0% found this document useful (0 votes)
2 views50 pages

Module 5

The document outlines the importance of cybersecurity compliance, particularly in relation to RBI guidelines and the integration of Governance, Risk, and Compliance (GRC) with automation. It details the roles of various organizations like RBI and NCIIPC in overseeing cybersecurity measures, as well as the specific guidelines for banks and financial institutions to ensure robust cyber defenses. Additionally, it emphasizes the necessity of regular audits and assessments to maintain and improve cybersecurity programs within enterprises.

Uploaded by

athmika.cs22
Copyright
© All Rights Reserved
We take content rights seriously. If you suspect this is your content, claim it here.
Available Formats
Download as PDF, TXT or read online on Scribd
0% found this document useful (0 votes)
2 views50 pages

Module 5

The document outlines the importance of cybersecurity compliance, particularly in relation to RBI guidelines and the integration of Governance, Risk, and Compliance (GRC) with automation. It details the roles of various organizations like RBI and NCIIPC in overseeing cybersecurity measures, as well as the specific guidelines for banks and financial institutions to ensure robust cyber defenses. Additionally, it emphasizes the necessity of regular audits and assessments to maintain and improve cybersecurity programs within enterprises.

Uploaded by

athmika.cs22
Copyright
© All Rights Reserved
We take content rights seriously. If you suspect this is your content, claim it here.
Available Formats
Download as PDF, TXT or read online on Scribd

Module 5

Cyber Security Compliance: RBI Guidelines and Master Directions,


Combination of Governance, Risk and Compliance (GRC) and automation of
GRC. Enterprise Cyber defense Assessment: Assessing Enterprise
Cybersecurity.

Alakananda K
Asst Prof, CSE
CYBER SECURITY COMPLIANCE

• Compliance means following all the rules and requirements related to cybersecurity.
It includes the organization’s own cyber security policy, as well as regulatory
requirements, contractual, and legal obligations.
• To make sure the organization follows its own policies, security controls are used.
• These security controls come from defined processes, which are based on standards and
frameworks (like ISO, NIST, etc.).
• The standards and frameworks are created to help the organization meet its cybersecurity
policy goals.
• So, the policy is implemented in practice through these security controls.

o Just like internal security policies(internal Infosec policy), controls are also created to
follow regulatory, legal, and contractual requirements.
• Different departments or units in the organization are responsible for regularly checking
and monitoring these controls.
• The audit team reviews how well these controls are implemented.
• This acts as the third level of defense in cybersecurity.
CYBER SECURITY COMPLIANCE

• The audit report is sent to the Board-level Audit Committee,


which reviews it and gives directions for improvements.
• This completes the compliance cycle - from requirements → controls → reporting.
• In banks, the RBI (Reserve Bank of India) oversees cybersecurity through its CSITE
wing (Cyber Security and IT Examination).
• RBI issues guidelines like:
• Cyber Security Framework (CSF)
• Master Direction on Digital Payment Security Controls
• RBI also sends cybersecurity alerts and advisories to banks based on incidents in India
and other countries.
• CERT-In (Computer Emergency Response Team–India), under the Ministry of
Electronics and IT, also releases regular security alerts using information from global
CERT teams and intelligence sources.
CYBER SECURITY COMPLIANCE

•National Critical Information Infrastructure Protection Centre (NCIIPC) is a government


organization created in 2014 under Section 70A of the IT Act, 2000.
•Its main job is to protect India’s critical sectors like:
•Defense
•Energy
•Finance
•Emergency services from cyber-attacks by terrorist groups or foreign
countries.
•NCIIPC also creates a map of all important computer networks and systems in the country.
•If a major cyberattack happens on any critical infrastructure, NCIIPC helps in response
and recovery.
•It works together with CERT-In to handle incidents and ensure quick action and recovery.
CYBER SECURITY COMPLIANCE
• Translation Process of Infosec Policy into Controls" shows how high-level security intentions become concrete,
enforceable actions. Think of it as a funnel that turns broad goals into specific tools. Here's how each stage works:
• 1. Infosec Policy
• The organization's formal commitment to protecting information.
• Example: “We will ensure data confidentiality, integrity, and availability.”
• Role: Sets the vision and priorities.
• 2. Standards & Framework
• Industry guidelines and structured models to support the policy.
• Example: ISO 27001, NIST Cybersecurity Framework.
• Role: Provides a blueprint for implementation.
• 3. Processes
• Operational procedures that follow the standards.
• Example: Access control procedures, incident response workflows.
• Role: Turns theory into repeatable actions.
• 4. Controls
• Specific tools or mechanisms that enforce the processes.
• Example: Firewalls, encryption, multi-factor authentication.
• Role: Directly protect systems and data.
14.4.1 RBI Guidelines and Master Directions
RBI – Cyber Security Wing (CSITE)
• In 2015, the Reserve Bank of India (RBI) created a special cyber security wing called CSITE (Cyber
Security and IT Examination).
• Its main job is to check and assess how strong and prepared banks and other RBI-supervised entities
(SEs) are against cyber threats.
Main Functions of CSITE
• CSITE conducts IT examinations and cyber security reviews of supervised entities.
• It issues cyber advisories and alerts based on:
• Market intelligence (latest threat updates), and
• Incidents reported by banks and financial institutions.
• These advisories include remedial actions and CSITE ensures they are properly implemented.
Cyber Crisis Management
• CSITE has a Cyber Crisis Management Group (CCMG) that handles major cyber incidents and suggests
how to respond effectively.
Monitoring and Assessment
• CSITE regularly collects reports and data (periodic or ad-hoc) from banks to monitor their cyber
readiness.
• It uses 128 Key Risk Indicators (KRIs) to measure the cyber security posture of each supervised
entity.
RBI Guidelines and Master Directions
ReBIT – IT Subsidiary
• RBI has also set up an IT subsidiary, ReBIT (Reserve Bank Information Technology Pvt. Ltd.),
which supports cyber security within both RBI and its supervised entities.
Cyber Security Guidelines
CSITE prepares cyber security guidelines for banks and financial institutions, such as: two types
• Cyber Security Framework (CSF) – issued on June 2, 2016.
• Master Direction on Digital Payment Security Controls (DPSC) – issued on February 2, 2022.
These guidelines are detailed documents with over 100 points each to help ensure strong cyber protection.
Broad Cyber Security Framework (CSF) Guidelines of
02.06.2016
•There are about 120 requirements. These can be broadly grouped as follows.
1. Keep track of all IT assets and make sure software is regularly updated and patched.
2. Have a Cyber Security Policy approved by top management and review it every year.
3. Create a Cyber Crisis Management Plan (CCMP) to handle cyber incidents quickly and test it often.
4. Design your IT systems and network in a way that supports strong cyber security.
5. Assign clear responsibilities for cyber security at all levels in the organization.
6. Set up a 24x7 Security Operations Centre (SOC) to monitor systems and networks continuously.
7. Use strong login systems like multi-factor authentication to control access.
8. Ensure network and database security — all data transfers should be encrypted.
9. Protect customer data, especially sensitive information.
10. Regularly perform vulnerability tests and penetration testing (VAPT) to find and fix weaknesses.
11. Track cyber preparedness and performance using indicators (KPIs) and report them to RBI.
12. Have forensic tools ready to investigate any cyber incidents.
13. Use transaction monitoring systems to detect and stop fraudulent activities.
14. Conduct cyber security awareness programs for all - management, employees, vendors, and
customers.
Broad Digital Payment Security Controls (DPSC) Master
Directions – 02.02.2022
• The Master Direction on Digital Payment Security Controls provides necessary guidelines for Scheduled Commercial
Banks (except RRBs), Small Finance Banks, Payment Banks, and Credit Card issuing NBFCs.
• These guidelines help to set up a robust governance structure and implement common minimum standards of
security controls for digital payment products and services.
• The guidelines are technology and platform agnostic, meaning they apply to all types of digital payment systems and
technologies.
• They aim to create an enhanced and enabling environment for customers to use digital payment products in a safe
and secure manner.

•RBI issued these rules on February 2, 2022.


•These guidelines are for banks and NBFCs that handle digital payments (except Regional Rural
Banks).
•They help set up a strong security system and ensure safe digital payment operations.
•The rules apply to all types of technologies and platforms used for digital payments.
•The aim is to make digital payments safer and easier for customers to use.
•The guidelines cover key security control areas for better protection of digital transactions.

•The Master Direction consolidates important control aspects broadly in the following areas.
Broad Digital Payment Security Controls (DPSC) Master
Directions – 02.02.2022
The Master Direction consolidates important control aspects broadly in the following areas.
1. Governance and Management of Security Risks
2. Generic Controls:-
3. Application Security Life Cycle:
4. Authentication Framework:-
5. Fraud Risk Management:-
6. Reconciliation mechanism:
7. Customer protection:-
8. Awareness and grievance redressal mechanism:-
9. Internet Banking application security controls:-
10. Mobile payment application security controls:-
11. Card payment security controls:
1. Governance and Management of Security Risks
• Focuses on identifying, analyzing, monitoring, and managing fraud risk and compliance risk related to digital
payment products.
• Achieved through proper risk governance and risk management programs.
• Digital Payment Security Policy Must be approved by the Board of Directors.
• Should be reviewed regularly to ensure it stays updated with new threats and technologies.
2. Generic Security Controls
• Implement an appropriate level of encryption across all digital payment channels, especially for internet-based
systems.
• Deploy a Web Application Firewall (WAF) to protect online payment applications.
• Prevent DDoS Attacks: Distributed Denial of Service (DDoS) attacks to maintain service availability.
3. Application Security Life Cycle
• Applications must be protected by following recognized security standards and guidelines, such as:
• OWASP (Open Web Application Security Project) -Helps find and fix common web app security problems.
• ISO 12812 (Data Protection Requirements) - Gives rules for protecting payment data.
• NIST (National Institute of Standards and Technology) Threat Catalogues - Lists possible threats and how
to handle them
• These standards should be followed from the very beginning of the application development process.
Phases
• Design: Identify risks & define security needs.
• Development: Use secure coding & code review.
• Testing: Perform security testing & fix issues.
• Deploy: Ensure secure setup & patch systems.
• Maintain: Monitor, update, and patch regularly.
4. Authentication Framework
• Regulated Entities (REs) must implement Multi-Factor Authentication (MFA) for:
• Payments, and Fund transfers through electronic modes and payment applications.
• Entities should use at least one authentication method that is:
• Dynamic (changes with each transaction), or
• Non-replicable (cannot be copied or reused).
5. Fraud Risk Management
• Entities must implement security controls to detect suspicious transactions through system configuration and
monitoring.
Key Parameters
• Transaction Velocity: Rapid fund transfers or new beneficiaries in inactive accounts.
• Card Indicators: Repeated failed PIN/CVV attempts (possible fake activity).
• New Accounts: Unusual or excess activity soon after creation.
• Geo/IP Check: Transactions from restricted zones or suspicious IPs.
• Blacklisted Links: Transfers to known fraud mobile numbers or wallets.
6. Reconciliation Mechanism
• A real-time or near real-time reconciliation system must be implemented.
• Reconciliation should be completed within 24 hours of receiving settlement files.
• Applies to all digital payment transactions between the Regulated Entity (RE) and other stakeholders.
• Helps in early detection and prevention of suspicious transactions.
7. Customer Protection
• Digital payment products/services should be offered only with customer consent, based on a written or
electronically authenticated request.
• Customers must receive a positive acknowledgement confirming acceptance of terms and conditions.
• REs must provide an in-app mechanism (mobile or internet banking) for customers to:
• Identify or mark transactions as fraudulent, and
• Instantly notify the RE with proper authentication.
8. Awareness and Grievance Redressal Mechanism
• REs should continuously create public awareness about:
• Various cyber threats and attacks, and Precautionary measures to stay safe while using digital payment
products.
• Customers must be cautioned and educated about common threats such as:
• Phishing, Vishing, Reverse Phishing, and Remote access attacks on mobile devices.
• Users should be advised to protect account details, credentials, PINs, card details, and devices.
• REs must establish online dispute resolution systems to handle customer disputes and grievances related
to digital payments, in line with updated RBI instructions
9. Internet Banking Application Security Controls
• Enable CAPTCHA and adaptive authentication for login security.
• Deactivate user sessions automatically after a set period of inactivity.
• Ensure secure delivery of initial passwords to users.
10. Mobile Payment Application Security Controls
• Collect minimal data and request only necessary app permissions.
• Use application sandboxing or containerization for isolation and protection.
• Implement device binding of the mobile app using both hardware and software methods.
• The app must not store sensitive information such as user IDs, passwords, keys, or hashes.
11. Card Payment Security Controls
• Implement ATM and PCI-related security standards, such as PCI DSS, for secure card
transactions.
Combination of Governance, Risk, and Compliance (GRC) & Automation

• GRC means Governance, Risk Management, and Compliance — three important parts of keeping an organization
secure and well-managed (key pillars of an effective cybersecurity program)
• Governance: Setting rules, policies, and responsibilities.
• Risk Management: Finding and reducing possible problems or threats.
• Compliance: Making sure all laws, regulations, and standards are followed.
These three together help organizations to:
• Follow legal and security rules,
• Control and reduce risks, and
• Keep all processes organized and consistent.
• Because doing all this manually takes a lot of time and effort, companies now use GRC automation — software tools
that automatically track risks, check compliance, and generate reports.
Automation of GRC
• 1. Automation of GRC in cybersecurity brings key benefits:
• Transparency – clear visibility into risks and compliance status.
• Efficiency – faster and more accurate processes.
• Accountability – better tracking of responsibilities and actions.
• 2. A modern GRC management tool offers:
• A configurable, user-friendly solution.
• Seamless integration with existing technology systems.
• 3. Advantages over legacy/manual systems:
• Improved data accuracy and reporting.
• Centralized management of risks and compliance.
• Real-time monitoring and automated updates.
4. Full Customisation
• GRC management systems provide a fully customized approach to:
• Identify risks across the business.
• Measure and mitigate those risks effectively.
• Ensure compliance with both internal policies and external regulations.
5. 24/7 Automation
• GRC tools operate continuously, reducing the need for manual data entry.
• They can:
•Track obligations: Keep an eye on what the organization must follow (rules, policies, laws).
•Find compliance gaps: Spot where the company is not meeting requirements.
•Fix issues automatically: Use smart workflows to take corrective actions right away.
• Enhances team productivity and reduces human error
6. Complete Visibility and Management
• Enables collaboration among all stakeholders on a single platform. (employees, managers, auditors, etc.)
• Provides integrated task management for:
•Track compliance activities — see what tasks are being done to meet rules.
•Monitor progress — keep a record of all actions for audit and review.
•Set deadlines — make sure everything is completed on time.
• Improves project management and overall compliance oversight.
7. Real-Time Reporting and Monitoring
• Compliance software provides dynamic dashboards and real-time reports.
• Offers executive-level insights into operations.
• Supported by automation and integrated data sets for accurate monitoring
8. Data & Security
• Ensures encrypted data storage and secure data transfers.
• Provides a safer approach to managing the entire GRC process.
9. Reduced Costs
•Automated and efficient GRC tools help save money by cutting down manual work and errors.
•A complete GRC suite should manage everything in one place, including:
•Risks, policies, and audits, and
•The full cycle of risk identification, measurement, control, monitoring, and reporting across all
business areas
Chapter 11: Assessing Enterprise Cybersecurity
• Cybersecurity Auditing Methodology
• Cybersecurity Audit Types
• “Audit First” Design Methodology
• Enterprise Cybersecurity Assessments
• Level 1 Assessment: Focus on Risk Mitigations
• Level 2 Assessment: Focus on Functional Areas
• Level 3 Assessment: Focus on Security Capabilities
• Level 4 Assessment: Focus on Controls, Technologies, and Processes
• Audit Deficiency Management
Chapter 1: Assessing Enterprise Cybersecurity
• Focuses on evaluating and improving an organization’s cybersecurity program.
Key Topics Covered
• Audit Process:
• Explains how auditing helps assess enterprise cybersecurity performance.
• Audits Driving Control Design:
• Highlights how audit findings should guide the design and improvement of cybersecurity controls.
• Levels of Assessment:
• Describes four levels of assessment detail to systematically evaluate cybersecurity.
• Deficiency Tracking:
• Discusses tracking and managing deficiencies as part of a formal audit or assessment process.
• Assessment Types:
• Can be performed by internal or external assessors.
• May be:
• Risk-based, Threat-based, Framework-based, or Control-based.

Importance of Regular Assessment


• Formal, periodic audits are essential for a strong cybersecurity program.
Without regular evaluation, programs may weaken over time due to neglect or shifting IT priorities.
Cybersecurity Auditing Methodology
What is a Cybersecurity Audit?
• A cybersecurity audit is a process of checking automated systems or operational processes to ensure they are
functioning properly.
• Involves reviewing system records or logs to collect evidence of correct operations.
• The collected evidence is compiled into artifacts that support the audit findings.
• These artifacts and conclusions are documented as audit results, which:
• Record what was done during the audit,
• Summarize findings, and
• Highlight any deficiencies and remediation actions

Audit Workflow
A cybersecurity audit follows a step-by-step process:
• Analyze Security Records:
Review the data and logs created by security tools (like firewalls, antivirus, etc.) to see how systems are working.
• Collect Evidence:
Gather proof that the systems and processes are running properly and securely.
• Compile Results:
Combine all the evidence into an official audit report that summarizes what was checked and what was found.
• Store and Share Results:
Keep the report safe and share it with managers or other key people who need to review it.
Cybersecurity Auditing Methodology
The Challenge of Proving Negatives
• One big problem in auditing is proving that nothing bad happened (like no hacking or misuse).
• It’s hard to prove the absence of problems directly.
• So instead, auditors look for evidence that there are no signs of suspicious activity in the records or
logs.
Evidence-Based Reasoning
The idea is: if something bad happened, it would usually leave a trace (like unusual log entries or errors).
So by checking the records carefully and not finding anything odd, auditors can be confident that systems were fine.
How deeply they check depends on the type of data:
• Financial data: needs checking every transaction carefully.
• Other data: checking samples or spot checks might be enough.
Cybersecurity Audit Objectives
The audit planning process begins with defining the audit objective.
The objective is usually written as:
“I want my audit to indicate that ___ is occurring,” or
“I want my audit to indicate that ___ is NOT occurring.”
Examples of Cybersecurity Audit Objectives:
To confirm that web servers are functioning properly and serving correct web pages.
To confirm that IT systems comply with Sarbanes-Oxley regulations.
To confirm that payment information stored in systems is protected according to PCI (Payment Card
Industry) standards.
To confirm that attackers are NOT abusing system administrator accounts.
Threat-Based Audit Objectives:
These focus on the confidentiality, integrity, and availability of IT systems.
Examples include:
Ensuring that confidential customer data is not being accessed improperly.
Ensuring the integrity of financial transactions is being maintained (no unauthorized changes).
Ensuring the availability of front-end web applications is not being disrupted.
Cybersecurity Audit Objectives
Cybersecurity Audit Plans
Purpose of the Audit Plan:
• The second step after setting objectives is to create a plan for how the audit will be conducted to achieve the
desired results.
Challenge – Proving a Negative:
• Many audits aim to prove that something bad is NOT happening (e.g., no data breaches).
• It’s impossible to prove this with absolute certainty, but auditors can collect evidence that strongly supports the
idea that no such activity is occurring.
• The goal is to build a high level of confidence that systems are secure and undesired activities are not taking
place.
Steps in the Audit Planning Process:
• Step 1: Start with a clear audit objective.
• Step 2: Identify what evidence is needed to prove that objective.
• Step 3: Compare the desired evidence with the available evidence from:
• IT system audit trails and logs, and
• Manual process records.
Outcome:
The result is a structured audit plan that defines what will be checked, how evidence will be collected, and how
conclusions will be drawn.
Cybersecurity Audit Objectives
Cybersecurity Audit Planning Process
The cybersecurity audit planning process is a six-step method used to identify and collect the right
evidence to meet the audit objectives.
Sometimes, it may also involve updating IT systems or manual processes to record additional data.
Six Steps of the Cybersecurity Audit Planning Process
1. Analyze the Audit Objective:
• The auditor reviews and understands what the audit is trying to prove or verify.
• This helps determine what kind of information is needed to meet the objective.
2. Determine the Desired Evidence:
• The auditor identifies the type of evidence that would best support or prove the audit objective.
3. Review Available Records:
• The auditor checks what system logs, reports, or records are currently available for analysis.
4. Evaluate the Available Evidence:
• The auditor studies the available data to see if it is sufficient and relevant to satisfy the audit
objectives.
Cybersecurity Audit Planning Process
5. Modify Systems or Processes (if needed):
• If the current evidence is not enough, the auditor may recommend changes in IT systems or manual
processes.
• These changes help generate or log more useful data for future audits.
6. Develop Audit Procedures:
• Finally, the auditor creates. specific audit procedures - the step-by-step methods to analyze the collected
evidence and confirm whether the audit objectives are achieved
Audit Evidence Collection
Audit Procedures and Audit Artifacts
1. Audit Procedures:
• Define how records and evidence are analyzed to meet audit objectives.
Document includes:
• What records to analyze
• Analysis process or method
• Key info – record sources, contacts, sample sizes
• Audits often use statistical sampling instead of reviewing all records.
• Sample sizes and methods are chosen to give reasonable proof of compliance or non-compliance.
• Sampling is adjusted based on past failures, control weaknesses, and other issues.
Example: Imagine you want to check if your school keeps attendance records correctly.
• You decide which records to look at (attendance register).
• You plan how to check (compare with student logs).
• You decide how many records to review (maybe just 10 days instead of the whole year).
• This plan is your audit procedure.
2. Audit Artifacts:
• Records reviewed during audits become artifacts that support findings.
• Artifacts answer the “because” question – provide evidence behind conclusions.
• Example: “We believe admin accounts aren’t compromised because we reviewed 50% of admin activity
over two weeks and found no anomalies.”
Audit Evidence Collection
• Audit Artifacts (Proof or evidence)
• Example : These are the records or data you collect while doing the audit.
They are the proof that supports your conclusion.
• Example:
After checking the attendance register, you find no mistakes for 10 days.
You write:
• “Attendance records are correct because we checked 10 random days and found no errors.”
• Those 10 records you checked are your audit artifacts — they are evidence for your
statement.

3. Audit Artifacts : Artifacts are the evidence or data collected during an audit.
Example:
“Admin accounts are safe because 50% of admin activities checked for two weeks showed no
issues.”
Key Points:
Artifacts = data evidence supporting audit conclusions.
They are copied from system logs and stored with the audit report
Kept longer than original logs — smaller size, needed for future review.
Audit Evidence Collection
4. Audit Results
Final Step: All audit findings are summarized and reported to management.
What’s Included:
• What was audited
• Key findings and problems (deficiencies) to fix
How It’s Presented:
• Simple summary for managers - business impact and risk level.
• Technical details for security teams - to fix the problems.
Why It Matters:
• Results must be actionable (clear steps to improve).
• Security teams should use the report to create a plan for improvement before the next audit.

5. Deficiency Tracking
• During audits, security weaknesses (deficiencies) are often found.
• These issues must be tracked and fixed (remediated) - even if fixing happens later.
• If problems are not fixed or happen repeatedly, they must be reported to management.
Sometimes, fixing may be delayed because:
• It’s too costly, or
• Other business priorities come first.
• Any unfixed issue should be treated as a risk and managed through the organization’s risk management process
Audit Evidence Collection
7. Reporting and Records Retention
Reporting:
• Audit results and any fixes (remediations) should be shared with management.
• This helps with reviewing progress and ensuring follow-up.
Audit Records:
• Include the audit report and all evidence (artifacts).
• Artifacts from IT logs should be copied and stored safely, even after the original logs are deleted.
Retention (How long to keep records):
• Regulatory audits: Follow legal or auditor requirements.
• Non-regulatory audits: Keep records like other business or financial documents.

8. Deficiency Remediation Reporting


Timing of Reporting:
• Remediation may not be included in the original audit report.
• Reason: remediation can take weeks or months after the audit is completed.
Follow-Up Briefing:
• The remediation team can provide a separate follow-up briefing once remediation is done.
Regular Audits:
• For scheduled audits, the remediation team can report on deficiencies at the start of the next audit
cycle.
Cybersecurity Audit Types
General: All audits follow: objectives → evidence → report
1. Threat Audit (Hunting):
• Detects active cyberattacks on systems
• Focuses on CIA: confidentiality, integrity, availability
• Uses latest attacker tactics (TTPs)
• Reports which attacks occur and their outcomes
2. Assessment Audit:
•Checks if security controls follow rules or standards
•Finds out:
•Are controls stopping threats?
•Are they meeting regulations?
•How well do they work?
•Report shows controls, related rules, and how effective they are
•3. Validation Audit:
• Evaluates if controls are operating as designed
• Confirms actual effectiveness, not just applicability
• Helps improve control design and demonstrate compliance
Note: Audits can be combined, but inputs and outputs must be considered.
Cybersecurity Audit Types

Audit First Design Methodology


• Each audit type has specific inputs and outputs for evaluating different aspects of enterprise cybersecurity.
Problem with Preventive-First Design:
• Security practitioners often start with preventive controls (e.g., firewalls, antivirus).
• These controls are cheap, exciting, and easy to explain (“We block that behavior”).
• Reality: cybersecurity becomes security by obscurity until attackers bypass it.
• Preventive controls have vulnerabilities and dependencies that attackers can exploit.
Audit First Approach:
Design controls in this order:
• Audit controls → ensure visibility and monitoring
• Forensic controls → investigate incidents after they occur
• Detective controls → detect suspicious activity in real time
• Preventive controls → block threats only after considering the others
Benefits:
• Builds stronger, layered security.
• Easier to understand and manage.
• Reduces hidden weaknesses between systems.
• Ensures security is based on real threats, not just assumptions.
Cybersecurity Audit Types

Control System Flow


Test:
Check or monitor the system to see what’s
happening (gather data).
Control Input:
Information or signals sent into the system
based on test results.
Control Logic:
The decision-making rules that determine what
to do next.
Control Decision:
The output decision made by the logic (e.g.,
take action, raise alert).
Control Processing:
The actual action or response carried out by the
system (e.g., blocking access, changing settings).
Threat Analysis
Audit First Methodology: Threat Analysis & Audit Controls
Start with Threat Analysis:
• Identify threats to confidentiality, integrity, and availability (CIA) of enterprise data and IT systems.
• Group assets and controls into security scopes based on shared business impact from common threats.
Threat Prioritization:
• Focus on threats that are most likely and/or most dangerous.
• Gradually expand to include additional or less-likely threats as resources allow.
• Prioritize just like physical security, addressing greatest risks first.
Audit Controls:
• After threat analysis, design threat audit controls to monitor and detect threat activities

Audit First Methodology: Controls Design


1. Threat Audit Controls
• Designed after threat analysis to search for attacker activity.
Questions to consider:
• Confidentiality: How to detect breaches? What evidence would an attacker leave?
• Integrity: How to investigate inappropriate data changes?
• Availability: How to differentiate failures from attacks?
• Helps determine what information should be collected for detection
Threat Analysis
2. Forensic Controls
Purpose: Collect necessary data to investigate confidentiality, integrity, and availability breaches.
Often requires upgrades to IT systems:
• Improve logging
• Enable log correlation
• Support effective investigations
• Focus on likely threat scenarios first, avoid logging everything.
• Logs should cover all enterprise cybersecurity functional areas.

3. Detective Controls
• Designed to detect attacker activity in real time using collected logs.
Key considerations:
•Purpose: Detect hacker activity while it’s happening using those logs.
•Alerts should be accurate and useful, not too noisy.
•Tools like SIEM or big data systems can analyze and connect alerts.
•Focus on real threats, like unusual scans inside internal firewalls.
•These controls are low impact and easy to update quickly.
•Benefit: Helps catch attacks early and stop them before they cause major damage.
Threat Analysis
4. Preventive Controls
Purpose: Stop bad activities and block attacks before they happen.
But many companies focus too much on these and ignore other important controls (audit, forensic, detective).
Problems:
• Can be expensive and disrupt business.
• Attackers can sometimes bypass them.
Best Practices:
Use preventive controls wisely - only where they add real value.
• Reduce unnecessary investigation work.
• Keep costs and disruptions low.
• Avoid adding new weaknesses when setting up controls.

Key Advantage of Audit First Approach:


• Focus first on detecting and investigating attacks.
• Then add preventive controls to stop the most dangerous ones.
• This way, Enables the enterprise to detect, investigate, and stop attacks before attackers bypass defenses.

•First: Detect attacks (using audit and detective controls).


•Then: Investigate what happened (using forensic controls).
•Finally: Add preventive controls to stop the most dangerous attacks.
Letting Audits Drive Control Design
Audit First Methodology: Control Design Flow
Purpose:
Design controls that detect attacker activity while minimizing business disruption.
Step 1: Threat Audit
• Identify the most likely threats to confidentiality, integrity, and availability (CIA).
• Search for attacks that have occurred. If a data breach happened before, analyze how it started and what
signs were visible.
• Collect supporting evidence for each threat.
Step 2: Forensic Records
• Determine which logs and records are needed to track incidents.
• Capture Indicators of Compromise (IOCs) for detected attacks.
Step 3: Detective Controls
• Create alerts based on IOCs to notify defenders of ongoing attacks.
• Ensure alerts are actionable and focused on real threats.
• If many failed login attempts happen from one IP, send an alert.
Step 4: Preventive Controls
• Block attack patterns that are most destructive or hardest to detect.
• Supported by business processes for control operation and exception management.
• After seeing repeated phishing attempts, set up stronger email filters and employee training.
Outcome: Balanced security with effective detection, investigation, and prevention.
Enterprise Cybersecurity Assessment
The enterprise cybersecurity architecture supports a hierarchical assessment model that provides quick measurable
and progressively detailed results.
The model is linked to the risk assessment process and the 11 functional areas of enterprise cybersecurity.
It uses a top-down approach, focusing on functional areas and capabilities rather than individual controls.
Unlike traditional assessments that yield many unprioritized recommendations, this method offers strategic guidance for
managing and prioritizing remediation.
Grouping results by functional areas helps organize, report, and delegate remediation tasks effectively.
The assessment operates on four levels:
(1) Risk Mitigations: Are major business risks being reduced?
(2) Functional Areas: How well is each cybersecurity function performing?
(3) Security Capabilities: What specific abilities exist (like monitoring or response)?
(4) Controls, Technologies, and Processes: What tools and procedures are in place?
Each level produces actionable results, with lower levels offering more detailed insights.
Figure 11-7 illustrates the four assessment types, and Appendix H gives an example for a notional enterprise.
Four Levels of Enterprise Cybersecurity Assessment
Level 1 – Risk Mitigations
Analyzes enterprise risks and threats to confidentiality, integrity, and availability.
Identifies key threat vectors and evaluates defenses to disrupt, detect, and defeat attacks.
Level 2 – Functional Areas
Reviews 11 cybersecurity functional areas and operations.
Finds vulnerable areas most likely to be exploited and prioritizes them for improvement.
Level 3 – Security Capabilities
Assesses 113 capabilities and 17 operational processes in detail.
Measures their effectiveness and identifies areas for enhancement.
Level 4 – Controls, Technologies, and Processes
Evaluates controls, tools, and processes delivering cybersecurity.
Recommends tuning or remediation to improve effectiveness.
Level 1 – Risk Mitigations
• What it does:
what major risks and threats could harm the organization’s data and systems.

• Finds threats to Confidentiality, Integrity, and Availability (CIA) — like data theft, data
tampering, or downtime.
• Identifies how attackers might strike (threat vectors).
• Checks if current defenses can block, detect, or stop those attacks.
• Example: Checks if the company can handle a ransomware or phishing attack.

Level 2 – Functional Areas


• What it does:
Reviews how well the company is performing across the 11 main cybersecurity areas (like
network security, incident response, access control, etc.).

• Finds weak spots in these areas — the ones hackers are most likely to exploit.
• Helps the company prioritize which areas to fix first.
• Example: If “identity management” is weak, that becomes a top priority to improve.
Level 3 – Security Capabilities
• What it does:
Goes deeper — examines specific security skills and processes the company uses.
There are 113 capabilities and 17 operational processes that are reviewed.

• Measures how well each capability works (like monitoring, response, patching).
• Identifies which ones need upgrading or improvement.
• Example: Checks if the company can quickly detect and respond to a data breach.

Level 4 – Controls, Technologies, and Processes


• What it does:
Looks at the actual tools, settings, and daily processes that keep systems safe.

• Reviews specific controls (like firewalls, antivirus, access logs).


• Suggests fine-tuning or fixes to make them more effective.
• Example: Recommends updating antivirus software or improving log monitoring.
Enterprise Cybersecurity Assessment conti..
•Assessments should match the specific security scopes (areas or systems being protected) because each faces
different threats.
•If there are multiple scopes, do separate assessments for each.
•A whole-organization assessment gives a big picture but less detail.
•Self-assessments are useful — they show security performance with less cost and time.
•Use numerical scores to measure cybersecurity strength (explained in Chapter 12).
•These scores help leaders balance security risks with business needs.

Level 1 Assessment – Risk Mitigations


Identifies the most likely and dangerous threats using the enterprise risk management methodology.
• Evaluates threats by analyzing their attack sequences and related security controls that log, detect, or block them.
• Reviews system logs to find evidence of past or ongoing attacks.
Produces outcomes including:
Key risks and threats to the security scope.
Attack sequence documentation.
Relevant controls and their effectiveness.
Scores showing how controls reduce attack likelihood or impact.
Level 1 Assessment – Focus on Risk Mitigations: (In detail)
Purpose
• This assessment checks how well an organization can detect, prevent, and reduce cybersecurity risks.
It looks at big threats to the system and how existing controls (security measures) protect against them.
Steps :
• Find threats – Identify what could harm your systems or data and how it might affect confidentiality,
integrity, and availability (CIA).
(Example: A hacker stealing data = confidentiality risk.)
• Prioritize threats – Figure out which threats are most likely to happen and which would cause the most
damage.
• Analyze attack methods – Understand how an attacker might carry out each major threat step-by-step.
• Check security controls – Review what security tools or processes (like firewalls, antivirus, logging, or
monitoring) are in place to: Detect attacks, Block them, Reduce their impact
• Review logs – If possible, look at system logs to see if attacks have already happened or if something was
missed.
Assessment Outcomes
• A list of the main risks and their related threats.
• Details of how attacks could happen for each risk.
• Identification of security measures that protect against those attacks.
• A score or rating showing how effective those controls are in reducing the chance or impact of attacks.
Level 2 Assessment – Focus on Functional Areas (In Deatil..)
Overview
Builds on Level 1 (Risk Mitigations) by evaluating the 11 enterprise cybersecurity functional areas and
security operations.
Estimates overall security effectiveness for each security scope using expert judgment and scoring.
Purpose
Measures the effectiveness of each functional area to identify strengths and weaknesses.
Each functional area is considered of equal importance; the weakest areas are the most vulnerable and
should be prioritized for improvement.
Scope of Assessment
Conducted for each security scope; multiple assessments may be needed if multiple scopes exist.
When combined with risk mitigations and security operations, there are 13 total characteristics to evaluate.
Assessment Activities
Use Level 1 results to identify security scopes and risk mitigations.
Assess all 11 functional areas for comprehensiveness and effectiveness using expert evaluation.
Evaluate security operations similarly at a high level.
Record results to identify strongest and weakest functional areas.
For weaker areas, identify improvement needs (people, processes, budgets, technology, capabilities).
Compare the overall security posture with the required security level of each scope.
Outcomes
Evaluation of all functional areas and security operations.
Identification of weakest areas for prioritization and strengthening.
Combined results with Level 1 (Risk Mitigations) and security operations review for a complete Level 2
Assessment outcome.
Level 2 Assessment – Focus on Functional Areas:
Purpose
• This level checks how well each part of your organization’s cybersecurity works.
It helps find which areas are strong and which are weak, so you know where to improve.
What It Builds On
• It continues from Level 1 (Risk Mitigations) : which focused on finding and reducing big risks and now looks at the 11
main cybersecurity functional areas (like access control, incident response, data protection, etc.) plus security
operations.
Assessment Activities:
• Use Level 1 results – Start with what you already learned about major risks and security scopes.
• Evaluate all 11 areas – Check how well each cybersecurity function is working (thoroughness, effectiveness, coverage).
• Review security operations – Look at how well your organization monitors, detects, and responds to threats.
• Record findings – Note which areas perform well and which ones need improvement.
• Identify improvements – For weak areas, suggest what’s needed — more staff, better processes, more training, tools, or
funding.
• Compare with goals – See if your current security level meets what’s required for your organization or system.
Results (Outcomes)
• A full review of all functional areas and security operations.
• Clear identification of the weakest areas to focus on improving.
• A complete picture of your organization’s overall cybersecurity strength when combined with Level 1 results.
Level 3 Assessment – Focus on Security Capabilities(In Deatil..)
Overview
• The Level 3 Assessment examines individual security capabilities within each functional area and the 17 operational processes.
• It evaluates each capability and process in terms of maturity (how well it works) and utilization (how consistently it is used).
Relation to Previous Levels
• Builds on Level 2 by replacing broad expert judgments with detailed evaluations.
• Can either replace Level 2 entirely or supplement it by focusing only on areas needing deeper review.
• (For example, instead of just “Access Control,” it checks password policies, multi-factor authentication, and account reviews
separately.)
Purpose
• Provides specific and actionable results while maintaining efficiency.
• Can be used to develop improvement plans for weaker areas or to validate the Level 2 findings.
• Offers a good balance between assessment effort and useful outcomes—suitable for self-assessment.
Assessment Activities
• Use Level 1 results to identify security scopes and related risk mitigations.
• Identify functional areas and their corresponding cybersecurity capabilities to be evaluated.
Evaluate each capability and process for:
• Maturity – how effectively it operates.
• Utilization – how consistently it is applied.
• Assess the technologies and processes supporting each capability.
• Identify strong and weak capabilities to prioritize for improvement.
Scope Options
• Can be a complete assessment (covering all capabilities and processes) or a partial one (focusing on specific areas needing attention).
Key Insight
• The presence of capabilities doesn’t guarantee effectiveness.
• A functional area may be strong without all capabilities, or weak despite having many—especially if poorly configured or easily
bypassed by attackers.
Level 4 Assessment – Focus on Controls, Technologies, and Processes(In Deatil..)

Overview
• The Level 4 Assessment evaluates specific controls, technologies, and supporting processes that enable risk
mitigations, security capabilities, and operational processes.
• It builds on Level 3 by going into technical and operational detail.
Purpose
• Identifies and prioritizes areas for improvement to enhance enterprise security.
• Can be full or partial, focusing on a specific functional area, set of capabilities, or selected controls as needed.
• Especially useful for deficient areas, helping to find tuning opportunities and cost-effective improvements.
Assessment Activities
• Identify relevant functional areas, capabilities, or operational processes and their associated controls, technologies,
or processes.
• Because of the detail involved, focus on a small, critical set of items of greatest concern.
• Examine in detail each control, technology, or process to find issues in effectiveness, configuration, or operation.
• Include any third-party products related to those controls or technologies.
• Develop specific, actionable recommendations to fix identified issues.
Outcome
• Produces targeted recommendations for improving the effectiveness of each examined control, technology, or
process.
• Recommendations can be combined into comprehensive change proposals to enhance overall enterprise security
performance.
• All results are technology-specific and actionable for immediate improvement.
Audit Deficiency Management
Deficiencies and Deficiency Tracking
Importance of Deficiency Tracking
• Tracking deficiencies is a critical part of the auditing process and should not be ignored after an audit
ends.
• Often, security shortcomings persist because attention shifts away once the audit is complete.
• Deficiencies weaken or nullify the protection provided by security controls and capabilities.
• Tracking them is one of the 17 key processes for successful cybersecurity operations.
Definition of a Deficiency
A security deficiency occurs when a capability, process, technology, or control does not function as
designed or documented.
It means the actual enterprise security is less effective than what documentation suggests.
Example: Documentation says firewalls block all inbound traffic except A, B, and C, but an audit finds D, E,
and F are also allowed — this is a security deficiency.
Purpose of Identifying Deficiencies
Audits expose discrepancies between expected and actual performance of security measures.
Deficiencies highlight gaps between policy and practice, showing where enterprise security may fail.
Deficiency Tracking Process
Once identified, deficiencies should be formally tracked until they are resolved or accepted.
Not all deficiencies require immediate remediation, but none should be ignored.
Tracking should be part of the enterprise risk management process to ensure no issues are overlooked.
Figure 11-8 illustrates the life cycle process for tracking deficiencies.
Deficiency Tracking Process
Formal Tracking Requirement
All deficiencies found during audits must be formally tracked until they are remediated.
If not remediated, they should be classified and tracked as enterprise risks.
The process includes six key steps within the broader auditing and deficiency tracking cycle.
Step 1 – Identify Deficiencies
Conduct audits or formal tests of security capabilities, processes, or technologies.
Deficiencies occur when:
• Systems don’t work as claimed,
• Reality doesn’t match documentation, or
• Security fails to meet required standards.
Step 2 – Track Deficiencies
Maintain a deficiency list using a spreadsheet, database, or tracking tool.
Tracking must be robust and persistent, ensuring data isn’t lost due to staff turnover or system changes.
The list should track unresolved issues over weeks, months, or years.
Regular reports should be provided to management until issues are resolved, converted to risks, or closed.
Step 3 – Remediate Deficiencies
Ideally, deficiencies are fixed promptly to restore proper functionality.
In reality, remediation often faces challenges such as:
• Disagreements between auditors and technical staff about the issue’s validity or severity.
• Delays or resource constraints (staffing, budget, or priorities).
Management must make final decisions and define reasonable timelines for remediation.
Deficiency Resolution and Documentation
Deficiency Resolution and Documentation
Documenting Resolved Deficiencies
Resolved deficiencies should be documented and reported just like open ones.
Documentation serves two key purposes:
• Recognizes and credits the teams fixing the issues.
• Provides visibility into deficiencies that recur frequently, especially in manual processes.
• Repeated deficiencies should be tracked as enterprise risks, since they indicate ongoing weaknesses.
Unresolved Deficiencies
• Deficiencies not remediated in a timely manner (e.g., over a year) are considered unresolved, unless
covered by an approved mitigation plan.
• Causes often include resource limitations or enterprise priorities.
Consequences of Unresolved Deficiencies
• The affected capability, process, technology, or control becomes less effective.
• Sometimes acceptable if compensating controls exist to limit the overall risk.
• Documentation must be updated to reflect the deficiency and its expected performance level.
Example and Documentation Practice
• Example: A manual account de-provisioning process that is 75% effective is acceptable if properly
documented.
• Future audits should expect 75% effectiveness, not 100%.
• Transparency prevents misunderstandings between auditors and management.
Risk Implications
• Unresolved deficiencies increase residual enterprise risk beyond planned levels.
• Auditors must inform management (especially CISOs) about deficiencies affecting key risk controls.
• Awareness ensures enterprise leadership understands true risk exposure.
Audit Follow-Up and Tracking
• All audit findings, deficiencies, and recommendations must be tracked to completion—whether from
internal, external, or threat audits.
Consistent tracking, follow-up, and timely remediation ensure the enterprise gains maximum benefit from
the audit process.

You might also like