MONITORING OF THE CYBERSECURITY RISK MANAGEMENT PROGRAM

DC15: The process for conducting ongoing and periodic evaluations of the operating effectiveness of key control activities and other components of internal control related to cybersecurity
  • The variety of different types of ongoing and separate evaluations used, which may include a combination of periodic and continuous internal audit assessments, penetration testing, and independent certifications made against established security and other specifications (for example, ISO 27001 and HITRUST)
  • The process for considering the rate of change in business and business processes when selecting and developing such evaluations
  • The process for performing the ongoing and periodic evaluations, including whether (a) the design and current state of the entity's cybersecurity risk management program, including the controls, are used to establish a baseline; (b) evaluators have sufficient knowledge to understand what is being evaluated; and (c) the scope and frequency of the evaluations is commensurate with the risk
DC16: The process used to evaluate and communicate, in a timely manner, identified security threats, vulnerabilities, and control deficiencies to parties responsible for taking corrective actions, including management and the board of directors, as appropriate
  • The process by which management and the board of directors, as appropriate, assess results of ongoing and periodic evaluations, including whether the process considers the remediation of identified security threats, vulnerabilities, and control deficiencies
  • The process for communicating identified security threats, vulnerabilities, and control deficiencies to parties responsible for taking corrective action and to senior management and the board of directors, as appropriate
  • The process for monitoring remediation of identified deficiencies

DC17: The process for developing a response to assessed risks, including the design and implementation of control processes

  • The process to align controls with risk responses needed to protect information assets and to detect, respond to, mitigate and recover from security events based on the assessed risks
  • The consideration of the environment in which the entity operates, the complexity of the environment, the nature and scope of the entity's operations, and its specific characteristics when selecting and developing control processes
  • The process for including a range and variety of controls (for example, manual and automated controls and preventive and detective controls) in risk mitigation activities to achieve a balanced approach to the mitigation of identified cybersecurity risks
  • The use of risk transfer strategies, including the purchase of insurance, to address risks that are not addressed by controls

DC18: A summary of the entity's IT infrastructure and its network architectural characteristics

  • The use of segmentation, where appropriate, and baseline configurations of both physical and virtual endpoints, devices, firewalls, routers, switches, operating systems, databases, and applications
  • The use of infrastructure and network elements provided by outsourced service providers

DC19: The key security policies and processes implemented and operated to address the entity's cybersecurity risks, including those addressing the following:

  • The process for establishing retention periods for types of confidential information and identifying the information when received or created and associating the information to a specific retention period
  • The process for identifying information classified as confidential
  • The process for preventing the destruction of identified information during its specified retention period
  • The process for identifying information that has reached the end of its retention period and information that is an exception to the retention policies
  • The process for destroying information identified for destruction

We hope you are adequately preparing for the new AICPA Assessment criteria.  We advise that everyone begins at the end, with DC19.  Comparatively, by the size of the implementation guidance, it's a whopper.

DC-19

As a sample of the size of the last control area in this guidance, here's the text for section DC-19

DC19: The key security policies and processes implemented and operated to address the entity's cybersecurity risks, including those addressing the following:

  • The process for establishing retention periods for types of confidential information and identifying the information when received or created and associating the information to a specific retention period
  • The process for identifying information classified as confidential
  • The process for preventing the destruction of identified information during its specified retention period
  • The process for identifying information that has reached the end of its retention period and information that is an exception to the retention policies
  • The process for destroying information identified for destruction
Main Menu