Accounting Information Systems
Planning for cyber security
Saji K Mathew, PhD
Professor, Management Studies
INDIAN INSTITUTE OF TECHNOLOGY MADRAS
2016 Indian debit card breach
3.2 million debit cards compromised due to a malware in ATMs and PoS terminals.
Biggest card replacement drive initiated.
3
RBI circular on cyber security
Need for a Board approved Cyber-security Policy
Cyber Security Policy to be distinct from the broader IT
policy / IS Security Policy of a bank
Arrangement for continuous surveillance
IT architecture should be conducive to security
Comprehensively address network and database security
Ensuring Protection of customer information
Cyber Crisis Management Plan
Cyber security preparedness indicators
Sharing of info on cyber security incidents with RBI
Cyber-security awareness among stakeholders / Top
Management / Board
RBI established Institute for Development and Research in Banking Technology in Hyderabad
Cybersecurity policy
Policy is the essential foundation of an effective
information security program
Some basic rules must be followed when shaping a policy:
Never conflict with law
Stand up in court
Properly supported and administered
Contribute to the success of the organization
Involve end users of information systems
Policies require constant modification and maintenance
Slide 5
Information security planning
Approaches to cyber risk management
Governance-Risk-Compliance (GRC) approach
Dominant accounting/finance perspective
Cyber security management as an internal control mechanism
Standards driven approach
NIST cyber security framework (open)
ISO/IEC 27001 for information security (proprietary)
Organizational planning approach
Cyber security as a part of strategic planning and risk
management
Contingency planning a constituent of the approach
GRC approach: Control frameworks
Widespread accounting fraud in the late 90’s to early 2000
resulted in mandatory reforms to prevent fraud
COBIT: Control Objectives of Information Related Technology
Framework for IT control, useful for benchmarking
Specified by ISACA (Information Systems Audit and Control
Association)
COSO: Committee of Sponsoring Organizations
Framework for enterprise internal controls (control-based
approach)
Specified by American Accounting Association and others
COSO-ERM (Enterprise Risk Management)
Expands COSO framework taking a risk-based approach
COBIT 5 Separates Governance from
Management
Choice point data breach: Governance deficit
Components of COSO Frameworks
COSO COSO-ERM
Control (internal) Internal environment
environment Objective setting
Risk assessment Event identification
Control activities Risk assessment
Information and Risk response
communication Control activities
Monitoring Information and
communication
Monitoring
ISO 27000 series
ISO/IEC 17799:2005 has 133 possible controls, not all of
which must be used; part of the process is to identify
which are relevant
Each section includes four categories of information:
One or more objectives
Controls relevant to the achievement of the objectives
Implementation guidance
Other information
Renamed as ISO 27000 series in 2007
ISO 27001 provides guidelines on implementation (PDCA
format)
Slide 11
NIST security models
([Link]
NIST documents have two notable advantages:
They are publicly available at no charge
Open source vs proprietary debate
They have been available for some time and thus have been
broadly reviewed by government and industry professionals
SP 800-12, Computer Security Handbook
SP 800-14, Generally Accepted Security Principles & Practices
SP 800-18, Guide for Developing Security Plans
SP 800-26, Security Self-Assessment Guide-IT Systems
SP 800-30, Risk Management for Information Technology Systems
Slide 12
Threats, Attack, Vulnerability, Risk
Information security planning
What is contingency planning (CP)?
The overall planning for unexpected events is called
contingency planning (CP).
It is how organizational planners position their
organizations to prepare for, detect, react to, and recover
from events that threaten the security of information
resources and assets
Main goal: restoration to normal modes of operation with
minimum cost and disruption to normal business
activities after an unexpected event
Contingency Plan Management Committee (CPMT)
typically oversees the process
Key open resource: Contingency planning guide for Federal information systems, NIST
Components of CP
Incident response planning (IRP) focuses on immediate
response
Disaster recovery planning (DRP) focuses on restoring
operations at the primary site after disasters occur
Business continuity planning (BCP) facilitates establishment
of operations at an alternate site
Business Impact
Analysis (BIA)
Cost balancing
Contingency plan implementation
In general, an incident is a disaster when:
20 the impact of an incident OR
• organization is unable to contain or control
• level of damage or destruction from incident is so severe, the organization is unable to quickly recover