New York Codes Rules Regulations (Last Updated: March 27,2024) |
TITLE 11. Insurance |
Chapter XIX. Privacy of Consumer FinancialandHealth Information |
Part 421. Standards for Safeguarding Customer Information |
Development and Implementation of Information Security Program |
Sec. 421.5. Assess risk
Latest version.
- The licensee:(a) identifies reasonably foreseeable internal or external threats that could result in unauthorized disclosure, misuse, alteration, or destruction of customer information or customer information systems;(b) assesses the likelihood and potential damage of these threats, taking into consideration the sensitivity of customer information; and(c) assesses the sufficiency of policies, procedures, customer information systems, and other arrangements in place to control risks.