Resource: NY DFS Issues New Cybersecurity Guidance to Address Risks Associated with the Use of Third-Party Service Providers - DataBreaches.Net
Briefly

Resource: NY DFS Issues New Cybersecurity Guidance to Address Risks Associated with the Use of Third-Party Service Providers - DataBreaches.Net
"New York State Department of Financial Services (DFS) Acting Superintendent Kaitlin Asrow today issued new cybersecurity guidance addressing the risks associated with entities becoming increasingly reliant on third-party service providers (TPSPs). The guidance builds on the Department's ongoing work to protect New Yorkers and DFS-regulated entities from cybersecurity risks through its nation-leading cybersecurity regulation."
""While third-party service providers have driven innovation and enabled significant efficiencies in our financial system, regulated entities are still ultimately accountable for protecting consumers and managing risk," said Acting Superintendent Kaitlin Asrow. "To ensure the safe and secure operation of financial services and the protection of nonpublic information, entities must establish and maintain appropriate internal risk management controls when using third-party service providers." This guidance does not impose new requirements or obligations on DFS-regulated entities. Rather, the guidance is intended to clarify regulatory requirements under DFS's cybersecurity regulation and share best practices that entities should consider implementing."
New York State Department of Financial Services issued cybersecurity guidance addressing risks from increased reliance on third-party service providers (TPSPs). The guidance builds on existing DFS cybersecurity regulation and emphasizes that regulated entities remain ultimately accountable for protecting consumers and managing risk when using TPSPs. Entities are instructed to establish and maintain appropriate internal risk-management controls to ensure safe operation of financial services and protection of nonpublic information. The guidance does not create new regulatory obligations; instead, it clarifies expectations and shares best practices. A copy of the guidance and additional cybersecurity resources are available on the Department's website and Cybersecurity Resource Center.
Read at DataBreaches.Net
Unable to calculate read time
[
|
]