Encryption of Nonpublic Information
In a significant change, the Regulation now allows Covered Entities to either encrypt Nonpublic Information or use alternative compensating controls. As originally drafted, the Proposed Regulation would have permitted the use of compensating controls only for a limited transition period—one year to start encrypting data in transit and five years to commence encrypting data at rest. Now, the Proposed Regulation permits the use of alternative compensating controls indefinitely, provided such controls are reviewed and deemed effective by the Covered Entity’s chief information security officer (“CISO”). Moreover, to the extent that encryption is not used, the CISO must review “the feasibility of encryption and effectiveness of the compensating controls” at least annually. The Proposed Regulation now also clarifies that information in transit refers to transit “over external networks.”
Chief Information Security Officer
The Regulation requires that each Covered Entity designate a CISO to oversee and implement the Covered Entity’s cybersecurity program and written cybersecurity policy. Some commentators expressed concerns regarding the feasibility or practicality of hiring or appointing an individual whose exclusive job would be to serve as CISO, under that specific title. In response, the NYDFS clarified the Proposed Regulation to provide that the person carrying out the duties of the CISO does not need to be exclusively dedicated to such activities and does not need a specific title. In fact, the revisions explicitly permit the CISO requirement to be satisfied by an employee of an affiliate or third-party service provider (subject to certain requirements).
Audit Trail
As originally drafted, the Regulation required Covered Entities to maintain sufficiently detailed records to be able to, among other things:
- Completely reconstruct all financial transactions and accounting necessary to enable the Covered Entity to detect and respond to attempted and actual attacks; and
- Track and maintain data logging of all authorized user access to critical systems, including all physical access to hardware, that allows for event reconstruction.
Some commentators argued that this extensive audit trail requirement was excessive and would lead to the retention of too much information. In response, the NYDFS significantly reduced the requirement by adding multiple materiality qualifiers and as noted above, tying it to the Covered Entity’s Risk Assessment. Moreover, the applicable record retention period was shortened from six years to five, consistent with the retention requirements of other aspects of the Proposed Regulation.

Whether you're preparing for Cybersecurity certification, working with government standards, or simply starting your career in compliance, these are the NIST Federal Information Processing Standards (FIPS), Special Publication (SP), and Interagency Report (IR) topics