NYDFS Cybersecurity Regulation
NYDFS Cybersecurity Regulation ist eine Regel eines Bundesstaats (NY), veröffentlicht als 23 NYCRR Part 500. Erlassen am 2017-03-01, gilt ab 2023-11-01. In Kraft, weitere Fristen stehen aus: Seit 2017 in Kraft. Die zweite Änderung gilt seit dem 1. November 2023, mit Übergangsfristen bis November 2025.
- NYDFS Cybersecurity Regulation umfasst cybersecurity program and policy, chief information security officer, multi-factor authentication und notice of a cybersecurity event.
- NYDFS Cybersecurity Regulation entscheidet nicht, ob ein einzelnes Unternehmen die Anforderungen erfüllt. Das steht im eigenen Text des Unternehmens und in seinen Berichten.
- Aufsicht: New York State Department of Financial Services. Der Text wird veröffentlicht von New York State Department of Financial Services.
- Der Text benennt finanzdienstleistungen und versicherung.
- nis2-2022-2555: Beide Texte benennen eine verantwortliche Funktion, verlangen Berichte an das Leitungsorgan und sehen eine frühe Meldung schwerwiegender Vorfälle vor. Der EU-Text gilt für wesentliche Einrichtungen, die Regel des Bundesstaats für lizenzierte Finanzunternehmen.
- US regulatory register
- Finanzdienstleistungen
- Versicherung
- New York State Department of Financial Services
- NIS2 — Directive (EU) 2022/2555
Identität
| Bezeichnung | 23 NYCRR Part 500 |
|---|---|
| Erlassen | 2017-03-01 |
| Gilt ab | 2023-11-01 |
| Status | Seit 2017 in Kraft. Die zweite Änderung gilt seit dem 1. November 2023, mit Übergangsfristen bis November 2025. |
| Aufsicht | New York State Department of Financial Services |
| Benannte Marktbereiche | Finanzdienstleistungen, Versicherung |
| Risikobereiche | Informationssicherheit, Aufbewahrung |
Anforderungen im Text
- Cybersecurity program and policy, Fundstelle: 23 NYCRR 500.2 and 500.3. A documented programme and a policy approved by the board or a senior officer.
- Chief Information Security Officer, Fundstelle: 23 NYCRR 500.4. A named officer and an annual written report to the governing body.
- Multi-factor authentication, Fundstelle: 23 NYCRR 500.12. Multi-factor authentication for remote and privileged access.
- Notice of a cybersecurity event, Fundstelle: 23 NYCRR 500.17. Notice to the supervisor within 72 hours, and an annual certification.
Offizielle Quellen
- 23 NYCRR Part 500, Cybersecurity Requirements for Financial Services Companies, New York State Department of Financial Services
ExploreWorldAI is operated by Valkiv Ventures AB (Reg. no. 556995-1311), Kungsgatan 8, 111 43 Stockholm, Sweden. EU-hosted, with data processing assessed against the GDPR. Contact: hello@exploreworldai.com.
Machine-readable summaries for AI agents: /llms.txt and /llms-full.txt.