What is the NY SHIELD Act?
The New York Stop Hacks and Improve Electronic Data Security Act (SHIELD Act, NY General Business Law Section 899-bb, effective March 2020) imposes reasonable security obligations on any business that owns or licenses private information of a NY resident, regardless of where the business is located. Section 899-bb(2)(b)(II) explicitly itemizes 8 technical-safeguard areas. The NY Attorney General actively enforces with public settlement orders.
The longer answer.
The SHIELD Act applies to any business that owns or licenses private information of New York residents, wherever the business is located. The New York Attorney General enforces it, with civil penalties of up to 5,000 dollars per violation.
Its technical safeguards require a business to assess risks in network and software design and in information processing, transmission and storage, to detect, prevent and respond to attacks or system failures, and to regularly test and monitor the effectiveness of key controls. Continuous CIS benchmark scanning with drift detection is direct evidence for that ongoing testing and monitoring.
More questions on Frameworks?
Our compliance engineers can show you exactly how CISGuard handles Frameworks in a briefing scoped to your environment.