ABCD
1
2
3
SECURITY QUESTIONNAIRE
4
CATEGORY: RISK MANAGEMENT
5
6
7
PC.3.1Please supply the organization's Risk Management Program (RMP) Policy that includes guidance on the identification of potential threats, rating the significance of the risks associated with the identified threats, and mitigation strategies for those risks.
9
PC.3.2Is a formal and independent risk assessment performed at least annually?
11
PC.3.3Does the organization carry cyber-risk insurance to protect against unforeseen service outages, data that is lost or stolen, and security incidents?
13
PC.3.3.1Please provide the Cyber Insurance Certificate.
15
PC.3.4How much cyber-risk insurance coverage do you have for data breach or security incident?
17
PC.3.5Has the organization had a security/data breach in the last 10 years? If yes, please describe.
19
20
21
22
23
24
25
26
27
28
29