article thumbnail

New York Proposes Major Changes to Cybersecurity Regulation

FICO

Data encryption. The NYDFS requires data encryption not just for data in-transit but also for data at-rest. The requirements also mandate that organizations include these enhanced standards in their contracts with third-party service providers. Annual certification.

article thumbnail

PCI requirements and who needs to follow them

Basis Theory

Third-Party Service Provider ( TPSP or "service provider") refers to an entity other than the Merchant, Acquirer, or Issuer involved in storing, processing, or transmitting card data. While capturing this information can happen in transit (see: #4), most of all, data spends 99.9%

PCI DSS 88