New York regulations

9 NYCRR 6220.1

Executive Department

Browse New York regulations by title, part, and section.

Definitions

Definitions

Compiled text through Mar 31, 2022

Register checked through Jul 29, 2026

No later Register activity identified in this check.

Dates and status
Compiling agency
Executive Department
Text status
Westlaw Inline Boundary Correction
Compiled text through
Mar 31, 2022
Register checked through
July 29, 2026/Vol. XLVIII, Issue 30 (2026-07-29)
Activity status
No later Register activity identified in this check.
Latest notice
SBE-13-21-00015-A · Adopted rule · Aug 18, 2021
Source snapshot
Jun 6, 2026
(a)Authentication means the process or action of verifying the identity of a user, process or device.
(b)Board of Elections or county board means each County Board of Elections.
(c)Cloud service means a wide range of services delivered on-demand over the Internet. These services are designed to provide affordable and easy access to applications and resources.
(d)Complex password management policy means a password policy on any information system that supports election data and is capable of complying with guidelines set forth in National Institute of Standards and Technology (NIST) Special Publication 800-63B Digital Identity Guidelines Authentication and Lifecycle Management.
(e)Cyber incident reporting procedure means the process created by the State Board of Elections to be followed by both the county board and/or the State Board of Elections when reporting a cyber security incident.
(f)Cyber security incident means any imminent or successful act to gain unauthorized access to, or create disruption resulting in the misuse of, any information system that processes election data or any non-public information by the Boards of Elections.
(g)Data assets means the data that an organization collects, manages, produces, modifies or stores either electronically or physically. This can refer to any application output file, document, database information, web page code, etc.
(h)Domain-based messaging, authentication, reporting and conformance (DMARC) means an email authentication, policy, and reporting protocol that can improve email protection by monitoring email messages to help mitigate risk to the organization.
(i)Domain naming system (DNS) means a hierarchical and decentralized system for computers, services, or other resources connected to the Internet or a private network that translates a name to an Internet protocol address.
(j)Election data means all data contained on servers, workstations and devices, other than voting systems, used for the administration of elections, including but not limited to:
(1)voter registration data;
(2)election management data;
(3)poll site data;
(4)ballot access data;
(5)electronic transmission of absentee ballot data; and
(6)public-facing website data.
(k)Baseline image means an organization’s standard set of necessary, trusted applications, including operating system with up-to-date patch levels, installed for the set of systems for which it is designed.
(l)Information system means integrated components that collect, store and process data which are used to provide information, or perform tasks.
(m)Intrusion detection system (IDS) or intrusion prevention system (IPS) means a device or software application that monitors a network for malicious activity or security policy violations and, in the case of an intrusion prevention system, blocks such activity.
(n)Managed services provider means a vendor providing outsourced administration, maintenance, security, operations, and/or support of information technology operations and assets. The relationship is often managed with performance and service metrics outlined in a service level agreement.
(o)Penetration test means an authorized simulated cyber attack on a computer system or network, performed to evaluate the security of the system or network. A penetration test can help determine whether a system is vulnerable to attack, if the controls in place are sufficient, and which controls (if any) the test bypassed. Penetration test reports may also assess potential impacts to the organization and suggest countermeasures to reduce risk.
(p)Phishing means a fraudulent attempt to obtain sensitive information or data such as usernames, passwords and credit card details, or install malicious software, by disguising oneself as a trustworthy entity in an electronic communication.
(q)Risk remediation plan means the process of developing an approach and actions to reduce the likelihood of an adverse event from occurring due to an exploit of a vulnerability by a threat actor.
(r)State Board of Elections or State board means the New York State Board of Elections.
(s)Secure elections center means the State Board of Elections organizational unit that offers services to Boards of Elections that help assess, manage, and reduce risk to the administration of elections.
(t)Secure system development life cycle (SSDLC) means a process for defining security requirements and tasks that must be considered and addressed within every system, project or application throughout every phase (from design through disposal).
(u)Server message block (SMB) protocol means a network file sharing protocol that allows applications on a computer to read and write to files and to request services from server programs in a computer network.
(v)Transport layer security (TLS) means a cryptographic protocol designed to provide secure communication over a computer network.
(w)The principle of least privilege means any user, program, or process shall have only the bare minimum privileges necessary to perform its function.
(x)Validated means a particular hardware, software, network appliance, or service is still supported by the manufacturer or vendor.
(y)Virtual local area network (VLAN) means a broadcast domain that is partitioned and isolated in a computer.
(z)Vulnerability scan means the process of discovering, and the inspection of, a network and networked systems to identify potential weaknesses which could be exploited.
(aa)Authenticated vulnerability scanning means the process of performing a vulnerability scan using credentials. Authenticated vulnerability scans obtain vulnerability information on protected devices to obtain detailed and accurate information about the operating system, installed software, including configuration issues and missing security patches.

State Register activity

1 rulemaking · 2 notices

  1. Implementation of Cyber Security Requirements for Local Boards of Elections.

    SBE-13-21-00015State Board of ElectionsPart-level action

    The Register recorded this action against the whole Part, which includes this section (9 NYCRR Part 6220).

    1. Adopted ruleSBE-13-21-00015-A

      Addition of Part 6220 to Title 9 NYCRR.

    2. Proposed ruleSBE-13-21-00015-P

      Addition of Part 6220 to Title 9 NYCRR.

Register checked through July 29, 2026/Vol. XLVIII, Issue 30 (2026-07-29)

State Register notices matched to this citation. This is Register status evidence, not compiled regulation text: a notice does not by itself amend the text shown here.

LawEngine organizes New York regulations for fast review. Use independent legal judgment before filing.