01
Programme Framework
Part 500 architecture · 2023 amendments · Class A overlay
02
Covered Entity Scope
Live JS · standard vs Class A vs limited exemption
03
CISO Role
Designation · qualifications · authority · annual report
04
Risk Assessment
Annual · NYDFS-aligned · evidence retention
05
Governance & Senior Mgmt
Board / senior-officer oversight · governance documentation
06
MFA / Encryption / Access
Privileged access · MFA · encryption · password discipline
07
Vendor Management
Third-party DD · contractual standards · monitoring
08
Incident Reporting (72-hr)
Trigger · DFS portal · cybersecurity event · ransomware
09
Ransomware Payment
24-hour pre-notification · OFAC overlay · post-payment report
10
Training & Awareness
Annual · phishing · BSA / sanctions overlay
11
Annual CISO Certification
Apr 15 deadline · scope · written acknowledgement
12
Examination Readiness
DFS exam pack · evidence inventory · attestation history
13
Committee Charter
CISO chair · CCO · CTO · GC · cadence · authority