Designate one or more employees, an affiliate, or an outside vendor to be responsible for the Information Security Program. Require the Board of Directors (or appropriate committee) or senior management to receive an annual written report from the ISP designee covering: overall status of the Program + material matters relating to the Program including issues such as risk assessment + risk management and control decisions + service provider arrangements + results of testing + cybersecurity events or violations and management response + recommendations for material changes. File annual cybersecurity certification with state insurance commissioner by 15 February following the calendar year covered.
The graph holds this control, the 0 it maps to, and the evidence behind each claim, over MCP and REST.