logo

Database

NYDFS

Last updated: 2023/09/18
logo

The NYDFS Cybersecurity Regulation (23 NYCRR 500) is a set of regulations from the New York State Department of Financial Services (NYDFS) that places cybersecurity requirements on all covered entities. The version used in this section is NYDFS, February 2017.

Control-Requirement Mapping

DefinitionRequirements
500_2. Cybersecurity program
500_3. Cybersecurity policy
500_5. Penetration testing and vulnerability assessments
500_6. Audit trail
500_7. Access privileges
500_10. Cybersecurity personnel and intelligence
500_11. Third party service provider security policy
500_12. Multi-factor authentication
500_13. Limitations on data retention
500_14. Training and monitoring
500_15. Encryption of nonpublic information
500_16. Incident response plan