Leela
Insurance information security
IS-01
Draft

Maintain a risk-based security program

Requirement

Identify assets and nonpublic information, document risk, assign accountable security leadership and obtain the required policy approval. Map each applicable Part 500 provision and exemption to an owner.

Trigger

Annual

At material risk changes and the company’s annual program review

Action

Identify assets and nonpublic information, document risk, assign accountable security leadership and obtain the required policy approval. Map each applicable Part 500 provision and exemption to an owner.

Evidence
  • Risk assessment, policy approval and scope register

    Controlled record with date, owner, source and review history

Owner

CISO

Leela can
Prepare for review

Leela can prepare the artifact and hand it to a person for review.

Leela can prepare a draft and evidence checklist for the accountable reviewer. Adoption and legal conclusions require human review.

Applies

Tell Leela about your company to see whether this applies.

Status
Setup needed

Tell Leela how you handle it today, or hand it over: see what’s next.

What’s next?