NYDFS covered entities

NYDFS 23 NYCRR 500 Technical Evidence Support

Show what the control did, not only what the policy says. Technical testing connects governance claims to identities, assets, configurations, logs, tickets, exceptions, and retest evidence.

Bagged hard drive beside a forensic write blocker.

The engagement

Policy statement, mapped to observable records

Organizations subject to 23 NYCRR Part 500 need more than policy language. GDF supports security and compliance teams with technical evidence concerning asset inventory (500.9), risk assessment (500.9), vulnerability management and penetration testing (500.5), access control and MFA (500.7 and 500.12), logging and audit trail (500.6), incident response (500.16), and 72-hour cybersecurity event notification (500.17).

Counsel determines regulatory interpretation and reporting obligations. GDF produces the underlying technical record on which the covered entity's CISO report (500.4), the annual certification of material compliance (500.17(b)), and internal audit assurances rest.

A test plan identifies the policy statement, system owner, technical implementation, evidence source, population, sample, expected result, exception path, and retest method. The work is designed to coexist with internal audit, outside counsel, and existing governance platforms.

Scope

  • Asset and scope reconciliation

    Information systems and nonpublic information mapped across identity providers, endpoint agents, cloud tenants, application inventories, and third-party services. Excluded populations are documented.

  • Penetration testing and vulnerability program evidence

    Annual penetration test and biannual vulnerability assessment cadence documented against 500.5. Coverage reconciled to inventory. Findings tracked through remediation, exception approval, and retest.

  • Privileged access and identity control

    Account inventories, privileged access reviews, MFA enforcement records under 500.12, and periodic review evidence. Break-glass and service account use is documented and reviewable.

  • Logging, monitoring, and retention

    Audit trail evidence under 500.6: log sources, retention periods, tamper protection, and monitoring workflows. Retention decisions are recorded with the business and evidentiary rationale.

  • Incident response and recovery evidence

    Incident response plan (500.16) tested against actual events and exercises. Recovery evidence, decision logs, and 500.17 event notification records are collected in reviewable form.

  • Third-party and vendor risk

    Third-party service provider records supporting 500.11: due diligence, contractual protections, monitoring, and periodic reassessment. Access reviews for vendor identities are documented.

  • Remediation and exception packaging

    Material findings tracked through vulnerability remediation, owner response, exception approval, and technical retest. Exception population and expiration dates are visible.

Methodology

How Part 500 evidence work runs

  1. Scope

    Covered assets, information systems, and third-party services are identified. The review period, Part 500 requirement version, and prior findings inform sample design.

  2. Collect

    Configuration exports, identity records, scan coverage, tickets, log configurations, and incident and vendor records are collected with source, date, and operator.

  3. Test

    Populations are sampled; expected results are compared with observed behavior. Exceptions become tracked items with owner, correction plan, and retest date.

  4. Package

    Evidence is indexed by Part 500 section, cross-referenced to source system, and organized for CISO reporting, internal audit, and DFS examiner review.

Evidence commonly examined

Evidence reviewed

  • Asset, identity, and application inventories reconciled
  • Penetration test and vulnerability scan reports with coverage
  • Privileged access and MFA enforcement records
  • Log source inventories, retention configurations, and monitoring records
  • Incident response plan, exercise records, and event notification files
  • Vendor due diligence, monitoring, and reassessment records

What you can expect

What you receive

  • Evidence map from Part 500 section to source system
  • Section-by-section evidence package with sampling notes
  • Exception and corrective-action register with owner and dates
  • Retest evidence for material findings
  • CISO-ready summary aligned to the 500.4 annual reporting cycle

Frequently asked

Common questions

Do you issue a legal compliance opinion or certification?

No. GDF produces the underlying technical record. The covered entity's CISO, general counsel, and where relevant its board committee retain interpretation, certification, and reporting.

How is the annual penetration test scoped?

Scope is defined against the information systems in 500.1, coverage reconciled to inventory, and testing performed by qualified practitioners. Findings feed the risk register and the remediation and retest workflow.

Can you help prepare for a DFS examination?

Yes. GDF can support mock reviews of technical evidence, help package materials for the examiner, and identify gaps for correction before formal submission. Legal representation to DFS remains with counsel.

Talk with an examiner

Discuss the matter and the next step.

Call to discuss timing, scope and the safest way to share information. Do not send evidence or credentials by email.

24/7 hotline: 1-800-868-8189

Privacy center

Choose your site settings

Optional technology stays off until you choose otherwise. You can change these browser settings at any time. Access to the core site does not depend on optional technologies.

Technology preferences
Sale or cross-context sharing: not used GDF does not sell or share website personal information for cross-context behavioral advertising.