logo

NYDFS


Summary

The NYDFS Cybersecurity Regulation (23 NYCRR 500) is a set of regulations from the New York State Department of Financial Services (NYDFS) that places cybersecurity requirements on all covered entities. The version used in this section is NYDFS, February 2017.


Definitions

DefinitionRequirements
NYDFS-500_2. Cybersecurity program
NYDFS-500_3. Cybersecurity policy
NYDFS-500_5. Penetration testing and vulnerability assessments
NYDFS-500_6. Audit trail
NYDFS-500_7. Access privileges
NYDFS-500_10. Cybersecurity personnel and intelligence
NYDFS-500_11. Third party service provider security policy
NYDFS-500_12. Multi-factor authentication
NYDFS-500_13. Limitations on data retention
NYDFS-500_14. Training and monitoring
NYDFS-500_15. Encryption of nonpublic information
NYDFS-500_16. Incident response plan

Last updated

2023/09/18