Added · Updated
The Bank of Jamaica issued this Standard of Sound Practice to establish minimum cyber risk management requirements for deposit-taking institutions under the Banking Services Act. The document mandates a comprehensive governance framework featuring four lines of defense, requiring Boards to exercise direct oversight, define risk tolerance, and foster a cyber-risk-aware culture. It further specifies operational responsibilities for senior management and key roles, including the CISO and CIRR functions, to ensure robust identification, mitigation, and reporting of cyber threats.
BOJ published 1 document in the last 30 days — get each new one by email the day it lands.
STANDARD OF SOUND PRACTICE
MANAGEMENT OF CYBER RISKS
FINAL DRAFT
Last Updated: 29 Nov. 2023
Background and Context........................................................................................... 1
1.0 Legal Basis............................................................................................................................................1
1.1 Context ................................................................................................................................................1
Definitions................................................................................................................ 2
Cyber Risk Governance.............................................................................................. 3
3.0 Preamble .............................................................................................................................................3
3.1 Board Oversight of Cyber Risks............................................................................................................3
Overseeing the Cyber Risk Management Framework ................................................. 6
4.0 Preamble .............................................................................................................................................6
First Line of Defence: Operational Management .......................................................................6
4.1 Structure and Expertise .......................................................................................................................6
4.2 Roles and Responsibilities ...................................................................................................................7
4.3 Third-Party Dependencies.................................................................................................................10
4.4 Risk Identification and Assessment ...................................................................................................11
4.5 Risk Mitigation and Control ...............................................................................................................12
4.6 Risk Monitoring and Reporting..........................................................................................................12
Second Line of Defence: Risk Management............................................................................. 13
4.7 Risk Management Function...............................................................................................................13
Third Line of Defence: Internal Audit...................................................................................... 14
4.8 Internal Audit Function......................................................................................................................14
Fourth Line of Defence: Information Sharing & External Assurance ......................................... 15
4.9 Information Sharing...........................................................................................................................15
4.10 External Assurance .......................................................................................................................15
Key Reports to the Board......................................................................................... 17
5.0 Preamble ...........................................................................................................................................17
5.1 Board Reports on Cybersecurity Effectiveness..................................................................................17
Tone at the Top – Cyber Risk-Aware Culture ............................................................ 19
6.0 Preamble ...........................................................................................................................................19
6.1 Reinforcing a Cyber Risk-Aware Culture............................................................................................19
6.2 Cyber Hygiene Best Practices ............................................................................................................20
Appendix 24
A. Cyber Risk Related Legislation
B. Cyber Resilience Principles
C. Cyber Risk Oversight Expectations and Questions to Ask
D. Types of Cyberattacks
E. Industry Standards on Cybersecurity
Additional Reference Material 37
STANDARD OF SOUND PRACTICE ON MANAGEMENT OF CYBER RISKS 1 Background and Context Cyber threats and incidents to the financial sector in Jamaica, and globally, pose a serious hazard to financial stability. This Standard of Sound Practice on the Management of Cyber Risks (“Guidelines”) is intended to establish minimum standards and guidelines on the management of cyber risk for the licensees under the Banking Services Act, 2014. Each licensee is expected to put an effective framework in place to manage the cyber risk exposures inherent in their operations, which could also result in significant financial loss, legal liabilities and reputational damage.
1.0 Legal Basis
1.0.1 Bank of Jamaica conducts risk-based examinations of licensees in accordance with
section 34D of the Bank of Jamaica Act, to assure compliance with standards set
out herein on the management of cyber risks. These Guidelines are issued pursuant to section 132(1)a of Banking Services Act. (See Appendix 1: Cyber Risk Related Legislation)
1.1 Context
1.1.1 It is important for deposit-taking institutions (“DTIs”) to understand and
manage their cyber risk to protect their assets, operations and information entrusted to them by customers and stakeholders. This is to build trust and confidence, which are two of the most important attributes of a financial sector.
1.1.2 Cyberattacks are becoming more frequent, and they continue to evolve in
terms of their complexity and sophistication. A successful cyberattack could have a debilitating impact on a DTI which could cause a significant financial or operational impact on a financial institution.
1.1.3 Cyber threats i.e. risks from hacking, malware, phishing, and other types of
cyberattacks, as well as from insider threats, can have significant financial loss, reputational damage, and loss of sensitive information, each of which negatively impacts customers, employees, shareholders, suppliers and threatens stability of the financial system and wider economy.
STANDARD OF SOUND PRACTICE ON MANAGEMENT OF CYBER RISKS 2 Definitions For the purpose of these Guidelines, the following definitions are provided:
Critical Operations Systems and processes, the failure of which will cause significant disruption to the DTI’s operations or materially impact the DTI’s service to its customers. Cyber Incident Any observable occurrence in an information system that
i. jeopardizes the cybersecurity of an information system or the
information the system processes, stores or transmits; or
ii. violates the security policies, security procedures or acceptable
use policies, whether resulting from malicious activity or not. Cyber Resilience The ability to recover quickly and deliver intended services and outcomes despite cyber incidents. Cyber Risk Risk of financial loss, operational disruption, or damage, from the failure of the digital technologies employed for informational and/or operational functions introduced to a system via electronic means from the unauthorized access, use, disruption, modification, or destruction of the system. Cyber Risk Governance The arrangements put in place by the Board to establish, implement and review its approach to managing cyber risks and support cyber incident response and recovery activities toward cyber resilience. Cyber Risk Management Framework A structured approach to identify, assess, and mitigate potential cyber threats to an organization. It involves establishing clear roles and responsibilities, defining risk tolerance levels, and implementing controls along with others policies, frameworks, guidelines and standards to minimize the likelihood and impact of cyber-attacks. Cybersecurity (a) The systems, technologies, processes, governing policies and human activity that an organization uses to safeguard its digital assets. (b) The practice of protecting critical systems and sensitive information from digital attacks, whether those threats originate from inside or outside of an organization. (c) Preservation of confidentiality, integrity and availability of information and/or information systems through the cyber medium. In addition, other properties, such as authenticity, accountability, non-repudiation and reliability can also be involved.
STANDARD OF SOUND PRACTICE ON MANAGEMENT OF CYBER RISKS 3 Cyber Risk Governance
3.0 Preamble
3.0.1 Cyber Risk Governance refers to the arrangements put in place by a board to
ensure the effective management of cyber risks through:
STANDARD OF SOUND PRACTICE ON MANAGEMENT OF CYBER RISKS 4
3.1.3 The Board, individually and collectively, must understand the seriousness of
the cyber threat environment. It should ensure that it collectively possesses the appropriate balance of skills, knowledge and experience to understand and assess the cyber risks facing the DTI. It should also be sufficiently informed and capable of credibly challenging the recommendations and decisions of designated senior management.
3.1.4 The Board and Senior Management must have an ongoing programme to
assess any gaps in the knowledge and expertise of the Board and management and to implement initiatives to address these gaps. That is, the Board and Senior Management team shall be appropriately constituted with representatives who have an appreciation of cyber risk management and programme implemented to ensure all members undergo continuous training.
3.1.5 The Board must review and approve a cyber risk management framework,
which should at minimum incorporate four lines of defence:
1 The term “critical operations” means systems and processes, the failure of which will cause significant disruption to the DTI’s operations or materially impact the DTI’s service to its customers.
STANDARD OF SOUND PRACTICE ON MANAGEMENT OF CYBER RISKS 5 effective in accordance with corporate governance principles. (See Corporate Governance: Board Oversight Handbook on BOJ website)
3.1.9 The Board must review, deliberate and challenge the cyber risk information
contained in the reports from sub-committee. Evidence of this deliberation and decision-making must be documented in relevant board minutes. It is not sufficient to circulate reports from the sub-committees for individual members to read at their convenience.
STANDARD OF SOUND PRACTICE ON MANAGEMENT OF CYBER RISKS 6 Overseeing the Cyber Risk Management Framework
4.0 Preamble
4.0.1 A Cyber Risk Management Framework is a structured approach to identifying,
assessing, and mitigating potential cyber threats to an organization. It involves establishing clear roles and responsibilities, defining risk tolerance levels, and implementing controls to minimize the likelihood and impact of cyberattacks. (See
Appendix 4: Types of Cyber Attacks)
4.0.2 Critical to the design of a Cyber Risk Management framework is defining the
accountabilities for the four lines of defence: Operational Management, Risk Management, Internal Audit along with Information Sharing & External Assurance.
4.0.3 Starting with the first line of defence, DTIs must have an operational
framework in place to:
STANDARD OF SOUND PRACTICE ON MANAGEMENT OF CYBER RISKS 7
4.1.2 These may include relevant enterprise-wide committees, functions and/or
designated officers with the requisite expertise to perform the responsibilities of a:
STANDARD OF SOUND PRACTICE ON MANAGEMENT OF CYBER RISKS 8
STANDARD OF SOUND PRACTICE ON MANAGEMENT OF CYBER RISKS 9
STANDARD OF SOUND PRACTICE ON MANAGEMENT OF CYBER RISKS 10 transfer, migration of data or applications or infrastructure between the cloud and/or other environments.
2
SOC 2 (Service Organization Control 2) is a framework developed by the American Institute of Certified Public Accountants (AICPA) to assess and report on the cybersecurity and data protection controls of service organizations. It focuses on five key principles: security, availability, processing integrity, confidentiality, and privacy. SOC 2 audits are conducted by third-party auditors to verify the effectiveness of these controls.
STANDARD OF SOUND PRACTICE ON MANAGEMENT OF CYBER RISKS 11 disruptions or able to return to operation in accordance with the DTI’s tolerance for disruption.
4.4 Risk Identification and Assessment
4.4.1 Risk identification entails the determination of the threats and
vulnerabilities to a DTI’s IT infrastructure including internal and external networks, hardware, software, applications, third-party services, systems interfaces, operations and human elements throughout the supply chain.
4.4.2 DTIs should be vigilant in identifying and analysing cyber risks as it is a crucial
step in the risk containment exercise. (See Appendix 4: Types of Cyber Threats)
4.4.3 A cyber risk may take the form of any condition, circumstance, incident or
person with the potential to cause harm by exploiting a vulnerability in a system.
4.4.4 DTIs should carry out penetration tests in order to conduct an in-depth
evaluation of the cybersecurity posture of the system through simulations of actual attacks on the system. DTIs should conduct penetration tests on internet-facing systems at least annually, or whenever these systems undergo major changes or updates. Full scope penetration tests at least once every two years.
4.4.5 DTIs should carry out regular scenario-based cyber exercises to validate their
response and recovery, as well as communication plans in case of a cyber-attack. These exercises could include social engineering 3 , table-top4 , cyber range 5 or adversarial attack simulation6 exercises.
4.4.6 Based on the type and objectives of the exercise, the DTI should involve all
relevant stakeholders including management, business functions, corporate communications, crisis management team, service providers, and technical staff responsible for cyber threat detection, response and recovery.
4.4.7 The objectives, scope and rules of engagement should be defined before the
commencement of the exercise. To ensure that the activities executed don’t disrupt the DTI’s production systems, the exercise must be closely supervised and performed in a controlled environment.
4.4.8 DTIs should bear in mind that the simulation of realistic adversarial
simulation attacks ought to be designed based on plausible cyber-attacks, and
3 Social engineering is a process in which cyber criminals manipulate an unsuspecting person into divulging sensitive details such as passwords through the use of techniques such as phishing, identity theft and spam. 4 Table-top exercise is a discussion-based exercise where personnel with roles and responsibilities in a particular IT plan meet in a classroom setting or in breakout groups to validate the content of the plan by discussing their roles during an emergency and their responses to a particular emergency situation. A facilitator initiates the discussion by presenting a scenario and asking questions based on the scenario. September 2006. 5 Cyber ranges are interactive, simulated representations of an organization’s local network, IT system, tools, and applications that are connected to a simulated Internet level environment. They provide a safe, legal environment to gain hands-on cyber skills and secure environment for product development and security posture testing. 6 Adversarial attack simulation exercise provides a more realistic picture of a DTI’s capability to prevent, detect and respond to real adversaries by simulating the tactics, techniques and procedures of real-world attackers to target people, processes and technology underpinning the DTI’s critical business functions or services.
STANDARD OF SOUND PRACTICE ON MANAGEMENT OF CYBER RISKS 12 therefore should design the exercises by using threat intelligence that is relevant to their IT environment. This technique facilitates the identification of threat actors who are highly probable to pose a threat to the DTI; as well as to assist in the identification of the tactics, techniques and procedures most likely to be used in such attacks.
4.5 Risk Mitigation and Control
4.5.1 Mitigating cyber risk is crucial for DTIs to protect their digital assets and
maintain operational continuity. Risk mitigation entails a methodical approach for evaluating, prioritizing and implementing appropriate risk-reduction controls. A combination of technical, procedural, operational and functional controls would provide a rigorous mode of reducing risks. In addition, acquiring insurance coverage for various insurable risks, including recovery and restitution costs should be considered.
4.5.2 For each type of risk identified, DTIs should develop and implement risk
treatment plan including mitigation and control strategies that are consistent with the criticality of the information system assets and the level of risk tolerance.
4.5.3 As it may not be practical to address all known risks simultaneously or in the
same timeframe, DTIs should give priority to threat and vulnerability pairings that could cause significant harm or impact to a DTI’s operation. The costs of risk controls should be balanced against the benefits to be derived.
4.5.4 DTIs must manage and control risks in a manner that will maintain their
financial and operational viability and stability, paying attention to the design of control standards and control patterns to secure their IT infrastructure, to mitigate cyber and IT-specific risks based on their risk appetite statement. The control objectives should cover all types of technology and cybersecurity controls which should map to industry standards. (Appendix 5:
Industry Standards on Cybersecurity)
4.5.5 DTIs must constantly monitor their attack surface to identify and block
potential threats as quickly as possible. As DTIs seek to expand their digital footprint and embrace new technologies, every effort should be made to ensure controls implemented are automated and/or can be technically enforced.
4.6 Risk Monitoring and Reporting
4.6.1 DTIs should maintain a risk register which facilitates the monitoring and
reporting of cyber and IT-specific risks. Risks of the highest severity should be accorded top priority and monitored closely with regular reporting on the actions that have been taken to mitigate them. DTIs should update the risk register periodically, and institute a monitoring and review process for continuous assessment and treatment of risks.
STANDARD OF SOUND PRACTICE ON MANAGEMENT OF CYBER RISKS 13
4.6.2 To facilitate risk reporting to management, DTIs should develop cyber and
IT-specific risk metrics to highlight systems, processes or infrastructure that have the highest risk exposure. An overall cyber and IT-specific risk profile of the organization should also be provided to the Board. In determining the cyber and IT-specific risk metrics, DTIs should consider risk events, regulatory requirements, vulnerability assessments, penetration test results and audit observations. (See
Section 5: Key Reports to Board)
4.6.3 Risk parameters may shift as the IT environment, cyber threat landscape and
delivery channels change. Thus, DTIs should review and update the risk processes accordingly, and conduct a periodic evaluation of risk-control methods that includes an assessment of the adequacy and effectiveness of IT controls and risk management processes.
4.6.4 Management of the DTI’s IT operation should review and update its IT risk
control and mitigation approach, taking into account changing circumstances and variations in the DTI’s risk profile and cyber threat landscape.
4.6.5 DTIs must conduct continuous monitoring of emerging cybersecurity threats
such as denial of service attacks, internal sabotage, and malware infestations to facilitate prompt detection of intrusion attempts, unauthorized or malicious activities by internal and external parties.
4.6.6 Incidents must be reported promptly to the Bank of Jamaica and appropriate
authorities within 72 hours. Local authorities may include:
a) Bank of Jamaica b) Financial Services Commission c) Jamaica Cyber Incident Response Team d) Office of the Information Commissioner e) Major Organised Crime and Anti-corruption Agency f) Financial Investigation Division of the Ministry of Finance g) Jamaica Constabulary Force Second Line of Defence: Risk Management
4.7 Risk Management Function
4.7.1 As the second line of defence, the responsibilities of Risk Management
function should include:
STANDARD OF SOUND PRACTICE ON MANAGEMENT OF CYBER RISKS 14
7 Data confidentiality refers to the protection of sensitive or confidential information such as customer data from unauthorized access, disclosure, etc.
STANDARD OF SOUND PRACTICE ON MANAGEMENT OF CYBER RISKS 15
4.8.2 The Internal Audit function should support coordination between independent
cybersecurity accessors and relevant regulators to measure the cyber risk governance framework against defined cybersecurity standards, such as NIST Cybersecurity Framework. Fourth Line of Defence: Information Sharing & External Assurance
4.9 Information Sharing
4.9.1 Senior Management should establish cyber information sharing
arrangements to take in consideration all available threat intelligence through information sharing and analysis centres established for the financial sector, at the national level, regionally and globally. This includes sharing of cyber threats, incidents and attacks with other financial institutions and local authorities that strengthens overall cyber resilience for the financial sector.
4.9.2 DTIs should establish an information sharing relationship with the Jamaica
Cyber Incident Response Team (JaCIRT) to align with the national cyber strategy and support testing activities, collective intelligence and coordinated responses to cyber threats and strengthen internal control systems.
4.9.3 DTIs should establish processes designed to maintain effective situational
awareness capabilities to reliably predict, analyse and respond to changes in its operating environment, cyber threat landscape while maintaining effective incident response.
4.9.4 DTIs should have a programme for gathering, analysing, understanding, and
sharing information about vulnerabilities and threats to arrive at actionable intelligence. Actionable intelligence can be gathered from various public and private sources.
4.10 External Assurance
4.10.1 DTIs must report cyber incidents and data breaches promptly to the Bank of
Jamaica within 72 hours along with relevant authorities (See Section 4.6.6). A digital forensics report from an external cybersecurity assessor may be requested.
4.10.2 DTIs must provide to Bank of Jamaica (BOJ) an annual attestation, to include
areas of weakness, compensating controls in areas of non or partial compliance, as well as initiatives being undertaken to address the concern(s). The yearly attestation shall alternate between a self-attestation or an independent attestation.
STANDARD OF SOUND PRACTICE ON MANAGEMENT OF CYBER RISKS 16 risk). This shall include; Internal Auditor, Corporate Risk Officer or Compliance Officer.
STANDARD OF SOUND PRACTICE ON MANAGEMENT OF CYBER RISKS 17 Key Reports to Board Key Reports to the Board
5.0 Preamble
5.0.1 Reporting to the Board on cybersecurity effectiveness is crucial to assure the
protection of an organization's digital assets. This should include evaluating:
STANDARD OF SOUND PRACTICE ON MANAGEMENT OF CYBER RISKS 18
STANDARD OF SOUND PRACTICE ON MANAGEMENT OF CYBER RISKS 19 Tone at the Top – Cyber Risk-Aware Culture
6.0 Preamble
6.0.1 The Board is expected to adopt the Financial System Stability Committee
(FSSC) Cyber Resilience Principles. Applying the 10 Cyber Resilience Principles at all levels of the organisation is expected to:
STANDARD OF SOUND PRACTICE ON MANAGEMENT OF CYBER RISKS 20
6.1.4 A cyber risk-aware culture should be reinforced at three levels:
STANDARD OF SOUND PRACTICE ON MANAGEMENT OF CYBER RISKS 21 from accessing the DTI’s core network. Prior approval of use of device and routine scanning of media should be required.
6.2.3 Board member, senior management, IT administrators and other user
account groups must exercise extreme caution when reviewing incoming emails and other forms of text messages. If an email or text message appears suspicious, refrain from clicking on any links, downloading attachments, or interacting with the email's contents.
6.2.4 Board must ensure policies and procedures are in place to ensure cyber
hygiene best practices are established and enforced for all users and devices. This must include:
STANDARD OF SOUND PRACTICE ON MANAGEMENT OF CYBER RISKS 22
APPENDIX 1
Cyber Risk Related Legislation
(Jamaica and Other Jurisdictions)
STANDARD OF SOUND PRACTICE ON MANAGEMENT OF CYBER RISKS 23 Extracted from Financial System Stability Committee Statement on 10 Cyber Resilience Principles (2023) Cyber resilience is essential for safeguarding financial stability. Financial institutions are expected to adopt these 10 Cyber Resilience Principles, which serve as a set of guiding concepts to manage cyber risks and to enhance each financial institution's ability to safeguard its operations, assets, and reputation in an increasingly digital and interconnected financial system. Principle 1. Not Just an IT Issue Ensures the strategies or measures in a financial institution’s cyber risk management framework is not restricted to securing the viability of its IT operations alone, but should also cover people, processes, data and facilities. Focus Areas:
STANDARD OF SOUND PRACTICE ON MANAGEMENT OF CYBER RISKS 24
STANDARD OF SOUND PRACTICE ON MANAGEMENT OF CYBER RISKS 25 Principle 5. Transparent, Thorough and Targeted Ensures board and management discussions about cyber resilience include high visibility reporting on gaps in addressing cyber risks using cyber resilience maturity models and assessments of cybersecurity effectiveness augmented by threat information sharing and penetration testing programmes. Focus Areas:
STANDARD OF SOUND PRACTICE ON MANAGEMENT OF CYBER RISKS 26 Principle 8. Least Privilege Ensures only the minimum level of access or permissions necessary to perform their tasks or functions are granted. This principle limits potential damage or misuse that could occur if users or systems were granted excessive privileges. Focus Area:
STANDARD OF SOUND PRACTICE ON MANAGEMENT OF CYBER RISKS 27
APPENDIX 3
Cyber Risk Oversight Expectations for Boards and Questions to Ask To effectively safeguard their organizations, board members must actively engage by asking the right questions. Board members play a crucial role in overseeing an organization's cybersecurity posture. While not cybersecurity experts, Boards should ask informed questions to ensure the organization is adequately protected against cyber threats. By posing the right questions, board members can gain a deeper understanding of their organization's security posture, identify potential risks, and work collaboratively with cybersecurity experts to ensure the highest level of protection against the ever-present cyber threats. While asking questions about the latest offline backups, how suspicious email are handled and the company’s password policy are useful conversation starters, there are a wider spectrum of critical cybersecurity risk considerations, as shown in the
table below, that every board should explore to uphold their fiduciary responsibility
and safeguard their organization's digital assets.
Board Oversight Expectations Questions for Next Board Meeting A. Understand the organization's current state of cybersecurity and any recent incidents or breaches.
STANDARD OF SOUND PRACTICE ON MANAGEMENT OF CYBER RISKS 28 Board Oversight Expectations Questions for Next Board Meeting B. Identify critical data and systems that need the highest level of protection.
6. What are our most valuable digital assets and
data?
7. Do we think there is adequate protection in place
if someone wanted to get at or damage our corporate “crown jewels” or other highly sensitive data? What would it take to feel confident that those assets/data were protected?
C. Ensure cybersecurity training
and awareness programme is improving both competence and behaviour.
8. Does the company perform employee training on
a semi-regular basis (at least twice a year or more)? Does this training address email policies and social media sites that employees might visit?
9. Are we spending wisely on cybersecurity tools
and training? Do we know if our spending is cost effective?
10. Are there metrics in place to measure the
effectiveness of our cybersecurity awareness and training initiatives?
11. When was the last phishing simulation
conducted? Are the results showing an improvement over-time? How can we close that gap? D. Ensure organisation’s capacity for cyber threat monitoring and information sharing.
12. Does our organization participate in any of the
public or private sector ecosystem-wide cybersecurity and information-sharing organizations? Should we? E. Assess the financial, reputational, and operational risks associated with cyber incidents.
13. What is the potential impact of a cyberattack on
our business?
F. Ensure the organization is compliant with relevant data protection and privacy regulations. Review and understand the organization's cybersecurity policies, incident response plan, and disaster recovery plan.
14. How are we addressing regulatory and
compliance requirements related to cybersecurity? What is outstanding? How can we close that gap? G. Ensure employees are educated about cybersecurity best
15. What cybersecurity training and awareness
programmes are in place for employees?
STANDARD OF SOUND PRACTICE ON MANAGEMENT OF CYBER RISKS 29 Board Oversight Expectations Questions for Next Board Meeting practices and the risks associated with cyber threats. H. Inquire about the frequency of security assessments, penetration tests, and audits to evaluate the effectiveness of security controls.
16. How often are security assessments and audits
conducted? What are the results telling us? What additional resources or expertise is needed to close that gap?
I. Ensure the organization has a
well-defined incident response plan and that it is regularly tested to ensure readiness in case of a breach.
17. What is our incident response plan, and has it
been tested?
J. Understand the budget allocated to cybersecurity and how it aligns with the organization's risk profile.
18. What is our cybersecurity budget and how is it
allocated?
K. Determine whether the organization has cybersecurity insurance and the extent of coverage it provides.
19. What cybersecurity insurance coverage do we
have?
L. Assess how the organization
evaluates and manages cybersecurity risks associated with third-party vendors and suppliers.
20. What is our strategy for third-party vendor risk
management?
M. Understand the tools and processes in place for monitoring the network and identifying potential threats.
21. How do we monitor and detect cybersecurity
threats and incidents?
N. Determine who the Chief
Information Security Officer
(CISO) or equivalent is and their role in managing cybersecurity.
22. Who is managing our cybersecurity? Who is
responsible for cybersecurity at the executive level? Do we have the right talent and clear lines of communication, accountability and responsibility for cybersecurity? Is cybersecurity risk included in our risk register? O. Explore how the organization stays current with evolving cybersecurity threats and technologies.
23. What investments are we making in emerging
cybersecurity technologies?
STANDARD OF SOUND PRACTICE ON MANAGEMENT OF CYBER RISKS 30 Board Oversight Expectations Questions for Next Board Meeting P. Discuss the organization's vision for cybersecurity and how it plans to adapt to future threats.
24. What is our long-term Cybersecurity
Preparedness Strategy?
Q. Understand the organization's approach to transparency and communication regarding cybersecurity incidents.
25. How do we communicate cybersecurity matters
to stakeholders, including customers and investors?
R. Stay informed about the latest cybersecurity threats and incidents in the industry and how they might affect the organization.
26. Are there any recent cybersecurity incidents or
trends in the industry that we should be aware of?
S. Ensuring data is securely retained and can be restored effectively in the event of data loss or disasters.
27. What is the company’s back-up procedure and
what back-up media are used by the IT department?
28. What is the policy for retaining backup data, and
are there plans for archiving older backups?
29. How long are different types of data retained,
and what criteria are used to determine retention periods?
30. How frequently are backups performed, and is
there a schedule for different types of data?
31. Is there a disaster recovery plan that includes
backup data?
32. What is the process for monitoring and
addressing backup failures or anomalies?
T. Review the company's password policy and access controls.
33. What is the company’s password policy? Is it
complex enough?
34. Is the current password policy considered
sufficiently robust and in compliance with industry standards and best practices?
35. What is the password expiration policy, and how
often do passwords expire for employees?
36. Do we have a process in place to promptly
revoke access for ex-employees?
37. How many former employees, promoted and
transferred employees still have active access to
STANDARD OF SOUND PRACTICE ON MANAGEMENT OF CYBER RISKS 31 Board Oversight Expectations Questions for Next Board Meeting resources tied to their previous role, and what steps are being taken to address this?
38. Are there any users with privileged access rights
who are anticipated to leave the company in the near future?
U. Review the frequency and effectiveness of the company’s patch programme.
39. When are critical patches and updates made to
the network? Once a week, once a month?
40. How quickly are critical or emergency patches
made? 48 hours, 72 hours, two weeks, or longer?
V. Review the effectiveness of
email security to filter suspicious emails, and other email security measures.
41. Does your company have in place some sort of
email ‘filtering’ system in order to reject any emails that might appear normal, but are actually sent from a spoofed or copycat address?
42. What is the incident response plan for handling
detected phishing emails or email security breaches?
43. How are email attachments and downloads
scanned for malware and other threats?
44. Are multi-factor authentication (MFA) and
strong password policies enforced for email accounts?
45. Is there a regular testing and evaluation process
for email security effectiveness such as simulated phishing tests and email security assessments? W. Review the capacity gaps within IT and cybersecurity
46. Does the company have enough IT staff to handle
not just security alerts that need to be investigated, but also handle patching, applications, the Cloud, and a host of other daily jobs that need to be performed?
47. What is the current state of our IT infrastructure,
and how well does it support our business operations and objectives?
48. What is the IT department's current workload,
and do they have the necessary resources to manage it effectively?
49. Are there any skill gaps within our IT team, and
if so, which areas need improvement?
STANDARD OF SOUND PRACTICE ON MANAGEMENT OF CYBER RISKS 32 Board Oversight Expectations Questions for Next Board Meeting
50. What is our cybersecurity budget, and is it
aligned with industry benchmarks and our risk profile?
51. Are there specific cybersecurity skills or
expertise that we lack internally?
52. Are there regular assessments or audits to
identify and address capacity gaps within IT and cybersecurity? What are the recurring gaps and most alarming findings?
X. Assess and strengthen the
organization's approach to managing risks associated with external partners
53. What is our strategy for assessing and managing
cybersecurity risks associated with third-party vendors and suppliers?
54. What due diligence processes are in place before
onboarding new third-party vendors or partners?
55. Is there a risk ranking or categorization system
for vendors based on their potential impact on our organization's security?
56. Are there contractual agreements that specify
cybersecurity requirements and responsibilities for our vendors?
57. How do we monitor third-party vendors'
ongoing compliance with cybersecurity requirements and agreements?
58. What reporting mechanisms are in place for
third-party vendors to notify us of cybersecurity incidents or breaches?
59. How do we ensure that our third-party vendors
comply with relevant cybersecurity regulations and industry standards?
60. Do we have alternative vendors or contingency
plans in place in case a critical third-party vendor experiences a security incident or disruption?
STANDARD OF SOUND PRACTICE ON MANAGEMENT OF CYBER RISKS 33
APPENDIX 4
TYPES OF CYBER ATTACKS
Cyberattacks can take various forms, targeting different aspects of computer systems, networks, and data. Organizations must train users on the types of cyber attacks; reduce vulnerabilities and strengthen controls. Insufficient safeguards around assets, data and technology provide an environment for cyber criminals to penetrate, blend in and then launch attacks that disrupt operations and deny services, mostly for financial gain. Here are some common types of cyberattacks:
STANDARD OF SOUND PRACTICE ON MANAGEMENT OF CYBER RISKS 34 SQL code into input fields on web applications to gain unauthorized access to databases or manipulate data.
STANDARD OF SOUND PRACTICE ON MANAGEMENT OF CYBER RISKS 35 .APPENDIX 5 Industry Standards on Cybersecurity Common industry standards include:
STANDARD OF SOUND PRACTICE ON MANAGEMENT OF CYBER RISKS 36
STANDARD OF SOUND PRACTICE ON MANAGEMENT OF CYBER RISKS 37 ADDITIONAL REFERENCE MATERIAL
STANDARD OF SOUND PRACTICE ON MANAGEMENT OF CYBER RISKS 38 28a03c303 940/mL/2018-10-24-g-7-fundamental-elements-for-threat-ledpenetration-testing-data.pdf
Note from RegAlert. AI assistants can read this document in full, and search 70,000+ more, through the RegAlert MCP connector (https://mcp.regalert.today/mcp). Free with an account. How to connect ChatGPT, Claude or Cursor.
Source: Bank of Jamaica — original document · Summary generated with machine assistance and reviewed before publication; the authoritative text is the regulator's original document. How RegAlert works
More like this from BOJ
BOJ published 1 document in the last 30 days. We email you each new one the day it's published.