NAIC Adopts Principles for Effective Cybersecurity Regulatory Guidance | Practical Law

NAIC Adopts Principles for Effective Cybersecurity Regulatory Guidance | Practical Law

The National Association of Insurance Commissioners' Cybersecurity Task Force has adopted Principles for Effective Cybersecurity Insurance Regulatory Guidance. The Guidance is intended for insurers, insurance producers and other regulated entities, and identifies principles to protect insurance consumers from cybersecurity breaches.

NAIC Adopts Principles for Effective Cybersecurity Regulatory Guidance

Practical Law Legal Update 5-609-8205 (Approx. 3 pages)

NAIC Adopts Principles for Effective Cybersecurity Regulatory Guidance

by Practical Law Intellectual Property & Technology
Published on 22 Apr 2015USA (National/Federal)
The National Association of Insurance Commissioners' Cybersecurity Task Force has adopted Principles for Effective Cybersecurity Insurance Regulatory Guidance. The Guidance is intended for insurers, insurance producers and other regulated entities, and identifies principles to protect insurance consumers from cybersecurity breaches.
On April 17, 2015, the National Association of Insurance Commissioners' Cybersecurity Task Force (NAIC CTF) published a press release announcing that it has adopted Principles for Effective Cybersecurity Insurance Regulatory Guidance. The Guidance is intended for insurers, insurance producers and other regulated entities and identifies types of safeguards regulators expect insurers to have in place to protect consumers from cybersecurity breaches. It is also intended to establish insurance regulatory guidance that promotes coordination and protects insurance consumers.
The Guidance adopts established data security principles, for example that effective programs include:
  • Incident response planning.
  • Vendor management and controls.
  • Periodic training and program assessment.
In addition, the Guidance note that regulatory guidance for insurers and insurance producers should be flexible, scalable, practical and consistent with nationally recognized cybersecurity efforts, such as the National Institute of Standards and Technology (NIST) Framework for Improving Critical Infrastructure Cybersecurity.