Law / United States /
New York
New York Department of Financial Services Cybersecurity Regulation, Monitoring of Authorized Users and Cybersecurity Awareness Training
In force.
A sector security regimes rule binding private bodies.
- Enforcement body
- The Superintendent of Financial Services.
- Instrument type
- a regulation made under an act
- Obligation class
- Security, Governance
As of .
What it requires
- It reaches you if you operate as a Covered Entity under 23 NYCRR 500.1(e): any person operating under, or required to operate under, a license, registration, charter, certificate, permit, accreditation or similar authorization under the Banking Law, the Insurance Law or the Financial Services Law, regardless of whether you are also regulated by other government agencies (reached by declaring that you provide financial services). The limited exemption in section 500.19(a) lifts the monitoring duty in the second line below, for a covered entity with fewer than 20 employees and independent contractors of the covered entity and its affiliates, less than $7,500,000 in gross annual revenue in each of the last three fiscal years, or less than $15,000,000 in year-end total assets, each counted as section 500.19(a) provides, but does not lift the training duty in the third line. Section 500.19(c) lifts section 500.14 for a covered entity that operates no information systems and holds no nonpublic information, and section 500.19(d) lifts section 500.14 for an article 70 insurer under the Insurance Law that holds no nonpublic information beyond information relating to its corporate parent or affiliates.
- Implement risk-based policies, procedures and controls designed to monitor the activity of authorized users (any employee, contractor, agent or other person that participates in your business operations and is authorized to access and use your information systems and data) and to detect unauthorized access or use of, or tampering with, nonpublic information by those authorized users.
- Provide cybersecurity awareness training that includes social engineering to all personnel periodically and at least annually, updated to reflect the risks you identified in your risk assessment.
What this law does
Section 500.14(a)(1) requires a covered entity, as part of its cybersecurity program, to implement risk-based policies, procedures and controls designed to monitor the activity of authorized users and detect unauthorized access or use of, or tampering with, nonpublic information by those authorized users.
An authorized user is any employee, contractor, agent or other person that participates in the business operations of the covered entity and is authorized to access and use any information systems and data of the covered entity. Section 500.14(a)(3) requires periodic, and at a minimum annual, cybersecurity awareness training that includes social engineering for all personnel, updated to reflect risks the covered entity has identified in its risk assessment.
The Department's industry letter of states that the regulation has always required cybersecurity training for all personnel and that covered entities must now provide at least annual cybersecurity awareness training that includes social engineering.
A covered entity with fewer than 20 employees and independent contractors of the covered entity and its affiliates, less than $7,500,000 in gross annual revenue in each of the last three fiscal years, or less than $15,000,000 in year-end total assets, each counted as section 500.19(a) provides, is exempt from section 500.14(a)(1) under that section. The limited exemption in section 500.19(a) does not name section 500.14(a)(3), so a covered entity holding it still owes the training duty.
Section 500.19(c) and (d) name section 500.14 among the sections they lift, (c) for a covered entity that operates no information systems and holds no nonpublic information and (d) for an article 70 insurer that holds no nonpublic information beyond information relating to its corporate parent or affiliates. Part 500 took effect on , and its Second Amendment on .
Section 500.22(c) gives covered entities 180 days from the Second Amendment's effective date to comply with its new requirements, except where subdivision (d) or (e) sets another period or day, and subdivision (d) names section 500.14(a)(2) and (b) but not section 500.14(a)(1) or (a)(3).
When LexLint raises it
When your app profile says your app provides financial services.