Pennsylvania Statutes

§ 4513 — Information security program

Pennsylvania·Title 40 INSURANCE·Part PART II·Ch. 45 INSURANCE DATA SECURITY·Subch. PROCEDURES
(a)Requirement for implementation and objectives.--Each licensee shall develop, implement and maintain a comprehensive written information security program based on the licensee's risk assessment that:
(1)Contains administrative, technical and physical safeguards for the protection of nonpublic information and the licensee's information systems.
(2)Is commensurate with the following:
(i)The size and complexity of the licensee.
(ii)The nature and scope of the licensee's activities, including the licensee's use of third-party service providers.
(iii)The sensitivity of the nonpublic information used by the licensee or in the licensee's possession, custody or control.
(3)Is designed to protect:
(i)The security and confidentiality of nonpublic information and the security of the

Free access — add to your briefcase to read the full text and ask questions with AI

Pennsylvania § 4513 (Information security program) — published by Counsel Stack Legal Research, free access to 12M+ legal documents.

Legislative History

Cross References.Section 4513 is referred to in sections 4514, 4516, 4521, 4532, 4536 of this title.

Nearby Sections

15
View on official source ↗