United States (NAIC model, enacted by states)

NAIC Insurance Data Security Model Law (MDL-668)

68 controls. 126 other frameworks in our corpus share controls with it. Here is all of it, and how much of it you are already doing.

Page built . This page is derived from the framework corpus, which changes when the corpus is extended rather than daily.

68 controls 126 frameworks share controls with it United States (NAIC model, enacted by states) verified against its source document

Every control below is one this framework asks for. The right hand column counts how many other frameworks in our corpus carry the same control, which is the difference between doing this work once and doing it again for the next standard.

NAIC Insurance Data Security Model Law Evidence & Implementation Kit

68 controls is the documentation set somebody has to write. This is that set, already written: an adopt-ready artifact for every control in policy and procedure text you edit rather than draft, and the evidence checklist an auditor asks for against each.

See what is in it, $249

The same set every buyer of this kit receives. Nothing here is produced on request.

What you already have

Frameworks whose controls overlap this one, most first. If you run any of them, the count is roughly what you have already evidenced.

Every control

CodeControlAlso in
NAIC-1NAIC Model Law Adoption, Scope, and Licensee Definitions95
NAIC-2Information Security Program (ISP) - Section 497
NAIC-3Risk Assessment and Risk Management - Section 4(B) and 4(C)0
NAIC-4Board and Senior Management Oversight - Section 4(F)0
NAIC-5Third Party Service Provider Oversight - Section 4(F)(3) and Section 527
NAIC-6Cybersecurity Event Investigation and Notification - Sections 6 and 765
NAIC-7Employee Training, Awareness, and Personnel Security - Section 4(D)(7) and 4(E)0
NAIC-8NY DFS 23 NYCRR 500 Alignment and State Adoption Variances0
1Title0
10Penalties0
11Rules and regulations0
12Severability0
13Effective date and implementation periods0
2Purpose and intent0
4Information Security Program0
4AImplementation of an Information Security Program0
4BObjectives of the Information Security Program0
4CRisk Assessment0
4C(1)Designate responsibility for the Information Security Program0
4C(2)Identify reasonably foreseeable threats0
4C(3)Assess the likelihood and potential damage of threats0
4C(4)Assess the sufficiency of safeguards0
4C(5)Implement safeguards and assess key controls at least annually0
4DRisk Management0
4D(1)Design the program to mitigate identified risks0
4D(2)Security measures0
4D(2)(a)Access controls on Information Systems0
4D(2)(b)Identify and manage data, personnel, devices, systems and facilities0
4D(2)(c)Restrict physical access to Nonpublic Information0
4D(2)(d)Encrypt Nonpublic Information in transit and on portable devices0
4D(2)(e)Secure development and evaluation of applications0
4D(2)(f)Modify the Information System in accordance with the program0
4D(2)(g)Effective controls including Multi-Factor Authentication0
4D(2)(h)Regularly test and monitor to detect attacks and intrusions0
4D(2)(i)Audit trails to detect, respond and reconstruct transactions0
4D(2)(j)Protect against environmental hazards and technological failures0
4D(2)(k)Secure disposal of Nonpublic Information0
4D(3)Include cybersecurity risks in enterprise risk management0
4D(4)Stay informed of emerging threats and share information securely0
4D(5)Cybersecurity awareness training0
4EOversight by Board of Directors0
4E(1)Board requires executive management to maintain the program0
4E(2)Annual written report to the board0
4E(3)Oversight of delegated responsibilities0
4FOversight of Third-Party Service Provider arrangements0
4F(1)Due diligence in selecting Third-Party Service Providers0
4F(2)Require Third-Party Service Providers to implement safeguards0
4GProgram adjustments0
4HIncident Response Plan0
4H(1)Establish a written incident response plan0
4H(2)Contents of the incident response plan0
4IAnnual certification to the Commissioner of the domiciliary State0
5Investigation of a Cybersecurity Event0
5APrompt investigation of an actual or suspected Cybersecurity Event0
5BInvestigation determinations0
5CEvents in systems maintained by Third-Party Service Providers0
5DRetain Cybersecurity Event records for five years0
6Notification of a Cybersecurity Event0
6ANotify the Commissioner within 72 hours0
6BContent of the notification and continuing updates0
6CNotification to Consumers0
6DEvents at Third-Party Service Providers0
6EReinsurer notice to ceding insurers and the domiciliary Commissioner0
6FInsurer notice to producers of record0
7Power of Commissioner0
8Confidentiality0
9AExceptions0
9BCompliance within 180 days of losing an exception0

Tell me when NAIC Insurance Data Security Model Law (MDL-668) files something new

One email when a public company newly discloses something this framework governs, naming the company and what our corpus says it puts in scope. Nothing else, and one click to stop.

What an auditor will ask you to produce

The artefacts named on the failure modes this framework speaks to.

  • TPSP register
  • AOC collection log
  • contractual responsibility matrix
  • monitoring cadence
  • vendor monitoring schedule
  • annual review reports
  • Risk assessment process
  • Fraud-risk consideration
  • Risk responses
  • Annual risk assessment report

How programmes fail on this

Failure modes named by this framework and others. Each opens the full record.

What this page is

A control-level reference for NAIC Insurance Data Security Model Law (MDL-668), drawn from our framework corpus. Control codes and titles are references to the standard, not reproductions of it. The overlap counts and the auditor artefacts are our own work and are the part you will not find elsewhere.

Measure this against what you already run · All frameworks · Today's edition