Cyber Insurance Application Scannermap an application to controls

Where the text comes from

Cyber Insurance Application Scanner holds the text of ISO 27001:2022, SOC 2 and NIST CSF 2.0, read clause by clause against the copy we hold. Each requirement is our statement of its clause, cited to it, not the instrument verbatim. Where a text is not held in full the page names it and does not state it. The carrier questions are public application documents, held from the source and refreshed by rebuilding the held snapshot, never fetched while you use the tool.

The frameworks

The held carrier applications

Worked answers

Evidence guidance is our words, from the held control area, not a statement of any standard and not binding on a carrier or an assessor. The full auditor-facing evidence guidance sits in the control data behind every mapping; a carrier page shows only the one or two items a carrier would actually ask for.