yourstate.us
Ind. Code § 27-2-27-20

Incident response plan

Indiana · Indiana Code Title 27 — Insurance · Status: effective

Get this as JSONEmbed this
Cite this
Citation
Ind. Code § 27-2-27-20, Incident response plan, Indiana, version 1 as recorded 2026-09-28, yourstate.us, https://yourstate.us/provision/1663077
Permanent ID
ys:prov:1663077@1
SHA-256
ed263801f2f2a0973cdc02cfef1e39789fe43e80287f704e8b0dbeb91c9bde33

The hash is SHA-256 of this version's text, with every run of whitespace collapsed to a single space and the ends trimmed. The ID always leads back here, and checking it says whether the text you cited is still the current version.

Full text

Sec. 20. (a) As part of its information security program, a licensee shall establish a written incident response plan designed to promptly respond to, and recover from, any cybersecurity event. (b) An incident response plan must include the following: (1) The internal process for responding to a cybersecurity event. (2) The goals of the incident response plan. (3) The definition of clear roles, responsibilities, and levels of decision making authority. (4) External and internal communications and information sharing. (5) Identification of requirements for the remediation of any identified weaknesses in information systems and associated controls. (6) Documentation and reporting regarding cybersecurity events and related incident response activities. (7) The evaluation and revision, as necessary, of the incident response plan. (c) Annually, not later than April 15, each insurer domiciled in Indiana shall submit to the commissioner a written statement certifying that the insurer is in compliance with the requirements set forth in sections 16 through 19 of this chapter and this section. Each insurer shall maintain for examination by the department all records, schedules, and data supporting this certificate for a period of five (5) years. To the extent an insurer has identified areas, systems, or processes that require material improvement, updating, or redesign, the insurer shall document the identification of the areas, systems, or processes and the remedial efforts planned and underway to address the areas, systems, or processes. The documentation must be available for inspection by the commissioner.