Indiana Statutes

§ 27-2-27-20 — Incident response plan

Indiana § 27-2-27-20
JurisdictionIndiana
Title 27INSURANCE
Art. 2POWERS AND DUTIES OF INSURERS
Ch. 27Insurance Data Security

This text of Indiana § 27-2-27-20 (Incident response plan) is published on Counsel Stack Legal Research, covering Indiana primary law. Counsel Stack provides free access to over 12 million legal documents including statutes, case law, regulations, and constitutions.

Bluebook
Ind. Code § 27-2-27-20 (2026).

Text

(a)As part of its information security program, a licensee shall establish a written incident response plan designed to promptly respond to, and recover from, any cybersecurity event.
(b)An incident response plan must include the following:
(1)The internal process for responding to a cybersecurity event.
(2)The goals of the incident response plan.
(3)The definition of clear roles, responsibilities, and levels of decision making authority.
(4)External and internal communications and information sharing.
(5)Identification of requirements for the remediation of any identified weaknesses in information systems and associated controls.
(6)Documentation and reporting regarding cybersecurity events and related incident response activities.
(7)The evaluation and revision, as necessary, of

Free access — add to your briefcase to read the full text and ask questions with AI

Legislative History

As added by P.L.130-2020, SEC.10.

Nearby Sections

15
View on official source ↗

Cite This Page — Counsel Stack

Bluebook (online)
Indiana § 27-2-27-20, Counsel Stack Legal Research, https://law.counselstack.com/statute/in/27-2-27-20.