NAIC Insurance Data Security Model Law (MDL-668)
Incident Response

NAIC Insurance Data Security Model Law (MDL-668) NAIC-6: Cybersecurity Event Investigation and Notification - Sections 6 and 7

Establish a written Incident Response Plan to respond to and recover from a Cybersecurity Event. Investigate Cybersecurity Events to determine scope + Nonpublic Information involved + impact of the Event + reasonable measures to restore the security of the Information Systems compromised. Notify the state insurance commissioner of the state-of-domicile within 72 hours of determining a Cybersecurity Event has occurred (if at least one of the threshold conditions is met). Notify affected consumers as required by state-specific consumer notification laws. Notify reinsurers and ceding insurers. Investigate Third-Party Service Provider Cybersecurity Events.

Query this from an agent

The graph holds this control, the 0 it maps to, and the evidence behind each claim, over MCP and REST.