Virginia Administrative Code
Title 14 - INSURANCE
Agency 5 - STATE CORPORATION COMMISSION, BUREAU OF INSURANCE
Chapter 430 - INSURANCE DATA SECURITY RISK ASSESSMENT AND REPORTING
Section 14VAC5-430-50 - Information security program security measures
Current through Register Vol. 41, No. 3, September 23, 2024
A. As part of its information security program and based on its risk assessments, each licensee shall implement appropriate security measures as follows:
B. Compliance with the provisions of this section is required of all licensees on or before July 1, 2022.
C. Security measures implemented in accordance with the objectives of the most current revision of NIST SP 800-53, NIST SP 800-171, or other substantially similar standard shall meet the requirements for security measures in subsection A of this section.
D. Effective July 1, 2022, each licensee that utilizes a third-party service provider shall:
DOCUMENTS INCORPORATED BY REFERENCE (14VAC5-430)
National Institute of Standards and Technology, Computer Security Division, Information Technology Laboratory, 100 Bureau Drive (Mail Stop 8930), Gaithersburg, MD 20899-8930, sec-cert@nist.gov
NIST, Special Publication, Guide for Conducting Risk Assessments, 800-30 (rev. 9/2012)
NIST, Special Publication, Managing Information Security Risk Organization, Mission, and Information System View, 800-39 (eff. 3/2011)
NIST, Special Publication, Security and Privacy Controls for Federal Information Systems and Organizations, 800-53 (rev. 9/2021)
NIST, Special Publication, Protecting Controlled Unclassified Information, 800-171 (rev. 2/2020)
Statutory Authority: §§ 12.1-13 and 38.2-223 of the Code of Virginia.