Law / United States /
New York
New York Department of Financial Services Cybersecurity Regulation, Third-Party Service Provider Security Policy
In force.
A sector security regimes rule binding private bodies.
- Enforcement body
- The Superintendent of Financial Services.
- Instrument type
- a regulation made under an act
- Obligation class
- Security, Governance
As of .
What it requires
- It reaches you if you operate as a Covered Entity under 23 NYCRR 500.1(e): any person operating under, or required to operate under, a license, registration, charter, certificate, permit, accreditation or similar authorization under the Banking Law, the Insurance Law or the Financial Services Law, regardless of whether you are also regulated by other government agencies (reached by declaring that you provide financial services). The limited exemption in section 500.19(a) and the exemptions in section 500.19(c) and (d) do not lift this duty; only the exemptions in section 500.19(b), (e) and (g), which exempt their named classes from the whole Part, do.
- Implement written policies and procedures, based on your risk assessment, designed to ensure the security of information systems and nonpublic information that are accessible to, or held by, third-party service providers (persons who are not your affiliates or governmental entities, provide services to you, and maintain, process or are permitted access to your nonpublic information through those services).
- Address in those policies, to the extent applicable: the identification and risk assessment of third-party service providers; the minimum cybersecurity practices they must meet to do business with you; the due diligence you use to evaluate the adequacy of their cybersecurity practices; and periodic assessment of them based on the risk they present and the continued adequacy of their practices.
- Include in those policies relevant guidelines for due diligence or contractual protections, addressing to the extent applicable each provider's access controls (including its use of multi-factor authentication), its use of encryption to protect nonpublic information in transit and at rest, notice to you of a cybersecurity event directly impacting your information systems or your nonpublic information the provider holds, and representations and warranties about its cybersecurity policies and procedures.
What this law does
Section 500.11 requires a covered entity to implement written policies and procedures designed to ensure the security of information systems and nonpublic information that are accessible to, or held by, third-party service providers.
The policies must be based on the covered entity's risk assessment and address, to the extent applicable, the identification and risk assessment of third-party service providers, the minimum cybersecurity practices they must meet to do business with the covered entity, due diligence on the adequacy of their practices, and periodic assessment of them.
The policies must include relevant guidelines for due diligence or contractual protections relating to third-party service providers, including to the extent applicable guidelines addressing the provider's access controls and use of multi-factor authentication and its use of encryption of nonpublic information in transit and at rest.
Those guidelines must also address, to the extent applicable, notice to the covered entity of a cybersecurity event directly impacting its information systems or its nonpublic information held by the provider, and representations and warranties on the provider's cybersecurity policies and procedures.
A third-party service provider is a person that is not an affiliate of the covered entity, is not a governmental entity, provides services to the covered entity, and maintains, processes or otherwise is permitted access to nonpublic information through its provision of services to the covered entity. The duty is the covered entity's own: the policies and the due diligence or contractual protections it must put in place are how Part 500 reaches a third-party service provider.
The limited exemption in section 500.19(a) for smaller covered entities does not name section 500.11, so a covered entity holding it still owes this duty. Section 500.19(c) and (d) each list the sections they lift, and neither list includes section 500.11. Section 500.19(b), (e) and (g) instead exempt their named classes from the requirements of the whole Part, which carries section 500.11 with it. Part 500 took effect on , and its Second Amendment on .
Section 500.22(c) gives covered entities 180 days from the Second Amendment's effective date to comply with its new requirements, except where subdivision (d) or (e) sets another period or day, and section 500.11 is not named in those subdivisions.
When LexLint raises it
When your app profile says your app provides financial services.