Back to Frameworks

NY DFS 23 NYCRR 500

United States
23 domains
23 controls

New York State Department of Financial Services Cybersecurity Regulation, Second Amendment (effective Nov 2023).

Verified

NY DFS 23 NYCRR 500 is a compliance framework from United States with 23 domains and 23 controls that map to 5 other frameworks. The largest domains are §500.10 (1 controls), §500.11 (1 controls), §500.12 (1 controls). Every control below carries what it requires and what an assessor expects to see.

Maintained by Gerard BlokdykVerified against the published standard Control text last updated

Framework summaries on this platform are AI-assisted interpretations for educational and compliance planning purposes. They do not reproduce or replace the official standards. Refer to the authoritative source for the definitive text. Framework names and trademarks belong to their respective organisations.

Framework Domains (23)

§500.10

1 controls
Controls in the §500.10 domain of NY DFS 23 NYCRR 500 — 1 controls
CodeTitle
§500.10Cybersecurity Personnel and Intelligence

§500.11

1 controls
Controls in the §500.11 domain of NY DFS 23 NYCRR 500 — 1 controls
CodeTitle
§500.11Third Party Service Provider Security Policy

§500.12

1 controls
Controls in the §500.12 domain of NY DFS 23 NYCRR 500 — 1 controls
CodeTitle
§500.12Multi-Factor Authentication

§500.13

1 controls
Controls in the §500.13 domain of NY DFS 23 NYCRR 500 — 1 controls
CodeTitle
§500.13Asset Management and Data Retention Requirements

§500.14

1 controls
Controls in the §500.14 domain of NY DFS 23 NYCRR 500 — 1 controls
CodeTitle
§500.14Monitoring and Training

§500.15

1 controls
Controls in the §500.15 domain of NY DFS 23 NYCRR 500 — 1 controls
CodeTitle
§500.15Encryption of Nonpublic Information

§500.16

1 controls
Controls in the §500.16 domain of NY DFS 23 NYCRR 500 — 1 controls
CodeTitle
§500.16Incident Response and Business Continuity Management

§500.17

1 controls
Controls in the §500.17 domain of NY DFS 23 NYCRR 500 — 1 controls
CodeTitle
§500.17Notices to Superintendent

§500.18

1 controls
Controls in the §500.18 domain of NY DFS 23 NYCRR 500 — 1 controls
CodeTitle
§500.18Confidentiality

§500.19

1 controls
Controls in the §500.19 domain of NY DFS 23 NYCRR 500 — 1 controls
CodeTitle
§500.19Exemptions

§500.2

1 controls
Controls in the §500.2 domain of NY DFS 23 NYCRR 500 — 1 controls
CodeTitle
§500.2Cybersecurity Program

§500.20

1 controls
Controls in the §500.20 domain of NY DFS 23 NYCRR 500 — 1 controls
CodeTitle
§500.20Enforcement

§500.21

1 controls
Controls in the §500.21 domain of NY DFS 23 NYCRR 500 — 1 controls
CodeTitle
§500.21Effective Date

§500.22

1 controls
Controls in the §500.22 domain of NY DFS 23 NYCRR 500 — 1 controls
CodeTitle
§500.22Transitional Periods

§500.23

1 controls
Controls in the §500.23 domain of NY DFS 23 NYCRR 500 — 1 controls
CodeTitle
§500.23Severability

§500.24

1 controls
Controls in the §500.24 domain of NY DFS 23 NYCRR 500 — 1 controls
CodeTitle
§500.24 (Second Amendment, Class A Companies)Class A Company Enhanced Obligations (cross-section)

§500.3

1 controls
Controls in the §500.3 domain of NY DFS 23 NYCRR 500 — 1 controls
CodeTitle
§500.3Cybersecurity Policy

§500.4

1 controls
Controls in the §500.4 domain of NY DFS 23 NYCRR 500 — 1 controls
CodeTitle
§500.4Cybersecurity Governance (CISO)

§500.5

1 controls
Controls in the §500.5 domain of NY DFS 23 NYCRR 500 — 1 controls
CodeTitle
§500.5Vulnerability Management

§500.6

1 controls
Controls in the §500.6 domain of NY DFS 23 NYCRR 500 — 1 controls
CodeTitle
§500.6Audit Trail

§500.7

1 controls
Controls in the §500.7 domain of NY DFS 23 NYCRR 500 — 1 controls
CodeTitle
§500.7Access Privileges and Management

§500.8

1 controls
Controls in the §500.8 domain of NY DFS 23 NYCRR 500 — 1 controls
CodeTitle
§500.8Application Security

§500.9

1 controls
Controls in the §500.9 domain of NY DFS 23 NYCRR 500 — 1 controls
CodeTitle
§500.9Risk Assessment

Your Compliance Coverage

If you comply with NY DFS 23 NYCRR 500, you already cover:

Maps to 5 other frameworks

23 total controls
ISO 27002:2022
16 source controls mapped|21 target controls covered
70%
ISO 27018:2019
1 source controls mapped|1 target controls covered
4%
ISO 27001:2022
1 source controls mapped|1 target controls covered
4%
ISO 22301:2019
1 source controls mapped|2 target controls covered
4%
ISO/IEC 23894:2023
1 source controls mapped|1 target controls covered
4%

Coverage is not the same as your position

This page shows what NY DFS 23 NYCRR 500 overlaps with in general. Where your organisation actually stands, against the standard you are going for and the certifications you already hold, is a different question. Same graph and the same recorded refutations, scoped to you rather than to a pair.

The Compliance Position Diagnostic, $5,000 fixed, ten business days

What is NY DFS 23 NYCRR 500 and who does it apply to?

NY DFS 23 NYCRR 500 is a compliance framework from United States with 23 domains and 23 controls. New York State Department of Financial Services Cybersecurity Regulation, Second Amendment (effective Nov 2023). It is used by organisations to establish and maintain compliance with industry standards and regulatory requirements.

What does NY DFS 23 NYCRR 500 actually require?

NY DFS 23 NYCRR 500 has 23 controls organised across 23 domains. The largest domains are §500.10 (1 controls), §500.11 (1 controls), §500.12 (1 controls). Each control defines specific requirements that organisations must implement to achieve compliance.

If I already comply with another framework, how much of NY DFS 23 NYCRR 500 do I already cover?

NY DFS 23 NYCRR 500 maps to 5 other compliance frameworks. The top mapping partners are ISO 27002:2022 (70% coverage), ISO 27018:2019 (4% coverage), ISO 27001:2022 (4% coverage). Use our comparison tool to explore control-level mappings between frameworks.

How do I implement NY DFS 23 NYCRR 500?

Start your NY DFS 23 NYCRR 500 compliance journey by running a self-assessment on our platform to identify your current compliance posture. Our AI advisory can answer specific questions about NY DFS 23 NYCRR 500 requirements, and cross-framework mapping helps you leverage existing controls from other frameworks you may already comply with. Create a free account to access all 23 controls and track your progress.

Start Your Compliance Journey

Create a free account to run self-assessments, get AI advisory, and track your compliance progress across 868 frameworks.

Get Started Free →

Free forever — no credit card required