§ 33-103. Information security program
West's Annotated Code of MarylandInsuranceEffective: October 1, 2022
Effective: October 1, 2022
MD Code, Insurance, § 33-103
§ 33-103. Information security program
(a)(1) Each carrier shall develop, implement, and maintain a comprehensive written information security program based on the carrier's risk assessment.
(b) A carrier's information security program shall be designed to:
(c) Each carrier shall:
(2) identify reasonably foreseeable internal or external threats that could result in unauthorized access, transmission, disclosure, misuse, alteration, or destruction of nonpublic information, including the security of information systems and nonpublic information that are accessible to, or held by, third-party service providers;
(d) Based on its risk assessment, a carrier shall:
(1) design its information security program to mitigate the identified risks, commensurate with the size and complexity of the carrier's activities, including its use of third-party service providers, and the sensitivity of the nonpublic information used by the carrier or in the carrier's possession, custody, or control; and
(e) A carrier's enterprise risk management process shall include cybersecurity risks.
Carrier to stay informed regarding emerging threats or vulnerabilities; provide personnel with cybersecurity awareness training
(f) Each carrier shall:
(g)(1) If a carrier has a board of directors, the board or an appropriate committee of the board shall, at a minimum:
2. material matters related to the information security program, addressing issues such as risk assessment, risk management and control decisions, third-party service provider arrangements, results of testing, cybersecurity events or violations and management's responses thereto, and recommendations for changes in the information security program.
(h) A carrier shall require a third-party service provider to implement appropriate administrative, technical, and physical measures to protect and secure the information systems and nonpublic information that are accessible to or held by the third-party service provider.
(i)(1) Each carrier shall establish a written incident response plan designed to promptly respond to, and recover from, any cybersecurity event that compromises the confidentiality, integrity, or availability of nonpublic information in its possession, the carrier's information systems, or the continuing functionality of any aspect of the carrier's business or operations.
(j)(1) Except as provided in subsection (k) of this section, on or before April 15 each year, each carrier shall submit to the Commissioner a written statement certifying that the carrier is in compliance with the requirements set forth in this section.
(k) A carrier that is not domiciled in the State is exempt from the provisions of subsection (j)(1) of this section if the carrier:
Credits
Added by Acts 2022, c. 231, § 1, eff. Oct. 1, 2022.
MD Code, Insurance, § 33-103, MD INSURANCE § 33-103
Current with legislation effective through June 1, 2023, from the 2023 Regular Session of the General Assembly. Some statute sections may be more current, see credits for details.
End of Document |