Indiana Statutes

§ 27-2-27-17 — Risk assessment; requirements

Indiana·Title 27 INSURANCE·Art. 2 POWERS AND DUTIES OF INSURERS·Ch. 27 Insurance Data Security

A licensee shall conduct a risk assessment of its information systems and treatment of nonpublic information by doing the following:

(1)Designating one (1) or more employees, an affiliate, or an outside vendor designated to act on behalf of the licensee information security program.
(2)Identifying reasonably foreseeable internal or external threats that could result in a cybersecurity event, including threats to information systems and nonpublic information held or accessed by third party service providers.
(3)Assessing the likelihood and potential damage of the threats identified in subdivision (2), taking into consideration the sensitivity of the nonpublic information.
(4)Assessing the sufficiency of the policies, procedures, information systems, and other safeguards currently in pla

Free access — add to your briefcase to read the full text and ask questions with AI

Indiana § 27-2-27-17 (Risk assessment; requirements) — published by Counsel Stack Legal Research, free access to 12M+ legal documents.

Legislative History

As added by P.L.130-2020, SEC.10.

Nearby Sections

15
View on official source ↗