Compliance
NYCRR 500
The New York State Department of Financial Services (DFS) has been closely monitoring the growing threat that nation-states, organized groups, and independent criminals pose to information and financial systems. Increasingly, cybercriminals exploit technological vulnerabilities to reach sensitive electronic data.
23 NYCRR 500 is a regulatory standard governing the financial-services industry in New York. It requires each covered institution to maintain a cybersecurity program, designate a Chief Information Security Officer (CISO), and implement access controls, asset management, data governance, secure software-development practices, annual compliance certification, and more.
The regulation requires banks, insurance companies, and other DFS-regulated financial-services institutions to establish and maintain a cybersecurity program designed to protect consumers and ensure the safety and soundness of New York State’s financial-services industry.
Key elements
A compliant cybersecurity program must:
- Adopt a written cybersecurity policy
- Identify and assess internal and external cybersecurity risks to the security or integrity of stored data
- Use defensive infrastructure, policies, and procedures to protect IT systems from unauthorized access or malicious acts
- Detect cybersecurity events
- Respond to detected events to mitigate negative effects
- Recover from events and restore normal operations
- Fulfill applicable regulatory reporting requirements
It also requires:
- A designated Chief Information Security Officer
- Cybersecurity training for employees
- Management of third-party service-provider risk
- Incident monitoring and reporting
- Information security audits
The program must be able to generate alerts when cybersecurity events are detected. CYK helps DFS-regulated firms build, document, and maintain a program that meets these requirements.