NAIC Insurance Data Security Model Law (MDL-668)
Personnel Security

NAIC Insurance Data Security Model Law (MDL-668) NAIC-7: Employee Training, Awareness, and Personnel Security - Section 4(D)(7) and 4(E)

Provide cybersecurity awareness training to all personnel as part of the Information Security Program with frequency commensurate with risk + role-based training for personnel with privileged access + escalated training upon material change in risk + training records retention. Conduct background checks on employees with access to Nonpublic Information per state-specific requirements. Implement access provisioning and deprovisioning processes tied to HR lifecycle. Discipline personnel for security violations.

Maintained by Gerard BlokdykVerified against the published standard Control text last updated

Query this from an agent

The graph holds this control, the 0 it maps to, and the evidence behind each claim, over MCP and REST.