Module 5
Module 5
Alakananda K
Asst Prof, CSE
CYBER SECURITY COMPLIANCE
• Compliance means following all the rules and requirements related to cybersecurity.
It includes the organization’s own cyber security policy, as well as regulatory
requirements, contractual, and legal obligations.
• To make sure the organization follows its own policies, security controls are used.
• These security controls come from defined processes, which are based on standards and
frameworks (like ISO, NIST, etc.).
• The standards and frameworks are created to help the organization meet its cybersecurity
policy goals.
• So, the policy is implemented in practice through these security controls.
o Just like internal security policies(internal Infosec policy), controls are also created to
follow regulatory, legal, and contractual requirements.
• Different departments or units in the organization are responsible for regularly checking
and monitoring these controls.
• The audit team reviews how well these controls are implemented.
• This acts as the third level of defense in cybersecurity.
CYBER SECURITY COMPLIANCE
•The Master Direction consolidates important control aspects broadly in the following areas.
Broad Digital Payment Security Controls (DPSC) Master
Directions – 02.02.2022
The Master Direction consolidates important control aspects broadly in the following areas.
1. Governance and Management of Security Risks
2. Generic Controls:-
3. Application Security Life Cycle:
4. Authentication Framework:-
5. Fraud Risk Management:-
6. Reconciliation mechanism:
7. Customer protection:-
8. Awareness and grievance redressal mechanism:-
9. Internet Banking application security controls:-
10. Mobile payment application security controls:-
11. Card payment security controls:
1. Governance and Management of Security Risks
• Focuses on identifying, analyzing, monitoring, and managing fraud risk and compliance risk related to digital
payment products.
• Achieved through proper risk governance and risk management programs.
• Digital Payment Security Policy Must be approved by the Board of Directors.
• Should be reviewed regularly to ensure it stays updated with new threats and technologies.
2. Generic Security Controls
• Implement an appropriate level of encryption across all digital payment channels, especially for internet-based
systems.
• Deploy a Web Application Firewall (WAF) to protect online payment applications.
• Prevent DDoS Attacks: Distributed Denial of Service (DDoS) attacks to maintain service availability.
3. Application Security Life Cycle
• Applications must be protected by following recognized security standards and guidelines, such as:
• OWASP (Open Web Application Security Project) -Helps find and fix common web app security problems.
• ISO 12812 (Data Protection Requirements) - Gives rules for protecting payment data.
• NIST (National Institute of Standards and Technology) Threat Catalogues - Lists possible threats and how
to handle them
• These standards should be followed from the very beginning of the application development process.
Phases
• Design: Identify risks & define security needs.
• Development: Use secure coding & code review.
• Testing: Perform security testing & fix issues.
• Deploy: Ensure secure setup & patch systems.
• Maintain: Monitor, update, and patch regularly.
4. Authentication Framework
• Regulated Entities (REs) must implement Multi-Factor Authentication (MFA) for:
• Payments, and Fund transfers through electronic modes and payment applications.
• Entities should use at least one authentication method that is:
• Dynamic (changes with each transaction), or
• Non-replicable (cannot be copied or reused).
5. Fraud Risk Management
• Entities must implement security controls to detect suspicious transactions through system configuration and
monitoring.
Key Parameters
• Transaction Velocity: Rapid fund transfers or new beneficiaries in inactive accounts.
• Card Indicators: Repeated failed PIN/CVV attempts (possible fake activity).
• New Accounts: Unusual or excess activity soon after creation.
• Geo/IP Check: Transactions from restricted zones or suspicious IPs.
• Blacklisted Links: Transfers to known fraud mobile numbers or wallets.
6. Reconciliation Mechanism
• A real-time or near real-time reconciliation system must be implemented.
• Reconciliation should be completed within 24 hours of receiving settlement files.
• Applies to all digital payment transactions between the Regulated Entity (RE) and other stakeholders.
• Helps in early detection and prevention of suspicious transactions.
7. Customer Protection
• Digital payment products/services should be offered only with customer consent, based on a written or
electronically authenticated request.
• Customers must receive a positive acknowledgement confirming acceptance of terms and conditions.
• REs must provide an in-app mechanism (mobile or internet banking) for customers to:
• Identify or mark transactions as fraudulent, and
• Instantly notify the RE with proper authentication.
8. Awareness and Grievance Redressal Mechanism
• REs should continuously create public awareness about:
• Various cyber threats and attacks, and Precautionary measures to stay safe while using digital payment
products.
• Customers must be cautioned and educated about common threats such as:
• Phishing, Vishing, Reverse Phishing, and Remote access attacks on mobile devices.
• Users should be advised to protect account details, credentials, PINs, card details, and devices.
• REs must establish online dispute resolution systems to handle customer disputes and grievances related
to digital payments, in line with updated RBI instructions
9. Internet Banking Application Security Controls
• Enable CAPTCHA and adaptive authentication for login security.
• Deactivate user sessions automatically after a set period of inactivity.
• Ensure secure delivery of initial passwords to users.
10. Mobile Payment Application Security Controls
• Collect minimal data and request only necessary app permissions.
• Use application sandboxing or containerization for isolation and protection.
• Implement device binding of the mobile app using both hardware and software methods.
• The app must not store sensitive information such as user IDs, passwords, keys, or hashes.
11. Card Payment Security Controls
• Implement ATM and PCI-related security standards, such as PCI DSS, for secure card
transactions.
Combination of Governance, Risk, and Compliance (GRC) & Automation
• GRC means Governance, Risk Management, and Compliance — three important parts of keeping an organization
secure and well-managed (key pillars of an effective cybersecurity program)
• Governance: Setting rules, policies, and responsibilities.
• Risk Management: Finding and reducing possible problems or threats.
• Compliance: Making sure all laws, regulations, and standards are followed.
These three together help organizations to:
• Follow legal and security rules,
• Control and reduce risks, and
• Keep all processes organized and consistent.
• Because doing all this manually takes a lot of time and effort, companies now use GRC automation — software tools
that automatically track risks, check compliance, and generate reports.
Automation of GRC
• 1. Automation of GRC in cybersecurity brings key benefits:
• Transparency – clear visibility into risks and compliance status.
• Efficiency – faster and more accurate processes.
• Accountability – better tracking of responsibilities and actions.
• 2. A modern GRC management tool offers:
• A configurable, user-friendly solution.
• Seamless integration with existing technology systems.
• 3. Advantages over legacy/manual systems:
• Improved data accuracy and reporting.
• Centralized management of risks and compliance.
• Real-time monitoring and automated updates.
4. Full Customisation
• GRC management systems provide a fully customized approach to:
• Identify risks across the business.
• Measure and mitigate those risks effectively.
• Ensure compliance with both internal policies and external regulations.
5. 24/7 Automation
• GRC tools operate continuously, reducing the need for manual data entry.
• They can:
•Track obligations: Keep an eye on what the organization must follow (rules, policies, laws).
•Find compliance gaps: Spot where the company is not meeting requirements.
•Fix issues automatically: Use smart workflows to take corrective actions right away.
• Enhances team productivity and reduces human error
6. Complete Visibility and Management
• Enables collaboration among all stakeholders on a single platform. (employees, managers, auditors, etc.)
• Provides integrated task management for:
•Track compliance activities — see what tasks are being done to meet rules.
•Monitor progress — keep a record of all actions for audit and review.
•Set deadlines — make sure everything is completed on time.
• Improves project management and overall compliance oversight.
7. Real-Time Reporting and Monitoring
• Compliance software provides dynamic dashboards and real-time reports.
• Offers executive-level insights into operations.
• Supported by automation and integrated data sets for accurate monitoring
8. Data & Security
• Ensures encrypted data storage and secure data transfers.
• Provides a safer approach to managing the entire GRC process.
9. Reduced Costs
•Automated and efficient GRC tools help save money by cutting down manual work and errors.
•A complete GRC suite should manage everything in one place, including:
•Risks, policies, and audits, and
•The full cycle of risk identification, measurement, control, monitoring, and reporting across all
business areas
Chapter 11: Assessing Enterprise Cybersecurity
• Cybersecurity Auditing Methodology
• Cybersecurity Audit Types
• “Audit First” Design Methodology
• Enterprise Cybersecurity Assessments
• Level 1 Assessment: Focus on Risk Mitigations
• Level 2 Assessment: Focus on Functional Areas
• Level 3 Assessment: Focus on Security Capabilities
• Level 4 Assessment: Focus on Controls, Technologies, and Processes
• Audit Deficiency Management
Chapter 1: Assessing Enterprise Cybersecurity
• Focuses on evaluating and improving an organization’s cybersecurity program.
Key Topics Covered
• Audit Process:
• Explains how auditing helps assess enterprise cybersecurity performance.
• Audits Driving Control Design:
• Highlights how audit findings should guide the design and improvement of cybersecurity controls.
• Levels of Assessment:
• Describes four levels of assessment detail to systematically evaluate cybersecurity.
• Deficiency Tracking:
• Discusses tracking and managing deficiencies as part of a formal audit or assessment process.
• Assessment Types:
• Can be performed by internal or external assessors.
• May be:
• Risk-based, Threat-based, Framework-based, or Control-based.
Audit Workflow
A cybersecurity audit follows a step-by-step process:
• Analyze Security Records:
Review the data and logs created by security tools (like firewalls, antivirus, etc.) to see how systems are working.
• Collect Evidence:
Gather proof that the systems and processes are running properly and securely.
• Compile Results:
Combine all the evidence into an official audit report that summarizes what was checked and what was found.
• Store and Share Results:
Keep the report safe and share it with managers or other key people who need to review it.
Cybersecurity Auditing Methodology
The Challenge of Proving Negatives
• One big problem in auditing is proving that nothing bad happened (like no hacking or misuse).
• It’s hard to prove the absence of problems directly.
• So instead, auditors look for evidence that there are no signs of suspicious activity in the records or
logs.
Evidence-Based Reasoning
The idea is: if something bad happened, it would usually leave a trace (like unusual log entries or errors).
So by checking the records carefully and not finding anything odd, auditors can be confident that systems were fine.
How deeply they check depends on the type of data:
• Financial data: needs checking every transaction carefully.
• Other data: checking samples or spot checks might be enough.
Cybersecurity Audit Objectives
The audit planning process begins with defining the audit objective.
The objective is usually written as:
“I want my audit to indicate that ___ is occurring,” or
“I want my audit to indicate that ___ is NOT occurring.”
Examples of Cybersecurity Audit Objectives:
To confirm that web servers are functioning properly and serving correct web pages.
To confirm that IT systems comply with Sarbanes-Oxley regulations.
To confirm that payment information stored in systems is protected according to PCI (Payment Card
Industry) standards.
To confirm that attackers are NOT abusing system administrator accounts.
Threat-Based Audit Objectives:
These focus on the confidentiality, integrity, and availability of IT systems.
Examples include:
Ensuring that confidential customer data is not being accessed improperly.
Ensuring the integrity of financial transactions is being maintained (no unauthorized changes).
Ensuring the availability of front-end web applications is not being disrupted.
Cybersecurity Audit Objectives
Cybersecurity Audit Plans
Purpose of the Audit Plan:
• The second step after setting objectives is to create a plan for how the audit will be conducted to achieve the
desired results.
Challenge – Proving a Negative:
• Many audits aim to prove that something bad is NOT happening (e.g., no data breaches).
• It’s impossible to prove this with absolute certainty, but auditors can collect evidence that strongly supports the
idea that no such activity is occurring.
• The goal is to build a high level of confidence that systems are secure and undesired activities are not taking
place.
Steps in the Audit Planning Process:
• Step 1: Start with a clear audit objective.
• Step 2: Identify what evidence is needed to prove that objective.
• Step 3: Compare the desired evidence with the available evidence from:
• IT system audit trails and logs, and
• Manual process records.
Outcome:
The result is a structured audit plan that defines what will be checked, how evidence will be collected, and how
conclusions will be drawn.
Cybersecurity Audit Objectives
Cybersecurity Audit Planning Process
The cybersecurity audit planning process is a six-step method used to identify and collect the right
evidence to meet the audit objectives.
Sometimes, it may also involve updating IT systems or manual processes to record additional data.
Six Steps of the Cybersecurity Audit Planning Process
1. Analyze the Audit Objective:
• The auditor reviews and understands what the audit is trying to prove or verify.
• This helps determine what kind of information is needed to meet the objective.
2. Determine the Desired Evidence:
• The auditor identifies the type of evidence that would best support or prove the audit objective.
3. Review Available Records:
• The auditor checks what system logs, reports, or records are currently available for analysis.
4. Evaluate the Available Evidence:
• The auditor studies the available data to see if it is sufficient and relevant to satisfy the audit
objectives.
Cybersecurity Audit Planning Process
5. Modify Systems or Processes (if needed):
• If the current evidence is not enough, the auditor may recommend changes in IT systems or manual
processes.
• These changes help generate or log more useful data for future audits.
6. Develop Audit Procedures:
• Finally, the auditor creates. specific audit procedures - the step-by-step methods to analyze the collected
evidence and confirm whether the audit objectives are achieved
Audit Evidence Collection
Audit Procedures and Audit Artifacts
1. Audit Procedures:
• Define how records and evidence are analyzed to meet audit objectives.
Document includes:
• What records to analyze
• Analysis process or method
• Key info – record sources, contacts, sample sizes
• Audits often use statistical sampling instead of reviewing all records.
• Sample sizes and methods are chosen to give reasonable proof of compliance or non-compliance.
• Sampling is adjusted based on past failures, control weaknesses, and other issues.
Example: Imagine you want to check if your school keeps attendance records correctly.
• You decide which records to look at (attendance register).
• You plan how to check (compare with student logs).
• You decide how many records to review (maybe just 10 days instead of the whole year).
• This plan is your audit procedure.
2. Audit Artifacts:
• Records reviewed during audits become artifacts that support findings.
• Artifacts answer the “because” question – provide evidence behind conclusions.
• Example: “We believe admin accounts aren’t compromised because we reviewed 50% of admin activity
over two weeks and found no anomalies.”
Audit Evidence Collection
• Audit Artifacts (Proof or evidence)
• Example : These are the records or data you collect while doing the audit.
They are the proof that supports your conclusion.
• Example:
After checking the attendance register, you find no mistakes for 10 days.
You write:
• “Attendance records are correct because we checked 10 random days and found no errors.”
• Those 10 records you checked are your audit artifacts — they are evidence for your
statement.
3. Audit Artifacts : Artifacts are the evidence or data collected during an audit.
Example:
“Admin accounts are safe because 50% of admin activities checked for two weeks showed no
issues.”
Key Points:
Artifacts = data evidence supporting audit conclusions.
They are copied from system logs and stored with the audit report
Kept longer than original logs — smaller size, needed for future review.
Audit Evidence Collection
4. Audit Results
Final Step: All audit findings are summarized and reported to management.
What’s Included:
• What was audited
• Key findings and problems (deficiencies) to fix
How It’s Presented:
• Simple summary for managers - business impact and risk level.
• Technical details for security teams - to fix the problems.
Why It Matters:
• Results must be actionable (clear steps to improve).
• Security teams should use the report to create a plan for improvement before the next audit.
5. Deficiency Tracking
• During audits, security weaknesses (deficiencies) are often found.
• These issues must be tracked and fixed (remediated) - even if fixing happens later.
• If problems are not fixed or happen repeatedly, they must be reported to management.
Sometimes, fixing may be delayed because:
• It’s too costly, or
• Other business priorities come first.
• Any unfixed issue should be treated as a risk and managed through the organization’s risk management process
Audit Evidence Collection
7. Reporting and Records Retention
Reporting:
• Audit results and any fixes (remediations) should be shared with management.
• This helps with reviewing progress and ensuring follow-up.
Audit Records:
• Include the audit report and all evidence (artifacts).
• Artifacts from IT logs should be copied and stored safely, even after the original logs are deleted.
Retention (How long to keep records):
• Regulatory audits: Follow legal or auditor requirements.
• Non-regulatory audits: Keep records like other business or financial documents.
3. Detective Controls
• Designed to detect attacker activity in real time using collected logs.
Key considerations:
•Purpose: Detect hacker activity while it’s happening using those logs.
•Alerts should be accurate and useful, not too noisy.
•Tools like SIEM or big data systems can analyze and connect alerts.
•Focus on real threats, like unusual scans inside internal firewalls.
•These controls are low impact and easy to update quickly.
•Benefit: Helps catch attacks early and stop them before they cause major damage.
Threat Analysis
4. Preventive Controls
Purpose: Stop bad activities and block attacks before they happen.
But many companies focus too much on these and ignore other important controls (audit, forensic, detective).
Problems:
• Can be expensive and disrupt business.
• Attackers can sometimes bypass them.
Best Practices:
Use preventive controls wisely - only where they add real value.
• Reduce unnecessary investigation work.
• Keep costs and disruptions low.
• Avoid adding new weaknesses when setting up controls.
• Finds threats to Confidentiality, Integrity, and Availability (CIA) — like data theft, data
tampering, or downtime.
• Identifies how attackers might strike (threat vectors).
• Checks if current defenses can block, detect, or stop those attacks.
• Example: Checks if the company can handle a ransomware or phishing attack.
• Finds weak spots in these areas — the ones hackers are most likely to exploit.
• Helps the company prioritize which areas to fix first.
• Example: If “identity management” is weak, that becomes a top priority to improve.
Level 3 – Security Capabilities
• What it does:
Goes deeper — examines specific security skills and processes the company uses.
There are 113 capabilities and 17 operational processes that are reviewed.
• Measures how well each capability works (like monitoring, response, patching).
• Identifies which ones need upgrading or improvement.
• Example: Checks if the company can quickly detect and respond to a data breach.
Overview
• The Level 4 Assessment evaluates specific controls, technologies, and supporting processes that enable risk
mitigations, security capabilities, and operational processes.
• It builds on Level 3 by going into technical and operational detail.
Purpose
• Identifies and prioritizes areas for improvement to enhance enterprise security.
• Can be full or partial, focusing on a specific functional area, set of capabilities, or selected controls as needed.
• Especially useful for deficient areas, helping to find tuning opportunities and cost-effective improvements.
Assessment Activities
• Identify relevant functional areas, capabilities, or operational processes and their associated controls, technologies,
or processes.
• Because of the detail involved, focus on a small, critical set of items of greatest concern.
• Examine in detail each control, technology, or process to find issues in effectiveness, configuration, or operation.
• Include any third-party products related to those controls or technologies.
• Develop specific, actionable recommendations to fix identified issues.
Outcome
• Produces targeted recommendations for improving the effectiveness of each examined control, technology, or
process.
• Recommendations can be combined into comprehensive change proposals to enhance overall enterprise security
performance.
• All results are technology-specific and actionable for immediate improvement.
Audit Deficiency Management
Deficiencies and Deficiency Tracking
Importance of Deficiency Tracking
• Tracking deficiencies is a critical part of the auditing process and should not be ignored after an audit
ends.
• Often, security shortcomings persist because attention shifts away once the audit is complete.
• Deficiencies weaken or nullify the protection provided by security controls and capabilities.
• Tracking them is one of the 17 key processes for successful cybersecurity operations.
Definition of a Deficiency
A security deficiency occurs when a capability, process, technology, or control does not function as
designed or documented.
It means the actual enterprise security is less effective than what documentation suggests.
Example: Documentation says firewalls block all inbound traffic except A, B, and C, but an audit finds D, E,
and F are also allowed — this is a security deficiency.
Purpose of Identifying Deficiencies
Audits expose discrepancies between expected and actual performance of security measures.
Deficiencies highlight gaps between policy and practice, showing where enterprise security may fail.
Deficiency Tracking Process
Once identified, deficiencies should be formally tracked until they are resolved or accepted.
Not all deficiencies require immediate remediation, but none should be ignored.
Tracking should be part of the enterprise risk management process to ensure no issues are overlooked.
Figure 11-8 illustrates the life cycle process for tracking deficiencies.
Deficiency Tracking Process
Formal Tracking Requirement
All deficiencies found during audits must be formally tracked until they are remediated.
If not remediated, they should be classified and tracked as enterprise risks.
The process includes six key steps within the broader auditing and deficiency tracking cycle.
Step 1 – Identify Deficiencies
Conduct audits or formal tests of security capabilities, processes, or technologies.
Deficiencies occur when:
• Systems don’t work as claimed,
• Reality doesn’t match documentation, or
• Security fails to meet required standards.
Step 2 – Track Deficiencies
Maintain a deficiency list using a spreadsheet, database, or tracking tool.
Tracking must be robust and persistent, ensuring data isn’t lost due to staff turnover or system changes.
The list should track unresolved issues over weeks, months, or years.
Regular reports should be provided to management until issues are resolved, converted to risks, or closed.
Step 3 – Remediate Deficiencies
Ideally, deficiencies are fixed promptly to restore proper functionality.
In reality, remediation often faces challenges such as:
• Disagreements between auditors and technical staff about the issue’s validity or severity.
• Delays or resource constraints (staffing, budget, or priorities).
Management must make final decisions and define reasonable timelines for remediation.
Deficiency Resolution and Documentation
Deficiency Resolution and Documentation
Documenting Resolved Deficiencies
Resolved deficiencies should be documented and reported just like open ones.
Documentation serves two key purposes:
• Recognizes and credits the teams fixing the issues.
• Provides visibility into deficiencies that recur frequently, especially in manual processes.
• Repeated deficiencies should be tracked as enterprise risks, since they indicate ongoing weaknesses.
Unresolved Deficiencies
• Deficiencies not remediated in a timely manner (e.g., over a year) are considered unresolved, unless
covered by an approved mitigation plan.
• Causes often include resource limitations or enterprise priorities.
Consequences of Unresolved Deficiencies
• The affected capability, process, technology, or control becomes less effective.
• Sometimes acceptable if compensating controls exist to limit the overall risk.
• Documentation must be updated to reflect the deficiency and its expected performance level.
Example and Documentation Practice
• Example: A manual account de-provisioning process that is 75% effective is acceptable if properly
documented.
• Future audits should expect 75% effectiveness, not 100%.
• Transparency prevents misunderstandings between auditors and management.
Risk Implications
• Unresolved deficiencies increase residual enterprise risk beyond planned levels.
• Auditors must inform management (especially CISOs) about deficiencies affecting key risk controls.
• Awareness ensures enterprise leadership understands true risk exposure.
Audit Follow-Up and Tracking
• All audit findings, deficiencies, and recommendations must be tracked to completion—whether from
internal, external, or threat audits.
Consistent tracking, follow-up, and timely remediation ensure the enterprise gains maximum benefit from
the audit process.