Sec. 20. (a) As part of its information security program, a licensee shall establish a written incident response plan designed to promptly respond to, and recover from, any cybersecurity event.
(b) An incident response plan must include the following:
(1) The internal process for responding to a cybersecurity event.
(2) The goals of the incident response plan.
(3) The definition of clear roles, responsibilities, and levels of decision making authority.
(4) External and internal communications and information sharing.
(5) Identification of requirements for the remediation of any identified weaknesses in information systems and associated controls.
(6) Documentation and reporting regarding cybersecurity events and related incident response activities.
(7) The evaluation and revision, as necessary, of the incident response plan.
(c) Annually, not later than April 15, each insurer domiciled in Indiana shall submit to the commissioner a written statement certifying that the insurer is in compliance with the requirements set forth in sections 16 through 19 of this chapter and this section. Each insurer shall maintain for examination by the department all records, schedules, and data supporting this certificate for a period of five (5) years. To the extent an insurer has identified areas, systems, or processes that require material improvement, updating, or redesign, the insurer shall document the identification of the areas, systems, or processes and the remedial efforts planned and underway to address the areas, systems, or processes. The documentation must be available for inspection by the commissioner.
As added by P.L.130-2020, SEC.10.
Structure Indiana Code
Article 2. Powers and Duties of Insurers
Chapter 27. Insurance Data Security
27-2-27-1. Applicability of Chapter
27-2-27-2. "Authorized Individual"
27-2-27-5. "Cybersecurity Event"
27-2-27-8. "Information Security Program"
27-2-27-9. "Information System"
27-2-27-11. "Multi-Factor Authentication"
27-2-27-12. "Nonpublic Information"
27-2-27-13. "Publicly Available Information"
27-2-27-15. "Third Party Service Provider"
27-2-27-16. Information Security Program; Requirements
27-2-27-17. Risk Assessment; Requirements
27-2-27-18. Actions Required Based on Risk Assessment Results
27-2-27-19. Board of Directors; Executive Management
27-2-27-20. Incident Response Plan
27-2-27-21. Investigation of Cybersecurity Event
27-2-27-22. Notice to Ceding Insurers and Commissioner of Cybersecurity Event
27-2-27-23. Notice to Producers of Cybersecurity Event
27-2-27-24. Powers of Commissioner
27-2-27-26. Exemptions From Chapter
27-2-27-27. Suspension; Revocation
27-2-27-29. Private Right of Action