Remove Business Services Remove Document Remove Exercises Remove Training
article thumbnail

Proposed Amendments to NY Financial Services Cybersecurity Regulations Impose New Obligations on Large Entities, Boards of Directors and CISOs

Hunton Privacy

As part of the “training and monitoring” requirements under Section 500.14 Covered entities must undergo annual penetration testing by a qualified independent party, as well as regular vulnerability assessments, and material gaps found during testing must be documented and reporting to the senior governing body.

article thumbnail

NYDFS proposes significant cybersecurity regulation amendments

Data Protection Report

The draft amendments would also require that relevant employees be trained for their implementation. The proposed changes would further require the documented asset inventory to include the frequency required to update and validate the covered entity’s asset inventory. Asset inventories and Access Controls.