NAIC-1 | NAIC Model Law Adoption, Scope, and Licensee Definitions | 95 |
NAIC-2 | Information Security Program (ISP) - Section 4 | 97 |
NAIC-3 | Risk Assessment and Risk Management - Section 4(B) and 4(C) | 0 |
NAIC-4 | Board and Senior Management Oversight - Section 4(F) | 0 |
NAIC-5 | Third Party Service Provider Oversight - Section 4(F)(3) and Section 5 | 27 |
NAIC-6 | Cybersecurity Event Investigation and Notification - Sections 6 and 7 | 65 |
NAIC-7 | Employee Training, Awareness, and Personnel Security - Section 4(D)(7) and 4(E) | 0 |
NAIC-8 | NY DFS 23 NYCRR 500 Alignment and State Adoption Variances | 0 |
1 | Title | 0 |
10 | Penalties | 0 |
11 | Rules and regulations | 0 |
12 | Severability | 0 |
13 | Effective date and implementation periods | 0 |
2 | Purpose and intent | 0 |
4 | Information Security Program | 0 |
4A | Implementation of an Information Security Program | 0 |
4B | Objectives of the Information Security Program | 0 |
4C | Risk Assessment | 0 |
4C(1) | Designate responsibility for the Information Security Program | 0 |
4C(2) | Identify reasonably foreseeable threats | 0 |
4C(3) | Assess the likelihood and potential damage of threats | 0 |
4C(4) | Assess the sufficiency of safeguards | 0 |
4C(5) | Implement safeguards and assess key controls at least annually | 0 |
4D | Risk Management | 0 |
4D(1) | Design the program to mitigate identified risks | 0 |
4D(2) | Security measures | 0 |
4D(2)(a) | Access controls on Information Systems | 0 |
4D(2)(b) | Identify and manage data, personnel, devices, systems and facilities | 0 |
4D(2)(c) | Restrict physical access to Nonpublic Information | 0 |
4D(2)(d) | Encrypt Nonpublic Information in transit and on portable devices | 0 |
4D(2)(e) | Secure development and evaluation of applications | 0 |
4D(2)(f) | Modify the Information System in accordance with the program | 0 |
4D(2)(g) | Effective controls including Multi-Factor Authentication | 0 |
4D(2)(h) | Regularly test and monitor to detect attacks and intrusions | 0 |
4D(2)(i) | Audit trails to detect, respond and reconstruct transactions | 0 |
4D(2)(j) | Protect against environmental hazards and technological failures | 0 |
4D(2)(k) | Secure disposal of Nonpublic Information | 0 |
4D(3) | Include cybersecurity risks in enterprise risk management | 0 |
4D(4) | Stay informed of emerging threats and share information securely | 0 |
4D(5) | Cybersecurity awareness training | 0 |
4E | Oversight by Board of Directors | 0 |
4E(1) | Board requires executive management to maintain the program | 0 |
4E(2) | Annual written report to the board | 0 |
4E(3) | Oversight of delegated responsibilities | 0 |
4F | Oversight of Third-Party Service Provider arrangements | 0 |
4F(1) | Due diligence in selecting Third-Party Service Providers | 0 |
4F(2) | Require Third-Party Service Providers to implement safeguards | 0 |
4G | Program adjustments | 0 |
4H | Incident Response Plan | 0 |
4H(1) | Establish a written incident response plan | 0 |
4H(2) | Contents of the incident response plan | 0 |
4I | Annual certification to the Commissioner of the domiciliary State | 0 |
5 | Investigation of a Cybersecurity Event | 0 |
5A | Prompt investigation of an actual or suspected Cybersecurity Event | 0 |
5B | Investigation determinations | 0 |
5C | Events in systems maintained by Third-Party Service Providers | 0 |
5D | Retain Cybersecurity Event records for five years | 0 |
6 | Notification of a Cybersecurity Event | 0 |
6A | Notify the Commissioner within 72 hours | 0 |
6B | Content of the notification and continuing updates | 0 |
6C | Notification to Consumers | 0 |
6D | Events at Third-Party Service Providers | 0 |
6E | Reinsurer notice to ceding insurers and the domiciliary Commissioner | 0 |
6F | Insurer notice to producers of record | 0 |
7 | Power of Commissioner | 0 |
8 | Confidentiality | 0 |
9A | Exceptions | 0 |
9B | Compliance within 180 days of losing an exception | 0 |