Research listings are separate from implemented scans. No quote or assessment is available for this profile yet. Public uploads must contain no patient data or other restricted information.
Documents to review
Information security programResearch document type
Incident response planResearch document type
Third party risk policyResearch document type
Consumer privacy policyResearch document type
Scope questions
Industry alone does not establish legal applicability. Confirm location, activities, role, data and relevant thresholds.
Where does the organization operate, and which regulator, license, permit or contract governs the activity?
Which business activities, data types and organization roles does the document describe?
Do the relevant thresholds or exceptions change which requirements apply?
Unknown answers stay unresolved. Document detection does not answer these questions for you.
A fictional example to explore
This short policy outline demonstrates the document's structure and research questions. It is a navigation example; scans for this profile are not available yet.
PDF pages are counted exactly. DOCX and TXT use the disclosed word-count estimate, so the same policy can have different billable page counts.
Regulations and frameworks to explore
These are research candidates for this profile. Confirm the exact organization and activity before concluding that a rule applies.
Research only
Insurance data security laws based on NAIC Model 668
State-enacted insurance data security laws; NAIC Model Law 668 as research seed
NAIC Model 668 is a model, not binding law by itself. An insurer or other licensee must review each applicable state enactment, licensing scope, exemptions and notification/security-program provisions. Do not apply a single nationwide threshold or deadline from the model; state law and the licensee’s facts control.
Jurisdictions: US-STATES
Research applicability questions
In which states is the organization licensed, and which enacted insurance data-security laws apply?
What licensee type, size/data thresholds and statutory exemptions apply under each state enactment?
Certain financial institutions under FTC jurisdiction must safeguard customer information; activities and regulator routing determine coverage. Banks supervised under other GLBA regulators must be routed to their own rules. An MSP is not automatically a covered financial institution: assess customer-contract duties and any external Qualified Individual role separately from direct institutional duties.
Jurisdictions: US-FEDERAL
Research applicability questions
Does the organization engage in a financial activity covered by the applicable GLBA rule?
Is the organization subject to FTC jurisdiction for the activity being assessed?
Does the organization maintain customer information covered by the rule?
How many consumers’ customer information records do you maintain, and do any section 314.6 exemptions apply?
Voluntary cybersecurity risk-management framework for organizations of any size or sector. Customer contracts may request alignment; it is not a law or a certification. Map the selected profile and desired outcomes; do not score optional framework alignment as a legal violation.
Jurisdictions: GLOBAL
Research applicability questions
Has your organization or a customer selected a NIST CSF profile or outcomes to evaluate?
Does a customer contract, regulator or internal policy require a particular CSF profile or outcome set?
Scope follows a New York DFS license, registration, charter or similar authorization under the Banking, Insurance or Financial Services Laws, with full/limited exemptions to review. An ICT supplier is not automatically a Covered Entity; customer contracts can require third-party controls. Review the current amended regulation and applicable phase-in dates. DFS also published risk-assessment guidance on September 10, 2026.
Jurisdictions: US-NY
Research applicability questions
Which New York DFS licenses, registrations or authorizations does the organization hold?
Does the licensed organization fall within the covered-entity definition for Part 500?
Which specific exemption conditions can the organization substantiate, and which duties remain?
Does the organization meet the Part 500 Class A definition or another applicable entity classification?