0% found this document useful (0 votes)
27 views20 pages

Cybersecurity Governance and Compliance Framework

The document discusses the importance of cyber security planning in the context of banking, highlighting the 2016 Indian debit card breach and the subsequent need for a Board-approved Cyber-security Policy as mandated by the RBI. It outlines various approaches to cyber risk management, including Governance-Risk-Compliance (GRC) and standards-driven methods like ISO/IEC 27001 and NIST frameworks. Additionally, it emphasizes the necessity of contingency planning to prepare for unexpected events that threaten information security.

Uploaded by

saikaumudi28
Copyright
© All Rights Reserved
We take content rights seriously. If you suspect this is your content, claim it here.
Available Formats
Download as PDF, TXT or read online on Scribd
0% found this document useful (0 votes)
27 views20 pages

Cybersecurity Governance and Compliance Framework

The document discusses the importance of cyber security planning in the context of banking, highlighting the 2016 Indian debit card breach and the subsequent need for a Board-approved Cyber-security Policy as mandated by the RBI. It outlines various approaches to cyber risk management, including Governance-Risk-Compliance (GRC) and standards-driven methods like ISO/IEC 27001 and NIST frameworks. Additionally, it emphasizes the necessity of contingency planning to prepare for unexpected events that threaten information security.

Uploaded by

saikaumudi28
Copyright
© All Rights Reserved
We take content rights seriously. If you suspect this is your content, claim it here.
Available Formats
Download as PDF, TXT or read online on Scribd

Accounting Information Systems

Planning for cyber security


Saji K Mathew, PhD
Professor, Management Studies
INDIAN INSTITUTE OF TECHNOLOGY MADRAS
2016 Indian debit card breach
 3.2 million debit cards compromised due to a malware in ATMs and PoS terminals.
 Biggest card replacement drive initiated.

3
RBI circular on cyber security
 Need for a Board approved Cyber-security Policy
 Cyber Security Policy to be distinct from the broader IT
policy / IS Security Policy of a bank
 Arrangement for continuous surveillance
 IT architecture should be conducive to security
 Comprehensively address network and database security
 Ensuring Protection of customer information
 Cyber Crisis Management Plan
 Cyber security preparedness indicators
 Sharing of info on cyber security incidents with RBI
 Cyber-security awareness among stakeholders / Top
Management / Board
RBI established Institute for Development and Research in Banking Technology in Hyderabad
Cybersecurity policy
 Policy is the essential foundation of an effective
information security program
 Some basic rules must be followed when shaping a policy:
 Never conflict with law
 Stand up in court
 Properly supported and administered
 Contribute to the success of the organization
 Involve end users of information systems
 Policies require constant modification and maintenance

Slide 5
Information security planning
Approaches to cyber risk management
 Governance-Risk-Compliance (GRC) approach
 Dominant accounting/finance perspective
 Cyber security management as an internal control mechanism

 Standards driven approach


 NIST cyber security framework (open)
 ISO/IEC 27001 for information security (proprietary)

 Organizational planning approach


 Cyber security as a part of strategic planning and risk
management
 Contingency planning a constituent of the approach
GRC approach: Control frameworks
Widespread accounting fraud in the late 90’s to early 2000
resulted in mandatory reforms to prevent fraud
 COBIT: Control Objectives of Information Related Technology
 Framework for IT control, useful for benchmarking
 Specified by ISACA (Information Systems Audit and Control
Association)
 COSO: Committee of Sponsoring Organizations
 Framework for enterprise internal controls (control-based
approach)
 Specified by American Accounting Association and others
 COSO-ERM (Enterprise Risk Management)
 Expands COSO framework taking a risk-based approach
COBIT 5 Separates Governance from
Management

Choice point data breach: Governance deficit


Components of COSO Frameworks

COSO COSO-ERM
 Control (internal)  Internal environment
environment  Objective setting
 Risk assessment  Event identification
 Control activities  Risk assessment
 Information and  Risk response
communication  Control activities
 Monitoring  Information and
communication
 Monitoring
ISO 27000 series
 ISO/IEC 17799:2005 has 133 possible controls, not all of
which must be used; part of the process is to identify
which are relevant
 Each section includes four categories of information:
 One or more objectives
 Controls relevant to the achievement of the objectives
 Implementation guidance
 Other information
 Renamed as ISO 27000 series in 2007
 ISO 27001 provides guidelines on implementation (PDCA
format)

Slide 11
NIST security models
([Link]

 NIST documents have two notable advantages:


 They are publicly available at no charge
 Open source vs proprietary debate
 They have been available for some time and thus have been
broadly reviewed by government and industry professionals
 SP 800-12, Computer Security Handbook
 SP 800-14, Generally Accepted Security Principles & Practices
 SP 800-18, Guide for Developing Security Plans
 SP 800-26, Security Self-Assessment Guide-IT Systems
 SP 800-30, Risk Management for Information Technology Systems

Slide 12
Threats, Attack, Vulnerability, Risk
Information security planning
What is contingency planning (CP)?
 The overall planning for unexpected events is called
contingency planning (CP).
 It is how organizational planners position their
organizations to prepare for, detect, react to, and recover
from events that threaten the security of information
resources and assets
 Main goal: restoration to normal modes of operation with
minimum cost and disruption to normal business
activities after an unexpected event
 Contingency Plan Management Committee (CPMT)
typically oversees the process

 Key open resource: Contingency planning guide for Federal information systems, NIST
Components of CP
Incident response planning (IRP) focuses on immediate
response

Disaster recovery planning (DRP) focuses on restoring


operations at the primary site after disasters occur

Business continuity planning (BCP) facilitates establishment


of operations at an alternate site
Business Impact
Analysis (BIA)
Cost balancing
Contingency plan implementation

In general, an incident is a disaster when:


20 the impact of an incident OR
• organization is unable to contain or control
• level of damage or destruction from incident is so severe, the organization is unable to quickly recover

You might also like