NAIC Insurance Data Security Model Law (MDL-668)
Risk Assessment

NAIC Insurance Data Security Model Law (MDL-668) NAIC-3: Risk Assessment and Risk Management - Section 4(B) and 4(C)

Conduct comprehensive risk assessments to identify reasonably foreseeable internal and external threats that could result in unauthorised access to or transmission, disclosure, misuse, alteration, or destruction of Nonpublic Information stored on the licensees information systems. Assess likelihood and potential damage. Reassess sufficiency of safeguards on a regular basis. Document risk treatment decisions including accept + mitigate + transfer + avoid. Update risk register on at least an annual basis or upon material change in operations or threat landscape.

Maintained by Gerard BlokdykVerified against the published standard Control text last updated

Query this from an agent

The graph holds this control, the 0 it maps to, and the evidence behind each claim, over MCP and REST.