FEDERAL DEPOSIT INSURANCE CORPORATION 1
Cyber Security Assessment Tool Overview
Cyber Security Assessment Tool Overview FEDERAL DEPOSIT INSURANCE - - PowerPoint PPT Presentation
Cyber Security Assessment Tool Overview FEDERAL DEPOSIT INSURANCE CORPORATION 1 Objectives Cybersecurity Discuss the Evolution of Data Security Define Cybersecurity Review Threat Environment Discuss Information Security
FEDERAL DEPOSIT INSURANCE CORPORATION 1
Cyber Security Assessment Tool Overview
FEDERAL DEPOSIT INSURANCE CORPORATION 2
Objectives
Cybersecurity
Cyber Risk
FEDERAL DEPOSIT INSURANCE CORPORATION 3
Evolution of Data Security
Cybersecurity
FEDERAL DEPOSIT INSURANCE CORPORATION 4
defines cybersecurity as: “The process of protecting information by preventing, detecting, and responding to attacks.”
Identify Detect Respond Protect Recover
Definition
Cybersecurity
FEDERAL DEPOSIT INSURANCE CORPORATION 5
Appendix B to Part 364
Cybersecurity
information;
security or integrity of such information;
information that could result in substantial harm or inconvenience to any customer; and
consumer information.
FEDERAL DEPOSIT INSURANCE CORPORATION 6
People and Patches
Cybersecurity
“…a campaign of just ten e-mails yields a greater than 90% chance that at least one person will become the criminal’s prey…” “…11% of recipients of phishing messages click on attachments.”
Source: Verizon 2015 Data Breach Investigations Report
FEDERAL DEPOSIT INSURANCE CORPORATION 7
People and Patches
Cybersecurity “99.9% of the exploited vulnerabilities had been compromised more than a year after the associated [patch] was published.” “Ten [vulnerabilities] accounted for almost 97% of the exploits
“In 2014, there were 7,945 security vulnerabilities identified. That is 22 new vulnerabilities a day. Nearly one an hour.”
Sources: Verizon 2015 Data Breach Investigations Report NopSec
FEDERAL DEPOSIT INSURANCE CORPORATION 8
Threat Environment: Vulnerabilities
inventories, weaknesses in/over-reliance on third parties
FEDERAL DEPOSIT INSURANCE CORPORATION 9
Threat Environment: Actors
Cybersecurity
takeovers, ATM cash-outs, and payment card fraud.
States es - Attempt to gain strategic advantage by stealing trade secrets and engaging in cyber espionage.
awareness for specific causes.
financial gain or as a response to a personal grievance with the
FEDERAL DEPOSIT INSURANCE CORPORATION 10
Threat Environment: Attacks
Cybersecurity
Phishing/Trojan
FEDERAL DEPOSIT INSURANCE CORPORATION 11
Threat Environment: Example
Cybersecurity
Execution Installation Email
Potential Concerns Patches People Detection
FEDERAL DEPOSIT INSURANCE CORPORATION 12
Governance
Cybersecurity
Duties
resources.
information security.
included cybersecurity.
FEDERAL DEPOSIT INSURANCE CORPORATION 13
Risk Assessment
Cybersecurity
residual risk
cyber threat environment
FEDERAL DEPOSIT INSURANCE CORPORATION 14
Control Structure
Cybersecurity
Cyber er Hyg Hygien iene
FEDERAL DEPOSIT INSURANCE CORPORATION 15
Control Structure
Cybersecurity
“Think Before You Click”
FEDERAL DEPOSIT INSURANCE CORPORATION 16
Control Structure
Cybersecurity
FEDERAL DEPOSIT INSURANCE CORPORATION 17
Control Structure
Cybersecurity
Conference, NACHA Conference
FEDERAL DEPOSIT INSURANCE CORPORATION 18
Control Structure
Cybersecurity
FEDERAL DEPOSIT INSURANCE CORPORATION 19
Control Structure
Cybersecurity
Internet Banking Environment
– Initial Login/Authentication and Funds Transfers
FIL-50-2011
FEDERAL DEPOSIT INSURANCE CORPORATION 20
Control Structure
Cybersecurity
FEDERAL DEPOSIT INSURANCE CORPORATION 21
Disaster Recovery/Business Continuity Planning
Cybersecurity
(BIA)
systems identified in BIA
recovery plans
FEDERAL DEPOSIT INSURANCE CORPORATION 22
Program Charter/Policy Committee Universe (Scope)
Plan/Budget Reporting Findings/Tracking
Audit
Cybersecurity
Types General Controls GLBA Vulnerability Assessment Penetration Test ACH/Wires Social Engineering
FEDERAL DEPOSIT INSURANCE CORPORATION 23
and Sharing Statement,” dated November 3, 2014
sufficient awareness of cybersecurity threats and vulnerability information so they may evaluate risk and respond accordingly.”
Center (FS-ISAC) is encouraged.
Technology Services
Information Security Program: Refocused
FEDERAL DEPOSIT INSURANCE CORPORATION 24
Third-Party Management
Cybersecurity
Core Transactional Internet Banking Mobile Banking Managed Network Security
FEDERAL DEPOSIT INSURANCE CORPORATION 25
Appendix J: Third-Party Management
Cybersecurity
FEDERAL DEPOSIT INSURANCE CORPORATION 26
Appendix J: Resilience
Cybersecurity
FEDERAL DEPOSIT INSURANCE CORPORATION 27
Appendix J: Incident Response
Cybersecurity
cyber threats
Unauthorized Access to Customer Information and Customer Notice,” dated April 1, 2005
misused
FEDERAL DEPOSIT INSURANCE CORPORATION 28
FFIEC Cybersecurity Assessment Tool
June 30, 2015
assessing their cybersecurity preparedness
inform management of their institution’s risks and cybersecurity preparedness over time
FEDERAL DEPOSIT INSURANCE CORPORATION 29
FFIEC Cybersecurity Assessment Tool
FEDERAL DEPOSIT INSURANCE CORPORATION 30
FFIEC Cybersecurity Assessment Tool
FEDERAL DEPOSIT INSURANCE CORPORATION 31
FFIEC Cybersecurity Assessment Tool
FEDERAL DEPOSIT INSURANCE CORPORATION 32
FFIEC Cybersecurity Assessment Tool
FEDERAL DEPOSIT INSURANCE CORPORATION 33
Cybersecurity
cybersecurity – there will NOT be a separate cybersecurity handbook, which is in keeping with the regulatory viewpoint that the baseline standards are already integrated throughout existing guidance.
FEDERAL DEPOSIT INSURANCE CORPORATION 34
Cybersecurity
should be enhanced to address cybersecurity risks
financial institutions
FEDERAL DEPOSIT INSURANCE CORPORATION 35
Cybersecurity Resources
Information Technology Risk Examination
FEDERAL DEPOSIT INSURANCE CORPORATION 37
Workprogram
Core Modules
Audit Management
(Ongoing)
Standards (GLBA)
Development and Acquisition
(Acquisition)
Support and Delivery
(IDS, Firewall)
Cybersecurity
FEDERAL DEPOSIT INSURANCE CORPORATION 38
Framework
URSIT assessment factors
FEDERAL DEPOSIT INSURANCE CORPORATION 39
Features
Standards (Part 364 Appendix B)
decision factor
FEDERAL DEPOSIT INSURANCE CORPORATION 40