New York State Department of Financial Services
(NYDFS NYCRR)
The NYDFS NYCRR Library includes:
- Cybersecurity Requirements (NYDFS NYCRR 500)
- Virtual Currencies (NYDFS 23 NYCRR 200), and
- Transaction Monitoring and Filtering (NYDFS 3 NYCRR 504)
The Cybersecurity Requirements (NYDFS NYCRR 500) Playbook addresses the following areas:
- Cybersecurity Program; Cybersecurity Policy; Chief Information Security Officer; Penetration Testing and Vulnerability Assessments; Audit Trail; Access Privileges; Application Security; Risk Assessment; Cybersecurity Personnel and Intelligence; Third Party Service Provider Security Policy; Multi-Factor Authentication; Limitations on Data Retention; Training and Monitoring; Encryption of Nonpublic Information; Incident Response Plan; Notification of Cybersecurity Event(s): Confidentiality; and Exemptions.
The Virtual Currencies (NYDFS 23 NYCRR 200) Playbook addresses the following areas:
- License; Compliance; Capital requirements; Custody and protection of customer assets; Material change to business; Change of control; mergers and acquisitions; Books and records; Reports and financial disclosures; Anti-money laundering program; Cyber security program; Business continuity and disaster recovery; Advertising and marketing; Consumer protection.
The Transaction Monitoring and Filtering (NYDFS 3 NYCRR 504) Playbook addresses the following areas:
- Transaction Monitoring Program Requirements; Transaction Filtering Program Requirements; Transaction Monitoring and Filtering Program; Remediation Annual Board Resolution or Senior Officer(s) Compliance Finding; Information Sharing - USA PATRIOT Act Section 314
Note: You must first install the GRC Playbook software before you can open and use the encrypted Playbooks.
All Playbooks are encrypted to protect the privacy and confidentiality of your data. The GRC Playbook software automatically generates and applies the password to programmatically unencrypt a Playbook and open it for use.
Save the downloaded Playbooks to a secure location on your system. Open your Playbooks from your secure location. GRC Playbook Limited does not have visibility into any of the data you enter into your downloaded Playbooks.
Based on Authoritative Sources