Controls / Sector rules (add-ons)
The business knows the notice its rule requires after an incident or a data breach, to whom and by when
What the applicant reports, the rules behind it in each jurisdiction, and the evidence an assessor asks for. In the applicant's words: write down the notice your rule requires after an incident or a data breach: to whom, and by when.
In the United States
FTC Safeguards Rule, when it applies
Financial institutions under FTC jurisdiction, for example tax preparers, mortgage brokers and auto dealers that arrange financing.
| Clause | The held text, and the evidence an assessor asks for |
|---|---|
| 314.4(j)(1) FTC Safeguards Rule (add-on) | 314.4(j)(1) Notice to the FTC within 30 days of a notification event affecting 500 or more consumers On discovering a notification event (the unauthorised acquisition of unencrypted customer information) involving the information of at least 500 consumers, the institution notifies the FTC as soon as possible and no later than 30 days after discovery, electronically on the form on the FTC's website, giving its name and contact information, a description of the types of information involved, the date or date range if determinable, the number of consumers affected or potentially affected, a general description of the event, and whether a law enforcement official has provided a written determination that public notification would impede a criminal investigation or damage national security, with a means for the FTC to contact that official. The requirement's own words: no later than 30 days after discovery evidence an assessor asks for Notification procedure with the 500-consumer threshold, 30-day clock and the six content items; Records of notifications made and law enforcement determinations |
23 NYCRR 500, when it applies
Entities licensed by the New York Department of Financial Services. Section 500.19 sets limited exemptions for smaller covered entities: whether one applies is a question for the business, and this page never decides it.
| Clause | The held text, and the evidence an assessor asks for |
|---|---|
| 500.17 23 NYCRR 500 (add-on) | Notices to Superintendent Notify the Superintendent within 72 hours of a Cybersecurity Incident affecting the Covered Entity. Provide notice of extortion payment within 24 hours, with detailed explanation within 30 days. File annual Notice of Compliance or Acknowledgment of Noncompliance by April 15 signed by highest-ranking executive and CISO. Maintain supporting records for five years. The requirement's own words: within 72 hours of a Cybersecurity Incident; within 24 hours; within 30 days evidence an assessor asks for Incident notification SOP with ยง500.17(a) criteria; Sample submitted 72-hour notices through the Department's portal; 24-hour ransom payment notice procedure and 30-day explanation template; Signed annual Notice of Compliance covering prior calendar year; Acknowledgment of Noncompliance with remediation plan if applicable; Five-year retention of supporting records and schedules; Internal escalation runbook ensuring CISO and CEO sign-off |
Questions
- What does the applicant report for this control?
- Whether it is in place, partly in place, not in place or not sure. Partly, not in place and not sure are gaps; not sure reads as a question.
- When is it due on the 90-day schedule?
- Day 90 by the default rule: a sector add-on line. The underwriter or broker can move it.
- Does this page check the control?
- No. The applicant reports a closure with a date and a note; the schedule records it as reported and never checks it.