NYDFS covered entities
NYDFS 23 NYCRR 500 Technical Evidence Support
Show what the control did, not only what the policy says. Technical testing connects governance claims to identities, assets, configurations, logs, tickets, exceptions, and retest evidence.
The engagement
Policy statement, mapped to observable records
Organizations subject to 23 NYCRR Part 500 need more than policy language. GDF supports security and compliance teams with technical evidence concerning asset inventory (500.9), risk assessment (500.9), vulnerability management and penetration testing (500.5), access control and MFA (500.7 and 500.12), logging and audit trail (500.6), incident response (500.16), and 72-hour cybersecurity event notification (500.17).
Counsel determines regulatory interpretation and reporting obligations. GDF produces the underlying technical record on which the covered entity's CISO report (500.4), the annual certification of material compliance (500.17(b)), and internal audit assurances rest.
A test plan identifies the policy statement, system owner, technical implementation, evidence source, population, sample, expected result, exception path, and retest method. The work is designed to coexist with internal audit, outside counsel, and existing governance platforms.
Scope
Asset and scope reconciliation
Information systems and nonpublic information mapped across identity providers, endpoint agents, cloud tenants, application inventories, and third-party services. Excluded populations are documented.
Penetration testing and vulnerability program evidence
Annual penetration test and biannual vulnerability assessment cadence documented against 500.5. Coverage reconciled to inventory. Findings tracked through remediation, exception approval, and retest.
Privileged access and identity control
Account inventories, privileged access reviews, MFA enforcement records under 500.12, and periodic review evidence. Break-glass and service account use is documented and reviewable.
Logging, monitoring, and retention
Audit trail evidence under 500.6: log sources, retention periods, tamper protection, and monitoring workflows. Retention decisions are recorded with the business and evidentiary rationale.
Incident response and recovery evidence
Incident response plan (500.16) tested against actual events and exercises. Recovery evidence, decision logs, and 500.17 event notification records are collected in reviewable form.
Third-party and vendor risk
Third-party service provider records supporting 500.11: due diligence, contractual protections, monitoring, and periodic reassessment. Access reviews for vendor identities are documented.
Remediation and exception packaging
Material findings tracked through vulnerability remediation, owner response, exception approval, and technical retest. Exception population and expiration dates are visible.
Methodology
How Part 500 evidence work runs
-
Scope
Covered assets, information systems, and third-party services are identified. The review period, Part 500 requirement version, and prior findings inform sample design.
-
Collect
Configuration exports, identity records, scan coverage, tickets, log configurations, and incident and vendor records are collected with source, date, and operator.
-
Test
Populations are sampled; expected results are compared with observed behavior. Exceptions become tracked items with owner, correction plan, and retest date.
-
Package
Evidence is indexed by Part 500 section, cross-referenced to source system, and organized for CISO reporting, internal audit, and DFS examiner review.
Evidence commonly examined
Evidence reviewed
- Asset, identity, and application inventories reconciled
- Penetration test and vulnerability scan reports with coverage
- Privileged access and MFA enforcement records
- Log source inventories, retention configurations, and monitoring records
- Incident response plan, exercise records, and event notification files
- Vendor due diligence, monitoring, and reassessment records
What you can expect
What you receive
- Evidence map from Part 500 section to source system
- Section-by-section evidence package with sampling notes
- Exception and corrective-action register with owner and dates
- Retest evidence for material findings
- CISO-ready summary aligned to the 500.4 annual reporting cycle
Frequently asked
Common questions
Do you issue a legal compliance opinion or certification?
No. GDF produces the underlying technical record. The covered entity's CISO, general counsel, and where relevant its board committee retain interpretation, certification, and reporting.
How is the annual penetration test scoped?
Scope is defined against the information systems in 500.1, coverage reconciled to inventory, and testing performed by qualified practitioners. Findings feed the risk register and the remediation and retest workflow.
Can you help prepare for a DFS examination?
Yes. GDF can support mock reviews of technical evidence, help package materials for the examiner, and identify gaps for correction before formal submission. Legal representation to DFS remains with counsel.
Related capabilities
Related services
Talk with an examiner
Discuss the matter and the next step.
Call to discuss timing, scope and the safest way to share information. Do not send evidence or credentials by email.
24/7 hotline: 1-800-868-8189