6 questions in this section
attestedDoes the Applicant review and audit information security/privacy controls of IT, cloud, and non-IT service providers?
verifiedIs service provider access to network/data restricted on least-privilege basis, reviewed periodically?
attestedDo written agreements with third parties contain defense/indemnification + insurance requirements?
attestedDoes the Applicant fully outsource payment card processing?
attestedHas any service provider with access to Applicant's network sustained outage longer than 4 hours?
partialDoes the Applicant use a cloud provider, and which provider stores the largest quantity of sensitive records?
Stop answering this from memory
Connect Microsoft 365, Entra ID, and Azure read-only. Insurance Posture reads the live configuration behind each application answer and shows you which ones you can prove before you sign.
Assess your posture