CYBERSECURITY RISK ASSESSMENT PROCESS

DC11: The process for (1) identifying cybersecurity risks and environmental, technological, organizational and other changes that could have a significant effect on the entity's cybersecurity risk management program and (2) assessing the related risks to the achievement of the entity's cybersecurity objectives
  • The use of new technologies
  • Changes to the regulatory, economic, and physical environment in which the entity operates
  • New business lines
  • Changes to the composition of existing business lines
  • Changes in available resources
  • Acquired or divested business operations
  • Rapid growth
  • Changing operational presence in foreign countries
  • Changing political climates
DC12: The process for identifying, assessing, and managing the risks associated with vendors and business partners
  • Establishing specific requirements for a vendor and other business partner engagement that includes scope of services and product specifications, roles and responsibilities, compliance requirements, and service levels
  • Assessing, on a periodic basis, the risks that the vendors and business partners represent to the achievement of the entity's objectives, including risks that arise from those entities' relevant vendors and business partners (often referred to as fourth party risk)
  • Assigning responsibility and accountability for the management of associated risks
  • Establishing communication and resolution protocols for service and product issues, including reporting of identified threats
  • Establishing exception-handling procedures
  • Periodically assessing the performance of vendors and business partners and those entities' relevant vendors and business partners
  • Implementing procedures for addressing associated risks

CYBERSECURITY COMMUNICATIONS AND QUALITY OF CYBERSECURITY INFORMATION

DC-13 to DC-16
DC13: The process for internally communicating relevant cybersecurity information necessary to support the functioning of the entity's cybersecurity risk management program, including (1) objectives and responsibilities for cybersecurity and (2) thresholds for communicating identified security events that are monitored, investigated, and determined to be security incidents requiring a response, remediation, or both
  • Awareness programs, including training about detecting and avoiding social engineering threats and security breach reporting and response
  • Job descriptions
  • Acknowledgement of code of conduct and policies,
  • Employee signed confidentiality agreements, and
  • Policy and procedures manuals)
DC14: The process for communicating with external parties regarding matters affecting the functioning of the entity's cybersecurity risk management program
  • The existence and use of open communication channels that allow input from customers, consumers, vendors, business partners, external auditors, regulators, financial analysts, and others to provide management and the board of directors with relevant information
  • The process for creating and updating communications regarding cybersecurity, including considerations of timing, audience, and nature of information when selecting the communication method to be used
  • The use of various communication channels, such as whistle-blower hotlines, to enable anonymous or confidential communication when normal channels are inoperative or ineffective
  • The process by which legal, regulatory, and fiduciary requirements, including required communication of data breaches and incidents, are considered when making communications
Main Menu