| A | B | C | D | |
|---|---|---|---|---|
1 | ||||
2 | ||||
3 | SECURITY QUESTIONNAIRE | |||
4 | CATEGORY: RISK MANAGEMENT | |||
5 | ||||
6 | ||||
7 | PC.3.1 | Please supply the organization's Risk Management Program (RMP) Policy that includes guidance on the identification of potential threats, rating the significance of the risks associated with the identified threats, and mitigation strategies for those risks. | ||
9 | PC.3.2 | Is a formal and independent risk assessment performed at least annually? | ||
11 | PC.3.3 | Does the organization carry cyber-risk insurance to protect against unforeseen service outages, data that is lost or stolen, and security incidents? | ||
13 | PC.3.3.1 | Please provide the Cyber Insurance Certificate. | ||
15 | PC.3.4 | How much cyber-risk insurance coverage do you have for data breach or security incident? | ||
17 | PC.3.5 | Has the organization had a security/data breach in the last 10 years? If yes, please describe. | ||
19 | ||||
20 | ||||
21 | ||||
22 | ||||
23 | ||||
24 | ||||
25 | ||||
26 | ||||
27 | ||||
28 | ||||
29 |