Section node
Multi-factor authentication
23 NYCRR 500.12
- What this page is
- Section node, 23 NYCRR 500.12
- Checked against the official source
- 2026-08-15Changed
- Responsible publisher
- ExploreWorld Legal, editorial deskLiability position
Short answer
What does 23 NYCRR 500.12 require, and where does it carry an outcome in the rule tree?
23 NYCRR 500.12 is the paragraph the NYDFS Part 500 decision agent rests on for this question. Multi-factor authentication for remote and privileged access. The block was read against the publisher on 2026-08-15 and carries 2 outcomes in the agent's rule tree. The reference can be cited as it stands, with a link to the official text and a content hash.
23 NYCRR 500.12Checked against the publisher 2026-08-15
A source reference, not legal advice.
- Jurisdiction
- 23 NYCRR Part 500
- Section node
- mfa
- Read
- 2026-08-15
- Hash
- sha256:3524023584860871
Outcomes resting on this section
The rules below point to this section in their outcome. The verdict is a machine classification, not a judgment on an individual matter.
nydfs-mfa
Multi-factor authentication is absent
23 NYCRR 500.12 requires multi-factor authentication for all remote access to the network, for access to third party applications holding nonpublic information and for privileged accounts.
prohibited, Requirement applies
nydfs-base
The regulation applies to the business
23 NYCRR Part 500 applies to every entity licensed under New York banking, insurance or financial services law. The requirements cover the program, the responsible function, authentication and notice.
risk, Requirement applies
Section nodes
- Cybersecurity program and policy23 NYCRR 500.2 and 500.3
- Chief Information Security Officer23 NYCRR 500.4
- Notice of a cybersecurity event23 NYCRR 500.17
The verdict is a machine classification of the outcome, not legal advice and not a compliance decision.
Verifiable trust signals
- Six fixed blocks, one source per line
- No sentence written by a language model
- Engine version and read date on every answer
- No customer data, no documents, no advice
- Model card and audit published under the EU AI Act