Regulation
NYDFS Part 500
NYDFS Part 500 — NY Cybersecurity Regulation
18 requirements · 17 connected unified controls
Open NYDFS Part 500 in the mapRequirements and control mappings
“Full” and “Partial” describe the catalog mapping to a unified control. A partial mapping includes the remaining requirement. These mappings do not establish an organization’s implementation or certification.
NYDFS 500 (NY Cybersecurity Regulation, 23 NYCRR 500)
| Requirement | Unified control and mapping |
|---|---|
| 500.2Cybersecurity program | UC-GOV-15 — Operate a management-approved information security programPartial Remaining requirement: Program's core functions must also include fulfilling applicable regulatory reporting obligations |
| 500.3Cybersecurity policy | |
| 500.4Chief Information Security Officer (CISO) | UC-GOV-09 — Appoint accountable security leadership (CISO)Partial Remaining requirement: 500.4(c) also requires timely reporting of material cybersecurity issues, not only annual reports |
| 500.5Vulnerability management (penetration testing and scanning) | UC-VULN-01 — Scan for vulnerabilities and track advisories on a defined cadencePartial Remaining requirement: also requires annual penetration testing by a qualified independent party |
| 500.6Audit trail | UC-LOG-03 — Protect audit logs and retain them for required periodsPartial Remaining requirement: also requires trails reconstructing material financial transactions |
| 500.7Access privileges and management | UC-ACCESS-02 — Review user access rights periodicallyPartial Remaining requirement: least-privilege limits and termination revocation satisfied by companion access controls |
| 500.8Application security | |
| 500.9Risk assessment | |
| 500.10Cybersecurity personnel and intelligence | |
| 500.11Third-party service provider security policy | UC-TPRM-01 — Operate a third-party security risk management programPartial Remaining requirement: policies must address TPSP MFA/access, encryption, event-notice, and representations guidelines |
| 500.12Multi-factor authentication | UC-ACCESS-09 — Authenticate all users with multi-factor authenticationPartial Remaining requirement: amended 500.12 requires MFA for any access to any information system |
| 500.13Asset management and data retention limitations | UC-GOV-30 — Maintain asset, media, and physical protection policiesPartial Remaining requirement: Inventory must track owner, location, classification, support expiration, RTO, plus update frequency |
| 500.14Monitoring and training | UC-TRAIN-01 — Deliver security awareness training to all personnelPartial Remaining requirement: authorized-user activity monitoring and email/web filtering prongs not covered |
| 500.15Encryption of nonpublic information | |
| 500.16Incident response and business continuity management | UC-BCDR-01 — Maintain business continuity and disaster recovery plansPartial Remaining requirement: plan testing, training, and backup restore verification satisfied by companion controls |
| 500.17Notices to superintendent (incident notification and annual certification) | |
| 500.18Confidentiality | |
| 500.19Exemptions |