Remove Access Remove Authentication Remove Business Services Remove Exercises
article thumbnail

Proposed Amendments to NY Financial Services Cybersecurity Regulations Impose New Obligations on Large Entities, Boards of Directors and CISOs

Hunton Privacy

As part of the “access privileges” requirements under Section 500.7 Covered entities also must conduct an “impact assessment whenever a change in the business or technology causes a material change in the covered entity’s cyber risk.” As part of the “penetration testing and vulnerability assessments” requirements under Section 500.5

article thumbnail

NYDFS proposes significant cybersecurity regulation amendments

Data Protection Report

Annual Updating of Risk Assessment : The proposed regulations would require annual updating of risk assessments, and would also require impact assessments be conducted whenever a change in business or technology causes a material change to the company’s cyber risk. Asset inventories and Access Controls. Notifications to DFS.