Compliance

7/24/2018 Compliance

The Equifax Effect: NYS DFS' Breach Response

The New York State Department of Financial Services (DFS) has recently issued a new regulation concerning Credit Reporting Agencies (CRA) with operations in New York, in response to the substantial data breach involving Equifax in 2017. This newly effective CRA regulation, called the “Registration Requirements and Prohibited Practices for Credit Reporting Agencies,” aims to protect New Yorkers from the possibility of data breaches by requiring credit reporting agencies to comply with the NYS DFS 500 Cybersecurity Regulations and to register with the DFS annually.

 

This announcement was made by NYS DFS Monday, July 23rd and will be implemented in 4 phases, the first one beginning in November. Digital Edge wants to inform all credit reporting agencies of this new requirement and offer our knowledge on DFS500 regulations. Learn more about this new regulation by reading the full article! 

 

Digital Edge is an expert in ISO standards, and is certified by the International Standard Organization on Information Security and Quality (ISO 27001). There is a clear crosswalk between DFS law and ISO standards. Digital Edge will help to implement policies, standards and practices to cover all DFS requirements based on International Standards Organization framework.

6/25/2018 Compliance

Ask Our VP of Compliance: June 2018

"How Do Audit Findings Work?"

Many companies undergoing a certification audit spend countless hours undergoing stress and worry that their auditor will find something wrong. Will they just leave in the middle of the audit? Will they refuse to grant you certification? Will they never come back? Do they have to find something wrong? These questions run through the heads of many implementers as they await the certification audit, but it is not as bad as you fear!

Today, Digital Edge's VP of Compliance answer a few questions about how audit findings work, what nonconformities mean, and what you need to do about them:

 

6/4/2018 Compliance

Digital Edge's Open Letter to Congress – In Response to EU's GDPR

Last Friday, May 25th, EU’s privacy law, the General Data Protection Regulation (GDPR), took effect. The GDPR imposes new rules on companies, government agencies, non-profits, and other organizations that offer goods and services to people in the European Union (EU), or that collect and analyze data tied to the EU residents. The GDPR applies no matter where you are located.

Digital Edge has extensive expertise in protecting data, championing privacy, and complying with complex regulations, and is currently in compliance with GDPR. We are committed to GDPR compliance across our cloud services, in addition to providing GDPR related assurances in our contractual commitments.

However, Digital Edge felt it was necessary to write an open letter to Congress urging NOT to adopt the European Union’s GDPR. While we strongly feel that the United States needs a privacy framework implemented, the GDPR model should not be mirrored. 

To view this letter, which includes our justification of why Digital Edge feels this way, please click here!

5/24/2018 Compliance

Ask Our VP of Compliance: May 2018

"GDPR"

With the General Data Protection Regulation (GDPR) legislation set to go into effect on May 25th of this year, it’s no surprise that there has been a plethora of questions come our way regarding this data protection regulations. Digital Edge's VP of Compliance answers the most commonly asked questions! 

 

5/22/2018 Compliance

Digital Edge Green Policy

Author: Danielle Johnsen (VP of Compliance)
Date: 22 May 2018
Version: 2.4

This document defines Digital Edge’s Green Policy.

5/22/2018 Compliance

Are You Ready for GDPR on May 25th?

Digital Edge is always working to stay compliant, which helps make compliance easier for your business.

5/21/2018 Compliance

Digital Edge GDPR Compliance Statement

Author: Danielle Johnsen (VP of Compliance)
Date: 21 May 2018
Version: 1.1

This document defines Digital Edge’s policy on General Data Protection Regulation of European Union and is based and principles.

5/17/2018 Compliance

Risk Driven Information Technology Organization

Or one may say Compliance Driven IT organization. As in the core of any today’s compliance lays Risk Management.

This article explains how to setup Risk Management practices for Cyber Security management. When it comes to Cyber Securty it's best to prepare for the worst-case scenario. It'll guide you on how to find ways to identify threats, face them and prepare to defend your business as well as give you templates to download to start your own risk management practice!

"The best garison is not the one that has lots of weapons but the one who has lot training."  

-M. Petrov CEO

 

5/11/2018 Compliance

Ask Our VP of Compliance: April 2018

"DFS"

Last month, many New York State Financial Institutions received their scary “Failure to File Certification of Compliance” email and were perplexed by what to do next… Don’t fear, the Digital Edge's VP of Compliance is here to answer your many many submitted questions regarding NYS Department of Financial Services Part 500 Mandatory Cybersecurity Requirements! These are the questions for this month:

4/5/2017 Compliance

ISO 27001:2013 High Level Information Security Policy

Author: Danielle Johnsen (VP of Compliance)
Date: 5 April 2017
Version: 2.0

This document defines Digital Edge’s policy on Information Security and is based on the following principles.