Intro

Financial-services organizations may already have multiple tools telling them what exists across their environment. The problem is that those tools do not always agree.

An endpoint platform may recognize a device that a vulnerability scanner does not. A network system may identify an active device that is missing from another asset record. The same device may even appear under multiple names across different platforms.

That creates a simple but important question: Which view can you trust?

For organizations regulated by the New York Department of Financial Services, that question has added importance. 23 NYCRR Part 500 requires covered organizations to maintain a risk-based cybersecurity program, while Section 500.13specifically requires policies and procedures designed to produce and maintain a complete, accurate and documented inventory of information systems.

Teneo can help organizations explore whether their existing technology provides the asset, security-control, and network visibility needed to support those efforts.

What is NYDFS Part 500?

NYDFS Part 500 is the Cybersecurity Regulation for financial-services organizations operating under certain New York banking, insurance and financial-services authorizations.

It may apply to banks, insurers, mortgage companies, money transmitters, virtual-currency businesses, and other covered organizations.

A company does not necessarily have to be headquartered in New York. The important factor is whether it operates under an authorization overseen by NYDFS.

Part 500 requires covered entities to maintain cybersecurity policies and programs based on their risks. The regulation addresses areas including:

  • Cybersecurity governance
  • Risk assessment
  • Asset management
  • Access controls
  • Vulnerability management
  • Multifactor authentication
  • Security monitoring
  • Incident response
  • Business continuity
  • Third-party security

What is the April 15 NYDFS filing?

Covered entities must submit an annual filing by April 15, covering the previous calendar year.

Organizations that materially complied with the applicable requirements submit a Certification of Material Compliance. Organizations that did not materially comply with all applicable requirements submit an Acknowledgment of Noncompliance, identifying the affected sections, describing the noncompliance and providing a remediation timeline or confirming that remediation has been completed.

Both filings must be signed by the organization’s highest-ranking executive and CISO. If the organization does not have a CISO, the highest-ranking executive and senior officer responsible for the cybersecurity program sign the filing.

Supporting records, documentation and remediation information must also be retained for five years and made available to NYDFS upon request.

That puts a premium on having information that leadership can confidently rely on, not just at filing time, but throughout the year.

Organizations may therefore approach the technology challenge from different starting points. Some may be working toward their next Certification of Material Compliance. Others may already have submitted an Acknowledgment of Noncompliance and be working against a documented remediation timeline. In either situation, the ability to establish a trusted view of assets and security controls can support the organization’s internal remediation and reporting processes.

What does NYDFS Section 500.13 require?

Section 500.13 covers asset management and data retention.

It requires covered entities to implement written policies and procedures designed to produce and maintain a complete, accurate and documented asset inventory of the covered entity’s information systems.

Those policies and procedures must include a method for tracking, where applicable:

  • Asset owner
  • Location
  • Classification or sensitivity
  • Support expiration date
  • Recovery time objective
  • How frequently the inventory is updated and validated

Section 500.13 also addresses the secure disposal of certain nonpublic information that is no longer required.

The regulation does not prescribe one required technology or say that every covered organization must use continuous asset discovery. Each organization remains responsible for establishing policies and processes appropriate to its environment and risks.

Why is maintaining an accurate asset inventory difficult?

Most financial-services organizations already have several sources of asset information.

These may include:

  • Endpoint protection platforms
  • Vulnerability scanners
  • Mobile-device management
  • Cloud-management systems
  • Configuration-management databases (CMDB)
  • Identity platforms
  • DNS, DHCP and IP address management (DDI)
  • Network-management tools
  • IT service-management platforms

The problem is that these systems may not agree.

One tool may identify an active asset that another cannot see. The same device may appear under different names. A security agent may be installed but no longer reporting. An active IP address may not be linked to a current asset record.

For architects, network engineers and security teams responsible for maintaining that visibility, this creates several important questions:

  • What information systems do we currently have?
  • Are there unknown or unmanaged assets?
  • Do our systems agree about which assets exist?
  • Can we see which controls should protect each asset?
  • Are those controls active?
  • Can leadership rely on the information being presented?
  • And would leadership be comfortable relying on that information when supporting the annual NYDFS filing?

Answering those questions can require security and IT teams to spend hours or days comparing data manually across multiple platforms and spreadsheets, without always being certain they have captured the full picture.

How can CAASM support asset and security-control visibility?

Cyber Asset Attack Surface Management, or CAASM, connects information from existing security and IT tools to create a more centralized and trusted view.

For example, a device may appear in an endpoint platform, a vulnerability-management tool and a device-management system under different names or may be visible to only one of those platforms. CAASM correlates those records to help determine whether they represent the same asset and highlight systems that other tools may be missing.

Teneo’s CAASM solution can help organizations:

  • Identify known, unknown and unmanaged assets
  • Reconcile conflicting or duplicate records
  • Understand which security tools recognize each asset
  • Validate whether expected controls are operating
  • Identify missing or inactive controls
  • Monitor asset and security coverage over time
  • Support reporting and remediation workflows

CAASM complements existing technology investments rather than replacing them. It brings disconnected information together so teams can better understand what is present, what is protected and where gaps may exist.

CAASM can help organizations create a more trusted technical asset view across existing tools and provide greater visibility into security-control coverage. Information such as ownership, classification, support expiration or recovery objectives may still come from other systems and governance processes, depending on the organization’s environment.

How can Core Network Services support asset visibility?

Accurate asset information also depends on reliable network-addressing and connectivity data.

Teneo’s Core Network Services combine:

  • DNS (Domain Name System)
  • DHCP (Dynamic Host Configuration Protocol)
  • IPAM (IP address management)

Together, these services are commonly known as DDI.

Core Network Services can help organizations understand:

  • Which IP addresses are allocated or active
  • Maintain current, authoritative DNS, DHCP and IPAM data as the environment changes
  • Which devices are requesting or receiving network addresses
  • How address space is organized across the environment
  • Where addressing conflicts or inconsistencies exist
  • How DNS, DHCP and IP information is managed

This information can provide valuable network context for an organization’s wider asset-management process.

Core Network Services can provide an authoritative source of network-addressing and connectivity information that complements asset information held in other IT and security platforms.

How do CAASM and Core Network Services differ?

CAASM and Core Network Services address related but different visibility questions.

Core Network Services can help answer:

  • Which IP addresses are allocated or active?
  • Which devices are receiving network addresses?
  • How is address space organized?
  • Are there unexpected connections or addressing inconsistencies?

CAASM can help answer:

  • Do our security and IT tools agree that an asset exists?
  • Is the asset known, managed or unmanaged?
  • Which security tools recognize it?
  • Does it have the expected controls?
  • Are those controls active and operating as expected?
  • Are they configured correctly, current and reporting as expected?
  • Where are the remaining coverage gaps?

Depending on the organization’s environment, these capabilities may provide complementary information.

Core Network Services provide authoritative network-addressing and connectivity context. CAASM correlates asset and control information across multiple security and IT platforms, helping teams understand security posture across the asset estate and identify actionable remediation where gaps exist.

What other technologies may be relevant?

Section 500.13 is only one part of the wider NYDFS Cybersecurity Regulation.

Depending on an organization’s risks and current environment, other Teneo capabilities may support its broader cybersecurity program.

Workload access control and micro-segmentation can help restrict unnecessary communication between systems and reduce lateral-movement risk following a compromise.

Visibility Fabric can help provide security and monitoring tools with the relevant network traffic they need to operate effectively.

Network Performance Monitoring and Diagnostics can provide real-time and historical packet-level evidence for troubleshooting and technical investigations. It also helps organizations understand the cryptographic protocols and cipher suites operating across their networks. This visibility can help security teams identify legacy or quantum-vulnerable encryption methods, support cryptographic inventory efforts, and establish a baseline for future post-quantum migration initiatives.

These capabilities do not replace the organization’s governance, policies or compliance processes. Their relevance depends on the technical challenges the organization needs to address.

Questions to consider about your current technology

Security and IT teams may find it useful to ask:

  1. Do our security and IT platforms agree about which assets exist?
  2. How do we identify unknown or unmanaged systems?
  3. How frequently is our asset information updated and validated?
  4. Can we determine which IP addresses and devices are currently active?
  5. Can we see whether expected security controls are active and operating as expected?
  6. Does leadership receive a clear and trusted view of the environment?

The answers may help determine whether the organization can confidently demonstrate a complete, accurate and current understanding of its technology environment and, where gaps exist, identify areas that may benefit from additional attention or support

How can Teneo help?

Every financial-services organization has a different environment, risk profile and combination of existing tools.

We can speak with security and IT teams to understand:

  • How asset information is currently maintained
  • Which platforms contribute asset and security-control data
  • Whether those systems provide a consistent view
  • How DNS, DHCP and IP address information is managed
  • How unknown or unmanaged assets are identified
  • Whether expected controls can be validated
  • Where additional network or security visibility may help

Based on that conversation, we can explore whether CAASM, Core Network Services or another Teneo capability may support the organization’s priorities.

Technology is one component of a broader cybersecurity and compliance program. Teneo does not provide legal or regulatory advice or determine whether an organization complies with NYDFS Part 500.

Discuss your NYDFS technology requirements with Teneo

NYDFS Part 500 requires covered organizations to maintain strong cybersecurity governance, accurate information-system inventories and evidence supporting their annual filing.

Section 500.13 places specific emphasis on maintaining a complete, accurate and documented asset inventory.

Teneo can help you explore whether your current technology provides the asset, security-control and network visibility needed to support those efforts.

Speak with a Teneo technical expert about your environment, existing tools and priorities.

This article is provided for general informational purposes and does not constitute legal, regulatory or compliance advice. Organizations should consult their legal and compliance advisers regarding the application of 23 NYCRR Part 500 to their circumstances.

 

Frequently asked questions

What is NYDFS Part 500?

NYDFS Part 500 is a New York cybersecurity regulation for covered financial-services organizations. It requires them to maintain risk-based cybersecurity programs designed to protect their information systems and nonpublic information.

What does Section 500.13 require?

Section 500.13 requires covered entities to maintain written policies and procedures designed to produce and maintain a complete, accurate and documented inventory of their information systems.

When is the annual NYDFS filing due?

The annual Certification of Material Compliance or Acknowledgment of Noncompliance is due by April 15 for the previous calendar year.

How can CAASM support asset visibility?

CAASM brings information together from existing security and IT tools, providing a consolidated view of assets across the environment. It can help identify unknown assets, reconcile inconsistent records, improve visibility into security-control coverage and support efforts to maintain a more complete and accurate understanding of the technology environment.

How can Core Network Services support asset visibility?

Core Network Services centralize DNS, DHCP and IP address management, providing a current and authoritative source of network information that can help identify active devices, validate addressing data and detect inconsistencies while supporting broader asset-visibility efforts.

Can CAASM or Core Network Services make an organization NYDFS compliant?

No single technology guarantees compliance. These capabilities may strengthen asset, security-control and network visibility, but the covered organization remains responsible for its governance, policies, risk assessments, controls and regulatory decisions.

Cookie Policy
Teneo Logo

This website uses cookies so we can provide you with the best user experience possible.

Cookies are small files containing information that enables a website to recognise you. They’re downloaded to the device you use when you visit a website and sent back to that website each time you re-visit, or sent to another website that recognises the same cookie.

Our cookie policy tells you how and why we use cookies, and how this allows us to improve your online experience. You can read our full Cookie Policy here.

Strictly Necessary Cookies

Strictly necessary cookies include session cookies and persistent cookies. Session cookies keep track of your current visit and how you navigate the site. They only last for the duration of your visit and are deleted from your device when you close your Internet browser. Persistent cookies last after you’ve closed your Internet browser and enable our website to recognise you as a repeat visitor and remember your actions and preferences when you return.

Third Party Cookies

Third party cookies include performance cookies and targeting cookies. Performance cookies collect information about how you use a website, e.g. which pages you go to most often, and if you get error messages from web pages. These cookies don’t collect information that identifies you personally as a visitor, although they might collect the IP address of the device you use to access the site. Targeting cookies collect information about your browsing habits. They are usually placed by advertising networks such as Google. The cookies remember that you have visited a website and this information is shared with other organisations such as media publishers.

Keeping these cookies enabled helps us to improve our website and display content that is more relevant to you and your interests across the Google content network.