Get NIST-y

·S2 E35

New York Compliance: What the MSP Owns and What It Doesn't

September 1
21 mins

Episode Description

Following NIST does not automatically cover New York-specific rules, and that does not mean your MSP needs to become a law firm. We sort out where legal counsel belongs, what the client must own, and which responsibilities an MSP can safely take on. We also thank our listeners for helping Get NIST-y win an MSP Influencer award.Takeaways:• Keep lawyers focused on legal and privacy questions, not every security policy detail.• Put one client executive in charge of the security program and risk.• Treat SSO as a security control, not a substitute for application-level user audits.We answer:• How can an MSP track New York Education Law 2-d and 23 NYCRR Part 500 without becoming a lawyer?• How much of the client’s compliance work should the MSP actually own?Make sure to follow the podcast or ask your own questions at:https://blacksmithinfosec.com/nisty/

See all episodes