GroundRules
← Search the law
Pennsylvania · Through 2024-08-21 (Statute Update stamp, 40 Pa.C.S.)

40 Pa.C.S. § 4512: Risk assessment.

Read at publisher ↗
Where this section sits in the code
  1. Title 40 - INSURANCE
  2. PART II REGULATION OF INSURERS AND RELATED PERSONS GENERALLY
  3. CHAPTER 45 INSURANCE DATA SECURITY
  4. SUBCHAPTER B PROCEDURES

A licensee shall conduct a risk assessment, which must:

(1) Identify reasonably foreseeable internal or external threats that could result in unauthorized access, transmission, disclosure, misuse, alteration or destruction of nonpublic information, including the security of information systems and nonpublic information that are accessible to, or held by, third-party service providers.

(2) Assess the likelihood and potential damage of threats, taking into consideration the sensitivity of the nonpublic information.

(3) Assess the sufficiency of policies, procedures, information systems and other safeguards in place to manage threats in each relevant area of the licensee's operations, including:

(i) Employee training and management.

(ii) Information systems, including network and software design and information classification, governance, processing, storage, transmission and disposal.

(iii) Detection, prevention and response to attacks, intrusions or other system failures.

(4) Implement information safeguards to manage the threats identified in its ongoing assessment.

(5) At least annually, assess the effectiveness of the safeguards' key controls, systems and procedures.

Collected 2026-09-02T16:33:08Z. Source file · JSON

Browse this collection