ISNP Security Audit

ISNP stands for Insurance Self Network Platform, meant to be an electronic platform set up by any applicant with the permission of the authority.

The Insurance Regulatory and Development Authority of India (IRDA) had issued guidelines for insurance e-commerce to standardize rules for conducting insurance e-commerce activities. As per the new guidelines, any Insurance Agency that is looking to setup an Electronic Platform, they must comply with the following requirements as defined by the guidelines IRDA/ INT/ GDU ECM/ 055/03/2017

The guidelines were put forth to standardize the ecommerce rules of the online insurance business. As per the regulations, anyone willing to sell insurance online is required to set-up an ISNP and follow all the regulations specified for it by IRDA with a view to conducting insurance e-commerce activity. ISNP can be set up in any of the following forms:

  • Website (desktop or mobile version)

  • Mobile application

  • Both

Insurance Companies, Aggregators and intermediaries must be in compliance with Insurance Self Service Network Platform ISNP guidelines as per IRDA of India. The key objectives of having an ISPN audit is as follows:

  • Implementation of Internal Monitoring Controls for Data Processing Systems

  • Board approved annual security review of the controls, systems, procedures and safeguards by CISA or DISA auditor or CERT-IN

  • Compliance to ISO/IEC 27001 – Information Security Management System

  • Reporting of any adverse findings that impact policyholders with the IRDA

As a CERT-IN empanelled body, QRC will help you understand, manage and comply with IRDA’s Cyber Security requirements as published in the IRDA’s Guidelines on Insurance E-Commerce on a periodic basis.

Audit Approach

ISNP Security Audit

Business Understanding

Evaluating business process and environment to understand the in-scope elements

ISNP Security Audit

Audit Scope Finalization

Detailed questionnaire is shared with your teams to aid in the scope definition, planning and preparation of the audit and objectives

ISNP Security Audit

Initial/Readiness Assessment

As per the IRDA guidelines, we will conduct an initial audit measuring the IT related risks to enhance the reliability of processes, critical system platforms, networks and physical components.

ISNP Security Audit

Risk Assessment

Identifying and analysing the risks in the information security posture.

ISNP Security Audit

Data Flow Assessment

Conducting thorough systems analysis to evaluate data flow and possible leakages

ISNP Security Audit

Remediation Support

As per the assessment QRC will provide remediation support for complying with the IRDA cybersecurity guidelines for each domain.

ISNP Security Audit

Scans And Testing

Identify critical vulnerabilities in your system with a robust testing approach

ISNP Security Audit

Evidence Review

Review of the evidence collected to assess their maturity, in line with the compliance

ISNP Security Audit

Final Audit

Post remediation, we conduct a final audit and review your evidence as identified during the audit. On successful closure, we will share the confirmation letter that all assets defined as per the scope meet the prescribed guidelines.

ISNP Security Audit

Concise Reporting

Our team documents a comprehensive report detailing all findings covered during the assessment cycle.

Related Updates




LinkedIn Facebook Twitter Youtube

We use cookies to enhance your user experience. By continuing to browse, you hereby agree to the use of cookies. Know more Privacy Policy & Cookies Policy.

X