Artwork

Контент предоставлен G Mark Hardy & Ross Young, G Mark Hardy, and Ross Young. Весь контент подкастов, включая эпизоды, графику и описания подкастов, загружается и предоставляется непосредственно компанией G Mark Hardy & Ross Young, G Mark Hardy, and Ross Young или ее партнером по платформе подкастов. Если вы считаете, что кто-то использует вашу работу, защищенную авторским правом, без вашего разрешения, вы можете выполнить процедуру, описанную здесь https://ru.player.fm/legal.
Player FM - приложение для подкастов
Работайте офлайн с приложением Player FM !

#175 - Navigating NYDFS Cyber Regulation

33:24
 
Поделиться
 

Manage episode 409977214 series 2849492
Контент предоставлен G Mark Hardy & Ross Young, G Mark Hardy, and Ross Young. Весь контент подкастов, включая эпизоды, графику и описания подкастов, загружается и предоставляется непосредственно компанией G Mark Hardy & Ross Young, G Mark Hardy, and Ross Young или ее партнером по платформе подкастов. Если вы считаете, что кто-то использует вашу работу, защищенную авторским правом, без вашего разрешения, вы можете выполнить процедуру, описанную здесь https://ru.player.fm/legal.

This episode of CISO Tradecraft dives deep into the New York Department of Financial Services Cybersecurity Regulation, known as Part 500. Hosted by G Mark Hardy, the podcast outlines the significance of this regulation for financial services companies and beyond. Hardy emphasizes that Part 500 serves as a high-level framework applicable not just in New York or the financial sector but across various industries globally due to its comprehensive cybersecurity requirements. The discussion includes an overview of the regulation's history, amendments to enhance governance and incident response, and a detailed analysis of key sections such as multi-factor authentication, audit trails, access privilege management, and incident response. Additionally, the need for written policies, designating a Chief Information Security Officer (CISO), and ensuring adequate resources for implementing a cybersecurity program are highlighted. The podcast also offers guidance on how to approach certain regulatory mandates, emphasizing the importance of teamwork between CISOs, legal teams, and executive management to comply with and benefit from the regulation's requirements.

AuditScripts: https://www.auditscripts.com/free-resources/critical-security-controls/

NYDFS: https://www.dfs.ny.gov/industry_guidance/cybersecurity

Transcripts: https://docs.google.com/document/d/1CWrhNjHXG1rePtOQT-iHyhed2jfBaZud

Chapters

  • 00:00 Introduction
  • 00:35 Why Part 500 Matters Beyond New York
  • 01:48 The Evolution of Financial Cybersecurity Regulations
  • 03:20 Understanding Part 500: Definitions and Amendments
  • 08:44 The Importance of Multi-Factor Authentication
  • 14:33 Navigating the Complexities of Cybersecurity Regulations
  • 20:23 The Critical Role of Asset Management and Access Privileges 25:37 The Essentials of Application Security and Risk Assessment
  • 31:11 Incident Response and Business Continuity Management
  • 32:36 Concluding Thoughts on NYDFS Cybersecurity Regulation
  continue reading

179 эпизодов

Artwork
iconПоделиться
 
Manage episode 409977214 series 2849492
Контент предоставлен G Mark Hardy & Ross Young, G Mark Hardy, and Ross Young. Весь контент подкастов, включая эпизоды, графику и описания подкастов, загружается и предоставляется непосредственно компанией G Mark Hardy & Ross Young, G Mark Hardy, and Ross Young или ее партнером по платформе подкастов. Если вы считаете, что кто-то использует вашу работу, защищенную авторским правом, без вашего разрешения, вы можете выполнить процедуру, описанную здесь https://ru.player.fm/legal.

This episode of CISO Tradecraft dives deep into the New York Department of Financial Services Cybersecurity Regulation, known as Part 500. Hosted by G Mark Hardy, the podcast outlines the significance of this regulation for financial services companies and beyond. Hardy emphasizes that Part 500 serves as a high-level framework applicable not just in New York or the financial sector but across various industries globally due to its comprehensive cybersecurity requirements. The discussion includes an overview of the regulation's history, amendments to enhance governance and incident response, and a detailed analysis of key sections such as multi-factor authentication, audit trails, access privilege management, and incident response. Additionally, the need for written policies, designating a Chief Information Security Officer (CISO), and ensuring adequate resources for implementing a cybersecurity program are highlighted. The podcast also offers guidance on how to approach certain regulatory mandates, emphasizing the importance of teamwork between CISOs, legal teams, and executive management to comply with and benefit from the regulation's requirements.

AuditScripts: https://www.auditscripts.com/free-resources/critical-security-controls/

NYDFS: https://www.dfs.ny.gov/industry_guidance/cybersecurity

Transcripts: https://docs.google.com/document/d/1CWrhNjHXG1rePtOQT-iHyhed2jfBaZud

Chapters

  • 00:00 Introduction
  • 00:35 Why Part 500 Matters Beyond New York
  • 01:48 The Evolution of Financial Cybersecurity Regulations
  • 03:20 Understanding Part 500: Definitions and Amendments
  • 08:44 The Importance of Multi-Factor Authentication
  • 14:33 Navigating the Complexities of Cybersecurity Regulations
  • 20:23 The Critical Role of Asset Management and Access Privileges 25:37 The Essentials of Application Security and Risk Assessment
  • 31:11 Incident Response and Business Continuity Management
  • 32:36 Concluding Thoughts on NYDFS Cybersecurity Regulation
  continue reading

179 эпизодов

ทุกตอน

×
 
Loading …

Добро пожаловать в Player FM!

Player FM сканирует Интернет в поисках высококачественных подкастов, чтобы вы могли наслаждаться ими прямо сейчас. Это лучшее приложение для подкастов, которое работает на Android, iPhone и веб-странице. Зарегистрируйтесь, чтобы синхронизировать подписки на разных устройствах.

 

Краткое руководство