Law / United States /
New York
New York Department of Financial Services Cybersecurity Regulation, Cybersecurity Program and Cybersecurity Policy
In force.
A sector security regimes rule binding private bodies.
- Enforcement body
- The Superintendent of Financial Services.
- Instrument type
- a regulation made under an act
- Obligation class
- Security, Governance
As of .
What it requires
- It reaches you if you operate as a Covered Entity under 23 NYCRR 500.1(e): any person operating under, or required to operate under, a license, registration, charter, certificate, permit, accreditation or similar authorization under the Banking Law, the Insurance Law or the Financial Services Law, regardless of whether you are also regulated by other government agencies (reached by declaring that you provide financial services). Section 500.19(c) lifts sections 500.2 and 500.3 for a covered entity that operates no information systems and holds no nonpublic information, and section 500.19(d) lifts sections 500.2 and 500.3 for an article 70 insurer under the Insurance Law that holds no nonpublic information beyond information relating to its corporate parent or affiliates. The limited exemption in section 500.19(a) for smaller covered entities does not lift either section.
- Maintain a cybersecurity program, based on your risk assessment, designed to protect the confidentiality, integrity and availability of your information systems and the nonpublic information stored on them, and designed to identify and assess risks, protect against unauthorized access, detect cybersecurity events, respond to and recover from them, and fulfill applicable regulatory reporting obligations.
- Make all documentation and information relevant to your cybersecurity program, including any provisions you adopt from an affiliate's program, available to the Superintendent on request.
- If you are a Class A company as 23 NYCRR 500.1(d) defines it, design and conduct independent audits of your cybersecurity program based on your risk assessment.
- Implement and maintain a written cybersecurity policy or policies for the protection of your information systems and the nonpublic information stored on them, approved at least annually by a senior officer or your senior governing body, and develop, document and implement procedures in accordance with the policy.
- Base the policy and procedures on your risk assessment and address, at a minimum and to the extent applicable to your operations: information security; data governance, classification and retention; asset inventory, device management and end of life management; access controls, including remote access and identity management; business continuity and disaster recovery planning and resources; systems operations and availability concerns; systems and network security and monitoring; security awareness and training; systems and application security and development and quality assurance; physical security and environmental controls; customer data privacy; vendor and third-party service provider management; risk assessment; incident response and notification; and vulnerability management.
What this law does
Section 500.2 of 23 NYCRR Part 500 requires each covered entity to maintain a cybersecurity program designed to protect the confidentiality, integrity and availability of its information systems and of the nonpublic information stored on them.
The program must be based on the covered entity's risk assessment and designed to perform six core functions: identifying and assessing risks, protecting against unauthorized access, detecting cybersecurity events, responding to them, recovering from them, and fulfilling applicable regulatory reporting obligations.
A covered entity may meet the requirements of the Part by adopting the relevant and applicable provisions of a cybersecurity program maintained by an affiliate, provided those provisions satisfy the Part as applied to the covered entity. All documentation and information relevant to the cybersecurity program, including any affiliate provisions the covered entity has adopted, must be made available to the Superintendent on request.
A Class A company must also design and conduct independent audits of its cybersecurity program based on its risk assessment. A Class A company is a covered entity with at least $20,000,000 in gross annual revenue in each of the last two fiscal years and either over 2,000 employees averaged over those years or over $1,000,000,000 in gross annual revenue in each of those years, counted as section 500.1(d) provides.
Section 500.3 requires a covered entity to implement and maintain a written policy or policies for the protection of its information systems and nonpublic information, approved at least annually by a senior officer or its senior governing body. The policy and its procedures must be based on the risk assessment and address, to the extent applicable to the covered entity's operations, fifteen areas, from information security and data governance to incident response and vulnerability management.
Section 500.4 separately requires the Chief Information Security Officer to report in writing at least annually to the senior governing body on the cybersecurity program. Section 500.19(c) lifts sections 500.2 and 500.3 for a covered entity that operates no information systems and holds no nonpublic information. Section 500.19(d) does the same for an article 70 insurer that holds no nonpublic information other than information relating to its corporate parent or affiliates.
The limited exemption in section 500.19(a) for smaller covered entities names neither section 500.2 nor section 500.3, so a covered entity holding it still owes both. Part 500 took effect on , and its Second Amendment on .
Section 500.22(c) gives covered entities 180 days from the Second Amendment's effective date to comply with its new requirements, except where subdivision (d) or (e) sets another period or day, and neither section 500.2 nor section 500.3 is named in those subdivisions.
Guidance on this law
How the bodies that enforce this law read it. Guidance binds nobody by itself, so LexLint never raises a finding from it; the duty is this law's.
- DFS Guidance: Cybersecurity Risks Arising from Artificial Intelligence and Strategies to Combat Related Risks, the New York Department of Financial Services
When LexLint raises it
When your app profile says your app provides financial services.