Skip to main content
Advanced Search
Search Terms
Content Type

Exact Matches
Tag Searches
Date Options
Updated after
Updated before
Created after
Created before

Search Results

84 total results found

Which US state privacy and security laws affect security-vendor selection?

US State & Sector Vendor-Risk Guides

Short answer: A growing patchwork of US state laws imposes obligations that flow down to a company's vendors — comprehensive privacy acts (California, Virginia, Colorado, Texas, and others), sector rules like New York DFS Part 500 for financial services, data-...

Type
FAQ
Source
US State & Sector Vendor-Risk Guides

How does Cyber Crucible support New York DFS Part 500 cybersecurity requirements?

US State & Sector Vendor-Risk Guides

Short answer: For a financial institution covered by New York DFS Part 500 (23 NYCRR 500), Cyber Crucible supports several required controls — multi-factor authentication, encryption, access controls, and incident response — while reducing third-party risk bec...

Type
FAQ
Source
US State & Sector Vendor-Risk Guides

How does Cyber Crucible support California CCPA/CPRA vendor obligations?

US State & Sector Vendor-Risk Guides

Short answer: Cyber Crucible acts as a service provider under the CCPA/CPRA, bound by contract to process data only on the customer's instructions, and it does not sell or share personal information. Because it collects essentially no personal information in t...

Type
FAQ
Source
US State & Sector Vendor-Risk Guides

How does Cyber Crucible support the Texas Data Privacy and Security Act (TDPSA)?

US State & Sector Vendor-Risk Guides

Short answer: Under the Texas Data Privacy and Security Act, Cyber Crucible acts as a processor bound by a data processing agreement, assisting the controller with security and data-subject requests. Its data-minimization design — collecting no customer conten...

Type
FAQ
Source
US State & Sector Vendor-Risk Guides

How does Cyber Crucible support Virginia's Consumer Data Protection Act (VCDPA)?

US State & Sector Vendor-Risk Guides

Short answer: Cyber Crucible supports a controller's VCDPA obligations as a processor operating under a data processing agreement, helping with data-security duties and consumer-rights requests. Its no-collection design means it holds little to no personal dat...

Type
FAQ
Source
US State & Sector Vendor-Risk Guides

How does Cyber Crucible support the Colorado Privacy Act (CPA)?

US State & Sector Vendor-Risk Guides

Short answer: Cyber Crucible operates as a processor under the Colorado Privacy Act, bound by a data processing agreement to follow the controller's instructions, assist with security, and support consumer rights. Because it collects essentially no personal da...

Type
FAQ
Source
US State & Sector Vendor-Risk Guides

How does Cyber Crucible support Massachusetts 201 CMR 17.00 (WISP)?

US State & Sector Vendor-Risk Guides

Short answer: Massachusetts 201 CMR 17.00 requires any organization holding personal information about a Massachusetts resident to maintain a Written Information Security Program with specific safeguards. Cyber Crucible supports a customer's WISP with encrypti...

Type
FAQ
Source
US State & Sector Vendor-Risk Guides

How does Cyber Crucible address Illinois BIPA and biometric-data concerns?

US State & Sector Vendor-Risk Guides

Short answer: Cyber Crucible does not collect, store, or process biometric identifiers or biometric information, so it does not create the exposure Illinois's Biometric Information Privacy Act (BIPA) is written to address. There is no biometric data in its cus...

Type
FAQ
Source
US State & Sector Vendor-Risk Guides

How does Cyber Crucible support Pennsylvania's breach-notification law?

US State & Sector Vendor-Risk Guides

Short answer: Pennsylvania's Breach of Personal Information Notification Act (73 P.S. §2301, as amended by Act 151 of 2022) requires notifying affected residents — and, for larger breaches, the Attorney General — after a breach of covered personal information....

Type
FAQ
Source
US State & Sector Vendor-Risk Guides

How does Cyber Crucible support the Connecticut Data Privacy Act (CTDPA)?

US State & Sector Vendor-Risk Guides

Short answer: Cyber Crucible operates as a processor under the Connecticut Data Privacy Act, bound by a data processing agreement to act on the controller's instructions and to assist with security and data-subject requests. Because it collects no customer con...

Type
FAQ
Source
US State & Sector Vendor-Risk Guides

How does Cyber Crucible support Utah's Consumer Privacy Act (UCPA)?

US State & Sector Vendor-Risk Guides

Short answer: Cyber Crucible acts as a processor under the Utah Consumer Privacy Act, following the controller's documented instructions under a data processing agreement. Its no-collection design means there is little personal data in its custody for the UCPA...

Type
FAQ
Source
US State & Sector Vendor-Risk Guides

How does Cyber Crucible support Oregon's Consumer Privacy Act (OCPA)?

US State & Sector Vendor-Risk Guides

Short answer: Cyber Crucible operates as a processor under the Oregon Consumer Privacy Act, bound by contract to process only on the controller's instructions and to assist with security and consumer-rights requests. Because it collects essentially no personal...

Type
FAQ
Source
US State & Sector Vendor-Risk Guides

How does Cyber Crucible support Washington's My Health My Data Act?

US State & Sector Vendor-Risk Guides

Short answer: Washington's My Health My Data Act regulates "consumer health data" broadly and carries a private right of action, so vendors that touch such data face real exposure. Cyber Crucible does not collect consumer health data — it analyzes process and ...

Type
FAQ
Source
US State & Sector Vendor-Risk Guides

How does Cyber Crucible support the newer 2025–2026 state privacy laws?

US State & Sector Vendor-Risk Guides

Short answer: A wave of comprehensive state privacy laws took effect across 2025 and 2026 — including New Jersey, Delaware, Iowa, Nebraska, New Hampshire, Tennessee, Minnesota, Maryland, and, in 2026, Indiana, Kentucky, and Rhode Island. They share a common st...

Type
FAQ
Source
US State & Sector Vendor-Risk Guides

¿Qué leyes estatales de EE. UU. sobre privacidad y seguridad afectan la selección de proveedores de seguridad?

Guías de Riesgo de Proveedores por Esta...

Respuesta breve: Un mosaico cada vez mayor de leyes estatales de EE. UU. impone obligaciones que se trasladan a los proveedores de una empresa — leyes integrales de privacidad (California, Virginia, Colorado, Texas y otras), normas sectoriales como el New York...

Language
es
TranslatedFrom
441
Source
US State & Sector Vendor-Risk Guides

¿Cómo respalda Cyber Crucible los requisitos de ciberseguridad de la Parte 500 del NY DFS?

Guías de Riesgo de Proveedores por Esta...

Respuesta breve: Para una institución financiera sujeta a la Parte 500 del NY DFS (23 NYCRR 500), Cyber Crucible respalda varios controles requeridos —autenticación multifactor, cifrado, controles de acceso y respuesta a incidentes— a la vez que reduce el ries...

Language
es
TranslatedFrom
442
Source
US State & Sector Vendor-Risk Guides

¿Cómo respalda Cyber Crucible las obligaciones de proveedores conforme a la CCPA/CPRA de California?

Guías de Riesgo de Proveedores por Esta...

Respuesta breve: Cyber Crucible actúa como proveedor de servicios (service provider) bajo la CCPA/CPRA, obligado por contrato a procesar los datos únicamente según las instrucciones del cliente, y no vende ni comparte información personal. Dado que, en primer ...

Language
es
TranslatedFrom
443
Source
US State & Sector Vendor-Risk Guides

¿Cómo respalda Cyber Crucible la Ley de Privacidad y Seguridad de Datos de Texas (TDPSA)?

Guías de Riesgo de Proveedores por Esta...

Respuesta breve: En virtud de la Ley de Privacidad y Seguridad de Datos de Texas, Cyber Crucible actúa como procesador, sujeto a un acuerdo de procesamiento de datos, que asiste al controlador con la seguridad y las solicitudes de los titulares de los datos. S...

Language
es
TranslatedFrom
444
Source
US State & Sector Vendor-Risk Guides