{"data":{"id":"us-ok/okla.-stat.-tit.-36-36-673","jurisdiction":"us-ok","citation":"Okla. Stat. tit. 36, § 36-673","heading":"Information security program","body":"A. Each licensee in this state shall develop, implement, and\n\nmaintain a comprehensive written information security program based\n\non the risk assessment of the licensee provided for in this act and\n\nthat contains administrative, technical, and physical safeguards for\n\nthe protection of nonpublic information and the information systems\n\nof the licensee. The program shall be commensurate with the size\n\nand complexity of the licensee, the nature and scope of the\n\nactivities of the licensee, including its use of third-party service\n\nproviders, and the sensitivity of the nonpublic information used by\n\nthe licensee or in the possession, custody, or control of the\n\nlicensee.\n\nB. An information security program of a licensee shall be\n\ndesigned to:\n\n1. Protect the security and confidentiality of nonpublic\n\ninformation and the security of the information systems;\n\n2. Protect against any threats or hazards to the security or\n\nintegrity of nonpublic information and the information systems;\n\n3. Protect against unauthorized access to or use of nonpublic\n\ninformation, and minimize the likelihood of harm to any consumer;\n\nand\n\n4. Define and periodically reevaluate a schedule for retention\n\nof nonpublic information and a mechanism for its destruction when no\n\nlonger needed.\n\nC. The licensee shall:\n\n1. Designate one or more employees, an affiliate, or an outside\n\nvendor designated to act on behalf of the licensee who is\n\nresponsible for the information security program;\n\n2. Identify reasonably foreseeable internal or external threats\n\nthat could result in unauthorized access, transmission, disclosure,\n\nmisuse, alteration, or destruction of nonpublic information\n\nincluding, but not limited to, the security of information systems\n\nand nonpublic information that are accessible to, or held by, third-\n\nparty service providers;\n\n3. Assess the likelihood and potential damage of these threats,\n\ntaking into consideration the sensitivity of the nonpublic\n\ninformation;\n\n4. Assess the sufficiency of policies, procedures, information\n\nsystems, and other safeguards in place to manage these threats,\n\nincluding consideration of threats in each relevant area of the\n\noperations of the licensee, including:\n\na. employee training and management,\n\nb. information systems, including, but not limited to,\n\nnetwork and software design, as well as information\n\nclassification, governance, processing, storage,\n\ntransmission, and disposal, and\n\nc. detecting, preventing, and responding to attacks,\n\nintrusions, or other systems failures; and\n\n5. Implement information safeguards to manage the threats\n\nidentified in its ongoing assessment, and no less than annually,\n\nassess the effectiveness of the key controls, systems, and\n\nprocedures of the safeguards.\n\nD. Based on the results of the risk assessment, the licensee\n\nshall:\n\n1. Design its information security program to mitigate the\n\nidentified risks, commensurate with the size and complexity of the\n\nlicensee, the nature and scope of the activities of the licensee\n\nincluding its use of third-party service providers, and the\n\nsensitivity of the nonpublic information used by the licensee or in\n\nthe possession, custody, or control of the licensee;\n\n2. Determine and implement security measures deemed\n\nappropriate, including:\n\na. place access controls on information systems including\n\ncontrols to authenticate and permit access only to\n\nauthorized individuals to protect against the\n\nunauthorized acquisition of nonpublic information,\n\nb. identify and manage the data, personnel, devices,\n\nsystems, and facilities that enable the organization\n\nto achieve business purposes in accordance with their\n\nrelative importance to business objectives and the\n\nrisk strategy of the organization,\n\nc. restrict physical access to nonpublic information to\n\nauthorized individuals only,\n\nd. protect by encryption or other appropriate means, all\n\nnonpublic information while being transmitted over an\nes,\n\nsystems, and facilities that enable the organization\n\nto achieve business purposes in accordance with their\n\nrelative importance to business objectives and the\n\nrisk strategy of the organization,\n\nc. restrict physical access to nonpublic information to\n\nauthorized individuals only,\n\nd. protect by encryption or other appropriate means, all\n\nnonpublic information while being transmitted over an\n\nexternal network and all nonpublic information stored\n\non a laptop computer or other portable computing or\n\nstorage device or media,\n\ne. adopt secure development practices for in-house\n\ndeveloped applications utilized by the licensee,\n\nf. modify the information system in accordance with the\n\ninformation security program of the licensee,\n\ng. utilize effective controls, which may include multi-\n\nfactor authentication procedures for any authorized\n\nindividual accessing nonpublic information,\n\nh. regularly test and monitor systems and procedures to\n\ndetect actual and attempted attacks on, or intrusions\n\ninto, information systems,\n\ni. include audit trails within the information security\n\nprogram designed to detect and respond to\n\ncybersecurity events and designed to reconstruct\n\nmaterial financial transactions sufficient to support\n\nnormal operations and obligations of the licensee,\n\nj. implement measures to protect against destruction,\n\nloss, or damage of nonpublic information due to\n\nenvironmental hazards such as fire and water damage or\n\nother catastrophic events or technological failures,\n\nand\n\nk. develop, implement, and maintain procedures for the\n\nsecure disposal of nonpublic information in any\n\nformat;\n\n3. Include cybersecurity risks in the enterprise risk\n\nmanagement process of the licensee;\n\n4. Stay informed regarding emerging threats or vulnerabilities\n\nand utilize reasonable security measures when sharing information\n\nrelative to the character of the sharing and the type of information\n\nshared; and\n\n5. Provide its personnel with cybersecurity awareness training\n\nthat is updated as necessary to reflect risks identified by the\n\nlicensee in the risk assessment.\n\nE. If the licensee has a board of directors, the board or an\n\nappropriate committee of the board, at a minimum, within one (1)\n\nyear of July 1, 2024, shall:\n\n1. Require the executive management of the licensee or its\n\ndelegates to develop, implement, and maintain the information\n\nsecurity program of the licensee;\n\n2. Require the executive management of the licensee or its\n\ndelegates to report to the board in writing, at least annually, the\n\nfollowing information:\n\na. the overall status of the information security program\n\nand the compliance of the licensee with this act, and\n\nb. material matters related to the information security\n\nprogram, addressing issues such as risk assessment,\n\nrisk management and control decisions, third-party\n\nservice provider arrangements, results of testing,\n\ncybersecurity events or violations and responses of\n\nthe management to those events or violations, and\n\nrecommendations for changes in the information\n\nsecurity program; and\n\n3. If executive management delegates any of its\n\nresponsibilities, it shall oversee the development, implementation,\n\nand maintenance of the information security program of the licensee\n\nprepared by the delegate or delegates and shall receive a report\n\nfrom the delegate or delegates complying with the requirements of\n\nthe report to the board.\n\nF. A licensee shall exercise due diligence in selecting its\n\nthird-party service provider and shall require the provider to\n\nimplement appropriate administrative, technical, and physical\n\nmeasures to protect and secure the information systems and nonpublic\n\ninformation that are accessible to, or held by, the third-party\n\nservice provider.\n\nG. The licensee shall monitor, evaluate, and adjust, as\n\nappropriate, the information security program consistent with any\nrd-party service provider and shall require the provider to\n\nimplement appropriate administrative, technical, and physical\n\nmeasures to protect and secure the information systems and nonpublic\n\ninformation that are accessible to, or held by, the third-party\n\nservice provider.\n\nG. The licensee shall monitor, evaluate, and adjust, as\n\nappropriate, the information security program consistent with any\n\nrelevant changes in technology, the sensitivity of its nonpublic\n\ninformation, internal or external threats to information and the\n\nchanging business arrangements of the licensee, such as mergers and\n\nacquisitions, alliances and joint ventures, outsourcing\n\narrangements, and changes to information systems.\n\nH. As part of its information security program, each licensee\n\nshall establish a written incident response plan designed to\n\npromptly respond to, and recover from, any cybersecurity event that\n\ncompromises the confidentiality, integrity, or availability of\n\nnonpublic information in its possession, the information systems of\n\nthe licensee, or the continuing functionality of any aspect of the\n\nbusiness or operations of the licensee.\n\nThe incident response plan shall address the following areas:\n\n1. The internal process for responding to a cybersecurity\n\nevent;\n\n2. The goals of the incident response plan;\n\n3. The definition of clear roles, responsibilities, and levels\n\nof decision-making authority;\n\n4. External and internal communications and information\n\nsharing;\n\n5. Identification of requirements for the remediation of any\n\nidentified weaknesses in information systems and associated\n\ncontrols;\n\n6. Documentation and reporting regarding cybersecurity events\n\nand related incident response activities; and\n\n7. The evaluation and revision as necessary of the incident\n\nresponse plan following a cybersecurity event.\n\nI. Annually, each insurer domiciled in this state shall submit\n\nto the Insurance Commissioner a written statement by April 15,\n\ncertifying that the insurer complies with the requirements set forth\n\nin this section. Each insurer shall maintain, for examination by\n\nthe Insurance Department, all records, schedules, and data\n\nsupporting this certificate for a period of five (5) years. To the\n\nextent an insurer has identified areas, systems, or processes that\n\nrequire material improvement, updating, or redesign, the insurer\n\nshall document the identification and the remedial efforts planned\n\nand underway to address such areas, systems, or processes. The\n\ndocumentation shall be available for inspection by the Commissioner\n\nupon request.","path":["OK Code","Title 36"],"source_url":"https://www.oklegislature.gov/OK_Statutes/CompleteTitles/os36.pdf","current_through":"2026-08-14","vintage":"open-us-law v2026.08, retrieved 2026-09-14","retrieved_at":"2026-09-14T18:32:36Z","sha256":"5fc220bb817cc01fd3e91246869cb2e4bd1838f623a93b11c06d119d5340d2f8","source_id":"us-ok","stale":false,"prev":"us-ok/okla.-stat.-tit.-36-36-672","next":"us-ok/okla.-stat.-tit.-36-36-674"},"notice":"GroundRules: Original legal text. Not legal advice."}
