Uncategorised

Template for Security Implementation at GIC Re

  • GIC Re Website/Portal/Web Application has been placed in protected zones with the implementation of firewalls, IDS (Intrusion Detection System), and high-availability solutions.
  • Before the launch of the GIC Re Website/Portal/Web Application, simulated penetration tests were conducted. Post-launch, penetration testing is conducted periodically.
  • The GIC Re Website/Portal/Web Application underwent audits for known application-level vulnerabilities before the launch, and all identified vulnerabilities were addressed.
  • Server hardening has been performed per the Cyber Security Division’s guidelines before launching the GIC Re Website/Portal/Web Application.
  • Access to web servers hosting the GIC Re Website/Portal/Web Application is restricted both physically and through the network.
  • Logs are maintained at different locations to record authorized physical access to the GIC Re Website/Portal/Web Application servers.
  • Web servers hosting the GIC Re Website/Portal/Web Application are configured behind IDS, IPS (Intrusion Prevention System), and system firewalls.
  • Development work is performed in a separate development environment and thoroughly tested on a staging server before deployment to the production server.
  • Applications are uploaded to the production server using SSH and VPN through a single point after successful testing on the staging server.
  • Content contributed from remote locations undergoes an authentication process and is not published directly on the production server. Content is moderated before final publication.
  • All web page content is verified for malicious code before final upload to the web server.
  • Audit logs and system activity logs are maintained and archived. Rejected accesses and services are logged and reviewed in exception reports.
  • The Help Desk staff at GIC Re IT Monitoring Team monitors the GIC Re Website/Portal/Web Application at intervals to ensure pages are operational, unauthorized changes are absent, and no unauthorized links are established.
  • System software patches, bug fixes, and upgrades are regularly reviewed and installed on production web servers.
  • Internet browsing, email, and other desktop applications are disabled on production web servers. Only server administration tasks are permitted.
  • Server passwords are changed every month and shared among administrators.
  • <Insert Administrator Name(s)> are designated as administrators for the GIC Re Website/Portal/Web Application and are responsible for implementing this policy and coordinating with the audit team.
  • After major modifications in application development, the GIC Re Website/Portal/Web Application is re-audited for application-level vulnerabilities.

Compliance Audit

The GIC Re Website/Portal/Web Application has been audited before launch and complies with all policies outlined by the Cyber Security Group.

The GIC Re Website/Portal/Web Application has also undergone automated risk assessment through vulnerability identification software both before and after launch, with all identified vulnerabilities addressed.

The GIC Re Website/Portal/Web Application is critical for delivering timely and accurate information to stakeholders. To ensure its reliability, usability, and security, a structured monitoring plan is implemented

The website is constantly monitored on the following parameters

  1. Functionality: All modules of the GIC Re Website/Portal/Web Application are regularly tested to ensure seamless functionality. Any identified issues are resolved promptly to maintain an uninterrupted user experience.
  2. Performance: Key web pages are tested for download time and responsiveness. Efforts are made to optimize performance and provide a fast and efficient user experience.
  3. Broken Links: A meticulous review of the website is conducted to identify and address any broken links or errors. This ensures all links redirect users to the intended destinations without disruption.
  4. Traffic Analysis: Traffic to the website is regularly monitored and analysed. Insights from traffic patterns help improve content delivery and identify areas for enhancement.
  5. Feedback: Feedback from website users is collected and reviewed periodically. Necessary changes and updates are implemented to ensure the website remains user-friendly and aligned with user needs.
  6. Security Monitoring: The hosting service provider for the GIC Re Website/Portal/Web Application has implemented a state-of-the-art, multi-tier security infrastructure. This includes firewalls, intrusion prevention systems, and real-time threat monitoring.

Additional Monitoring and Reporting

  1. A monitoring team within GIC Re IT Management ensures that the website is up and always running.
  2. Logs and reports are generated for critical events and reviewed for any anomalies or security threats.
  3. Scheduled performance checks and updates are conducted to align the website with the latest technological and security standards.
Page last updated on: 25/09/2026
Visitors : 36072063
 

9th rank

Ranked 9thLargest Global Reinsurer Group(Non-IFRS 17 Reporting Reinsurer- compiled by AM Best)