
The General Data Protection Regulation (GDPR) is a legal framework that sets guidelines for the collection and processing of personal information of the European Union (EU) data subjects. The GDPR protects the rights and freedoms of personal information in the attempts to prevent data breaches from occurring.The GDPR also imposes fines on entities that do not maintain compliance with the mandates.GDPR went into effect on May 25, 2018.
The FTC's Standards for Safeguarding Customer Information Rule ('Safeguards Rule') was created to safeguard the security of customer information.
Canada's Personal Information Protection and Electronic Document's Act (PIPEDA) applies tocorporations in Canada that "collect, use or disclose personal information in the course of a commercial activity."PIPEDA defines a commercial activirty as "any particular transaction, act, or conduct, or any regular course of conduct that is of a commercial character, including the selling, bartering, or leasing of donor, membership, or other fundraising lists."
Various forms of information are protected under the Cybersecurity Regulation.
Learn MoreThe CIA Triad represents the three pillars of information security: confidentiality, integrity, and availability The triad is a benchmark model for information securrity programs as each attribute represents an important aspect of information security.
Learn MoreThe term confidentiality means preserving authorized restrictions on access and disclosure, including means for protecting personal privacy and proprietary information.
Learn MoreIntegrity means guarding against improper information modification or destruction. and includes ensuring information authenticity
Learn MoreAvailability means ensuring timely and reliable access to and use of information
Learn MoreSince the original 2017 version of the Cybersecurity Regulation, Covered Entities were required to notify the DFS of any cybersecurity event. See 23 NYCRR 500.1(f), (g). In the most recent amendment to 23 NYCRR 500, Covered Entities are required to notify NYDFS of a qualifying "cybersecurity incident." See 23 NYCRR 500.1(f), (g).
Cybersecurity Event: any act or attempt, successful or unsuccessful, to gain unauthorized access to, disrupt or misuse an Information System or information stored on such Information System
Cybersecurity Incident: a cybersecurity event that has occurred at the covered entity, its affiliates, or a third-party service provider that:
1) impacts the covered entity and requires the convered entity to notify any government body, self-regulatory agency or any other supervisory body;
2) has a reasonable likelihood of materially harming any material part of the normal operation(s) of the covered entity; or
3) results in the deployment of ransomware within a material part of the covered entity's information systems.
WHY is this important?
The original cybersecurity event definition generally covered malicious attacks on confidentiality, integrity, and availability, it mandates a continuous notification scheme to DFS.
In the recent amendments, cybersecurity incidents do not have to be situations where there was a malicious actor; but rather any flaw found within a Covered Entity's systems that impact the Entity, or have a reasonable likelihood of harming the Entity must not be reported.
