News

Cybersecurity – Necessary security controls

Published Date: Feb 13, 2019

By LCUC CIO Cyber Security Team 

In today’s day and age, it is crucial that your organization develops a strategic plan to ensure necessary controls are in place to mitigate the risk of cyber security related incidents. Gone are the days when all you needed was a basic firewall and anti-virus solution that provided a sufficient amount of protection for your organization. 

Attacks are becoming increasingly sophisticated, extremely targeted and a great deal of time is normally spent by an attacker to gain access to your most vital assets. It is important to ensure critical areas of your infrastructure are properly protected no matter the size of your Credit Union. To aid with this, there are many different standards and frameworks that have been developed by reputable entities that are available to leverage, providing insight on how well your organization is protected alongside industry practices. 

It doesn’t matter which one you select and follow; the most important aspect is that your Credit Union is starting to develop a strategic direction around Cyber Security. But where to start? After all, these frameworks are comprehensive and contain hundreds of controls which can be a challenge to implement without a methodology and platform to assist both the initial rollout and the ongoing management reporting. Below is a recommendation of which framework to consider based on your business size: 

Small-Medium Sized Credit Union’s

Medium – Large Sized Credit Union’s 

Let’s assume that you have decided to adopt the Critical Security Controls (CSC) framework. This framework might be the one that makes the most sense for your business. CIS framework is probably one of the easiest controls to understand because they are grouped into three classes that are fairly easy to understand: 

  • Basic CIS Controls
  • Foundational CIS Controls
  • Organizational CIS Controls

There are a few practical considerations an organization should make when embarking on this journey. Keeping these suggestions in mind and building them into the program’s plan will help to ensure its success. Specifically, an organization should:

  • Make a formal, conscious top-level decision to make the CIS Controls part of the organization’s standard for defense. Senior management and the Board of Directors should be on board for support and accountability.
  • Assign a program manager who will be empowered and responsible for the implementation of the CIS Controls.
  • Decide who will be responsible for the long-term sustainability of maintaining cyber defenses.
  • Start with a gap analysis, assessment or audit of the current organization’s state against the CIS Controls and develop an implementation plan scheduled with priority focus on the first five Controls.
  • Document the long-term plan (3-5 years) for implementing cyber defenses that are not already a part of the entity’s defensive strategy.
  • Embed the definitions or goals of the CIS Controls into the organization’s documented security policies to streamline their implementation.
  • Ensure that internal and external auditors use the CIS Controls as a part of their benchmark for assessing the organization’s security stance.
  • Educate workforce members on the organization’s security goals and enlist their help as a part of the long-term defense of the organization’s data.

While there may be other steps that help improve an organization’s chances of success, these considerations are a good starting point for structuring an organization’s defensive program. 

There may be influencers, both internal and external, that will help your organization decide upon an appropriate framework in which to manage and measure the capability of your cyber security risk management program. Inevitably there will come a time when you may need to correlate your chosen framework, implemented controls and standards against other established assurance frameworks. Some of these frameworks and standards by their very nature cover differing breadth and depth in regard to information security, risk management and assurance. 

Most information security practitioners will admit to, after completing an extensive audit or assessment as part of the lifecycle of their program, having to complete an additional, seemingly similar assessment for a third-party, a regulator or other internal body. While this may be a wonderful learning opportunity for the practitioners involved, it is often resource intensive and impacting to business and risk management activities. 

Never fear – the Secure Controls Framework is here. Long sought after by security professionals and their assurance counter-parts and colleagues, the Secure Controls Framework is essentially the result of many man-hours of tedious work correlating the many established industry standards’ requirements and expectations around protective controls for information and information technology systems. 

For example, if you had implemented the CIS Critical Security Controls at your organization but needed to cross-reference against NIST’s Cyber Security Framework, the matrix provided would enable you to correlate which CIS CSC control maps to which NIST control. Similarly, you could also find correlation and mapping to the expectations of COBIT 5, PCI DSS, PIPEDA, et al. 

An organization may also choose to use several security frameworks simultaneously, given that each standard may not excel in all areas or domains, leading to selection of specific components. For example, an organization may use the operational, tactical components of NIST’s Cyber Security Framework, with the risk management oversight principles of OSFI guidance, supported by the program management and governance practices of ISACA’s COBIT 5. The choice may not be your own: a Credit Union could be mandated federally to align with OSFI, provincially to follow COBIT 5, and be required to implement NIST’s CSF by their regulator or insurer! 

Without attempting to be “the be-all and end-all of security frameworks”, the true value in the Secure Controls Framework is the ability to identify which components of other frameworks your organization is already compliant with in terms of performance and conformance. More importantly, to be able to reutilize evidence and results from a completed assessment against one framework, for coverage in part or in full for a similar assessment using a different industry framework, saving you precious time and effort. 

The Secure Controls Framework is a work in progress, with maturity and capability levels planned for inclusion in an upcoming version release. The matrix of mapped controls is free to download and utilize after email registration (they provide news and updates about releases). To clarify, the mentioned matrix is not a management or governance framework, but a mapping or consolidation of controls across frameworks that may assist you in completing assessments against your information security risk management program. 

https://www.securecontrolsframework.com/

Skip to content