Law / United States /
New York
New York Department of Financial Services Cybersecurity Regulation, Encryption of Nonpublic Information
In force.
A sector security regimes rule binding private bodies.
- Enforcement body
- The Superintendent of Financial Services.
- Instrument type
- a regulation made under an act
- Obligation class
- Security
As of .
What it requires
- It reaches you if you operate as a Covered Entity under 23 NYCRR 500.1(e): any person operating under, or required to operate under, a license, registration, charter, certificate, permit, accreditation or similar authorization under the Banking Law, the Insurance Law or the Financial Services Law, regardless of whether you are also regulated by other government agencies (reached by declaring that you provide financial services). The limited exemption in section 500.19(a) lifts this duty for a covered entity with fewer than 20 employees and independent contractors of the covered entity and its affiliates, less than $7,500,000 in gross annual revenue in each of the last three fiscal years, or less than $15,000,000 in year-end total assets, each counted as section 500.19(a) provides. Section 500.19(c) lifts section 500.15 for a covered entity that operates no information systems and holds no nonpublic information, and section 500.19(d) lifts section 500.15 for an article 70 insurer under the Insurance Law that holds no nonpublic information beyond information relating to its corporate parent or affiliates.
- Implement a written policy requiring encryption that meets industry standards, to protect the nonpublic information you hold or transmit both in transit over external networks and at rest.
- If you determine that encrypting nonpublic information at rest is infeasible, secure it instead with effective alternative compensating controls that your Chief Information Security Officer has reviewed and approved in writing, and have that officer review the feasibility of encryption and the effectiveness of the compensating controls at least annually.
What this law does
Section 500.15 requires a covered entity, as part of its cybersecurity program, to implement a written policy requiring encryption that meets industry standards, to protect nonpublic information held or transmitted by the covered entity both in transit over external networks and at rest.
To the extent a covered entity determines that encryption of nonpublic information at rest is infeasible, it may instead secure that information using effective alternative compensating controls that its Chief Information Security Officer has reviewed and approved in writing. The Chief Information Security Officer must review the feasibility of encryption and the effectiveness of the compensating controls at least annually.
A covered entity with fewer than 20 employees and independent contractors of the covered entity and its affiliates, less than $7,500,000 in gross annual revenue in each of the last three fiscal years, or less than $15,000,000 in year-end total assets, each counted as section 500.19(a) provides, is exempt from section 500.15 under that section.
Section 500.19(c) and (d) name section 500.15 among the sections they lift, (c) for a covered entity that operates no information systems and holds no nonpublic information and (d) for an article 70 insurer that holds no nonpublic information beyond information relating to its corporate parent or affiliates. Part 500 took effect on , and its Second Amendment on .
Section 500.22(d)(2) gives covered entities one year from the effective date of the Second Amendment to comply with its new requirements in section 500.15.
When LexLint raises it
When your app profile says your app provides financial services.