2024-05-09
Added · Updated
This Notice applies to licensed insurers and certain insurance agents, requiring them to secure administrative accounts, apply security patches commensurate with risk, and maintain written security standards for all systems. Affected entities must implement network perimeter controls, deploy malware protection where available, and enforce multi-factor authentication for administrative accounts on critical systems and any internet-accessed customer information systems. The requirements take effect on 10 May 2024, with exemptions allowed only if the entity cannot exercise direct or indirect control over a system and cannot reasonably procure an alternative provider.
More like this from MAS
We email you every new MAS publication the day it's published.