N.Y. Comp. Codes R. & Regs. Tit. 23 § 500.9 - Risk Assessment
(a) Each
covered entity shall conduct a periodic risk assessment of the covered entity's
information systems sufficient to inform the design of the cybersecurity
program as required by this Part. Such risk assessment shall be reviewed and
updated as reasonably necessary, but at a minimum annually, and whenever a
change in the business or technology causes a material change to the covered
entity's cyber risk . The covered entity's risk assessment shall allow for
revision of controls to respond to technological developments and evolving
threats and shall consider the particular risks of the covered entity's
business operations related to cybersecurity, nonpublic information collected
or stored, information systems utilized and the availability and effectiveness
of controls to protect nonpublic information and information systems.
(b) The Risk Assessment shall be
carried out in accordance with written policies and procedures and shall be
documented. Such policies and procedures shall include:
(1) criteria for the evaluation and
categorization of identified cybersecurity risks or threats facing the Covered
Entity;
(2) criteria for the
assessment of the confidentiality, integrity, security and availability of the
Covered Entity's Information Systems and Nonpublic Information, including the
adequacy of existing controls in the context of identified risks; and
(3) requirements describing how identified
risks will be mitigated or accepted based on the Risk Assessment and how the
cybersecurity program will address the risks.
Notes
State regulations are updated quarterly; we currently have two versions available. Below is a comparison between our most recent version and the prior quarterly release. More comparison features will be added as we have more versions to compare.
No prior version found.