Compliance

Which rules ask your clients for scanning and vendor oversight?

Most of the small regulated firms MSPs look after answer to at least one rule that asks for regular vulnerability testing and oversight of service providers. For financial firms, the usual ones are the FTC Safeguards Rule, SEC Regulation S-P and NYDFS Part 500. Outerwall supplies external scan evidence and supplier monitoring for each.

At a glance

The rules, side by side

RuleWho it coversWhat it asks forHow Outerwall helps
FTC Safeguards Rule16 CFR 314Non-bank financial firms such as mortgage brokers, tax preparers and finance companiesContinuous monitoring, or an annual penetration test and vulnerability assessments every six months. Oversight of service providers.External scan evidence and supplier monitoring
SEC Regulation S-P2024 amendmentsBroker-dealers, investment advisers, investment companies and transfer agentsOversight of service providers through due diligence and monitoring, and breach notice from them within 72 hours.Supplier inventory and monitoring evidence
NYDFS Part 50023 NYCRR 500Financial services firms regulated in New YorkAn annual penetration test, risk-based automated scans, an asset inventory and a third-party service provider policy.External scans, an inventory of internet-facing assets and supplier monitoring
PCI DSS v4.0.1Requirement 11.3.2Anyone that handles card dataExternal vulnerability scans every three months by an Approved Scanning Vendor.Adds to those scans; Outerwall is not an Approved Scanning Vendor
HIPAA Security RuleProposed updateHealthcare providers, health plans and their business associatesProposed: vulnerability scans every six months, a yearly penetration test and an asset inventory.The same evidence, if the rule is finalized

Outerwall’s output supports a client’s compliance evidence. It does not, by itself, make a client compliant.

Rule by rule

What each rule asks, and how an MSP evidences it

  • 16 CFR 314

    FTC Safeguards Rule

    Continuous monitoring, or an annual penetration test and vulnerability assessments every six months. Oversight of service providers.

    Read the summary
  • 2024 amendments

    SEC Regulation S-P

    Oversight of service providers through due diligence and monitoring, and breach notice from them within 72 hours.

    Read the summary
  • 23 NYCRR 500

    NYDFS Part 500

    An annual penetration test, risk-based automated scans, an asset inventory and a third-party service provider policy.

    Read the summary

These pages summarize each rule for MSPs. They aren’t legal advice.

Give your clients evidence, every month.

Design partners shape the evidence packs mapped to each rule.