Framework overlap

Does NIST Cybersecurity Framework 2.0 cover IAIS Insurance Core Principles (ICPs)?

You hold NIST Cybersecurity Framework 2.0 and have been told to do IAIS Insurance Core Principles (ICPs). Here is how much overlaps, control by control.

17% of IAIS Insurance Core Principles (ICPs) you already have

NIST Cybersecurity Framework 2.0 already covers about 17% of IAIS Insurance Core Principles (ICPs), leaving 39 of 47 controls as genuinely new work.

Already covered 4 Likely covered 4 New work 39

What is genuinely new work

Nothing in NIST Cybersecurity Framework 2.0 reaches these. This is the list to scope.

ICP-10
Preventive Measures, Corrective Measures and Sanctions
ICP-12
Exit from the Market and Resolution
ICP-14
Valuation
ICP-17
Capital Adequacy
ICP-18
Intermediaries
ICP-19
Conduct of Business
ICP-2
Supervisor
ICP-21
Countering Fraud in Insurance
ICP-22
Anti-Money Laundering and Combating the Financing of Terrorism
ICP-23
Group-wide Supervision
ICP-3
Information Sharing and Confidentiality Requirements
ICP-4
Licensing
ICP-5
Suitability of Persons
ICP-6
Changes in Control and Portfolio Transfers
ICP-7
Corporate Governance
ICP-9
Supervisory Review and Reporting
ICP1
Objectives, Powers and Responsibilities of the Supervisor
ICP10
Preventive Measures, Corrective Measures and Sanctions
ICP12
Exit from the Market and Resolution
ICP13
Reinsurance and Other Forms of Risk Transfer
ICP14
Valuation
ICP15
Investments
ICP16
Enterprise Risk Management and ORSA
ICP17
Capital Adequacy
ICP18
Intermediaries
ICP19
Conduct of Business
ICP2
Supervisor Independence and Resources
ICP20
Public Disclosure
ICP21
Countering Fraud in Insurance
ICP22
Anti Money Laundering and Combating the Financing of Terrorism
ICP23
Group Wide Supervision
ICP24
Macroprudential Supervision
ICP3
Information Exchange and Confidentiality
ICP4
Licensing
ICP5
Suitability of Persons
ICP6
Changes in Control and Portfolio Transfers
ICP7
Corporate Governance
ICP8
Risk Management and Internal Controls
ICP9
Supervisory Review and Reporting
Show the 8 you already have
ICP-1
Objectives, Powers and Responsibilities of the Supervisor
ICP-16
Enterprise Risk Management for Solvency Purposes
ICP-24
Macroprudential Surveillance and Insurance Supervision
ICP-8
Risk Management and Internal Controls
ICP-13
Reinsurance and Other Forms of Risk Transfer
ICP-15
Investment
ICP-20
Public Disclosure
ICP-25
Supervisory Cooperation and Coordination

How this is calculated

Already covered means a mapping runs from a control in NIST Cybersecurity Framework 2.0 to that control. Likely covered means no direct mapping exists but both frameworks map to the same control in a third standard. New work means neither. We keep those separate rather than adding them into one friendlier number, because blending them would present a two-hop inference as a verified fact.

Coverage is not symmetric. Run it the other way and you will get a different number; both are correct.

From 332,959 cross-framework control mappings across 723 frameworks, 531 of them verified against their source documents. It does not tell you that you are compliant: a mapped control means the two standards ask for the same thing, not that you have done it.

Try another pair ยท Today's edition