◦ Reference · Framework

NYDFS Part 500

New York Department of Financial Services 23 NYCRR Part 500, the US cybersecurity regulation for covered financial institutions operating under a DFS license. Drives the CISO designation, the 72-hour notification clock, the annual certification of compliance, and the risk-based program elements. Attention is triggered by late 72-hour notifications, by incomplete annual certifications on the prior calendar year, by missing third-party service provider security due-diligence, and by a Class A DFS-regulated entity that fails the multi-factor authentication or privileged-access-monitoring signal in 500.12.

/nydfs-500