Indiana Statutes

§ 27-2-27-18 — Actions required based on risk assessment results

Indiana·Title 27 INSURANCE·Art. 2 POWERS AND DUTIES OF INSURERS·Ch. 27 Insurance Data Security

Based on the results of the risk assessment, a licensee shall do the following:

(1)Design its information security program to mitigate the identified risks, commensurate with:
(A)the licensee's size and complexity;
(B)the nature and scope of the licensee's activities; and
(C)the sensitivity of the nonpublic information in the licensee's control.
(2)Determine and implement appropriate security measures, which may include the following:
(A)Placing access controls on information systems, including controls to authenticate and permit only authorized individuals to have access to nonpublic information.
(B)Identifying and managing the data, personnel, devices, systems, and facilities that enable the licensee to achieve business purposes in accordance with their relative importance to busi

Free access — add to your briefcase to read the full text and ask questions with AI

Indiana § 27-2-27-18 (Actions required based on risk assessment results) — published by Counsel Stack Legal Research, free access to 12M+ legal documents.

Legislative History

As added by P.L.130-2020, SEC.10.

Nearby Sections

15
View on official source ↗