otherwise profit from the biometric information of individuals?" (Munich Re) "Do you subject biometric data to any of the following measures?" (Munich Re) "Do you have a policy to encrypt mobile computing devices (for example laptops, tablets, mobile telephones, PDAs) and portable data storage media (for example external drives or magnetic tapes) which hold, process, transact or store any of the personal data referred to in 1.7?" (Hiscox UK) "Have you ever received a complaint relating to the handling of someone's personally identifiable information?" (Hiscox UK) |
| PR.AA-05 Access permissions, entitlements, and authorizations are defined in a policy, managed, enforced, and reviewed, and incorporate the principles of least privilege and separation of duties | NIST CSF 2.0 | 20 | "Does Named Insured require dual control when transferring funds in excess of $25,000?" (Coalition) "Cyber Crime (Only if applying for this coverage) Does the Applicant accept funds transfer information from clients over the telephone, email, text message or similar method of communication?" (Chubb) "Does the Applicant authenticate instructions by calling the customer at a predetermined phone number or require receipt of a customer identity code?" (Chubb) "Is approval by more than one person required to initiate a wire transfer?" (Chubb) "If No, is such information stored on a segregated server with role-based access controls?" (Hiscox) "in place with all third parties that have access to sensitive information, including business associate agreements?" (Hiscox) "Employee access to systems and data is limited to only what they need to do their job?" (Hiscox) "Employee access to systems and data is cut when employees leave the organization?" (Hiscox) "Before acting on a transfer, do you verify the request or account detail changes using a method other than the initial contact method (Example: the initial request is received by mail and verification is done by telephone?" (Hiscox) "c. a loss of money, securities, or property due to social engineering, fraud, or other criminal acts?" (Hiscox) "Does the Applicant terminate all computer access and user accounts as part of the regular exit process when an employee leaves the company or when a third party contractor no longer provides the contracted services?" (AmTrust) "Is multifactor authentication (MFA) required to remotely connect to the network, all critical internet facing systems and privilege accounts?" (Great American Insurance Group) "Are firewalls configured according to the principles of least privileges?" (Great American Insurance Group) "(2) Access control with role-based assignments?" (Tokio Marine HCC) "Do you use 2-factor authentication to secure all domain or network administrator accounts?" (Tokio Marine HCC) "Does your organization send and/or receive wire transfers?" (Tokio Marine HCC) "If "Yes", does your wire transfer authorization process include the following: (1) A wire request documentation form?" (Tokio Marine HCC) "(2) A protocol for obtaining proper written authorization for wire transfers?" (Tokio Marine HCC) "(3) A separation of authority protocol?" (Tokio Marine HCC) "Does the Applicant or its Managed Security Service Provider, if applicable, implement MFA for all administrator access?" (AXIS Insurance) "Does the Applicant employ a protocol to confirm transfer instructions including a call back, email or an alternative method of authenticating the instruction?" (AXIS Insurance) "Does the Applicant employ a protocol requiring more than one or next-level approval?" (AXIS Insurance) "Does the Applicant conduct anti-fraud training of employees at least annually?" (AXIS Insurance) "Does the applicant have formal policies and procedures in place for secure fund transfers, such as senior management approval and obtaining verbal confirmation for any fund transfer requests?" (RLI) "Prior to executing an electronic payment, does the applicant verify the validity of the funds transfer request or payment change request, with the requestor, via a separate means of communication prior to transferring funds or making payment changes?" (RLI) "How are privileged accounts secured and managed?" (Corvus Insurance) "Prior to executing an electronic payment, do you verify the validity of the funds transfer request or payment change request, with the requestor, via a separate means of communication prior to transferring funds or making payment changes?" (Corvus Insurance) "Does the organization authenticate funds transfer requests (e.g. by calling a customer to verify the request at a predetermined phone number?" (Cowbell Cyber) "Does the organization prevent unauthorized employees from initiating wire transfers?" (Cowbell Cyber) "ve at SS bay Security Controls Does the Applicant have controls in place which require all fund and wire transfers over $25,000 to be authorized and verified by at least two employees prior to execution?" (At-Bay) "a. Do the applicant's privileged users require more extensive training relating to phishing attacks?" (QBE) "Does the applicant utilize a Privileged Access Management (PAM) solution?" (QBE) "If not utilizing a PAM solution, what compensating controls exist to protect privileged accounts?" (QBE) "Does the applicant restrict Local Admin rights?" (QBE) "Exec/Employee directed request wire transfer without first validating the request with a call back to the requestor (inclusive of any owner) at a pre-determined work phone number or with a f ace to face confirmation?" (The Hanover Insurance Group) "If "No", what kind of training does the Applicant provide to help combat these types of fraudulent schemes and how often?" (The Hanover Insurance Group) "Does any applicant accept fund transfer requests from customers?" (The Hartford) "If yes, is the funds transfer instruction validated by a method other than the original means of request?" (The Hartford) "Do you set up a separate account for each user (including any contractors needing access?" (CNA) "Do you physically and electronically limit access to sensitive information on a need –to-know basis and revoke access privileges upon a reduction in an individual's need to know?" (CNA) "Do you physically and electronically limit access to sensitive information on a need-to-know basis and revoke access privileges upon a reduction in an individual's need to know?" (CNA) "(2) Access control with role-based assignments?" (Encore Fiduciary) "Do you use MFA to protect all local and remote access to privileged user accounts?" (Encore Fiduciary) "Do you manage privileged accounts using privileged account management software (PAM) (e.g., CyberArk, BeyondTrust, etc.?" (Encore Fiduciary) "If "Yes", complete the following: (1) Provide the name of your PAM software provider: (2) Is access protected by MFA?" (Encore Fiduciary) "Do you actively monitor all administrator access for unusual behavior patterns?" (Encore Fiduciary) "Do non-IT users have local administration rights on their laptop / desktop?" (Encore Fiduciary) "Does your organization send and/or receive wire transfers?" (Encore Fiduciary) "If "Yes", does your wire transfer authorization process include the following: (1) A wire request documentation form?" (Encore Fiduciary) "(2) A protocol for obtaining proper written authorization for wire transfers?" (Encore Fiduciary) "(3) A separation of authority protocol?" (Encore Fiduciary) "Does the Applicant restrict access based on job function and responsibilities?" (Everest Insurance) "Payment Card Information (PCI) (e.g., credit card, debit card numbers or other financial account numbers?" (Everest Insurance) "Is access to the internet from terminals restricted for employees?" (Everest Insurance) "You enforce a policy of auditing of managing computer and user accounts?" (RSA) "Do you perform background checks on employees & contractors who have access to sensitive information?" (Munich Re) "Do you terminate user access rights as part of the employee exit process?" (Munich Re) "Do you restrict user access (employees, contractors etc.) on a business need-to-know & least-privilege basis?" (Munich Re) "Do you have a central Identity & Access Management ("IAM") system for assigning and revoking access rights?" (Munich Re) "Do you have a formal process in place for assigning and revoking user accounts and access rights?" (Munich Re) "Do assets owners review access rights at least annually?" (Munich Re) "If Yes, which of the following accounts are enrolled into the PAM tool?" (Munich Re) "Which of the following features are enabled on the PAM tool?" (Munich Re) "Is logging and alerting configured for all privileged account activity?" (Munich Re) "Are domain admin accounts limited to administrative functions only?" (Munich Re) "Please provide the number of service accounts in the domain admin group?" (Munich Re) "Do you configure service accounts using the principle of least privilege?" (Munich Re) "Do you configure service accounts to deny interactive log-ins?" (Munich Re) "Do you log the activity of service accounts that are able to override system or application controls (e.g. elevation Yes No of privileges, lateral movement etc.?" (Munich Re) "Do you prohibit local admin rights on workstations for users?" (Munich Re) "Do you periodically review and update vendor access rights?" (Munich Re) "Do you ensure multi-factor authentication for any fund transfer?" (Hiscox UK) "Do you have a process in place to confirm that any payment requests received by email are from a known source?" (Hiscox UK) |
| PR.DS-11 Backups of data are created, protected, maintained, and tested | NIST CSF 2.0 | 20 | "Does Named Insured have procedures to back up, archive, and restore sensitive data and critical business systems?" (Coalition) "Business Interruption (Only if applying for this coverage) Are system backup and recovery procedures implemented, documented and tested at least annually for all mission-critical systems?" (Chubb) "Do you regularly back up your business critical data?" (Beazley) "If you rely on a cloud-based backup service, is it a "syncing service"?" (Beazley) "Please specify how often you back-up all of your critical data and systems?" (Hiscox) "please indicate frequency) Never Is the back-up disconnected from your systems?" (Hiscox) "If Yes, is the back-up regularly tested?" (Hiscox) "If you have a back-up of all of your critical data and systems, does that include an offline copy?" (Hiscox) "If Yes, how old is the back-up?" (Hiscox) "Do you utilize cloud back-ups?" (Hiscox) "If Yes, are the cloud back-ups secured via two-factor authentication or other similar means?" (Hiscox) "Do you backup all mission critical systems and data?" (Great American Insurance Group) "How frequently do you back up?" (Great American Insurance Group) "o Daily/nightly o Weekly o Less frequently than weekly Which of the following back-up solutions do you employ?" (Great American Insurance Group) "How quickly can you restore from back-ups?" (Great American Insurance Group) "Are back-up restoration plans tested?" (Great American Insurance Group) "How frequently do you test your ability to restore from back-ups?" (Great American Insurance Group) "Do you use a data backup solution for all critical data?" (Tokio Marine HCC) "Daily Weekly Monthly (2) Which of the following best describes your data backup solution?" (Tokio Marine HCC) "Local backup Network drive Tape backup Off-site storage Cloud backup Other: (3) Please list your data backup provider: (4) Is your data backup solution: (a) physically disconnected from your network?" (Tokio Marine HCC) "(5) How long do you expect it to take to recover from backups in the event of a widespread malware or ransomware attack within your network?" (Tokio Marine HCC) "Does the Applicant conduct regular backup of data?" (AXIS Insurance) "Is Critical Information backed up at least?" (AXIS Insurance) "Which of the following does the Applicant utilize Tapes Disks Cloud for backups?" (AXIS Insurance) "Where are backups stored?" (AXIS Insurance) "Are backups subject to the following measures?" (AXIS Insurance) "Is full recovery from a backup tested at least annually?" (AXIS Insurance) "Backup and recovery procedures in place for all important business and customer data If Yes, are such procedures automated?" (Travelers) "Based upon testing results, how long does it take to restore the Applicant's critical business operations following a network or systems interruption?" (Travelers) "Do you have a backup solution?" (Corvus Insurance) "If "Yes", how frequently do you back up systems and data?" (Corvus Insurance) "Which of the following are in place for your backup solution(s?" (Corvus Insurance) "How often does the organization perform backups of business-critical data?" (Cowbell Cyber) "Does the Applicant keep offline backups that are disconnected from its network or store backups with a cloud service provider?" (At-Bay) "Does the applicant perform full backups for databases, applications, endpoints, and servers (operating systems?" (QBE) "How often are full backups performed?" (QBE) "Are backups stored offline?" (QBE) "Where are backups stored?" (QBE) "If yes, how are the backups accessed and who can access them?" (QBE) "If no, how is the applicant protecting the backups?" (QBE) "Is virus/malware scanning used on the backups?" (QBE) "Are backups tested for vulnerabilities/malware prior to restoration?" (QBE) "back-ups of critical Data and Computer Systems If either 2.a. or 2.b. has been selected is one copy stored on-line?" (The Hanover Insurance Group) "at rest While electronically in transit While on mobile devices Backups & Recovery Is your business' critical data regularly backed up?" (The Hartford) "weekly Yes, monthly If yes, are backups stored offline and/or isolated from production systems?" (The Hartford) "And, how often do the applicants test recovering data from the backup?" (The Hartford) "Do you back-up your network data and configuration files daily and store back-up files in a secure location, and rehearse your procedure for restoring from back-ups at least yearly?" (CNA) "Do you use a data backup solution?" (Encore Fiduciary) "Which best describes your data backup solution?" (Encore Fiduciary) "How frequently are backups run?" (Encore Fiduciary) "Does the Applicant maintain redundant backups of sensitive and critical system information?" (Everest Insurance) "If "Yes", is there at least one backup destination that is maintained offline?" (Everest Insurance) "on enterprise assets (e.g., databases, file shares, backups?" (Everest Insurance) "You back up Your Critical Data at least weekly to a different location?" (RSA) "The backup of Your Critical Data is stored in a secure locked location with access restricted to authorised personnel only?" (RSA) "How quickly can you obtain backups of Critical Data?" (RSA) "How long would it take You to fully restore from your backup?" (RSA) "How are your backups stored?" (Munich Re) "Are unique backup credentials stored separately from other user credentials?" (Munich Re) "Are backup processes tested to ensure data can be restored with minimal impact to the business?" (Munich Re) "Are full system backups taken at least weekly and stored either off site or disconnected from your network?" (Hiscox UK) |
| A1.3 Testing recovery plan procedures | SOC 2 | 20 | "Does Named Insured have procedures to back up, archive, and restore sensitive data and critical business systems?" (Coalition) "Business Interruption (Only if applying for this coverage) Are system backup and recovery procedures implemented, documented and tested at least annually for all mission-critical systems?" (Chubb) "Do you regularly back up your business critical data?" (Beazley) "If you rely on a cloud-based backup service, is it a "syncing service"?" (Beazley) "Please specify how often you back-up all of your critical data and systems?" (Hiscox) "please indicate frequency) Never Is the back-up disconnected from your systems?" (Hiscox) "If Yes, is the back-up regularly tested?" (Hiscox) "If you have a back-up of all of your critical data and systems, does that include an offline copy?" (Hiscox) "If Yes, how old is the back-up?" (Hiscox) "Do you utilize cloud back-ups?" (Hiscox) "Do you backup all mission critical systems and data?" (Great American Insurance Group) "How frequently do you back up?" (Great American Insurance Group) "o Daily/nightly o Weekly o Less frequently than weekly Which of the following back-up solutions do you employ?" (Great American Insurance Group) "How quickly can you restore from back-ups?" (Great American Insurance Group) "Are back-up restoration plans tested?" (Great American Insurance Group) "How frequently do you test your ability to restore from back-ups?" (Great American Insurance Group) "Do you use a data backup solution for all critical data?" (Tokio Marine HCC) "Daily Weekly Monthly (2) Which of the following best describes your data backup solution?" (Tokio Marine HCC) "Local backup Network drive Tape backup Off-site storage Cloud backup Other: (3) Please list your data backup provider: (4) Is your data backup solution: (a) physically disconnected from your network?" (Tokio Marine HCC) "(5) How long do you expect it to take to recover from backups in the event of a widespread malware or ransomware attack within your network?" (Tokio Marine HCC) "Does the Applicant conduct regular backup of data?" (AXIS Insurance) "Is Critical Information backed up at least?" (AXIS Insurance) "Which of the following does the Applicant utilize Tapes Disks Cloud for backups?" (AXIS Insurance) "Where are backups stored?" (AXIS Insurance) "Are backups subject to the following measures?" (AXIS Insurance) "Is full recovery from a backup tested at least annually?" (AXIS Insurance) "Backup and recovery procedures in place for all important business and customer data If Yes, are such procedures automated?" (Travelers) "Based upon testing results, how long does it take to restore the Applicant's critical business operations following a network or systems interruption?" (Travelers) "Do you have a backup solution?" (Corvus Insurance) "If "Yes", how frequently do you back up systems and data?" (Corvus Insurance) "Which of the following are in place for your backup solution(s?" (Corvus Insurance) "How often does the organization perform backups of business-critical data?" (Cowbell Cyber) "Does the Applicant keep offline backups that are disconnected from its network or store backups with a cloud service provider?" (At-Bay) "Does the applicant perform full backups for databases, applications, endpoints, and servers (operating systems?" (QBE) "How often are full backups performed?" (QBE) "Are backups stored offline?" (QBE) "Where are backups stored?" (QBE) "If yes, how are the backups accessed and who can access them?" (QBE) "If no, how is the applicant protecting the backups?" (QBE) "Is virus/malware scanning used on the backups?" (QBE) "Are backups tested for vulnerabilities/malware prior to restoration?" (QBE) "back-ups of critical Data and Computer Systems If either 2.a. or 2.b. has been selected is one copy stored on-line?" (The Hanover Insurance Group) "weekly Yes, monthly If yes, are backups stored offline and/or isolated from production systems?" (The Hartford) "And, how often do the applicants test recovering data from the backup?" (The Hartford) "Do you back-up your network data and configuration files daily and store back-up files in a secure location, and rehearse your procedure for restoring from back-ups at least yearly?" (CNA) "Do you use a data backup solution?" (Encore Fiduciary) "Which best describes your data backup solution?" (Encore Fiduciary) "How frequently are backups run?" (Encore Fiduciary) "Does the Applicant maintain redundant backups of sensitive and critical system information?" (Everest Insurance) "If "Yes", is there at least one backup destination that is maintained offline?" (Everest Insurance) "on enterprise assets (e.g., databases, file shares, backups?" (Everest Insurance) "You back up Your Critical Data at least weekly to a different location?" (RSA) "The backup of Your Critical Data is stored in a secure locked location with access restricted to authorised personnel only?" (RSA) "How quickly can you obtain backups of Critical Data?" (RSA) "How long would it take You to fully restore from your backup?" (RSA) "How are your backups stored?" (Munich Re) "Are backup processes tested to ensure data can be restored with minimal impact to the business?" (Munich Re) "Are full system backups taken at least weekly and stored either off site or disconnected from your network?" (Hiscox UK) |
| A.5.19 Information security in supplier relationships | ISO 27001:2022 | 20 | "Does the Applicant verify all vendor and supplier bank accounts by a direct call to the receiving bank, prior to accounts being established in the accounts payable system?" (Chubb) "Is your IT infrastructure primarily operated and managed in-house or outsourced?" (CFC Underwriting) "If it is outsourced, who do you outsource it to?" (CFC Underwriting) "When a vendor or supplier requests any change to its account details (including routing numbers and account numbers), do you confirm requested changes via an out-of-band authentication (a method other than the original means of request?" (Beazley) "Regular cyber security assessments of your systems performed by third parties?" (Hiscox) "If Yes, do you ensure these contracts contain hold harmless/indemnity clauses that benefit you?" (Hiscox) "Do you have procedures in place to vet the security and privacy controls of your vendors and outsourcers?" (Hiscox) "Do you contractually indemnify your clients for costs they incur as a result of your breach of their sensitive data?" (Hiscox) "Does the Applicant provide data processing, data storage, or data hosting services to third parties?" (AmTrust) "Do you outsource your web hosting?" (Great American Insurance Group) "Do you use a cloud provider to store data or host applications?" (Tokio Marine HCC) "(4) A protocol for confirming all payment or funds transfer instructions/requests from a new vendor, client or customer via direct call to that vendor, client or customer using only the telephone number provided by the vendor, client or customer before the payment or funds transfer instruction/request was received?" (Tokio Marine HCC) "(5) A protocol for confirming any vendor, client or customer account information change requests (including requests to change bank account numbers, contact information or mailing addresses) via direct call to that vendor, client or customer using only the telephone number provided by the vendor, client or customer before the change request was received?" (Tokio Marine HCC) "Does the Applicant store or process Personal Information on behalf of a third party?" (AXIS Insurance) "Does the Applicant have a Security Operations Center (SOC) or utilize a Managed Security Service Provider?" (AXIS Insurance) "Does the Applicant have an alternative solution in the event of a failure or outage to one of these service providers?" (Travelers) "If Payment processing is answered Yes above, does the Applicant have an alternative means of processing card data in the event of an outsourced provider failure or outage?" (Travelers) "Does the applicant use a Managed Service Provider (MSP?" (RLI) "If the applicant accepts payment cards, is the applicant PCI compliant or using an outsourced payment processor that is PCI compliant?" (RLI) "If the Applicant accepts payment cards in exchange for goods or services rendered, is the Applicant or their outsourced payment processor PCI compliant?" (Corvus Insurance) "Does the organization verify vendor/supplier bank accounts before adding to their accounts payable systems?" (Cowbell Cyber) "Do agreements with third-party service providers require levels of security commensurate with the organization's information security standard?" (Cowbell Cyber) "Does the Applicant keep offline backups that are disconnected from its network or store backups with a cloud service provider?" (At-Bay) "Is multifactor authentication (MFA) required for all internal, external, and vendor access to the applicant's network?" (QBE) "Does the Applicant have written and documented procedures in place which are provided to Your Employees and which require Employees to authenticate all requested changes to vendor/supplier 926-1701 APP 10/21 Page 3 of 5 Cyber Advantage Pro New Business Application Or client/customer information (such as changes to bank accounts, routing numbers, contact inf ormation) with a phone call to an authorized representative of the vendor/supplier or client/customer at a pre-determined phone number on file?" (The Hanover Insurance Group) "If yes, is cybersecurity managed in-house or outsourced to a third party?" (The Hartford) "web-based email Funds Transfer Controls Do the applicants all have a dual authentication protocol for confirming all funds transfer requests or account information changes from a vendor/partner through a secondary method of communication before the account information is changed or a funds transfer request is carried out?" (The Hartford) "Do you use a cloud provider to store data or host applications?" (Encore Fiduciary) "(4) A protocol for confirming all payment or funds transfer instructions/requests from a new vendor, client or customer via direct call to that vendor, client or customer using only the telephone number provided by the vendor, client or customer before the payment or funds transfer instruction/request was received?" (Encore Fiduciary) "(5) A protocol for confirming any vendor, client or customer account information change requests (including requests to change bank account numbers, contact information or mailing addresses) via direct call to Encore Fiduciary Cyber Liability Application (2.2022) Page 4 of 10 that vendor, client or customer using only the telephone number provided by the vendor, client or customer before the change request was received?" (Encore Fiduciary) "Does the Applicant's privacy policy allow for the sharing of Confidential Information with third parties?" (Everest Insurance) "If "Yes", does the Applicant have agreements with these vendors or other third parties which requires the other party to indemnify the Applicant for legal liability arising out the third party's loss, release, or disclosure of this information?" (Everest Insurance) "with third party services (e.g., cloud provider?" (Everest Insurance) "Does the Applicant require evidence of the errors and omissions insurance from the subcontractors?" (Everest Insurance) "Does the standard contract contain hold harmless clauses for the benefit of the Applicant?" (Everest Insurance) "Does the Applicant agree to hold harmless/indemnify others?" (Everest Insurance) "Do You provide personal identifiable, sensitive or confidential information to Your sub-contractors?" (RSA) "If Yes, Do You always obtain a hold harmless or indemnity from sub-contractors for claims that may arise from a breach of the data provided by them?" (RSA) "Do you share any personal data with third parties?" (Munich Re) "If Yes, do you have data sharing agreements in place with all third parties where personal data is shared?" (Munich Re) "Do you obtain authorization prior to sharing customer data with third parties?" (Munich Re) "Do you give data subjects the ability to opt-out of allowing personal data to be shared with third parties?" (Munich Re) "Do you identify & categorise third party vendors based on their access to company systems and/or data?" (Munich Re) "Is an information security assessment performed on vendors at due diligence stage with findings addressed?" (Munich Re) "Do you perform periodic audits of vendors and enforce the right to audit in contractual agreement?" (Munich Re) "Do vendor agreements require levels of security commensurate with your own information security standards?" (Munich Re) |
| A.8.5 Secure authentication | ISO 27001:2022 | 19 | "Does Named Insured require dual control when transferring funds in excess of $25,000?" (Coalition) "Cyber Crime (Only if applying for this coverage) Does the Applicant accept funds transfer information from clients over the telephone, email, text message or similar method of communication?" (Chubb) "Does the Applicant authenticate instructions by calling the customer at a predetermined phone number or require receipt of a customer identity code?" (Chubb) "Is approval by more than one person required to initiate a wire transfer?" (Chubb) "Do you require Multi-Factor Authentication (MFA) for remote access to your network (both cloud-hosted and on- premises, including via Virtual Private Networks (VPNs)?" (Beazley) "Do you require MFA for access to web-based email?" (Beazley) "A policy that requires strong passwords that should be updated on a regular basis?" (Hiscox) "Multi-factor authentication in place for remote access by employees?" (Hiscox) "Multi-factor authentication in place for remote access by third parties?" (Hiscox) "If Yes, are the cloud back-ups secured via two-factor authentication or other similar means?" (Hiscox) "Before acting on a transfer, do you verify the request or account detail changes using a method other than the initial contact method (Example: the initial request is received by mail and verification is done by telephone?" (Hiscox) "c. a loss of money, securities, or property due to social engineering, fraud, or other criminal acts?" (Hiscox) "Password/passcode protected Encryption Traditional or next generation firewalls enabled/turned on Traditional or next generation antivirus products on all endpoints Endpoint Detection and Response (EDR) 24/7/365 on all devices If yes to EDR, Who is your provider?" (Great American Insurance Group) "Is multi factor authentication (MFA) to access Email required?" (Great American Insurance Group) "Is multi factor authentication (MFA) for personal devices required?" (Great American Insurance Group) "Is multifactor authentication (MFA) required to remotely connect to the network, all critical internet facing systems and privilege accounts?" (Great American Insurance Group) "If "Yes": (1) Do you use 2-factor authentication to secure all remote access to your network?" (Tokio Marine HCC) "If "No", is RDP and/or RDG protected by two-factor authentication?" (Tokio Marine HCC) "Do you use 2-factor authentication to secure all domain or network administrator accounts?" (Tokio Marine HCC) "Do you use 2-factor authentication to secure remote access to your email accounts?" (Tokio Marine HCC) "(b) segregated with 2-factor authentication access control?" (Tokio Marine HCC) "Does your organization send and/or receive wire transfers?" (Tokio Marine HCC) "If "Yes", does your wire transfer authorization process include the following: (1) A wire request documentation form?" (Tokio Marine HCC) "(2) A protocol for obtaining proper written authorization for wire transfers?" (Tokio Marine HCC) "Is Multi Factor Authentication used for access?" (AXIS Insurance) "If remote access is available, does the Applicant implement MFA for all remote access?" (AXIS Insurance) "Does the Applicant or its Managed Security Service Provider, if applicable, implement MFA for all administrator access?" (AXIS Insurance) "Does the Applicant employ a protocol to confirm transfer instructions including a call back, email or an alternative method of authenticating the instruction?" (AXIS Insurance) "Does the Applicant employ a protocol requiring more than one or next-level approval?" (AXIS Insurance) "Does the Applicant conduct anti-fraud training of employees at least annually?" (AXIS Insurance) "Does the applicant have formal policies and procedures in place for secure fund transfers, such as senior management approval and obtaining verbal confirmation for any fund transfer requests?" (RLI) "Prior to executing an electronic payment, does the applicant verify the validity of the funds transfer request or payment change request, with the requestor, via a separate means of communication prior to transferring funds or making payment changes?" (RLI) "Which of the of the following apply to your Multi-Factor Authentication (MFA) implementation?" (Corvus Insurance) "Prior to executing an electronic payment, do you verify the validity of the funds transfer request or payment change request, with the requestor, via a separate means of communication prior to transferring funds or making payment changes?" (Corvus Insurance) "Do you enforce Multi-Factor Authentication (MFA) for all employees, contractors, and partners on the following?" (Cowbell Cyber) "Does the organization authenticate funds transfer requests (e.g. by calling a customer to verify the request at a predetermined phone number?" (Cowbell Cyber) "Does the organization prevent unauthorized employees from initiating wire transfers?" (Cowbell Cyber) "ve at SS bay Security Controls Does the Applicant have controls in place which require all fund and wire transfers over $25,000 to be authorized and verified by at least two employees prior to execution?" (At-Bay) "Is multifactor authentication (MFA) required for all internal, external, and vendor access to the applicant's network?" (QBE) "Do these users require additional credentials to access?" (QBE) "What is the minimum length for passwords?" (QBE) "If yes, does the applicant require strong authentication (e.g., two factor/ MFA?" (QBE) "Can backups only be accessed via an authentication mechanism (i.e., MFA/password vault/separate credentials or credential checkout?" (QBE) "Exec/Employee directed request wire transfer without first validating the request with a call back to the requestor (inclusive of any owner) at a pre-determined work phone number or with a f ace to face confirmation?" (The Hanover Insurance Group) "If "No", what kind of training does the Applicant provide to help combat these types of fraudulent schemes and how often?" (The Hanover Insurance Group) "Security & Controls MFA Is Multi-Factor Authentication (MFA) required for ALL remote access to your business' network?" (The Hartford) "Is MFA required for access to email?" (The Hartford) "Does any applicant accept fund transfer requests from customers?" (The Hartford) "If yes, is the funds transfer instruction validated by a method other than the original means of request?" (The Hartford) "Do you enforce a strong/complex password policy of at least 8-20 characters?" (CNA) "Information Security and Cyber Infrastructure Self-Assessment 14 On your wireless networks; do you use security at least as strong as WPA2 authentication and encryption, and do you require two factor authentication (access token and password/account logon) before allowing wireless connections to your network?" (CNA) "if you do not use wireless networks.) 15 Do you require multi-factor authorization when your network is accessed remotely and/or when cloud resources are utilized?" (CNA) "On your wireless networks; do you use security at least as strong as WPA2 authentication and encryption, and do you require two factor authentication (access token and password/account logon) before allowing wireless connections to your network?" (CNA) "Do you require multi-factor authorization when your network is accessed remotely and/or when cloud resources are utilized?" (CNA) "If "Yes", do you enforce Multi-Factor Authentication (MFA?" (Encore Fiduciary) "If "Yes", do you use MFA to secure all remote access to your network, including any remote desktop protocol (RDP) connections?" (Encore Fiduciary) "Encore Fiduciary Cyber Liability Application (2.2022) Page 2 of 10 If MFA is used, complete the following: (1) Provide the name of your MFA provider: (2) Describe your MFA type: (3) Does your MFA configuration ensure that the compromise of a single device will only compromise a single authenticator?" (Encore Fiduciary) "Do you use MFA to protect all local and remote access to privileged user accounts?" (Encore Fiduciary) "If "Yes", complete the following: (1) Provide the name of your PAM software provider: (2) Is access protected by MFA?" (Encore Fiduciary) "Does your organization send and/or receive wire transfers?" (Encore Fiduciary) "If "Yes", does your wire transfer authorization process include the following: (1) A wire request documentation form?" (Encore Fiduciary) "(2) A protocol for obtaining proper written authorization for wire transfers?" (Encore Fiduciary) "Does the Applicant use multi-factor authentication for access to critical applications or databases (including those that contain personally identifiable information, private health information or payment card information?" (Everest Insurance) "Does the Applicant enforce password changes every 8-12 weeks?" (Everest Insurance) "Payment Card Information (PCI) (e.g., credit card, debit card numbers or other financial account numbers?" (Everest Insurance) "Are unique backup credentials stored separately from other user credentials?" (Munich Re) "Is web-based email available to employees?" (Munich Re) "Are logins to web-based email monitored with alerts for suspicious activity implemented?" (Munich Re) "Is multi-factor authentication (MFA) in place for web-based email logins?" (Munich Re) "Do you have a formal password policy that explains good password hygiene, such as not using obvious or repeated passwords, for all systems providing access to personal or confidential information?" (Hiscox UK) "Do all users with remote access provide at least two different forms of identification ('multi-factor authentication') to verify their identity prior to log-in?" (Hiscox UK) "Do you require multi-factor authentication for all online banking logins?" (Hiscox UK) "Do you ensure multi-factor authentication for any fund transfer?" (Hiscox UK) "Do you have a process in place to confirm that any payment requests received by email are from a known source?" (Hiscox UK) |
| GV.SC-01 A cybersecurity supply chain risk management program, strategy, objectives, policies, and processes are established and agreed to by organizational stakeholders | NIST CSF 2.0 | 19 | "Does the Applicant verify all vendor and supplier bank accounts by a direct call to the receiving bank, prior to accounts being established in the accounts payable system?" (Chubb) "Is your IT infrastructure primarily operated and managed in-house or outsourced?" (CFC Underwriting) "If it is outsourced, who do you outsource it to?" (CFC Underwriting) "When a vendor or supplier requests any change to its account details (including routing numbers and account numbers), do you confirm requested changes via an out-of-band authentication (a method other than the original means of request?" (Beazley) "Regular cyber security assessments of your systems performed by third parties?" (Hiscox) "If Yes, do you ensure these contracts contain hold harmless/indemnity clauses that benefit you?" (Hiscox) "Do you have procedures in place to vet the security and privacy controls of your vendors and outsourcers?" (Hiscox) "Do you contractually indemnify your clients for costs they incur as a result of your breach of their sensitive data?" (Hiscox) "Does the Applicant provide data processing, data storage, or data hosting services to third parties?" (AmTrust) "Do you outsource your web hosting?" (Great American Insurance Group) "Do you use a cloud provider to store data or host applications?" (Tokio Marine HCC) "(4) A protocol for confirming all payment or funds transfer instructions/requests from a new vendor, client or customer via direct call to that vendor, client or customer using only the telephone number provided by the vendor, client or customer before the payment or funds transfer instruction/request was received?" (Tokio Marine HCC) "(5) A protocol for confirming any vendor, client or customer account information change requests (including requests to change bank account numbers, contact information or mailing addresses) via direct call to that vendor, client or customer using only the telephone number provided by the vendor, client or customer before the change request was received?" (Tokio Marine HCC) "Does the Applicant have an alternative solution in the event of a failure or outage to one of these service providers?" (Travelers) "If Payment processing is answered Yes above, does the Applicant have an alternative means of processing card data in the event of an outsourced provider failure or outage?" (Travelers) "Does the applicant use a Managed Service Provider (MSP?" (RLI) "If the applicant accepts payment cards, is the applicant PCI compliant or using an outsourced payment processor that is PCI compliant?" (RLI) "If the Applicant accepts payment cards in exchange for goods or services rendered, is the Applicant or their outsourced payment processor PCI compliant?" (Corvus Insurance) "Does the organization verify vendor/supplier bank accounts before adding to their accounts payable systems?" (Cowbell Cyber) "Do agreements with third-party service providers require levels of security commensurate with the organization's information security standard?" (Cowbell Cyber) "Does the Applicant keep offline backups that are disconnected from its network or store backups with a cloud service provider?" (At-Bay) "Is multifactor authentication (MFA) required for all internal, external, and vendor access to the applicant's network?" (QBE) "Does the Applicant have written and documented procedures in place which are provided to Your Employees and which require Employees to authenticate all requested changes to vendor/supplier 926-1701 APP 10/21 Page 3 of 5 Cyber Advantage Pro New Business Application Or client/customer information (such as changes to bank accounts, routing numbers, contact inf ormation) with a phone call to an authorized representative of the vendor/supplier or client/customer at a pre-determined phone number on file?" (The Hanover Insurance Group) "If yes, is cybersecurity managed in-house or outsourced to a third party?" (The Hartford) "web-based email Funds Transfer Controls Do the applicants all have a dual authentication protocol for confirming all funds transfer requests or account information changes from a vendor/partner through a secondary method of communication before the account information is changed or a funds transfer request is carried out?" (The Hartford) "Do you use a cloud provider to store data or host applications?" (Encore Fiduciary) "(4) A protocol for confirming all payment or funds transfer instructions/requests from a new vendor, client or customer via direct call to that vendor, client or customer using only the telephone number provided by the vendor, client or customer before the payment or funds transfer instruction/request was received?" (Encore Fiduciary) "(5) A protocol for confirming any vendor, client or customer account information change requests (including requests to change bank account numbers, contact information or mailing addresses) via direct call to Encore Fiduciary Cyber Liability Application (2.2022) Page 4 of 10 that vendor, client or customer using only the telephone number provided by the vendor, client or customer before the change request was received?" (Encore Fiduciary) "If "Yes", does the Applicant have agreements with these vendors or other third parties which requires the other party to indemnify the Applicant for legal liability arising out the third party's loss, release, or disclosure of this information?" (Everest Insurance) "with third party services (e.g., cloud provider?" (Everest Insurance) "Does the Applicant require evidence of the errors and omissions insurance from the subcontractors?" (Everest Insurance) "Does the standard contract contain hold harmless clauses for the benefit of the Applicant?" (Everest Insurance) "Does the Applicant agree to hold harmless/indemnify others?" (Everest Insurance) "Do You provide personal identifiable, sensitive or confidential information to Your sub-contractors?" (RSA) "If Yes, Do You always obtain a hold harmless or indemnity from sub-contractors for claims that may arise from a breach of the data provided by them?" (RSA) "Do you obtain authorization prior to sharing customer data with third parties?" (Munich Re) "Is an information security assessment performed on vendors at due diligence stage with findings addressed?" (Munich Re) "Do you perform periodic audits of vendors and enforce the right to audit in contractual agreement?" (Munich Re) "Do vendor agreements require levels of security commensurate with your own information security standards?" (Munich Re) |
| CC6.3 Role-based access, least privilege and segregation of duties | SOC 2 | 18 | "Does Named Insured require dual control when transferring funds in excess of $25,000?" (Coalition) "Cyber Crime (Only if applying for this coverage) Does the Applicant accept funds transfer information from clients over the telephone, email, text message or similar method of communication?" (Chubb) "Does the Applicant authenticate instructions by calling the customer at a predetermined phone number or require receipt of a customer identity code?" (Chubb) "Is approval by more than one person required to initiate a wire transfer?" (Chubb) "Before acting on a transfer, do you verify the request or account detail changes using a method other than the initial contact method (Example: the initial request is received by mail and verification is done by telephone?" (Hiscox) "Is multifactor authentication (MFA) required to remotely connect to the network, all critical internet facing systems and privilege accounts?" (Great American Insurance Group) "Are firewalls configured according to the principles of least privileges?" (Great American Insurance Group) "Do you use 2-factor authentication to secure all domain or network administrator accounts?" (Tokio Marine HCC) "Does your organization send and/or receive wire transfers?" (Tokio Marine HCC) "If "Yes", does your wire transfer authorization process include the following: (1) A wire request documentation form?" (Tokio Marine HCC) "(2) A protocol for obtaining proper written authorization for wire transfers?" (Tokio Marine HCC) "Does the Applicant or its Managed Security Service Provider, if applicable, implement MFA for all administrator access?" (AXIS Insurance) "Does the Applicant employ a protocol to confirm transfer instructions including a call back, email or an alternative method of authenticating the instruction?" (AXIS Insurance) "Does the Applicant employ a protocol requiring more than one or next-level approval?" (AXIS Insurance) "Does the applicant have formal policies and procedures in place for secure fund transfers, such as senior management approval and obtaining verbal confirmation for any fund transfer requests?" (RLI) "Prior to executing an electronic payment, does the applicant verify the validity of the funds transfer request or payment change request, with the requestor, via a separate means of communication prior to transferring funds or making payment changes?" (RLI) "How are privileged accounts secured and managed?" (Corvus Insurance) "Prior to executing an electronic payment, do you verify the validity of the funds transfer request or payment change request, with the requestor, via a separate means of communication prior to transferring funds or making payment changes?" (Corvus Insurance) "Does the organization authenticate funds transfer requests (e.g. by calling a customer to verify the request at a predetermined phone number?" (Cowbell Cyber) "Does the organization prevent unauthorized employees from initiating wire transfers?" (Cowbell Cyber) "ve at SS bay Security Controls Does the Applicant have controls in place which require all fund and wire transfers over $25,000 to be authorized and verified by at least two employees prior to execution?" (At-Bay) "a. Do the applicant's privileged users require more extensive training relating to phishing attacks?" (QBE) "Does the applicant utilize a Privileged Access Management (PAM) solution?" (QBE) "If not utilizing a PAM solution, what compensating controls exist to protect privileged accounts?" (QBE) "Does the applicant restrict Local Admin rights?" (QBE) "Exec/Employee directed request wire transfer without first validating the request with a call back to the requestor (inclusive of any owner) at a pre-determined work phone number or with a f ace to face confirmation?" (The Hanover Insurance Group) "Does any applicant accept fund transfer requests from customers?" (The Hartford) "If yes, is the funds transfer instruction validated by a method other than the original means of request?" (The Hartford) "Do you physically and electronically limit access to sensitive information on a need –to-know basis and revoke access privileges upon a reduction in an individual's need to know?" (CNA) "Do you physically and electronically limit access to sensitive information on a need-to-know basis and revoke access privileges upon a reduction in an individual's need to know?" (CNA) "Do you use MFA to protect all local and remote access to privileged user accounts?" (Encore Fiduciary) "Do you manage privileged accounts using privileged account management software (PAM) (e.g., CyberArk, BeyondTrust, etc.?" (Encore Fiduciary) "If "Yes", complete the following: (1) Provide the name of your PAM software provider: (2) Is access protected by MFA?" (Encore Fiduciary) "Do you actively monitor all administrator access for unusual behavior patterns?" (Encore Fiduciary) "Do non-IT users have local administration rights on their laptop / desktop?" (Encore Fiduciary) "Does your organization send and/or receive wire transfers?" (Encore Fiduciary) "If "Yes", does your wire transfer authorization process include the following: (1) A wire request documentation form?" (Encore Fiduciary) "(2) A protocol for obtaining proper written authorization for wire transfers?" (Encore Fiduciary) "Payment Card Information (PCI) (e.g., credit card, debit card numbers or other financial account numbers?" (Everest Insurance) "Do you restrict user access (employees, contractors etc.) on a business need-to-know & least-privilege basis?" (Munich Re) "If Yes, which of the following accounts are enrolled into the PAM tool?" (Munich Re) "Which of the following features are enabled on the PAM tool?" (Munich Re) "Is logging and alerting configured for all privileged account activity?" (Munich Re) "Are domain admin accounts limited to administrative functions only?" (Munich Re) "Please provide the number of service accounts in the domain admin group?" (Munich Re) "Do you configure service accounts using the principle of least privilege?" (Munich Re) "Do you configure service accounts to deny interactive log-ins?" (Munich Re) "Do you log the activity of service accounts that are able to override system or application controls (e.g. elevation Yes No of privileges, lateral movement etc.?" (Munich Re) "Do you prohibit local admin rights on workstations for users?" (Munich Re) "Do you ensure multi-factor authentication for any fund transfer?" (Hiscox UK) "Do you have a process in place to confirm that any payment requests received by email are from a known source?" (Hiscox UK) |
| A.8.24 Use of cryptography | ISO 27001:2022 | 18 | "Does Named Insured enable disk encryption on laptops, desktops, and other portable media devices?" (Coalition) "Does Named Insured accept credit cards or collect Personally Identifiable Information (PII) or Protected Health Information (PHI) from its customers?" (Coalition) "Does the Applicant have third party software protecting its network (e.g. antivirus, encryption, firewalls, etc.?" (Chubb) "If Yes, do all of the Applicant's point-of-sale terminals accept chip-enabled cards?" (Chubb) "Is this information encrypted while at rest?" (Hiscox) "Is this information encrypted while in transit?" (Hiscox) "If Yes, are such devices encrypted?" (Hiscox) "PCI DSS v.3.2 (Payment Card Industry Data Security Standard?" (Hiscox) "in place that scan both encrypted and unencrypted data to restrict network traffic?" (Hiscox) "If Yes, do you encrypt this data?" (Hiscox) "Do you host sensitive data belonging to your clients' customers?" (Hiscox) "Does the Applicant accept credit cards for goods sold or services rendered?" (AmTrust) "Does the Applicant have and enforce policies concerning the encryption of internal and external communication?" (AmTrust) "Does the Applicant encrypt data stored on laptop computers and portable media?" (AmTrust) "Are tapes or other portable media containing backup materials encrypted?" (AmTrust) "Which controls are in place to protect confidential, sensitive, or otherwise regulated data?" (Great American Insurance Group) "Password/passcode protected Encryption Traditional or next generation firewalls enabled/turned on Traditional or next generation antivirus products on all endpoints Endpoint Detection and Response (EDR) 24/7/365 on all devices If yes to EDR, Who is your provider?" (Great American Insurance Group) "Do you encrypt all sensitive and confidential information stored on your organization's systems and networks?" (Tokio Marine HCC) "Do you process, store, or handle credit card transactions?" (Tokio Marine HCC) "Which version of PCI-DSS was the Applicant assessed against?" (AXIS Insurance) "Does the Applicant employ mandatory encryption to protect the following?" (AXIS Insurance) "Does the applicant encrypt all physical devices, critical data, sensitive emails?" (RLI) "What security controls are in place to protect against unauthorized access to sensitive and confidential data?" (Corvus Insurance) "Does the organization encrypt all external communications containing sensitive information?" (Cowbell Cyber) "Does the organization encrypt sensitive information stored on the cloud?" (Cowbell Cyber) "Does the Applicant store or process personal, health or credit card information of more than 500,000 individuals?" (At-Bay) "Is all backup data encrypted once replicated?" (QBE) "Does the applicant have a policy that all portable devices use full disk encryption?" (QBE) "Where does the applicant use encryption?" (QBE) "How often does the applicant use encryption?" (QBE) "at rest While electronically in transit While on mobile devices Backups & Recovery Is your business' critical data regularly backed up?" (The Hartford) "Information Security and Cyber Infrastructure Self-Assessment 14 On your wireless networks; do you use security at least as strong as WPA2 authentication and encryption, and do you require two factor authentication (access token and password/account logon) before allowing wireless connections to your network?" (CNA) "Do you encrypt all sensitive records and files that are held at rest and/or transmitted across public networks, and that are to be transmitted wirelessly?" (CNA) "On your wireless networks; do you use security at least as strong as WPA2 authentication and encryption, and do you require two factor authentication (access token and password/account logon) before allowing wireless connections to your network?" (CNA) "Do you process, store or handle credit card transactions?" (Encore Fiduciary) "Do you encrypt all sensitive and confidential information stored on your organization's systems and networks?" (Encore Fiduciary) "Are all terminals EMV enabled?" (Everest Insurance) "Are the POS and corporate networks segregated?" (Everest Insurance) "Do you disable media ports or restrict usage to only encrypted removable storage devices?" (Munich Re) "Do you enforce the use of encryption over all external communication lines (e.g. website, email, wireless?" (Munich Re) "Do you enforce the use of encryption of sensitive information while at rest (e.g. on premise, mobile device, Yes No cloud?" (Munich Re) "Do you utilize a Data Loss Prevention (DLP) product for email?" (Munich Re) "Is a DLP solution in use on endpoints, external and internal (including email) servers?" (Munich Re) "Do you accept card payments for goods and/or services?" (Munich Re) "How do you process payment card transactions?" (Munich Re) "Do you store payment card data on your network?" (Munich Re) "If Yes, is payment card data either encrypted or tokenised at all times?" (Munich Re) "Do you comply with the relevant Payment Card Industry Data Security Standard?" (Munich Re) "Has the payment processor provided you with evidence of its PCI DSS compliance?" (Munich Re) "Do you have a policy to encrypt mobile computing devices (for example laptops, tablets, mobile telephones, PDAs) and portable data storage media (for example external drives or magnetic tapes) which hold, process, transact or store any of the personal data referred to in 1.7?" (Hiscox UK) |
| CC9.2 Assessing and managing vendor and business partner risk | SOC 2 | 18 | "Does the Applicant verify all vendor and supplier bank accounts by a direct call to the receiving bank, prior to accounts being established in the accounts payable system?" (Chubb) "Is your IT infrastructure primarily operated and managed in-house or outsourced?" (CFC Underwriting) "If it is outsourced, who do you outsource it to?" (CFC Underwriting) "Do you, or an outsourced service provider on your behalf, actively manage and install critical patches across your internet-facing systems?" (Beazley) "When a vendor or supplier requests any change to its account details (including routing numbers and account numbers), do you confirm requested changes via an out-of-band authentication (a method other than the original means of request?" (Beazley) "Regular cyber security assessments of your systems performed by third parties?" (Hiscox) "If Yes, do you ensure these contracts contain hold harmless/indemnity clauses that benefit you?" (Hiscox) "Do you have procedures in place to vet the security and privacy controls of your vendors and outsourcers?" (Hiscox) "Do you contractually indemnify your clients for costs they incur as a result of your breach of their sensitive data?" (Hiscox) "Does the Applicant provide data processing, data storage, or data hosting services to third parties?" (AmTrust) "Do you outsource your web hosting?" (Great American Insurance Group) "Do you use a cloud provider to store data or host applications?" (Tokio Marine HCC) "(4) A protocol for confirming all payment or funds transfer instructions/requests from a new vendor, client or customer via direct call to that vendor, client or customer using only the telephone number provided by the vendor, client or customer before the payment or funds transfer instruction/request was received?" (Tokio Marine HCC) "(5) A protocol for confirming any vendor, client or customer account information change requests (including requests to change bank account numbers, contact information or mailing addresses) via direct call to that vendor, client or customer using only the telephone number provided by the vendor, client or customer before the change request was received?" (Tokio Marine HCC) "Annual penetration testing If Yes, is such testing conducted by a third party service provider?" (Travelers) "Does the Applicant have an alternative solution in the event of a failure or outage to one of these service providers?" (Travelers) "If Payment processing is answered Yes above, does the Applicant have an alternative means of processing card data in the event of an outsourced provider failure or outage?" (Travelers) "Does the applicant use a Managed Service Provider (MSP?" (RLI) "If the applicant accepts payment cards, is the applicant PCI compliant or using an outsourced payment processor that is PCI compliant?" (RLI) "If the Applicant accepts payment cards in exchange for goods or services rendered, is the Applicant or their outsourced payment processor PCI compliant?" (Corvus Insurance) "Does the organization verify vendor/supplier bank accounts before adding to their accounts payable systems?" (Cowbell Cyber) "Are all internet-accessible systems (e.g. web-, email-servers) segregated from the organization's trusted network (e.g. within a demilitarized zone (DMZ) or at a third-party service provider?" (Cowbell Cyber) "Do agreements with third-party service providers require levels of security commensurate with the organization's information security standard?" (Cowbell Cyber) "Is multifactor authentication (MFA) required for all internal, external, and vendor access to the applicant's network?" (QBE) "Does the Applicant have written and documented procedures in place which are provided to Your Employees and which require Employees to authenticate all requested changes to vendor/supplier 926-1701 APP 10/21 Page 3 of 5 Cyber Advantage Pro New Business Application Or client/customer information (such as changes to bank accounts, routing numbers, contact inf ormation) with a phone call to an authorized representative of the vendor/supplier or client/customer at a pre-determined phone number on file?" (The Hanover Insurance Group) "If yes, is cybersecurity managed in-house or outsourced to a third party?" (The Hartford) "web-based email Funds Transfer Controls Do the applicants all have a dual authentication protocol for confirming all funds transfer requests or account information changes from a vendor/partner through a secondary method of communication before the account information is changed or a funds transfer request is carried out?" (The Hartford) "If the Applicant's network security is outsourced, are you the main contact for the network security provider named in question b. above?" (Encore Fiduciary) "Do you use a cloud provider to store data or host applications?" (Encore Fiduciary) "(4) A protocol for confirming all payment or funds transfer instructions/requests from a new vendor, client or customer via direct call to that vendor, client or customer using only the telephone number provided by the vendor, client or customer before the payment or funds transfer instruction/request was received?" (Encore Fiduciary) "(5) A protocol for confirming any vendor, client or customer account information change requests (including requests to change bank account numbers, contact information or mailing addresses) via direct call to Encore Fiduciary Cyber Liability Application (2.2022) Page 4 of 10 that vendor, client or customer using only the telephone number provided by the vendor, client or customer before the change request was received?" (Encore Fiduciary) "If "Yes", does the Applicant have agreements with these vendors or other third parties which requires the other party to indemnify the Applicant for legal liability arising out the third party's loss, release, or disclosure of this information?" (Everest Insurance) "with third party services (e.g., cloud provider?" (Everest Insurance) "Does the Applicant require evidence of the errors and omissions insurance from the subcontractors?" (Everest Insurance) "Does the standard contract contain hold harmless clauses for the benefit of the Applicant?" (Everest Insurance) "Does the Applicant agree to hold harmless/indemnify others?" (Everest Insurance) "Do You provide personal identifiable, sensitive or confidential information to Your sub-contractors?" (RSA) "If Yes, Do You always obtain a hold harmless or indemnity from sub-contractors for claims that may arise from a breach of the data provided by them?" (RSA) "Do you obtain authorization prior to sharing customer data with third parties?" (Munich Re) "Do you identify & categorise third party vendors based on their access to company systems and/or data?" (Munich Re) "Is an information security assessment performed on vendors at due diligence stage with findings addressed?" (Munich Re) "Do you perform periodic audits of vendors and enforce the right to audit in contractual agreement?" (Munich Re) "Do vendor agreements require levels of security commensurate with your own information security standards?" (Munich Re) |
| A.8.1 User end point devices | ISO 27001:2022 | 18 | "Does Named Insured enable disk encryption on laptops, desktops, and other portable media devices?" (Coalition) "Does the Applicant have third party software protecting its network (e.g. antivirus, encryption, firewalls, etc.?" (Chubb) "Do you protect all company devices with anti-virus, anti-malware, and/or endpoint protection software?" (Beazley) "Do you disable macros in your office productivity software by default?" (Beazley) "Is this information encrypted while at rest?" (Hiscox) "Is this information stored on mobile computing devices, including laptops or smart phones?" (Hiscox) "The use of anti-virus software on all computer devices and networks?" (Hiscox) "in place that scan both encrypted and unencrypted data to restrict network traffic?" (Hiscox) "Are users able to store data to the hard drive of portable computers or portable media devices such as USB drives?" (AmTrust) "Does the Applicant encrypt data stored on laptop computers and portable media?" (AmTrust) "Is multi factor authentication (MFA) for personal devices required?" (Great American Insurance Group) "Do you use anti-virus software and a firewall to protect your network?" (Tokio Marine HCC) "Do you encrypt all sensitive and confidential information stored on your organization's systems and networks?" (Tokio Marine HCC) "Do you use Endpoint Detection and Response (EDR) or a Next-Generation Antivirus (NGAV) software (e.g., CrowdStrike, Cylance, Carbon Black) to secure all system endpoints?" (Tokio Marine HCC) "Does the Applicant employ an Endpoint Detection and Response solution (EDR) that covers 100% of its environment?" (AXIS Insurance) "Does the applicant encrypt all physical devices, critical data, sensitive emails?" (RLI) "What Endpoint Security Technology do you have in place?" (Corvus Insurance) "Does the organization encrypt sensitive information stored on the cloud?" (Cowbell Cyber) "Is there an Endpoint Detection and Response (EDR) tool deployed on all endpoints?" (QBE) "Does the applicant have a policy that all portable devices use full disk encryption?" (QBE) "Have you identified the paper, electronic, and other records, computing systems, and storage media including laptops, mobile phones, and portable devices that contain sensitive information?" (CNA) "Do you encrypt all sensitive records and files that are held at rest and/or transmitted across public networks, and that are to be transmitted wirelessly?" (CNA) "Do you have up-to-date versions of system security agent software (including malware, antivirus, and firewall protection) and reasonably up-to-date (within 30 days) security patches and virus definitions?" (CNA) "Do you encrypt all sensitive and confidential information stored on your organization's systems and networks?" (Encore Fiduciary) "Do you use a next-generation antivirus (NGAV) product to protect all endpoints across your enterprise?" (Encore Fiduciary) "If "Yes", complete the following: (1) Provide the name of your EDR provider: (2) Do you enforce application whitelisting/blacklisting?" (Encore Fiduciary) "(3) Is EDR deployed on 100% of endpoints?" (Encore Fiduciary) "If "No", please use the Additional Comments section to outline which assets do not have EDR, and whether any mitigating safeguards are in place for such assets. (4) Can users access the network with their own device ("Bring Your Own Device"?" (Encore Fiduciary) "If "Yes", is EDR required to be installed on these devices?" (Encore Fiduciary) "Do you roll out a hardened baseline configuration across servers, laptops, desktops and managed mobile devices?" (Encore Fiduciary) "Do you use endpoint application isolation and containment technology on all endpoints?" (Encore Fiduciary) "Can users run Microsoft Office Macro enabled documents on their system by default?" (Encore Fiduciary) "on mobile assets (e.g., laptops, phones, tablets, flash drives?" (Everest Insurance) "What anti-virus software do you use?" (RSA) "Are all mobile devices managed using a Mobile Device Management (MDM) solution?" (Munich Re) "Do you disable media ports or restrict usage to only encrypted removable storage devices?" (Munich Re) "Do you allow employees to use personal mobile devices to access company data (e.g. email?" (Munich Re) "If Yes, do you have a Bring Your Own Device (BYOD) policy in place that governs usage and controls?" (Munich Re) "Do you enforce the use of encryption of sensitive information while at rest (e.g. on premise, mobile device, Yes No cloud?" (Munich Re) "Do you update all systems including firewalls and anti-virus software at least every 30 days?" (Hiscox UK) "Do you have a policy to encrypt mobile computing devices (for example laptops, tablets, mobile telephones, PDAs) and portable data storage media (for example external drives or magnetic tapes) which hold, process, transact or store any of the personal data referred to in 1.7?" (Hiscox UK) |
| A.6.3 Information security awareness, education and training | ISO 27001:2022 | 18 | "Does Named Insured require dual control when transferring funds in excess of $25,000?" (Coalition) "Cyber Crime (Only if applying for this coverage) Does the Applicant accept funds transfer information from clients over the telephone, email, text message or similar method of communication?" (Chubb) "Does the Applicant authenticate instructions by calling the customer at a predetermined phone number or require receipt of a customer identity code?" (Chubb) "Is approval by more than one person required to initiate a wire transfer?" (Chubb) "Before acting on a transfer, do you verify the request or account detail changes using a method other than the initial contact method (Example: the initial request is received by mail and verification is done by telephone?" (Hiscox) "c. a loss of money, securities, or property due to social engineering, fraud, or other criminal acts?" (Hiscox) "Do any of the following employees at your company complete social engineering training: (1) Employees with financial or accounting responsibilities?" (Tokio Marine HCC) "Does your organization send and/or receive wire transfers?" (Tokio Marine HCC) "If "Yes", does your wire transfer authorization process include the following: (1) A wire request documentation form?" (Tokio Marine HCC) "(2) A protocol for obtaining proper written authorization for wire transfers?" (Tokio Marine HCC) "Does the Applicant employ a protocol to confirm transfer instructions including a call back, email or an alternative method of authenticating the instruction?" (AXIS Insurance) "Does the Applicant employ a protocol requiring more than one or next-level approval?" (AXIS Insurance) "Does the Applicant conduct anti-fraud training of employees at least annually?" (AXIS Insurance) "Does the applicant have formal policies and procedures in place for secure fund transfers, such as senior management approval and obtaining verbal confirmation for any fund transfer requests?" (RLI) "Prior to executing an electronic payment, does the applicant verify the validity of the funds transfer request or payment change request, with the requestor, via a separate means of communication prior to transferring funds or making payment changes?" (RLI) "Prior to executing an electronic payment, do you verify the validity of the funds transfer request or payment change request, with the requestor, via a separate means of communication prior to transferring funds or making payment changes?" (Corvus Insurance) "Does the organization hold mandatory cybersecurity training with all employees at least annually?" (Cowbell Cyber) "Does the organization authenticate funds transfer requests (e.g. by calling a customer to verify the request at a predetermined phone number?" (Cowbell Cyber) "Does the organization prevent unauthorized employees from initiating wire transfers?" (Cowbell Cyber) "ve at SS bay Security Controls Does the Applicant have controls in place which require all fund and wire transfers over $25,000 to be authorized and verified by at least two employees prior to execution?" (At-Bay) "Does the applicant allow users to report suspicious emails?" (QBE) "If yes, does the applicant conduct training on spotting and reporting such emails?" (QBE) "Exec/Employee directed request wire transfer without first validating the request with a call back to the requestor (inclusive of any owner) at a pre-determined work phone number or with a f ace to face confirmation?" (The Hanover Insurance Group) "If "No", what kind of training does the Applicant provide to help combat these types of fraudulent schemes and how often?" (The Hanover Insurance Group) "Does any applicant accept fund transfer requests from customers?" (The Hartford) "If yes, is the funds transfer instruction validated by a method other than the original means of request?" (The Hartford) "At least once a year, do you provide security awareness training for everyone who accesses your network or sensitive information in your care?" (CNA) "At time of hire and at least once a year, do you provide security awareness training for everyone who accesses your network or sensitive information in your care?" (CNA) "Do any of the following employees at your company complete social engineering training: (1) Employees with financial or accounting responsibilities?" (Encore Fiduciary) "Does your organization send and/or receive wire transfers?" (Encore Fiduciary) "If "Yes", does your wire transfer authorization process include the following: (1) A wire request documentation form?" (Encore Fiduciary) "(2) A protocol for obtaining proper written authorization for wire transfers?" (Encore Fiduciary) "Payment Card Information (PCI) (e.g., credit card, debit card numbers or other financial account numbers?" (Everest Insurance) "Does the Applicant have a formalized training program for newly hired employees?" (Everest Insurance) "Do You have a written Policy that addresses information security awareness which is communicated to all employees?" (RSA) "Which of the following information security and privacy trainings are conducted?" (Munich Re) "Are your developers regularly trained in secure programming techniques and code reviews?" (Munich Re) "Do you have a process in place to confirm that any payment requests received by email are from a known source?" (Hiscox UK) |
| CC6.6 Protection against threats from outside the system boundary | SOC 2 | 17 | "How often do you conduct pentration testing of you network architecture?" (CFC Underwriting) "Do you require Multi-Factor Authentication (MFA) for remote access to your network (both cloud-hosted and on- premises, including via Virtual Private Networks (VPNs)?" (Beazley) "Multi-factor authentication in place for remote access by employees?" (Hiscox) "Multi-factor authentication in place for remote access by third parties?" (Hiscox) "If yes, is it segregated from the network?" (Great American Insurance Group) "When did the Applicant last have a comprehensive (i.e. inclusive of vulnerability scanning and penetration testing) network security assessment completed?" (Great American Insurance Group) "Last 6 Months o Last 18 months o Last 36 months o Never Was the network security assessment completed internally?" (Great American Insurance Group) "Was the network security assessment completed by a Third Party?" (Great American Insurance Group) "Do you use anti-virus software and a firewall to protect your network?" (Tokio Marine HCC) "Do you allow remote access to your network?" (Tokio Marine HCC) "If "Yes": (1) Do you use 2-factor authentication to secure all remote access to your network?" (Tokio Marine HCC) "(2) Do you utilize IP whitelisting to further protect remote access connections?" (Tokio Marine HCC) "Have you disabled the Remote Desktop Protocol (RDP) and/or Remote Desktop Gateway (RDG) on all system endpoints and servers?" (Tokio Marine HCC) "If "No", is RDP and/or RDG protected by two-factor authentication?" (Tokio Marine HCC) "Do you use 2-factor authentication to secure remote access to your email accounts?" (Tokio Marine HCC) "Is Remote Desktop Protocol (RDP) enabled?" (AXIS Insurance) "Is RDP accessible externally?" (AXIS Insurance) "If remote access is available, does the Applicant implement MFA for all remote access?" (AXIS Insurance) "Annual network security assessments If Yes, are such assessments conducted by a third party service provider?" (Travelers) "Are all internet-accessible systems (e.g. web-, email-servers) segregated from the organization's trusted network (e.g. within a demilitarized zone (DMZ) or at a third-party service provider?" (Cowbell Cyber) "Does the applicant segment the network via Next Generation Firewalls, Virtual Local Area Networks (VLAN), demilitarized zones (DMZ), etc.?" (QBE) "How does the applicant eliminate or limit lateral movement within its network?" (QBE) "Does the applicant utilize remote desktop protocol (RDP?" (QBE) "Is this behind a Virtual Private Network (VPN) or gateway?" (QBE) "Is RDP ever exposed to the internet?" (QBE) "Has traf fic using Remote Desktop Protocol (RDP) TCP ports 3389 and Server Message Block (SMB) TCP ports 445, 135, and 139 been blocked?" (The Hanover Insurance Group) "Security & Controls MFA Is Multi-Factor Authentication (MFA) required for ALL remote access to your business' network?" (The Hartford) "If no, how is remote access to the network controlled?" (The Hartford) "Have you installed firewalls between your internal network and the Internet?" (CNA) "Within the Applicant's organization, who is responsible for network security?" (Encore Fiduciary) "If the Applicant's network security is outsourced, are you the main contact for the network security provider named in question b. above?" (Encore Fiduciary) "Do you allow remote access to your network?" (Encore Fiduciary) "If "Yes", do you use MFA to secure all remote access to your network, including any remote desktop protocol (RDP) connections?" (Encore Fiduciary) "ZScaler, Quad9, OpenDNS or the public sector PDNS to block access to known malicious websites?" (Encore Fiduciary) "Is network segmentation (e.g., firewalls, software- defined networking) used to limit movement across the network?" (Everest Insurance) "VPN, remote desktop?" (Everest Insurance) "You secure remote access (access control procedures to prevent unauthorised access) to Your network and Your data?" (RSA) "What firewall(s) do you use?" (RSA) "Is a Web Application Firewall (WAF) used to protect publicly exposed web application?" (Munich Re) "Do you ensure that all publicly facing ports are protected by a pre-configured firewall that blocks unauthorised Yes No network traffic?" (Munich Re) "Do you regularly scan publicly accessible ports and ensure unnecessary ones are locked down?" (Munich Re) "Do you allow Remote Desktop Protocol (RDP) connections?" (Munich Re) "How is web traffic filtered?" (Munich Re) "Have you configured host-based and network firewalls to disallow inbound connections by default?" (Munich Re) "Do you perform periodic reviews of firewall rules to ensure configurations are on a need-to-have basis?" (Munich Re) "Do you utilize any of the following technologies to physically or logically segregate your network?" (Munich Re) "Do you update all systems including firewalls and anti-virus software at least every 30 days?" (Hiscox UK) "Do all users with remote access provide at least two different forms of identification ('multi-factor authentication') to verify their identity prior to log-in?" (Hiscox UK) |
| CC6.7 Restricting and protecting information in transmission, movement and removal | SOC 2 | 17 | "Does Named Insured enable disk encryption on laptops, desktops, and other portable media devices?" (Coalition) "If Yes, do all of the Applicant's point-of-sale terminals accept chip-enabled cards?" (Chubb) "Is this information encrypted while at rest?" (Hiscox) "Is this information encrypted while in transit?" (Hiscox) "Is this information stored on mobile computing devices, including laptops or smart phones?" (Hiscox) "PCI DSS v.3.2 (Payment Card Industry Data Security Standard?" (Hiscox) "in place that scan both encrypted and unencrypted data to restrict network traffic?" (Hiscox) "Does the Applicant accept credit cards for goods sold or services rendered?" (AmTrust) "Does the Applicant have and enforce policies concerning the encryption of internal and external communication?" (AmTrust) "Are users able to store data to the hard drive of portable computers or portable media devices such as USB drives?" (AmTrust) "Does the Applicant encrypt data stored on laptop computers and portable media?" (AmTrust) "Is multi factor authentication (MFA) for personal devices required?" (Great American Insurance Group) "Do you encrypt all sensitive and confidential information stored on your organization's systems and networks?" (Tokio Marine HCC) "Do you process, store, or handle credit card transactions?" (Tokio Marine HCC) "Which version of PCI-DSS was the Applicant assessed against?" (AXIS Insurance) "Does the applicant encrypt all physical devices, critical data, sensitive emails?" (RLI) "Does the organization encrypt all external communications containing sensitive information?" (Cowbell Cyber) "Does the organization encrypt sensitive information stored on the cloud?" (Cowbell Cyber) "Does the Applicant store or process personal, health or credit card information of more than 500,000 individuals?" (At-Bay) "Does the applicant have a policy that all portable devices use full disk encryption?" (QBE) "at rest While electronically in transit While on mobile devices Backups & Recovery Is your business' critical data regularly backed up?" (The Hartford) "Have you identified the paper, electronic, and other records, computing systems, and storage media including laptops, mobile phones, and portable devices that contain sensitive information?" (CNA) "Do you encrypt all sensitive records and files that are held at rest and/or transmitted across public networks, and that are to be transmitted wirelessly?" (CNA) "Do you process, store or handle credit card transactions?" (Encore Fiduciary) "Do you encrypt all sensitive and confidential information stored on your organization's systems and networks?" (Encore Fiduciary) "on mobile assets (e.g., laptops, phones, tablets, flash drives?" (Everest Insurance) "Are all terminals EMV enabled?" (Everest Insurance) "Are the POS and corporate networks segregated?" (Everest Insurance) "Are all mobile devices managed using a Mobile Device Management (MDM) solution?" (Munich Re) "Do you disable media ports or restrict usage to only encrypted removable storage devices?" (Munich Re) "Do you allow employees to use personal mobile devices to access company data (e.g. email?" (Munich Re) "If Yes, do you have a Bring Your Own Device (BYOD) policy in place that governs usage and controls?" (Munich Re) "Do you enforce the use of encryption over all external communication lines (e.g. website, email, wireless?" (Munich Re) "Do you enforce the use of encryption of sensitive information while at rest (e.g. on premise, mobile device, Yes No cloud?" (Munich Re) "Do you utilize a Data Loss Prevention (DLP) product for email?" (Munich Re) "Is a DLP solution in use on endpoints, external and internal (including email) servers?" (Munich Re) "Do you accept card payments for goods and/or services?" (Munich Re) "How do you process payment card transactions?" (Munich Re) "Do you store payment card data on your network?" (Munich Re) "If Yes, is payment card data either encrypted or tokenised at all times?" (Munich Re) "Do you comply with the relevant Payment Card Industry Data Security Standard?" (Munich Re) "Has the payment processor provided you with evidence of its PCI DSS compliance?" (Munich Re) "Do you have a policy to encrypt mobile computing devices (for example laptops, tablets, mobile telephones, PDAs) and portable data storage media (for example external drives or magnetic tapes) which hold, process, transact or store any of the personal data referred to in 1.7?" (Hiscox UK) |
| A.5.20 Addressing information security within supplier agreements | ISO 27001:2022 | 17 | "Does the Applicant verify all vendor and supplier bank accounts by a direct call to the receiving bank, prior to accounts being established in the accounts payable system?" (Chubb) "Is your IT infrastructure primarily operated and managed in-house or outsourced?" (CFC Underwriting) "If it is outsourced, who do you outsource it to?" (CFC Underwriting) "When a vendor or supplier requests any change to its account details (including routing numbers and account numbers), do you confirm requested changes via an out-of-band authentication (a method other than the original means of request?" (Beazley) "Regular cyber security assessments of your systems performed by third parties?" (Hiscox) "If Yes, do you ensure these contracts contain hold harmless/indemnity clauses that benefit you?" (Hiscox) "Do you have procedures in place to vet the security and privacy controls of your vendors and outsourcers?" (Hiscox) "Do you contractually indemnify your clients for costs they incur as a result of your breach of their sensitive data?" (Hiscox) "Does the Applicant provide data processing, data storage, or data hosting services to third parties?" (AmTrust) "Do you outsource your web hosting?" (Great American Insurance Group) "Do you use a cloud provider to store data or host applications?" (Tokio Marine HCC) "(4) A protocol for confirming all payment or funds transfer instructions/requests from a new vendor, client or customer via direct call to that vendor, client or customer using only the telephone number provided by the vendor, client or customer before the payment or funds transfer instruction/request was received?" (Tokio Marine HCC) "(5) A protocol for confirming any vendor, client or customer account information change requests (including requests to change bank account numbers, contact information or mailing addresses) via direct call to that vendor, client or customer using only the telephone number provided by the vendor, client or customer before the change request was received?" (Tokio Marine HCC) "Does the Applicant have an alternative solution in the event of a failure or outage to one of these service providers?" (Travelers) "If Payment processing is answered Yes above, does the Applicant have an alternative means of processing card data in the event of an outsourced provider failure or outage?" (Travelers) "Does the applicant use a Managed Service Provider (MSP?" (RLI) "If the applicant accepts payment cards, is the applicant PCI compliant or using an outsourced payment processor that is PCI compliant?" (RLI) "If the Applicant accepts payment cards in exchange for goods or services rendered, is the Applicant or their outsourced payment processor PCI compliant?" (Corvus Insurance) "Does the organization verify vendor/supplier bank accounts before adding to their accounts payable systems?" (Cowbell Cyber) "Do agreements with third-party service providers require levels of security commensurate with the organization's information security standard?" (Cowbell Cyber) "Does the Applicant have written and documented procedures in place which are provided to Your Employees and which require Employees to authenticate all requested changes to vendor/supplier 926-1701 APP 10/21 Page 3 of 5 Cyber Advantage Pro New Business Application Or client/customer information (such as changes to bank accounts, routing numbers, contact inf ormation) with a phone call to an authorized representative of the vendor/supplier or client/customer at a pre-determined phone number on file?" (The Hanover Insurance Group) "If yes, is cybersecurity managed in-house or outsourced to a third party?" (The Hartford) "web-based email Funds Transfer Controls Do the applicants all have a dual authentication protocol for confirming all funds transfer requests or account information changes from a vendor/partner through a secondary method of communication before the account information is changed or a funds transfer request is carried out?" (The Hartford) "Do you use a cloud provider to store data or host applications?" (Encore Fiduciary) "(4) A protocol for confirming all payment or funds transfer instructions/requests from a new vendor, client or customer via direct call to that vendor, client or customer using only the telephone number provided by the vendor, client or customer before the payment or funds transfer instruction/request was received?" (Encore Fiduciary) "(5) A protocol for confirming any vendor, client or customer account information change requests (including requests to change bank account numbers, contact information or mailing addresses) via direct call to Encore Fiduciary Cyber Liability Application (2.2022) Page 4 of 10 that vendor, client or customer using only the telephone number provided by the vendor, client or customer before the change request was received?" (Encore Fiduciary) "If "Yes", does the Applicant have agreements with these vendors or other third parties which requires the other party to indemnify the Applicant for legal liability arising out the third party's loss, release, or disclosure of this information?" (Everest Insurance) "with third party services (e.g., cloud provider?" (Everest Insurance) "Does the Applicant require evidence of the errors and omissions insurance from the subcontractors?" (Everest Insurance) "Does the standard contract contain hold harmless clauses for the benefit of the Applicant?" (Everest Insurance) "Does the Applicant agree to hold harmless/indemnify others?" (Everest Insurance) "Do You provide personal identifiable, sensitive or confidential information to Your sub-contractors?" (RSA) "If Yes, Do You always obtain a hold harmless or indemnity from sub-contractors for claims that may arise from a breach of the data provided by them?" (RSA) "Do you obtain authorization prior to sharing customer data with third parties?" (Munich Re) "Is an information security assessment performed on vendors at due diligence stage with findings addressed?" (Munich Re) "Do you perform periodic audits of vendors and enforce the right to audit in contractual agreement?" (Munich Re) "Do vendor agreements require levels of security commensurate with your own information security standards?" (Munich Re) |
| A.5.21 Managing information security in the information and communication technology (ICT) supply chain | ISO 27001:2022 | 17 | "Does the Applicant verify all vendor and supplier bank accounts by a direct call to the receiving bank, prior to accounts being established in the accounts payable system?" (Chubb) "Is your IT infrastructure primarily operated and managed in-house or outsourced?" (CFC Underwriting) "If it is outsourced, who do you outsource it to?" (CFC Underwriting) "When a vendor or supplier requests any change to its account details (including routing numbers and account numbers), do you confirm requested changes via an out-of-band authentication (a method other than the original means of request?" (Beazley) "Regular cyber security assessments of your systems performed by third parties?" (Hiscox) "If Yes, do you ensure these contracts contain hold harmless/indemnity clauses that benefit you?" (Hiscox) "Do you have procedures in place to vet the security and privacy controls of your vendors and outsourcers?" (Hiscox) "Do you contractually indemnify your clients for costs they incur as a result of your breach of their sensitive data?" (Hiscox) "Does the Applicant provide data processing, data storage, or data hosting services to third parties?" (AmTrust) "Do you outsource your web hosting?" (Great American Insurance Group) "Do you use a cloud provider to store data or host applications?" (Tokio Marine HCC) "(4) A protocol for confirming all payment or funds transfer instructions/requests from a new vendor, client or customer via direct call to that vendor, client or customer using only the telephone number provided by the vendor, client or customer before the payment or funds transfer instruction/request was received?" (Tokio Marine HCC) "(5) A protocol for confirming any vendor, client or customer account information change requests (including requests to change bank account numbers, contact information or mailing addresses) via direct call to that vendor, client or customer using only the telephone number provided by the vendor, client or customer before the change request was received?" (Tokio Marine HCC) "Does the Applicant have an alternative solution in the event of a failure or outage to one of these service providers?" (Travelers) "If Payment processing is answered Yes above, does the Applicant have an alternative means of processing card data in the event of an outsourced provider failure or outage?" (Travelers) "Does the applicant use a Managed Service Provider (MSP?" (RLI) "If the applicant accepts payment cards, is the applicant PCI compliant or using an outsourced payment processor that is PCI compliant?" (RLI) "If the Applicant accepts payment cards in exchange for goods or services rendered, is the Applicant or their outsourced payment processor PCI compliant?" (Corvus Insurance) "Does the organization verify vendor/supplier bank accounts before adding to their accounts payable systems?" (Cowbell Cyber) "Do agreements with third-party service providers require levels of security commensurate with the organization's information security standard?" (Cowbell Cyber) "Does the Applicant have written and documented procedures in place which are provided to Your Employees and which require Employees to authenticate all requested changes to vendor/supplier 926-1701 APP 10/21 Page 3 of 5 Cyber Advantage Pro New Business Application Or client/customer information (such as changes to bank accounts, routing numbers, contact inf ormation) with a phone call to an authorized representative of the vendor/supplier or client/customer at a pre-determined phone number on file?" (The Hanover Insurance Group) "If yes, is cybersecurity managed in-house or outsourced to a third party?" (The Hartford) "web-based email Funds Transfer Controls Do the applicants all have a dual authentication protocol for confirming all funds transfer requests or account information changes from a vendor/partner through a secondary method of communication before the account information is changed or a funds transfer request is carried out?" (The Hartford) "Do you use a cloud provider to store data or host applications?" (Encore Fiduciary) "(4) A protocol for confirming all payment or funds transfer instructions/requests from a new vendor, client or customer via direct call to that vendor, client or customer using only the telephone number provided by the vendor, client or customer before the payment or funds transfer instruction/request was received?" (Encore Fiduciary) "(5) A protocol for confirming any vendor, client or customer account information change requests (including requests to change bank account numbers, contact information or mailing addresses) via direct call to Encore Fiduciary Cyber Liability Application (2.2022) Page 4 of 10 that vendor, client or customer using only the telephone number provided by the vendor, client or customer before the change request was received?" (Encore Fiduciary) "If "Yes", does the Applicant have agreements with these vendors or other third parties which requires the other party to indemnify the Applicant for legal liability arising out the third party's loss, release, or disclosure of this information?" (Everest Insurance) "with third party services (e.g., cloud provider?" (Everest Insurance) "Does the Applicant require evidence of the errors and omissions insurance from the subcontractors?" (Everest Insurance) "Does the standard contract contain hold harmless clauses for the benefit of the Applicant?" (Everest Insurance) "Does the Applicant agree to hold harmless/indemnify others?" (Everest Insurance) "Do You provide personal identifiable, sensitive or confidential information to Your sub-contractors?" (RSA) "If Yes, Do You always obtain a hold harmless or indemnity from sub-contractors for claims that may arise from a breach of the data provided by them?" (RSA) "Do you obtain authorization prior to sharing customer data with third parties?" (Munich Re) "Is an information security assessment performed on vendors at due diligence stage with findings addressed?" (Munich Re) "Do you perform periodic audits of vendors and enforce the right to audit in contractual agreement?" (Munich Re) "Do vendor agreements require levels of security commensurate with your own information security standards?" (Munich Re) |
| GV.SC-05 Requirements to address cybersecurity risks in supply chains are established, prioritized, and integrated into contracts and other types of agreements with suppliers and other relevant third parties | NIST CSF 2.0 | 17 | "Does the Applicant verify all vendor and supplier bank accounts by a direct call to the receiving bank, prior to accounts being established in the accounts payable system?" (Chubb) "Is your IT infrastructure primarily operated and managed in-house or outsourced?" (CFC Underwriting) "If it is outsourced, who do you outsource it to?" (CFC Underwriting) "When a vendor or supplier requests any change to its account details (including routing numbers and account numbers), do you confirm requested changes via an out-of-band authentication (a method other than the original means of request?" (Beazley) "Regular cyber security assessments of your systems performed by third parties?" (Hiscox) "If Yes, do you ensure these contracts contain hold harmless/indemnity clauses that benefit you?" (Hiscox) "Do you have procedures in place to vet the security and privacy controls of your vendors and outsourcers?" (Hiscox) "Do you contractually indemnify your clients for costs they incur as a result of your breach of their sensitive data?" (Hiscox) "Does the Applicant provide data processing, data storage, or data hosting services to third parties?" (AmTrust) "Do you outsource your web hosting?" (Great American Insurance Group) "Do you use a cloud provider to store data or host applications?" (Tokio Marine HCC) "(4) A protocol for confirming all payment or funds transfer instructions/requests from a new vendor, client or customer via direct call to that vendor, client or customer using only the telephone number provided by the vendor, client or customer before the payment or funds transfer instruction/request was received?" (Tokio Marine HCC) "(5) A protocol for confirming any vendor, client or customer account information change requests (including requests to change bank account numbers, contact information or mailing addresses) via direct call to that vendor, client or customer using only the telephone number provided by the vendor, client or customer before the change request was received?" (Tokio Marine HCC) "Does the Applicant have an alternative solution in the event of a failure or outage to one of these service providers?" (Travelers) "If Payment processing is answered Yes above, does the Applicant have an alternative means of processing card data in the event of an outsourced provider failure or outage?" (Travelers) "Does the applicant use a Managed Service Provider (MSP?" (RLI) "If the applicant accepts payment cards, is the applicant PCI compliant or using an outsourced payment processor that is PCI compliant?" (RLI) "If the Applicant accepts payment cards in exchange for goods or services rendered, is the Applicant or their outsourced payment processor PCI compliant?" (Corvus Insurance) "Does the organization verify vendor/supplier bank accounts before adding to their accounts payable systems?" (Cowbell Cyber) "Do agreements with third-party service providers require levels of security commensurate with the organization's information security standard?" (Cowbell Cyber) "Does the Applicant have written and documented procedures in place which are provided to Your Employees and which require Employees to authenticate all requested changes to vendor/supplier 926-1701 APP 10/21 Page 3 of 5 Cyber Advantage Pro New Business Application Or client/customer information (such as changes to bank accounts, routing numbers, contact inf ormation) with a phone call to an authorized representative of the vendor/supplier or client/customer at a pre-determined phone number on file?" (The Hanover Insurance Group) "If yes, is cybersecurity managed in-house or outsourced to a third party?" (The Hartford) "web-based email Funds Transfer Controls Do the applicants all have a dual authentication protocol for confirming all funds transfer requests or account information changes from a vendor/partner through a secondary method of communication before the account information is changed or a funds transfer request is carried out?" (The Hartford) "Do you use a cloud provider to store data or host applications?" (Encore Fiduciary) "(4) A protocol for confirming all payment or funds transfer instructions/requests from a new vendor, client or customer via direct call to that vendor, client or customer using only the telephone number provided by the vendor, client or customer before the payment or funds transfer instruction/request was received?" (Encore Fiduciary) "(5) A protocol for confirming any vendor, client or customer account information change requests (including requests to change bank account numbers, contact information or mailing addresses) via direct call to Encore Fiduciary Cyber Liability Application (2.2022) Page 4 of 10 that vendor, client or customer using only the telephone number provided by the vendor, client or customer before the change request was received?" (Encore Fiduciary) "If "Yes", does the Applicant have agreements with these vendors or other third parties which requires the other party to indemnify the Applicant for legal liability arising out the third party's loss, release, or disclosure of this information?" (Everest Insurance) "with third party services (e.g., cloud provider?" (Everest Insurance) "Does the Applicant require evidence of the errors and omissions insurance from the subcontractors?" (Everest Insurance) "Does the standard contract contain hold harmless clauses for the benefit of the Applicant?" (Everest Insurance) "Does the Applicant agree to hold harmless/indemnify others?" (Everest Insurance) "Do You provide personal identifiable, sensitive or confidential information to Your sub-contractors?" (RSA) "If Yes, Do You always obtain a hold harmless or indemnity from sub-contractors for claims that may arise from a breach of the data provided by them?" (RSA) "Do you obtain authorization prior to sharing customer data with third parties?" (Munich Re) "Is an information security assessment performed on vendors at due diligence stage with findings addressed?" (Munich Re) "Do you perform periodic audits of vendors and enforce the right to audit in contractual agreement?" (Munich Re) "Do vendor agreements require levels of security commensurate with your own information security standards?" (Munich Re) |
| P6.4 Privacy commitments from vendors and third parties | SOC 2 | 17 | "Does the Applicant verify all vendor and supplier bank accounts by a direct call to the receiving bank, prior to accounts being established in the accounts payable system?" (Chubb) "Is your IT infrastructure primarily operated and managed in-house or outsourced?" (CFC Underwriting) "If it is outsourced, who do you outsource it to?" (CFC Underwriting) "When a vendor or supplier requests any change to its account details (including routing numbers and account numbers), do you confirm requested changes via an out-of-band authentication (a method other than the original means of request?" (Beazley) "Regular cyber security assessments of your systems performed by third parties?" (Hiscox) "If Yes, do you ensure these contracts contain hold harmless/indemnity clauses that benefit you?" (Hiscox) "Do you have procedures in place to vet the security and privacy controls of your vendors and outsourcers?" (Hiscox) "Do you contractually indemnify your clients for costs they incur as a result of your breach of their sensitive data?" (Hiscox) "Does the Applicant provide data processing, data storage, or data hosting services to third parties?" (AmTrust) "Do you outsource your web hosting?" (Great American Insurance Group) "Do you use a cloud provider to store data or host applications?" (Tokio Marine HCC) "(4) A protocol for confirming all payment or funds transfer instructions/requests from a new vendor, client or customer via direct call to that vendor, client or customer using only the telephone number provided by the vendor, client or customer before the payment or funds transfer instruction/request was received?" (Tokio Marine HCC) "(5) A protocol for confirming any vendor, client or customer account information change requests (including requests to change bank account numbers, contact information or mailing addresses) via direct call to that vendor, client or customer using only the telephone number provided by the vendor, client or customer before the change request was received?" (Tokio Marine HCC) "Does the Applicant have an alternative solution in the event of a failure or outage to one of these service providers?" (Travelers) "If Payment processing is answered Yes above, does the Applicant have an alternative means of processing card data in the event of an outsourced provider failure or outage?" (Travelers) "Does the applicant use a Managed Service Provider (MSP?" (RLI) "If the applicant accepts payment cards, is the applicant PCI compliant or using an outsourced payment processor that is PCI compliant?" (RLI) "If the Applicant accepts payment cards in exchange for goods or services rendered, is the Applicant or their outsourced payment processor PCI compliant?" (Corvus Insurance) "Does the organization verify vendor/supplier bank accounts before adding to their accounts payable systems?" (Cowbell Cyber) "Do agreements with third-party service providers require levels of security commensurate with the organization's information security standard?" (Cowbell Cyber) "Does the Applicant have written and documented procedures in place which are provided to Your Employees and which require Employees to authenticate all requested changes to vendor/supplier 926-1701 APP 10/21 Page 3 of 5 Cyber Advantage Pro New Business Application Or client/customer information (such as changes to bank accounts, routing numbers, contact inf ormation) with a phone call to an authorized representative of the vendor/supplier or client/customer at a pre-determined phone number on file?" (The Hanover Insurance Group) "If yes, is cybersecurity managed in-house or outsourced to a third party?" (The Hartford) "web-based email Funds Transfer Controls Do the applicants all have a dual authentication protocol for confirming all funds transfer requests or account information changes from a vendor/partner through a secondary method of communication before the account information is changed or a funds transfer request is carried out?" (The Hartford) "Do you use a cloud provider to store data or host applications?" (Encore Fiduciary) "(4) A protocol for confirming all payment or funds transfer instructions/requests from a new vendor, client or customer via direct call to that vendor, client or customer using only the telephone number provided by the vendor, client or customer before the payment or funds transfer instruction/request was received?" (Encore Fiduciary) "(5) A protocol for confirming any vendor, client or customer account information change requests (including requests to change bank account numbers, contact information or mailing addresses) via direct call to Encore Fiduciary Cyber Liability Application (2.2022) Page 4 of 10 that vendor, client or customer using only the telephone number provided by the vendor, client or customer before the change request was received?" (Encore Fiduciary) "If "Yes", does the Applicant have agreements with these vendors or other third parties which requires the other party to indemnify the Applicant for legal liability arising out the third party's loss, release, or disclosure of this information?" (Everest Insurance) "with third party services (e.g., cloud provider?" (Everest Insurance) "Does the Applicant require evidence of the errors and omissions insurance from the subcontractors?" (Everest Insurance) "Does the standard contract contain hold harmless clauses for the benefit of the Applicant?" (Everest Insurance) "Does the Applicant agree to hold harmless/indemnify others?" (Everest Insurance) "Do You provide personal identifiable, sensitive or confidential information to Your sub-contractors?" (RSA) "If Yes, Do You always obtain a hold harmless or indemnity from sub-contractors for claims that may arise from a breach of the data provided by them?" (RSA) "Do you obtain authorization prior to sharing customer data with third parties?" (Munich Re) "Is an information security assessment performed on vendors at due diligence stage with findings addressed?" (Munich Re) "Do you perform periodic audits of vendors and enforce the right to audit in contractual agreement?" (Munich Re) "Do vendor agreements require levels of security commensurate with your own information security standards?" (Munich Re) |
| A.8.7 Protection against malware | ISO 27001:2022 | 16 | "Does the Applicant have third party software protecting its network (e.g. antivirus, encryption, firewalls, etc.?" (Chubb) "What security controls do you have in place for incoming email?" (Beazley) "How often do you conduct interactive social engineering (i.e., phishing) training?" (Beazley) "Do you protect all company devices with anti-virus, anti-malware, and/or endpoint protection software?" (Beazley) "Do you use the Microsoft 365 Defender add-on or an equivalent cybersecurity product with advanced threat hunting to protect against phishing and business email compromise?" (Beazley) "Do you disable macros in your office productivity software by default?" (Beazley) "Are employees who are responsible for disbursing or transmitting funds provided anti-fraud training, including detection of social engineering, phishing, business email compromise and other scams, on at least an annual basis?" (Beazley) "The use of anti-virus software on all computer devices and networks?" (Hiscox) "in place to ensure compliance with the Telephone Consumer Protection Act, anti-SPAM statutes, and any other consumer protection act?" (Hiscox) "Are Sender Policy Framework (SPF), Domain-based Message Authentication Reporting and Compliance (DMARC) or Domain Keys Identified Mail (DKIM) in place?" (Great American Insurance Group) "Do you use anti-virus software and a firewall to protect your network?" (Tokio Marine HCC) "Do you use Endpoint Detection and Response (EDR) or a Next-Generation Antivirus (NGAV) software (e.g., CrowdStrike, Cylance, Carbon Black) to secure all system endpoints?" (Tokio Marine HCC) "Do you use an email filtering solution designed to prevent phishing or ransomware attacks (in addition to any filtering solution(s) provided by your email provider?" (Tokio Marine HCC) "If "Yes" to question 7.a.(1) or 7.a.(2) above, does your social engineering training include phishing simulation?" (Tokio Marine HCC) "Does the Applicant employ an Endpoint Detection and Response solution (EDR) that covers 100% of its environment?" (AXIS Insurance) "Does the Applicant employ any of the following SPF DKIM DMARC solutions?" (AXIS Insurance) "Does the Applicant conduct mandatory information security, phishing and privacy training for employees and contractors at least quarterly?" (AXIS Insurance) "Are Phishing Simulations conducted for all employees?" (AXIS Insurance) "Does the Applicant have a report phishing email add-in enabled for all email users?" (AXIS Insurance) "Does the company scan email for potentially malicious attachments and / or links?" (RLI) "Do you have email filtering in place?" (Corvus Insurance) "What Endpoint Security Technology do you have in place?" (Corvus Insurance) "Do you conduct employee security training or phishing training, for all employees, at least annually?" (Corvus Insurance) "Phishing a. How often does the applicant use simulated phishing attacks to test employees?" (QBE) "Does the applicant flag external emails?" (QBE) "Email filtering Does the applicant utilize email filtering protocols such as Domain-based Message Authentication, Reporting and Conformance (DMARC), DomainKeys Identified Mail (DKIM), or Sender Policy Framework (SPF?" (QBE) "Is there an Endpoint Detection and Response (EDR) tool deployed on all endpoints?" (QBE) "Is virus/malware scanning used on the backups?" (QBE) "Detect and identify social engineering/phishing scams where a f raudulent email or phone call f rom purported vendor or client is received, requesting their vendor or client bank account inf ormation be changed?" (The Hanover Insurance Group) "Detect and identify social engineering/phishing scams where a f raudulent email or phone call f rom a purported owner or employee of the Applicant is received, requesting a wire transfer be made on their behalf?" (The Hanover Insurance Group) "Is there an Endpoint Detection and Response (EDR) or Managed Detection and Response (MDR) product in place?" (The Hartford) "for malicious attachments Screening for malicious links Tagging emails from external senders How often is Antiphishing and Cybersecurity Awareness training conducted for employees?" (The Hartford) "Do you have up-to-date versions of system security agent software (including malware, antivirus, and firewall protection) and reasonably up-to-date (within 30 days) security patches and virus definitions?" (CNA) "Do you pre-screen emails for potentially malicious attachments and links?" (Encore Fiduciary) "If "Yes", complete the following: (1) Provide the name of your email pre-screen provider: (2) Do you have the capability to automatically detonate and evaluate attachments in a sandbox to determine if they are malicious prior to delivery to the end-user?" (Encore Fiduciary) "Have you implemented any of the following to protect against phishing messages?" (Encore Fiduciary) "Sender Policy Framework (SPF) Domain Keys Identified Mail (DKIM) Domain-based Message Authentication, Reporting & Conformance (DMARC) None of the above d.Can your users access email through a web application or a non-corporate device?" (Encore Fiduciary) "If "Yes", do you use the Office 365 Advanced Threat Protection add-on?" (Encore Fiduciary) "Do you use a next-generation antivirus (NGAV) product to protect all endpoints across your enterprise?" (Encore Fiduciary) "Do you use an endpoint detection and response (EDR) tool that includes centralized monitoring and logging of all endpoint activity across your enterprise?" (Encore Fiduciary) "If "Yes", complete the following: (1) Provide the name of your EDR provider: (2) Do you enforce application whitelisting/blacklisting?" (Encore Fiduciary) "(3) Is EDR deployed on 100% of endpoints?" (Encore Fiduciary) "If "No", please use the Additional Comments section to outline which assets do not have EDR, and whether any mitigating safeguards are in place for such assets. (4) Can users access the network with their own device ("Bring Your Own Device"?" (Encore Fiduciary) "If "Yes", is EDR required to be installed on these devices?" (Encore Fiduciary) "Do you use endpoint application isolation and containment technology on all endpoints?" (Encore Fiduciary) "Can users run Microsoft Office Macro enabled documents on their system by default?" (Encore Fiduciary) "If "Yes" to question 9.a.(1) or 9.a.(2) above, does your social engineering training include phishing simulation?" (Encore Fiduciary) "What anti-virus software do you use?" (RSA) "Do you conduct employee phishing campaigns?" (Munich Re) "How often are phishing campaigns conducted?" (Munich Re) "Do you mandate additional training to those employees who fail to acknowledge phishing emails?" (Munich Re) "Do you implement any of the following controls to protect against malicious emails?" (Munich Re) "Do you scan incoming emails for malicious attachments and/or links?" (Munich Re) "Do you have the ability to automatically quarantine, detonate and evaluate attachments?" (Munich Re) "Are blocked emails classed as incidents and remediated?" (Munich Re) "Do you update all systems including firewalls and anti-virus software at least every 30 days?" (Hiscox UK) |
| CC6.8 Preventing and detecting unauthorised or malicious software | SOC 2 | 16 | "Does the Applicant have third party software protecting its network (e.g. antivirus, encryption, firewalls, etc.?" (Chubb) "What security controls do you have in place for incoming email?" (Beazley) "How often do you conduct interactive social engineering (i.e., phishing) training?" (Beazley) "Do you protect all company devices with anti-virus, anti-malware, and/or endpoint protection software?" (Beazley) "Do you use the Microsoft 365 Defender add-on or an equivalent cybersecurity product with advanced threat hunting to protect against phishing and business email compromise?" (Beazley) "Do you disable macros in your office productivity software by default?" (Beazley) "Are employees who are responsible for disbursing or transmitting funds provided anti-fraud training, including detection of social engineering, phishing, business email compromise and other scams, on at least an annual basis?" (Beazley) "The use of anti-virus software on all computer devices and networks?" (Hiscox) "in place to ensure compliance with the Telephone Consumer Protection Act, anti-SPAM statutes, and any other consumer protection act?" (Hiscox) "Are Sender Policy Framework (SPF), Domain-based Message Authentication Reporting and Compliance (DMARC) or Domain Keys Identified Mail (DKIM) in place?" (Great American Insurance Group) "Do you use anti-virus software and a firewall to protect your network?" (Tokio Marine HCC) "Do you use Endpoint Detection and Response (EDR) or a Next-Generation Antivirus (NGAV) software (e.g., CrowdStrike, Cylance, Carbon Black) to secure all system endpoints?" (Tokio Marine HCC) "Do you use an email filtering solution designed to prevent phishing or ransomware attacks (in addition to any filtering solution(s) provided by your email provider?" (Tokio Marine HCC) "If "Yes" to question 7.a.(1) or 7.a.(2) above, does your social engineering training include phishing simulation?" (Tokio Marine HCC) "Does the Applicant employ an Endpoint Detection and Response solution (EDR) that covers 100% of its environment?" (AXIS Insurance) "Does the Applicant employ any of the following SPF DKIM DMARC solutions?" (AXIS Insurance) "Does the Applicant conduct mandatory information security, phishing and privacy training for employees and contractors at least quarterly?" (AXIS Insurance) "Are Phishing Simulations conducted for all employees?" (AXIS Insurance) "Does the Applicant have a report phishing email add-in enabled for all email users?" (AXIS Insurance) "Does the company scan email for potentially malicious attachments and / or links?" (RLI) "Do you have email filtering in place?" (Corvus Insurance) "What Endpoint Security Technology do you have in place?" (Corvus Insurance) "Do you conduct employee security training or phishing training, for all employees, at least annually?" (Corvus Insurance) "Phishing a. How often does the applicant use simulated phishing attacks to test employees?" (QBE) "Does the applicant flag external emails?" (QBE) "Email filtering Does the applicant utilize email filtering protocols such as Domain-based Message Authentication, Reporting and Conformance (DMARC), DomainKeys Identified Mail (DKIM), or Sender Policy Framework (SPF?" (QBE) "Is there an Endpoint Detection and Response (EDR) tool deployed on all endpoints?" (QBE) "Detect and identify social engineering/phishing scams where a f raudulent email or phone call f rom purported vendor or client is received, requesting their vendor or client bank account inf ormation be changed?" (The Hanover Insurance Group) "Detect and identify social engineering/phishing scams where a f raudulent email or phone call f rom a purported owner or employee of the Applicant is received, requesting a wire transfer be made on their behalf?" (The Hanover Insurance Group) "for malicious attachments Screening for malicious links Tagging emails from external senders How often is Antiphishing and Cybersecurity Awareness training conducted for employees?" (The Hartford) "Do you have up-to-date versions of system security agent software (including malware, antivirus, and firewall protection) and reasonably up-to-date (within 30 days) security patches and virus definitions?" (CNA) "Do you pre-screen emails for potentially malicious attachments and links?" (Encore Fiduciary) "If "Yes", complete the following: (1) Provide the name of your email pre-screen provider: (2) Do you have the capability to automatically detonate and evaluate attachments in a sandbox to determine if they are malicious prior to delivery to the end-user?" (Encore Fiduciary) "Have you implemented any of the following to protect against phishing messages?" (Encore Fiduciary) "Sender Policy Framework (SPF) Domain Keys Identified Mail (DKIM) Domain-based Message Authentication, Reporting & Conformance (DMARC) None of the above d.Can your users access email through a web application or a non-corporate device?" (Encore Fiduciary) "If "Yes", do you use the Office 365 Advanced Threat Protection add-on?" (Encore Fiduciary) "Do you use a next-generation antivirus (NGAV) product to protect all endpoints across your enterprise?" (Encore Fiduciary) "If "Yes", complete the following: (1) Provide the name of your EDR provider: (2) Do you enforce application whitelisting/blacklisting?" (Encore Fiduciary) "(3) Is EDR deployed on 100% of endpoints?" (Encore Fiduciary) "If "No", please use the Additional Comments section to outline which assets do not have EDR, and whether any mitigating safeguards are in place for such assets. (4) Can users access the network with their own device ("Bring Your Own Device"?" (Encore Fiduciary) "If "Yes", is EDR required to be installed on these devices?" (Encore Fiduciary) "Do you use endpoint application isolation and containment technology on all endpoints?" (Encore Fiduciary) "Can users run Microsoft Office Macro enabled documents on their system by default?" (Encore Fiduciary) "If "Yes" to question 9.a.(1) or 9.a.(2) above, does your social engineering training include phishing simulation?" (Encore Fiduciary) "What anti-virus software do you use?" (RSA) "Do you conduct employee phishing campaigns?" (Munich Re) "How often are phishing campaigns conducted?" (Munich Re) "Do you mandate additional training to those employees who fail to acknowledge phishing emails?" (Munich Re) "Do you implement any of the following controls to protect against malicious emails?" (Munich Re) "Do you scan incoming emails for malicious attachments and/or links?" (Munich Re) "Do you have the ability to automatically quarantine, detonate and evaluate attachments?" (Munich Re) "Are blocked emails classed as incidents and remediated?" (Munich Re) "Do you update all systems including firewalls and anti-virus software at least every 30 days?" (Hiscox UK) |
| CC7.1 Detecting configuration changes and new vulnerabilities | SOC 2 | 15 | "How often do you patch your operating sytems?" (CFC Underwriting) "How often do you conduct vulnerability scanning of your network perimeter?" (CFC Underwriting) "How often do you conduct pentration testing of you network architecture?" (CFC Underwriting) "Do you, or an outsourced service provider on your behalf, actively manage and install critical patches across your internet-facing systems?" (Beazley) "Do you use the Microsoft 365 Defender add-on or an equivalent cybersecurity product with advanced threat hunting to protect against phishing and business email compromise?" (Beazley) "What security solutions do you use to prevent or detect malicious activity on your network?" (Beazley) "Regular updating and patching of critical systems and software in a timely manner?" (Hiscox) "1) If stored offsite, are transportation logs maintained?" (AmTrust) "Password/passcode protected Encryption Traditional or next generation firewalls enabled/turned on Traditional or next generation antivirus products on all endpoints Endpoint Detection and Response (EDR) 24/7/365 on all devices If yes to EDR, Who is your provider?" (Great American Insurance Group) "Managed Detection and Response (MDR) If yes to MDR, Who is your provider?" (Great American Insurance Group) "Security Information and Event Management (SIEM) If yes to SIEM, Who is your provider?" (Great American Insurance Group) "Are there any end-of-life or end-of-support software in use?" (Great American Insurance Group) "Is an email filtering tool in place to detect and/or block SPAM, malicious links, and attachments?" (Great American Insurance Group) "Are firewalls rules and alerts regularly reviewed?" (Great American Insurance Group) "When did the Applicant last have a comprehensive (i.e. inclusive of vulnerability scanning and penetration testing) network security assessment completed?" (Great American Insurance Group) "Last 6 Months o Last 18 months o Last 36 months o Never Was the network security assessment completed internally?" (Great American Insurance Group) "Was the network security assessment completed by a Third Party?" (Great American Insurance Group) "Does the Applicant employ any Intrusion Detection and Prevention solutions (IDP), e.g. anti- virus software?" (AXIS Insurance) "What is the Applicant's Critical Patching Target?" (AXIS Insurance) "Does the Applicant maintain a Normal Vulnerability Management patching target within 30 days?" (AXIS Insurance) "Does the Applicant have a Security Operations Center (SOC) or utilize a Managed Security Service Provider?" (AXIS Insurance) "If yes, is it monitored 24/7?" (AXIS Insurance) "Does the Applicant have any End-of-Life software or systems present in its environment?" (AXIS Insurance) "Are these policies, practices and solutions applied to the Firewalls Intrusion detection and following?" (AXIS Insurance) "Is the local logging performed on a per-host basis?" (AXIS Insurance) "Are local logs centralized into a log management system?" (AXIS Insurance) "How frequently are logs audited?" (AXIS Insurance) "How long are audit logs maintained?" (AXIS Insurance) "In response to any of these matters, has the Applicant commenced or completed any change to its network and information security and handling practices, or other changes, to remediate the effects of the matter or remove a vulnerability that gave rise to the matter?" (AXIS Insurance) "A process in place to regularly download, test, and install patches If Yes, is this process automated?" (Travelers) "If Yes, are critical patches installed within 30 days of release?" (Travelers) "Annual penetration testing If Yes, is such testing conducted by a third party service provider?" (Travelers) "Annual network security assessments If Yes, are such assessments conducted by a third party service provider?" (Travelers) "Do you have an Intrusion Detection System (IDS) or Intrusion Prevention System (IPS) in place?" (Corvus Insurance) "Do you conduct penetration testing of your network at least annually?" (Corvus Insurance) "How often does the organization apply updates to critical IT-systems and applications ("security patching"?" (Cowbell Cyber) "Does the applicant track compliance for deploying critical patches?" (QBE) "Does the applicant have a policy (to enforce) when patches must be deployed?" (QBE) "If yes, what is the timeframe critical patches must be deployed?" (QBE) "Does the applicant implement a Security Information and Event management (SIEM) tool to monitor activity logs and centralize tools?" (QBE) "Does the applicant monitor for unusual or suspicious network activity?" (QBE) "Does the applicant have any end-of-life (EOL) software or applications currently running on the network?" (QBE) "If yes, how is that patched and managed?" (QBE) "Does the applicant conduct full vulnerability scans across the entirety of its network?" (QBE) "Cybersecurity Function & Contact Person Is there a dedicated cybersecurity team monitoring the network for your business?" (The Hartford) "Is there an Endpoint Detection and Response (EDR) or Managed Detection and Response (MDR) product in place?" (The Hartford) "Do you check for security patches to your systems at least weekly and implement them within 30 days?" (CNA) "Do you have up-to-date versions of system security agent software (including malware, antivirus, and firewall protection) and reasonably up-to-date (within 30 days) security patches and virus definitions?" (CNA) "Do you have monitoring in place to alert you to the occurrence of unauthorized use of or access to sensitive information?" (CNA) "Do you tag external emails to alert employees that the message originated from outside the organization?" (Encore Fiduciary) "Do you use an endpoint detection and response (EDR) tool that includes centralized monitoring and logging of all endpoint activity across your enterprise?" (Encore Fiduciary) "How frequently do you install critical and high severity patches across your enterprise?" (Encore Fiduciary) "Do you have any end of life or end of support software?" (Encore Fiduciary) "Do you utilize a Security Information and Event Management system (SIEM?" (Encore Fiduciary) "Do you utilize a Security Operations Center (SOC?" (Encore Fiduciary) "If "Yes", complete the following: (1) Is your SOC monitored 24 hours a day, 7 days a week?" (Encore Fiduciary) "Do you use a vulnerability management tool?" (Encore Fiduciary) "If "Yes", complete the following: (1) Provide the name of your provider: (2) What is your patching cadence?" (Encore Fiduciary) "Vulnerability Assessment and Remediation Does the Applicant have a formal process in place to detect software/application vulnerabilities and automatically push critical updates and patches to all computing resources?" (Everest Insurance) "If "Yes", is the length of time required for the deployment of critical updates and patches less than or equal to 2 weeks?" (Everest Insurance) "Are your audit logs immutable?" (Munich Re) "Do you regularly conduct vulnerability scanning across your internal and external-facing assets?" (Munich Re) "Are logins to web-based email monitored with alerts for suspicious activity implemented?" (Munich Re) "Do you tag external emails to alert employees that the message originated from outside the organization?" (Munich Re) "Do you conduct security tests or code analysis during system development, before go-live and after N/A Yes No system changes take place?" (Munich Re) "Do you ensure that any acquired applications/functions and code is free from known vulnerabilities?" (Munich Re) "Do you restrict vendor access to limited time-windows and monitor their access to your network?" (Munich Re) "Are you utilising a Security Incident Event Management (SIEM) solution?" (Munich Re) "How are security incident alerts monitored and responded to?" (Munich Re) "Is the full scope of the SOC operating on a 24/7/365 basis?" (Munich Re) "Does your 24/7/365 service have the authority to contain/isolate systems following a suspicious event?" (Munich Re) |
| A.5.15 Access control | ISO 27001:2022 | 15 | "If Yes, do all of the Applicant's point-of-sale terminals accept chip-enabled cards?" (Chubb) "Do you require MFA for access to web-based email?" (Beazley) "If No, is such information stored on a segregated server with role-based access controls?" (Hiscox) "PCI DSS v.3.2 (Payment Card Industry Data Security Standard?" (Hiscox) "in place with all third parties that have access to sensitive information, including business associate agreements?" (Hiscox) "Employee access to systems and data is limited to only what they need to do their job?" (Hiscox) "Employee access to systems and data is cut when employees leave the organization?" (Hiscox) "Does the Applicant terminate all computer access and user accounts as part of the regular exit process when an employee leaves the company or when a third party contractor no longer provides the contracted services?" (AmTrust) "Does the Applicant accept credit cards for goods sold or services rendered?" (AmTrust) "Which controls are in place to protect confidential, sensitive, or otherwise regulated data?" (Great American Insurance Group) "Are firewalls configured according to the principles of least privileges?" (Great American Insurance Group) "(2) Access control with role-based assignments?" (Tokio Marine HCC) "Do you process, store, or handle credit card transactions?" (Tokio Marine HCC) "(b) segregated with 2-factor authentication access control?" (Tokio Marine HCC) "(3) A separation of authority protocol?" (Tokio Marine HCC) "Which version of PCI-DSS was the Applicant assessed against?" (AXIS Insurance) "How are privileged accounts secured and managed?" (Corvus Insurance) "What security controls are in place to protect against unauthorized access to sensitive and confidential data?" (Corvus Insurance) "Does the Applicant store or process personal, health or credit card information of more than 500,000 individuals?" (At-Bay) "a. Do the applicant's privileged users require more extensive training relating to phishing attacks?" (QBE) "Does the applicant utilize a Privileged Access Management (PAM) solution?" (QBE) "If not utilizing a PAM solution, what compensating controls exist to protect privileged accounts?" (QBE) "Does the applicant restrict Local Admin rights?" (QBE) "Do you set up a separate account for each user (including any contractors needing access?" (CNA) "Do you physically and electronically limit access to sensitive information on a need –to-know basis and revoke access privileges upon a reduction in an individual's need to know?" (CNA) "Do you have monitoring in place to alert you to the occurrence of unauthorized use of or access to sensitive information?" (CNA) "Do you physically and electronically limit access to sensitive information on a need-to-know basis and revoke access privileges upon a reduction in an individual's need to know?" (CNA) "Do you process, store or handle credit card transactions?" (Encore Fiduciary) "(2) Access control with role-based assignments?" (Encore Fiduciary) "Do you manage privileged accounts using privileged account management software (PAM) (e.g., CyberArk, BeyondTrust, etc.?" (Encore Fiduciary) "Do you actively monitor all administrator access for unusual behavior patterns?" (Encore Fiduciary) "Do non-IT users have local administration rights on their laptop / desktop?" (Encore Fiduciary) "(3) A separation of authority protocol?" (Encore Fiduciary) "Does the Applicant restrict access based on job function and responsibilities?" (Everest Insurance) "Are all terminals EMV enabled?" (Everest Insurance) "Are the POS and corporate networks segregated?" (Everest Insurance) "Is access to the internet from terminals restricted for employees?" (Everest Insurance) "The backup of Your Critical Data is stored in a secure locked location with access restricted to authorised personnel only?" (RSA) "You enforce a policy of auditing of managing computer and user accounts?" (RSA) "Do you perform background checks on employees & contractors who have access to sensitive information?" (Munich Re) "Do you terminate user access rights as part of the employee exit process?" (Munich Re) "Do you restrict user access (employees, contractors etc.) on a business need-to-know & least-privilege basis?" (Munich Re) "Do you have a central Identity & Access Management ("IAM") system for assigning and revoking access rights?" (Munich Re) "Do you have a formal process in place for assigning and revoking user accounts and access rights?" (Munich Re) "Do assets owners review access rights at least annually?" (Munich Re) "If Yes, which of the following accounts are enrolled into the PAM tool?" (Munich Re) "Which of the following features are enabled on the PAM tool?" (Munich Re) "Is logging and alerting configured for all privileged account activity?" (Munich Re) "Are domain admin accounts limited to administrative functions only?" (Munich Re) "Please provide the number of service accounts in the domain admin group?" (Munich Re) "Do you configure service accounts using the principle of least privilege?" (Munich Re) "Do you configure service accounts to deny interactive log-ins?" (Munich Re) "Do you log the activity of service accounts that are able to override system or application controls (e.g. elevation Yes No of privileges, lateral movement etc.?" (Munich Re) "Do you prohibit local admin rights on workstations for users?" (Munich Re) "Is web-based email available to employees?" (Munich Re) "Is multi-factor authentication (MFA) in place for web-based email logins?" (Munich Re) "Do you periodically review and update vendor access rights?" (Munich Re) "Do you restrict vendor access to limited time-windows and monitor their access to your network?" (Munich Re) "Do you accept card payments for goods and/or services?" (Munich Re) "How do you process payment card transactions?" (Munich Re) "Do you store payment card data on your network?" (Munich Re) "If Yes, is payment card data either encrypted or tokenised at all times?" (Munich Re) "Do you comply with the relevant Payment Card Industry Data Security Standard?" (Munich Re) "Has the payment processor provided you with evidence of its PCI DSS compliance?" (Munich Re) |
| DE.CM-01 Networks and network services are monitored to find potentially adverse events | NIST CSF 2.0 | 15 | "What security solutions do you use to prevent or detect malicious activity on your network?" (Beazley) "1) If stored offsite, are transportation logs maintained?" (AmTrust) "Managed Detection and Response (MDR) If yes to MDR, Who is your provider?" (Great American Insurance Group) "Security Information and Event Management (SIEM) If yes to SIEM, Who is your provider?" (Great American Insurance Group) "If yes, is it segregated from the network?" (Great American Insurance Group) "Is an email filtering tool in place to detect and/or block SPAM, malicious links, and attachments?" (Great American Insurance Group) "Are firewalls rules and alerts regularly reviewed?" (Great American Insurance Group) "(2) Do you utilize IP whitelisting to further protect remote access connections?" (Tokio Marine HCC) "Does the Applicant employ any Intrusion Detection and Prevention solutions (IDP), e.g. anti- virus software?" (AXIS Insurance) "Does the Applicant have a Security Operations Center (SOC) or utilize a Managed Security Service Provider?" (AXIS Insurance) "If yes, is it monitored 24/7?" (AXIS Insurance) "Are these policies, practices and solutions applied to the Firewalls Intrusion detection and following?" (AXIS Insurance) "Is the local logging performed on a per-host basis?" (AXIS Insurance) "Are local logs centralized into a log management system?" (AXIS Insurance) "How frequently are logs audited?" (AXIS Insurance) "How long are audit logs maintained?" (AXIS Insurance) "Do you have an Intrusion Detection System (IDS) or Intrusion Prevention System (IPS) in place?" (Corvus Insurance) "Are all internet-accessible systems (e.g. web-, email-servers) segregated from the organization's trusted network (e.g. within a demilitarized zone (DMZ) or at a third-party service provider?" (Cowbell Cyber) "Does the applicant segment the network via Next Generation Firewalls, Virtual Local Area Networks (VLAN), demilitarized zones (DMZ), etc.?" (QBE) "How does the applicant eliminate or limit lateral movement within its network?" (QBE) "Does the applicant implement a Security Information and Event management (SIEM) tool to monitor activity logs and centralize tools?" (QBE) "Does the applicant monitor for unusual or suspicious network activity?" (QBE) "Has traf fic using Remote Desktop Protocol (RDP) TCP ports 3389 and Server Message Block (SMB) TCP ports 445, 135, and 139 been blocked?" (The Hanover Insurance Group) "Cybersecurity Function & Contact Person Is there a dedicated cybersecurity team monitoring the network for your business?" (The Hartford) "Is there an Endpoint Detection and Response (EDR) or Managed Detection and Response (MDR) product in place?" (The Hartford) "Have you installed firewalls between your internal network and the Internet?" (CNA) "Do you have monitoring in place to alert you to the occurrence of unauthorized use of or access to sensitive information?" (CNA) "Within the Applicant's organization, who is responsible for network security?" (Encore Fiduciary) "If the Applicant's network security is outsourced, are you the main contact for the network security provider named in question b. above?" (Encore Fiduciary) "Do you tag external emails to alert employees that the message originated from outside the organization?" (Encore Fiduciary) "Do you use an endpoint detection and response (EDR) tool that includes centralized monitoring and logging of all endpoint activity across your enterprise?" (Encore Fiduciary) "Do you actively monitor all administrator access for unusual behavior patterns?" (Encore Fiduciary) "ZScaler, Quad9, OpenDNS or the public sector PDNS to block access to known malicious websites?" (Encore Fiduciary) "Do you utilize a Security Information and Event Management system (SIEM?" (Encore Fiduciary) "Do you utilize a Security Operations Center (SOC?" (Encore Fiduciary) "If "Yes", complete the following: (1) Is your SOC monitored 24 hours a day, 7 days a week?" (Encore Fiduciary) "Is network segmentation (e.g., firewalls, software- defined networking) used to limit movement across the network?" (Everest Insurance) "What firewall(s) do you use?" (RSA) "Is a Web Application Firewall (WAF) used to protect publicly exposed web application?" (Munich Re) "Do you ensure that all publicly facing ports are protected by a pre-configured firewall that blocks unauthorised Yes No network traffic?" (Munich Re) "Do you regularly scan publicly accessible ports and ensure unnecessary ones are locked down?" (Munich Re) "Is logging and alerting configured for all privileged account activity?" (Munich Re) "Do you configure service accounts to deny interactive log-ins?" (Munich Re) "Do you log the activity of service accounts that are able to override system or application controls (e.g. elevation Yes No of privileges, lateral movement etc.?" (Munich Re) "Are your audit logs immutable?" (Munich Re) "Are logins to web-based email monitored with alerts for suspicious activity implemented?" (Munich Re) "Do you tag external emails to alert employees that the message originated from outside the organization?" (Munich Re) "How is web traffic filtered?" (Munich Re) "Have you configured host-based and network firewalls to disallow inbound connections by default?" (Munich Re) "Do you perform periodic reviews of firewall rules to ensure configurations are on a need-to-have basis?" (Munich Re) "Do you utilize any of the following technologies to physically or logically segregate your network?" (Munich Re) "Do you restrict vendor access to limited time-windows and monitor their access to your network?" (Munich Re) "Are you utilising a Security Incident Event Management (SIEM) solution?" (Munich Re) "How are security incident alerts monitored and responded to?" (Munich Re) "Is the full scope of the SOC operating on a 24/7/365 basis?" (Munich Re) "Does your 24/7/365 service have the authority to contain/isolate systems following a suspicious event?" (Munich Re) |
| PR.PS-05 Installation and execution of unauthorized software are prevented | NIST CSF 2.0 | 15 | "What security controls do you have in place for incoming email?" (Beazley) "How often do you conduct interactive social engineering (i.e., phishing) training?" (Beazley) "Do you protect all company devices with anti-virus, anti-malware, and/or endpoint protection software?" (Beazley) "Do you use the Microsoft 365 Defender add-on or an equivalent cybersecurity product with advanced threat hunting to protect against phishing and business email compromise?" (Beazley) "Do you disable macros in your office productivity software by default?" (Beazley) "Are employees who are responsible for disbursing or transmitting funds provided anti-fraud training, including detection of social engineering, phishing, business email compromise and other scams, on at least an annual basis?" (Beazley) "The use of anti-virus software on all computer devices and networks?" (Hiscox) "in place to ensure compliance with the Telephone Consumer Protection Act, anti-SPAM statutes, and any other consumer protection act?" (Hiscox) "Are Sender Policy Framework (SPF), Domain-based Message Authentication Reporting and Compliance (DMARC) or Domain Keys Identified Mail (DKIM) in place?" (Great American Insurance Group) "Do you use anti-virus software and a firewall to protect your network?" (Tokio Marine HCC) "Do you use Endpoint Detection and Response (EDR) or a Next-Generation Antivirus (NGAV) software (e.g., CrowdStrike, Cylance, Carbon Black) to secure all system endpoints?" (Tokio Marine HCC) "Do you use an email filtering solution designed to prevent phishing or ransomware attacks (in addition to any filtering solution(s) provided by your email provider?" (Tokio Marine HCC) "If "Yes" to question 7.a.(1) or 7.a.(2) above, does your social engineering training include phishing simulation?" (Tokio Marine HCC) "Does the Applicant employ an Endpoint Detection and Response solution (EDR) that covers 100% of its environment?" (AXIS Insurance) "Does the Applicant employ any of the following SPF DKIM DMARC solutions?" (AXIS Insurance) "Does the Applicant conduct mandatory information security, phishing and privacy training for employees and contractors at least quarterly?" (AXIS Insurance) "Are Phishing Simulations conducted for all employees?" (AXIS Insurance) "Does the Applicant have a report phishing email add-in enabled for all email users?" (AXIS Insurance) "Does the company scan email for potentially malicious attachments and / or links?" (RLI) "Do you have email filtering in place?" (Corvus Insurance) "What Endpoint Security Technology do you have in place?" (Corvus Insurance) "Do you conduct employee security training or phishing training, for all employees, at least annually?" (Corvus Insurance) "Phishing a. How often does the applicant use simulated phishing attacks to test employees?" (QBE) "a. Do the applicant's privileged users require more extensive training relating to phishing attacks?" (QBE) "Does the applicant flag external emails?" (QBE) "Email filtering Does the applicant utilize email filtering protocols such as Domain-based Message Authentication, Reporting and Conformance (DMARC), DomainKeys Identified Mail (DKIM), or Sender Policy Framework (SPF?" (QBE) "Is there an Endpoint Detection and Response (EDR) tool deployed on all endpoints?" (QBE) "Is virus/malware scanning used on the backups?" (QBE) "Detect and identify social engineering/phishing scams where a f raudulent email or phone call f rom purported vendor or client is received, requesting their vendor or client bank account inf ormation be changed?" (The Hanover Insurance Group) "Detect and identify social engineering/phishing scams where a f raudulent email or phone call f rom a purported owner or employee of the Applicant is received, requesting a wire transfer be made on their behalf?" (The Hanover Insurance Group) "for malicious attachments Screening for malicious links Tagging emails from external senders How often is Antiphishing and Cybersecurity Awareness training conducted for employees?" (The Hartford) "Do you have up-to-date versions of system security agent software (including malware, antivirus, and firewall protection) and reasonably up-to-date (within 30 days) security patches and virus definitions?" (CNA) "Do you pre-screen emails for potentially malicious attachments and links?" (Encore Fiduciary) "If "Yes", complete the following: (1) Provide the name of your email pre-screen provider: (2) Do you have the capability to automatically detonate and evaluate attachments in a sandbox to determine if they are malicious prior to delivery to the end-user?" (Encore Fiduciary) "Have you implemented any of the following to protect against phishing messages?" (Encore Fiduciary) "Sender Policy Framework (SPF) Domain Keys Identified Mail (DKIM) Domain-based Message Authentication, Reporting & Conformance (DMARC) None of the above d.Can your users access email through a web application or a non-corporate device?" (Encore Fiduciary) "If "Yes", do you use the Office 365 Advanced Threat Protection add-on?" (Encore Fiduciary) "Do you use a next-generation antivirus (NGAV) product to protect all endpoints across your enterprise?" (Encore Fiduciary) "If "Yes", complete the following: (1) Provide the name of your EDR provider: (2) Do you enforce application whitelisting/blacklisting?" (Encore Fiduciary) "(3) Is EDR deployed on 100% of endpoints?" (Encore Fiduciary) "If "No", please use the Additional Comments section to outline which assets do not have EDR, and whether any mitigating safeguards are in place for such assets. (4) Can users access the network with their own device ("Bring Your Own Device"?" (Encore Fiduciary) "If "Yes", is EDR required to be installed on these devices?" (Encore Fiduciary) "Do you use endpoint application isolation and containment technology on all endpoints?" (Encore Fiduciary) "Can users run Microsoft Office Macro enabled documents on their system by default?" (Encore Fiduciary) "If "Yes" to question 9.a.(1) or 9.a.(2) above, does your social engineering training include phishing simulation?" (Encore Fiduciary) "What anti-virus software do you use?" (RSA) "Do you conduct employee phishing campaigns?" (Munich Re) "How often are phishing campaigns conducted?" (Munich Re) "Do you mandate additional training to those employees who fail to acknowledge phishing emails?" (Munich Re) "Do you implement any of the following controls to protect against malicious emails?" (Munich Re) "Do you scan incoming emails for malicious attachments and/or links?" (Munich Re) "Do you have the ability to automatically quarantine, detonate and evaluate attachments?" (Munich Re) "Are blocked emails classed as incidents and remediated?" (Munich Re) "Do you update all systems including firewalls and anti-virus software at least every 30 days?" (Hiscox UK) |
| PR.IR-01 Networks and environments are protected from unauthorized logical access and usage | NIST CSF 2.0 | 15 | "Do you require Multi-Factor Authentication (MFA) for remote access to your network (both cloud-hosted and on- premises, including via Virtual Private Networks (VPNs)?" (Beazley) "Multi-factor authentication in place for remote access by employees?" (Hiscox) "Multi-factor authentication in place for remote access by third parties?" (Hiscox) "If yes, is it segregated from the network?" (Great American Insurance Group) "Do you allow remote access to your network?" (Tokio Marine HCC) "If "Yes": (1) Do you use 2-factor authentication to secure all remote access to your network?" (Tokio Marine HCC) "(2) Do you utilize IP whitelisting to further protect remote access connections?" (Tokio Marine HCC) "Have you disabled the Remote Desktop Protocol (RDP) and/or Remote Desktop Gateway (RDG) on all system endpoints and servers?" (Tokio Marine HCC) "If "No", is RDP and/or RDG protected by two-factor authentication?" (Tokio Marine HCC) "Do you use 2-factor authentication to secure remote access to your email accounts?" (Tokio Marine HCC) "Is Remote Desktop Protocol (RDP) enabled?" (AXIS Insurance) "Is RDP accessible externally?" (AXIS Insurance) "If remote access is available, does the Applicant implement MFA for all remote access?" (AXIS Insurance) "Are all internet-accessible systems (e.g. web-, email-servers) segregated from the organization's trusted network (e.g. within a demilitarized zone (DMZ) or at a third-party service provider?" (Cowbell Cyber) "Does the applicant segment the network via Next Generation Firewalls, Virtual Local Area Networks (VLAN), demilitarized zones (DMZ), etc.?" (QBE) "How does the applicant eliminate or limit lateral movement within its network?" (QBE) "Does the applicant utilize remote desktop protocol (RDP?" (QBE) "Is this behind a Virtual Private Network (VPN) or gateway?" (QBE) "Is RDP ever exposed to the internet?" (QBE) "Has traf fic using Remote Desktop Protocol (RDP) TCP ports 3389 and Server Message Block (SMB) TCP ports 445, 135, and 139 been blocked?" (The Hanover Insurance Group) "Security & Controls MFA Is Multi-Factor Authentication (MFA) required for ALL remote access to your business' network?" (The Hartford) "If no, how is remote access to the network controlled?" (The Hartford) "Have you installed firewalls between your internal network and the Internet?" (CNA) "Within the Applicant's organization, who is responsible for network security?" (Encore Fiduciary) "If the Applicant's network security is outsourced, are you the main contact for the network security provider named in question b. above?" (Encore Fiduciary) "Do you allow remote access to your network?" (Encore Fiduciary) "If "Yes", do you use MFA to secure all remote access to your network, including any remote desktop protocol (RDP) connections?" (Encore Fiduciary) "ZScaler, Quad9, OpenDNS or the public sector PDNS to block access to known malicious websites?" (Encore Fiduciary) "Is network segmentation (e.g., firewalls, software- defined networking) used to limit movement across the network?" (Everest Insurance) "VPN, remote desktop?" (Everest Insurance) "You secure remote access (access control procedures to prevent unauthorised access) to Your network and Your data?" (RSA) "What firewall(s) do you use?" (RSA) "Is a Web Application Firewall (WAF) used to protect publicly exposed web application?" (Munich Re) "Do you ensure that all publicly facing ports are protected by a pre-configured firewall that blocks unauthorised Yes No network traffic?" (Munich Re) "Do you regularly scan publicly accessible ports and ensure unnecessary ones are locked down?" (Munich Re) "Do you allow Remote Desktop Protocol (RDP) connections?" (Munich Re) "How is web traffic filtered?" (Munich Re) "Have you configured host-based and network firewalls to disallow inbound connections by default?" (Munich Re) "Do you perform periodic reviews of firewall rules to ensure configurations are on a need-to-have basis?" (Munich Re) "Do you utilize any of the following technologies to physically or logically segregate your network?" (Munich Re) "Do all users with remote access provide at least two different forms of identification ('multi-factor authentication') to verify their identity prior to log-in?" (Hiscox UK) |
| A.5.17 Authentication information | ISO 27001:2022 | 14 | "Do you require Multi-Factor Authentication (MFA) for remote access to your network (both cloud-hosted and on- premises, including via Virtual Private Networks (VPNs)?" (Beazley) "Do you require MFA for access to web-based email?" (Beazley) "A policy that requires strong passwords that should be updated on a regular basis?" (Hiscox) "Multi-factor authentication in place for remote access by employees?" (Hiscox) "Multi-factor authentication in place for remote access by third parties?" (Hiscox) "If Yes, are the cloud back-ups secured via two-factor authentication or other similar means?" (Hiscox) "Password/passcode protected Encryption Traditional or next generation firewalls enabled/turned on Traditional or next generation antivirus products on all endpoints Endpoint Detection and Response (EDR) 24/7/365 on all devices If yes to EDR, Who is your provider?" (Great American Insurance Group) "Is multi factor authentication (MFA) to access Email required?" (Great American Insurance Group) "Is multi factor authentication (MFA) for personal devices required?" (Great American Insurance Group) "Is multifactor authentication (MFA) required to remotely connect to the network, all critical internet facing systems and privilege accounts?" (Great American Insurance Group) "If "Yes": (1) Do you use 2-factor authentication to secure all remote access to your network?" (Tokio Marine HCC) "If "No", is RDP and/or RDG protected by two-factor authentication?" (Tokio Marine HCC) "Do you use 2-factor authentication to secure all domain or network administrator accounts?" (Tokio Marine HCC) "Do you use 2-factor authentication to secure remote access to your email accounts?" (Tokio Marine HCC) "(b) segregated with 2-factor authentication access control?" (Tokio Marine HCC) "Is Multi Factor Authentication used for access?" (AXIS Insurance) "If remote access is available, does the Applicant implement MFA for all remote access?" (AXIS Insurance) "Does the Applicant or its Managed Security Service Provider, if applicable, implement MFA for all administrator access?" (AXIS Insurance) "Which of the of the following apply to your Multi-Factor Authentication (MFA) implementation?" (Corvus Insurance) "Do you enforce Multi-Factor Authentication (MFA) for all employees, contractors, and partners on the following?" (Cowbell Cyber) "Is multifactor authentication (MFA) required for all internal, external, and vendor access to the applicant's network?" (QBE) "Do these users require additional credentials to access?" (QBE) "What is the minimum length for passwords?" (QBE) "If yes, does the applicant require strong authentication (e.g., two factor/ MFA?" (QBE) "Can backups only be accessed via an authentication mechanism (i.e., MFA/password vault/separate credentials or credential checkout?" (QBE) "Security & Controls MFA Is Multi-Factor Authentication (MFA) required for ALL remote access to your business' network?" (The Hartford) "Is MFA required for access to email?" (The Hartford) "Do you enforce a strong/complex password policy of at least 8-20 characters?" (CNA) "Information Security and Cyber Infrastructure Self-Assessment 14 On your wireless networks; do you use security at least as strong as WPA2 authentication and encryption, and do you require two factor authentication (access token and password/account logon) before allowing wireless connections to your network?" (CNA) "if you do not use wireless networks.) 15 Do you require multi-factor authorization when your network is accessed remotely and/or when cloud resources are utilized?" (CNA) "On your wireless networks; do you use security at least as strong as WPA2 authentication and encryption, and do you require two factor authentication (access token and password/account logon) before allowing wireless connections to your network?" (CNA) "Do you require multi-factor authorization when your network is accessed remotely and/or when cloud resources are utilized?" (CNA) "If "Yes", do you enforce Multi-Factor Authentication (MFA?" (Encore Fiduciary) "If "Yes", do you use MFA to secure all remote access to your network, including any remote desktop protocol (RDP) connections?" (Encore Fiduciary) "Encore Fiduciary Cyber Liability Application (2.2022) Page 2 of 10 If MFA is used, complete the following: (1) Provide the name of your MFA provider: (2) Describe your MFA type: (3) Does your MFA configuration ensure that the compromise of a single device will only compromise a single authenticator?" (Encore Fiduciary) "Do you use MFA to protect all local and remote access to privileged user accounts?" (Encore Fiduciary) "If "Yes", complete the following: (1) Provide the name of your PAM software provider: (2) Is access protected by MFA?" (Encore Fiduciary) "Does the Applicant use multi-factor authentication for access to critical applications or databases (including those that contain personally identifiable information, private health information or payment card information?" (Everest Insurance) "Does the Applicant enforce password changes every 8-12 weeks?" (Everest Insurance) "Are unique backup credentials stored separately from other user credentials?" (Munich Re) "Is multi-factor authentication (MFA) in place for web-based email logins?" (Munich Re) "Do you have a formal password policy that explains good password hygiene, such as not using obvious or repeated passwords, for all systems providing access to personal or confidential information?" (Hiscox UK) "Do all users with remote access provide at least two different forms of identification ('multi-factor authentication') to verify their identity prior to log-in?" (Hiscox UK) "Do you require multi-factor authentication for all online banking logins?" (Hiscox UK) "Do you ensure multi-factor authentication for any fund transfer?" (Hiscox UK) |
| A.5.14 Information transfer | ISO 27001:2022 | 14 | "What security controls do you have in place for incoming email?" (Beazley) "How often do you conduct interactive social engineering (i.e., phishing) training?" (Beazley) "Do you use the Microsoft 365 Defender add-on or an equivalent cybersecurity product with advanced threat hunting to protect against phishing and business email compromise?" (Beazley) "Are employees who are responsible for disbursing or transmitting funds provided anti-fraud training, including detection of social engineering, phishing, business email compromise and other scams, on at least an annual basis?" (Beazley) "Is this information encrypted while in transit?" (Hiscox) "in place to ensure compliance with the Telephone Consumer Protection Act, anti-SPAM statutes, and any other consumer protection act?" (Hiscox) "Does the Applicant have and enforce policies concerning the encryption of internal and external communication?" (AmTrust) "Are Sender Policy Framework (SPF), Domain-based Message Authentication Reporting and Compliance (DMARC) or Domain Keys Identified Mail (DKIM) in place?" (Great American Insurance Group) "Do you use an email filtering solution designed to prevent phishing or ransomware attacks (in addition to any filtering solution(s) provided by your email provider?" (Tokio Marine HCC) "If "Yes" to question 7.a.(1) or 7.a.(2) above, does your social engineering training include phishing simulation?" (Tokio Marine HCC) "Does the Applicant employ any of the following SPF DKIM DMARC solutions?" (AXIS Insurance) "Does the Applicant conduct mandatory information security, phishing and privacy training for employees and contractors at least quarterly?" (AXIS Insurance) "Are Phishing Simulations conducted for all employees?" (AXIS Insurance) "Does the Applicant have a report phishing email add-in enabled for all email users?" (AXIS Insurance) "Does the company scan email for potentially malicious attachments and / or links?" (RLI) "Do you have email filtering in place?" (Corvus Insurance) "Do you conduct employee security training or phishing training, for all employees, at least annually?" (Corvus Insurance) "Does the organization encrypt all external communications containing sensitive information?" (Cowbell Cyber) "Phishing a. How often does the applicant use simulated phishing attacks to test employees?" (QBE) "Does the applicant flag external emails?" (QBE) "Email filtering Does the applicant utilize email filtering protocols such as Domain-based Message Authentication, Reporting and Conformance (DMARC), DomainKeys Identified Mail (DKIM), or Sender Policy Framework (SPF?" (QBE) "Detect and identify social engineering/phishing scams where a f raudulent email or phone call f rom purported vendor or client is received, requesting their vendor or client bank account inf ormation be changed?" (The Hanover Insurance Group) "Detect and identify social engineering/phishing scams where a f raudulent email or phone call f rom a purported owner or employee of the Applicant is received, requesting a wire transfer be made on their behalf?" (The Hanover Insurance Group) "at rest While electronically in transit While on mobile devices Backups & Recovery Is your business' critical data regularly backed up?" (The Hartford) "for malicious attachments Screening for malicious links Tagging emails from external senders How often is Antiphishing and Cybersecurity Awareness training conducted for employees?" (The Hartford) "Do you pre-screen emails for potentially malicious attachments and links?" (Encore Fiduciary) "If "Yes", complete the following: (1) Provide the name of your email pre-screen provider: (2) Do you have the capability to automatically detonate and evaluate attachments in a sandbox to determine if they are malicious prior to delivery to the end-user?" (Encore Fiduciary) "Have you implemented any of the following to protect against phishing messages?" (Encore Fiduciary) "Sender Policy Framework (SPF) Domain Keys Identified Mail (DKIM) Domain-based Message Authentication, Reporting & Conformance (DMARC) None of the above d.Can your users access email through a web application or a non-corporate device?" (Encore Fiduciary) "If "Yes", do you use the Office 365 Advanced Threat Protection add-on?" (Encore Fiduciary) "If "Yes" to question 9.a.(1) or 9.a.(2) above, does your social engineering training include phishing simulation?" (Encore Fiduciary) "Do you conduct employee phishing campaigns?" (Munich Re) "How often are phishing campaigns conducted?" (Munich Re) "Do you mandate additional training to those employees who fail to acknowledge phishing emails?" (Munich Re) "Do you enforce the use of encryption over all external communication lines (e.g. website, email, wireless?" (Munich Re) "Do you implement any of the following controls to protect against malicious emails?" (Munich Re) "Do you scan incoming emails for malicious attachments and/or links?" (Munich Re) "Do you have the ability to automatically quarantine, detonate and evaluate attachments?" (Munich Re) "Are blocked emails classed as incidents and remediated?" (Munich Re) |
| PR.AA-03 Users, services, and hardware are authenticated | NIST CSF 2.0 | 14 | "Do you require Multi-Factor Authentication (MFA) for remote access to your network (both cloud-hosted and on- premises, including via Virtual Private Networks (VPNs)?" (Beazley) "Do you require MFA for access to web-based email?" (Beazley) "Multi-factor authentication in place for remote access by employees?" (Hiscox) "Multi-factor authentication in place for remote access by third parties?" (Hiscox) "If Yes, are the cloud back-ups secured via two-factor authentication or other similar means?" (Hiscox) "Is multi factor authentication (MFA) to access Email required?" (Great American Insurance Group) "Is multi factor authentication (MFA) for personal devices required?" (Great American Insurance Group) "Is multifactor authentication (MFA) required to remotely connect to the network, all critical internet facing systems and privilege accounts?" (Great American Insurance Group) "If "Yes": (1) Do you use 2-factor authentication to secure all remote access to your network?" (Tokio Marine HCC) "If "No", is RDP and/or RDG protected by two-factor authentication?" (Tokio Marine HCC) "Do you use 2-factor authentication to secure all domain or network administrator accounts?" (Tokio Marine HCC) "Do you use 2-factor authentication to secure remote access to your email accounts?" (Tokio Marine HCC) "(b) segregated with 2-factor authentication access control?" (Tokio Marine HCC) "Is Multi Factor Authentication used for access?" (AXIS Insurance) "If remote access is available, does the Applicant implement MFA for all remote access?" (AXIS Insurance) "Does the Applicant or its Managed Security Service Provider, if applicable, implement MFA for all administrator access?" (AXIS Insurance) "Which of the of the following apply to your Multi-Factor Authentication (MFA) implementation?" (Corvus Insurance) "Do you enforce Multi-Factor Authentication (MFA) for all employees, contractors, and partners on the following?" (Cowbell Cyber) "Is multifactor authentication (MFA) required for all internal, external, and vendor access to the applicant's network?" (QBE) "If yes, does the applicant require strong authentication (e.g., two factor/ MFA?" (QBE) "Can backups only be accessed via an authentication mechanism (i.e., MFA/password vault/separate credentials or credential checkout?" (QBE) "Security & Controls MFA Is Multi-Factor Authentication (MFA) required for ALL remote access to your business' network?" (The Hartford) "Is MFA required for access to email?" (The Hartford) "Information Security and Cyber Infrastructure Self-Assessment 14 On your wireless networks; do you use security at least as strong as WPA2 authentication and encryption, and do you require two factor authentication (access token and password/account logon) before allowing wireless connections to your network?" (CNA) "if you do not use wireless networks.) 15 Do you require multi-factor authorization when your network is accessed remotely and/or when cloud resources are utilized?" (CNA) "On your wireless networks; do you use security at least as strong as WPA2 authentication and encryption, and do you require two factor authentication (access token and password/account logon) before allowing wireless connections to your network?" (CNA) "Do you require multi-factor authorization when your network is accessed remotely and/or when cloud resources are utilized?" (CNA) "Sender Policy Framework (SPF) Domain Keys Identified Mail (DKIM) Domain-based Message Authentication, Reporting & Conformance (DMARC) None of the above d.Can your users access email through a web application or a non-corporate device?" (Encore Fiduciary) "If "Yes", do you enforce Multi-Factor Authentication (MFA?" (Encore Fiduciary) "If "Yes", do you use MFA to secure all remote access to your network, including any remote desktop protocol (RDP) connections?" (Encore Fiduciary) "Encore Fiduciary Cyber Liability Application (2.2022) Page 2 of 10 If MFA is used, complete the following: (1) Provide the name of your MFA provider: (2) Describe your MFA type: (3) Does your MFA configuration ensure that the compromise of a single device will only compromise a single authenticator?" (Encore Fiduciary) "Do you use MFA to protect all local and remote access to privileged user accounts?" (Encore Fiduciary) "If "Yes", complete the following: (1) Provide the name of your PAM software provider: (2) Is access protected by MFA?" (Encore Fiduciary) "Does the Applicant use multi-factor authentication for access to critical applications or databases (including those that contain personally identifiable information, private health information or payment card information?" (Everest Insurance) "Is web-based email available to employees?" (Munich Re) "Is multi-factor authentication (MFA) in place for web-based email logins?" (Munich Re) "Do all users with remote access provide at least two different forms of identification ('multi-factor authentication') to verify their identity prior to log-in?" (Hiscox UK) "Do you require multi-factor authentication for all online banking logins?" (Hiscox UK) "Do you ensure multi-factor authentication for any fund transfer?" (Hiscox UK) |
| A.6.7 Remote working | ISO 27001:2022 | 14 | "Do you require Multi-Factor Authentication (MFA) for remote access to your network (both cloud-hosted and on- premises, including via Virtual Private Networks (VPNs)?" (Beazley) "Is this information stored on mobile computing devices, including laptops or smart phones?" (Hiscox) "Multi-factor authentication in place for remote access by employees?" (Hiscox) "Multi-factor authentication in place for remote access by third parties?" (Hiscox) "Are users able to store data to the hard drive of portable computers or portable media devices such as USB drives?" (AmTrust) "Do you allow remote access to your network?" (Tokio Marine HCC) "If "Yes": (1) Do you use 2-factor authentication to secure all remote access to your network?" (Tokio Marine HCC) "(2) Do you utilize IP whitelisting to further protect remote access connections?" (Tokio Marine HCC) "Have you disabled the Remote Desktop Protocol (RDP) and/or Remote Desktop Gateway (RDG) on all system endpoints and servers?" (Tokio Marine HCC) "If "No", is RDP and/or RDG protected by two-factor authentication?" (Tokio Marine HCC) "Do you use 2-factor authentication to secure remote access to your email accounts?" (Tokio Marine HCC) "Is Remote Desktop Protocol (RDP) enabled?" (AXIS Insurance) "Is RDP accessible externally?" (AXIS Insurance) "If remote access is available, does the Applicant implement MFA for all remote access?" (AXIS Insurance) "Does the applicant utilize remote desktop protocol (RDP?" (QBE) "Is this behind a Virtual Private Network (VPN) or gateway?" (QBE) "Is RDP ever exposed to the internet?" (QBE) "Has traf fic using Remote Desktop Protocol (RDP) TCP ports 3389 and Server Message Block (SMB) TCP ports 445, 135, and 139 been blocked?" (The Hanover Insurance Group) "Security & Controls MFA Is Multi-Factor Authentication (MFA) required for ALL remote access to your business' network?" (The Hartford) "If no, how is remote access to the network controlled?" (The Hartford) "Have you identified the paper, electronic, and other records, computing systems, and storage media including laptops, mobile phones, and portable devices that contain sensitive information?" (CNA) "Do you allow remote access to your network?" (Encore Fiduciary) "If "Yes", do you use MFA to secure all remote access to your network, including any remote desktop protocol (RDP) connections?" (Encore Fiduciary) "VPN, remote desktop?" (Everest Insurance) "on mobile assets (e.g., laptops, phones, tablets, flash drives?" (Everest Insurance) "You secure remote access (access control procedures to prevent unauthorised access) to Your network and Your data?" (RSA) "Are all mobile devices managed using a Mobile Device Management (MDM) solution?" (Munich Re) "Do you allow employees to use personal mobile devices to access company data (e.g. email?" (Munich Re) "If Yes, do you have a Bring Your Own Device (BYOD) policy in place that governs usage and controls?" (Munich Re) "Do you allow Remote Desktop Protocol (RDP) connections?" (Munich Re) "Do all users with remote access provide at least two different forms of identification ('multi-factor authentication') to verify their identity prior to log-in?" (Hiscox UK) |
| PR.DS-02 The confidentiality, integrity, and availability of data-in-transit are protected | NIST CSF 2.0 | 14 | "Does Named Insured enable disk encryption on laptops, desktops, and other portable media devices?" (Coalition) "Does the Applicant have third party software protecting its network (e.g. antivirus, encryption, firewalls, etc.?" (Chubb) "Is this information encrypted while at rest?" (Hiscox) "Is this information encrypted while in transit?" (Hiscox) "If Yes, are such devices encrypted?" (Hiscox) "in place that scan both encrypted and unencrypted data to restrict network traffic?" (Hiscox) "If Yes, do you encrypt this data?" (Hiscox) "Do you host sensitive data belonging to your clients' customers?" (Hiscox) "Does the Applicant have and enforce policies concerning the encryption of internal and external communication?" (AmTrust) "Does the Applicant encrypt data stored on laptop computers and portable media?" (AmTrust) "Are tapes or other portable media containing backup materials encrypted?" (AmTrust) "Do you encrypt all sensitive and confidential information stored on your organization's systems and networks?" (Tokio Marine HCC) "Does the Applicant employ mandatory encryption to protect the following?" (AXIS Insurance) "Does the applicant encrypt all physical devices, critical data, sensitive emails?" (RLI) "Does the organization encrypt all external communications containing sensitive information?" (Cowbell Cyber) "Does the organization encrypt sensitive information stored on the cloud?" (Cowbell Cyber) "Is all backup data encrypted once replicated?" (QBE) "Does the applicant have a policy that all portable devices use full disk encryption?" (QBE) "Where does the applicant use encryption?" (QBE) "How often does the applicant use encryption?" (QBE) "at rest While electronically in transit While on mobile devices Backups & Recovery Is your business' critical data regularly backed up?" (The Hartford) "Do you encrypt all sensitive records and files that are held at rest and/or transmitted across public networks, and that are to be transmitted wirelessly?" (CNA) "Do you encrypt all sensitive and confidential information stored on your organization's systems and networks?" (Encore Fiduciary) "Do you disable media ports or restrict usage to only encrypted removable storage devices?" (Munich Re) "Do you enforce the use of encryption over all external communication lines (e.g. website, email, wireless?" (Munich Re) "Do you enforce the use of encryption of sensitive information while at rest (e.g. on premise, mobile device, Yes No cloud?" (Munich Re) "Do you utilize a Data Loss Prevention (DLP) product for email?" (Munich Re) "Is a DLP solution in use on endpoints, external and internal (including email) servers?" (Munich Re) "If Yes, is payment card data either encrypted or tokenised at all times?" (Munich Re) "Do you have a policy to encrypt mobile computing devices (for example laptops, tablets, mobile telephones, PDAs) and portable data storage media (for example external drives or magnetic tapes) which hold, process, transact or store any of the personal data referred to in 1.7?" (Hiscox UK) |
| CC1.4 Attracting, developing and retaining competent people (COSO principle 4) | SOC 2 | 14 | "How often do you conduct interactive social engineering (i.e., phishing) training?" (Beazley) "Are employees who are responsible for disbursing or transmitting funds provided anti-fraud training, including detection of social engineering, phishing, business email compromise and other scams, on at least an annual basis?" (Beazley) "Screening of potential employees (e.g. background, drug, criminal, credit, etc.?" (Hiscox) "c. a loss of money, securities, or property due to social engineering, fraud, or other criminal acts?" (Hiscox) "Do any of the following employees at your company complete social engineering training: (1) Employees with financial or accounting responsibilities?" (Tokio Marine HCC) "If "Yes" to question 7.a.(1) or 7.a.(2) above, does your social engineering training include phishing simulation?" (Tokio Marine HCC) "Does the Applicant conduct mandatory information security, phishing and privacy training for employees and contractors at least quarterly?" (AXIS Insurance) "Are Phishing Simulations conducted for all employees?" (AXIS Insurance) "Does the Applicant conduct anti-fraud training of employees at least annually?" (AXIS Insurance) "Do you conduct employee security training or phishing training, for all employees, at least annually?" (Corvus Insurance) "Does the organization hold mandatory cybersecurity training with all employees at least annually?" (Cowbell Cyber) "If yes, does the applicant conduct training on spotting and reporting such emails?" (QBE) "Detect and identify social engineering/phishing scams where a f raudulent email or phone call f rom purported vendor or client is received, requesting their vendor or client bank account inf ormation be changed?" (The Hanover Insurance Group) "Detect and identify social engineering/phishing scams where a f raudulent email or phone call f rom a purported owner or employee of the Applicant is received, requesting a wire transfer be made on their behalf?" (The Hanover Insurance Group) "If "No", what kind of training does the Applicant provide to help combat these types of fraudulent schemes and how often?" (The Hanover Insurance Group) "for malicious attachments Screening for malicious links Tagging emails from external senders How often is Antiphishing and Cybersecurity Awareness training conducted for employees?" (The Hartford) "Do you conduct full, nationwide, criminal background check, sexual offender check, and if possible a credit check on all prospective employees?" (CNA) "At least once a year, do you provide security awareness training for everyone who accesses your network or sensitive information in your care?" (CNA) "At time of hire and at least once a year, do you provide security awareness training for everyone who accesses your network or sensitive information in your care?" (CNA) "Do you conduct full, nationwide, criminal background checks, sexual offender checks, and if possible, credit checks on all prospective employees?" (CNA) "Do any of the following employees at your company complete social engineering training: (1) Employees with financial or accounting responsibilities?" (Encore Fiduciary) "If "Yes" to question 9.a.(1) or 9.a.(2) above, does your social engineering training include phishing simulation?" (Encore Fiduciary) "Does the Applicant have a formalized training program for newly hired employees?" (Everest Insurance) "Do You have a written Policy that addresses information security awareness which is communicated to all employees?" (RSA) "Which of the following information security and privacy trainings are conducted?" (Munich Re) "Do you conduct employee phishing campaigns?" (Munich Re) "How often are phishing campaigns conducted?" (Munich Re) "Do you mandate additional training to those employees who fail to acknowledge phishing emails?" (Munich Re) "Are your developers regularly trained in secure programming techniques and code reviews?" (Munich Re) |
| PR.AT-01 Personnel are provided with awareness and training so that they possess the knowledge and skills to perform general tasks with cybersecurity risks in mind | NIST CSF 2.0 | 14 | "How often do you conduct interactive social engineering (i.e., phishing) training?" (Beazley) "Are employees who are responsible for disbursing or transmitting funds provided anti-fraud training, including detection of social engineering, phishing, business email compromise and other scams, on at least an annual basis?" (Beazley) "c. a loss of money, securities, or property due to social engineering, fraud, or other criminal acts?" (Hiscox) "Do any of the following employees at your company complete social engineering training: (1) Employees with financial or accounting responsibilities?" (Tokio Marine HCC) "If "Yes" to question 7.a.(1) or 7.a.(2) above, does your social engineering training include phishing simulation?" (Tokio Marine HCC) "Does the Applicant conduct mandatory information security, phishing and privacy training for employees and contractors at least quarterly?" (AXIS Insurance) "Are Phishing Simulations conducted for all employees?" (AXIS Insurance) "Does the Applicant have a report phishing email add-in enabled for all email users?" (AXIS Insurance) "Does the Applicant conduct anti-fraud training of employees at least annually?" (AXIS Insurance) "Do you conduct employee security training or phishing training, for all employees, at least annually?" (Corvus Insurance) "Does the organization hold mandatory cybersecurity training with all employees at least annually?" (Cowbell Cyber) "Does the applicant flag external emails?" (QBE) "Does the applicant allow users to report suspicious emails?" (QBE) "If yes, does the applicant conduct training on spotting and reporting such emails?" (QBE) "Detect and identify social engineering/phishing scams where a f raudulent email or phone call f rom purported vendor or client is received, requesting their vendor or client bank account inf ormation be changed?" (The Hanover Insurance Group) "Detect and identify social engineering/phishing scams where a f raudulent email or phone call f rom a purported owner or employee of the Applicant is received, requesting a wire transfer be made on their behalf?" (The Hanover Insurance Group) "If "No", what kind of training does the Applicant provide to help combat these types of fraudulent schemes and how often?" (The Hanover Insurance Group) "for malicious attachments Screening for malicious links Tagging emails from external senders How often is Antiphishing and Cybersecurity Awareness training conducted for employees?" (The Hartford) "At least once a year, do you provide security awareness training for everyone who accesses your network or sensitive information in your care?" (CNA) "At time of hire and at least once a year, do you provide security awareness training for everyone who accesses your network or sensitive information in your care?" (CNA) "Do any of the following employees at your company complete social engineering training: (1) Employees with financial or accounting responsibilities?" (Encore Fiduciary) "If "Yes" to question 9.a.(1) or 9.a.(2) above, does your social engineering training include phishing simulation?" (Encore Fiduciary) "Does the Applicant have a formalized training program for newly hired employees?" (Everest Insurance) "Do You have a written Policy that addresses information security awareness which is communicated to all employees?" (RSA) "Which of the following information security and privacy trainings are conducted?" (Munich Re) "Do you conduct employee phishing campaigns?" (Munich Re) "How often are phishing campaigns conducted?" (Munich Re) "Do you mandate additional training to those employees who fail to acknowledge phishing emails?" (Munich Re) "Are your developers regularly trained in secure programming techniques and code reviews?" (Munich Re) |
| A.5.3 Segregation of duties | ISO 27001:2022 | 14 | "Does Named Insured require dual control when transferring funds in excess of $25,000?" (Coalition) "Cyber Crime (Only if applying for this coverage) Does the Applicant accept funds transfer information from clients over the telephone, email, text message or similar method of communication?" (Chubb) "Does the Applicant authenticate instructions by calling the customer at a predetermined phone number or require receipt of a customer identity code?" (Chubb) "Is approval by more than one person required to initiate a wire transfer?" (Chubb) "Before acting on a transfer, do you verify the request or account detail changes using a method other than the initial contact method (Example: the initial request is received by mail and verification is done by telephone?" (Hiscox) "c. a loss of money, securities, or property due to social engineering, fraud, or other criminal acts?" (Hiscox) "Does your organization send and/or receive wire transfers?" (Tokio Marine HCC) "If "Yes", does your wire transfer authorization process include the following: (1) A wire request documentation form?" (Tokio Marine HCC) "(2) A protocol for obtaining proper written authorization for wire transfers?" (Tokio Marine HCC) "Does the Applicant employ a protocol to confirm transfer instructions including a call back, email or an alternative method of authenticating the instruction?" (AXIS Insurance) "Does the Applicant employ a protocol requiring more than one or next-level approval?" (AXIS Insurance) "Does the Applicant conduct anti-fraud training of employees at least annually?" (AXIS Insurance) "Does the applicant have formal policies and procedures in place for secure fund transfers, such as senior management approval and obtaining verbal confirmation for any fund transfer requests?" (RLI) "Prior to executing an electronic payment, does the applicant verify the validity of the funds transfer request or payment change request, with the requestor, via a separate means of communication prior to transferring funds or making payment changes?" (RLI) "Prior to executing an electronic payment, do you verify the validity of the funds transfer request or payment change request, with the requestor, via a separate means of communication prior to transferring funds or making payment changes?" (Corvus Insurance) "Does the organization authenticate funds transfer requests (e.g. by calling a customer to verify the request at a predetermined phone number?" (Cowbell Cyber) "Does the organization prevent unauthorized employees from initiating wire transfers?" (Cowbell Cyber) "ve at SS bay Security Controls Does the Applicant have controls in place which require all fund and wire transfers over $25,000 to be authorized and verified by at least two employees prior to execution?" (At-Bay) "Exec/Employee directed request wire transfer without first validating the request with a call back to the requestor (inclusive of any owner) at a pre-determined work phone number or with a f ace to face confirmation?" (The Hanover Insurance Group) "If "No", what kind of training does the Applicant provide to help combat these types of fraudulent schemes and how often?" (The Hanover Insurance Group) "Does any applicant accept fund transfer requests from customers?" (The Hartford) "If yes, is the funds transfer instruction validated by a method other than the original means of request?" (The Hartford) "Does your organization send and/or receive wire transfers?" (Encore Fiduciary) "If "Yes", does your wire transfer authorization process include the following: (1) A wire request documentation form?" (Encore Fiduciary) "(2) A protocol for obtaining proper written authorization for wire transfers?" (Encore Fiduciary) "Payment Card Information (PCI) (e.g., credit card, debit card numbers or other financial account numbers?" (Everest Insurance) "Do you ensure multi-factor authentication for any fund transfer?" (Hiscox UK) "Do you have a process in place to confirm that any payment requests received by email are from a known source?" (Hiscox UK) |
| CC3.3 Considering fraud risk (COSO principle 8) | SOC 2 | 14 | "Does Named Insured require dual control when transferring funds in excess of $25,000?" (Coalition) "Cyber Crime (Only if applying for this coverage) Does the Applicant accept funds transfer information from clients over the telephone, email, text message or similar method of communication?" (Chubb) "Does the Applicant authenticate instructions by calling the customer at a predetermined phone number or require receipt of a customer identity code?" (Chubb) "Is approval by more than one person required to initiate a wire transfer?" (Chubb) "Before acting on a transfer, do you verify the request or account detail changes using a method other than the initial contact method (Example: the initial request is received by mail and verification is done by telephone?" (Hiscox) "Does your organization send and/or receive wire transfers?" (Tokio Marine HCC) "If "Yes", does your wire transfer authorization process include the following: (1) A wire request documentation form?" (Tokio Marine HCC) "(2) A protocol for obtaining proper written authorization for wire transfers?" (Tokio Marine HCC) "Does the Applicant employ a protocol to confirm transfer instructions including a call back, email or an alternative method of authenticating the instruction?" (AXIS Insurance) "Does the Applicant employ a protocol requiring more than one or next-level approval?" (AXIS Insurance) "Does the applicant have formal policies and procedures in place for secure fund transfers, such as senior management approval and obtaining verbal confirmation for any fund transfer requests?" (RLI) "Prior to executing an electronic payment, does the applicant verify the validity of the funds transfer request or payment change request, with the requestor, via a separate means of communication prior to transferring funds or making payment changes?" (RLI) "Prior to executing an electronic payment, do you verify the validity of the funds transfer request or payment change request, with the requestor, via a separate means of communication prior to transferring funds or making payment changes?" (Corvus Insurance) "Does the organization authenticate funds transfer requests (e.g. by calling a customer to verify the request at a predetermined phone number?" (Cowbell Cyber) "Does the organization prevent unauthorized employees from initiating wire transfers?" (Cowbell Cyber) "ve at SS bay Security Controls Does the Applicant have controls in place which require all fund and wire transfers over $25,000 to be authorized and verified by at least two employees prior to execution?" (At-Bay) "Exec/Employee directed request wire transfer without first validating the request with a call back to the requestor (inclusive of any owner) at a pre-determined work phone number or with a f ace to face confirmation?" (The Hanover Insurance Group) "Does any applicant accept fund transfer requests from customers?" (The Hartford) "If yes, is the funds transfer instruction validated by a method other than the original means of request?" (The Hartford) "Does your organization send and/or receive wire transfers?" (Encore Fiduciary) "If "Yes", does your wire transfer authorization process include the following: (1) A wire request documentation form?" (Encore Fiduciary) "(2) A protocol for obtaining proper written authorization for wire transfers?" (Encore Fiduciary) "Payment Card Information (PCI) (e.g., credit card, debit card numbers or other financial account numbers?" (Everest Insurance) "Do you have a process in place to confirm that any payment requests received by email are from a known source?" (Hiscox UK) |
| GV.OC-03 Legal, regulatory, and contractual requirements regarding cybersecurity - including privacy and civil liberties obligations - are understood and managed | NIST CSF 2.0 | 13 | "Does Named Insured accept credit cards or collect Personally Identifiable Information (PII) or Protected Health Information (PHI) from its customers?" (Coalition) "GDPR (EU General Data Protection Regulation?" (Hiscox) "HIPAA (Health Insurance Portability and Accountability Act?" (Hiscox) "CCPA (California Consumer Privacy Act?" (Hiscox) "BIPA (Biometric Information Privacy Act?" (Hiscox) "A written corporate privacy policy which is reviewed by a qualified lawyer and actively followed?" (Hiscox) "Obtaining consent from individuals when collecting Personally Identifiable Information?" (Hiscox) "Does the applicant have a privacy policy in place published on the website?" (Great American Insurance Group) "Are trackers, web beacons and/or pixels used on the Applicant's website?" (Great American Insurance Group) "If yes, is the data being collected in compliance with applicable data privacy laws – specific to consent of user?" (Great American Insurance Group) "If yes, is the data being collected limited to the minimum information necessary to accomplish its purpose and not be used or disclosed beyond what is legally permissible?" (Great American Insurance Group) "If "Yes", have you reviewed your policies relating to the collection, storage and destruction of such information or data with a qualified attorney and confirmed compliance with applicable federal, state, local and foreign laws?" (Tokio Marine HCC) "Does the Applicant sell or share Personal Information?" (AXIS Insurance) "Does the Applicant store or process Personal Information on behalf of a third party?" (AXIS Insurance) "Does the Applicant have a written privacy policy or privacy notice reviewed by an attorney and updated at least annually?" (AXIS Insurance) "Do these policies enable the Applicant to identify all Personal Information subjected to the following activities during the last 12 months?" (AXIS Insurance) "Do these policies enable the Applicant to identify the source(s) from which Personal Information was collected, sold or shared?" (AXIS Insurance) "Do these policies enable the Applicant to identify the business purpose(s) for which Personal Information was collected, sold or shared?" (AXIS Insurance) "Are any of the Applicant's products or services used in the collection, use, processing, sharing, sale, profit from, possession, retention and destruction of Biometric Information?" (AXIS Insurance) "Is the Applicant a Healthcare Provider, Business Associate, or Covered Entity under HIPAA?" (Travelers) "If Yes, is the Applicant HIPAA compliant?" (Travelers) "Is the Applicant subject to the General Data Protection Regulation (GDPR?" (Travelers) "Does the Applicant collect, capture, purchase, receive through trade, or otherwise obtain biometric data (biometric data is data related to body measurements and calculations related to human characteristics and includes, but is not limited to, fingerprints, iris or retina scans, voiceprints, sleep/health/exercise data, DNA or biological markers?" (Corvus Insurance) "If user inf ormation is collected, the user has the option to opt-in or opt-out of allowing the collection or use of their information?" (The Hanover Insurance Group) "If Personal Information gathered from customers is sold, the Applicant notifies and obtains consent prior to dissemination of such information?" (The Hanover Insurance Group) "If "Yes", have you reviewed your policies relating to the collection, storage and destruction of such information or data with a qualified attorney and confirmed compliance with applicable federal, state, local and foreign laws?" (Encore Fiduciary) "Does the Applicant's privacy policy allow for the sharing of Confidential Information with third parties?" (Everest Insurance) "Does the Applicant use multi-factor authentication for access to critical applications or databases (including those that contain personally identifiable information, private health information or payment card information?" (Everest Insurance) "Personally Identifiable Information (PII) (non-public information such as social security numbers, driver's licenses, phone numbers, and email addresses?" (Everest Insurance) "Private Health Information (PHI) (e.g., healthcare or medical records?" (Everest Insurance) "Has the Applicant's privacy policy, terms of use, terms of service, and other customer policies been review by an outside counsel?" (Everest Insurance) "Do you have a written Privacy Policy that clearly discloses who You share Personal data with?" (RSA) "Do you have a written privacy policy that is reviewed (at least annually) by qualified legal counsel?" (Munich Re) "Do you share any personal data with third parties?" (Munich Re) "If Yes, do you have data sharing agreements in place with all third parties where personal data is shared?" (Munich Re) "Do you give data subjects the ability to opt-out of allowing personal data to be shared with third parties?" (Munich Re) "Do you have a process in place to respond to data subject requests (e.g. access requests, right to erasure) and Yes No complaints based on applicable data privacy regulations?" (Munich Re) "Do you clearly outline to individuals how any biometric information will be collected, used and/or destroyed?" (Munich Re) "Do you obtain written consent from individuals prior to collection, receipt or retention of biometric information?" (Munich Re) "Do you have a retention schedule outlining how long biometric information is retained?" (Munich Re) "Do you sell, lease, trade or otherwise profit from the biometric information of individuals?" (Munich Re) "Do you subject biometric data to any of the following measures?" (Munich Re) "Have you ever received a complaint relating to the handling of someone's personally identifiable information?" (Hiscox UK) |
| A.5.34 Privacy and protection of personal identifiable information (PII) | ISO 27001:2022 | 13 | "Does Named Insured accept credit cards or collect Personally Identifiable Information (PII) or Protected Health Information (PHI) from its customers?" (Coalition) "GDPR (EU General Data Protection Regulation?" (Hiscox) "HIPAA (Health Insurance Portability and Accountability Act?" (Hiscox) "CCPA (California Consumer Privacy Act?" (Hiscox) "BIPA (Biometric Information Privacy Act?" (Hiscox) "A written corporate privacy policy which is reviewed by a qualified lawyer and actively followed?" (Hiscox) "Obtaining consent from individuals when collecting Personally Identifiable Information?" (Hiscox) "Does the applicant have a privacy policy in place published on the website?" (Great American Insurance Group) "Are trackers, web beacons and/or pixels used on the Applicant's website?" (Great American Insurance Group) "If yes, is the data being collected in compliance with applicable data privacy laws – specific to consent of user?" (Great American Insurance Group) "If yes, is the data being collected limited to the minimum information necessary to accomplish its purpose and not be used or disclosed beyond what is legally permissible?" (Great American Insurance Group) "If "Yes", have you reviewed your policies relating to the collection, storage and destruction of such information or data with a qualified attorney and confirmed compliance with applicable federal, state, local and foreign laws?" (Tokio Marine HCC) "Does the Applicant sell or share Personal Information?" (AXIS Insurance) "Does the Applicant store or process Personal Information on behalf of a third party?" (AXIS Insurance) "Does the Applicant have a written privacy policy or privacy notice reviewed by an attorney and updated at least annually?" (AXIS Insurance) "Do these policies enable the Applicant to identify all Personal Information subjected to the following activities during the last 12 months?" (AXIS Insurance) "Do these policies enable the Applicant to identify the source(s) from which Personal Information was collected, sold or shared?" (AXIS Insurance) "Do these policies enable the Applicant to identify the business purpose(s) for which Personal Information was collected, sold or shared?" (AXIS Insurance) "Is the Applicant a Healthcare Provider, Business Associate, or Covered Entity under HIPAA?" (Travelers) "If Yes, is the Applicant HIPAA compliant?" (Travelers) "Is the Applicant subject to the General Data Protection Regulation (GDPR?" (Travelers) "Does the Applicant collect, capture, purchase, receive through trade, or otherwise obtain biometric data (biometric data is data related to body measurements and calculations related to human characteristics and includes, but is not limited to, fingerprints, iris or retina scans, voiceprints, sleep/health/exercise data, DNA or biological markers?" (Corvus Insurance) "If user inf ormation is collected, the user has the option to opt-in or opt-out of allowing the collection or use of their information?" (The Hanover Insurance Group) "If Personal Information gathered from customers is sold, the Applicant notifies and obtains consent prior to dissemination of such information?" (The Hanover Insurance Group) "If "Yes", have you reviewed your policies relating to the collection, storage and destruction of such information or data with a qualified attorney and confirmed compliance with applicable federal, state, local and foreign laws?" (Encore Fiduciary) "Does the Applicant's privacy policy allow for the sharing of Confidential Information with third parties?" (Everest Insurance) "Does the Applicant use multi-factor authentication for access to critical applications or databases (including those that contain personally identifiable information, private health information or payment card information?" (Everest Insurance) "Personally Identifiable Information (PII) (non-public information such as social security numbers, driver's licenses, phone numbers, and email addresses?" (Everest Insurance) "Private Health Information (PHI) (e.g., healthcare or medical records?" (Everest Insurance) "Has the Applicant's privacy policy, terms of use, terms of service, and other customer policies been review by an outside counsel?" (Everest Insurance) "Do you have a written Privacy Policy that clearly discloses who You share Personal data with?" (RSA) "Do you have a written privacy policy that is reviewed (at least annually) by qualified legal counsel?" (Munich Re) "Do you share any personal data with third parties?" (Munich Re) "If Yes, do you have data sharing agreements in place with all third parties where personal data is shared?" (Munich Re) "Do you give data subjects the ability to opt-out of allowing personal data to be shared with third parties?" (Munich Re) "Do you have a process in place to respond to data subject requests (e.g. access requests, right to erasure) and Yes No complaints based on applicable data privacy regulations?" (Munich Re) "Do you clearly outline to individuals how any biometric information will be collected, used and/or destroyed?" (Munich Re) "Do you sell, lease, trade or otherwise profit from the biometric information of individuals?" (Munich Re) "Do you subject biometric data to any of the following measures?" (Munich Re) "Have you ever received a complaint relating to the handling of someone's personally identifiable information?" (Hiscox UK) |
| P1.1 Privacy notice to data subjects | SOC 2 | 13 | "Does Named Insured accept credit cards or collect Personally Identifiable Information (PII) or Protected Health Information (PHI) from its customers?" (Coalition) "GDPR (EU General Data Protection Regulation?" (Hiscox) "HIPAA (Health Insurance Portability and Accountability Act?" (Hiscox) "CCPA (California Consumer Privacy Act?" (Hiscox) "BIPA (Biometric Information Privacy Act?" (Hiscox) "A written corporate privacy policy which is reviewed by a qualified lawyer and actively followed?" (Hiscox) "Obtaining consent from individuals when collecting Personally Identifiable Information?" (Hiscox) "Does the applicant have a privacy policy in place published on the website?" (Great American Insurance Group) "Are trackers, web beacons and/or pixels used on the Applicant's website?" (Great American Insurance Group) "If yes, is the data being collected in compliance with applicable data privacy laws – specific to consent of user?" (Great American Insurance Group) "If yes, is the data being collected limited to the minimum information necessary to accomplish its purpose and not be used or disclosed beyond what is legally permissible?" (Great American Insurance Group) "If "Yes", have you reviewed your policies relating to the collection, storage and destruction of such information or data with a qualified attorney and confirmed compliance with applicable federal, state, local and foreign laws?" (Tokio Marine HCC) "Does the Applicant sell or share Personal Information?" (AXIS Insurance) "Does the Applicant store or process Personal Information on behalf of a third party?" (AXIS Insurance) "Does the Applicant have a written privacy policy or privacy notice reviewed by an attorney and updated at least annually?" (AXIS Insurance) "Do these policies enable the Applicant to identify all Personal Information subjected to the following activities during the last 12 months?" (AXIS Insurance) "Do these policies enable the Applicant to identify the source(s) from which Personal Information was collected, sold or shared?" (AXIS Insurance) "Do these policies enable the Applicant to identify the business purpose(s) for which Personal Information was collected, sold or shared?" (AXIS Insurance) "Is the Applicant a Healthcare Provider, Business Associate, or Covered Entity under HIPAA?" (Travelers) "If Yes, is the Applicant HIPAA compliant?" (Travelers) "Is the Applicant subject to the General Data Protection Regulation (GDPR?" (Travelers) "Does the Applicant collect, capture, purchase, receive through trade, or otherwise obtain biometric data (biometric data is data related to body measurements and calculations related to human characteristics and includes, but is not limited to, fingerprints, iris or retina scans, voiceprints, sleep/health/exercise data, DNA or biological markers?" (Corvus Insurance) "If user inf ormation is collected, the user has the option to opt-in or opt-out of allowing the collection or use of their information?" (The Hanover Insurance Group) "If Personal Information gathered from customers is sold, the Applicant notifies and obtains consent prior to dissemination of such information?" (The Hanover Insurance Group) "If "Yes", have you reviewed your policies relating to the collection, storage and destruction of such information or data with a qualified attorney and confirmed compliance with applicable federal, state, local and foreign laws?" (Encore Fiduciary) "Does the Applicant's privacy policy allow for the sharing of Confidential Information with third parties?" (Everest Insurance) "Does the Applicant use multi-factor authentication for access to critical applications or databases (including those that contain personally identifiable information, private health information or payment card information?" (Everest Insurance) "Personally Identifiable Information (PII) (non-public information such as social security numbers, driver's licenses, phone numbers, and email addresses?" (Everest Insurance) "Private Health Information (PHI) (e.g., healthcare or medical records?" (Everest Insurance) "Has the Applicant's privacy policy, terms of use, terms of service, and other customer policies been review by an outside counsel?" (Everest Insurance) "Do you have a written Privacy Policy that clearly discloses who You share Personal data with?" (RSA) "Do you have a written privacy policy that is reviewed (at least annually) by qualified legal counsel?" (Munich Re) "Do you share any personal data with third parties?" (Munich Re) "If Yes, do you have data sharing agreements in place with all third parties where personal data is shared?" (Munich Re) "Do you give data subjects the ability to opt-out of allowing personal data to be shared with third parties?" (Munich Re) "Do you have a process in place to respond to data subject requests (e.g. access requests, right to erasure) and Yes No complaints based on applicable data privacy regulations?" (Munich Re) "Do you clearly outline to individuals how any biometric information will be collected, used and/or destroyed?" (Munich Re) "Do you sell, lease, trade or otherwise profit from the biometric information of individuals?" (Munich Re) "Do you subject biometric data to any of the following measures?" (Munich Re) "Have you ever received a complaint relating to the handling of someone's personally identifiable information?" (Hiscox UK) |
| A.5.31 Legal, statutory, regulatory and contractual requirements | ISO 27001:2022 | 13 | "Does Named Insured accept credit cards or collect Personally Identifiable Information (PII) or Protected Health Information (PHI) from its customers?" (Coalition) "GDPR (EU General Data Protection Regulation?" (Hiscox) "HIPAA (Health Insurance Portability and Accountability Act?" (Hiscox) "CCPA (California Consumer Privacy Act?" (Hiscox) "BIPA (Biometric Information Privacy Act?" (Hiscox) "A written corporate privacy policy which is reviewed by a qualified lawyer and actively followed?" (Hiscox) "Obtaining consent from individuals when collecting Personally Identifiable Information?" (Hiscox) "Does the applicant have a privacy policy in place published on the website?" (Great American Insurance Group) "Are trackers, web beacons and/or pixels used on the Applicant's website?" (Great American Insurance Group) "If yes, is the data being collected in compliance with applicable data privacy laws – specific to consent of user?" (Great American Insurance Group) "If yes, is the data being collected limited to the minimum information necessary to accomplish its purpose and not be used or disclosed beyond what is legally permissible?" (Great American Insurance Group) "If "Yes", have you reviewed your policies relating to the collection, storage and destruction of such information or data with a qualified attorney and confirmed compliance with applicable federal, state, local and foreign laws?" (Tokio Marine HCC) "Does the Applicant sell or share Personal Information?" (AXIS Insurance) "Does the Applicant store or process Personal Information on behalf of a third party?" (AXIS Insurance) "Does the Applicant have a written privacy policy or privacy notice reviewed by an attorney and updated at least annually?" (AXIS Insurance) "Do these policies enable the Applicant to identify all Personal Information subjected to the following activities during the last 12 months?" (AXIS Insurance) "Do these policies enable the Applicant to identify the source(s) from which Personal Information was collected, sold or shared?" (AXIS Insurance) "Do these policies enable the Applicant to identify the business purpose(s) for which Personal Information was collected, sold or shared?" (AXIS Insurance) "Is the Applicant a Healthcare Provider, Business Associate, or Covered Entity under HIPAA?" (Travelers) "If Yes, is the Applicant HIPAA compliant?" (Travelers) "Is the Applicant subject to the General Data Protection Regulation (GDPR?" (Travelers) "Does the Applicant collect, capture, purchase, receive through trade, or otherwise obtain biometric data (biometric data is data related to body measurements and calculations related to human characteristics and includes, but is not limited to, fingerprints, iris or retina scans, voiceprints, sleep/health/exercise data, DNA or biological markers?" (Corvus Insurance) "If user inf ormation is collected, the user has the option to opt-in or opt-out of allowing the collection or use of their information?" (The Hanover Insurance Group) "If Personal Information gathered from customers is sold, the Applicant notifies and obtains consent prior to dissemination of such information?" (The Hanover Insurance Group) "If "Yes", have you reviewed your policies relating to the collection, storage and destruction of such information or data with a qualified attorney and confirmed compliance with applicable federal, state, local and foreign laws?" (Encore Fiduciary) "Does the Applicant's privacy policy allow for the sharing of Confidential Information with third parties?" (Everest Insurance) "Personally Identifiable Information (PII) (non-public information such as social security numbers, driver's licenses, phone numbers, and email addresses?" (Everest Insurance) "Private Health Information (PHI) (e.g., healthcare or medical records?" (Everest Insurance) "Has the Applicant's privacy policy, terms of use, terms of service, and other customer policies been review by an outside counsel?" (Everest Insurance) "Do you have a written Privacy Policy that clearly discloses who You share Personal data with?" (RSA) "Do you have a written privacy policy that is reviewed (at least annually) by qualified legal counsel?" (Munich Re) "Do you share any personal data with third parties?" (Munich Re) "If Yes, do you have data sharing agreements in place with all third parties where personal data is shared?" (Munich Re) "Do you give data subjects the ability to opt-out of allowing personal data to be shared with third parties?" (Munich Re) "Do you have a process in place to respond to data subject requests (e.g. access requests, right to erasure) and Yes No complaints based on applicable data privacy regulations?" (Munich Re) "Do you clearly outline to individuals how any biometric information will be collected, used and/or destroyed?" (Munich Re) "Do you sell, lease, trade or otherwise profit from the biometric information of individuals?" (Munich Re) "Do you subject biometric data to any of the following measures?" (Munich Re) "Have you ever received a complaint relating to the handling of someone's personally identifiable information?" (Hiscox UK) |
| P3.1 Collecting personal information consistent with objectives | SOC 2 | 13 | "Does Named Insured accept credit cards or collect Personally Identifiable Information (PII) or Protected Health Information (PHI) from its customers?" (Coalition) "GDPR (EU General Data Protection Regulation?" (Hiscox) "HIPAA (Health Insurance Portability and Accountability Act?" (Hiscox) "CCPA (California Consumer Privacy Act?" (Hiscox) "BIPA (Biometric Information Privacy Act?" (Hiscox) "A written corporate privacy policy which is reviewed by a qualified lawyer and actively followed?" (Hiscox) "Obtaining consent from individuals when collecting Personally Identifiable Information?" (Hiscox) "Does the applicant have a privacy policy in place published on the website?" (Great American Insurance Group) "Are trackers, web beacons and/or pixels used on the Applicant's website?" (Great American Insurance Group) "If yes, is the data being collected in compliance with applicable data privacy laws – specific to consent of user?" (Great American Insurance Group) "If yes, is the data being collected limited to the minimum information necessary to accomplish its purpose and not be used or disclosed beyond what is legally permissible?" (Great American Insurance Group) "If "Yes", have you reviewed your policies relating to the collection, storage and destruction of such information or data with a qualified attorney and confirmed compliance with applicable federal, state, local and foreign laws?" (Tokio Marine HCC) "Does the Applicant sell or share Personal Information?" (AXIS Insurance) "Does the Applicant store or process Personal Information on behalf of a third party?" (AXIS Insurance) "Does the Applicant have a written privacy policy or privacy notice reviewed by an attorney and updated at least annually?" (AXIS Insurance) "Do these policies enable the Applicant to identify all Personal Information subjected to the following activities during the last 12 months?" (AXIS Insurance) "Do these policies enable the Applicant to identify the source(s) from which Personal Information was collected, sold or shared?" (AXIS Insurance) "Do these policies enable the Applicant to identify the business purpose(s) for which Personal Information was collected, sold or shared?" (AXIS Insurance) "Is the Applicant a Healthcare Provider, Business Associate, or Covered Entity under HIPAA?" (Travelers) "If Yes, is the Applicant HIPAA compliant?" (Travelers) "Is the Applicant subject to the General Data Protection Regulation (GDPR?" (Travelers) "Does the Applicant collect, capture, purchase, receive through trade, or otherwise obtain biometric data (biometric data is data related to body measurements and calculations related to human characteristics and includes, but is not limited to, fingerprints, iris or retina scans, voiceprints, sleep/health/exercise data, DNA or biological markers?" (Corvus Insurance) "If user inf ormation is collected, the user has the option to opt-in or opt-out of allowing the collection or use of their information?" (The Hanover Insurance Group) "If Personal Information gathered from customers is sold, the Applicant notifies and obtains consent prior to dissemination of such information?" (The Hanover Insurance Group) "If "Yes", have you reviewed your policies relating to the collection, storage and destruction of such information or data with a qualified attorney and confirmed compliance with applicable federal, state, local and foreign laws?" (Encore Fiduciary) "Does the Applicant's privacy policy allow for the sharing of Confidential Information with third parties?" (Everest Insurance) "Personally Identifiable Information (PII) (non-public information such as social security numbers, driver's licenses, phone numbers, and email addresses?" (Everest Insurance) "Private Health Information (PHI) (e.g., healthcare or medical records?" (Everest Insurance) "Has the Applicant's privacy policy, terms of use, terms of service, and other customer policies been review by an outside counsel?" (Everest Insurance) "Do you have a written Privacy Policy that clearly discloses who You share Personal data with?" (RSA) "Do you have a written privacy policy that is reviewed (at least annually) by qualified legal counsel?" (Munich Re) "Do you share any personal data with third parties?" (Munich Re) "If Yes, do you have data sharing agreements in place with all third parties where personal data is shared?" (Munich Re) "Do you give data subjects the ability to opt-out of allowing personal data to be shared with third parties?" (Munich Re) "Do you have a process in place to respond to data subject requests (e.g. access requests, right to erasure) and Yes No complaints based on applicable data privacy regulations?" (Munich Re) "Do you clearly outline to individuals how any biometric information will be collected, used and/or destroyed?" (Munich Re) "Do you sell, lease, trade or otherwise profit from the biometric information of individuals?" (Munich Re) "Do you subject biometric data to any of the following measures?" (Munich Re) "Have you ever received a complaint relating to the handling of someone's personally identifiable information?" (Hiscox UK) |
| A.8.8 Management of technical vulnerabilities | ISO 27001:2022 | 13 | "How often do you patch your operating sytems?" (CFC Underwriting) "How often do you conduct vulnerability scanning of your network perimeter?" (CFC Underwriting) "How often do you conduct pentration testing of you network architecture?" (CFC Underwriting) "Do you, or an outsourced service provider on your behalf, actively manage and install critical patches across your internet-facing systems?" (Beazley) "Regular updating and patching of critical systems and software in a timely manner?" (Hiscox) "Are there any end-of-life or end-of-support software in use?" (Great American Insurance Group) "When did the Applicant last have a comprehensive (i.e. inclusive of vulnerability scanning and penetration testing) network security assessment completed?" (Great American Insurance Group) "Last 6 Months o Last 18 months o Last 36 months o Never Was the network security assessment completed internally?" (Great American Insurance Group) "Was the network security assessment completed by a Third Party?" (Great American Insurance Group) "What is the Applicant's Critical Patching Target?" (AXIS Insurance) "Does the Applicant maintain a Normal Vulnerability Management patching target within 30 days?" (AXIS Insurance) "Does the Applicant have any End-of-Life software or systems present in its environment?" (AXIS Insurance) "In response to any of these matters, has the Applicant commenced or completed any change to its network and information security and handling practices, or other changes, to remediate the effects of the matter or remove a vulnerability that gave rise to the matter?" (AXIS Insurance) "A process in place to regularly download, test, and install patches If Yes, is this process automated?" (Travelers) "If Yes, are critical patches installed within 30 days of release?" (Travelers) "Annual penetration testing If Yes, is such testing conducted by a third party service provider?" (Travelers) "Annual network security assessments If Yes, are such assessments conducted by a third party service provider?" (Travelers) "Do you conduct penetration testing of your network at least annually?" (Corvus Insurance) "How often does the organization apply updates to critical IT-systems and applications ("security patching"?" (Cowbell Cyber) "Does the applicant track compliance for deploying critical patches?" (QBE) "Does the applicant have a policy (to enforce) when patches must be deployed?" (QBE) "If yes, what is the timeframe critical patches must be deployed?" (QBE) "Does the applicant have any end-of-life (EOL) software or applications currently running on the network?" (QBE) "If yes, how is that patched and managed?" (QBE) "Does the applicant conduct full vulnerability scans across the entirety of its network?" (QBE) "Do you check for security patches to your systems at least weekly and implement them within 30 days?" (CNA) "Do you have up-to-date versions of system security agent software (including malware, antivirus, and firewall protection) and reasonably up-to-date (within 30 days) security patches and virus definitions?" (CNA) "How frequently do you install critical and high severity patches across your enterprise?" (Encore Fiduciary) "Do you have any end of life or end of support software?" (Encore Fiduciary) "Do you use a vulnerability management tool?" (Encore Fiduciary) "If "Yes", complete the following: (1) Provide the name of your provider: (2) What is your patching cadence?" (Encore Fiduciary) "Vulnerability Assessment and Remediation Does the Applicant have a formal process in place to detect software/application vulnerabilities and automatically push critical updates and patches to all computing resources?" (Everest Insurance) "If "Yes", is the length of time required for the deployment of critical updates and patches less than or equal to 2 weeks?" (Everest Insurance) "Do you regularly conduct vulnerability scanning across your internal and external-facing assets?" (Munich Re) "Do you conduct security tests or code analysis during system development, before go-live and after N/A Yes No system changes take place?" (Munich Re) "Do you ensure that any acquired applications/functions and code is free from known vulnerabilities?" (Munich Re) |
| A.8.19 Installation of software on operational systems | ISO 27001:2022 | 13 | "How often do you patch your operating sytems?" (CFC Underwriting) "How often do you conduct vulnerability scanning of your network perimeter?" (CFC Underwriting) "How often do you conduct pentration testing of you network architecture?" (CFC Underwriting) "Do you, or an outsourced service provider on your behalf, actively manage and install critical patches across your internet-facing systems?" (Beazley) "Regular updating and patching of critical systems and software in a timely manner?" (Hiscox) "Are there any end-of-life or end-of-support software in use?" (Great American Insurance Group) "When did the Applicant last have a comprehensive (i.e. inclusive of vulnerability scanning and penetration testing) network security assessment completed?" (Great American Insurance Group) "Last 6 Months o Last 18 months o Last 36 months o Never Was the network security assessment completed internally?" (Great American Insurance Group) "Was the network security assessment completed by a Third Party?" (Great American Insurance Group) "What is the Applicant's Critical Patching Target?" (AXIS Insurance) "Does the Applicant maintain a Normal Vulnerability Management patching target within 30 days?" (AXIS Insurance) "Does the Applicant have any End-of-Life software or systems present in its environment?" (AXIS Insurance) "In response to any of these matters, has the Applicant commenced or completed any change to its network and information security and handling practices, or other changes, to remediate the effects of the matter or remove a vulnerability that gave rise to the matter?" (AXIS Insurance) "A process in place to regularly download, test, and install patches If Yes, is this process automated?" (Travelers) "If Yes, are critical patches installed within 30 days of release?" (Travelers) "Annual penetration testing If Yes, is such testing conducted by a third party service provider?" (Travelers) "Annual network security assessments If Yes, are such assessments conducted by a third party service provider?" (Travelers) "Do you conduct penetration testing of your network at least annually?" (Corvus Insurance) "How often does the organization apply updates to critical IT-systems and applications ("security patching"?" (Cowbell Cyber) "Does the applicant track compliance for deploying critical patches?" (QBE) "Does the applicant have a policy (to enforce) when patches must be deployed?" (QBE) "If yes, what is the timeframe critical patches must be deployed?" (QBE) "Does the applicant have any end-of-life (EOL) software or applications currently running on the network?" (QBE) "If yes, how is that patched and managed?" (QBE) "Does the applicant conduct full vulnerability scans across the entirety of its network?" (QBE) "Do you check for security patches to your systems at least weekly and implement them within 30 days?" (CNA) "How frequently do you install critical and high severity patches across your enterprise?" (Encore Fiduciary) "Do you have any end of life or end of support software?" (Encore Fiduciary) "Do you use a vulnerability management tool?" (Encore Fiduciary) "If "Yes", complete the following: (1) Provide the name of your provider: (2) What is your patching cadence?" (Encore Fiduciary) "Vulnerability Assessment and Remediation Does the Applicant have a formal process in place to detect software/application vulnerabilities and automatically push critical updates and patches to all computing resources?" (Everest Insurance) "If "Yes", is the length of time required for the deployment of critical updates and patches less than or equal to 2 weeks?" (Everest Insurance) "Do you regularly conduct vulnerability scanning across your internal and external-facing assets?" (Munich Re) "Do you conduct security tests or code analysis during system development, before go-live and after N/A Yes No system changes take place?" (Munich Re) "Do you ensure that any acquired applications/functions and code is free from known vulnerabilities?" (Munich Re) |
| A.8.20 Networks security | ISO 27001:2022 | 13 | "If yes, is it segregated from the network?" (Great American Insurance Group) "Are firewalls rules and alerts regularly reviewed?" (Great American Insurance Group) "Do you use anti-virus software and a firewall to protect your network?" (Tokio Marine HCC) "Do you allow remote access to your network?" (Tokio Marine HCC) "(2) Do you utilize IP whitelisting to further protect remote access connections?" (Tokio Marine HCC) "Have you disabled the Remote Desktop Protocol (RDP) and/or Remote Desktop Gateway (RDG) on all system endpoints and servers?" (Tokio Marine HCC) "Is Remote Desktop Protocol (RDP) enabled?" (AXIS Insurance) "Is RDP accessible externally?" (AXIS Insurance) "Are these policies, practices and solutions applied to the Firewalls Intrusion detection and following?" (AXIS Insurance) "Are all internet-accessible systems (e.g. web-, email-servers) segregated from the organization's trusted network (e.g. within a demilitarized zone (DMZ) or at a third-party service provider?" (Cowbell Cyber) "Does the applicant segment the network via Next Generation Firewalls, Virtual Local Area Networks (VLAN), demilitarized zones (DMZ), etc.?" (QBE) "How does the applicant eliminate or limit lateral movement within its network?" (QBE) "Does the applicant utilize remote desktop protocol (RDP?" (QBE) "Is this behind a Virtual Private Network (VPN) or gateway?" (QBE) "Is RDP ever exposed to the internet?" (QBE) "Has traf fic using Remote Desktop Protocol (RDP) TCP ports 3389 and Server Message Block (SMB) TCP ports 445, 135, and 139 been blocked?" (The Hanover Insurance Group) "If no, how is remote access to the network controlled?" (The Hartford) "Have you installed firewalls between your internal network and the Internet?" (CNA) "Within the Applicant's organization, who is responsible for network security?" (Encore Fiduciary) "If the Applicant's network security is outsourced, are you the main contact for the network security provider named in question b. above?" (Encore Fiduciary) "Do you allow remote access to your network?" (Encore Fiduciary) "ZScaler, Quad9, OpenDNS or the public sector PDNS to block access to known malicious websites?" (Encore Fiduciary) "Is network segmentation (e.g., firewalls, software- defined networking) used to limit movement across the network?" (Everest Insurance) "VPN, remote desktop?" (Everest Insurance) "You secure remote access (access control procedures to prevent unauthorised access) to Your network and Your data?" (RSA) "What firewall(s) do you use?" (RSA) "Is a Web Application Firewall (WAF) used to protect publicly exposed web application?" (Munich Re) "Do you ensure that all publicly facing ports are protected by a pre-configured firewall that blocks unauthorised Yes No network traffic?" (Munich Re) "Do you regularly scan publicly accessible ports and ensure unnecessary ones are locked down?" (Munich Re) "Do you allow Remote Desktop Protocol (RDP) connections?" (Munich Re) "How is web traffic filtered?" (Munich Re) "Have you configured host-based and network firewalls to disallow inbound connections by default?" (Munich Re) "Do you perform periodic reviews of firewall rules to ensure configurations are on a need-to-have basis?" (Munich Re) "Do you utilize any of the following technologies to physically or logically segregate your network?" (Munich Re) "Do you update all systems including firewalls and anti-virus software at least every 30 days?" (Hiscox UK) |
| A.8.29 Security testing in development and acceptance | ISO 27001:2022 | 13 | "How often do you patch your operating sytems?" (CFC Underwriting) "How often do you conduct vulnerability scanning of your network perimeter?" (CFC Underwriting) "How often do you conduct pentration testing of you network architecture?" (CFC Underwriting) "Do you, or an outsourced service provider on your behalf, actively manage and install critical patches across your internet-facing systems?" (Beazley) "Regular updating and patching of critical systems and software in a timely manner?" (Hiscox) "Are there any end-of-life or end-of-support software in use?" (Great American Insurance Group) "When did the Applicant last have a comprehensive (i.e. inclusive of vulnerability scanning and penetration testing) network security assessment completed?" (Great American Insurance Group) "Last 6 Months o Last 18 months o Last 36 months o Never Was the network security assessment completed internally?" (Great American Insurance Group) "Was the network security assessment completed by a Third Party?" (Great American Insurance Group) "What is the Applicant's Critical Patching Target?" (AXIS Insurance) "Does the Applicant maintain a Normal Vulnerability Management patching target within 30 days?" (AXIS Insurance) "Does the Applicant have any End-of-Life software or systems present in its environment?" (AXIS Insurance) "In response to any of these matters, has the Applicant commenced or completed any change to its network and information security and handling practices, or other changes, to remediate the effects of the matter or remove a vulnerability that gave rise to the matter?" (AXIS Insurance) "A process in place to regularly download, test, and install patches If Yes, is this process automated?" (Travelers) "If Yes, are critical patches installed within 30 days of release?" (Travelers) "Annual penetration testing If Yes, is such testing conducted by a third party service provider?" (Travelers) "Annual network security assessments If Yes, are such assessments conducted by a third party service provider?" (Travelers) "Do you conduct penetration testing of your network at least annually?" (Corvus Insurance) "How often does the organization apply updates to critical IT-systems and applications ("security patching"?" (Cowbell Cyber) "Does the applicant track compliance for deploying critical patches?" (QBE) "Does the applicant have a policy (to enforce) when patches must be deployed?" (QBE) "If yes, what is the timeframe critical patches must be deployed?" (QBE) "Does the applicant have any end-of-life (EOL) software or applications currently running on the network?" (QBE) "If yes, how is that patched and managed?" (QBE) "Does the applicant conduct full vulnerability scans across the entirety of its network?" (QBE) "Do you check for security patches to your systems at least weekly and implement them within 30 days?" (CNA) "How frequently do you install critical and high severity patches across your enterprise?" (Encore Fiduciary) "Do you have any end of life or end of support software?" (Encore Fiduciary) "Do you use a vulnerability management tool?" (Encore Fiduciary) "If "Yes", complete the following: (1) Provide the name of your provider: (2) What is your patching cadence?" (Encore Fiduciary) "Vulnerability Assessment and Remediation Does the Applicant have a formal process in place to detect software/application vulnerabilities and automatically push critical updates and patches to all computing resources?" (Everest Insurance) "If "Yes", is the length of time required for the deployment of critical updates and patches less than or equal to 2 weeks?" (Everest Insurance) "Do you regularly conduct vulnerability scanning across your internal and external-facing assets?" (Munich Re) "Do you conduct security tests or code analysis during system development, before go-live and after N/A Yes No system changes take place?" (Munich Re) "Do you ensure that any acquired applications/functions and code is free from known vulnerabilities?" (Munich Re) |
| ID.RA-01 Vulnerabilities in assets are identified, validated, and recorded | NIST CSF 2.0 | 13 | "How often do you patch your operating sytems?" (CFC Underwriting) "How often do you conduct vulnerability scanning of your network perimeter?" (CFC Underwriting) "How often do you conduct pentration testing of you network architecture?" (CFC Underwriting) "Do you, or an outsourced service provider on your behalf, actively manage and install critical patches across your internet-facing systems?" (Beazley) "Regular updating and patching of critical systems and software in a timely manner?" (Hiscox) "Are there any end-of-life or end-of-support software in use?" (Great American Insurance Group) "When did the Applicant last have a comprehensive (i.e. inclusive of vulnerability scanning and penetration testing) network security assessment completed?" (Great American Insurance Group) "Last 6 Months o Last 18 months o Last 36 months o Never Was the network security assessment completed internally?" (Great American Insurance Group) "Was the network security assessment completed by a Third Party?" (Great American Insurance Group) "What is the Applicant's Critical Patching Target?" (AXIS Insurance) "Does the Applicant maintain a Normal Vulnerability Management patching target within 30 days?" (AXIS Insurance) "Does the Applicant have any End-of-Life software or systems present in its environment?" (AXIS Insurance) "In response to any of these matters, has the Applicant commenced or completed any change to its network and information security and handling practices, or other changes, to remediate the effects of the matter or remove a vulnerability that gave rise to the matter?" (AXIS Insurance) "A process in place to regularly download, test, and install patches If Yes, is this process automated?" (Travelers) "If Yes, are critical patches installed within 30 days of release?" (Travelers) "Annual penetration testing If Yes, is such testing conducted by a third party service provider?" (Travelers) "Annual network security assessments If Yes, are such assessments conducted by a third party service provider?" (Travelers) "Do you conduct penetration testing of your network at least annually?" (Corvus Insurance) "How often does the organization apply updates to critical IT-systems and applications ("security patching"?" (Cowbell Cyber) "Does the applicant track compliance for deploying critical patches?" (QBE) "Does the applicant have a policy (to enforce) when patches must be deployed?" (QBE) "If yes, what is the timeframe critical patches must be deployed?" (QBE) "Does the applicant have any end-of-life (EOL) software or applications currently running on the network?" (QBE) "If yes, how is that patched and managed?" (QBE) "Does the applicant conduct full vulnerability scans across the entirety of its network?" (QBE) "Do you check for security patches to your systems at least weekly and implement them within 30 days?" (CNA) "How frequently do you install critical and high severity patches across your enterprise?" (Encore Fiduciary) "Do you have any end of life or end of support software?" (Encore Fiduciary) "Do you use a vulnerability management tool?" (Encore Fiduciary) "If "Yes", complete the following: (1) Provide the name of your provider: (2) What is your patching cadence?" (Encore Fiduciary) "Vulnerability Assessment and Remediation Does the Applicant have a formal process in place to detect software/application vulnerabilities and automatically push critical updates and patches to all computing resources?" (Everest Insurance) "If "Yes", is the length of time required for the deployment of critical updates and patches less than or equal to 2 weeks?" (Everest Insurance) "Do you regularly conduct vulnerability scanning across your internal and external-facing assets?" (Munich Re) "Do you conduct security tests or code analysis during system development, before go-live and after N/A Yes No system changes take place?" (Munich Re) "Do you ensure that any acquired applications/functions and code is free from known vulnerabilities?" (Munich Re) |
| PR.PS-02 Software is maintained, replaced, and removed commensurate with risk | NIST CSF 2.0 | 13 | "How often do you patch your operating sytems?" (CFC Underwriting) "How often do you conduct vulnerability scanning of your network perimeter?" (CFC Underwriting) "How often do you conduct pentration testing of you network architecture?" (CFC Underwriting) "Do you, or an outsourced service provider on your behalf, actively manage and install critical patches across your internet-facing systems?" (Beazley) "Regular updating and patching of critical systems and software in a timely manner?" (Hiscox) "Are there any end-of-life or end-of-support software in use?" (Great American Insurance Group) "When did the Applicant last have a comprehensive (i.e. inclusive of vulnerability scanning and penetration testing) network security assessment completed?" (Great American Insurance Group) "Last 6 Months o Last 18 months o Last 36 months o Never Was the network security assessment completed internally?" (Great American Insurance Group) "Was the network security assessment completed by a Third Party?" (Great American Insurance Group) "What is the Applicant's Critical Patching Target?" (AXIS Insurance) "Does the Applicant maintain a Normal Vulnerability Management patching target within 30 days?" (AXIS Insurance) "Does the Applicant have any End-of-Life software or systems present in its environment?" (AXIS Insurance) "In response to any of these matters, has the Applicant commenced or completed any change to its network and information security and handling practices, or other changes, to remediate the effects of the matter or remove a vulnerability that gave rise to the matter?" (AXIS Insurance) "A process in place to regularly download, test, and install patches If Yes, is this process automated?" (Travelers) "If Yes, are critical patches installed within 30 days of release?" (Travelers) "Annual penetration testing If Yes, is such testing conducted by a third party service provider?" (Travelers) "Annual network security assessments If Yes, are such assessments conducted by a third party service provider?" (Travelers) "Do you conduct penetration testing of your network at least annually?" (Corvus Insurance) "How often does the organization apply updates to critical IT-systems and applications ("security patching"?" (Cowbell Cyber) "Does the applicant track compliance for deploying critical patches?" (QBE) "Does the applicant have a policy (to enforce) when patches must be deployed?" (QBE) "If yes, what is the timeframe critical patches must be deployed?" (QBE) "Does the applicant have any end-of-life (EOL) software or applications currently running on the network?" (QBE) "If yes, how is that patched and managed?" (QBE) "Does the applicant conduct full vulnerability scans across the entirety of its network?" (QBE) "Do you check for security patches to your systems at least weekly and implement them within 30 days?" (CNA) "How frequently do you install critical and high severity patches across your enterprise?" (Encore Fiduciary) "Do you have any end of life or end of support software?" (Encore Fiduciary) "Do you use a vulnerability management tool?" (Encore Fiduciary) "If "Yes", complete the following: (1) Provide the name of your provider: (2) What is your patching cadence?" (Encore Fiduciary) "Vulnerability Assessment and Remediation Does the Applicant have a formal process in place to detect software/application vulnerabilities and automatically push critical updates and patches to all computing resources?" (Everest Insurance) "If "Yes", is the length of time required for the deployment of critical updates and patches less than or equal to 2 weeks?" (Everest Insurance) "Do you regularly conduct vulnerability scanning across your internal and external-facing assets?" (Munich Re) "Do you conduct security tests or code analysis during system development, before go-live and after N/A Yes No system changes take place?" (Munich Re) "Do you ensure that any acquired applications/functions and code is free from known vulnerabilities?" (Munich Re) |
| PR.AA-01 Identities and credentials for authorized users, services, and hardware are managed by the organization | NIST CSF 2.0 | 12 | "If No, is such information stored on a segregated server with role-based access controls?" (Hiscox) "in place with all third parties that have access to sensitive information, including business associate agreements?" (Hiscox) "A policy that requires strong passwords that should be updated on a regular basis?" (Hiscox) "Employee access to systems and data is limited to only what they need to do their job?" (Hiscox) "Employee access to systems and data is cut when employees leave the organization?" (Hiscox) "Does the Applicant terminate all computer access and user accounts as part of the regular exit process when an employee leaves the company or when a third party contractor no longer provides the contracted services?" (AmTrust) "Password/passcode protected Encryption Traditional or next generation firewalls enabled/turned on Traditional or next generation antivirus products on all endpoints Endpoint Detection and Response (EDR) 24/7/365 on all devices If yes to EDR, Who is your provider?" (Great American Insurance Group) "Are firewalls configured according to the principles of least privileges?" (Great American Insurance Group) "(2) Access control with role-based assignments?" (Tokio Marine HCC) "(b) segregated with 2-factor authentication access control?" (Tokio Marine HCC) "(3) A separation of authority protocol?" (Tokio Marine HCC) "What security controls are in place to protect against unauthorized access to sensitive and confidential data?" (Corvus Insurance) "Do these users require additional credentials to access?" (QBE) "What is the minimum length for passwords?" (QBE) "Can backups only be accessed via an authentication mechanism (i.e., MFA/password vault/separate credentials or credential checkout?" (QBE) "Do you set up a separate account for each user (including any contractors needing access?" (CNA) "Do you enforce a strong/complex password policy of at least 8-20 characters?" (CNA) "Do you physically and electronically limit access to sensitive information on a need –to-know basis and revoke access privileges upon a reduction in an individual's need to know?" (CNA) "Information Security and Cyber Infrastructure Self-Assessment 14 On your wireless networks; do you use security at least as strong as WPA2 authentication and encryption, and do you require two factor authentication (access token and password/account logon) before allowing wireless connections to your network?" (CNA) "Do you physically and electronically limit access to sensitive information on a need-to-know basis and revoke access privileges upon a reduction in an individual's need to know?" (CNA) "On your wireless networks; do you use security at least as strong as WPA2 authentication and encryption, and do you require two factor authentication (access token and password/account logon) before allowing wireless connections to your network?" (CNA) "(2) Access control with role-based assignments?" (Encore Fiduciary) "(3) A separation of authority protocol?" (Encore Fiduciary) "Does the Applicant restrict access based on job function and responsibilities?" (Everest Insurance) "Does the Applicant enforce password changes every 8-12 weeks?" (Everest Insurance) "Is access to the internet from terminals restricted for employees?" (Everest Insurance) "The backup of Your Critical Data is stored in a secure locked location with access restricted to authorised personnel only?" (RSA) "You secure remote access (access control procedures to prevent unauthorised access) to Your network and Your data?" (RSA) "You enforce a policy of auditing of managing computer and user accounts?" (RSA) "Do you perform background checks on employees & contractors who have access to sensitive information?" (Munich Re) "Do you terminate user access rights as part of the employee exit process?" (Munich Re) "Do you restrict user access (employees, contractors etc.) on a business need-to-know & least-privilege basis?" (Munich Re) "Do you have a central Identity & Access Management ("IAM") system for assigning and revoking access rights?" (Munich Re) "Do you have a formal process in place for assigning and revoking user accounts and access rights?" (Munich Re) "Do assets owners review access rights at least annually?" (Munich Re) "Do you configure service accounts using the principle of least privilege?" (Munich Re) "Are unique backup credentials stored separately from other user credentials?" (Munich Re) "Do you periodically review and update vendor access rights?" (Munich Re) "Do you have a formal password policy that explains good password hygiene, such as not using obvious or repeated passwords, for all systems providing access to personal or confidential information?" (Hiscox UK) |
| A.8.23 Web filtering | ISO 27001:2022 | 12 | "What security controls do you have in place for incoming email?" (Beazley) "How often do you conduct interactive social engineering (i.e., phishing) training?" (Beazley) "Do you use the Microsoft 365 Defender add-on or an equivalent cybersecurity product with advanced threat hunting to protect against phishing and business email compromise?" (Beazley) "Are employees who are responsible for disbursing or transmitting funds provided anti-fraud training, including detection of social engineering, phishing, business email compromise and other scams, on at least an annual basis?" (Beazley) "in place to ensure compliance with the Telephone Consumer Protection Act, anti-SPAM statutes, and any other consumer protection act?" (Hiscox) "Are Sender Policy Framework (SPF), Domain-based Message Authentication Reporting and Compliance (DMARC) or Domain Keys Identified Mail (DKIM) in place?" (Great American Insurance Group) "Is an email filtering tool in place to detect and/or block SPAM, malicious links, and attachments?" (Great American Insurance Group) "Do you use an email filtering solution designed to prevent phishing or ransomware attacks (in addition to any filtering solution(s) provided by your email provider?" (Tokio Marine HCC) "If "Yes" to question 7.a.(1) or 7.a.(2) above, does your social engineering training include phishing simulation?" (Tokio Marine HCC) "Does the Applicant employ any of the following SPF DKIM DMARC solutions?" (AXIS Insurance) "Does the Applicant conduct mandatory information security, phishing and privacy training for employees and contractors at least quarterly?" (AXIS Insurance) "Are Phishing Simulations conducted for all employees?" (AXIS Insurance) "Does the Applicant have a report phishing email add-in enabled for all email users?" (AXIS Insurance) "Does the company scan email for potentially malicious attachments and / or links?" (RLI) "Do you have email filtering in place?" (Corvus Insurance) "Do you conduct employee security training or phishing training, for all employees, at least annually?" (Corvus Insurance) "Phishing a. How often does the applicant use simulated phishing attacks to test employees?" (QBE) "Does the applicant flag external emails?" (QBE) "Email filtering Does the applicant utilize email filtering protocols such as Domain-based Message Authentication, Reporting and Conformance (DMARC), DomainKeys Identified Mail (DKIM), or Sender Policy Framework (SPF?" (QBE) "Detect and identify social engineering/phishing scams where a f raudulent email or phone call f rom purported vendor or client is received, requesting their vendor or client bank account inf ormation be changed?" (The Hanover Insurance Group) "Detect and identify social engineering/phishing scams where a f raudulent email or phone call f rom a purported owner or employee of the Applicant is received, requesting a wire transfer be made on their behalf?" (The Hanover Insurance Group) "for malicious attachments Screening for malicious links Tagging emails from external senders How often is Antiphishing and Cybersecurity Awareness training conducted for employees?" (The Hartford) "Do you tag external emails to alert employees that the message originated from outside the organization?" (Encore Fiduciary) "Do you pre-screen emails for potentially malicious attachments and links?" (Encore Fiduciary) "If "Yes", complete the following: (1) Provide the name of your email pre-screen provider: (2) Do you have the capability to automatically detonate and evaluate attachments in a sandbox to determine if they are malicious prior to delivery to the end-user?" (Encore Fiduciary) "Have you implemented any of the following to protect against phishing messages?" (Encore Fiduciary) "Sender Policy Framework (SPF) Domain Keys Identified Mail (DKIM) Domain-based Message Authentication, Reporting & Conformance (DMARC) None of the above d.Can your users access email through a web application or a non-corporate device?" (Encore Fiduciary) "If "Yes", do you use the Office 365 Advanced Threat Protection add-on?" (Encore Fiduciary) "If "Yes" to question 9.a.(1) or 9.a.(2) above, does your social engineering training include phishing simulation?" (Encore Fiduciary) "Do you conduct employee phishing campaigns?" (Munich Re) "How often are phishing campaigns conducted?" (Munich Re) "Do you mandate additional training to those employees who fail to acknowledge phishing emails?" (Munich Re) "Do you implement any of the following controls to protect against malicious emails?" (Munich Re) "Do you scan incoming emails for malicious attachments and/or links?" (Munich Re) "Do you have the ability to automatically quarantine, detonate and evaluate attachments?" (Munich Re) "Are blocked emails classed as incidents and remediated?" (Munich Re) "Do you tag external emails to alert employees that the message originated from outside the organization?" (Munich Re) |
| A.8.22 Segregation of networks | ISO 27001:2022 | 12 | "If yes, is it segregated from the network?" (Great American Insurance Group) "Do you allow remote access to your network?" (Tokio Marine HCC) "(2) Do you utilize IP whitelisting to further protect remote access connections?" (Tokio Marine HCC) "Have you disabled the Remote Desktop Protocol (RDP) and/or Remote Desktop Gateway (RDG) on all system endpoints and servers?" (Tokio Marine HCC) "Is Remote Desktop Protocol (RDP) enabled?" (AXIS Insurance) "Is RDP accessible externally?" (AXIS Insurance) "Are all internet-accessible systems (e.g. web-, email-servers) segregated from the organization's trusted network (e.g. within a demilitarized zone (DMZ) or at a third-party service provider?" (Cowbell Cyber) "Does the applicant segment the network via Next Generation Firewalls, Virtual Local Area Networks (VLAN), demilitarized zones (DMZ), etc.?" (QBE) "How does the applicant eliminate or limit lateral movement within its network?" (QBE) "Does the applicant utilize remote desktop protocol (RDP?" (QBE) "Is this behind a Virtual Private Network (VPN) or gateway?" (QBE) "Is RDP ever exposed to the internet?" (QBE) "Has traf fic using Remote Desktop Protocol (RDP) TCP ports 3389 and Server Message Block (SMB) TCP ports 445, 135, and 139 been blocked?" (The Hanover Insurance Group) "If no, how is remote access to the network controlled?" (The Hartford) "Have you installed firewalls between your internal network and the Internet?" (CNA) "Within the Applicant's organization, who is responsible for network security?" (Encore Fiduciary) "If the Applicant's network security is outsourced, are you the main contact for the network security provider named in question b. above?" (Encore Fiduciary) "Do you allow remote access to your network?" (Encore Fiduciary) "ZScaler, Quad9, OpenDNS or the public sector PDNS to block access to known malicious websites?" (Encore Fiduciary) "Is network segmentation (e.g., firewalls, software- defined networking) used to limit movement across the network?" (Everest Insurance) "VPN, remote desktop?" (Everest Insurance) "You secure remote access (access control procedures to prevent unauthorised access) to Your network and Your data?" (RSA) "What firewall(s) do you use?" (RSA) "Is a Web Application Firewall (WAF) used to protect publicly exposed web application?" (Munich Re) "Do you ensure that all publicly facing ports are protected by a pre-configured firewall that blocks unauthorised Yes No network traffic?" (Munich Re) "Do you regularly scan publicly accessible ports and ensure unnecessary ones are locked down?" (Munich Re) "Do you allow Remote Desktop Protocol (RDP) connections?" (Munich Re) "How is web traffic filtered?" (Munich Re) "Have you configured host-based and network firewalls to disallow inbound connections by default?" (Munich Re) "Do you perform periodic reviews of firewall rules to ensure configurations are on a need-to-have basis?" (Munich Re) "Do you utilize any of the following technologies to physically or logically segregate your network?" (Munich Re) |
| A.5.29 Information security during disruption | ISO 27001:2022 | 12 | "If the Applicant's customer is primarily dependent on the product or service provided by the Applicant, does the Applicant have a contingency plan in place to address this exposure?" (Chubb) "Do you have a Business Continuity or Disaster Recovery Plan in place that covers cyber event scenarios, such as ransomware attacks?" (Hiscox) "If Yes, is this Plan regularly tested?" (Hiscox) "If you suffer a network disruption, how long would it take to become fully operational?" (Hiscox) "Are back-up restoration plans tested?" (Great American Insurance Group) "Does the Applicant have a written business continuity plan?" (AXIS Insurance) "How frequently is this plan tested?" (AXIS Insurance) "Does the Applicant have a written disaster recovery plan?" (AXIS Insurance) "Are copies of the business continuity/disaster recovery and incident response plans stored so that they will be accessible if the Applicant's network became completely unavailable?" (AXIS Insurance) "Is full recovery from a backup tested at least annually?" (AXIS Insurance) "In the event of an interruption of the Applicant's network, at most how long is the Applicant's recovery time objective (RTO) for critical systems, applications, and processes?" (AXIS Insurance) "If Yes, are such procedures tested on an annual basis?" (Travelers) "Are all plans indicated above tested regularly with any critical deficiencies remediated?" (Travelers) "Do you have a Business Continuity Plan (BCP) or Disaster Recovery Plan (DRP) in place?" (Corvus Insurance) "Does the organization have an incident response plan - tested and in-effect - setting forth specific action items and responsibilities for relevant parties in the event of a cyber incident or data breach matter?" (Cowbell Cyber) "Has the organization tested a full failover of the most critical servers?" (Cowbell Cyber) "What is the applicant's target recovery time objective (RTO) for critical systems?" (QBE) "Are backups tested for vulnerabilities/malware prior to restoration?" (QBE) "How often are full network failover tests conducted?" (QBE) "Do all applicants have a Cyber Incident Response Plan or Business Continuity plan in place to respond to a computer system disruption?" (The Hartford) "If yes, how often is the Cyber Incident Response or Business Continuity plan tested?" (The Hartford) "Does the Applicant have documented business continuity and disaster recovery plans?" (Everest Insurance) "Does the Applicant maintain redundant backups of sensitive and critical system information?" (Everest Insurance) "have a Business Continuity Plan or Disaster Response plan which includes Cyber perils?" (RSA) "Do you have a written business continuity or disaster recovery plan that addresses network outages & cyber-attacks?" (Munich Re) "What is your Recovery Time Objective (RTO) for critical systems?" (Munich Re) "Do you have a defined Recovery Point Objective (RPO) for critical systems?" (Munich Re) "Have you planned for redundancy for your critical system infrastructure?" (Munich Re) "Do you conduct redundancy testing at least annually to ensure that failover works as intended?" (Munich Re) |
| PR.IR-03 Mechanisms are implemented to achieve resilience requirements in normal and adverse situations | NIST CSF 2.0 | 12 | "If the Applicant's customer is primarily dependent on the product or service provided by the Applicant, does the Applicant have a contingency plan in place to address this exposure?" (Chubb) "Do you have a Business Continuity or Disaster Recovery Plan in place that covers cyber event scenarios, such as ransomware attacks?" (Hiscox) "If Yes, is this Plan regularly tested?" (Hiscox) "If you suffer a network disruption, how long would it take to become fully operational?" (Hiscox) "Are back-up restoration plans tested?" (Great American Insurance Group) "Does the Applicant have a written business continuity plan?" (AXIS Insurance) "How frequently is this plan tested?" (AXIS Insurance) "Does the Applicant have a written disaster recovery plan?" (AXIS Insurance) "Are copies of the business continuity/disaster recovery and incident response plans stored so that they will be accessible if the Applicant's network became completely unavailable?" (AXIS Insurance) "Is full recovery from a backup tested at least annually?" (AXIS Insurance) "In the event of an interruption of the Applicant's network, at most how long is the Applicant's recovery time objective (RTO) for critical systems, applications, and processes?" (AXIS Insurance) "If Yes, are such procedures tested on an annual basis?" (Travelers) "Are all plans indicated above tested regularly with any critical deficiencies remediated?" (Travelers) "Do you have a Business Continuity Plan (BCP) or Disaster Recovery Plan (DRP) in place?" (Corvus Insurance) "Does the organization have an incident response plan - tested and in-effect - setting forth specific action items and responsibilities for relevant parties in the event of a cyber incident or data breach matter?" (Cowbell Cyber) "Has the organization tested a full failover of the most critical servers?" (Cowbell Cyber) "What is the applicant's target recovery time objective (RTO) for critical systems?" (QBE) "Are backups tested for vulnerabilities/malware prior to restoration?" (QBE) "How often are full network failover tests conducted?" (QBE) "Do all applicants have a Cyber Incident Response Plan or Business Continuity plan in place to respond to a computer system disruption?" (The Hartford) "If yes, how often is the Cyber Incident Response or Business Continuity plan tested?" (The Hartford) "Does the Applicant have documented business continuity and disaster recovery plans?" (Everest Insurance) "Does the Applicant maintain redundant backups of sensitive and critical system information?" (Everest Insurance) "have a Business Continuity Plan or Disaster Response plan which includes Cyber perils?" (RSA) "Do you have a written business continuity or disaster recovery plan that addresses network outages & cyber-attacks?" (Munich Re) "What is your Recovery Time Objective (RTO) for critical systems?" (Munich Re) "Do you have a defined Recovery Point Objective (RPO) for critical systems?" (Munich Re) "Have you planned for redundancy for your critical system infrastructure?" (Munich Re) "Do you conduct redundancy testing at least annually to ensure that failover works as intended?" (Munich Re) |
| A.7.10 Storage media | ISO 27001:2022 | 12 | "Does Named Insured enable disk encryption on laptops, desktops, and other portable media devices?" (Coalition) "Is this information encrypted while at rest?" (Hiscox) "Is this information stored on mobile computing devices, including laptops or smart phones?" (Hiscox) "in place that scan both encrypted and unencrypted data to restrict network traffic?" (Hiscox) "Are users able to store data to the hard drive of portable computers or portable media devices such as USB drives?" (AmTrust) "Does the Applicant encrypt data stored on laptop computers and portable media?" (AmTrust) "Do you encrypt all sensitive and confidential information stored on your organization's systems and networks?" (Tokio Marine HCC) "Does the applicant encrypt all physical devices, critical data, sensitive emails?" (RLI) "Does the organization encrypt sensitive information stored on the cloud?" (Cowbell Cyber) "Does the applicant have a policy that all portable devices use full disk encryption?" (QBE) "Have you identified the paper, electronic, and other records, computing systems, and storage media including laptops, mobile phones, and portable devices that contain sensitive information?" (CNA) "Do you encrypt all sensitive records and files that are held at rest and/or transmitted across public networks, and that are to be transmitted wirelessly?" (CNA) "Do you encrypt all sensitive and confidential information stored on your organization's systems and networks?" (Encore Fiduciary) "If "No", please use the Additional Comments section to outline which assets do not have EDR, and whether any mitigating safeguards are in place for such assets. (4) Can users access the network with their own device ("Bring Your Own Device"?" (Encore Fiduciary) "Do you roll out a hardened baseline configuration across servers, laptops, desktops and managed mobile devices?" (Encore Fiduciary) "on mobile assets (e.g., laptops, phones, tablets, flash drives?" (Everest Insurance) "Are all mobile devices managed using a Mobile Device Management (MDM) solution?" (Munich Re) "Do you disable media ports or restrict usage to only encrypted removable storage devices?" (Munich Re) "Do you allow employees to use personal mobile devices to access company data (e.g. email?" (Munich Re) "If Yes, do you have a Bring Your Own Device (BYOD) policy in place that governs usage and controls?" (Munich Re) "Do you enforce the use of encryption of sensitive information while at rest (e.g. on premise, mobile device, Yes No cloud?" (Munich Re) "Do you have a policy to encrypt mobile computing devices (for example laptops, tablets, mobile telephones, PDAs) and portable data storage media (for example external drives or magnetic tapes) which hold, process, transact or store any of the personal data referred to in 1.7?" (Hiscox UK) |
| A.5.30 ICT readiness for business continuity | ISO 27001:2022 | 11 | "If the Applicant's customer is primarily dependent on the product or service provided by the Applicant, does the Applicant have a contingency plan in place to address this exposure?" (Chubb) "Do you have a Business Continuity or Disaster Recovery Plan in place that covers cyber event scenarios, such as ransomware attacks?" (Hiscox) "If Yes, is this Plan regularly tested?" (Hiscox) "If you suffer a network disruption, how long would it take to become fully operational?" (Hiscox) "Does the Applicant have a written business continuity plan?" (AXIS Insurance) "How frequently is this plan tested?" (AXIS Insurance) "Does the Applicant have a written disaster recovery plan?" (AXIS Insurance) "Are copies of the business continuity/disaster recovery and incident response plans stored so that they will be accessible if the Applicant's network became completely unavailable?" (AXIS Insurance) "In the event of an interruption of the Applicant's network, at most how long is the Applicant's recovery time objective (RTO) for critical systems, applications, and processes?" (AXIS Insurance) "If Yes, are such procedures tested on an annual basis?" (Travelers) "Are all plans indicated above tested regularly with any critical deficiencies remediated?" (Travelers) "Do you have a Business Continuity Plan (BCP) or Disaster Recovery Plan (DRP) in place?" (Corvus Insurance) "Does the organization have an incident response plan - tested and in-effect - setting forth specific action items and responsibilities for relevant parties in the event of a cyber incident or data breach matter?" (Cowbell Cyber) "Has the organization tested a full failover of the most critical servers?" (Cowbell Cyber) "What is the applicant's target recovery time objective (RTO) for critical systems?" (QBE) "How often are full network failover tests conducted?" (QBE) "Do all applicants have a Cyber Incident Response Plan or Business Continuity plan in place to respond to a computer system disruption?" (The Hartford) "If yes, how often is the Cyber Incident Response or Business Continuity plan tested?" (The Hartford) "Does the Applicant have documented business continuity and disaster recovery plans?" (Everest Insurance) "have a Business Continuity Plan or Disaster Response plan which includes Cyber perils?" (RSA) "Do you have a written business continuity or disaster recovery plan that addresses network outages & cyber-attacks?" (Munich Re) "What is your Recovery Time Objective (RTO) for critical systems?" (Munich Re) "Do you have a defined Recovery Point Objective (RPO) for critical systems?" (Munich Re) "Have you planned for redundancy for your critical system infrastructure?" (Munich Re) "Do you conduct redundancy testing at least annually to ensure that failover works as intended?" (Munich Re) |
| CC9.1 Mitigating risks of business disruption | SOC 2 | 11 | "If the Applicant's customer is primarily dependent on the product or service provided by the Applicant, does the Applicant have a contingency plan in place to address this exposure?" (Chubb) "Do you have a Business Continuity or Disaster Recovery Plan in place that covers cyber event scenarios, such as ransomware attacks?" (Hiscox) "If Yes, is this Plan regularly tested?" (Hiscox) "If you suffer a network disruption, how long would it take to become fully operational?" (Hiscox) "Does the Applicant have a written business continuity plan?" (AXIS Insurance) "How frequently is this plan tested?" (AXIS Insurance) "Does the Applicant have a written disaster recovery plan?" (AXIS Insurance) "Are copies of the business continuity/disaster recovery and incident response plans stored so that they will be accessible if the Applicant's network became completely unavailable?" (AXIS Insurance) "In the event of an interruption of the Applicant's network, at most how long is the Applicant's recovery time objective (RTO) for critical systems, applications, and processes?" (AXIS Insurance) "If Yes, are such procedures tested on an annual basis?" (Travelers) "Are all plans indicated above tested regularly with any critical deficiencies remediated?" (Travelers) "Do you have a Business Continuity Plan (BCP) or Disaster Recovery Plan (DRP) in place?" (Corvus Insurance) "Does the organization have an incident response plan - tested and in-effect - setting forth specific action items and responsibilities for relevant parties in the event of a cyber incident or data breach matter?" (Cowbell Cyber) "Has the organization tested a full failover of the most critical servers?" (Cowbell Cyber) "What is the applicant's target recovery time objective (RTO) for critical systems?" (QBE) "How often are full network failover tests conducted?" (QBE) "Do all applicants have a Cyber Incident Response Plan or Business Continuity plan in place to respond to a computer system disruption?" (The Hartford) "If yes, how often is the Cyber Incident Response or Business Continuity plan tested?" (The Hartford) "Does the Applicant have documented business continuity and disaster recovery plans?" (Everest Insurance) "have a Business Continuity Plan or Disaster Response plan which includes Cyber perils?" (RSA) "Do you have a written business continuity or disaster recovery plan that addresses network outages & cyber-attacks?" (Munich Re) "What is your Recovery Time Objective (RTO) for critical systems?" (Munich Re) "Do you have a defined Recovery Point Objective (RPO) for critical systems?" (Munich Re) "Have you planned for redundancy for your critical system infrastructure?" (Munich Re) "Do you conduct redundancy testing at least annually to ensure that failover works as intended?" (Munich Re) |
| RC.RP-01 The recovery portion of the incident response plan is executed once initiated from the incident response process | NIST CSF 2.0 | 11 | "If the Applicant's customer is primarily dependent on the product or service provided by the Applicant, does the Applicant have a contingency plan in place to address this exposure?" (Chubb) "Do you have a Business Continuity or Disaster Recovery Plan in place that covers cyber event scenarios, such as ransomware attacks?" (Hiscox) "If Yes, is this Plan regularly tested?" (Hiscox) "If you suffer a network disruption, how long would it take to become fully operational?" (Hiscox) "Does the Applicant have a written business continuity plan?" (AXIS Insurance) "How frequently is this plan tested?" (AXIS Insurance) "Does the Applicant have a written disaster recovery plan?" (AXIS Insurance) "Are copies of the business continuity/disaster recovery and incident response plans stored so that they will be accessible if the Applicant's network became completely unavailable?" (AXIS Insurance) "In the event of an interruption of the Applicant's network, at most how long is the Applicant's recovery time objective (RTO) for critical systems, applications, and processes?" (AXIS Insurance) "If Yes, are such procedures tested on an annual basis?" (Travelers) "Are all plans indicated above tested regularly with any critical deficiencies remediated?" (Travelers) "Do you have a Business Continuity Plan (BCP) or Disaster Recovery Plan (DRP) in place?" (Corvus Insurance) "Does the organization have an incident response plan - tested and in-effect - setting forth specific action items and responsibilities for relevant parties in the event of a cyber incident or data breach matter?" (Cowbell Cyber) "Has the organization tested a full failover of the most critical servers?" (Cowbell Cyber) "What is the applicant's target recovery time objective (RTO) for critical systems?" (QBE) "How often are full network failover tests conducted?" (QBE) "Do all applicants have a Cyber Incident Response Plan or Business Continuity plan in place to respond to a computer system disruption?" (The Hartford) "If yes, how often is the Cyber Incident Response or Business Continuity plan tested?" (The Hartford) "Does the Applicant have documented business continuity and disaster recovery plans?" (Everest Insurance) "have a Business Continuity Plan or Disaster Response plan which includes Cyber perils?" (RSA) "Do you have a written business continuity or disaster recovery plan that addresses network outages & cyber-attacks?" (Munich Re) "What is your Recovery Time Objective (RTO) for critical systems?" (Munich Re) "Do you have a defined Recovery Point Objective (RPO) for critical systems?" (Munich Re) "Have you planned for redundancy for your critical system infrastructure?" (Munich Re) "Do you conduct redundancy testing at least annually to ensure that failover works as intended?" (Munich Re) |
| CC2.2 Internal communication of objectives and control responsibilities (COSO principle 14) | SOC 2 | 11 | "c. a loss of money, securities, or property due to social engineering, fraud, or other criminal acts?" (Hiscox) "Do any of the following employees at your company complete social engineering training: (1) Employees with financial or accounting responsibilities?" (Tokio Marine HCC) "Does the Applicant have a report phishing email add-in enabled for all email users?" (AXIS Insurance) "Does the Applicant conduct anti-fraud training of employees at least annually?" (AXIS Insurance) "Does the organization hold mandatory cybersecurity training with all employees at least annually?" (Cowbell Cyber) "Does the applicant flag external emails?" (QBE) "Does the applicant allow users to report suspicious emails?" (QBE) "If yes, does the applicant conduct training on spotting and reporting such emails?" (QBE) "If "No", what kind of training does the Applicant provide to help combat these types of fraudulent schemes and how often?" (The Hanover Insurance Group) "At least once a year, do you provide security awareness training for everyone who accesses your network or sensitive information in your care?" (CNA) "At time of hire and at least once a year, do you provide security awareness training for everyone who accesses your network or sensitive information in your care?" (CNA) "Do any of the following employees at your company complete social engineering training: (1) Employees with financial or accounting responsibilities?" (Encore Fiduciary) "Does the Applicant have a formalized training program for newly hired employees?" (Everest Insurance) "Do You have a written Policy that addresses information security awareness which is communicated to all employees?" (RSA) "Which of the following information security and privacy trainings are conducted?" (Munich Re) "Are your developers regularly trained in secure programming techniques and code reviews?" (Munich Re) |
| A.8.16 Monitoring activities | ISO 27001:2022 | 10 | "What security solutions do you use to prevent or detect malicious activity on your network?" (Beazley) "1) If stored offsite, are transportation logs maintained?" (AmTrust) "Managed Detection and Response (MDR) If yes to MDR, Who is your provider?" (Great American Insurance Group) "Security Information and Event Management (SIEM) If yes to SIEM, Who is your provider?" (Great American Insurance Group) "Is an email filtering tool in place to detect and/or block SPAM, malicious links, and attachments?" (Great American Insurance Group) "Are firewalls rules and alerts regularly reviewed?" (Great American Insurance Group) "Does the Applicant employ any Intrusion Detection and Prevention solutions (IDP), e.g. anti- virus software?" (AXIS Insurance) "Does the Applicant have a Security Operations Center (SOC) or utilize a Managed Security Service Provider?" (AXIS Insurance) "If yes, is it monitored 24/7?" (AXIS Insurance) "Are these policies, practices and solutions applied to the Firewalls Intrusion detection and following?" (AXIS Insurance) "Is the local logging performed on a per-host basis?" (AXIS Insurance) "Are local logs centralized into a log management system?" (AXIS Insurance) "How frequently are logs audited?" (AXIS Insurance) "How long are audit logs maintained?" (AXIS Insurance) "Do you have an Intrusion Detection System (IDS) or Intrusion Prevention System (IPS) in place?" (Corvus Insurance) "Does the applicant allow users to report suspicious emails?" (QBE) "Does the applicant implement a Security Information and Event management (SIEM) tool to monitor activity logs and centralize tools?" (QBE) "Does the applicant monitor for unusual or suspicious network activity?" (QBE) "Cybersecurity Function & Contact Person Is there a dedicated cybersecurity team monitoring the network for your business?" (The Hartford) "Is there an Endpoint Detection and Response (EDR) or Managed Detection and Response (MDR) product in place?" (The Hartford) "Do you have monitoring in place to alert you to the occurrence of unauthorized use of or access to sensitive information?" (CNA) "Do you tag external emails to alert employees that the message originated from outside the organization?" (Encore Fiduciary) "Do you use an endpoint detection and response (EDR) tool that includes centralized monitoring and logging of all endpoint activity across your enterprise?" (Encore Fiduciary) "Do you utilize a Security Information and Event Management system (SIEM?" (Encore Fiduciary) "Do you utilize a Security Operations Center (SOC?" (Encore Fiduciary) "If "Yes", complete the following: (1) Is your SOC monitored 24 hours a day, 7 days a week?" (Encore Fiduciary) "Are your audit logs immutable?" (Munich Re) "Are logins to web-based email monitored with alerts for suspicious activity implemented?" (Munich Re) "Do you tag external emails to alert employees that the message originated from outside the organization?" (Munich Re) "Do you restrict vendor access to limited time-windows and monitor their access to your network?" (Munich Re) "Are you utilising a Security Incident Event Management (SIEM) solution?" (Munich Re) "How are security incident alerts monitored and responded to?" (Munich Re) "Is the full scope of the SOC operating on a 24/7/365 basis?" (Munich Re) "Does your 24/7/365 service have the authority to contain/isolate systems following a suspicious event?" (Munich Re) |
| A.8.15 Logging | ISO 27001:2022 | 10 | "What security solutions do you use to prevent or detect malicious activity on your network?" (Beazley) "1) If stored offsite, are transportation logs maintained?" (AmTrust) "Managed Detection and Response (MDR) If yes to MDR, Who is your provider?" (Great American Insurance Group) "Security Information and Event Management (SIEM) If yes to SIEM, Who is your provider?" (Great American Insurance Group) "Is an email filtering tool in place to detect and/or block SPAM, malicious links, and attachments?" (Great American Insurance Group) "Are firewalls rules and alerts regularly reviewed?" (Great American Insurance Group) "Does the Applicant employ any Intrusion Detection and Prevention solutions (IDP), e.g. anti- virus software?" (AXIS Insurance) "Does the Applicant have a Security Operations Center (SOC) or utilize a Managed Security Service Provider?" (AXIS Insurance) "If yes, is it monitored 24/7?" (AXIS Insurance) "Are these policies, practices and solutions applied to the Firewalls Intrusion detection and following?" (AXIS Insurance) "Is the local logging performed on a per-host basis?" (AXIS Insurance) "Are local logs centralized into a log management system?" (AXIS Insurance) "How frequently are logs audited?" (AXIS Insurance) "How long are audit logs maintained?" (AXIS Insurance) "Do you have an Intrusion Detection System (IDS) or Intrusion Prevention System (IPS) in place?" (Corvus Insurance) "Does the applicant implement a Security Information and Event management (SIEM) tool to monitor activity logs and centralize tools?" (QBE) "Does the applicant monitor for unusual or suspicious network activity?" (QBE) "Cybersecurity Function & Contact Person Is there a dedicated cybersecurity team monitoring the network for your business?" (The Hartford) "Is there an Endpoint Detection and Response (EDR) or Managed Detection and Response (MDR) product in place?" (The Hartford) "Do you have monitoring in place to alert you to the occurrence of unauthorized use of or access to sensitive information?" (CNA) "Do you tag external emails to alert employees that the message originated from outside the organization?" (Encore Fiduciary) "Do you use an endpoint detection and response (EDR) tool that includes centralized monitoring and logging of all endpoint activity across your enterprise?" (Encore Fiduciary) "Do you utilize a Security Information and Event Management system (SIEM?" (Encore Fiduciary) "Do you utilize a Security Operations Center (SOC?" (Encore Fiduciary) "If "Yes", complete the following: (1) Is your SOC monitored 24 hours a day, 7 days a week?" (Encore Fiduciary) "Are your audit logs immutable?" (Munich Re) "Are logins to web-based email monitored with alerts for suspicious activity implemented?" (Munich Re) "Do you tag external emails to alert employees that the message originated from outside the organization?" (Munich Re) "Do you restrict vendor access to limited time-windows and monitor their access to your network?" (Munich Re) "Are you utilising a Security Incident Event Management (SIEM) solution?" (Munich Re) "How are security incident alerts monitored and responded to?" (Munich Re) "Is the full scope of the SOC operating on a 24/7/365 basis?" (Munich Re) "Does your 24/7/365 service have the authority to contain/isolate systems following a suspicious event?" (Munich Re) |
| CC7.2 Monitoring system components for anomalies | SOC 2 | 10 | "What security solutions do you use to prevent or detect malicious activity on your network?" (Beazley) "1) If stored offsite, are transportation logs maintained?" (AmTrust) "Managed Detection and Response (MDR) If yes to MDR, Who is your provider?" (Great American Insurance Group) "Security Information and Event Management (SIEM) If yes to SIEM, Who is your provider?" (Great American Insurance Group) "Is an email filtering tool in place to detect and/or block SPAM, malicious links, and attachments?" (Great American Insurance Group) "Are firewalls rules and alerts regularly reviewed?" (Great American Insurance Group) "Does the Applicant employ any Intrusion Detection and Prevention solutions (IDP), e.g. anti- virus software?" (AXIS Insurance) "Does the Applicant have a Security Operations Center (SOC) or utilize a Managed Security Service Provider?" (AXIS Insurance) "If yes, is it monitored 24/7?" (AXIS Insurance) "Are these policies, practices and solutions applied to the Firewalls Intrusion detection and following?" (AXIS Insurance) "Is the local logging performed on a per-host basis?" (AXIS Insurance) "Are local logs centralized into a log management system?" (AXIS Insurance) "How frequently are logs audited?" (AXIS Insurance) "How long are audit logs maintained?" (AXIS Insurance) "Do you have an Intrusion Detection System (IDS) or Intrusion Prevention System (IPS) in place?" (Corvus Insurance) "Does the applicant implement a Security Information and Event management (SIEM) tool to monitor activity logs and centralize tools?" (QBE) "Does the applicant monitor for unusual or suspicious network activity?" (QBE) "Cybersecurity Function & Contact Person Is there a dedicated cybersecurity team monitoring the network for your business?" (The Hartford) "Is there an Endpoint Detection and Response (EDR) or Managed Detection and Response (MDR) product in place?" (The Hartford) "Do you have monitoring in place to alert you to the occurrence of unauthorized use of or access to sensitive information?" (CNA) "Do you tag external emails to alert employees that the message originated from outside the organization?" (Encore Fiduciary) "Do you use an endpoint detection and response (EDR) tool that includes centralized monitoring and logging of all endpoint activity across your enterprise?" (Encore Fiduciary) "Do you utilize a Security Information and Event Management system (SIEM?" (Encore Fiduciary) "Do you utilize a Security Operations Center (SOC?" (Encore Fiduciary) "If "Yes", complete the following: (1) Is your SOC monitored 24 hours a day, 7 days a week?" (Encore Fiduciary) "Are your audit logs immutable?" (Munich Re) "Are logins to web-based email monitored with alerts for suspicious activity implemented?" (Munich Re) "Do you tag external emails to alert employees that the message originated from outside the organization?" (Munich Re) "Do you restrict vendor access to limited time-windows and monitor their access to your network?" (Munich Re) "Are you utilising a Security Incident Event Management (SIEM) solution?" (Munich Re) "How are security incident alerts monitored and responded to?" (Munich Re) "Is the full scope of the SOC operating on a 24/7/365 basis?" (Munich Re) "Does your 24/7/365 service have the authority to contain/isolate systems following a suspicious event?" (Munich Re) |
| PR.PS-04 Log records are generated and made available for continuous monitoring | NIST CSF 2.0 | 10 | "What security solutions do you use to prevent or detect malicious activity on your network?" (Beazley) "1) If stored offsite, are transportation logs maintained?" (AmTrust) "Managed Detection and Response (MDR) If yes to MDR, Who is your provider?" (Great American Insurance Group) "Security Information and Event Management (SIEM) If yes to SIEM, Who is your provider?" (Great American Insurance Group) "Is an email filtering tool in place to detect and/or block SPAM, malicious links, and attachments?" (Great American Insurance Group) "Are firewalls rules and alerts regularly reviewed?" (Great American Insurance Group) "Does the Applicant employ any Intrusion Detection and Prevention solutions (IDP), e.g. anti- virus software?" (AXIS Insurance) "Does the Applicant have a Security Operations Center (SOC) or utilize a Managed Security Service Provider?" (AXIS Insurance) "If yes, is it monitored 24/7?" (AXIS Insurance) "Are these policies, practices and solutions applied to the Firewalls Intrusion detection and following?" (AXIS Insurance) "Is the local logging performed on a per-host basis?" (AXIS Insurance) "Are local logs centralized into a log management system?" (AXIS Insurance) "How frequently are logs audited?" (AXIS Insurance) "How long are audit logs maintained?" (AXIS Insurance) "Do you have an Intrusion Detection System (IDS) or Intrusion Prevention System (IPS) in place?" (Corvus Insurance) "Does the applicant implement a Security Information and Event management (SIEM) tool to monitor activity logs and centralize tools?" (QBE) "Does the applicant monitor for unusual or suspicious network activity?" (QBE) "Cybersecurity Function & Contact Person Is there a dedicated cybersecurity team monitoring the network for your business?" (The Hartford) "Is there an Endpoint Detection and Response (EDR) or Managed Detection and Response (MDR) product in place?" (The Hartford) "Do you have monitoring in place to alert you to the occurrence of unauthorized use of or access to sensitive information?" (CNA) "Do you tag external emails to alert employees that the message originated from outside the organization?" (Encore Fiduciary) "Do you use an endpoint detection and response (EDR) tool that includes centralized monitoring and logging of all endpoint activity across your enterprise?" (Encore Fiduciary) "Do you utilize a Security Information and Event Management system (SIEM?" (Encore Fiduciary) "Do you utilize a Security Operations Center (SOC?" (Encore Fiduciary) "If "Yes", complete the following: (1) Is your SOC monitored 24 hours a day, 7 days a week?" (Encore Fiduciary) "Are your audit logs immutable?" (Munich Re) "Are logins to web-based email monitored with alerts for suspicious activity implemented?" (Munich Re) "Do you tag external emails to alert employees that the message originated from outside the organization?" (Munich Re) "Do you restrict vendor access to limited time-windows and monitor their access to your network?" (Munich Re) "Are you utilising a Security Incident Event Management (SIEM) solution?" (Munich Re) "How are security incident alerts monitored and responded to?" (Munich Re) "Is the full scope of the SOC operating on a 24/7/365 basis?" (Munich Re) "Does your 24/7/365 service have the authority to contain/isolate systems following a suspicious event?" (Munich Re) |
| PR.AA-06 Physical access to assets is managed, monitored, and enforced commensurate with risk | NIST CSF 2.0 | 10 | "Is this information stored on mobile computing devices, including laptops or smart phones?" (Hiscox) "Do you utilize cloud back-ups?" (Hiscox) "Are users able to store data to the hard drive of portable computers or portable media devices such as USB drives?" (AmTrust) "Are tapes or other portable media stored offsite using secured transportation and secured storage facilities?" (AmTrust) "Is multi factor authentication (MFA) for personal devices required?" (Great American Insurance Group) "How quickly can you restore from back-ups?" (Great American Insurance Group) "How frequently do you test your ability to restore from back-ups?" (Great American Insurance Group) "Local backup Network drive Tape backup Off-site storage Cloud backup Other: (3) Please list your data backup provider: (4) Is your data backup solution: (a) physically disconnected from your network?" (Tokio Marine HCC) "back-ups of critical Data and Computer Systems If either 2.a. or 2.b. has been selected is one copy stored on-line?" (The Hanover Insurance Group) "If either 2.a. or 2.b. has been selected is one copy stored off-site and off-line?" (The Hanover Insurance Group) "Have you identified the paper, electronic, and other records, computing systems, and storage media including laptops, mobile phones, and portable devices that contain sensitive information?" (CNA) "Do you have a policy in place not to leave your laptops, phones or other devices unattended in public, even locked in a car?" (CNA) "Do you enforce a "clean desk" and "clear screen" policy in which sensitive information must not be accessible or visible when left unattended?" (CNA) "Have you installed electrical surge protectors and UPS (uninterruptible power supply?" (CNA) "Have you installed electrical surge protectors and uninterruptible power supply (UPS?" (CNA) "Do you roll out a hardened baseline configuration across servers, laptops, desktops and managed mobile devices?" (Encore Fiduciary) "Do non-IT users have local administration rights on their laptop / desktop?" (Encore Fiduciary) "on mobile assets (e.g., laptops, phones, tablets, flash drives?" (Everest Insurance) "Are all mobile devices managed using a Mobile Device Management (MDM) solution?" (Munich Re) "Do you allow employees to use personal mobile devices to access company data (e.g. email?" (Munich Re) "If Yes, do you have a Bring Your Own Device (BYOD) policy in place that governs usage and controls?" (Munich Re) "Does your company operate a clean desk policy at all sites?" (Munich Re) "Are blocked emails classed as incidents and remediated?" (Munich Re) "Are full system backups taken at least weekly and stored either off site or disconnected from your network?" (Hiscox UK) |
| DE.CM-09 Computing hardware and software, runtime environments, and their data are monitored to find potentially adverse events | NIST CSF 2.0 | 10 | "Do you protect all company devices with anti-virus, anti-malware, and/or endpoint protection software?" (Beazley) "Do you disable macros in your office productivity software by default?" (Beazley) "The use of anti-virus software on all computer devices and networks?" (Hiscox) "Do you use anti-virus software and a firewall to protect your network?" (Tokio Marine HCC) "Do you use Endpoint Detection and Response (EDR) or a Next-Generation Antivirus (NGAV) software (e.g., CrowdStrike, Cylance, Carbon Black) to secure all system endpoints?" (Tokio Marine HCC) "Does the Applicant employ an Endpoint Detection and Response solution (EDR) that covers 100% of its environment?" (AXIS Insurance) "What Endpoint Security Technology do you have in place?" (Corvus Insurance) "Is there an Endpoint Detection and Response (EDR) tool deployed on all endpoints?" (QBE) "Do you have up-to-date versions of system security agent software (including malware, antivirus, and firewall protection) and reasonably up-to-date (within 30 days) security patches and virus definitions?" (CNA) "Do you use a next-generation antivirus (NGAV) product to protect all endpoints across your enterprise?" (Encore Fiduciary) "If "Yes", complete the following: (1) Provide the name of your EDR provider: (2) Do you enforce application whitelisting/blacklisting?" (Encore Fiduciary) "(3) Is EDR deployed on 100% of endpoints?" (Encore Fiduciary) "If "No", please use the Additional Comments section to outline which assets do not have EDR, and whether any mitigating safeguards are in place for such assets. (4) Can users access the network with their own device ("Bring Your Own Device"?" (Encore Fiduciary) "If "Yes", is EDR required to be installed on these devices?" (Encore Fiduciary) "Do you use endpoint application isolation and containment technology on all endpoints?" (Encore Fiduciary) "Can users run Microsoft Office Macro enabled documents on their system by default?" (Encore Fiduciary) "What anti-virus software do you use?" (RSA) "Do you update all systems including firewalls and anti-virus software at least every 30 days?" (Hiscox UK) |
| A.5.1 Policies for information security | ISO 27001:2022 | 10 | "Information security governance Who is responsible for IT security within your organisation (by job title?" (CFC Underwriting) "Who is responsible for privacy and information security within your organization?" (Hiscox) "If Yes, is this policy regularly updated?" (Hiscox) "Does the Applicant have and require employees to follow written computer and information systems policies and procedures?" (AmTrust) "If yes, is it reviewed/updated at least annually by a legal counsel?" (Great American Insurance Group) "Who is primarily responsible for the Applicant's cyber security program?" (Great American Insurance Group) "Does the Applicant have a written information security policy?" (AXIS Insurance) "Does the organization assign a person responsible for information security?" (Cowbell Cyber) "Cybersecurity Function & Contact Person Is there a dedicated cybersecurity team monitoring the network for your business?" (The Hartford) "Do you enforce a company policy governing security, privacy and acceptable use of company property that must be followed by anyone who accesses your network or sensitive information in your care?" (CNA) "Does the Applicant have a Chief Information Security Officer (CISO) or functional equivalent?" (Everest Insurance) "Do you have a Chief Privacy Officer, Data Protection Officer or function equivalent?" (Munich Re) "Do you have a written privacy policy that is reviewed (at least annually) by qualified legal counsel?" (Munich Re) "Is your information security policy reviewed (at least annually) and approved by senior management?" (Munich Re) "Chief Information Security Officer?" (Munich Re) "If Yes, does this person regularly report to senior level management?" (Munich Re) |
| CC1.3 Structures, reporting lines, authorities and responsibilities (COSO principle 3) | SOC 2 | 10 | "Information security governance Who is responsible for IT security within your organisation (by job title?" (CFC Underwriting) "Who is responsible for privacy and information security within your organization?" (Hiscox) "If Yes, is this policy regularly updated?" (Hiscox) "Does the Applicant have and require employees to follow written computer and information systems policies and procedures?" (AmTrust) "If yes, is it reviewed/updated at least annually by a legal counsel?" (Great American Insurance Group) "Who is primarily responsible for the Applicant's cyber security program?" (Great American Insurance Group) "Does the Applicant have a written information security policy?" (AXIS Insurance) "Does the organization assign a person responsible for information security?" (Cowbell Cyber) "Do you enforce a company policy governing security, privacy and acceptable use of company property that must be followed by anyone who accesses your network or sensitive information in your care?" (CNA) "Within the Applicant's organization, who is responsible for network security?" (Encore Fiduciary) "Does the Applicant have a Chief Information Security Officer (CISO) or functional equivalent?" (Everest Insurance) "Do you have a Chief Privacy Officer, Data Protection Officer or function equivalent?" (Munich Re) "Is your information security policy reviewed (at least annually) and approved by senior management?" (Munich Re) "Chief Information Security Officer?" (Munich Re) "If Yes, does this person regularly report to senior level management?" (Munich Re) |
| GV.PO-01 Policy for managing cybersecurity risks is established based on organizational context, cybersecurity strategy, and priorities and is communicated and enforced | NIST CSF 2.0 | 10 | "Information security governance Who is responsible for IT security within your organisation (by job title?" (CFC Underwriting) "Who is responsible for privacy and information security within your organization?" (Hiscox) "If Yes, is this policy regularly updated?" (Hiscox) "Does the Applicant have and require employees to follow written computer and information systems policies and procedures?" (AmTrust) "If yes, is it reviewed/updated at least annually by a legal counsel?" (Great American Insurance Group) "Who is primarily responsible for the Applicant's cyber security program?" (Great American Insurance Group) "Does the Applicant have a written information security policy?" (AXIS Insurance) "Does the applicant have formal policies and procedures in place for secure fund transfers, such as senior management approval and obtaining verbal confirmation for any fund transfer requests?" (RLI) "Does the organization assign a person responsible for information security?" (Cowbell Cyber) "Do you enforce a company policy governing security, privacy and acceptable use of company property that must be followed by anyone who accesses your network or sensitive information in your care?" (CNA) "Does the Applicant have a Chief Information Security Officer (CISO) or functional equivalent?" (Everest Insurance) "Do you have a Chief Privacy Officer, Data Protection Officer or function equivalent?" (Munich Re) "Is your information security policy reviewed (at least annually) and approved by senior management?" (Munich Re) "Chief Information Security Officer?" (Munich Re) "If Yes, does this person regularly report to senior level management?" (Munich Re) |
| CC6.2 Registering and authorising users before issuing credentials | SOC 2 | 9 | "If No, is such information stored on a segregated server with role-based access controls?" (Hiscox) "in place with all third parties that have access to sensitive information, including business associate agreements?" (Hiscox) "Employee access to systems and data is limited to only what they need to do their job?" (Hiscox) "Employee access to systems and data is cut when employees leave the organization?" (Hiscox) "Does the Applicant terminate all computer access and user accounts as part of the regular exit process when an employee leaves the company or when a third party contractor no longer provides the contracted services?" (AmTrust) "(2) Access control with role-based assignments?" (Tokio Marine HCC) "(b) segregated with 2-factor authentication access control?" (Tokio Marine HCC) "(3) A separation of authority protocol?" (Tokio Marine HCC) "What security controls are in place to protect against unauthorized access to sensitive and confidential data?" (Corvus Insurance) "Do you set up a separate account for each user (including any contractors needing access?" (CNA) "(2) Access control with role-based assignments?" (Encore Fiduciary) "(3) A separation of authority protocol?" (Encore Fiduciary) "Does the Applicant restrict access based on job function and responsibilities?" (Everest Insurance) "Is access to the internet from terminals restricted for employees?" (Everest Insurance) "You enforce a policy of auditing of managing computer and user accounts?" (RSA) "Do you perform background checks on employees & contractors who have access to sensitive information?" (Munich Re) "Do you terminate user access rights as part of the employee exit process?" (Munich Re) "Do you have a central Identity & Access Management ("IAM") system for assigning and revoking access rights?" (Munich Re) "Do you have a formal process in place for assigning and revoking user accounts and access rights?" (Munich Re) "Do assets owners review access rights at least annually?" (Munich Re) "Do you periodically review and update vendor access rights?" (Munich Re) |
| A.5.2 Information security roles and responsibilities | ISO 27001:2022 | 9 | "Information security governance Who is responsible for IT security within your organisation (by job title?" (CFC Underwriting) "Who is responsible for privacy and information security within your organization?" (Hiscox) "If Yes, is this policy regularly updated?" (Hiscox) "Does the Applicant have and require employees to follow written computer and information systems policies and procedures?" (AmTrust) "If yes, is it reviewed/updated at least annually by a legal counsel?" (Great American Insurance Group) "Who is primarily responsible for the Applicant's cyber security program?" (Great American Insurance Group) "Does the Applicant have a written information security policy?" (AXIS Insurance) "Does the organization assign a person responsible for information security?" (Cowbell Cyber) "Do you enforce a company policy governing security, privacy and acceptable use of company property that must be followed by anyone who accesses your network or sensitive information in your care?" (CNA) "Does the Applicant have a Chief Information Security Officer (CISO) or functional equivalent?" (Everest Insurance) "Do you have a Chief Privacy Officer, Data Protection Officer or function equivalent?" (Munich Re) "Is your information security policy reviewed (at least annually) and approved by senior management?" (Munich Re) "Chief Information Security Officer?" (Munich Re) "If Yes, does this person regularly report to senior level management?" (Munich Re) |
| A.5.4 Management responsibilities | ISO 27001:2022 | 9 | "Information security governance Who is responsible for IT security within your organisation (by job title?" (CFC Underwriting) "Who is responsible for privacy and information security within your organization?" (Hiscox) "If Yes, is this policy regularly updated?" (Hiscox) "Does the Applicant have and require employees to follow written computer and information systems policies and procedures?" (AmTrust) "If yes, is it reviewed/updated at least annually by a legal counsel?" (Great American Insurance Group) "Who is primarily responsible for the Applicant's cyber security program?" (Great American Insurance Group) "Does the Applicant have a written information security policy?" (AXIS Insurance) "Does the organization assign a person responsible for information security?" (Cowbell Cyber) "Do you enforce a company policy governing security, privacy and acceptable use of company property that must be followed by anyone who accesses your network or sensitive information in your care?" (CNA) "Does the Applicant have a Chief Information Security Officer (CISO) or functional equivalent?" (Everest Insurance) "Do you have a Chief Privacy Officer, Data Protection Officer or function equivalent?" (Munich Re) "Is your information security policy reviewed (at least annually) and approved by senior management?" (Munich Re) "Chief Information Security Officer?" (Munich Re) "If Yes, does this person regularly report to senior level management?" (Munich Re) |
| CC5.3 Deploying controls through policies and procedures (COSO principle 12) | SOC 2 | 9 | "Information security governance Who is responsible for IT security within your organisation (by job title?" (CFC Underwriting) "Who is responsible for privacy and information security within your organization?" (Hiscox) "If Yes, is this policy regularly updated?" (Hiscox) "Does the Applicant have and require employees to follow written computer and information systems policies and procedures?" (AmTrust) "If yes, is it reviewed/updated at least annually by a legal counsel?" (Great American Insurance Group) "Who is primarily responsible for the Applicant's cyber security program?" (Great American Insurance Group) "Does the Applicant have a written information security policy?" (AXIS Insurance) "Does the organization assign a person responsible for information security?" (Cowbell Cyber) "Do you enforce a company policy governing security, privacy and acceptable use of company property that must be followed by anyone who accesses your network or sensitive information in your care?" (CNA) "Does the Applicant have a Chief Information Security Officer (CISO) or functional equivalent?" (Everest Insurance) "Do you have a Chief Privacy Officer, Data Protection Officer or function equivalent?" (Munich Re) "Is your information security policy reviewed (at least annually) and approved by senior management?" (Munich Re) "Chief Information Security Officer?" (Munich Re) "If Yes, does this person regularly report to senior level management?" (Munich Re) |
| GV.RR-01 Organizational leadership is responsible and accountable for cybersecurity risk and fosters a culture that is risk-aware, ethical, and continually improving | NIST CSF 2.0 | 9 | "Information security governance Who is responsible for IT security within your organisation (by job title?" (CFC Underwriting) "Who is responsible for privacy and information security within your organization?" (Hiscox) "If Yes, is this policy regularly updated?" (Hiscox) "Does the Applicant have and require employees to follow written computer and information systems policies and procedures?" (AmTrust) "If yes, is it reviewed/updated at least annually by a legal counsel?" (Great American Insurance Group) "Who is primarily responsible for the Applicant's cyber security program?" (Great American Insurance Group) "Does the Applicant have a written information security policy?" (AXIS Insurance) "Does the organization assign a person responsible for information security?" (Cowbell Cyber) "Do you enforce a company policy governing security, privacy and acceptable use of company property that must be followed by anyone who accesses your network or sensitive information in your care?" (CNA) "Does the Applicant have a Chief Information Security Officer (CISO) or functional equivalent?" (Everest Insurance) "Do you have a Chief Privacy Officer, Data Protection Officer or function equivalent?" (Munich Re) "Is your information security policy reviewed (at least annually) and approved by senior management?" (Munich Re) "Chief Information Security Officer?" (Munich Re) "If Yes, does this person regularly report to senior level management?" (Munich Re) |
| A.8.2 Privileged access rights | ISO 27001:2022 | 8 | "Is multifactor authentication (MFA) required to remotely connect to the network, all critical internet facing systems and privilege accounts?" (Great American Insurance Group) "Are firewalls configured according to the principles of least privileges?" (Great American Insurance Group) "Do you use 2-factor authentication to secure all domain or network administrator accounts?" (Tokio Marine HCC) "Does the Applicant or its Managed Security Service Provider, if applicable, implement MFA for all administrator access?" (AXIS Insurance) "How are privileged accounts secured and managed?" (Corvus Insurance) "a. Do the applicant's privileged users require more extensive training relating to phishing attacks?" (QBE) "Does the applicant utilize a Privileged Access Management (PAM) solution?" (QBE) "If not utilizing a PAM solution, what compensating controls exist to protect privileged accounts?" (QBE) "Does the applicant restrict Local Admin rights?" (QBE) "Do you physically and electronically limit access to sensitive information on a need –to-know basis and revoke access privileges upon a reduction in an individual's need to know?" (CNA) "Do you physically and electronically limit access to sensitive information on a need-to-know basis and revoke access privileges upon a reduction in an individual's need to know?" (CNA) "Do you use MFA to protect all local and remote access to privileged user accounts?" (Encore Fiduciary) "Do you manage privileged accounts using privileged account management software (PAM) (e.g., CyberArk, BeyondTrust, etc.?" (Encore Fiduciary) "If "Yes", complete the following: (1) Provide the name of your PAM software provider: (2) Is access protected by MFA?" (Encore Fiduciary) "Do you actively monitor all administrator access for unusual behavior patterns?" (Encore Fiduciary) "Do non-IT users have local administration rights on their laptop / desktop?" (Encore Fiduciary) "Do you restrict user access (employees, contractors etc.) on a business need-to-know & least-privilege basis?" (Munich Re) "If Yes, which of the following accounts are enrolled into the PAM tool?" (Munich Re) "Which of the following features are enabled on the PAM tool?" (Munich Re) "Is logging and alerting configured for all privileged account activity?" (Munich Re) "Are domain admin accounts limited to administrative functions only?" (Munich Re) "Please provide the number of service accounts in the domain admin group?" (Munich Re) "Do you configure service accounts using the principle of least privilege?" (Munich Re) "Do you configure service accounts to deny interactive log-ins?" (Munich Re) "Do you log the activity of service accounts that are able to override system or application controls (e.g. elevation Yes No of privileges, lateral movement etc.?" (Munich Re) "Do you prohibit local admin rights on workstations for users?" (Munich Re) |
| A.5.16 Identity management | ISO 27001:2022 | 8 | "If No, is such information stored on a segregated server with role-based access controls?" (Hiscox) "in place with all third parties that have access to sensitive information, including business associate agreements?" (Hiscox) "Employee access to systems and data is limited to only what they need to do their job?" (Hiscox) "Employee access to systems and data is cut when employees leave the organization?" (Hiscox) "Does the Applicant terminate all computer access and user accounts as part of the regular exit process when an employee leaves the company or when a third party contractor no longer provides the contracted services?" (AmTrust) "(2) Access control with role-based assignments?" (Tokio Marine HCC) "(3) A separation of authority protocol?" (Tokio Marine HCC) "Do you set up a separate account for each user (including any contractors needing access?" (CNA) "(2) Access control with role-based assignments?" (Encore Fiduciary) "(3) A separation of authority protocol?" (Encore Fiduciary) "Does the Applicant restrict access based on job function and responsibilities?" (Everest Insurance) "Is access to the internet from terminals restricted for employees?" (Everest Insurance) "You enforce a policy of auditing of managing computer and user accounts?" (RSA) "Do you perform background checks on employees & contractors who have access to sensitive information?" (Munich Re) "Do you terminate user access rights as part of the employee exit process?" (Munich Re) "Do you have a central Identity & Access Management ("IAM") system for assigning and revoking access rights?" (Munich Re) "Do you have a formal process in place for assigning and revoking user accounts and access rights?" (Munich Re) "Do assets owners review access rights at least annually?" (Munich Re) "Do you periodically review and update vendor access rights?" (Munich Re) |
| A.5.18 Access rights | ISO 27001:2022 | 8 | "If No, is such information stored on a segregated server with role-based access controls?" (Hiscox) "in place with all third parties that have access to sensitive information, including business associate agreements?" (Hiscox) "Employee access to systems and data is limited to only what they need to do their job?" (Hiscox) "Employee access to systems and data is cut when employees leave the organization?" (Hiscox) "Does the Applicant terminate all computer access and user accounts as part of the regular exit process when an employee leaves the company or when a third party contractor no longer provides the contracted services?" (AmTrust) "(2) Access control with role-based assignments?" (Tokio Marine HCC) "(3) A separation of authority protocol?" (Tokio Marine HCC) "Do you set up a separate account for each user (including any contractors needing access?" (CNA) "(2) Access control with role-based assignments?" (Encore Fiduciary) "(3) A separation of authority protocol?" (Encore Fiduciary) "Does the Applicant restrict access based on job function and responsibilities?" (Everest Insurance) "Is access to the internet from terminals restricted for employees?" (Everest Insurance) "You enforce a policy of auditing of managing computer and user accounts?" (RSA) "Do you perform background checks on employees & contractors who have access to sensitive information?" (Munich Re) "Do you terminate user access rights as part of the employee exit process?" (Munich Re) "Do you have a central Identity & Access Management ("IAM") system for assigning and revoking access rights?" (Munich Re) "Do you have a formal process in place for assigning and revoking user accounts and access rights?" (Munich Re) "Do assets owners review access rights at least annually?" (Munich Re) "Do you periodically review and update vendor access rights?" (Munich Re) |
| A.8.21 Security of network services | ISO 27001:2022 | 8 | "If yes, is it segregated from the network?" (Great American Insurance Group) "Are all internet-accessible systems (e.g. web-, email-servers) segregated from the organization's trusted network (e.g. within a demilitarized zone (DMZ) or at a third-party service provider?" (Cowbell Cyber) "Does the applicant segment the network via Next Generation Firewalls, Virtual Local Area Networks (VLAN), demilitarized zones (DMZ), etc.?" (QBE) "How does the applicant eliminate or limit lateral movement within its network?" (QBE) "Have you installed firewalls between your internal network and the Internet?" (CNA) "Within the Applicant's organization, who is responsible for network security?" (Encore Fiduciary) "If the Applicant's network security is outsourced, are you the main contact for the network security provider named in question b. above?" (Encore Fiduciary) "ZScaler, Quad9, OpenDNS or the public sector PDNS to block access to known malicious websites?" (Encore Fiduciary) "Is network segmentation (e.g., firewalls, software- defined networking) used to limit movement across the network?" (Everest Insurance) "What firewall(s) do you use?" (RSA) "Is a Web Application Firewall (WAF) used to protect publicly exposed web application?" (Munich Re) "Do you ensure that all publicly facing ports are protected by a pre-configured firewall that blocks unauthorised Yes No network traffic?" (Munich Re) "Do you regularly scan publicly accessible ports and ensure unnecessary ones are locked down?" (Munich Re) "How is web traffic filtered?" (Munich Re) "Have you configured host-based and network firewalls to disallow inbound connections by default?" (Munich Re) "Do you perform periodic reviews of firewall rules to ensure configurations are on a need-to-have basis?" (Munich Re) "Do you utilize any of the following technologies to physically or logically segregate your network?" (Munich Re) |
| A.7.1 Physical security perimeters | ISO 27001:2022 | 8 | "Do you utilize cloud back-ups?" (Hiscox) "Are tapes or other portable media stored offsite using secured transportation and secured storage facilities?" (AmTrust) "1) If stored offsite, are transportation logs maintained?" (AmTrust) "How quickly can you restore from back-ups?" (Great American Insurance Group) "How frequently do you test your ability to restore from back-ups?" (Great American Insurance Group) "Local backup Network drive Tape backup Off-site storage Cloud backup Other: (3) Please list your data backup provider: (4) Is your data backup solution: (a) physically disconnected from your network?" (Tokio Marine HCC) "back-ups of critical Data and Computer Systems If either 2.a. or 2.b. has been selected is one copy stored on-line?" (The Hanover Insurance Group) "If either 2.a. or 2.b. has been selected is one copy stored off-site and off-line?" (The Hanover Insurance Group) "Do you have a policy in place not to leave your laptops, phones or other devices unattended in public, even locked in a car?" (CNA) "Do you enforce a "clean desk" and "clear screen" policy in which sensitive information must not be accessible or visible when left unattended?" (CNA) "Have you installed electrical surge protectors and UPS (uninterruptible power supply?" (CNA) "Have you installed electrical surge protectors and uninterruptible power supply (UPS?" (CNA) "Does your company operate a clean desk policy at all sites?" (Munich Re) "Are full system backups taken at least weekly and stored either off site or disconnected from your network?" (Hiscox UK) |
| A.8.3 Information access restriction | ISO 27001:2022 | 6 | "Are firewalls configured according to the principles of least privileges?" (Great American Insurance Group) "How are privileged accounts secured and managed?" (Corvus Insurance) "a. Do the applicant's privileged users require more extensive training relating to phishing attacks?" (QBE) "Does the applicant utilize a Privileged Access Management (PAM) solution?" (QBE) "If not utilizing a PAM solution, what compensating controls exist to protect privileged accounts?" (QBE) "Does the applicant restrict Local Admin rights?" (QBE) "Do you physically and electronically limit access to sensitive information on a need –to-know basis and revoke access privileges upon a reduction in an individual's need to know?" (CNA) "Do you physically and electronically limit access to sensitive information on a need-to-know basis and revoke access privileges upon a reduction in an individual's need to know?" (CNA) "Do you manage privileged accounts using privileged account management software (PAM) (e.g., CyberArk, BeyondTrust, etc.?" (Encore Fiduciary) "Do you actively monitor all administrator access for unusual behavior patterns?" (Encore Fiduciary) "Do non-IT users have local administration rights on their laptop / desktop?" (Encore Fiduciary) "Do you restrict user access (employees, contractors etc.) on a business need-to-know & least-privilege basis?" (Munich Re) "If Yes, which of the following accounts are enrolled into the PAM tool?" (Munich Re) "Which of the following features are enabled on the PAM tool?" (Munich Re) "Is logging and alerting configured for all privileged account activity?" (Munich Re) "Are domain admin accounts limited to administrative functions only?" (Munich Re) "Please provide the number of service accounts in the domain admin group?" (Munich Re) "Do you configure service accounts using the principle of least privilege?" (Munich Re) "Do you configure service accounts to deny interactive log-ins?" (Munich Re) "Do you log the activity of service accounts that are able to override system or application controls (e.g. elevation Yes No of privileges, lateral movement etc.?" (Munich Re) "Do you prohibit local admin rights on workstations for users?" (Munich Re) |
| CC8.1 Managing changes to procedures, software, data and infrastructure | SOC 2 | 6 | "Do you disable macros in your office productivity software by default?" (Beazley) "Do you use a hardened baseline configuration across all (or substantially all) of your devices?" (Beazley) "Is formal signoff and acceptance required when mid-project changes are requested?" (Hiscox) "Do you perform a technical review to ensure functional requirements can be met?" (Hiscox) "Do you replace factory default settings to ensure your information security systems are securely configured?" (CNA) "Encore Fiduciary Cyber Liability Application (2.2022) Page 2 of 10 If MFA is used, complete the following: (1) Provide the name of your MFA provider: (2) Describe your MFA type: (3) Does your MFA configuration ensure that the compromise of a single device will only compromise a single authenticator?" (Encore Fiduciary) "Do you roll out a hardened baseline configuration across servers, laptops, desktops and managed mobile devices?" (Encore Fiduciary) "Does the Applicant deploy system configuration management tools that enforce and redeploy configuration settings to systems (e.g., operating systems and software applications) at regular intervals?" (Everest Insurance) "Do you perform periodic reviews of firewall rules to ensure configurations are on a need-to-have basis?" (Munich Re) "Do you implement a hardened baseline configuration materially rolled out across servers and workstations?" (Munich Re) "Do you have a secure coding baseline in place (e.g. peer reviews & maintenance requirements?" (Munich Re) "Do you conduct security tests or code analysis during system development, before go-live and after N/A Yes No system changes take place?" (Munich Re) "Do you ensure that any acquired applications/functions and code is free from known vulnerabilities?" (Munich Re) |
| A.8.9 Configuration management | ISO 27001:2022 | 5 | "Do you disable macros in your office productivity software by default?" (Beazley) "Do you use a hardened baseline configuration across all (or substantially all) of your devices?" (Beazley) "Do you replace factory default settings to ensure your information security systems are securely configured?" (CNA) "Do you back-up your network data and configuration files daily and store back-up files in a secure location, and rehearse your procedure for restoring from back-ups at least yearly?" (CNA) "Encore Fiduciary Cyber Liability Application (2.2022) Page 2 of 10 If MFA is used, complete the following: (1) Provide the name of your MFA provider: (2) Describe your MFA type: (3) Does your MFA configuration ensure that the compromise of a single device will only compromise a single authenticator?" (Encore Fiduciary) "Do you roll out a hardened baseline configuration across servers, laptops, desktops and managed mobile devices?" (Encore Fiduciary) "Does the Applicant deploy system configuration management tools that enforce and redeploy configuration settings to systems (e.g., operating systems and software applications) at regular intervals?" (Everest Insurance) "Do you implement a hardened baseline configuration materially rolled out across servers and workstations?" (Munich Re) |
| PR.PS-01 Configuration management practices are established and applied | NIST CSF 2.0 | 5 | "Do you use a hardened baseline configuration across all (or substantially all) of your devices?" (Beazley) "Do you replace factory default settings to ensure your information security systems are securely configured?" (CNA) "Do you back-up your network data and configuration files daily and store back-up files in a secure location, and rehearse your procedure for restoring from back-ups at least yearly?" (CNA) "Encore Fiduciary Cyber Liability Application (2.2022) Page 2 of 10 If MFA is used, complete the following: (1) Provide the name of your MFA provider: (2) Describe your MFA type: (3) Does your MFA configuration ensure that the compromise of a single device will only compromise a single authenticator?" (Encore Fiduciary) "Do you roll out a hardened baseline configuration across servers, laptops, desktops and managed mobile devices?" (Encore Fiduciary) "Does the Applicant deploy system configuration management tools that enforce and redeploy configuration settings to systems (e.g., operating systems and software applications) at regular intervals?" (Everest Insurance) "Do you implement a hardened baseline configuration materially rolled out across servers and workstations?" (Munich Re) |
| A.5.24 Information security incident management planning and preparation | ISO 27001:2022 | 5 | "Do you have a written incident response plan in the event that Personally Identifiable Information is/may be compromised?" (Hiscox) "Does the insured implement any of the following response plans?" (Great American Insurance Group) "Does the Applicant have a written incident response plan?" (AXIS Insurance) "Does the firm have a documented Incident Response Plan?" (Everest Insurance) "Do you have an information security incident response plan?" (Munich Re) "Do you have an incident response or digital forensic outsourcing retainer agreement in place?" (Munich Re) |
| A.5.25 Assessment and decision on information security events | ISO 27001:2022 | 5 | "Do you have a written incident response plan in the event that Personally Identifiable Information is/may be compromised?" (Hiscox) "Does the insured implement any of the following response plans?" (Great American Insurance Group) "Does the Applicant have a written incident response plan?" (AXIS Insurance) "Does the firm have a documented Incident Response Plan?" (Everest Insurance) "Do you have an information security incident response plan?" (Munich Re) "Do you have an incident response or digital forensic outsourcing retainer agreement in place?" (Munich Re) |
| A.5.26 Response to information security incidents | ISO 27001:2022 | 5 | "Do you have a written incident response plan in the event that Personally Identifiable Information is/may be compromised?" (Hiscox) "Does the insured implement any of the following response plans?" (Great American Insurance Group) "Does the Applicant have a written incident response plan?" (AXIS Insurance) "Does the firm have a documented Incident Response Plan?" (Everest Insurance) "Do you have an information security incident response plan?" (Munich Re) "Do you have an incident response or digital forensic outsourcing retainer agreement in place?" (Munich Re) |
| CC7.3 Evaluating security events to identify incidents | SOC 2 | 5 | "Do you have a written incident response plan in the event that Personally Identifiable Information is/may be compromised?" (Hiscox) "Does the insured implement any of the following response plans?" (Great American Insurance Group) "Does the Applicant have a written incident response plan?" (AXIS Insurance) "Does the firm have a documented Incident Response Plan?" (Everest Insurance) "Do you have an information security incident response plan?" (Munich Re) "Do you have an incident response or digital forensic outsourcing retainer agreement in place?" (Munich Re) |
| CC7.4 Responding to security incidents | SOC 2 | 5 | "Do you have a written incident response plan in the event that Personally Identifiable Information is/may be compromised?" (Hiscox) "Does the insured implement any of the following response plans?" (Great American Insurance Group) "Does the Applicant have a written incident response plan?" (AXIS Insurance) "Does the firm have a documented Incident Response Plan?" (Everest Insurance) "Do you have an information security incident response plan?" (Munich Re) "Do you have an incident response or digital forensic outsourcing retainer agreement in place?" (Munich Re) |
| RS.CO-02 Internal and external stakeholders are notified of incidents | NIST CSF 2.0 | 5 | "Do you have a written incident response plan in the event that Personally Identifiable Information is/may be compromised?" (Hiscox) "Does the insured implement any of the following response plans?" (Great American Insurance Group) "Does the Applicant have a written incident response plan?" (AXIS Insurance) "Does the firm have a documented Incident Response Plan?" (Everest Insurance) "Do you have an information security incident response plan?" (Munich Re) "Do you have an incident response or digital forensic outsourcing retainer agreement in place?" (Munich Re) |
| RS.MA-01 The incident response plan is executed in coordination with relevant third parties once an incident is declared | NIST CSF 2.0 | 5 | "Do you have a written incident response plan in the event that Personally Identifiable Information is/may be compromised?" (Hiscox) "Does the insured implement any of the following response plans?" (Great American Insurance Group) "Does the Applicant have a written incident response plan?" (AXIS Insurance) "Does the firm have a documented Incident Response Plan?" (Everest Insurance) "Do you have an information security incident response plan?" (Munich Re) "Do you have an incident response or digital forensic outsourcing retainer agreement in place?" (Munich Re) |
| CC6.4 Restricting physical access to facilities and assets | SOC 2 | 4 | "Are tapes or other portable media stored offsite using secured transportation and secured storage facilities?" (AmTrust) "If either 2.a. or 2.b. has been selected is one copy stored off-site and off-line?" (The Hanover Insurance Group) "Has traf fic using Remote Desktop Protocol (RDP) TCP ports 3389 and Server Message Block (SMB) TCP ports 445, 135, and 139 been blocked?" (The Hanover Insurance Group) "Do you have a policy in place not to leave your laptops, phones or other devices unattended in public, even locked in a car?" (CNA) "Do you enforce a "clean desk" and "clear screen" policy in which sensitive information must not be accessible or visible when left unattended?" (CNA) "Have you installed electrical surge protectors and UPS (uninterruptible power supply?" (CNA) "Have you installed electrical surge protectors and uninterruptible power supply (UPS?" (CNA) "Do you regularly scan publicly accessible ports and ensure unnecessary ones are locked down?" (Munich Re) "Does your company operate a clean desk policy at all sites?" (Munich Re) "Are blocked emails classed as incidents and remediated?" (Munich Re) |
| A.7.2 Physical entry | ISO 27001:2022 | 4 | "Are tapes or other portable media stored offsite using secured transportation and secured storage facilities?" (AmTrust) "If either 2.a. or 2.b. has been selected is one copy stored off-site and off-line?" (The Hanover Insurance Group) "Do you have a policy in place not to leave your laptops, phones or other devices unattended in public, even locked in a car?" (CNA) "Do you enforce a "clean desk" and "clear screen" policy in which sensitive information must not be accessible or visible when left unattended?" (CNA) "Have you installed electrical surge protectors and UPS (uninterruptible power supply?" (CNA) "Have you installed electrical surge protectors and uninterruptible power supply (UPS?" (CNA) "Does your company operate a clean desk policy at all sites?" (Munich Re) |
| A.7.3 Securing offices, rooms and facilities | ISO 27001:2022 | 4 | "Are tapes or other portable media stored offsite using secured transportation and secured storage facilities?" (AmTrust) "If either 2.a. or 2.b. has been selected is one copy stored off-site and off-line?" (The Hanover Insurance Group) "Do you have a policy in place not to leave your laptops, phones or other devices unattended in public, even locked in a car?" (CNA) "Do you enforce a "clean desk" and "clear screen" policy in which sensitive information must not be accessible or visible when left unattended?" (CNA) "Have you installed electrical surge protectors and UPS (uninterruptible power supply?" (CNA) "Have you installed electrical surge protectors and uninterruptible power supply (UPS?" (CNA) "Does your company operate a clean desk policy at all sites?" (Munich Re) |
| CC6.5 Protecting data on assets until disposal | SOC 2 | 4 | "Are tapes or other portable media stored offsite using secured transportation and secured storage facilities?" (AmTrust) "If either 2.a. or 2.b. has been selected is one copy stored off-site and off-line?" (The Hanover Insurance Group) "Do you have a policy in place not to leave your laptops, phones or other devices unattended in public, even locked in a car?" (CNA) "Do you enforce a "clean desk" and "clear screen" policy in which sensitive information must not be accessible or visible when left unattended?" (CNA) "Have you installed electrical surge protectors and UPS (uninterruptible power supply?" (CNA) "Have you installed electrical surge protectors and uninterruptible power supply (UPS?" (CNA) "Does your company operate a clean desk policy at all sites?" (Munich Re) |
| PR.IR-02 The organization's technology assets are protected from environmental threats | NIST CSF 2.0 | 4 | "Are tapes or other portable media stored offsite using secured transportation and secured storage facilities?" (AmTrust) "If either 2.a. or 2.b. has been selected is one copy stored off-site and off-line?" (The Hanover Insurance Group) "Do you have a policy in place not to leave your laptops, phones or other devices unattended in public, even locked in a car?" (CNA) "Do you enforce a "clean desk" and "clear screen" policy in which sensitive information must not be accessible or visible when left unattended?" (CNA) "Have you installed electrical surge protectors and UPS (uninterruptible power supply?" (CNA) "Have you installed electrical surge protectors and uninterruptible power supply (UPS?" (CNA) "Does your company operate a clean desk policy at all sites?" (Munich Re) |
| A.5.33 Protection of records | ISO 27001:2022 | 3 | "Formal policies and procedures around the retention, destruction, and purging of data?" (Hiscox) "Does the Applicant have a written document retention policy?" (AXIS Insurance) "Are any of the Applicant's products or services used in the collection, use, processing, sharing, sale, profit from, possession, retention and destruction of Biometric Information?" (AXIS Insurance) "Do you obtain written consent from individuals prior to collection, receipt or retention of biometric information?" (Munich Re) "Do you have a retention schedule outlining how long biometric information is retained?" (Munich Re) |
| A.7.14 Secure disposal or re-use of equipment | ISO 27001:2022 | 3 | "Formal policies and procedures around the retention, destruction, and purging of data?" (Hiscox) "Does the Applicant have a written document retention policy?" (AXIS Insurance) "Are any of the Applicant's products or services used in the collection, use, processing, sharing, sale, profit from, possession, retention and destruction of Biometric Information?" (AXIS Insurance) "Do you obtain written consent from individuals prior to collection, receipt or retention of biometric information?" (Munich Re) "Do you have a retention schedule outlining how long biometric information is retained?" (Munich Re) |
| A.8.10 Information deletion | ISO 27001:2022 | 3 | "Formal policies and procedures around the retention, destruction, and purging of data?" (Hiscox) "Does the Applicant have a written document retention policy?" (AXIS Insurance) "Are any of the Applicant's products or services used in the collection, use, processing, sharing, sale, profit from, possession, retention and destruction of Biometric Information?" (AXIS Insurance) "Do you obtain written consent from individuals prior to collection, receipt or retention of biometric information?" (Munich Re) "Do you have a retention schedule outlining how long biometric information is retained?" (Munich Re) |
| P4.2 Retaining personal information | SOC 2 | 3 | "Formal policies and procedures around the retention, destruction, and purging of data?" (Hiscox) "Does the Applicant have a written document retention policy?" (AXIS Insurance) "Are any of the Applicant's products or services used in the collection, use, processing, sharing, sale, profit from, possession, retention and destruction of Biometric Information?" (AXIS Insurance) "Do you obtain written consent from individuals prior to collection, receipt or retention of biometric information?" (Munich Re) "Do you have a retention schedule outlining how long biometric information is retained?" (Munich Re) |
| P4.3 Securely disposing of personal information | SOC 2 | 3 | "Formal policies and procedures around the retention, destruction, and purging of data?" (Hiscox) "Does the Applicant have a written document retention policy?" (AXIS Insurance) "Are any of the Applicant's products or services used in the collection, use, processing, sharing, sale, profit from, possession, retention and destruction of Biometric Information?" (AXIS Insurance) "Do you obtain written consent from individuals prior to collection, receipt or retention of biometric information?" (Munich Re) "Do you have a retention schedule outlining how long biometric information is retained?" (Munich Re) |
| A.5.12 Classification of information | ISO 27001:2022 | 3 | "Which controls are in place to protect confidential, sensitive, or otherwise regulated data?" (Great American Insurance Group) "What security controls are in place to protect against unauthorized access to sensitive and confidential data?" (Corvus Insurance) "If you inventory hardware and/or software assets, do you have an asset classification policy that is enforced?" (Munich Re) "Do you identify & categorise third party vendors based on their access to company systems and/or data?" (Munich Re) |
| A.5.9 Inventory of information and other associated assets | ISO 27001:2022 | 3 | "Do you record and track all software and hardware assets deployed across your organization?" (Encore Fiduciary) "Does the Applicant have a continuous monitoring program to detect and maintain an inventory of all hardware and software on to its network?" (Everest Insurance) "If you inventory hardware and/or software assets, do you have an asset classification policy that is enforced?" (Munich Re) |
| ID.AM-01 Inventories of hardware managed by the organization are maintained | NIST CSF 2.0 | 3 | "Do you record and track all software and hardware assets deployed across your organization?" (Encore Fiduciary) "Does the Applicant have a continuous monitoring program to detect and maintain an inventory of all hardware and software on to its network?" (Everest Insurance) "If you inventory hardware and/or software assets, do you have an asset classification policy that is enforced?" (Munich Re) |
| ID.AM-02 Inventories of software, services, and systems managed by the organization are maintained | NIST CSF 2.0 | 3 | "Do you record and track all software and hardware assets deployed across your organization?" (Encore Fiduciary) "Does the Applicant have a continuous monitoring program to detect and maintain an inventory of all hardware and software on to its network?" (Everest Insurance) "If you inventory hardware and/or software assets, do you have an asset classification policy that is enforced?" (Munich Re) |
| A.6.1 Screening | ISO 27001:2022 | 2 | "Screening of potential employees (e.g. background, drug, criminal, credit, etc.?" (Hiscox) "Do you conduct full, nationwide, criminal background check, sexual offender check, and if possible a credit check on all prospective employees?" (CNA) "Do you conduct full, nationwide, criminal background checks, sexual offender checks, and if possible, credit checks on all prospective employees?" (CNA) |
| A.8.25 Secure development life cycle | ISO 27001:2022 | 2 | "Do you perform a technical review to ensure functional requirements can be met?" (Hiscox) "Do you have a secure coding baseline in place (e.g. peer reviews & maintenance requirements?" (Munich Re) "Are your developers regularly trained in secure programming techniques and code reviews?" (Munich Re) |
| A.8.26 Application security requirements | ISO 27001:2022 | 2 | "Do you perform a technical review to ensure functional requirements can be met?" (Hiscox) "Do you have a secure coding baseline in place (e.g. peer reviews & maintenance requirements?" (Munich Re) "Are your developers regularly trained in secure programming techniques and code reviews?" (Munich Re) |
| GV.RR-04 Cybersecurity is included in human resources practices | NIST CSF 2.0 | 2 | "Screening of potential employees (e.g. background, drug, criminal, credit, etc.?" (Hiscox) "Do you conduct full, nationwide, criminal background check, sexual offender check, and if possible a credit check on all prospective employees?" (CNA) "Do you conduct full, nationwide, criminal background checks, sexual offender checks, and if possible, credit checks on all prospective employees?" (CNA) |
| PR.PS-06 Secure software development practices are integrated, and their performance is monitored throughout the software development life cycle | NIST CSF 2.0 | 2 | "Do you perform a technical review to ensure functional requirements can be met?" (Hiscox) "Do you have a secure coding baseline in place (e.g. peer reviews & maintenance requirements?" (Munich Re) "Are your developers regularly trained in secure programming techniques and code reviews?" (Munich Re) |
| A.8.28 Secure coding | ISO 27001:2022 | 2 | "Do you perform a technical review to ensure functional requirements can be met?" (Hiscox) "Do you have a secure coding baseline in place (e.g. peer reviews & maintenance requirements?" (Munich Re) |
| ID.RA-09 The authenticity and integrity of hardware and software are assessed prior to acquisition and use | NIST CSF 2.0 | 2 | "Do you perform a technical review to ensure functional requirements can be met?" (Hiscox) "Do you have a secure coding baseline in place (e.g. peer reviews & maintenance requirements?" (Munich Re) |
| PI1.3 Controls over system processing | SOC 2 | 2 | "Do you perform a technical review to ensure functional requirements can be met?" (Hiscox) "Do you have a secure coding baseline in place (e.g. peer reviews & maintenance requirements?" (Munich Re) |
| A.5.13 Labelling of information | ISO 27001:2022 | 1 | "If you inventory hardware and/or software assets, do you have an asset classification policy that is enforced?" (Munich Re) "Do you identify & categorise third party vendors based on their access to company systems and/or data?" (Munich Re) |
| A.8.12 Data leakage prevention | ISO 27001:2022 | 1 | "Do you utilize a Data Loss Prevention (DLP) product for email?" (Munich Re) "Is a DLP solution in use on endpoints, external and internal (including email) servers?" (Munich Re) |
| C1.1 Identifying and maintaining confidential information | SOC 2 | 1 | "Do you utilize a Data Loss Prevention (DLP) product for email?" (Munich Re) "Is a DLP solution in use on endpoints, external and internal (including email) servers?" (Munich Re) |
| A.5.7 Threat intelligence | ISO 27001:2022 | 1 | "Does the Applicant have any risk management procedures in place?" (Everest Insurance) |
| A.8.11 Data masking | ISO 27001:2022 | 1 | "If Yes, is payment card data either encrypted or tokenised at all times?" (Munich Re) |
| A.8.32 Change management | ISO 27001:2022 | 1 | "Is formal signoff and acceptance required when mid-project changes are requested?" (Hiscox) |
| CC3.2 Identifying and analysing risks to objectives (COSO principle 7) | SOC 2 | 1 | "Does the Applicant have any risk management procedures in place?" (Everest Insurance) |
| GV.RM-01 Risk management objectives are established and agreed to by organizational stakeholders | NIST CSF 2.0 | 1 | "Does the Applicant have any risk management procedures in place?" (Everest Insurance) |
| ID.AM-05 Assets are prioritized based on classification, criticality, resources, and impact on the mission | NIST CSF 2.0 | 1 | "Do you identify & categorise third party vendors based on their access to company systems and/or data?" (Munich Re) |
| ID.AM-07 Inventories of data and corresponding metadata for designated data types are maintained | NIST CSF 2.0 | 1 | "Do you identify & categorise third party vendors based on their access to company systems and/or data?" (Munich Re) |
| ID.RA-02 Cyber threat intelligence is received from information sharing forums and sources | NIST CSF 2.0 | 1 | "Do you use the Microsoft 365 Defender add-on or an equivalent cybersecurity product with advanced threat hunting to protect against phishing and business email compromise?" (Beazley) |
| ID.RA-05 Threats, vulnerabilities, likelihoods, and impacts are used to understand inherent risk and inform risk response prioritization | NIST CSF 2.0 | 1 | "Does the Applicant have any risk management procedures in place?" (Everest Insurance) |
| ID.RA-07 Changes and exceptions are managed, assessed for risk impact, recorded, and tracked | NIST CSF 2.0 | 1 | "Is formal signoff and acceptance required when mid-project changes are requested?" (Hiscox) |
| 6.1.2 Information security risk assessment | ISO 27001:2022 | 1 | "Does the Applicant have any risk management procedures in place?" (Everest Insurance) |
| 6.1.3 Information security risk treatment | ISO 27001:2022 | 1 | "Does the Applicant have any risk management procedures in place?" (Everest Insurance) |
| 6.3 Planning of changes | ISO 27001:2022 | 1 | "Is formal signoff and acceptance required when mid-project changes are requested?" (Hiscox) |
A control no held question reaches is not listed here; it is listed as not asked in that held document on the carrier page, never as something the carrier does not underwrite on. Framework links open the standard on the standards site. Evidence guidance for a control is in the CSV export. Worked answers: what counts as MFA on an application and the funds-transfer verification question.