academic-research-comp…
Guide a research project through the full academic lifecycle — from raw idea to concrete research question, literature grounding, methodology, writing,…
NYDFS 23 NYCRR 500 expert for financial services. Deep knowledge of New York Department of Financial Services cybersecurity requirements including all 23 sections, annual certification, CISO requirements, penetration testing, incident notification, and third-party risk
$ npx -y skills add GRCEngClub/claude-grc-engineering --skill nydfs-expert --agent claude-codeHow it fires
How this skill gets triggered: by you, by Claude, or both.
/nydfs-expertContext preview
The summary Claude sees to decide when to auto-load this skill.
NYDFS 23 NYCRR 500 expert for financial services. Deep knowledge of New York Department of Financial Services cybersecurity requirements including all 23 sections, annual certification, CISO requirements, penetration testing, incident notification, and third-party risk
name: nydfs-expert description: NYDFS 23 NYCRR 500 expert for financial services. Deep knowledge of New York Department of Financial Services cybersecurity requirements including all 23 sections, annual certification, CISO requirements, penetration testing, incident notification, and third-party risk management. allowed-tools: Read, Glob, Grep, Write
Deep expertise in New York Department of Financial Services (NYDFS) 23 NYCRR 500 cybersecurity requirements for financial services institutions.
**Official Title**: "Cybersecurity Requirements for Financial Services Companies" **Authority**: New York Department of Financial Services (Superintendent) **Effective Date**: March 1, 2017 (phased implementation through February 2019) **Major Amendment**: November 1, 2023 (significant updates) **Scope**: Financial services institutions operating in New York State **Annual Certification**: Due April 15 each year
**Regulatory Authority**:
**Purpose**:
**Financial Institutions Subject to 23 NYCRR 500**:
**Exemptions from Coverage**:
**Affiliate Entities**:
Purpose and scope of regulation.
**Key Defined Terms**:
**Requirements**:
**Program Elements Must Include**:
**Risk-Based Approach**:
**Written Policy Required**:
**Policy Must Address**:
1. Information security 2. Data governance and classification 3. Asset inventory and device management 4. Access controls and identity management 5. Business continuity and disaster recovery planning 6. Systems operations and availability concerns 7. Systems and network security 8. Systems and application development and quality assurance 9. Physical security and environmental controls 10. Customer data privacy 11. Vendor and third-party service provider management 12. Risk assessment 13. Incident response
**Board Approval**:
**CISO Requirement**:
**CISO Responsibilities**:
**Reporting**:
**Qualifications**:
**Material Change Notification** (500.18):
Open-source GRC Engineering resource for Claude. claude-grc-engineering turns technical evidence from cloud, SaaS, code, and security tools into framework-aligned findings, gap reports, remediation guidance, evidence packages, and OSCAL workflows.
Repo: GRCEngClub/claude-grc-engineering
Guide a research project through the full academic lifecycle — from raw idea to concrete research question, literature grounding, methodology, writing,…
Expertise in evaluating AWS accounts for compliance — what checks are meaningful, which SCF controls they map to, and how to interpret aws CLI output.
Use when interpreting AWS Secrets Manager connector output, deciding between inspector and retrieve modes, drafting SCF-mapped controls for rotation / KMS /…
Expertise in evaluating Azure subscription findings from azure-inspector and mapping them to SCF controls.
Interpret CrowdStrike Falcon findings for sensor coverage, policy visibility, and host group scoping.
Interpret datadog-inspector findings and translate Datadog monitoring, audit, log-retention, SSO, and RBAC results into GRC evidence and remediation.