The NYDFS Cybersecurity Regulations | Practical Law

The NYDFS Cybersecurity Regulations | Practical Law

A Practice Note explaining the New York Department of Financial Services (NYDFS) Cybersecurity Requirements for Financial Services Companies (23 NYCRR Part 500) which require state-licensed financial institutions to protect their information systems and the nonpublic information (NPI) that they store. This Note details compliance obligations for state-licensed financial institutions including required policies and procedures, risk assessment, and core cybersecurity program elements. It also discusses additional cybersecurity controls required under Part 500, such as encryption and monitoring, multi-factor authentication, reporting and certification requirements, and application to consumer credit reporting agencies under 23 NYCRR Part 201.

The NYDFS Cybersecurity Regulations

Practical Law Practice Note w-016-7142 (Approx. 35 pages)

The NYDFS Cybersecurity Regulations

by Tara Swaminatha, ZeroDay Law LLC, with Practical Law Data Privacy & Cybersecurity
MaintainedNew York, USA (National/Federal)
A Practice Note explaining the New York Department of Financial Services (NYDFS) Cybersecurity Requirements for Financial Services Companies (23 NYCRR Part 500) which require state-licensed financial institutions to protect their information systems and the nonpublic information (NPI) that they store. This Note details compliance obligations for state-licensed financial institutions including required policies and procedures, risk assessment, and core cybersecurity program elements. It also discusses additional cybersecurity controls required under Part 500, such as encryption and monitoring, multi-factor authentication, reporting and certification requirements, and application to consumer credit reporting agencies under 23 NYCRR Part 201.