Indiana Statutes
§ 27-2-27-20 — Incident response plan
(a)As part of its information security
program, a licensee shall establish a written incident response plan
designed to promptly respond to, and recover from, any cybersecurity
event.
(b)An incident response plan must include the following:
(1)The internal process for responding to a cybersecurity event.
(2)The goals of the incident response plan.
(3)The definition of clear roles, responsibilities, and levels of
decision making authority.
(4)External and internal communications and information
sharing.
(5)Identification of requirements for the remediation of any
identified weaknesses in information systems and associated
controls.
(6)Documentation and reporting regarding cybersecurity events
and related incident response activities.
(7)The evaluation and revision, as necessary, of
Free access — add to your briefcase to read the full text and ask questions with AI
Indiana § 27-2-27-20 (Incident response plan) — published by Counsel Stack Legal Research, free access to 12M+ legal documents.
Legislative History
As added by P.L.130-2020, SEC.10.
Nearby Sections
15
§ 27-1-1-1
Creation; functions§ 27-1-1-2
Insurance commissioner§ 27-1-1-3
Personnel§ 27-1-1-4
Repealed§ 27-1-1-5
Repealed§ 27-1-1.5-10
"Annual Statement Blank"§ 27-1-1.5-11
"Annual Statement Instructions"§ 27-1-1.5-12
"Current Dental Terminology"; "CDT"§ 27-1-1.5-13
"Current Procedural Terminology"; "CPT"§ 27-1-1.5-15
"Financial Analysis Handbook"§ 27-1-1.5-16
"Financial Condition Examiner's Handbook"§ 27-1-1.5-18
"Healthcare Common Procedure Coding System"; "HCPCS"