Law / United States /
New York
New York Department of Financial Services Cybersecurity Regulation, Access Privileges and Management
In force.
A sector security regimes rule binding private bodies.
- Enforcement body
- The Superintendent of Financial Services.
- Instrument type
- a regulation made under an act
- Obligation class
- Security
As of .
What it requires
- It reaches you if you operate as a Covered Entity under 23 NYCRR 500.1(e): any person operating under, or required to operate under, a license, registration, charter, certificate, permit, accreditation or similar authorization under the Banking Law, the Insurance Law or the Financial Services Law, regardless of whether you are also regulated by other government agencies (reached by declaring that you provide financial services). Section 500.19(c) lifts section 500.7 for a covered entity that operates no information systems and holds no nonpublic information, and section 500.19(d) lifts section 500.7 for an article 70 insurer under the Insurance Law that holds no nonpublic information beyond information relating to its corporate parent or affiliates. The limited exemption in section 500.19(a) for smaller covered entities does not lift it.
- Based on your risk assessment, limit user access privileges on information systems that provide access to nonpublic information to only those necessary to perform the user's job, limit the number of privileged accounts and their access functions to only those necessary to perform the user's job, and use a privileged account only when performing functions that require that access.
- Review all user access privileges periodically and at least annually, and remove or disable accounts and access that are no longer necessary; promptly terminate access following departures.
- Disable or securely configure all protocols that permit remote control of devices.
- If you use passwords as a method of authentication, implement a written password policy that meets industry standards.
- If you are a Class A company as 23 NYCRR 500.1(d) defines it, monitor privileged access activity and implement a privileged access management solution and an automated method of blocking commonly used passwords for all accounts on information systems you own or control and, wherever feasible, for all other accounts; where you determine that blocking is infeasible, your Chief Information Security Officer may instead approve in writing, at least annually, the infeasibility and the use of reasonably equivalent or more secure compensating controls.
What this law does
Section 500.7 requires a covered entity, as part of its cybersecurity program and based on its risk assessment, to limit user access privileges to information systems that provide access to nonpublic information to only those necessary to perform the user's job. It must also limit the number of privileged accounts and their access functions to only those necessary to perform the user's job, and limit the use of privileged accounts to only when performing functions requiring that access.
It must review all user access privileges periodically and at least annually, and remove or disable accounts and access that are no longer necessary. It must disable or securely configure all protocols that permit remote control of devices, and promptly terminate access following departures. To the extent passwords are employed as a method of authentication, the covered entity must implement a written password policy that meets industry standards.
A Class A company must also monitor privileged access activity and implement a privileged access management solution and an automated method of blocking commonly used passwords for all accounts on information systems it owns or controls and, wherever feasible, for all other accounts.
Where a Class A company determines that blocking commonly used passwords is infeasible, its Chief Information Security Officer may instead approve in writing, at least annually, the infeasibility and the use of reasonably equivalent or more secure compensating controls.
A Class A company is a covered entity with at least $20,000,000 in gross annual revenue in each of the last two fiscal years and either over 2,000 employees averaged over those years or over $1,000,000,000 in gross annual revenue in each of those years, counted as section 500.1(d) provides.
Section 500.19(c) and (d) name section 500.7 among the sections they lift, (c) for a covered entity that operates no information systems and holds no nonpublic information and (d) for an article 70 insurer that holds no nonpublic information beyond information relating to its corporate parent or affiliates. The limited exemption in section 500.19(a) for smaller covered entities does not name section 500.7, so a covered entity holding it still owes these duties.
Part 500 took effect on , and its Second Amendment on . Section 500.22(d)(3) gives covered entities 18 months from the effective date of the Second Amendment to comply with its new requirements in section 500.7.
When LexLint raises it
When your app profile says your app provides financial services.