Lloyds of London Minimum Standards 11 (MS11) - Cyber Security developed by Lloyds Performance Management Directorate (PMD) within Society of Lloyds + applicable to all Lloyds managing agents + syndicates + members agents + service companies + Lloyds Insurance Company SA Brussels (post-Brexit EU establishment). Minimum Standards are the prudential baseline expectations Lloyds requires of its market participants + part of broader Lloyds Minimum Standards suite (MS1-19 covering Governance + Risk Management + Underwriting + Reserving + Investment + Reinsurance + Operational Risk + Outsourcing + ICT + Conduct + Capital + etc) + MS11 specifically addresses Cyber Security adopted 2017 + revised 2021/2023. MS11.1 Cyber Security Governance and Board Oversight - Board-level cyber risk oversight + Chief Information Security Officer (CISO) or equivalent + cyber risk appetite + governance forum + cyber risk reporting cadence + risk committee oversight + Senior Manager Function (SMF24) Chief Operations + SMF18 Other Overall Responsibility allocation under PRA/FCA Senior Managers and Certification Regime (SM&CR). MS11.2 Cyber Risk Identification and Assessment - comprehensive cyber risk assessment integrating Lloyds Realistic Disaster Scenarios (RDS) + Lloyds Catastrophe Model + threat-led penetration testing + scenario analysis + emerging threats + ransomware specific scenario + supply chain compromise scenario. MS11.3 Information Asset Inventory - comprehensive Configuration Management Database (CMDB) + Crown Jewels identification + business criticality classification + dependency mapping + third-party dependencies + cloud workloads + OT/ICS where applicable. PRA Supervisory Statement SS1/21 + SS2/21 Operational Resilience alignment + FCA Operational Resilience Policy Statement PS21/3 + Bank of England Operational Resilience.
The graph holds this control, the 0 it maps to, and the evidence behind each claim, over MCP and REST.