New York finalizes cybersecurity regulations for financial institutions

Purpose To analyze the cybersecurity regulations for financial institutions issued by the New York State Department of Financial Services on February 16, 2017. Design/methodology/approach This article summarizes the regulations’ scope and requirements including definition of Covered Entities and sub...

Ausführliche Beschreibung

Gespeichert in:
Bibliographische Detailangaben
Veröffentlicht in:The journal of investment compliance 2017-07, Vol.18 (2), p.27-30
Hauptverfasser: Cedarbaum, Jonathan G, Powell, Benjamin A, Freeman, D. Reed, Schloss, Leah, Abrahamson, Reed
Format: Artikel
Sprache:eng
Online-Zugang:Volltext
Tags: Tag hinzufügen
Keine Tags, Fügen Sie den ersten Tag hinzu!
Beschreibung
Zusammenfassung:Purpose To analyze the cybersecurity regulations for financial institutions issued by the New York State Department of Financial Services on February 16, 2017. Design/methodology/approach This article summarizes the regulations’ scope and requirements including definition of Covered Entities and substantive requirements including periodic Risk Assessments, cyber policies, dedicated and trained personnel, testing, audit trails, control over Third Party Service Providers, authentication, secure disposal, encryption, and incident reporting. Findings The regulations go beyond federal requirements in a number of important respects. Originality/value This article provides a guide for regulated entities to start preparing for compliance with the new regulations from experienced lawyers with specialties in cybersecurity, privacy and communications.
ISSN:1528-5812
1758-7476
DOI:10.1108/JOIC-04-2017-0020