VaulithNine questions, free
The canon · Security · SEC-2.1

Describe access controls, including multi-factor authentication, applied to systems holding insurer nonpublic information.

This is one of the twenty-five questions a carrier reviewer sends a vendor, in the words an examiner uses. Below it: the answers that make a reviewer stop on this item, derived by running Vaulith's rules engine on an estate that gets everything wrong, and the free questions that reach it.

What stops a reviewer here

One finding reaches this item.

Will escalateR-MFA · blocks this item

Multi-factor authentication is not stated for access to insurer data

You have not said whether multi-factor authentication is enforced for everyone who can reach insurer data. Section 500.12 requires the carrier to have it for any access to nonpublic information, and the carrier cannot answer that question for its own examiner while a vendor holding the same data cannot. A reviewer treats silence here as a no, because every vendor that has it says so in the first sentence.

To fix: Enforce a second factor for every account, including administrators, service accounts that a person can use, and any third party with access. Then say so, with the mechanism named, in the security section of the profile.

How it is scored

Credit per verdict, times the weight.

A standard item carries weight 2. A pass earns 1.00 of it, a questioned answer 0.60, an escalated one 0.20 and a stop 0.00. An unanswered item earns nothing and still takes the citation penalty, so a profile cannot be improved by leaving an inconvenient question blank. The whole arithmetic is shown on the homepage and in every assessment.