Sec. 19. (a) If the licensee has a board of directors, the board of directors shall require the licensee's executive management or its delegates to develop, implement, and maintain the licensee's information security program.
(b) If the licensee's executive management delegates any of its responsibilities under this section, it shall:
(1) oversee the development, implementation, and maintenance of the licensee's information security program prepared by the delegate; and
(2) receive a report from the delegate concerning:
(A) the overall status of the information security program;
(B) the licensee's compliance with this chapter; and
(C) material matters related to the information security program addressing such issues as:
(i) risk assessment;
(ii) risk management and control decisions;
(iii) third party service provider arrangements;
(iv) results of testing;
(v) cybersecurity events and management's responses to cybersecurity events; and
(vi) recommendations for changes in the information security program.
As added by P.L.130-2020, SEC.10.
Structure Indiana Code
Article 2. Powers and Duties of Insurers
Chapter 27. Insurance Data Security
27-2-27-1. Applicability of Chapter
27-2-27-2. "Authorized Individual"
27-2-27-5. "Cybersecurity Event"
27-2-27-8. "Information Security Program"
27-2-27-9. "Information System"
27-2-27-11. "Multi-Factor Authentication"
27-2-27-12. "Nonpublic Information"
27-2-27-13. "Publicly Available Information"
27-2-27-15. "Third Party Service Provider"
27-2-27-16. Information Security Program; Requirements
27-2-27-17. Risk Assessment; Requirements
27-2-27-18. Actions Required Based on Risk Assessment Results
27-2-27-19. Board of Directors; Executive Management
27-2-27-20. Incident Response Plan
27-2-27-21. Investigation of Cybersecurity Event
27-2-27-22. Notice to Ceding Insurers and Commissioner of Cybersecurity Event
27-2-27-23. Notice to Producers of Cybersecurity Event
27-2-27-24. Powers of Commissioner
27-2-27-26. Exemptions From Chapter
27-2-27-27. Suspension; Revocation
27-2-27-29. Private Right of Action