Regulation

NYDFS Part 500

NYDFS Part 500 — NY Cybersecurity Regulation

18 requirements · 17 connected unified controls

Open NYDFS Part 500 in the map
Version
23 NYCRR 500, Second Amendment
Published
2023-11-01
Effective
2023-11-01 (phased through 2025-11-01)
Amendments
Second Amendment (2023)

Requirements and control mappings

“Full” and “Partial” describe the catalog mapping to a unified control. A partial mapping includes the remaining requirement. These mappings do not establish an organization’s implementation or certification.

NYDFS 500 (NY Cybersecurity Regulation, 23 NYCRR 500)

RequirementUnified control and mapping
500.2Cybersecurity program
UC-GOV-15 — Operate a management-approved information security programPartial

Remaining requirement: Program's core functions must also include fulfilling applicable regulatory reporting obligations

500.3Cybersecurity policy
500.4Chief Information Security Officer (CISO)
UC-GOV-09 — Appoint accountable security leadership (CISO)Partial

Remaining requirement: 500.4(c) also requires timely reporting of material cybersecurity issues, not only annual reports

500.5Vulnerability management (penetration testing and scanning)
UC-VULN-01 — Scan for vulnerabilities and track advisories on a defined cadencePartial

Remaining requirement: also requires annual penetration testing by a qualified independent party

500.6Audit trail
UC-LOG-03 — Protect audit logs and retain them for required periodsPartial

Remaining requirement: also requires trails reconstructing material financial transactions

500.7Access privileges and management
UC-ACCESS-02 — Review user access rights periodicallyPartial

Remaining requirement: least-privilege limits and termination revocation satisfied by companion access controls

500.8Application security
500.9Risk assessment
500.10Cybersecurity personnel and intelligence
500.11Third-party service provider security policy
UC-TPRM-01 — Operate a third-party security risk management programPartial

Remaining requirement: policies must address TPSP MFA/access, encryption, event-notice, and representations guidelines

500.12Multi-factor authentication
UC-ACCESS-09 — Authenticate all users with multi-factor authenticationPartial

Remaining requirement: amended 500.12 requires MFA for any access to any information system

500.13Asset management and data retention limitations
UC-GOV-30 — Maintain asset, media, and physical protection policiesPartial

Remaining requirement: Inventory must track owner, location, classification, support expiration, RTO, plus update frequency

500.14Monitoring and training
UC-TRAIN-01 — Deliver security awareness training to all personnelPartial

Remaining requirement: authorized-user activity monitoring and email/web filtering prongs not covered

500.15Encryption of nonpublic information
500.16Incident response and business continuity management
UC-BCDR-01 — Maintain business continuity and disaster recovery plansPartial

Remaining requirement: plan testing, training, and backup restore verification satisfied by companion controls

500.17Notices to superintendent (incident notification and annual certification)
500.18Confidentiality
500.19Exemptions