Compliance
Which rules ask your clients for scanning and vendor oversight?
Most of the small regulated firms MSPs look after answer to at least one rule that asks for regular vulnerability testing and oversight of service providers. For financial firms, the usual ones are the FTC Safeguards Rule, SEC Regulation S-P and NYDFS Part 500. Outerwall supplies external scan evidence and supplier monitoring for each.
At a glance
The rules, side by side
| Rule | Who it covers | What it asks for | How Outerwall helps |
|---|---|---|---|
| FTC Safeguards Rule16 CFR 314 | Non-bank financial firms such as mortgage brokers, tax preparers and finance companies | Continuous monitoring, or an annual penetration test and vulnerability assessments every six months. Oversight of service providers. | External scan evidence and supplier monitoring |
| SEC Regulation S-P2024 amendments | Broker-dealers, investment advisers, investment companies and transfer agents | Oversight of service providers through due diligence and monitoring, and breach notice from them within 72 hours. | Supplier inventory and monitoring evidence |
| NYDFS Part 50023 NYCRR 500 | Financial services firms regulated in New York | An annual penetration test, risk-based automated scans, an asset inventory and a third-party service provider policy. | External scans, an inventory of internet-facing assets and supplier monitoring |
| PCI DSS v4.0.1Requirement 11.3.2 | Anyone that handles card data | External vulnerability scans every three months by an Approved Scanning Vendor. | Adds to those scans; Outerwall is not an Approved Scanning Vendor |
| HIPAA Security RuleProposed update | Healthcare providers, health plans and their business associates | Proposed: vulnerability scans every six months, a yearly penetration test and an asset inventory. | The same evidence, if the rule is finalized |
Outerwall’s output supports a client’s compliance evidence. It does not, by itself, make a client compliant.
Rule by rule
What each rule asks, and how an MSP evidences it
16 CFR 314
FTC Safeguards Rule
Continuous monitoring, or an annual penetration test and vulnerability assessments every six months. Oversight of service providers.
Read the summary2024 amendments
SEC Regulation S-P
Oversight of service providers through due diligence and monitoring, and breach notice from them within 72 hours.
Read the summary23 NYCRR 500
NYDFS Part 500
An annual penetration test, risk-based automated scans, an asset inventory and a third-party service provider policy.
Read the summary
These pages summarize each rule for MSPs. They aren’t legal advice.
Give your clients evidence, every month.
Design partners shape the evidence packs mapped to each rule.