Information Security Policies Q1, Q2(a-d), Q5-6 | pages 1-2
Security policies and accountability
Review protection of information assets, security officer responsibilities, confidentiality requirements, classification and disposal, acceptable use, internet and social media use, email use, employee acknowledgment, and annual policy review. Contract terms are confirmed with the client's legal team.
Evidence we review: Approved policies, assigned owners, acknowledgment records, review dates, and confidentiality agreement records.
Information Security Policies Q3-4; Web Server Security Q9-11 | pages 1 and 3
Identity and access controls
Review unique user credentials, assigned access rights, least-privilege database access, session lifetimes, and application-specific permissions. Implement agreed identity and access changes and document exceptions.
Evidence we review: Account inventories, access matrices, access reviews, database permission reports, and session configuration evidence.
Personnel Hiring Practices Q1(a-c), Q2; Premises Security Q1-3 | page 2
Personnel and premises security
Assess records of employee and nonemployee screening with HR, and equipment-room access, access-event investigation, and visitor verification with facilities. HR and facilities own screening, physical safeguards, and supporting records; implementation by those teams is tracked in the remediation plan.
Evidence we review: Screening procedures and completion records, nonemployee access lists, physical access logs, visitor records, and investigation procedures.
Web Server Security Q1-6, Q8, Q12 | pages 2-3
Web server and application security
Assess web-system policies, web application firewalls, DMZ or equivalent segmentation, encryption in transit, remote administration protocols, testing during development and deployment and after release, insecure credential transmission, and unnecessary services. Scope configuration improvements and validation with the application and infrastructure owners.
Evidence we review: Architecture and firewall configuration, encryption settings, hardening baselines, development and release testing records, and application security reports.
Web Server Security Q7 | page 3
Vulnerability remediation
Establish the actual time taken to fix discovered vulnerabilities, compare it with agreed targets, prioritize remediation, and validate eligible fixes. A planned deadline is distinguished from measured performance.
Evidence we review: Dated findings, remediation tickets, severity-based targets, exception approvals, and retest results.
Information Security Policies Q2(e-f); Mobile Device Security Q1(a-b), Q2 | pages 1 and 3
Mobile devices and sensitive data
Review protection of sensitive data on mobile devices and removable or backup media, visibility into copying to mobile media and sending through email, and smartphone encryption. Scope device management, data protection, and monitoring controls according to platform and licensing.
Evidence we review: Device and encryption reports, removable-media policies, data loss prevention configuration, and representative alert or audit records.
Service Providers Q1(a-e), Q2(a-e) | page 3
Service provider assurance
Inventory third parties providing backup, website hosting, sensitive-data processing, application maintenance, and infrastructure hosting. Review the security evaluation method and available audit reports with the client. Record what was actually evaluated and preserve the form's requested report type rather than claiming a different report is equivalent.
Evidence we review: Vendor inventory, service descriptions, audit reports, review notes, due diligence records, and unresolved vendor risks.
PCI Compliance Q1 and follow-ups; HIPAA Compliance Q1-6 | page 4
PCI and HIPAA readiness
Review PCI assessment records and corrective actions; document client-confirmed HIPAA applicability, PHI volumes, audit history, control reviews, remediation timing, and business associate agreements. Support readiness and evidence collection. A Qualified Security Assessor performs the formal PCI assessment; the client's legal team confirms legal status and indemnification terms.
Evidence we review: Assessor reports, correction records, PHI inventory, audit findings, remediation dates, and client-approved agreement records.
Written Records Management Q1(a-d), Q2(a-c) | page 5
Written records and secure disposal
Review paper collection, shredding after entry, locked files, restricted storage, clean-desk practices, final disposal, and offsite storage providers. Facilities and records owners operate physical controls; the client's legal team confirms provider responsibility and loss-allocation clauses.
Evidence we review: Records inventory, retention and destruction procedures, disposal receipts, provider contracts, and documented reviews of available provider audit reports.
Data Breach Incident Response Q1(a-e), follow-ups (i-vi), Q2(a-e) | pages 5-6
Incident response and breach readiness
Review response to unauthorized system or data access, denial of service and outages, extortion, and data corruption. Assess leadership approval, legal coordination, annual exercises, remediation of exercise findings, client-approved response cost estimates, plan ownership, and update cadence. Document contacts for counsel, notification, public relations, monitoring, and forensics; those specialist services are separately arranged.
Evidence we review: Approved response plan, contact roster, exercise records, improvement tracker, cost assumptions, recovery procedures, and plan review history.
The assessment documents each applicable response as supported, a gap, not applicable with an explanation, or awaiting evidence. The client approves application statements. Prior-knowledge disclosures, material changes, declarations, signatures, and producer details remain with the applicant and agency. Additional carrier requirements may include MFA, EDR, protected backups, and recovery testing even where this supplemental form does not ask for them directly.