15 questions in this section
attestedWho is the most senior role with responsibility for information security (CISO/CSO/CIO)?
attestedIs the Applicant's network security managed in-house or outsourced?
attestedIs the InfoSec policy aligned with NIST CSF, ISO 27001, or other framework?
attestedDoes the Applicant employ mandatory annual InfoSec/privacy training for employees and contractors?
attestedAre wire transfers over $25K dual-control authorized? Is callback verification required for new vendor / banking change?
attestedAre job applicants screened (credit, criminal records, drug testing) as permitted by law?
attestedDoes the Applicant participate in information sharing programs (ISAC, CISA, peer)?
partialDoes the Applicant terminate computer access promptly when employee/contractor leaves?
attestedDoes the Applicant have a privacy review process (attorney) for published content / media?
attestedWhat is the Applicant's industry classification (NAICS / industry select)?
partialWhat are the Applicant's websites / domains (main website, corporate email domains, subsidiary/franchise sites)?
attestedDoes the Applicant attest that all statements in the application are true, complete, and accurate and form the basis of the policy (misrepresentation voids coverage)?
attestedHow many IT personnel are on the Applicant's team?
attestedHow many dedicated IT security personnel are on the Applicant's team?
attestedDoes the Applicant use, disseminate or display material or content of others?
Stop answering this from memory
Connect Microsoft 365, Entra ID, and Azure read-only. Insurance Posture reads the live configuration behind each application answer and shows you which ones you can prove before you sign.
Assess your posture