Public-domain · open source
OpenJurist

N.Y. State Technology Law § 209

Notification of a breach of the security of the system or a breach of network security; shared data

Redline — January 1, 2022 → current.View current text →
Current — January 1, 2023
As of January 1, 2022
§ 209. Notification of data breach or network security breach; shared\ndata. 1. The office shall, within twenty-four hours following the\ndiscovery of a data breach or network security breach or receiving\nnotice of a data breach or network security breach, notify the chief\ninformation officer, and where appropriate, the chief information\nsecurity officer, of any state entity with which it shares data,\nprovides networked services or shares a network connection whose data,\nservices or connection is or may have been the subject of such breach\nwhether or not such data was, or is reasonably believed to have been,\nacquired or used by an unauthorized person.\n 2. The office shall, in addition to the provisions of subdivision one\nof this section, notify the chief information officer, and where\nappropriate, the chief information security officer, of such state\nentity with which it shares data, provides networked services or shares\na network connection and whose data is or may have been the subject of\nsuch breach, of its plan for remediation of the breach and future\nprotection of such data and network.\n 3. For purposes of this section:\n (a) "Data breach" shall mean an intentional or unintentional incident\nwhere data is disclosed, released, stolen, or taken without the\nknowledge or authorization of the data's owner or steward.\n (b) "Network security breach" shall mean an intentional or\nunintentional incident where an unauthorized party has gained access to\nan organization's network without the knowledge or authorization of the\nnetwork owner or steward.\n (c) "State entity" shall mean any state board, bureau, division,\ncommittee, commission, council, department, public authority, public\nbenefit corporation, office or other governmental entity performing a\ngovernmental or proprietary function for the state of New York,\nincluding the state legislature and the judiciary.\n
§ 209. Notification of a breach of the security of the system or a\nbreach of network security; shared data. 1. The office shall, within\ntwenty-four hours of either being notified of or receiving evidence of a\nbreach of the security of the system, or a breach of network security,\nas defined in paragraphs (a) and (b) of subdivision three of this\nsection, notify the chief information officer, the chief information\nsecurity officer, and where appropriate, the cyber security coordinator\nof any state entity with which it shares data, provides networked\nservices or shares a network connection whose data, services or\nconnection is reasonably suspected to be affected by any such breach.\n 2. The office shall provide the chief information officer, the chief\ninformation security officer, and where appropriate, the cyber risk\ncoordinator of any state entity, who has been notified pursuant to\nsubdivision one of this section, with its plan for remediation of the\nbreach and future protection of such data and network.\n 3. For purposes of this section:\n (a) "Breach of the security of the system" shall have the same meaning\nas defined in paragraph (b) of subdivision one of section two hundred\neight of this article.\n (b) "Breach of network security" shall mean unauthorized access to or\naccess without valid authorization of a computer network which\ncompromises the security, confidentiality, or integrity of such network.\n (c) "State entity" shall have the same meaning as provided by\nparagraph (c) of subdivision one of section two hundred eight of this\narticle.\n

Official source: NYS Open Legislation (New York State Senate). Reproduced from public-domain New York statutes; confirm against the official source for the current text. Not legal advice.