Model policy · version 1
Draft
Insurance information security
Protect insurer systems and nonpublic information.
What’s in this policy5 sections · Insurance information security · Read the full policy
4Obligations · things you must do
4Evidence · records that prove it
1Monitoring · checks and deadlines
0Reporting · reports you must send
Does this apply to you?
Answer a few questions and each obligation is marked applies, likely, or needs more information.
Tell Leela about your companyHand over the whole policy
Every obligation in this policy, in one request.
What the policy requires
Automate
Leela can perform the work through your connected systems.
Monitor
Leela can watch for the trigger, keep the clock, and flag what is late.
Prepare for review
Leela can prepare the artifact and hand it to a person for review.
Human required
A person must do the work; Leela can track it and file the evidence.
TriggerAnnual · At material risk changes and the company’s annual program review
EvidenceRisk assessment, policy approval and scope register
TriggerContinuous · On access changes and security alerts
EvidenceAccess review, control evidence and exception register
TriggerEvent-driven · Before onboarding a provider and at material changes
EvidenceProvider assessment, contract controls and follow-up
TriggerEvent-driven · At a cybersecurity event and response exercise
EvidenceIncident timeline, notification assessment and exercise findings