02-031 C.M.R. ch. 980, § 4 - Information Security Program
A.
Program
Required. Each regulated insurance entity shall implement a written,
comprehensive information security program that includes administrative,
technical, and physical safeguards for the protection of customer information.
The administrative, technical, and physical safeguards included in the
information security program shall be appropriate to the size and complexity of
the regulated insurance entity and the nature and scope of its
activities.
B.
Deference
to Primary Regulator. If a regulated insurance entity is domiciled in
another jurisdiction or subject to the primary jurisdiction of a different
functional regulator, and the statutes and regulations administered by its
domiciliary regulator or primary functional regulator establish standards for
protecting the security of customer information which are substantially similar
to those established by this Rule, then good faith compliance with those
standards to the satisfaction of the regulated insurance entity's primary
regulator shall constitute compliance with this Rule.
Notes
State regulations are updated quarterly; we currently have two versions available. Below is a comparison between our most recent version and the prior quarterly release. More comparison features will be added as we have more versions to compare.
No prior version found.