NAIC Insurance Data Security Model Law (MDL-668)
Information Security Program

NAIC Insurance Data Security Model Law (MDL-668) NAIC-2: Information Security Program (ISP) - Section 4

Develop, implement, and maintain a comprehensive written Information Security Program (ISP) based on the licensees risk assessment that includes administrative, technical, and physical safeguards for protecting Nonpublic Information and the licensees information systems. Scale the ISP commensurate with size + complexity + nature + scope of activities + sensitivity of Nonpublic Information used + handled. Address Section 4(D) requirements covering nine specific controls: access controls + identification + authentication + change management + system monitoring + protective controls + physical security + business continuity + vendor oversight.

Query this from an agent

The graph holds this control, the 0 it maps to, and the evidence behind each claim, over MCP and REST.