NAIC Insurance Data Security Model Law (MDL-668)
Third Party Management

NAIC Insurance Data Security Model Law (MDL-668) NAIC-5: Third Party Service Provider Oversight - Section 4(F)(3) and Section 5

Exercise due diligence in selecting Third-Party Service Providers and require Third-Party Service Providers to implement appropriate administrative, technical, and physical measures to protect and secure the Information Systems and Nonpublic Information that are accessible to or held by Third-Party Service Providers. Conduct periodic assessment of Third-Party Service Providers based on the risk they present and the continued adequacy of their cybersecurity practices. Maintain contractual obligations including SOC 2 Type II reports + audit rights + notification on cybersecurity events + termination rights + return of data.

Query this from an agent

The graph holds this control, the 0 it maps to, and the evidence behind each claim, over MCP and REST.