/nydfs-expert
NYDFS 23 NYCRR 500 expert for financial services. Deep knowledge of New York Department of Financial Services cybersecurity requirements including all 23 sections, annual certification, CISO requirements, penetration testing, incident notification, and third-party risk
$ npx -y skills add GRCEngClub/claude-grc-engineering --skill nydfs-expert --agent claude-codeHow it fires
How this skill gets triggered: by you, by Claude, or both.
- Fires itselfAuto-invocation. Claude auto-loads it when your prompt matches the work.
- You can call itInvoke it directly when you want it.
- Slash command
/nydfs-expert
Context preview
The summary Claude sees to decide when to auto-load this skill.
NYDFS 23 NYCRR 500 expert for financial services. Deep knowledge of New York Department of Financial Services cybersecurity requirements including all 23 sections, annual certification, CISO requirements, penetration testing, incident notification, and third-party risk
SKILL.md
nydfs-expert.SKILL.mdname: nydfs-expert
description: NYDFS 23 NYCRR 500 expert for financial services. Deep knowledge of New York Department of Financial Services cybersecurity requirements including all 23 sections, annual certification, CISO requirements, penetration testing, incident notification, and third-party risk management.
allowed-tools: Read, Glob, Grep, Write
NYDFS Expert
Deep expertise in New York Department of Financial Services (NYDFS) 23 NYCRR 500 cybersecurity requirements for financial services institutions.
Expertise Areas
NYDFS 23 NYCRR 500 Overview
**Official Title**: "Cybersecurity Requirements for Financial Services Companies" **Authority**: New York Department of Financial Services (Superintendent) **Effective Date**: March 1, 2017 (phased implementation through February 2019) **Major Amendment**: November 1, 2023 (significant updates) **Scope**: Financial services institutions operating in New York State **Annual Certification**: Due April 15 each year
**Regulatory Authority**:
- NY Financial Services Law Section 201
- NY Insurance Law Section 302
- NY Banking Law Article 2
- Superintendent's emergency rulemaking authority
**Purpose**:
- Protect consumer financial data
- Ensure operational resilience of financial sector
- Establish minimum cybersecurity standards
- Promote cybersecurity risk management culture
- Align NY with leading cybersecurity practices
Covered Entities
**Financial Institutions Subject to 23 NYCRR 500**:
- State-chartered banks
- Foreign bank branches in NY
- Trust companies and private bankers
- Insurance companies (life, health, P&C)
- Insurance agents and brokers
- Licensed lenders and mortgage companies
- Money transmitters
- Virtual currency businesses (BitLicense)
- Premium finance agencies
- Any entity operating under NYDFS supervision
**Exemptions from Coverage**:
- Entities exempt from licensing
- Entities with <10 employees, <$5M revenue, <$10M assets (limited exemptions for certain requirements)
- Charitable organizations (some)
**Affiliate Entities**:
- Parent companies may be covered
- Subsidiaries subject if meet criteria
- Shared services models common
23 Sections Deep Dive
**500.00 - Introduction**
Purpose and scope of regulation.
**500.01 - Definitions**
**Key Defined Terms**:
- **Affiliate**: Entity that controls, is controlled by, or is under common control
- **Authorized User**: Person with access to Information Systems
- **Board of Directors**: Governing body or senior officer(s)
- **Covered Entity**: Entity required to comply with 23 NYCRR 500
- **Cybersecurity Event**: Act that threatens confidentiality, integrity, or availability
- **Information System**: Systems owned/operated by covered entity or service providers
- **Multi-Factor Authentication**: At least two of: knowledge, possession, inherence
- **Nonpublic Information**: Business-related information not publicly available + private customer information
- **Penetration Testing**: Simulated attack to identify exploitable vulnerabilities
- **Privileged Account**: Account with elevated access rights
- **Risk Assessment**: Process to identify reasonably foreseeable threats
- **Senior Officer**: Senior executive with regular contact with Board
- **Service Provider**: Third party granted access to Information Systems or Nonpublic Information
**500.02 - Cybersecurity Program**
**Requirements**:
- Maintain cybersecurity program based on Risk Assessment
- Written policies and procedures
- Protect confidentiality, integrity, and availability
- NIST Cybersecurity Framework alignment (recommended)
**Program Elements Must Include**:
- Information security
- Data governance and classification
- Asset inventory and device management
- Access controls and identity management
- Business continuity and disaster recovery
- Systems operations and availability
- Systems and network security
- Systems and application development
- Physical security and environmental controls
- Customer data privacy
- Vendor and third-party management
- Risk assessment
- Incident response
**Risk-Based Approach**:
- Tailor to size, complexity, resources
- Focus on material risks
- Document risk-based decisions
- CISO approval of risk-based approaches
**500.03 - Cybersecurity Policy**
**Written Policy Required**:
- Board of Directors approved
- Addresses all areas in 500.02
- Reviewed and updated regularly
- Communicated to personnel
**Policy Must Address**:
1. Information security 2. Data governance and classification 3. Asset inventory and device management 4. Access controls and identity management 5. Business continuity and disaster recovery planning 6. Systems operations and availability concerns 7. Systems and network security 8. Systems and application development and quality assurance 9. Physical security and environmental controls 10. Customer data privacy 11. Vendor and third-party service provider management 12. Risk assessment 13. Incident response
**Board Approval**:
- Annual review minimum
- Documented Board approval
- Updates as needed
- Version control
**500.04 - Chief Information Security Officer (CISO)**
**CISO Requirement**:
- Designated qualified individual
- Can be employee, affiliate, or third-party
- Oversees and implements cybersecurity program
- Enforces cybersecurity policy
- Reports to Board of Directors or Senior Officer
**CISO Responsibilities**:
- Program oversight and implementation
- Policy development and enforcement
- Annual risk assessment
- Board reporting
- Incident response leadership
- Third-party risk oversight
- Compliance management
- Resource planning
**Reporting**:
- To Board or Senior Officer
- Annual report minimum
- Incident notifications
- Material changes (15-day notice)
**Qualifications**:
- Adequate expertise and resources
- Financial services experience (preferred)
- Regulatory compliance knowledge
- Technical and leadership skills
**Material Change Notification** (500.18):
- 15
Read more
name: nydfs-expert description: NYDFS 23 NYCRR 500 expert for financial services. Deep knowledge of New York Department of Financial Services cybersecurity requirements including all 23 sections, annual certification, CISO requirements, penetration testing, incident notification, and third-party risk management. allowed-tools: Read, Glob, Grep, Write
NYDFS Expert
Deep expertise in New York Department of Financial Services (NYDFS) 23 NYCRR 500 cybersecurity requirements for financial services institutions.
Expertise Areas
NYDFS 23 NYCRR 500 Overview
**Official Title**: "Cybersecurity Requirements for Financial Services Companies" **Authority**: New York Department of Financial Services (Superintendent) **Effective Date**: March 1, 2017 (phased implementation through February 2019) **Major Amendment**: November 1, 2023 (significant updates) **Scope**: Financial services institutions operating in New York State **Annual Certification**: Due April 15 each year
**Regulatory Authority**:
- NY Financial Services Law Section 201
- NY Insurance Law Section 302
- NY Banking Law Article 2
- Superintendent's emergency rulemaking authority
**Purpose**:
- Protect consumer financial data
- Ensure operational resilience of financial sector
- Establish minimum cybersecurity standards
- Promote cybersecurity risk management culture
- Align NY with leading cybersecurity practices
Covered Entities
**Financial Institutions Subject to 23 NYCRR 500**:
- State-chartered banks
- Foreign bank branches in NY
- Trust companies and private bankers
- Insurance companies (life, health, P&C)
- Insurance agents and brokers
- Licensed lenders and mortgage companies
- Money transmitters
- Virtual currency businesses (BitLicense)
- Premium finance agencies
- Any entity operating under NYDFS supervision
**Exemptions from Coverage**:
- Entities exempt from licensing
- Entities with <10 employees, <$5M revenue, <$10M assets (limited exemptions for certain requirements)
- Charitable organizations (some)
**Affiliate Entities**:
- Parent companies may be covered
- Subsidiaries subject if meet criteria
- Shared services models common
23 Sections Deep Dive
**500.00 - Introduction**
Purpose and scope of regulation.
**500.01 - Definitions**
**Key Defined Terms**:
- **Affiliate**: Entity that controls, is controlled by, or is under common control
- **Authorized User**: Person with access to Information Systems
- **Board of Directors**: Governing body or senior officer(s)
- **Covered Entity**: Entity required to comply with 23 NYCRR 500
- **Cybersecurity Event**: Act that threatens confidentiality, integrity, or availability
- **Information System**: Systems owned/operated by covered entity or service providers
- **Multi-Factor Authentication**: At least two of: knowledge, possession, inherence
- **Nonpublic Information**: Business-related information not publicly available + private customer information
- **Penetration Testing**: Simulated attack to identify exploitable vulnerabilities
- **Privileged Account**: Account with elevated access rights
- **Risk Assessment**: Process to identify reasonably foreseeable threats
- **Senior Officer**: Senior executive with regular contact with Board
- **Service Provider**: Third party granted access to Information Systems or Nonpublic Information
**500.02 - Cybersecurity Program**
**Requirements**:
- Maintain cybersecurity program based on Risk Assessment
- Written policies and procedures
- Protect confidentiality, integrity, and availability
- NIST Cybersecurity Framework alignment (recommended)
**Program Elements Must Include**:
- Information security
- Data governance and classification
- Asset inventory and device management
- Access controls and identity management
- Business continuity and disaster recovery
- Systems operations and availability
- Systems and network security
- Systems and application development
- Physical security and environmental controls
- Customer data privacy
- Vendor and third-party management
- Risk assessment
- Incident response
**Risk-Based Approach**:
- Tailor to size, complexity, resources
- Focus on material risks
- Document risk-based decisions
- CISO approval of risk-based approaches
**500.03 - Cybersecurity Policy**
**Written Policy Required**:
- Board of Directors approved
- Addresses all areas in 500.02
- Reviewed and updated regularly
- Communicated to personnel
**Policy Must Address**:
1. Information security 2. Data governance and classification 3. Asset inventory and device management 4. Access controls and identity management 5. Business continuity and disaster recovery planning 6. Systems operations and availability concerns 7. Systems and network security 8. Systems and application development and quality assurance 9. Physical security and environmental controls 10. Customer data privacy 11. Vendor and third-party service provider management 12. Risk assessment 13. Incident response
**Board Approval**:
- Annual review minimum
- Documented Board approval
- Updates as needed
- Version control
**500.04 - Chief Information Security Officer (CISO)**
**CISO Requirement**:
- Designated qualified individual
- Can be employee, affiliate, or third-party
- Oversees and implements cybersecurity program
- Enforces cybersecurity policy
- Reports to Board of Directors or Senior Officer
**CISO Responsibilities**:
- Program oversight and implementation
- Policy development and enforcement
- Annual risk assessment
- Board reporting
- Incident response leadership
- Third-party risk oversight
- Compliance management
- Resource planning
**Reporting**:
- To Board or Senior Officer
- Annual report minimum
- Incident notifications
- Material changes (15-day notice)
**Qualifications**:
- Adequate expertise and resources
- Financial services experience (preferred)
- Regulatory compliance knowledge
- Technical and leadership skills
**Material Change Notification** (500.18):
- 15
Showing the first part of this file.
Open-source GRC Engineering resource for Claude. claude-grc-engineering turns technical evidence from cloud, SaaS, code, and security tools into framework-aligned findings, gap reports, remediation guidance, evidence packages, and OSCAL workflows.
Repo: GRCEngClub/claude-grc-engineering
Other skills on trust-center.
- /academic-research-companion
Guide a research project through the full academic lifecycle — from raw idea to concrete research question, literature grounding, methodology, writing, feedback, and publication. Use this skill whenever the user shares a research idea, asks to "flesh out" a topic, wants sources
Open skill - /aws-inspector-expert
Expertise in evaluating AWS accounts for compliance — what checks are meaningful, which SCF controls they map to, and how to interpret aws CLI output.
Open skill - /azure-inspector-expert
Expertise in evaluating Azure subscription findings from azure-inspector and mapping them to SCF controls.
Open skill - /crowdstrike-inspector-expert
Interpret CrowdStrike Falcon findings for sensor coverage, policy visibility, and host group scoping.
Open skill - /datadog-inspector-expert
Interpret datadog-inspector findings and translate Datadog monitoring, audit, log-retention, SSO, and RBAC results into GRC evidence and remediation.
Open skill - /drata-inspector-expert
Interpret drata-inspector findings generated from drata-cli workflows and turn Drata control, monitor, evidence, personnel, and integration posture into GRC action.
Open skill

