New York finalizes cybersecurity regulations for financial institutions
Purpose To analyze the cybersecurity regulations for financial institutions issued by the New York State Department of Financial Services on February 16, 2017. Design/methodology/approach This article summarizes the regulations’ scope and requirements including definition of Covered Entities and sub...
Gespeichert in:
Veröffentlicht in: | The journal of investment compliance 2017-07, Vol.18 (2), p.27-30 |
---|---|
Hauptverfasser: | , , , , |
Format: | Artikel |
Sprache: | eng |
Online-Zugang: | Volltext |
Tags: |
Tag hinzufügen
Keine Tags, Fügen Sie den ersten Tag hinzu!
|
Zusammenfassung: | Purpose
To analyze the cybersecurity regulations for financial institutions issued by the New York State Department of Financial Services on February 16, 2017.
Design/methodology/approach
This article summarizes the regulations’ scope and requirements including definition of Covered Entities and substantive requirements including periodic Risk Assessments, cyber policies, dedicated and trained personnel, testing, audit trails, control over Third Party Service Providers, authentication, secure disposal, encryption, and incident reporting.
Findings
The regulations go beyond federal requirements in a number of important respects.
Originality/value
This article provides a guide for regulated entities to start preparing for compliance with the new regulations from experienced lawyers with specialties in cybersecurity, privacy and communications. |
---|---|
ISSN: | 1528-5812 1758-7476 |
DOI: | 10.1108/JOIC-04-2017-0020 |