Indiana Statutes
§ 27-2-27-17 — Risk assessment; requirements
A licensee shall conduct a risk assessment of its information systems and treatment of nonpublic information by doing the following:
(1)Designating one (1) or more employees, an affiliate, or an
outside vendor designated to act on behalf of the licensee
information security program.
(2)Identifying reasonably foreseeable internal or external threats
that could result in a cybersecurity event, including threats to
information systems and nonpublic information held or accessed
by third party service providers.
(3)Assessing the likelihood and potential damage of the threats
identified in subdivision (2), taking into consideration the
sensitivity of the nonpublic information.
(4)Assessing the sufficiency of the policies, procedures,
information systems, and other safeguards currently in pla
Free access — add to your briefcase to read the full text and ask questions with AI
Indiana § 27-2-27-17 (Risk assessment; requirements) — published by Counsel Stack Legal Research, free access to 12M+ legal documents.
Legislative History
As added by P.L.130-2020, SEC.10.
Nearby Sections
15
§ 27-1-1-1
Creation; functions§ 27-1-1-2
Insurance commissioner§ 27-1-1-3
Personnel§ 27-1-1-4
Repealed§ 27-1-1-5
Repealed§ 27-1-1.5-10
"Annual Statement Blank"§ 27-1-1.5-11
"Annual Statement Instructions"§ 27-1-1.5-12
"Current Dental Terminology"; "CDT"§ 27-1-1.5-13
"Current Procedural Terminology"; "CPT"§ 27-1-1.5-15
"Financial Analysis Handbook"§ 27-1-1.5-16
"Financial Condition Examiner's Handbook"§ 27-1-1.5-18
"Healthcare Common Procedure Coding System"; "HCPCS"