Due Diligence and Ongoing Monitoring

 View Only
  • 1.  Insurance Carrier Due Diligence

    This message was posted by a user wishing to remain anonymous
    Posted 01-29-2024 12:09 PM
    This message was posted by a user wishing to remain anonymous

    For those who track insurance companies in their TPRM program, what types of documentation do you obtain from insurance companies based outside the US? Obviously, for privacy one would want a copy of their privacy policy/notice and DPA. But for security, do you normally ask for just evidence of penetration and vulnerability testing? We're finding that these companies do not have SOC2s. Nor do they have pre-completed SIG Lite questionnaire which they can provide.



  • 2.  RE: Insurance Carrier Due Diligence

    Posted 01-29-2024 03:42 PM

     

    Alternatives in EU

    SAE3000

    ISO 27001 cert with SoA