Home / Blog / Cybersecurity
March 5, 2021 by FoxPointe Solutions
An updated cybersecurity law that the IT organization (along with other college/university departments) will need to continue to integrate into its compliance programs, policies, and controls is the recent changes to New York’s General Business Law 899-aa and 899-bb (aka SHIELD Act). The compliance actions supporting this law have already passed (compliance was required by March 2020), and as such, our observations and recommendations have noted areas that would be applicable to this law based on our understanding of its applicability; however, we recommend that College/University seeks out a legal opinion regarding compliance requirements for this law and then adjust the needed controls to comply with the law.
Additionally, we wanted to bring the following to Management’s attention, as compliance with the Gramm-Leach Bliley Act Safeguards Rule is likely required for the College/University. The Federal Trade Commission (FTC) has proposed several changes to the existing Gramm-Leach Bliley Act (GLBA). They include items such as the following:
The sample items below from the proposed update are specific to the Safeguards Rule, which applies to the College/University. These compliance items, if approved, mirror current S/B College/University compliance actions in multiple areas, but not everywhere. They would require College/University to:
How this will ultimately affect College/University is unclear; however, we would suggest that those GLBA changes be monitored by College/University’s Privacy and Security Officers.
For additional cybersecurity information, please reach out to our experts at FoxPointe Solutions today!
FoxPointe Solutions is solely responsible only for the content of FoxPointe Solutions authored information and is subject to change at any time. Any forward-looking statements are not predictions. FoxPointe Solutions is not responsible for any errors or omissions, or for the results obtained from the use of this information. Questions regarding your legal or compliance position should be addressed through your legal counsel, security advisor and/or your relevant standard authority. Nothing contained herein should be used nor relied upon as advice nor constitute a consultant-client relationship.