Close Window
Table of Contents
The Anderson Report on
Client Data Security
Section 1: Why be Concerned?
Section 2: What's the Problem? Examples of Data Breaches
- Employee Malpractices
- Employee Negligence
- Theft of Equipment
- External Attacks
- Not Just in the U.S.
- Not Always Customer Data!
- Conclusion
Section 3: What Data Needs Protection?
- Confidentiality Criteria
- Integrity Criteria
- Availability Criteria
- Data Classification Groups
Section 4: Steps to Protect Client Data
- Scale Down—Keep Only What You Need
- Lock it—Protect the Information
- Risk Assessment
- Policies and Procedures
- Access Control
- Network Security
- Encryption
- Change Control
- Backup and Recovery
- Anti-Virus
- Physical Security
- Personnel Security
- Pitch—Proper Disposal
- Disposing of Shredded Paper
- Plan Ahead—Create a Plan to Respond to a Security Incident
- Reporting Incidents
- Types of Incidents
- Classification of Incidents
- Incident Analysis
- Gathering Evidence
- Corrective Action and Follow-Up
- Trend Analysis
Section 5: Responsibility of Third-Party Providers
- Background Checks
- Confidentiality or Non-Disclosure Agreements (NDA)
- Security Training
- Anti-Virus
- Encryption
- Secure Network Access
Section 6: Insurance and Risk Transfer Techniques
- Client Data Breach Insurance Coverage
- Covered Causes of Loss
- Employee Breaches
- Media Type
- Digitization Requirement
- Regulatory Investigations
- Professional Services
- Identify Theft a Necessary Trigger?
- General Liability Policy
- Current Insurance Coverage Providers
- Coverage Questions and Comparison
- Contractual Risk Transfer
Section 7: Security Breach Laws
- Gramm-Leach-Bliley (GLB) Act
- Sarbanes-Oxley (SOx) Act
- Health Insurance Portability and Accountability (HIPAA) Act
- HITECH Act of 2009
- State Security Breach Notification Laws
- Summary of the State Laws' Provisions
Section 8: Resources
- Glossary of Security Terms
- ACT Webinar: Protecting Independent Agent Clients with Secure E-mail Using TLS
- The Business Case for Improved Password Workflows within the Real-Time Environment
- Protect your Clients with Secure E-mail using TLS
- ACT TLS—Frequently Asked Questions
- Insurance Carriers Enabled for TLS Email Encryption for their Agencies
- Insurance Coverage Information
Close Window