AWS Disruption Spurs Regulatory Focus on Third-Party Risk Management
… the New York State Department of Financial Services (NYS DFS) issued guidance (the “Guidance”) to all executives and information security personnel at all entities regulated by NYS DFS. The Guidance clarifies the related requirements under the department’s Cybersecurity Regulation related to TPSPs and outlines best practices for third-party risk mitigation and management. The key areas of focus outlined in the Guidance are: 1. Identification, Due Diligence, and Selection Assess TPSPs’ cybersecurity posture before engagement. Classify TPSPs by risk level and evaluate controls, data handling, and certifications. Use tools like questionnaires and interviews to validate claims. 2. Contracting Include …
https://www.epicbrokers.com/insights/aws-disruption-spurs-regulatory-focus-third-party-risk-management/