New NIST-Based Audit/Assurance Program Validates Cyber Controls

We live and work in a high-tech, interconnected world that is seeing increases in the volume and sophistication of cyberattacks. In order to function safely in this technology-driven, digital world, we must have strong cybersecurity controls. But how do we know if we have the right controls or if our controls are functioning as planned?

Because of the need for audit and assurance programs and processes around cybersecurity, ISACA has developed a new IS audit/assurance program, Cybersecurity: Based on the NIST Cybersecurity Framework. The goal of this program is to provide organizations with a formal, repeatable way to validate cybersecurity controls.

The program is based on the NIST Cybersecurity Framework and is built around the following five critical cybersecurity activities:

  1. Identify – Determine if the systems, assets, data and capabilities critical to cybersecurity have been identified and are understood by the organization. Process sub-areas include asset management, business environment, governance, risk assessment and risk management strategy.
  2. Protect – Review cybersecurity safeguards designed to limit the impact of potential events.  Process sub-areas include access control, awareness and training, data security, information protection processes and procedures, maintenance, and protective technology.
  3. Detect – Assess activities designed to identify the occurrence of cybersecurity events. Process sub-areas include anomalies and events, security continuous monitoring and detection processes.
  4. Respond – Evaluate action plans to take after learning of a security event. Process sub-areas include response planning, communications, analysis, mitigation and improvements.
  5. Recover – Analyze plans for resilience and the timely repair of compromised capabilities and services. Process sub-areas include recovery planning, improvements and communications.

The program is offered as a Microsoft Excel file with columns created so users can define controls to be tested (including frequency and results), as well as add references and comments. Testing steps have been identified for each NIST Cybersecurity Framework functional subcategory. These subcategories are labeled “Controls” in the program.

In addition, controls are referenced to COBIT 5 and ISO/IEC 27001:2013, making it easier for professionals to integrate the program into existing frameworks and/or audit programs.

Editor’s note: To download the Cybersecurity: Based on the NIST Cybersecurity Framework audit/assurance program, visit: www.isaca.org/Knowledge-Center/Research/ResearchDeliverables/Pages/Cybersecurity-Based-on-the-NIST-Cybersecurity-Framework.aspx.

ISACA also is offering a one-day workshop entitled “Cybersecurity for Auditors” immediately following the 2017 North America CACS conference in Las Vegas, Nevada. For more information and to register, visit: www.isaca.org/Education/Conferences/Pages/North-America-CACS-Presentations-and-Descriptions.aspx#ws7.

Russell Horn, CISA, CRISC, CISSP, President, CoNetrix

[ISACA Now Blog]

Davos Notes: Cybersecurity Must Keep Pace with Fintech Innovation

In today’s digitally connected world, it seems many have an increasingly myopic view, as it’s all too easy to get caught up in what’s important to individuals instead of collective needs. As such it was very interesting to attend a CNBC debate session at the World Economic Forum Annual Meeting in Davos, entitled “2016: The Year Fintech Dominated Disruption”.

The concept seems an oxymoron: as technology evolution continues exponentially, I wonder what comes after domination?  One panelist commented that, whilst many consumers will experiment with new tech that includes financial transactions, the financial investment is typically trivial, and the reality is that consumers will come back to the organisations they have trusted for decades in which to invest their entire capital wealth.

At the same time, there was acceptance that retail technology transition had overtaken the financial organisations, so they are now pushing for innovation. This drove much of the broader discussion on where and how such innovation is driven. One bank highlighted that today they are working with over 70 different financial technology companies through the partnerships, joint ventures or acquisitions they have made. Whether these are evolutionary or transformational, I would speculate all of the above.

Financial regulation has always seemed to be a constraining factor to fintech innovation, from my perception, but it was highlighted that more regulators are now starting to support small sandbox environments to allow more dynamic application of new environments to test fintech concepts. It was very interesting to hear the debate, which effectively challenged innovation versus trust, and given this, it was surprising cybersecurity didn’t enter the discussion further.

On one hand, fintech looks for new methods to deliver old services via such tools as blockchain, which can provide a new architecture to allow greater transaction volumes to be processed and stored, with timestamped and linked data blocks for a permanent verification trail. On the other hand, fintech also creates the opportunity for far more complex transactional processes; indeed there were predictions that machine-to-machine transactions will someday outweigh the number of human-based financial transactions.

There is an old adage that you’re only as strong as your weakest link, so considering what, in finance, looks likely to become a transaction process with greater volume and complexity, the need to transform how we secure platforms, applications and processes is clear. Typically, security is applied at each level in isolation, creating fragmented, high-volume and partial indications that then rely on human analysis in order to validate whether there is a cyber incident.

All too often cybersecurity comes after innovation, and while fintech is undoubtedly disrupting how transactions occur and consumers are pushing banks to evolve, cybersecurity requirements are only going to become more complex. It’s important to start to connect and automate the cybersecurity capabilities across the payment ecosystem, in collaboration with banks and fintech providers, to create security-aware, integrated platforms that are as automated as the transactions being processed. Only then can cybersecurity, and the required trust that goes with it, keep pace in this disruptive space.

[Palo Alto Networks Research Center]

English
Exit mobile version