Lloyds MS11.13 Security Awareness and Insider Risk - mandatory annual cyber security awareness training for all personnel + Senior Manager Function holders + Board + role-based deep training for IT + security + claims handlers + underwriters + actuaries + finance + legal + DPO + privileged users + phishing simulation programme + Insurance-specific phishing scenarios + Lloyds market fraud awareness + insider threat programme combining technical controls (UEBA + DLP + privileged session monitoring + access review) + non-technical controls (background screening + conflict of interest + clear policies + ethical leadership + Whistleblower Policy + SM&CR conduct rules + Lloyds Code of Conduct + Insurance Distribution Directive (IDD) conduct requirements + UK Senior Managers and Certification Regime SM&CR Conduct Rules + Lloyds market governance) + Lloyds Cyber Security Code of Practice + Insurance ISAC + Insurance Fraud Enforcement Department (IFED) coordination. MS11.16 Penetration Testing and Independent Assurance - mandatory annual penetration testing + threat-led penetration testing (TLPT) per CBEST (Bank of England) for systemically important entities + TIBER-EU consideration for cross-border + scope including external + internal + web applications + APIs + mobile applications + cloud + wireless + social engineering + physical + red team / purple team / blue team coordination + CREST-certified or equivalent providers + Independent Assurance via Internal Audit + External Audit + ISAE 3402 SOC 1 Type II + AICPA SOC 2 Type II + ISO 27001 surveillance audits + ISO 27701 PIMS-P + Lloyds Cyber Security maturity assessment.
The graph holds this control, the 0 it maps to, and the evidence behind each claim, over MCP and REST.