Legal sources with official primary sources

Printed ·

Hoppa till innehåll
Hoppa till svaret

How often must an NYDFS covered entity assess cyber risk?

The covered entity must conduct a periodic risk assessment sufficient to inform the design of its cybersecurity program and update it as reasonably necessary when business or technology changes cause a material change in cyber risk.

Dela sidan

Source

Source
23 NYCRR § 500.9
Source
New York State Senate Open Legislation
Area
Financial services
Source type
regulation
Status
In force at the reading date
Authority
New York State Department of Financial Services
Checked
2026-09-22

Questions

Nästa steg

Vill ni använda registret i eget arbete finns tre vägar in.

Börja med din uppgift