Lloyd's Minimum Standards — Cyber and IT Security
Mandatory minimum standards for all managing agents operating in the Lloyd's market. Covers IT governance and strategy, information security policy, risk assessment, access control, application security, change management, business continuity and disaster recovery, network security, data protection and classification, incident management, third-party and outsourcing risk, and security monitoring. Compliance assessed through Lloyd's annual oversight process.
| Clause | Title | SP 800-53 Controls |
|---|---|---|
| BP2.1 | Blueprint Two — Digital Platform Requirements | |
| BP2.2 | Blueprint Two — Data Standards and Crystal Messaging | |
| CRM.1 | Lloyd's Cyber Risk Management — Cyber Governance | |
| CRM.2 | Lloyd's Cyber Risk Management — Threat Assessment and Intelligence | |
| CRM.3 | Lloyd's Cyber Risk Management — Incident Response and Recovery | |
| GOV.1 | Board Oversight and Senior Management Accountability | |
| MS1.1 | Underwriting Systems and Data Quality | |
| MS2.1 | Claims Systems and Fraud Detection | |
| MS5.1 | Financial Systems and Reporting Integrity | |
| MS6.1 | Reinsurance Systems and Data Exchange | |
| MS7.1 | Regulatory Compliance and Data Protection | |
| MS8.1 | IT Governance and Strategy | |
| MS8.2 | Information Security Policy and Standards | |
| MS8.3 | Access Management and Identity Controls | |
| MS8.4 | Change Management | |
| MS8.5 | Incident Management and Cyber Response | |
| MS8.6 | Business Continuity and Disaster Recovery | |
| MS8.7 | Data Management and Quality | |
| MS8.8 | Third Party and Outsourcing Management | |
| MS8.9 | Cyber Security — Network and Perimeter Defence | |
| MS8.10 | Cyber Security — Endpoint and Malware Protection | |
| MS8.11 | Cyber Security — Vulnerability Management and Patching | |
| MS8.12 | Cyber Security — Security Monitoring and Logging | |
| MS8.13 | Cyber Security — Awareness and Training | |
| MS9.1 | Operational Resilience — Important Business Services | |
| MS9.2 | Operational Resilience — Scenario Testing and Exercising | |
| MS9.3 | Operational Resilience — Third Party Dependencies and Concentration Risk | |
| MS10.1 | Enterprise Risk Management Framework | |
| MS10.2 | Operational Risk Management — IT Risk | |
| MS13.1 | Delegated Authority — MGA Oversight and System Integration | |
| MS13.2 | Delegated Authority — Data Flows and Reporting | |
| PHYS.1 | Physical Security and Environmental Controls |