NAIC Insurance Data Security Model Law (MDL-668)
Evidence request list. 8 controls, 8 carrying auditor artefact guidance. Generated from the compliance knowledge graph on 12 September 2026. Published by The Art of Service.
Cross-State Compliance
Maintain awareness of New York DFS 23 NYCRR Part 500 Cybersecurity Regulation alignment (which NAIC Model Law substantively adopted in 2017 plus 2024 amendments adding ransomware payment notification + extortion payment disclosure + chief information security officer (CISO) reporting requirements). Track state-by-state variances including Connecticut 90-day vs 72-hour notification + South Carolina early adopter framework + Ohio safe harbor incentives + Mississippi inclusion of insurance group privacy + Indiana annual filing date variation. Implement multi-state controls capable of meeting the strictest state requirements per multi-licensed insurer compliance matrix.
- NY DFS 500 + NAIC alignment matrix
- State adoption tracker (24+ states)
- Multi-state variance compliance matrix
- Annual notification calendar
- NYDFS CISO certification
- Ransomware payment notification process
- No state adoption tracker
- Missing multi-state variances
- No NYDFS alignment
- No ransomware notification process
Governance Oversight
Designate one or more employees, an affiliate, or an outside vendor to be responsible for the Information Security Program. Require the Board of Directors (or appropriate committee) or senior management to receive an annual written report from the ISP designee covering: overall status of the Program + material matters relating to the Program including issues such as risk assessment + risk management and control decisions + service provider arrangements + results of testing + cybersecurity events or violations and management response + recommendations for material changes. File annual cybersecurity certification with state insurance commissioner by 15 February following the calendar year covered.
- ISP designee appointment letter
- Annual board report
- Board meeting minutes
- Senior management committee minutes
- 15 February annual certification filing
- Material matters log
- No designated ISP owner
- No annual board report
- Missing 15 February certification
- Inadequate board engagement
Governance and Scope
Comply with the NAIC Insurance Data Security Model Law (Model Law 668) as adopted by the licensees state-of-domicile insurance department (24+ states have adopted as of 2025 including South Carolina first, Ohio, Michigan, Mississippi, Alabama, Connecticut, Delaware, Indiana, New Hampshire, Louisiana, Virginia, Iowa, Hawaii, Minnesota, North Dakota, Maryland, Wisconsin, Tennessee, Kentucky, Vermont, Maine, Illinois, New Mexico, Alaska, Oklahoma). Establish program scope across all licensees including insurers, producers, third party administrators (TPAs), independent adjusters, and other entities licensed by the state insurance department. Maintain exemption analysis (HIPAA covered entities + small licensee fewer than 10 employees + reinsurers subject only at cedent level + employees of licensee not separately licensed).
- State-of-domicile adoption confirmation
- Licensee scope analysis
- Exemption qualification documentation
- Affiliate consolidation analysis
- Reinsurer scope analysis
- Annual scope review
- Outdated state adoption tracking
- Unclear licensee classification
- Missing exemption documentation
- No affiliate analysis
Incident Response
Establish a written Incident Response Plan to respond to and recover from a Cybersecurity Event. Investigate Cybersecurity Events to determine scope + Nonpublic Information involved + impact of the Event + reasonable measures to restore the security of the Information Systems compromised. Notify the state insurance commissioner of the state-of-domicile within 72 hours of determining a Cybersecurity Event has occurred (if at least one of the threshold conditions is met). Notify affected consumers as required by state-specific consumer notification laws. Notify reinsurers and ceding insurers. Investigate Third-Party Service Provider Cybersecurity Events.
- Written Incident Response Plan
- Cybersecurity Event log
- 72-hour Commissioner notification record
- Consumer notification records
- Reinsurer/cedent notification
- Third-Party event investigation
- Post-incident report
- No written IRP
- Missed 72-hour notification
- No consumer notification process
- Missing third-party event handling
Information Security Program
Develop, implement, and maintain a comprehensive written Information Security Program (ISP) based on the licensees risk assessment that includes administrative, technical, and physical safeguards for protecting Nonpublic Information and the licensees information systems. Scale the ISP commensurate with size + complexity + nature + scope of activities + sensitivity of Nonpublic Information used + handled. Address Section 4(D) requirements covering nine specific controls: access controls + identification + authentication + change management + system monitoring + protective controls + physical security + business continuity + vendor oversight.
- Written Information Security Program document
- Section 4(D) control mapping (1-9)
- Annual program review
- Risk-based scaling justification
- Program approval by senior official
- ISP version history
- No written program
- Missing Section 4(D) control coverage
- No risk-based scaling
- Outdated program
Personnel Security
Provide cybersecurity awareness training to all personnel as part of the Information Security Program with frequency commensurate with risk + role-based training for personnel with privileged access + escalated training upon material change in risk + training records retention. Conduct background checks on employees with access to Nonpublic Information per state-specific requirements. Implement access provisioning and deprovisioning processes tied to HR lifecycle. Discipline personnel for security violations.
- Annual training completion records
- Role-based training curricula
- Background check evidence
- Access provisioning workflow
- Deprovisioning records
- Disciplinary action records
- Training material approval
- No awareness training
- Incomplete completion records
- No role-based training
- Missing access lifecycle tied to HR
Risk Assessment
Conduct comprehensive risk assessments to identify reasonably foreseeable internal and external threats that could result in unauthorised access to or transmission, disclosure, misuse, alteration, or destruction of Nonpublic Information stored on the licensees information systems. Assess likelihood and potential damage. Reassess sufficiency of safeguards on a regular basis. Document risk treatment decisions including accept + mitigate + transfer + avoid. Update risk register on at least an annual basis or upon material change in operations or threat landscape.
- Annual risk assessment report
- Threat modelling output
- Risk register with treatment decisions
- Risk acceptance documentation
- Reassessment trigger log
- Senior official sign-off
- No documented risk assessment
- Stale risk register
- No reassessment cadence
- Missing senior official sign-off
Third Party Management
Exercise due diligence in selecting Third-Party Service Providers and require Third-Party Service Providers to implement appropriate administrative, technical, and physical measures to protect and secure the Information Systems and Nonpublic Information that are accessible to or held by Third-Party Service Providers. Conduct periodic assessment of Third-Party Service Providers based on the risk they present and the continued adequacy of their cybersecurity practices. Maintain contractual obligations including SOC 2 Type II reports + audit rights + notification on cybersecurity events + termination rights + return of data.
- Third-Party inventory
- Due diligence questionnaires
- Vendor risk classification
- Contract clauses (security + audit + notification)
- SOC 2 Type II reports
- Periodic vendor assessment
- Termination/exit clauses
- No vendor inventory
- Missing due diligence
- No risk classification
- No ongoing monitoring
Assembled from the framework’s own control set, so this list is regenerated rather than written and stays current as the graph does. See the NAIC Insurance Data Security Model Law (MDL-668) framework page.