New York Codes Rules Regulations (Last Updated: March 27,2024) |
TITLE 11. Insurance |
Chapter XIX. Privacy of Consumer FinancialandHealth Information |
Part 421. Standards for Safeguarding Customer Information |
Development and Implementation of Information Security Program |
Sec. 421.6. Manage and control risk
Latest version.
- The licensee:(a) designs its information security program to control the identified risks, commensurate with the sensitivity of the information as well as the complexity and scope of the licensee's activities;(b) trains staff, as appropriate, to implement the licensee's information security program; and(c) regularly tests the key controls, systems and procedures of the information security program. The frequency and nature of such tests are determined by the licensee's risk assessment.