Tailored to Risk

Proposed Regulation now makes clear that while all Covered Entities are required to maintain a cybersecurity program and a written cybersecurity policy, a particular Covered Entity’s program and policy should be based on the findings of its own Risk Assessment. Similarly, it is now clear that:

  • Penetration testing and vulnerability assessments are to be tailored towards the risks and vulnerabilities identified in the Risk Assessment, and such testing and assessments are not necessary if the entity otherwise maintains “effective continuous monitoring, or other systems to detect, on an ongoing basis, changes … that may create or indicate vulnerabilities”;
  • Audit trail systems are only required to the extent applicable and should be based on the Risk Assessment.
  • Limitations on user access privileges to systems that provide access to “Nonpublic Information” should be based on the Risk Assessment.
  • The required components of policies and procedures regarding the security of systems and information accessible to, or held by, third parties will depend on the applicable facts and the Risk Assessment.
  • Whether multifactor authentication should be used to protect against unauthorized access will be determined based on the Risk Assessment; and
  • The decision to encrypt Nonpublic Information or to employ alternative compensating controls should be determined based on the Risk Assessment.

Nonpublic Information

Secure “Nonpublic Information” from misuse, disruption, and unauthorized access, and the original version of the Proposed Regulation defined such information very broadly (e.g., far broader than what New York’s existing data protection law defines as “private information”). Accordingly, many of those commenting on the Proposed Regulation complained that it was overbroad, unclear or unnecessarily inconsistent with other existing standards. In response, the NYDFS revised the definition, significantly decreasing its scope.

Nonpublic Information to include any information (unless otherwise available to the general public from government records or widely distributed media):

that an individual provides to a Covered Entity in connection with the seeking or obtaining of any financial product or service from the Covered Entity or is about an individual resulting from a transaction involving a financial product or service between a Covered Entity and an individual, or a Covered Entity otherwise obtains about an individual in connection with providing a financial product or service to that individual.

The definition is limited to merely any information (again, unless otherwise available to the general public from government records or widely distributed media):

concerning an individual which because of name, number, personal mark, or another identifier can be used to identify such individual, in combination with any one or more of the following data elements: (i) social security number; (ii) driver’s license number or non-driver identification card number; (iii) account number, credit or debit card number; (iv) any security code, access code or password that would permit access to an individual’s financial account; or (v) biometric records.

Apart from the addition of “biometric records,” the amended language is substantially the same as the definition of “private information” in New York’s general data breach notification statute. However, overall, the definition of Nonpublic Information is still broader than “private information” because the definition includes: (1) healthcare information; and (2) “[b]business related information of a Covered Entity the tampering with which, or unauthorized disclosure, access or use of which, would cause a material adverse impact on the business, operations or security of the Covered Entity.”

Main Menu