Cyber Resilience for Financial Market Infrastructures NOVEMBER 2019 CONTENTS Abstract 1 Abbreviations 2 I. Introduction and Background 3 II. Description of the CROE 5 A. Levels of Expectation 6 B. Application of Levels of Expectations 6 III. ECB Cyber Resilience Oversight Expectations 8 1. Governance 8 2 Identification 12 3 Protection 13 4 Detection 19 5 Response and recovery 20 6 Testing 23 7 Situational awareness 26 8 Learning and evolving 28 Annex 1: Cyber Resilience Questionnaire  30 Annex 2: Guidance on the Senior Executive 36 Annex 3: Glossary 38 DISCLAIMER The Financial Inclusion Global Initiative led in partnership by the World Bank Group (WBG), Interna- tional Telecommunication Union (ITU), and the Committee on Payments and Market Infrastructures (CPMI), with the support of Bill & Melinda Gates Foundation (BMGF). The FIGI program is a three-year investment funding national implementations in three countries (China, Egypt, and Mexico), supporting topical working groups to tackle 3 sets of outstanding challenges in closing the global financial inclusion gap, and hosting 3 annual symposia to gather the engaged public on topics relevant to the grant and share intermediary learnings from its efforts. This work has been prepared for the Financial Inclusion Global Initiative by the Cybersecurity for FMI’s Workstream of the FIGI Security, Infrastructure and Trust (SIT) Working Group. The work is a product of the staff of the World Bank with external contributions prepared for the Financial Inclusion Global Initia- tive. The findings, interpretations, and conclusions expressed in this work do not necessarily reflect the views of the Financial Inclusion Global Initiative partners partners including The World Bank, its Board of Executive Directors, or the governments they represent, or the views of the Committee for Market Pay- ments Infrastructure, International Telecommunications Union, or the Bill & Melinda Gates Foundation. The World Bank does not guarantee the accuracy of the data included in this work. The boundaries, colors, denominations, and other information shown on any map in this work do not imply any judg- ment on the part of The World Bank concerning the legal status of any territory or the endorsement or acceptance of such boundaries. RIGHTS AND PERMISSIONS The material in this work is subject to copyright. Because the World Bank encourages dissemination of its knowledge, this work may be reproduced, in whole or in part, for noncommercial purposes as long as full attribution to this work is given. Any queries on rights and licenses, including subsidiary rights, should be addressed to the Office of the Publisher, The World Bank, 1818 H Street NW, Washington, DC 20433, USA; fax: 202-522-2422; e-mail: pubrights@worldbank.org. Cyber Resilience for Financial Market Infrastructures NOVEMBER 20191 ABSTRACT The Financial Inclusion Global Initiative (FIGI) was launched tribute to improve the cyber resilience of systems critical by the World Bank Group, the International Telecommuni- to financial stability and financial inclusion, especially in cation Union (ITU) and the Committee on Payments and developing countries. Market Infrastructures (CPMI), with support from the Bill & This document presents a methodology developed by Melinda Gates Foundation, to advance financial inclusion the European Central Bank to operationalize the CPMI- in developing countries. The FIGI initiative comprises 3 IOSCO Guidance on Cyber Resilience for FMIs (Guidance), working groups (WG), the Digital Identity WG, Electronic which could be used by FMIs to comply with the Guidance Payments Acceptance WG, and Security, Infrastructure and by authorities (supervisors and overseers) to assess and Trust WG. Under the Security, Infrastructure and Trust their FMIs against the Guidance, hence enhancing the Working Group, a dedicated workstream focus on cyber overall cyber resilience of financial market infrastructures security for Financial Market Infrastructures (FMIs), to con- critical for financial stability and financial inclusion. 1. The document was first presented during the FIGI Symposium in Cairo in January 2019 CYBER RESILIENCE FOR FINANCIAL MARKET INFRASTRUCTURES • 1 Abbreviations ABAC Attribute-based access control ISMS Information security management system AI Artificial intelligence International Organization for ISO/IEC AIM Asset inventory management Standardization/International CCP Central counterparty clearing house Electrotechnical Commission CISO Chief information security officer IT Information technology COBIT Control objectives for information and KPI Key performance indicators related technology KRI Key risk indicators CPMI Committee on Payments and Market NAC Network access control Infrastructures NCB National central bank CPSS Committee on Payment and Settlement NIST National Institute of Standards and Systems Technology CROE Cyber resilience oversight expectations ORPS Other retail payment systems CSD Central securities depository PFMIs Principles for financial market infrastructures CSIRT Computer security incident response team PIRPS Prominently important retail payment DDoS Distributed denial of service systems DMZ Demilitarised zone RBAC Role-based access control e-CF European e-Competence Framework RPO Recovery point objectives FFIEC Federal Financial Institutions Examination RTO Recovery time objectives Council SDLC Software/system development life cycle FMI Financial market infrastructure SFIA Skills Framework for the Information Age GRC Governance, risk management and SIEM Security information and event management compliance SIPS Systemically important payment systems HIDS Host intrusion detection system SLA Service level agreement HIPS Host intrusion prevention system SOC Security operations centre HR Human resources SSH Secure Shell IAM Identity and access management SSS Securities settlement system ICT Information and communication technology T2S Target2-Securities IDS Intrusion detection system TLS Transport layer security IOSCO International Organization of Securities TR Trade repositories Commissions VPN Virtual private network IoT Internet of things TIBER Threat intelligence-based ethical red IPS Intrusion prevention system teaming ISAE International Standard on Assurance CERT Computer emergency response team Engagements ISAC Information sharing and analysis centre ISAE 3402 Assurance reports on controls at a service TTP Tactics, techniques and procedures organisation 2 • FINANCIAL INCLUSION GLOBAL INITIATIVE I. Introduction and Background Financial inclusion, and payment services as a critical by an interconnected entity is not necessarily related financial need and gateway to other financial services, to the degree of that entity’s relevance to the FMI’s requires safe and efficient financial market infrastruc- business. Thirdly, some cyber-attacks can render some tures. Core payments infrastructures provide the founda- risk management and business continuity arrangements tion for the operation of electronic payment instruments of FMIs ineffective. Automated systems and data repli- and services, and constitute a critical enabler for finan- cation arrangements that are designed to help preserve cial inclusion, as demonstrated in the CPMI-WBG report sensitive data and software in the event of a physi- on Payment Aspects of Financial Inclusion (PAFI, 2016). cal disruptive event might in some instances fuel the Cyber threat2 has emerged as a systemic risk concern propagation of malware and corrupted data to backup for the financial sector, and especially for financial market systems. infrastructures, because of their unique role and charac- In 2016, the Committee on Payments and Market Infra- teristics. As demonstrated by the CPMI, cyber risk pres- structures (CPMI) and the International Organization of ents unique challenges for FMIs’ traditional operational Securities Commissions (IOSCO) published the “Guidance risk management frameworks. Firstly, the persistence on cyber resilience for financial market infrastructures” and sophistication of cyber risk, make cyber-attacks dif- (the Guidance), to support and standardize industry’s ficult to identify or fully eradicate and equally difficult to efforts to enhance the cyber resilience of payment and determine the breadth of damage caused by cyber-at- securities settlement systems, and to support the consis- tacks. Secondly, there is a broad range of entry points tent and effective oversight and supervision of their cyber through which an FMI could be compromised. As a result resilience. The Guidance covers the ability of FMIs to pre- of their interconnectedness, cyber-attacks could come empt cyber-attacks, respond rapidly and effectively to through an FMI’s participant, linked FMIs, service provid- them, and achieve faster and safer target recovery objec- ers, vendors and vendor products. FMIs can themselves tives if the attacks succeed. become a channel to further propagate cyber-attacks. The Guidance outlines five primary risk management Unlike physical operational disruptions, cyber risk posed categories and three overarching components that should be addressed across an FMI’s cyber resilience framework. The risk management categories are: governance; identi-  circumstance with the potential to exploit one or more vulnerabilities 2. A that adversely affects cyber security. (FSB Cyber Lexicon, November fication; protection; detection; and response and recov- 2018) CYBER RESILIENCE FOR FINANCIAL MARKET INFRASTRUCTURES • 3 FIGURE 1. PAFI Framework Universal access to and frequent usage of transaction accounts Transaction Leveraging Catalytic pillars— Readily Awareness account and large-volume Drivers of access available and financial payment recurrent and usage access points literacy product design payment streams Financial and ICT structure Foundations— Legal and regulatory framework Critical enablers Public and private sector commitment Source: Payment Aspects of Financial Inclusion, The World Bank 2016 ery. The overarching components are: testing; situational FIGURE 2. CPMI-IOSCO framework for cyber resilience of FMIs awareness; and learning and evolving. FMIs are required to comply with the Guidance, and nd evolv rning a ing overseers must develop an oversight approach to assess Lea ation awarene al their FMIs against the Guidance, but there is currently no Situ ss detailed methodology to do it (comparable to the PFMIs Testing methodology to assess the compliance with the CPMI- IOSCO Principles for Financial Market Infrastructures). In order to operationalize the CMPI Guidance, a more detailed methodology is therefore required. The European Central Recovery Identification Bank (ECB) has developed such a methodology, through the Cyber Resilience Oversight Expectations (CROE). They set out clear criteria against which the overseers can Governance assess the FMIs for which they are responsible, provide FMIs with concrete steps to implement the Guidance and enhance their cyber resilience, as well as a detailed basis Detection Protection for discussion between the FMIs and their authorities. Although the CROE is designed in the context of the European Union, it could be used by authorities and FMIs in many countries, enhancing cyber resilience of Testing S it s FMIs at a global level and allowing for international ref- u ati o nes nal aware erences and benchmarking. It is therefore proposed that Le a g rning and evolvin the FIGI cyber security for FMIs workstream considers using the methodology in its mandate to contribute to the dissemination of best practices related to cyber Source: CPMI-IOSCO Guidance, 2016 resilience of FMIs. 4 • FINANCIAL INCLUSION GLOBAL INITIATIVE II. Description of the CROE In March 2017 the Governing Council of the ECB approved to assess FMIs under their responsibility; and (iii) it pro- the “Eurosystem cyber resilience strategy for FMIs”3 . The vides the basis for a meaningful discussion between the objective of this strategy is to improve the cyber resilience FMIs and their respective overseers. of the euro area financial sector as a whole by enhancing The CROE are predicated on the Guidance and sup- the “cyber readiness” of individual FMIs that are overseen plement the existing ‘CPSS-IOSCO Principles for financial by the Eurosystem central banks, and to foster collabora- market infrastructures’ (PFMIs), to ensure a full and coher- tion among FMIs, their critical service suppliers and the ent set of expectations. Additionally, whilst developing authorities. Specifically, the strategy aims to put the Guid- the draft CROE, the ECB also considered existing interna- ance into practice and comprises three pillars. The evolv- tional guidance documents and frameworks. In particular, ing nature of cyberattacks makes it necessary to ensure the National Institute of Standards and Technology (NIST) that FMIs strengthen their individual level of cyber matu- Cybersecurity Framework, ISO/IEC 27002, COBIT 5, rity. In this regard, Pillar 1 (FMI Readiness) aims to ensure Information Security Forum’s Standard of Good Practice that the Guidance is put into practice in a consistent man- for Information Security and Federal Financial Institutions ner, by implementing a harmonised approach to assessing Examination Council’s (FFIEC) Cybersecurity Assessment FMIs in the euro area against the Guidance. To facilitate Tool were used as a basis. this process, the ECB has—among other things4—devel- In line with the Guidance, the CROE is presented in oped the CROE. eight chapters that outline five primary risk management The CROE serves three key purposes: (i) it provides categories and three overarching components that should FMIs with detailed steps on how to operationalise the be addressed across an FMI’s cyber resilience framework. Guidance, ensuring they are able to foster improvements The risk management categories are: (i) governance; and enhance their cyber resilience over a sustained period (ii) identification; (iii) protection; (iv) detection; and (v) of time; (ii) it provides overseers with clear expectations response and recovery. The overarching components are: testing; situational awareness; and learning and evolving. Each chapter sets out three levels of expectations, which 3. https://www.ecb.europa.eu/paym/cyber-resilience/fmi/html/index. provide clarity and further details to both the FMI and en.html its respective competent authority on how to concretely 4. See for example the TIBER-EU Framework (www.ecb.europa.eu/press/ operationalize the Guidance. It is expected to review and pr/date/2018/html/ecb.pr180502.en.html) CYBER RESILIENCE FOR FINANCIAL MARKET INFRASTRUCTURES • 5 update the CROE in light of future market developments, FIGURE 3. CROE Levels of Expectation as and when deemed necessary. The expectations in each chapter of the CROE are preceded by a preamble, taken from the Guidance, set- ting out the overarching objectives of each category and component. Depending on their complexity, chapters are INNOVATING then structured into one or more sections, which contain a specific set of expectations for each of the three levels. In order to achieve the cyber resilience objectives, investments across the eight categories and components included in this document can be mutually reinforcing and should be considered jointly. ADVANCING A. LEVELS OF EXPECTATION The cyber threat landscape is constantly evolving and EVOLVING reaching higher levels of sophistication. In light of this, FMIs should make ongoing efforts to adapt, evolve and improve their cyber resilience capabilities. To address the idea of laborating with its external stakeholders. The Innovating continuous adaptation, evolution and improvement, the level entails driving innovation in people, processes, and CROE sets out levels of expectations which provides the technology for the FMI and the wider ecosystem to man- overseers and the FMIs with a benchmark against which age cyber risks and enhance cyber resilience. This may they can evaluate the FMIs’ current level of cyber resil- entail developing new controls, new tools, or creating new ience, measure progression and establish priority areas for information-sharing groups. improvement. The CROE establishes three levels of expec- The CROE extensively refers to the term “capabilities”, tations: Evolving, Advancing and Innovating. which is the FMI’s “people, processes and technologies The essence of these three levels of expectations used to identify, mitigate and manage its cyber risks to is continuous improving and maturing on the part of support its objectives”. the FMI; the levels of expectations are not designed to establish static requirements and an end state of matu- rity, which risks creating a culture of compliance. Rather, APPLICATION OF LEVELS OF B.  FMIs are expected to be constantly evolving, advancing EXPECTATIONS and innovating in light of the continuously evolving cyber threat landscape. Although the CROE have been developed to provide The three levels of expectations (Evolving, Advancing FMIs with detailed and specific expectations on how to and Innovating) are defined as follows: operationalize the Guidance, they also allow a degree of Evolving level: Essential capabilities are established and flexibility needed when dealing with a heterogeneous set evolve, and are sustained across the FMI to identify, of FMIs that differ from one to another in terms of size, manage and mitigate cyber risks, in alignment with the volume and value of transactions and their role within the Board-approved cyber resilience strategy and framework, financial system. The role of the respective overseers or and performance of practices is monitored and managed. supervisors in applying this flexibility and judgement is very important. Advancing level: In addition to meeting the Evolving level, The CROE should not be considered as a checklist of practices incorporate more advanced implementations measures FMIs need to strictly comply with, but instead (e.g. advanced technology and risk management tools) as a set of practices that can contribute to FMIs’ com- that are integrated across the FMI’s business lines and pliance with the Guidance. The overseers or supervisors have been improved over time, to proactively manage will determine the level of expectation their FMIs should cyber risks to the FMI. meet and thereafter it will be the overseers’ or supervi- Innovating level: In addition to meeting the Evolving sors’ judgement to see whether the FMI, commensurate and Advancing levels, capabilities across the FMI are with its criticality, is meeting the Evolving, Advancing enhanced as needed, in the midst of the rapidly evolving or Innovating levels. The professional judgement of the cyber threat landscape, in order to strengthen the cyber overseer or supervisor is an essential factor in determin- resilience of the FMI and its ecosystem by proactively col- ing whether the FMI is meeting the levels of expectations. 6 • FINANCIAL INCLUSION GLOBAL INITIATIVE This judgement should be driven by a number of consid- of expectation building additional mutually reinforcing erations, such as: the local laws and regulations governing good practices on top of each other. the FMI; the overseer’s or supervisor’s broader historic Therefore, the FMI should review the CROE in detail knowledge of the FMI; the size, criticality and business and consider how to implement the expectations con- model of the FMI, which should ensure a proportionate tained therein, giving due consideration on how best to approach is taken; and the ongoing discussions between build, improve and use its people, processes and tech- the overseer/supervisor and the FMI. nologies. It is expected that FMIs will reach the levels of expec- As FMIs implement the expectations, it is acknowl- tations, as determined by the relevant authority, across edged that at times they will do so in different ways. In all eight categories of the Guidance; once FMIs reach cases where the FMI does not meet the prescribed expec- and maintain their prescribed levels of expectations, they tation, it should provide an explanation on how it meets should continue to evolve and improve by taking relevant the objective of the underlying expectation. The ‘meet or steps to reach the higher levels of expectations, where it explain’ principle provides the FMI with a degree of flexi- is appropriate and in line with their business specificities. bility in its approach of enhancing its cyber resilience This process of evolution and improvement should occur capabilities, given that FMIs are heterogeneous and will through discussions between the FMI and the respective differ by size, organizational and operating structure, overseer and supervisor over a sustained period of time business model and infrastructure set-up. Consequently, and commensurate with the criticality of the specific FMI. it is feasible that FMIs may fulfil the underlying objectives The three levels of expectations are intended to allow of the expectations by using different processes, technol- the FMI to build and improve its capabilities in a multi-lay- ogies and methodologies. ered fashion over a longer period of time, with each level CYBER RESILIENCE FOR FINANCIAL MARKET INFRASTRUCTURES • 7 III. ECB Cyber Resilience Oversight Expectations 1 GOVERNANCE and manage cyber risks at all levels within the organiza- tion and to provide appropriate resources and expertise 1.1 Preamble to deal with these risks. This chapter provides guidance on what basic elements an FMI’s cyber resilience framework Cyber governance refers to the arrangements an FMI should include and how an FMI’s governance arrange- has put in place to establish, implement and review its ments should support that framework. approach to managing cyber risks. Effective cyber gov- ernance should start with a clear and comprehensive 1.2 Expectations cyber resilience framework that prioritizes the security and efficiency of the FMI’s operations, and supports 1.2.1 Cyber resilience strategy and framework financial stability objectives. The framework should EVOLVING be guided by an FMI’s cyber resilience strategy, define Cyber resilience strategy: how the FMI’s cyber resilience objectives are deter- mined, and outline its people, processes and technol- 1. The FMI should establish an internal, cross-disciplinary ogy requirements for managing cyber risks and timely steering committee comprised of senior management communication in order to enable an FMI to collabo- and appropriate staff (employees and/or contractors) rate with relevant stakeholders to effectively respond from multiple business units (e.g. business, finance, risk to and recover from cyber-attacks. It is essential that management, internal audit, operations, cybersecurity, the framework is supported by clearly defined roles and information technology (IT), communications, legal responsibilities of the FMI’s Board (or equivalent) and and human resources, some of which may be external), its management, and it is incumbent upon its Board and to collectively develop a cyber resilience strategy and management to create a culture which recognizes that framework. The steering committee should provide staff at all levels have important responsibilities in ensur- multiple views and perspectives to ensure that the ing the FMI’s cyber resilience. cyber resilience strategy and framework is holistic and Strong cyber governance is essential to an FMI’s imple- focuses on all elements related to people, processes mentation of a systematic and proactive approach to and technology. Among other things, the steering managing the prevailing and emerging cyber threats that committee should: it faces. It also supports efforts to appropriately consider 8 • FINANCIAL INCLUSION GLOBAL INITIATIVE (a) e  valuate and prioritise internal and external stake- implementation plan will be delivered and how the holders’ needs and expectations, deciding on the Board should track and monitor delivery. overall requirements from cyber resilience; (g) The high-level scope of technology and assets (b) provide direction to senior management on what which will be used to manage cyber resilience. cyber resilience should achieve; (h) The interactions with other participants, FMIs and (c) define who makes cyber resilience decisions and third parties, on areas such as information sharing. how those decisions should be made; (i) The governance necessary to enable cyber resil- (d) consider the FMI’s risk landscape and risk toler- ience to be designed, transitioned, operated and ance when defining how cyber risks should be improved. addressed; (j) How cyber resilience initiatives will be delivered, (e) evaluate how the different business units are im- managed and funded, including the budgeting pacted and can work together in an integrated process and organisational capabilities. manner to achieve enterprise-wide outcomes; (k) How cyber resilience will be integrated into all (f) consider how to monitor the performance and aspects of the FMI, which includes people, pro- outcomes of cyber resilience and intervene if cesses, technology and new business initiatives. necessary to ensure that the specified direction 3. The FMI should ensure that the cyber resilience strat- is followed. egy is aligned to its corporate strategy and other rel- 2. Based on the above reflections, the FMI should doc- evant strategies (e.g. enterprise risk management, ument its cyber resilience strategy. The FMI should operational risk and IT). ensure that the following aspects are considered and 4. The FMI’s Board should approve the cyber resilience included in the strategy. strategy and should ensure that it is regularly reviewed (a) The importance of cyber resilience to the FMI and and updated according to the FMI’s threat landscape. its key stakeholders. 5. The Board should be kept regularly informed of the (b) Internal and external stakeholders’ high-level FMI’s cyber risk and ensure consistency with the FMI’s requirements, so that these can be taken into risk tolerance and appetite, so that it can achieve account when defining cyber resilience gover- the FMI’s overall business objectives and corporate nance and goals for cyber resilience management. strategy. Some common categories of stakeholders that may be considered include: owners and investors, Cyber resilience framework: customers and clients, suppliers, employees, legal and regulatory authorities, and competitors and 6. The FMI should have a cyber resilience framework that industry bodies. clearly sets out how it determines its cyber resilience objectives and risk tolerance, as well as how it effec- (c) The FMI’s vision and mission in relation to cyber tively identifies, mitigates, and manages its cyber risks resilience. to support its objectives. (d) The cyber resilience objectives that the FMI will work towards, which should include ensuring the 7. The FMI’s cyber resilience framework should system- ongoing efficiency, effectiveness and economic atically incorporate the requirements (i.e. policies, viability of its services to its users and maintaining procedures and controls) related to governance, iden- and promoting the FMI’s ability to anticipate, with- tification, protection, detection, response and recov- stand, contain and recover from cyber attacks. ery, testing, situational awareness, and learning and evolving. (e) The FMI’s cyber risk appetite, to ensure that it remains consistent with the FMI’s risk tolerance, as 8. The FMI should use leading international, national and well as with the FMI’s overall business objectives industry-level standards, guidelines or recommenda- and corporate strategy. tions (e.g. NIST, COBIT 5 and ISO/IEC 27000, etc.), (f) Clear and credible cyber maturity targets and a reflecting current industry best practices in managing roadmap or implementation plan with change deliv- cyber threats, as a benchmark for designing its cyber ery and planning of capabilities relating to people, resilience framework and incorporating the most effec- processes and technology at pace with threats and tive cyber resilience solutions. proportionate to the FMI’s size and criticality. The 9. At the broader level, the FMI’s cyber resilience frame- strategy should clearly set out how this roadmap or work should be consistent with its enterprise risk man- agement framework. CYBER RESILIENCE FOR FINANCIAL MARKET INFRASTRUCTURES • 9 The FMI’s Board should endorse this cyber resilience 10. INNOVATING framework, ensuring it is aligned with the FMI’s for- Cyber resilience strategy and framework: mulated cyber resilience strategy, review it at least The cyber resilience strategy should outline the FMI’s 15. annually and update it when needed to ensure that it future state of cyber resilience, in terms of maturity remains relevant. and/or risk, with short and long-term perspectives, and 11. The FMI’s cyber resilience framework should clearly senior management should continuously improve and define the roles and responsibilities, including account- adapt the existing cyber resilience strategy and frame- ability for decision-making within the organisation, for work as the desired maturity level and/or risk land- identifying, mitigating and managing cyber risk. scape changes. ADVANCING The FMI should establish the appropriate structures, 16. Cyber resilience strategy and framework: processes and relationships with the key stakehold- ers in the ecosystem to continuously and proactively The FMI should use maturity models and define rele- 12. enhance the ecosystem’s cyber resilience and promote vant metrics to assess and measure the adequacy and financial stability objectives as a whole. effectiveness of and adherence to its cyber resilience framework through independent compliance pro- 1.2.2 Role of the Board and senior management grammes and audits carried out by qualified staff on a regular basis. EVOLVING 13. The FMI should ensure that, as part of its formal pro- Board and management responsibilities: cess to review and update its cyber resilience strat- 17. The FMI’s Board should be responsible for approving egy and framework (including all policies, procedures the cyber resilience strategy and framework, setting and controls), a number of factors are considered, the FMI’s risk tolerance for cyber risks and closely such as: overseeing the FMI’s implementation of its cyber resil- (a) the current and evolving cyber threats (e.g. those ience framework and the policies, procedures and associated with the supply chain, use of cloud ser- controls that support it. vices, social networking, mobile applications and 18. In order to carry out the aforementioned responsi- the internet of things, etc.); bilities, the FMI’s Board should ensure that it collec- (b) threat intelligence on threat actors and new tac- tively possesses the appropriate balance of skills, tics, techniques and procedures which may specif- knowledge and experience to understand and assess ically impact the FMI; the cyber risks facing the FMI. It should also be suffi- (c) the results of risk assessments of the FMI’s critical ciently informed and capable of credibly challenging functions, key roles, processes, information assets, the recommendations and decisions of designated third-party service providers and interconnections; senior management. Although the Board should col- lectively increase its skills and knowledge on cyber- (d) actual cyber incidents that have impacted the FMI security, it can also access specific expertise through directly or external cyber incidents from the eco- a Board member with adequate experience, or system; through experienced staff and/or external indepen- (e) lessons learned from audits and tests on the cyber dent organisation(s) reporting to and advising the resilience framework; Board. (f) the FMI’s performance against the relevant metrics 19. The Board and senior management should ensure that and maturity models; a senior executive (e.g. the CISO) is responsible and (g) new business developments and future strategic accountable for implementing the cyber resilience objectives. strategy and framework at the enterprise level. The 14. The FMI’s cyber resilience strategy and framework Senior Executive should be independent, possess the should consider how the FMI would continuously appropriate balance of skills, knowledge and experi- review and proactively identify, mitigate and manage ence, and have sufficient resources and direct access the cyber risks that it bears from and poses to its par- to the Board. For further clarification on the possible ticipants, other FMIs, vendors, vendor products and its roles and responsibilities of such a senior executive, service providers, which are collectively referred to as see Annex 3. an FMI’s ecosystem. 20. The Board and senior management should ensure that staff (including senior management) who are respon- sible for cyber activities have suitable skills, knowl- 10 • FINANCIAL INCLUSION GLOBAL INITIATIVE edge and experience, and are sufficiently informed threats, threat actors and vulnerabilities), tactics and and empowered to make timely decisions. techniques (e.g. phishing, spear phishing, social engi- neering and mobile security) and emerging issues, 21. The Board and senior management should ensure according to staff members’ levels of responsibility that cyber risk, implementation of the cyber resilience and the risks associated with their respective roles. framework and any associated issues appear regularly on the Board’s meeting agenda. Boards should have Senior management should ensure that employees 28. adequate access to cybersecurity expertise (whether and contractors with privileged account permissions internal or external), and discussions about cyber risk and/or access to sensitive assets and information, management should be given adequate time on the receive additional cyber resilience training commen- Board’s meeting agenda. surate with their levels of responsibility, and that busi- ness units are provided with cyber resilience training 22. Senior management should regularly provide a written relevant to their criticality to the business. report to the Board on the overall status of its cyber resilience programme and keys risks and issues. In order to implement the cyber resilience strategy 29. and framework, senior management should ensure 23. As part of the Board’s updates, senior management that it identifies the competencies, skills and resources should provide their budgeting and forecasting required. Senior management could adopt well-known activities plan for ongoing and future resource needs skills frameworks, such as the European e-Compe- to ensure cyber resilience objectives are continually tence Framework (e-CF) or the Skills Framework for achieved. the Information Age (SFIA) to determine its organisa- tional needs. Culture: 24. The Board and senior management should cultivate a Senior management should continuously review the 30. strong level of awareness of and commitment to cyber skills, competencies and training requirements to resilience. To that end, an FMI’s Board and senior man- ensure that it has the right set of skills as technologies agement should promote a culture that recognises and risks evolve. that staff at all levels have important responsibilities ADVANCING for ensuring the FMI’s cyber resilience, and lead by Board and management responsibilities: example. 31. The FMI should ensure that the Board members’ and 25. The Board and senior management should ensure that senior managements’ understanding of their roles and behavioural and cultural change is nurtured and con- responsibilities with regard to cyber resilience is reg- veyed through leadership and vision, with clear and ularly assessed, including their knowledge of cyber effective messages such as cyber resilience is every- risks. one’s duty. This could be executed throughout the FMI, possibly built into charters, vision statements and The Board should ensure that senior management 32. mandates from senior management, or through cyber regularly conducts a cyber resilience self-assessment awareness campaigns. , which evaluates the FMI’s cyber maturity. The Board should review the self-assessment and take appropri- Senior management should ensure that situational 26. ate decisions to improve the effectiveness of cyber awareness materials are made available to relevant activities and integration with the corporate strategy employees when prompted by highly visible cyber across the FMI. incidents, changes to the threat landscape and the impacts of these threats to the FMI, or by regulatory 33. The Board should review and approve senior manage- alerts. For example, the FMI could send internal emails ment’s prioritisation and resource allocation decisions about cyber events or post articles on its intranet site. based on the results of the cyber (self-) assessments, performance against key performance indicators Skills and accountability: (KPIs) and their evolution against their target state of maturity, and the FMI’s overall business objectives. 27. Senior management should ensure that it has a pro- gramme for continuing cyber resilience training and Culture: skills development for all staff. This training pro- Senior management should establish and sustain 34. gramme should include the Board members and incentives (e.g. staff recognition awards) to ensure senior management and should be conducted at least behaviours are consistent with the intended cyber risk annually. The annual cyber resilience training should culture. include incident response, current cyber threats (e.g. CYBER RESILIENCE FOR FINANCIAL MARKET INFRASTRUCTURES • 11 35. Senior management should produce a formal cyber any available sector-defined requirements and coordi- Code of Conduct, which can be incorporated into the nated initiatives, and clearly communicate this to the FMI’s enterprise Code of Conduct, and ensure that all relevant stakeholders. employees comply with it. Culture: 36. Senior management should validate the effectiveness of its cyber resilience training programme (e.g. social Senior management should cooperate proactively 44. engineering or phishing tests) and assess whether with other stakeholders to promote a cyber resilience training and awareness programmes positively influ- culture across the ecosystem. ence behaviour. Based on the lessons learned from its training programme, the FMI should improve the Skills and accountability: employee awareness programmes. Senior management should regularly benchmark 45. its cyber resilience capabilities against the market 37. Senior management should develop key performance to identify its gaps in terms of governance, skills, metrics (e.g. KPIs) and key risk metrics (e.g. key risk resources and tools, treating these gaps as cyber risks indicators (KRIs)) and markers (both quantitative and and addressing them accordingly. qualitative) and ensure supporting data are routinely collected at the senior management level to monitor, Senior management should actively foster partner- 46. measure and report on the implementation, effective- ships with industry associations and cybersecurity ness, consistency and persistence of cyber activities. practitioners to develop solutions for future cyber resilience needs, which will be useful to the FMI and Skills and accountability: the ecosystem as a whole. 38. Senior management should embed a programme for talent recruitment, retention and succession planning for the staff, and ensure such staff are aligned to cyber 2 IDENTIFICATION activities and deployed effectively across the FMI. 2.1 Preamble Senior management should ensure that there are 39. well-defined plans for the succession of high-risk staff Given that an FMI’s operational failure can negatively (e.g. senior management, system administrators, soft- impact financial stability, it is crucial that FMIs identify ware developers and critical system operators, etc.), which of their operations and supporting information and the recruitment requirements for key cyber roles assets should, in order of priority, be protected against include suitable cyber skills, knowledge and experi- compromise. The ability of an FMI to understand its inter- ence in alignment with defined succession plans. nal situation and external dependencies is key to being able to effectively respond to potential cyber threats that Senior management should ensure that staff per- 40. might occur. This requires an FMI to know its information formance plans are tied to compliance with cyber assets and understand its processes, procedures, systems resilience policies and standards in order to hold and all dependencies to strengthen its overall cyber resil- employees accountable. ience posture. This chapter outlines areas where an FMI INNOVATING should identify and classify business processes and infor- mation assets as well as external dependencies. Board and management responsibilities: 41. The FMI should appoint a dedicated cyber expert to 2.2 Expectations the Board. EVOLVING 42. The standard Board meeting package should include 1. The FMI should identify and document all its critical reports and metrics that cover areas such as suspi- functions, key roles, processes and information assets cious cybersecurity events (e.g. increased network that support those functions, and update this informa- behaviour and unusual user activity), cyber incidents tion on a regular basis. and threat intelligence trends for the ecosystem to facilitate discussions on how the FMI should respond 2. The FMI should identify and document all processes accordingly. that are dependent on third-party service providers and identify its interconnections, and update this infor- The Board and senior management should proac- 43. mation on a regular basis. tively enhance its strategic goals, objectives and tac- tical plans, as needed, to support cyber activities and 3. The FMI should maintain an up-to-date inventory of improvements across the ecosystem, making use of all the critical functions, key roles, processes, infor- 12 • FINANCIAL INCLUSION GLOBAL INITIATIVE mation assets, third-party service providers and inter- assets, including the connections to business partners, connections. It should integrate identification efforts internet-facing services, cloud services and any other with other relevant processes, such as acquisition and third-party systems. It should use these maps to under- change management, in order to facilitate a regular take risk assessments of key dependencies and apply review of its inventory. appropriate risk controls, when necessary. 4. The FMI should have an enterprise risk management 11. The FMI should update its inventory to address new, framework to identify risks and conduct risk assess- relocated, repurposed and sunset information assets, ments on a regular basis and of all the critical functions, on a regular basis or when these changes occur. key roles, processes, information assets, third-party INNOVATING service providers and interconnections to determine, classify and document their level of criticality. 12. The FMI should use automated feeds from above (e.g. from AIM and IAM tools), in order to identify emerging 5. The FMI should create and maintain a simplified net- risks, update its risk assessments in a timely manner work map of network resources with an associated and take the necessary mitigating actions in line with plan addressing IPs which locate routing and security the FMI’s risk tolerance. devices and servers supporting the FMI’s critical func- tions, and which identify links with the outside world. The FMI should identify the cyber risks that it bears 13. from or poses to entities in its ecosystem and coor- 6. The FMI should conduct risk assessments before dinate with relevant entities, as appropriate. This deploying new and/or updated technologies, prod- may involve identifying common vulnerabilities and ucts, services and connections to identify potential threats, and taking appropriate measures collectively threats and vulnerabilities. It should also update its risk to address such risks, with the objective of improving assessment in case new information affecting cyberse- the ecosystem’s overall resilience. curity risks is identified (e.g. a new threat, vulnerability, adverse test result, hardware change, software change or configuration change). The results of the risk assess- 3 PROTECTION ments should feed into the cyber resilience strategy and framework. 3.1 Preamble 7. The FMI should have and maintain a fully comprehen- Cyber resilience depends on effective security controls sive inventory of all individual and system accounts and system and process design that protect the confi- (especially including privileged and remote access dentiality, integrity and availability of an FMI’s assets and accounts) so that they can be aware of the access services. These measures should be proportionate to an rights to information assets and their supporting sys- FMI’s threat landscape and systemic role in the financial tems. The FMI should review and update this inventory system, and consistent with its risk tolerance. This chapter on a regular basis. provides guidance on how FMIs should implement appro- ADVANCING priate and effective measures in line with leading cyber resilience and cybersecurity practices to prevent, limit or 8. The FMI should use automated tools (e.g. a centralised contain the impact of a potential cyber event. asset inventory management (AIM) tool) that enable it to support the identification and classification of the 3.2 Expectations critical functions, processes, information assets and interconnections. The FMI should ensure that the inven- 3.2.1 Protection of processes and assets tory is updated accurately and that these changes are Control implementation and design shared with the relevant staff in in a timely manner. EVOLVING 9. The FMI should use automated tools (e.g. a centralised 1. The FMI should implement a comprehensive and identity and access management (IAM) tool) that appropriate set of security controls that will allow enable it to support the identification and classifica- it to achieve the security objectives needed to meet tion process of roles, user profiles and individual and its business requirements. The FMI should implement system credentials, and ensure that these are updated these controls based on the identification of its criti- accurately and that relevant staff are informed of the cal functions, key roles, processes, information assets, changes in a timely manner. third-party service providers and interconnections, as The FMI should also maintain up-to-date and com- 10. per the risk assessment in the identification phase. The plete maps of network resources, interconnections and security objectives may include ensuring: dependencies, and data flows with other information CYBER RESILIENCE FOR FINANCIAL MARKET INFRASTRUCTURES • 13 (a) the continuity and availability of its information acquiring or modifying its systems, processes and systems; products. At each stage of the SDLC, the FMI should (b) the integrity of the information stored in its infor- manage its cyber risk and integrate resilience based on mation systems, while both in use and transit; risk analysis results. (c) the protection, integrity, confidentiality and avail- INNOVATING ability of data while at rest, in use and in transit; 8. The FMI should frequently review its ISMS, using certi- (d) conformity to applicable laws, regulation and stan- fication, audis or other relevant forms of assurance. dards. 9. The FMI should develop processes and procedures and 2. The FMI should develop its security controls in order explore potential technologies to constantly adjust to address cybersecurity and related physical security and refine its security countermeasures (controls). This and people security. The controls should be designed will help it to ensure it is protected against known and according to the threat landscape, prioritised in accor- emerging threats, based on knowledge and best prac- dance with the risks facing the FMI (risk-based security tices obtained from other FMIs across the ecosystem controls) and aligned to its business objectives. and through the use of threat intelligence. 3. The FMI should assess the effectiveness of its security Network and infrastructure management controls regularly in order to adapt them to its evolv- ing threat landscape. They should be monitored and EVOLVING audited regularly to ensure that they remain effective 10. The FMI should establish a secure boundary that pro- and have been applied to all assets where they might tects its network infrastructure (using tools such as be needed. a router, firewall, intrusion prevention system (IPS) 4. When designing, developing and acquiring its sys- or intrusion detection system (IDS), virtual private tems and processes, the FMI should capture security network (VPN), demilitarised zone (DMZ) or prox- requirements alongside system and process require- ies etc.). The boundary should identify trusted and ments in order to identify the security controls neces- untrusted zones according to the risk profile and crit- sary for protecting its systems, processes and data, at icality of information assets contained within each the earliest possible stage. zone, and appropriate access requirements should be implemented within and between each security zone 5. The FMI should apply a defence-in-depth strategy in according to the principle of least privilege. line with a risk-based approach, i.e. it should implement multiple independent security controls so that if one 11. The FMI should seek to use a separate and dedicated control fails or a vulnerability is exploited, alternative network for information system administration. At controls will be able to protect targeted assets and/or a minimum, the FMI should prohibit direct internet processes. access from devices or servers used for information system administration whenever possible. ADVANCING The FMI should establish a baseline system and secu- 12. 6. The FMI should develop and implement a bespoke rity configurations for information systems and sys- information security management system (ISMS), tem components, including devices used for accessing which could be based on a combination of well-rec- the FMI network remotely, to help the configuration ognised international standards (e.g. ISO 27001, ISO to and security reinforcement of those systems and 20000-1 and ISO 27103, etc.), in order to establish, components to be applied consistently. These base- implement, operate, continuously monitor, review, lines should be documented, formally reviewed and maintain and improve a comprehensive cybersecurity regularly updated to adapt them to the FMI’s evolving control framework. threat landscape. 7. The FMI should consider cyber resilience at the earli- 13. The FMI should reinforce its network infrastructure and est stage of system design, development and acqui- information systems using recognised industry security sition, as well as throughout the system development standards. Changes to system configurations should life cycle, so that vulnerabilities in software and hard- be strictly controlled and monitored and programmes ware are minimised and security controls are incorpo- that can alter or override system configuration should rated into systems and processes from their inception. be restricted. This should also be applicable to devices It should adopt a bespoke system development life and environments used for accessing the FMI network cycle (SDLC) methodology that embeds the resil- remotely. ience-by-design approach when designing, building, 14 • FINANCIAL INCLUSION GLOBAL INITIATIVE 14. The FMI should seek to use secure network protocols The FMI’s IT environments and functions should be 22. (e.g. Secure Shell and protocols relying on transport adequately separated with different security levels layer security (TLS) or equivalent), when appropriate, and controls implemented. in order to guarantee the confidentiality and integ- The FMI should implement technical measures to 23. rity of information exchanged within its network and prevent the execution of unauthorised code on insti- beyond, including remote connections. tution-owned or managed devices, network infra- 15. The FMI should define and implement procedures that structure and system components. limit, lock and terminate system and remote sessions 24. The FMI should consider implementing technical mea- after a predefined period of inactivity and predefined sures (e.g. network access control (NAC) solutions) conditions are met. in order to prevent unauthorised devices from being 16. The FMI should deploy a broad range of technologies connecting successfully. and tools to detect and block actual and attempted The FMI should employ automated mechanisms to 25. attacks or intrusions. The FMI may use intrusion detec- help maintain an up-to-date, complete, accurate and tion or prevention systems, end point security solutions readily available baseline of system and security con- (e.g. antivirus, a firewall, or a host intrusion detection figurations for the information system and system system (HIDS) or host intrusion prevention system components. These mechanisms might include hard- (HIPS)) or any other relevant solutions (e.g. an access ware and software inventory tools, configuration man- gateway or a jump box), in particular on devices and agement tools and network management tools. in environments used for accessing the FMI network remotely. INNOVATING 17. The FMI should implement controls that manage or pre- The FMI should implement automated mechanisms 26. vent non-controlled devices to connect to its internal that can isolate affected information assets in the case network from inside or outside the premises to ensure of an adverse event. that activities in these zones are logged and monitored 27. In the context of a defence-in-depth strategy, the FMI for inappropriate use or attempts to access business should seek to implement cyber deception capabilities systems. The FMI’s infrastructure should be scanned and techniques that enable it to lure the attacker and regularly to detect rogue devices and access points. trap it in a controlled environment where all activities 18. The FMI should scan its legacy technologies regularly can be contained and analysed, allowing the FMI to to identify potential vulnerabilities and seek upgrade gain vital threat intelligence that will help to improve opportunities. Controls and additional defence layers its protection controls. should be implemented and tested in order to protect unsupported or vulnerable systems. Logical and physical security management 19. The FMI should have policies and controls that prevent EVOLVING users from installing unauthorised applications. Proce- 28. The FMI should identify and restrict physical and log- dures should be in place to manage the installation of ical access to its system resources to the minimum applications. required for legitimate and approved work activities, according to the principle of least privilege. ADVANCING 20. The FMI should implement a defence-in-depth secu- The FMI should establish policies, procedures and 29. rity architecture, based on the network and data flow controls that address access privileges and how that diagrams that identify hardware, software and net- access should be administered. The information sys- work components, internal and external connections, tem access should be evaluated regularly to identify and type of information exchanged between systems. unneeded access or privileges. Physical, logical and/or As required in the identification phase, the FMI should remote access to critical systems should be restricted maintain current and complete network and data flow and logged and unauthorised access should be diagrams. blocked. Administration rights on systems should be strictly limited to operational needs. Procedures should 21. The FMI should segment its network infrastructure be in place for a periodic review of all access rights. with security policies appropriate to its use and com- mensurate to its risk score, which define proper access 30. The FMI should establish and administer user accounts policy to systems and applications. Sensitive traffic in accordance with a role-based access control (RBAC) between systems and zones should be segregated scheme that organises allowed information system using network management. access rights and privileges into roles. Role assign- CYBER RESILIENCE FOR FINANCIAL MARKET INFRASTRUCTURES • 15 ments should be reviewed regularly by appropriate The FMI should implement automated mechanisms 38. staff (e.g. management and system owners, etc.) in to support the management of information system order to take appropriate action when privileged role access accounts. This might include implementing assignments are no longer appropriate. security controls embedded in the information system, allowing it to automatically disable and/or remove 31. The FMI should establish processes to manage the cre- inactive, temporary and emergency accounts after a ation, modification or deletion of user access rights. predefined period of time. Such actions should be submitted to and approved by appropriate staff, and should be recorded for review if INNOVATING necessary. 39. The FMI should establish strong governance on iden- 32. The FMI should implement specific procedures to allo- tity and access management enforced by the use of cate privileged access on a need-to-use or an event- dedicated tools such as Identity and Access Manage- by-event basis. Administrators should have two types ment (IAM), in an integrated way, ensuring all systems of accounts: one for general purpose and one to carry update each other consistently. out their administrative tasks. The use of privileged The FMI should seek to use an attribute-based access 40. accounts should be tightly monitored and controlled. control (ABAC) paradigm that allows it to manage The use of generic accounts for administration pur- access to its IT environment contextually and dynami- pose should be strictly limited and traced. Whenever cally. possible, user and administrator accounts should be nominative and clearly identifiable (e.g. using dedi- 41. The FMI should employ automated mechanisms that cated taxonomy for usernames, which ensures that allow account creation, modification, enabling, dis- the positions and roles are not apparent). abling and removal actions to be monitored and audited continuously, in order to notify appropriate 33. The FMI should have a dedicated policy that covers all staff when potential malicious behaviour or damage is the characteristics of its authentication mechanisms detected. The FMI should implement adaptive access (e.g. password, smart cards and biometrics, etc.) and controls to prevent potential malicious behaviour or is in line with relevant standards (e.g. NIST-800-63). damage. Default authentication settings (e.g. passwords and unnecessary default accounts) should be deactivated, Change and patch management changed or removed before systems, software and/or EVOLVING services go live. The FMI should have policies, procedures and con- 42. The FMI should develop appropriate controls (e.g. 34. trols in place for change management, which should encryption, authentication and access control) to include criteria for prioritising and classifying the protect data at rest, in use and in transit. The controls changes (e.g. normal vs. emergency change). Prior to should be commensurate to the criticality and the sen- any change, the FMI should ensure that the change sitivity of the data held, used or being transmitted, as request is: per the risk assessment conducted in the identifica- (a) reviewed to ensure that it meets FMI business tion phase. needs; The FMI should have dedicated controls to prevent 35. (b) categorised and assessed for identifying poten- unauthorised access to cryptographic keys. Dedicated tial risks and to ensure that it will not negatively policy and procedures should be defined for the man- impact confidentiality, integrity and availability, as agement of and access to cryptographic materials. well as the FMI’s systems and data; ADVANCING (c) approved before it is implemented by the appro- 36. The FMI should implement controls to prevent unau- priate level of management. thorised privileged escalation (e.g. technical controls 43. The FMI should ensure that the cybersecurity team is that trigger automated notification to appropriate involved throughout the life cycle of the change man- staff in the case of changes to user access profiles). agement process, as appropriate. 37. The FMI should encrypt data as a result of its data The FMI should put necessary procedures in place 44. classification and risk assessment processes. The FMI (e.g. code review and unit testing, etc.), guarantee- should also use encryption and general cryptographic ing that changes are implemented correctly and effi- controls in line with recognised standards and pro- ciently. The FMI should employ best practices when cesses, which cover aspects such as algorithm, key implementing changes. length and key generation, etc. 16 • FINANCIAL INCLUSION GLOBAL INITIATIVE 45. The FMI should test, validate and document changes The FMI should consider building a segregated or 54. to the information system before implementing them separate environment that mirrors the production into production (this might include integration tests, environment, allowing rapid testing and changes and non-regression tests and user acceptance tests, etc.). patches to be implemented, and providing for rapid The changes to information systems include, but are fall-back when needed. not limited to, modifying hardware, software or firm- INNOVATING ware components and system and security configu- ration settings. The FMI should ensure that processes The FMI should implement automated mechanisms 55. are in place to schedule change implementation and to prohibit changes and patches from being installed communicate to those impacted prior to implementa- on the information system that have not been pre-ap- tion, including consulting them when necessary. proved. The FMI should have processes to identify, assess and 46. 3.2.2 People management approve genuine emergency changes. Post-implemen- tation reviews should be conducted to validate that Human resources security emergency procedures were appropriately followed EVOLVING and to determine the impact of the emergency change. The FMI should embed cybersecurity at each stage 56. 47. The FMI should have a comprehensive patch manage- of the employment life cycle, specifying security-re- ment policy and processes that include: maintaining lated actions required during the induction of each current knowledge of available patches; identifying employee and their ongoing management, and upon appropriate patches for particular systems and ana- the termination of their employment. lysing impacts if installed; assuring that patches are (a) Prior to employment, the FMI should carry out installed properly (e.g. by applying the four-eyes prin- background security checks on all candidates ciple) and tested prior to and monitored after installa- (employees and/or contractors) commensurate to tion; and documenting all associated procedures, such their future role and depending on the criticality of as specific configurations required. The policies, pro- the assets and information they might have access cedures and controls must make use of the informa- to in order to fulfil their duty. Responsibilities for tion AIM process described in the identification phase cybersecurity should be clearly stated in the con- that provides information on the installed programs tractual agreement. and binaries. (b) During employment, the FMI should ensure that The FMI should consider using standardised configu- 48. employees and contractors comply with estab- ration of IT resources to facilitate its patch manage- lished policies, procedures and controls. When ment process. an employee is changing responsibilities, the FMI should ensure that all access rights that are related The FMI should ensure that the installations of new 49. to his/her previous position and are not necessary patches have prior approval from the appropriate level for his/her new responsibilities are revoked in due of management. time. Employees in sensitive positions (e.g. those 50. The FMI should have in place necessary procedures for who change to roles requiring privileged access recovering quickly when changes or patches fail. Any to critical systems or who become high-risk staff) changes to the production environment must have an should be pre-screened. associated fall-back plan, when applicable. (c) The FMI should establish procedures to revoke 51. The FMI should have policies and procedures to pro- all departing employees’ access rights from the hibit changes and patch installation to the information information assets in a timely manner. Upon ter- system that have not been pre-approved. mination of employment, staff should be required to return all assets that belong to the FMI, includ- ADVANCING ing important documentation (e.g. related to busi- 52. The FMI should establish its change management ness processes, technical procedures and contact process based on well-established and industry-rec- details), equipment, software and authentication ognised standards and best practices (e.g. the infor- hardware, etc. mation technology infrastructure library). 57. The FMI should establish policies, procedures and con- 53. The FMI should consider automating its patch man- trols for granting or revoking employees physical and agement process when possible to guarantee that all logical access to its systems based on job responsibil- its systems remain consistently up to date. ities, principles of least privilege and segregation of CYBER RESILIENCE FOR FINANCIAL MARKET INFRASTRUCTURES • 17 duties. Procedures for regularly reviewing such access whether the training and awareness positively influ- should be in place. ence behaviour and ensure that staff comply with the cybersecurity policy and incident reporting process. The FMI should establish capabilities, including peo- 58. ple, processes and technologies to monitor privileged INNOVATING users’ activity and access to critical systems in order 67. The FMI’s senior management should ensure its cul- to identify and deter anomalous behaviour and notify tural awareness of cyber risk improves continuously appropriate staff. across the organisation and its ecosystem. Training ADVANCING programmes should be updated regularly to take the evolving threat landscape of the ecosystem into The FMI should implement mechanisms that trigger 59. account. automatic notifications to be sent to staff in charge of granting or revoking access to the information system Supplier and third-party security management upon change to employment status. EVOLVING The FMI should implement automatic mechanisms to 60. The FMI should maintain and regularly update an 68. grant or revoke staff access to its information system inventory of its participants and third-party service upon change to employment status. providers, and ensure that its cyber resilience frame- work addresses its interconnections with the afore- INNOVATING mentioned entities from a cyber risk perspective. 61. The FMI should monitor and analyse pattern behaviour (e.g. network use patterns, work hours and known The FMI’s third-party risk assessment should be car- 69. devices, etc.) to identify anomalous activities and ried out regularly, taking into account the evolution evaluate the implementation of innovative solutions of its threat landscape. The FMI should, using a risk- (e.g. data analytics, machine learning and artificial based approach, ensure that the provision of out- intelligence, etc.) to support detection and response sourced services are accorded the appropriate level of to insider threat activity in real time. cyber resilience. 70. The FMI should assess the third-party service provid- Security awareness and training er’s security capabilities at least through third-party EVOLVING self-assessment (e.g. self-assessment against Annex F ). Provision of settlement services to ancillary systems 62. The FMI should ensure that its employees have a good by overseen entities is not considered to be third- understanding of the cyber risk they might face when party service provision. conducting their jobs and that they understand their roles and responsibilities in protecting the FMI’s assets. ADVANCING 63. On a regular basis, at least once a year, the FMI should 71. The FMI should design security controls that detect provide its entire staff (employees and/or contractors) and prevent intrusions from third-party connections. with training to support cybersecurity policy compli- 72. The FMI should ensure that there are appropriate pro- ance and the incident reporting process. This training cedures in place to isolate or block its third-party con- should include elements aimed at maintaining appro- nections (in a timely manner) if there is a cyber attack priate awareness of cyber-related risks and good and/or a risk of contagion. practices for dealing with potential cyber incidents, including how to report unusual activity. Cybersecu- 73. The independent audit function should validate the rity awareness training should be part of the onboard- FMI’s third-party relationship management and out- ing programme for new staff. sourcing. 64. The FMI should ensure that high-risk staff receive ded- 74. The FMI should obtain assurance of the third-party icated security awareness training that is relevant to service provider’s cyber resilience capabilities, and their responsibilities. may use tools such as certification, external audits (e.g. ISAE 3402), summaries of test reports, service 65. Prior to going into service operations, staff operating level agreements (SLAs) and KPIs, etc. new systems should receive appropriate user training and be familiar with the operating procedures. INNOVATING 75. The FMI should work closely with its third-party ser- ADVANCING vice providers and other FMIs in the ecosystem to The FMI should validate the effectiveness of its train- 66. maintain and improve the security of interconnections ing (e.g. social engineering or phishing tests), assess 18 • FINANCIAL INCLUSION GLOBAL INITIATIVE and end point security. For example, the FMI could 7. The FMI should ensure that its relevant staff (employ- conduct response and recovery tests with its third- ees and/or contractors) are trained to be able to iden- party service providers and other FMIs. tify and report anomalous activity and events. 8. The FMI should build multilayered detection controls covering people, processes and technology which sup- 4 DETECTION port attack detection and isolation of infected points. 4.1 Preamble 9. The FMI should ensure that its detection capabilities are informed by threat or vulnerability information, which An FMI’s ability to recognise signs of a potential cyber can be collected from different sources and providers, incident, or detect that an actual breach has taken place, as set out in the chapter on situational awareness. is essential to strong cyber resilience. Early detection provides an FMI with useful lead time to mount appro- The FMI should define alert thresholds for its monitor- 10. priate countermeasures against a potential breach, and ing and detection systems in order to trigger and facil- allows proactive containment of actual breaches. In the itate the incident response process. latter case, early containment could effectively mitigate 11. The FMI’s monitoring and detection capabilities should the impact of the attack – for example, by preventing support information collection for the forensic inves- an intruder from gaining access to confidential data or tigation. To facilitate forensic investigation, the FMI exfiltration of such data. Given the stealthy and sophis- should ensure that its logs are backed up at a secure ticated nature of cyber attacks and the multiple entry location with controls in place to mitigate the risk of points through which a compromise could take place, an alteration. FMI should maintain effective capabilities to extensively monitor for anomalous activities. This chapter outlines ADVANCING monitoring and process-related guidance aimed at help- The FMI should develop and implement automated 12. ing FMIs detect cyber incidents. mechanisms (e.g. a security information and event management (SIEM) system), which correlates all the 4.2 Expectations network and system alerts and any other anomalous EVOLVING activity across its business units in order to detect mul- tifaceted attacks (e.g. simultaneous account takeover 1. Based on the risk assessment performed in the iden- or a distributed denial of service (DDoS) attack). tification phase, the FMI should define, consider and document the baseline profile of system activities to 13. The FMI should have a process to collect, centralise and help detect deviation from the baseline (e.g. anoma- correlate event information from multiple sources and lous activities and events). log analysis to continuously monitor the IT environ- ment (e.g. databases, servers and end points, etc.) and 2. The FMI should develop the appropriate capabilities, detect anomalous activities and events. This should including the people, processes and technology, to include information on anomalous activity and other monitor and detect anomalous activities and events, network and system alerts across business units. This by setting appropriate criteria, parameters and triggers capability could be achieved through a security opera- to enable alerts. tions centre (SOC) or equivalent. 3. The FMI should have capabilities in place to monitor The FMI should have processes in place to monitor 14. user activity, exceptions and cybersecurity events. activities that are not in line with its security policy 4. The FMI should have capabilities in place to monitor and might lead to data theft, integrity compromise or connections, external service providers, devices and destruction. software. 15. The FMI’s monitoring and detection capabilities should 5. The FMI should analyse the information collected and allow the appropriate staff who can respond to be use it to further enhance its detection and monitoring alerted automatically. capabilities and incident response process. The FMI should have the capabilities, in collabora- 16. 6. The FMI should ensure that its detection capabilities, tion with other stakeholders, to detect cyber events baseline profile of system activities and the criteria, and adapt its security controls swiftly. Such events parameters and triggers are periodically reviewed, may include attempted infiltration, movement of an tested and updated appropriately, in a controlled and attacker across systems, exploitation of vulnerabil- authorised manner. ities, unlawful access to systems and exfiltration of information or data. CYBER RESILIENCE FOR FINANCIAL MARKET INFRASTRUCTURES • 19 17. The FMI should continuously monitor connections 5.2 Expectations among information assets and cyber risk levels through- 5.2.1 Cyber resilience incident management out the information assets’ life cycles, and store and analyse these data. The information gathered this way EVOLVING should enable the FMI to support timely responses to 1. The FMI should—based on the identification of its crit- cyber threats (including insider threats) or vulnerabili- ical functions, key roles, processes, information assets, ties and investigation of anomalous activities. third-party service providers and interconnections – 18. The FMI should continuously monitor and inspect the plan for how to operate in a diminished capacity or how network traffic, including remote connections, and to safely restore services over time, based on services’ end point configuration and activity to identify poten- relative priorities, and with accurate data. In order to tial vulnerabilities or anomalous events in a timely make the best decisions about its recovery objectives manner. following a cyber incident, the FMI must first define its recovery point objectives (RPOs) and its recovery time The FMI should compare the network traffic and the 19. objectives (RTOs), commensurate to its business needs end point configuration with the expected traffic and and systemic role in the ecosystem. configuration baseline profile and data flows. 2. Based on Expectation 1 above, the FMI should consider INNOVATING a range of different cyber scenarios, including extreme 20. The FMI should use multiple external sources of intel- but plausible ones to which they may be exposed, and ligence, correlated log analysis, alerts, traffic flows, conduct business impact analyses to assess the poten- and geopolitical events to predict potential future tial impact such scenarios might have on the FMI. The attacks and attack trends, and proactively take the FMI should review its range of scenarios and conduct appropriate measures to improve its cyber resilience the business impact analysis in line with the evolving capabilities. threat landscape, on a regular basis. 21. The FMI should develop threat detection capabilities 3. The FMI should, based on the different cyber scenar- which can detect both known and unknown threats, ios, develop a contingency plan that achieves recovery with a proactive identification of vulnerabilities, state- objectives, restoration priorities and determines the of-the art threat detection and correlation between required capacities for continuous availability of the vulnerabilities and threats. system. The plan should define roles and responsibili- ties, and set out options to reroute or substitute critical The FMI should seek to continuously explore new 22. functions and/or services that may be affected for a technologies and techniques inhibiting lateral move- significant period by a successful cyber attack. ment (e.g. deception mechanisms) which trigger alerts and inform the FMI of potential malicious activ- 4. The FMI should develop comprehensive cyber incident ity when accessed. For example, the FMI could create response, resumption and recovery plans, to manage and place fictitious sensitive data with alerting tags cybersecurity events or incidents in a way that lim- attached to them. its damage and prioritises resumption and recovery actions in order to facilitate the processing of critical transactions, increases the confidence of external stake- 5 RESPONSE AND RECOVERY holders, and reduces recovery time and costs. Such plans should define policies and procedures, as well as 5.1 Preamble roles and responsibilities for escalating, responding to, and recovering from cybersecurity incidents. The FMI Financial stability may depend on an FMI’s ability to set- should ensure all relevant business units (including tle obligations when they are due. Therefore, an FMI’s communications) are integrated into the plans. arrangements should be designed to enable it to resume critical operations rapidly, safely and with accurate data 5. The FMI’s cyber incident response, resumption and in order to mitigate the potentially systemic risks of recovery processes should be closely integrated with failure to meet such obligations when participants are crisis management, business continuity, and disaster expecting it to meet them. Continuity planning is essen- recovery planning and recovery operations. tial for meeting related objectives. This chapter provides 6. The FMI should ensure that its incident response team guidance on an FMI’s capabilities to respond to and has the requisite skills and training to address cyber recover from cyber attacks. incidents. 20 • FINANCIAL INCLUSION GLOBAL INITIATIVE 7. The FMI should define alert parameters and thresholds imal service disruption. This capability might include for detecting cybersecurity incidents, which trigger direct cooperative or contractual agreements with the incident management processes and procedures, incident response organisations or providers to assist which in turn include alerting and conveying informa- rapidly with mitigation effort. tion to the appropriate staff. The FMI should define and develop functional and 14. 8. The FMI should regularly test its cyber contingency, security dependency maps of identified information response, resumption and recovery plans against a assets supporting critical functions to understand and range of different plausible scenarios. prioritise the order in which they should be restored. 9. The FMI should have processes and procedures in place The FMI should be able to use lessons learned from 15. for collating and reviewing information from its cyber- real-life cyber attacks on the institution and its ecosys- security incidents and testing results in order to contin- tem to improve its contingency, response, resumption uously improve its contingency, response, resumption and recovery plans. and recovery plans. The FMI should consult with relevant external stake- 16. 10. The FMI should have processes and procedures in place holders (e.g. main participants, service providers and to conduct an ex post root cause analysis of its cyber- other FMIs) within the ecosystem to further enhance its security incidents. The FMI should integrate its findings contingency, response, resumption and recovery plans. from the root cause analysis into its cyber response, The FMI should continuously monitor, evaluate and 17. resumption and recovery plans, as set out in Expecta- consider technological developments and solutions in tion 4 above. the market that may enhance its contingency, response, ADVANCING resumption and recovery capabilities. 11. The FMI should design and test its systems and pro- INNOVATING cesses to enable critical operations to be resumed 18. The FMI should implement processes to continuously safely within two hours of a cyber disruption and to improve its cyber response, resumption and recovery enable it to complete settlement by the end of the plans, taking into account cyber threat intelligence day of the disruption, even in the case of extreme but feeds, information sharing with its ecosystem and les- plausible scenarios. Notwithstanding this capability sons learned from previous events. to resume critical operations within two hours, FMIs should undertake careful problem analysis and exercise 19. The FMI should consult, collaborate and coordinate judgement (in agreement with competent authorities with relevant external stakeholders (e.g. main partic- and relevant stakeholders) when resuming operations ipants, service providers and other FMIs) within the so that risks to the FMI or its ecosystem do not escalate ecosystem to develop common contingency, response, as a result, while taking into account the fact that com- resumption and recovery plans for cyber scenarios pletion of settlement by the end of day is crucial. which may impact the ecosystem as a whole. The FMI should conduct regular scenario tests (e.g. indus- 12. The FMI should plan for scenarios in which resumption try-wide and FMI-specific simulation exercises) with within two hours cannot be achieved. The FMI should the relevant external stakeholders. analyse critical functions, transactions and interdepen- dencies to prioritise resumption and recovery actions, The FMI should implement a computer security inci- 20. which may, depending on the design of the FMI, help dent response team (CSIRT), whether in-house or out- critical transactions to be processed, for example, while sourced, that is responsible for responding to security remediation efforts continue. The FMI should also plan incidents and intrusions, and coordinating activities for situations in which critical people, processes or sys- among the relevant internal and external stakeholders. tems may be unavailable for significant periods – for Such a team should have the authority to direct the example, by potentially reverting (where feasible, safe FMI to make the changes necessary to recover from and practicable) to manual processing if automated the incident. systems are unavailable. 21. The FMI should establish and implement processes The FMI should implement an effective incident han- 13. to manage cybersecurity incidents and enable auto- dling capability for cybersecurity incidents that mated responses, triggered by predefined criteria, includes preparation, detection and analysis, contain- parameters and thresholds. For example, the FMI ment, eradication and recovery. Such capability should could develop configurable capability to isolate or allow the FMI to perform, at an early stage, analysis of disable automatically affected information systems if cybersecurity incidents upon their detection, with min- cyber attacks or security violations are detected. CYBER RESILIENCE FOR FINANCIAL MARKET INFRASTRUCTURES • 21 5.2.2 Data integrity 5.2.3 Communication and collaboration EVOLVING Contagion 22. The FMI should develop a formal backup policy speci- EVOLVING fying the minimum frequency and scope of data, based The FMI should identify, document and regularly 33. on data sensitivity and the frequency with which that review systems and processes supporting its critical new information is introduced. functions and/or operations that are dependent on 23. The FMI should develop backup and recovery meth- external connectivity. ods and strategies to be able to restore system opera- The FMI should develop policies and procedures that 34. tions with minimum downtime and limited disruption. define how it should work together with relevant inter- 24. The FMI should regularly back up all data necessary to connected entities to enable operations to be resumed replay participants’ transactions. (the first priority being its critical functions and ser- vices) as soon as it is safe and practicable to do so. 25. Backups should be protected at rest and in transit to ensure the confidentiality, integrity and availability ADVANCING of data. Backups should be tested regularly to verify The FMI should closely cooperate with its intercon- 35. their availability and integrity. nected entities within the ecosystem, establishing rollback processes in order to restore all its services ADVANCING accurately and safely. Moreover, the FMI should test The FMI should store backup copies at an alternate 26. the effectiveness of these procedures regularly. site with a different risk profile to the main site, and with transfer rates consistent with actual RPOs. The INNOVATING alternate site and backups should be safeguarded by The FMI should design its network connection infra- 36. stringent protective and detective controls. structure in a way that allows connections to be seg- mented or severed instantaneously to prevent conta- 27. The FMI’s information systems should implement trans- gion arising from cyber attacks. action recovery mechanisms for transaction-based systems, which might include transaction rollback and Crisis communication and responsible disclosure logging. EVOLVING 28. The FMI should conduct frequent periodic reconcilia- 37. The FMI should identify and determine staff who are tion of participants’ positions, with the assistance of essential for mitigating the risk of a cyber incident, participants where needed. and make them aware of their roles and responsibil- 29. The FMI should develop capabilities to restore infor- ities regarding incident escalation. mation system components within the actual RTOs The FMI’s incident response plan should identify the 38. using a predefined and standardised configuration of internal and external stakeholders that must be noti- IT resources, the integrity of which is protected. fied, as well as the information that has to be shared INNOVATING and reported, and when this should take place. The FMI’s backup and recovery methods and strat- 30. The FMI should establish criteria and procedures for 39. egies should be integrated into the FMI’s system escalating cyber incidents or vulnerabilities to the infrastructure at the development and/or acquisition Board and senior management based on the potential phase. impact and criticality of the risk. 31. The FMI should back up its information system by The FMI should have a communication plan and pro- 40. maintaining a redundant secondary system that is not cedures in place to notify, as required or necessary, all located in the same place as the primary system and relevant internal and external stakeholders (including that can be activated without information being lost oversight, regulatory authorities, media and custom- or operations disrupted. ers) in a timely manner, when the institution becomes 32. The FMI should consider having a data-sharing agree- aware of a cyber incident. The FMI should notify the ment with third parties and/or participants in order to appropriate internal and external stakeholders when a obtain uncorrupted data from them for recovering its cyber incident occurs. business operations in a timely manner and with accu- 41. The FMI should have a policy and procedures to enable rate data. potential vulnerabilities to be disclosed responsibly. In particular, the FMI should prioritise disclosures that 22 • FINANCIAL INCLUSION GLOBAL INITIATIVE could help stakeholders to respond promptly and account the requirements of the local jurisdiction. mitigate risk, which could benefit the ecosystem and These procedures should describe how investigative broader financial stability. staff should produce step-by-step documentation of all activities performed on digital evidence and their 42. The FMI should establish and regularly review informa- impact. tion-sharing rules, agreements and modalities in order to control the publication and distribution of such 49. The FMI should establish policies for securely handling information, and to prevent sensitive information that and storing the collected digital evidence, ensuring its may have adverse consequences if disclosed improp- authenticity and integrity. The FMI should develop pro- erly from being disseminated. cedures to demonstrate that the evidence’s integrity is preserved whenever it is accessed, used or moved (i.e. ADVANCING chain of custody). After developing a range of cyber incident scenarios 43. based on the incident criteria established in the evolv- 50. The FMI should train its staff so that all those involved ing level, the FMI should develop appropriate incident in an incident understand their responsibilities related response and communication plans and procedures to handling the digital evidence, ensuring it is not com- to address the scenarios. These incident response and promised and remains valid as per the requirements of communication plans and procedures should take the local jurisdiction. into consideration the legal and regulatory reporting 51. The FMI should ensure that staff specifically involved in requirements at a jurisdictional level. the forensic investigation have the appropriate degree INNOVATING of competence in handling the digital evidence, ensur- ing its authenticity and integrity is not compromised The FMI should develop mechanisms that instan- 44. and remains valid as per the requirements of the local taneously notify its senior management, relevant jurisdiction. employees and relevant stakeholders (including over- sight and regulatory authorities) of cyber incidents ADVANCING through appropriate communication channels with The FMI should closely integrate plans for forensic 52. tracking and verification of receipt. Such mechanisms readiness with plans for incident management and should be based on predefined criteria and informed other related business planning activities. by scenario-based planning and analysis, as well as prior experience. INNOVATING 53. The FMI should have a management review process 5.2.4 Forensic readiness that improves forensic readiness plans in accordance EVOLVING with experience and new knowledge. 45. The FMI should identify the threat scenarios that might The FMI should take an open and collaborative ap- 54. have a potential impact on its business and determine proach with the ecosystem to improve lawful foren- which pieces of digital evidence (e.g. types of logs) sic investigation and incident handling methodologies should be collected to facilitate forensic investigation. and tools. The FMI should identify and document the digital 46. evidence available on its systems and its location, 6 TESTING and understand how the evidence should be handled throughout its life cycle. 6.1 Preamble 47. Based on Expectations 45 and 46, the FMI should Testing is an integral component of any cyber resilience develop and implement a forensic readiness policy and framework. All elements of a cyber resilience framework the capability to support forensic investigation, which should be rigorously tested to determine their overall also outlines the relevant system logging policies that effectiveness before being deployed within an FMI, and include the types of logs to be maintained and their regularly thereafter. This includes the extent to which retention periods. The FMI may outsource the conduct the framework is implemented correctly, operating as of forensic investigations to external specialists. intended and producing desired outcomes. Under- 48. The FMI should establish procedures for securely col- standing the overall effectiveness of the cyber resilience lecting digital evidence in a forensically acceptable framework in the FMI and its environment is essential in manner and in accordance with the requirements determining the residual cyber risk to the FMI’s opera- defined in the forensic readiness policy, taking into tions, assets, and ecosystem. CYBER RESILIENCE FOR FINANCIAL MARKET INFRASTRUCTURES • 23 Sound testing regimes produce findings that are used 9. The FMI should test the information backups periodi- to identify gaps in stated resilience objectives and provide cally to verify they are accessible and readable. credible and meaningful inputs to the FMI’s cyber risk Vulnerability assessments: management process. Analysis of testing results provides direction on how to correct weaknesses or deficiencies in The FMI should develop a documented and regularly 10. the cyber resilience posture and reduce or eliminate iden- updated vulnerability management process in order tified gaps. This chapter provides guidance on areas that to classify, prioritise and remedy potential weaknesses should be included in an FMI’s testing and how results identified in vulnerability assessments and perform from testing can be used to improve the FMI’s cyber resil- subsequent validation to assess whether gaps have ience posture on an ongoing basis. The scope of testing been fully addressed. for the purpose of this guidance includes vulnerability 11. The FMI’s vulnerability management process should assessments, scenario-based testing, penetration tests help any type of exploitable weakness to be identified and tests using red teams. (technical, processual, organisational and emergent) in the critical functions, their supporting processes and 6.2 Expectations information assets where they reside. EVOLVING 12. The FMI should conduct vulnerability scanning for their General: external-facing services and the internal systems and 1. The FMI should establish and maintain a comprehen- networks on a regular basis. sive testing programme as an integral part of its cyber The FMI should perform vulnerability assessments 13. resilience framework. The testing programme should before any deployment or redeployment of new or consist of a broad spectrum of methodologies, prac- existing services supporting critical functions, appli- tices and tools for monitoring, assessing and evaluat- cations and infrastructure components for fixing bugs ing the effectiveness of the core components of the and weaknesses, consistently with change and release cyber resilience framework. management processes in place. 2. The FMI should adopt a risk-based approach in devel- The FMI should periodically conduct vulnerability 14. oping the comprehensive testing programme. This assessments on running services, applications and infra- should be reviewed and updated on a regular basis tak- structure components for compliance checks against ing into due account the evolving landscape of threats regulations, policy and configurations, as well as for and the criticality of information assets. monitoring and evaluating the effectiveness of security 3. The FMI should develop appropriate capabilities and controls to address the identified vulnerabilities. involve, if deemed necessary, all relevant internal stake- holders (including business lines and operational units) Scenario-based testing: when implementing its testing programme. 15. The FMI should perform different scenario-based tests, 4. The FMI should ensure that the tests are undertaken by including extreme but plausible scenarios, to evaluate independent parties, whether internal or external. and improve its incident detection capability, as well as response, resumption and recovery plans. Scenar- 5. For continuous improvement of its cyber resilience io-based tests can take the form of desktop exercises posture, the FMI should establish policies and proce- or simulations. dures to prioritise and remedy issues identified from the various tests and perform subsequent validation to The FMI’s Board and senior management should be 16. assess whether gaps have been fully addressed. engaged in the scenario-based test, when appropriate. 6. The FMI’s Board and senior management should incor- 17. To improve the FMI’s staff awareness and enhance the porate lessons learned from the test results. risk culture within the organisation, the scenario-based tests should include social engineering and phishing 7. The FMI should test critical systems, applications and simulation. data recovery plans at least annually. 18. The FMI should test of the extent to which internal skills, 8. The FMI should test response, resumption and recov- processes and procedures can adequately respond to ery plans, including governance and coordination, and extreme but plausible scenarios, with a view to achiev- crisis communication arrangements and practices, at ing stronger operational resilience. least annually. 24 • FINANCIAL INCLUSION GLOBAL INITIATIVE Penetration tests: use such stress tests to further improve its risk man- 19. The FMI should conduct penetration tests on their agement framework. external-facing services and the internal systems and Penetration tests: networks to identify vulnerabilities in the adopted 28. The FMI should design and perform penetration tests technology, organisation and operations regularly, or to simulate realistic attack techniques on systems, net- at least on an annual basis. Penetration tests should works, applications and procedures. be conducted using a risk-based approach and, at the very least, in cases of major changes and new system Red team testing: deployment. The FMI should conduct red team exercises to test 29. The FMI should perform penetration tests, engaging 20. critical functions for possible vulnerabilities and the all critical internal and external stakeholders in the effectiveness of an FMI’s mitigating controls, including penetration testing exercises: system owners, business its people, processes and technology. continuity, and incident and crisis response teams. 30. The FMI should perform red team exercises using reli- ADVANCING able and valuable cyber threat intelligence, based on General: specific and plausible threat scenarios. 21. The FMI should include testing practices as an inte- 31. The FMI should conduct independent red team exer- grated part of its enterprise risk management process cises, utilising regulatory and industry frameworks with the aim of identifying, analysing and fixing cyber- (e.g. the European Framework for Threat-Intelligence security vulnerabilities stemming from new products, Based Ethical Red teaming (TIBER-EU Framework) ). services or interconnections. 32. The FMI should build its internal processes and capa- 22. The FMI should develop capabilities to seek, analyse bilities to prepare for undertaking the independent and use cyber threat intelligence to help inform and red team exercise (e.g. establishing an internal white update its testing programme to ensure it is in line team, developing incident escalation procedures, fol- with the latest threat landscape, attackers’ modus lowing appropriate methodologies and establishing operandi and vulnerabilities. robust risk management controls), as set out in the TIBER-EU Framework, for example. 23. The FMI should adopt best practices and automated tools to support the processes and procedures in INNOVATING place to fix technical and organisational weaknesses General: identified during the testing exercises and to check for 33. The FMI should develop, monitor and analyse metrics compliance with approved policy and configurations. to assess the performance and effectiveness of its The FMI should perform security assessments and 24. testing programme. The FMI should use the analysis tests when applicable at all phases of the SDLC and conducted to further improve its testing programme. at any level (business, application and technology) for The FMI should regularly conduct tests in collabora- 34. the entire application portfolio, including mobile appli- tion with its peers, participants and third parties. cations. The FMI should proactively engage in industry-wide 35. Vulnerability assessments: exercises in order to test cooperation and coordination 25. The FMI should perform vulnerability scanning on an protocols and communication plans. These exercises ongoing basis, rotating among environments in order should foster the FMI’s awareness on cross-sector to scan all environments throughout the year. cooperation and third-party risks. Scenario-based testing: 36. The FMI should promote and participate in cross-sec- 26. The FMI should test its response, resumption and tor cyber testing exercises to assess the soundness recovery plans against cyber attack scenarios which and security of its value chain as a whole. include data destruction, data integrity corruption, 37. The FMI should test the cooperation arrangements data loss, and system and data availability. in place with relevant external entities at least annu- 27. The FMI should use cybersecurity incident scenarios ally (e.g. third-party security service providers, law involving significant financial loss, as part of its stress enforcement agencies, computer emergency response testing process, to better understand potential spill- teams (CERTs) or information sharing and analysis overs and risk to its business model. The FMI should centres (ISACs), etc.) in order to validate their effec- tiveness. CYBER RESILIENCE FOR FINANCIAL MARKET INFRASTRUCTURES • 25 38. The FMI should consider discussing relevant test con- can help an FMI better understand the vulnerabilities in its clusions with other stakeholders to boost the cyber critical business functions, and facilitate the adoption of resilience of its ecosystem and the financial sector as a appropriate risk mitigation strategies. It can also enable whole, as far as possible and under specific information- an FMI to validate its strategic direction, resource allo- sharing arrangements. cation, processes, procedures and controls with respect to building its cyber resilience. A key means of achieving Vulnerability assessments: situational awareness for an FMI and its ecosystem is an 39. The FMI should develop and adopt a range of effective FMI’s active participation in information-sharing arrange- practices and tools (e.g. a Bug Bounty programme and ments and collaboration with trusted stakeholders within static and dynamic code reviews, etc.) as part of its and outside the industry. This chapter provides guidance vulnerability management process, and have appro- for FMIs to establish a cyber threat intelligence process, priate safeguards in place to manage them. analysis and sharing processes. Scenario-based testing: 7.2 Expectations The FMI should conduct scenario-based tests that 40. cover breaches affecting multiple portions of the FMI’s 7.2.1 Cyber threat intelligence ecosystem in order to identify and analyse potential EVOLVING complexities, interdependencies and possible con- 1. The FMI should identify cyber threats that could mate- tagion both at business and operational level which rially affect its ability to perform or provide services as should be taken into account in the FMI’s cyber resil- expected, or that could have a significant impact on its ience framework. ability to meet its own obligations or have knock-on 41. The FMI should collaborate with the ecosystem to effects within its ecosystem. develop cybersecurity incident scenarios involving 2. The FMI should have capabilities in place to gather significant financial loss and use them for stress tests cyber threat information from internal and external to better understand potential spillovers and conta- sources (e.g. application, system and network logs; gion risk to the ecosystem. The FMI should use such security products such as firewalls and IDSs; trusted stress tests to further improve its cyber resilience pos- threat intelligence providers; and publicly available ture, which contributes to improving the ecosystem’s information). resilience as a whole. 3. The FMI should belong or subscribe to a threat and Red team testing: vulnerability information-sharing source and/or ISAC 42. In addition to periodic independent and external red that provides information on cyber threats and vulner- team exercises, the FMI should develop an internal red abilities. Cyber threat information gathered by the FMI team capability with the appropriate methodologies, should include analysis of tactics, techniques and pro- sophisticated tools and appropriately skilled staff. The cedures (TTPs) of real-life attackers, their modus ope- internal red team should regularly conduct red team randi and information on geopolitical developments exercises and engage with the internal blue team to that may trigger cyber attacks on any entity within the share its findings and make improvements to the FMI’s FMI’s ecosystem. cyber resilience posture. 4. The FMI should have the capabilities to analyse the cyber threat information gathered from different sources, while taking into account the business and 7 SITUATIONAL AWARENESS technical characteristics of the FMI, in order to: 7.1 Preamble (a) determine the motivation and capabilities of threat actors (including their TTPs) and the extent to Situational awareness refers to an FMI’s understanding which the FMI is at risk of a targeted attack from of the cyber threat environment within which it operates, them; and the implications of being in that environment for its (b) assess the risk of technical vulnerabilities in oper- business and the adequacy of its cyber risk mitigation ating systems, applications and other software, measures. Strong situational awareness, acquired through which could be exploited to perform attacks on an effective cyber threat intelligence process can make the FMI; a significant difference in the FMI’s ability to pre-empt cyber events or respond rapidly and effectively to them. (c) analyse cybersecurity incidents experienced by Specifically, a keen appreciation of the threat landscape other organisations (where available), including types of incident and origin of attacks, target of 26 • FINANCIAL INCLUSION GLOBAL INITIATIVE attacks, preceding threat events and frequency of The FMI should include in its threat analysis those 12. occurrence, and determine the potential risk these threats which could trigger extreme but plausible cyber pose to the FMI. events, even if they are considered unlikely to occur or have never occurred in the past. The FMI should review 5. The FMI should analyse the information gathered and update this analysis regularly. above to produce relevant cyber threat intelligence, and continuously use it to assess and manage secu- INNOVATING rity threats and vulnerabilities for the purpose of The FMI should ensure that the scope of cyber threat 13. implementing appropriate cybersecurity controls in intelligence gathering includes the capability to gather its systems and, on a more general level, enhancing and interpret information about relevant cyber threats its cyber resilience framework and capabilities on an arising from the FMI’s participants, service and utility ongoing basis. providers and other FMIs, and to interpret this infor- 6. The FMI should ensure that the gathering and analy- mation in ways that allow the FMI to identify, assess sis of cyber threat information and the production of and manage security threats and vulnerabilities for the cyber threat intelligence are reviewed and updated purpose of implementing appropriate safeguards in its regularly. systems. 7. The FMI should ensure that cyber threat intelligence is The FMI should integrate and align its cyber threat 14. made available to appropriate staff who are responsi- intelligence process with its SOC. The FMI should use ble for mitigating cyber risks at the strategic, tactical information gathered from its SOC to further enhance and operational levels within the FMI. its cyber threat intelligence; and conversely, use its cyber threat intelligence to inform its SOC. 8. The FMI should incorporate lessons learned from its analysis of the cyber threat information into the 7.2.2 Information sharing employee training and awareness programmes. EVOLVING ADVANCING 15. The FMI should define the goals and objectives of 9. The FMI should continuously use its cyber threat intel- information sharing, in line with its business objectives ligence to anticipate, as much as possible, a cyber and cyber resilience framework. At the very least, the attacker’s capabilities, intentions and modus operandi, objectives should include collecting and exchanging and subsequently possible future attacks. information in a timely manner that could facilitate the 10. The FMI should develop a cyber threat risk dashboard, detection, response, resumption and recovery of its which uses the cyber threat information and intelli- own systems and those of other sector participants gence to outline, among other things: during and following a cyber attack. (a) the most likely threat actors for the FMI; 16. The FMI should define the scope of information-shar- ing activities by identifying the types of information (b) the TTPs that may be used by such threat actors; available to be shared (e.g. attackers’ modus operandi, (c) the likely vulnerabilities that may be exploited by indicators of compromise, and threats and vulnerabil- such threat actors; ities, etc.), the circumstances under which sharing this (d) the likelihood of attack from such threat actors information is permitted (e.g. in the case of a cyber and the impact on the confidentiality, integrity and incident), those with whom the information can and availability of the FMI’s business processes and its should be shared (e.g. the FMI’s direct stakeholders reputation that could arise from such attacks; such as critical service providers, participants and other interconnected FMIs, etc.), and how information (e) the impact of attacks already conducted by such provided to the FMI and other sector participants will threat actors on the ecosystem; be acted upon. (f) the risk mitigation measures in place to manage a potential attack. 17. The FMI should establish and regularly review the information-sharing rules and agreements and imple- 11. The cyber threat risk dashboard should be continu- ment procedures that allow information to be shared ously reviewed and updated in the light of new threats promptly and in line with the objectives and scope and vulnerabilities and discussed by the Board and established above, while at the same time meeting senior management. its obligations to protect potentially sensitive data that may have adverse consequences if disclosed improperly. CYBER RESILIENCE FOR FINANCIAL MARKET INFRASTRUCTURES • 27 18. The FMI should establish trusted and safe channels 8.2 Expectations of communication with its direct stakeholders for 8.2.1 Cyber threat intelligence exchanging information. EVOLVING 19. The FMI should have in place a process to access 1. The FMI should have capabilities in place to gather and share information with external stakeholders in a information on common vulnerabilities, cyber threats, timely manner, such as regulators, law enforcement or events and incidents occurring both within and outside other organisations within the FMI’s ecosystem. the FMI. ADVANCING 2. The FMI should have the capabilities to analyse the 20. The FMI should participate actively in existing informa- information gathered and assess the potential impact tion-sharing groups and facilities, including cross-in- on its cyber resilience framework. dustry, cross-government and cross-border groups to gather, distribute and assess information about cyber 3. The FMI should distil and classify the lessons learned practices, cyber threats and early warning indicators (e.g. strategic, tactical and operational), identify the relating to cyber threats. key stakeholders to whom these apply, incorporate them to improve the FMI’s cyber resilience framework 21. The FMI should establish and implement protocols for and capabilities, and convey them to each relevant sharing information relating to threats, vulnerabilities stakeholder on an ongoing basis. and cyber incidents with employees, based on their specific roles and responsibilities. 4. Senior management should ensure that it has a pro- gramme for continuing cyber resilience training and 22. The FMI should share information with relevant stake- skills development for all staff. This training programme holders in the ecosystem to achieve broader cyber should include the Board members and senior manage- resilience situational awareness, including promoting ment and should be conducted at least annually. The an understanding of each other’s approach to achiev- annual cyber resilience training should include incident ing cyber resilience. response, current cyber threats (e.g. phishing, spear INNOVATING phishing, social engineering and mobile security) and emerging issues. The FMI should ensure that the train- 23. The FMI should make use of threat intelligence capa- ing programme equips staff to deal with cyber inci- bilities that provide internal and external threat and dents, including how to report unusual activity. vulnerability information, analyse this information, and disseminate it to the relevant stakeholders in the 5. The FMI should ensure that cybersecurity awareness ecosystem promptly, so as to help stakeholders to materials are made available to staff when prompted respond quickly and mitigate risks. by highly visible cyber events or by regulatory alerts. The FMI should participate in efforts to identify the 24. 6. The FMI should incorporate lessons learned into the gaps in current information-sharing mechanisms and staff training, awareness programmes and materials, seek to address them, in order to facilitate a sec- on an ongoing and dynamic basis. The FMI should uti- tor-wide response to large-scale incidents. lise industry and authority initiatives related to aware- ness and training, where possible. 7. The FMI should set a range of indicators and develop 8 LEARNING AND EVOLVING management information to measure and monitor the effective implementation of the cyber resilience strat- 8.1 Preamble egy and framework on a regular basis and its evolution An FMI’s cyber resilience framework needs to achieve over time. For example, relevant information and indi- continuous cyber resilience amid a changing threat envi- cators could be: the percentage of the FMI’s staff that ronment. To be effective in keeping pace with the rapid have received cybersecurity training; the percentage of evolution of cyber threats, an FMI should implement an incidents reported within the required timeframe per adaptive cyber resilience framework that evolves with the applicable incident category; the percentage of vul- dynamic nature of cyber risks and allows the FMI to iden- nerabilities mitigated within a defined time period after tify, assess and manage security threats and vulnerabilities discovery; and yearly reports monitoring progress of for the purpose of implementing appropriate safeguards indicators, etc. into its systems. An FMI should aim to instil a culture of cyber risk awareness whereby its resilience posture, at every level, is regularly and frequently re-evaluated. 28 • FINANCIAL INCLUSION GLOBAL INITIATIVE ADVANCING 11. The FMI should incorporate lessons learned from real- 8. The FMI should validate the effectiveness of incorpo- life cyber events and/or from testing results on the FMI rating lessons learned into the employee training and and/or other organisations, to improve the its risk mit- awareness programmes on a regular basis. igation capabilities, as well as its cyber contingency, response, resumption and recovery plans. 9. An FMI should actively monitor technological devel- opments and keep abreast of new cyber risk manage- The FMI should continuously track its progress in 12. ment processes that could effectively counter existing developing its cyber resilience capabilities from a cur- and newly developed forms of cyber attack. An FMI rent state to a defined future state. A maturity model should consider acquiring such technology and know- can assist the FMI in documenting this progress. how to maintain its cyber resilience. INNOVATING The FMI should analyse and correlate findings from 10. 13. The FMI should have capabilities in place to use mul- audits, management information, incidents, near tiple sources of intelligence, correlated log analysis, misses, tests (e.g. vulnerability assessment, penetra- alerts, traffic flows, cyber events across other sec- tion testing and red team testing, etc.), exercises and tors and geopolitical events to better understand the external and internal intelligence in order to enhance evolving threat landscape and proactively take the and improve its cyber resilience capabilities. An inter- appropriate measures to improve its cyber resilience nal cross-disciplinary steering committee could drive capabilities. this activity. CYBER RESILIENCE FOR FINANCIAL MARKET INFRASTRUCTURES • 29 ANNEX 1 Cyber Resilience Questionnaire This questionnaire has been designed to identify the level of cyber resilience of Financial Market Infrastructures (FMIs) operated primarily by central banks or financial sector authorities follow- ing the Bank for International Settlements (BIS) Guidance on cyber resilience for financial market infrastructures, 2016 and the ECB’s Cyber Resilience Oversight Expectations (CROE) for FMIs. It is structured in 6 sections; (i) Strategy and Governance, (ii) Identification, (iii) Protection, (iv) Detec- tion, (v) Response and Recovery and (vi) Monitoring and Evaluation -including lessons learned. The objectives of each section of the questionnaire are listed below. • Strategy and Governance: Having a framework that captures the objectives and arrangements in place to ensure the safe and efficient operation of FMIs is necessary. Operational resilience of an FMI can be measured against their readiness to identify, protect, detect, respond and recover from a cyber threat. Building on the CPMI-IOSCO Principles for FMIs, in particular the following: (i) P2 on Governance, (ii) P3 on framework for risk management, (iii) P8 on settlement finality, (iv) P17 on operational risks and (v) P20 on FMI links, the following guiding questions could help identify better the level of cyber resilience of a given FMI. • Identification: It is important that FMIs identify critical business functions and information and technological assets that should be protected against compromise. An FMI as a networked ecosys- tem involves systems and processes that are interconnected with systems and processes of entities in the ecosystem (e.g. other infrastructures, vendors, system participants). • Protection: Effective security controls should protect the confidentiality, integrity and availability of assets and its services. Data should be protected both in transit and at rest. Protective measures should balance threat landscape, the risk tolerance of the FMI and the systemic role of the FMI in the financial system. Management response can either contain or escalate the problem therefore governance is a key pillar of a cyber security framework for FMIs. 30 • FINANCIAL INCLUSION GLOBAL INITIATIVE • Detection: Strong cyber resilience requires the ability of an FMI to detect anomalies (attempted infiltration, movement of an attacker, across systems, exploitation of vulnerabilities) unlawful or unauthorized access to data, data abuse) and events that indicate a potential cyber incident. This early warning allows FMIs to adopt countermeasures against a potential incident and pro- active containment of actual breaches. • Response and Recovery: FMIs to run smoothly must be able to settle obligations when they are due and at the minimum by the end of the value date. It is therefore important that critical oper- ations resume within 2 hours after a cyber incident resulted in disruption. Effective continuity plans are essential to meet this objective. The capacity of an FMI to return to normal operations and limit damage to the organization and its stakeholders continue after the incident. • Monitoring the Effectiveness of the Framework: FMIs should use tools such as testing, continu- ous situational awareness regarding the threat landscape as well as re-evaluating the adequacy of the framework to the evolving nature of the cyber threats to maintain adequate levels of cyber resilience preserving the safety and efficiency of the FMIs. The guiding questions and assessment tool can be found below. GUIDING QUESTIONS: STRATEGY AND GOVERNANCE 1.1 Is there a Strategy on Cybersecurity already developed and supported by a framework? 1.2 Does the framework include technology, policies, procedures and training and is documented? 1.3 Are international Standards considered when defining the framework and strategy? 1.4 The Board approves the Strategy? 1.5 The organization’s strategy is aligned with the National Strategy on Cyber Security? 1.6 Members of the Board understand key cybersecurity controls in place? 1.7 The Board includes one Director with clear understanding of information security and cybersecurity? 1.8 The Board reviews the Cybersecurity strategy on a yearly basis? 1.9 The Board reviews the Cybersecurity strategy whenever there is a change in the organization’s information technology? 1.10 The Board reviews the Cybersecurity strategy whenever there is a new threat? 1.11 Cybersecurity Policies include a Chief Information Security Officer (CISO)? 1.12 Cybersecurity Policies include a clear definition of objectives, roles and responsibilities of Board and Management? 1.13 CISO reports to the CEO and is independent from areas using the organization’s information technology assets? 1.14 Management and Staff are held accountable for complying with information security policies? 1.15 The organization’s ICT strategy includes outsourcing critical information technology services (e.g. storage, data processing, data analytics) ? 1.16 The organization’s Cybersecurity Strategy includes purchasing insurance against cyber incidents? 1.17 The Cybersecurity strategy includes data breach notification processes to stakeholders and authorities? 1.18 The strategy includes clear procedures (e.g. communication protocols, decision making processes) to make timely decisions in case of a cyber attack? 1.19 The organization has a specific budget covering cybersecurity related needs? 1.20 The Board discusses the cybersecurity resources needs (e.g. budget, technology and HHRR) once a year? 1.21 Is the Strategy communicated to all units within the organization? 1.22 Is collaboration with other FMIs and their stakeholders considered in the strategy? CYBER RESILIENCE FOR FINANCIAL MARKET INFRASTRUCTURES • 31 1.23 Are key elements of the Strategy being discussed with other FMIs and stakeholders? 1.24 Is the FMI part of a CERT or other arrangement with stakeholders ensuring cooperation in cyber security aspects?   GUIDING QUESTIONS: IDENTIFICATION 2.1 Is there an exhaustive asset inventory of all system accounts? 2.2 Does the inventory include all business functions, information and technologies? Does the inventory take into consideration the interdependencies of functions and business 2.2 processes? Are business functions classified according to its relevance for the efficient performance of the 2.3 FMI? 2.4 If yes, is the inventory updated on a regular basis? 2.5 Is there a simplified map of network resources, with associated IP addressing plan? Are risk assessments conducted prior to the deployment of new technologies to identify potential 2.6 vulnerabilities? Are risk assessments conducted prior to the deployment of new products to identify potential 2.7 vulnerabilities? Are risk assessments conducted prior to the deployment of new services to identify potential 2.8 vulnerabilities? 2.9 Are business processed dependent on third party service providers listed and documented? 2.10 Are access rights and credentials recorded and kept up to date? 2.11 Are other critical infrastructures identified (e.g. energy, telecommunications)? 2.12 Is there any coordination mechanism between the entities in the FMIs ecosystem?   GUIDING QUESTIONS: PROTECTION 3.1 Are security measures in place to protect software, networks and hardware against cyber incidents? 3.2 Are those measures documented and based on International Standards? 3.3 Is the network segmented into multiple trust zones allowing for segregation of data and systems? 3.4 Are system users access profiles clearly defined and documented? 3.5 Automated processes detect and block unauthorized changes to software and hardware? 3.6 There is defense-in-depth strategy (i.e. multiple independent security controls to provide redundancy) applied? 3.7 Has a bespoke information security management system (ISMS) based on international standards (ISO) has been developed? 3.8 There is a secure boundary that protects the network infrastructure using network perimeter tools (e.g. router, firewall, IPS, proxies, VPN, DMZ)? 3.9 There are mechanisms in place to limit and terminate system and remote sessions after a pre- defined period of inactivity? 3.10 There are controls that prevent non-controlled devices to connect to its internal network (e.g. personal devices, rogue access point) and endpoints (e.g. removable media) from inside and outside the premises? 3.11 Legacy technologies are regularly scanned (at least every month) to identify potential vulnerabili- ties and seek upgrade opportunities? 3.12 Are there policies and controls that prevent users from installing unauthorized applications in systems and devices? 3.13 Are Remote access controls based on multifactor authentication (e.g. password, smart card, finger print)? 32 • FINANCIAL INCLUSION GLOBAL INITIATIVE 3.14 Is there a dedicated password policy that specify password characteristics such as complexity, renewal period, and limits to password attempts? 3.15 Have appropriate controls (e.g. end-to-end encryption, authentication and access control) to protect data at rest, in use and in transit been developed? 3.16 Are there dedicated controls to prevent unauthorized access to cryptographic keys? 3.17 A change management process is in place to request and approve changes to system configura- tions, hardware, apps and security tools? 3.18 Is there a comprehensive patch management policy and processes? 3.19 Are there policies, procedures and controls established for granting, revoking, employee physical and logical access to its systems? 3.20 Are there processes and technologies to monitor privileged user’s activity and access to critical systems? 3.21 Is there training provided (at least once a year) to the entire staff to support information security policy compliance and incident reporting? 3.22 Does high risk staff (e.g. management, system administrators, software developers) receive dedicated security awareness training as relevant for their responsibilities? 3.23 Is there an inventory of participants and third-party service providers? 3.24 Are contractual arrangements between the FMI operator and third-party service providers in place? 3.25 Are contractual arrangements (service level agreements -SLA) between the FMI operator and third-party service providers in place? 3.26 SLAs include confidentiality provisions regarding data? 3.27 SLAs include accountability provisions regarding data (corruption, unauthorized access and loss), systems and networks failures related to the service provided? 3.28 Risks assessments are conducted to service providers before entering into contract with them? 3.29 Security measures allow the identification of anomalies that could result in data corruption, loss caused by legitimate users? 3.30 Do you have a cyber insurance policy?   GUIDING QUESTIONS: DETECTION 4.1 Has your organization defined, considered and documented the baseline profile of system activities to help detect deviation from the baseline? 4.2 Are criteria, parameters and triggers to enable alerts in place? 4.3 Are there multi-layered detection controls covering people, processes and technology which support quick attack detection and isolation of infected points? 4.4 Are detection capabilities informed by threat or vulnerability information (public and not yet publicly known) ? 4.5 Are there alert thresholds defined for monitoring and detection systems in order to trigger and facilitate the incident response process? 4.6 Are logs with incident information in place and stored safely? 4.7 Are tools in place to monitor access by service providers? 4.8 Is there a cyber threat intelligence program in place? 4.9 Current processes monitor activities which are not in line with the security policy? GUIDING QUESTIONS: RESPONSE AND RECOVERY 5.1 Do you have in place an Incident Response Plan (IRP) and a Security Incident Response Team (SIRT)? 5.2 Are systems and processes of critical functions are designed to limit the impact of cyber incidents? 5.3 Do systems and processes allow the identification of the source of the attack? CYBER RESILIENCE FOR FINANCIAL MARKET INFRASTRUCTURES • 33 5.4 Do policies, processes and procedures allow to contain the attack before it damages critical systems or business processes? 5.5 Are activity logs are maintained and available for future investigation? 5.6 Are procedures and policies are in place to facilitate a rapid investigation of cyber incidents? 5.7 Is the FMI able to determine the systems and data compromised after a cyber incident? 5.8 Does your Business continuity plan (BCP) and disaster recovery plan (DRP) take into consideration cyber-attacks? 5.9 Are penetration testing conducted frequently (at least once a year)? 5.10 Can systems and business processes be restored from a trusted back-up? 5.12 Is there an internal communication plan to address cybersecurity incidents that includes communication protocols for key internal stakeholders (e.g. relevant business units, senior management, risk management, board of directors, etc.)? 5.13 Is there an external communication plan to address cybersecurity incidents that includes communication protocols and draft pre-scripted communications for key external stakeholders (i.e. customers, media, critical service providers, etc.)? 5.14 Does your DRP have in place a change of all user credentials and access controls? 5.15 Do policies, procedures and systems allow the FMI to resume operations in 2 hours since the cyber incident? 5.16 Does the back-up system provide the same level of service to system participants than the primary site? 5.17 Do systems allow the quick recovery of data after a data breach ensuring data integrity? 5.18 Does the IRP include mechanisms to respond to requests from law enforcement agencies, consumers, partners, system participants and service providers? 5.19 The IRP designed involves the participation of the legal counsel, security and ICT and the Board? 5.20 The IRP designed includes mechanisms to analyze the damage and measure the loss exposure? 5.21 Laws and regulations allow the evidence (digital audit trail) to be presented in court? 5.22 Laws and regulations establish a specific timeline for data breach notification to authorities? 5.23 Laws and regulations establish a specific timeline for data breach notification to public at large? GUIDING QUESTIONS: MONITORING TOOLS 6.1 The FMI has a testing program in place? 6.2 The testing program is integrated in the risk management framework? 6.3 Tests are undertaken by independent parties (internal or external) ? 6.4 Weaknesses identified are classified and remedial actions prioritized? 6.5 Board and Senior Management incorporate the lessons learned into the cyber security strategy? 6.6 The testing program includes critical systems, applications and data and back-up solutions? 6.7 Tests are conducted at least once a year? 6.8 Vulnerability assessments take into consideration regulations, policy and configuration? 6.9 Tests performed are designed based on different scenarios (e.g. one of them including a potential financial loss)? 6.1 Penetration tests to external facing services and internal networks and systems are conducted once a year? 6.11 Ethical hacking is conducted to critical business processes, systems and networks? 6.12 A bug bounty program is in place? 6.13 FMI is part of a threat and vulnerability information sharing platform? 6.14 Information obtained is analyzed and made available to relevant staff? 34 • FINANCIAL INCLUSION GLOBAL INITIATIVE 6.15 Lessons learned are captured into the cyber security framework? 6.16 An information sharing policy is defined? 6.17 Does the information to be shared include?: (a) Attacker’s name (b) Indicators for compromise (c) Threats and vulnerabilities (d) Modus operandi 6.18 Does the information policy include?: (a) Circumstances to share information   Recipients of the information (e.g. system participants, vendors, authorities, interconnected (b)    FMIs) (c) Actions to be taken based on information received   CYBER RESILIENCE FOR FINANCIAL MARKET INFRASTRUCTURES • 35 ANNEX 2 Guidance on the Senior Executive 5 1. The FMI should appoint a senior executive, normally (e) Helping to produce and update the contingency a Chief Information Security Officer (CISO), who is plan with regard to cyber issues. responsible for all cyber resilience issues within the (f) Initiating and monitoring the implementation of FMI and with regard to third parties. The Senior Exec- cyber resilience measures. utive ensures that the cyber resilience objectives and (g) Participating in projects relevant to cyber resil- measures defined in the FMI’s cyber strategy, cyber ience (e.g. monitoring security testing for new resilience policies and guidelines are properly com- components before entering production). municated both internally and, when relevant, to third parties, and that compliance with them is reviewed, Acting as a point of contact for any questions (h) monitored and ensured. relating to cyber resilience coming from within the FMI or from third parties. 2. The Senior Executive or CISO carries out the following tasks, in particular. (i) Investigating cyber incidents and reporting them to the senior management and the Board. (a) Supporting senior management and the Board when defining and updating the cyber resilience (j) Continuously surveying threats applicable to IT policies, and advising on all cyber resilience issues. assets. This includes helping to resolve conflicting goals Initiating and coordinating measures to raise (k) (e.g. cost-efficiency vs. cyber resilience). awareness on cyber resilience and training ses- (b) Participating in cyber risk management. sions. (c) Producing cyber resilience guidelines and, where (l) Reporting to senior management and the Board appropriate, any other relevant rules, as well as regularly, at least quarterly, and on an ad hoc basis checking compliance. on the status of cyber resilience issues. This status report includes, for example, an evaluation of the (d) Influencing the FMI’s cyber resilience processes, cyber resilience situation compared with the last monitoring IT service providers’ involvement and report, information about cyber resilience projects, assisting in any related tasks. cyber incidents and the results of penetration and 5. Annexes from the ECB CROE red team tests. 36 • FINANCIAL INCLUSION GLOBAL INITIATIVE 3. In terms of organisation and processes, the Senior Exec- (b) determination of the necessary resources required utive or CISO must be independent so as to avoid any by the Senior Executive or CISO; potential conflicts of interest. Therefore, the following (c) designation of a budget for cyber resilience train- measures, in particular, are expected to be applied: ing sessions within the FMI and for further training (a) organisational set-up to ensure that the Senior of the Senior Executive or CISO personnel/team; Executive or CISO can act independently from the requirement for all employees in the FMI and IT (d) IT/operations department and be able to report to service providers to report any incidents relevant senior management and the Board directly and at to the cyber resilience of the FMI, according to the any time9 also ensuring that the Senior Executive escalation procedure. or CISO is not involved in internal audit activities; 4. The FMI should have its own senior executive or CISO in-house, depending on the FMI’s specific structure  e do observe organizational set-ups where the CISO has a functional 9. W and organisational set-up. To the extent permitted by reporting line to the CIO, but with guarantees for the CISO to have direct access to senior management and the Board directly and with the national authority and in cases of group entities, sufficient resources for the CISO to conduct its independent role. this could include a group-wide CISO. CYBER RESILIENCE FOR FINANCIAL MARKET INFRASTRUCTURES • 37 ANNEX 3 Glossary 6 The Glossary contains the definitions of the core terms used throughout the CROE. The terms have been largely adopted from the Guidance6 and the Financial Stability Board’s Cyber Lexicon.7 For more technical terms, users should refer to glossaries produced by the international standard setters in this field, such as the International Orga- nization for Standardization (ISO), ISACA (previously known as the Information Systems Audit and Control Associ- ation), the SANS Institute and the US National Institute of Standards and Technology. Access control Means to ensure that access to assets is authorised and restricted based on business and security requirements. Source: ISO/IEC 27000:2018/FSB Cyber Lexicon Advanced A threat actor that possesses sophisticated levels of expertise and significant resources which persistent threat allow it to create opportunities to achieve its objectives by using multiple threat vectors. The (APT) advanced persistent threat: (i) pursues its objectives repeatedly over an extended period of time; (ii) adapts to defenders’ efforts to resist it; and (iii) is determined to execute its objectives. Source: Adapted from NIST/FSB Cyber Lexicon Asset Something of either tangible or intangible value that is worth protecting, including people, information, infrastructure, finances and reputation. Source: ISACA Fundamentals/FSB Cyber Lexicon Authenticity/ Property that an entity is what it claims to be. authentication Source: ISO/IEC 27000:2018/FSB Cyber Lexicon Availability Property of being accessible and usable on demand by an authorised entity. Source: ISO/IEC 27000:2018/FSB Cyber Lexicon 6. Annexes from the ECB CROE 7. See CPMI-IOSCO (June 2016), “Guidance on cyber resilience for financial market infrastructures”. 8. See FSB (November 2018), “Cyber Lexicon” 38 • FINANCIAL INCLUSION GLOBAL INITIATIVE Business process A collection of linked activities that takes one or more kinds of input and creates an output that is of value to an FMI’s stakeholders. A business process may comprise several assets, including information, ICT resources, personnel, logistics and organisational structure, which contribute either directly or indirectly to the added value of the service. Source: CPMI-IOSCO Guidance Capabilities People, processes and technologies used to identify, mitigate and manage its cyber risks to support its objectives. Source: CROE Compromise Violation of the security of an information system. Source: Adapted from ISO 21188:2018/FSB Cyber Lexicon Confidentiality Property that information is neither made available nor disclosed to unauthorised individuals, entities, processes or systems. Source: Adapted from ISO/IEC 27000:2018/FSB Cyber Lexicon Configuration The activity of managing the configuration of an information system throughout its life cycle. management Source: ISO/IEC 10032:2003 Critical operations Any activity, function, process or service, the loss of which, for even a short period of time, would materially affect the continued operation of an FMI, its participants, the market it serves, and/or the broader financial system. Source: CPMI-IOSCO Guidance Cyber Relating to, within, or through the medium of the interconnected information infrastructure of interactions among persons, processes, data, and information systems. Source: Adapted from CPMI-IOSCO Guidance (citing NICCS)/FSB Cyber Lexicon Cyber attack The use of an exploit by an adversary to take advantage of a weakness(es) with the intention of achieving an adverse effect on the ICT environment. Source: CPMI-IOSCO Guidance Cyber event Any observable occurrence in an information system. Cyber events sometimes provide indication that a cyber incident is occurring. Source: Adapted from NIST (definition of “Event”)/FSB Cyber Lexicon Cyber governance Arrangements an organisation puts in place to establish, implement and review its approach to managing cyber risks. Source: CPMI-IOSCO Guidance Cyber incident A cyber event that: (i) jeopardises the cybersecurity of an information system or the information the system pro- cesses, stores or transmits; or (ii) violates the security policies, security procedures or acceptable use policies, whether resulting from malicious activity or not. Source: Adapted from NIST (definition of “Incident”)/FSB Cyber Lexicon Cyber incident The documentation of a predetermined set of instructions or procedures to respond to and response plan limit consequences of a cyber incident. Source: Adapted from NIST (definition of “Incident Response Plan”) and NICCS/FSB Cyber Lexicon Cyber resilience The ability of an organisation to continue to carry out its mission by anticipating and adapting to cyber threats and other relevant changes in the environment and by withstanding, containing and rapidly recovering from cyber incidents. Source: Adapted from CERT Glossary (definition of “Operational resilience”), CPMI-IOSCO Guidance and NIST (definition of “Resilience”)/FSB Cyber Lexicon Cyber resilience Consists of the policies, procedures and controls an FMI has established to identify, protect, framework detect, respond to and recover from the plausible sources of cyber risks it faces. Source: CPMI-IOSCO Guidance CYBER RESILIENCE FOR FINANCIAL MARKET INFRASTRUCTURES • 39 Cyber resilience An FMI’s high-level principles and medium-term plans to achieve its objective of managing strategy cyber risks. Source: CPMI-IOSCO Guidance Cyber risk The combination of the probability of cyber incidents occurring and their impact. Source: Adapted from CPMI-IOSCO Guidance, ISACA Fundamentals (definition of “Risk”) and ISACA Full Glossary (definition of “Risk”)/FSB Cyber Lexicon Cybersecurity Preservation of confidentiality, integrity and availability of information and/or information systems through the cyber medium. In addition, other properties, such as authenticity, accountability, non-repudiation and reliability can also be involved. Source: Adapted from ISO/IEC 27032:2012/FSB Cyber Lexicon Cyber threat A circumstance with the potential to exploit one or more vulnerabilities that adversely affects cybersecurity. Source: Adapted from CPMI-IOSCO Guidance/FSB Cyber Lexicon Data breach/ Compromise of security that leads to the accidental or unlawful destruction, loss, alteration, integrity unauthorised disclosure of, or access to data transmitted, stored or otherwise processed. Source: Adapted from ISO/IEC 27040:2015/FSB Cyber Lexicon Defence in depth Security strategy integrating people, processes and technology to establish a variety of barriers across multiple layers and dimensions of the organisation. Source: Adapted from NIST and FFIEC/FSB Cyber Lexicon Disruption An event affecting an organisation’s ability to perform its critical operations. Source: CPMI-IOSCO Guidance Ecosystem A system or group of interconnected elements, formed linkages and dependencies. For an FMI, this may include participants, linked FMIs, service providers, vendors and vendor products. Source: CPMI-IOSCO Guidance Exploit A defined way to breach the security of information systems through vulnerability. Source: ISO/IEC 27039:2015/FSB Cyber Lexicon Financial market A multilateral system among participating institutions, including the operator of the system, infrastructure (FMI) used for the purposes of clearing, settling or recording payments, securities, derivatives or other financial transactions. Source: CPMI-IOSCO Guidance Forensic The application of investigative and analytical techniques to gather and preserve evidence investigation from a digital device impacted by a cyber attack. Source: CPMI-IOSCO Guidance Forensic readiness The ability of an FMI to maximise the use of digital evidence to identify the nature of a cyber attack. Source: CPMI-IOSCO Guidance Identity and access Encapsulates people, processes and technology to identify and manage the data used in an management (IAM) information system to authenticate users and grant or deny access rights to data and system resources. Source: Adapted from ISACA Full Glossary/FSB Cyber Lexicon Incident response Team of appropriately skilled and trusted members of the organisation that handles incidents team (IRT) [also during their life cycle. known as CERT or Source: ISO/IEC 27035-1:2016/FSB Cyber Lexicon CSIRT] Indicators of Identifying signs that a cyber incident may have occurred or may be currently occurring. compromise (IoCs) Source: Adapted from NIST (definition of “Indicator”)/FSB Cyber Lexicon 40 • FINANCIAL INCLUSION GLOBAL INITIATIVE Information asset Any piece of data, device or other component of the environment that supports information- related activities. In the context of this document, information assets include data, hardware and software. Information assets are not limited to those that are owned by the entity. They also include those that are rented or leased, and those that are used by service providers to deliver their services. Source: CPMI-IOSCO Guidance Information sharing An exchange of data, information and/or knowledge that can be used to manage risks or respond to events. Source: Adapted from NICCS/FSB Cyber Lexicon Information system Set of applications, services, IT assets or other information-handling components, which includes the operating environment. Source: Adapted from ISO/IEC 27000:2018/FSB Cyber Lexicon Integrity Property of accuracy and completeness. Source: ISO/IEC 27000:2018/FSB Cyber Lexicon Malware Software designed with malicious intent containing features or capabilities that can potentially cause harm directly or indirectly to entities or their information systems. Source: Adapted from ISO/IEC 27032:2012/FSB Cyber Lexicon Maturity model A mechanism to have cyber resilience controls, methods and processes assessed according to management best practice, against a clear set of external benchmarks. Source: Adapted from CPMI-IOSCO Guidance Non-repudiation Ability to prove the occurrence of a claimed event or action and its originating entities. Source: ISO 27000:2018/FSB Cyber Lexicon Patch management The systematic notification, identification, deployment, installation and verification of operating system and application software code revisions. These revisions are known as patches, hot fixes and service packs. Source: NIST/FSB Cyber Lexicon Penetration testing A test methodology in which assessors, using all available documentation (e.g. system design, source code, manuals) and working under specific constraints, attempt to circumvent the security features of an information system. Source: NIST/FSB Cyber Lexicon Recovery point Point to which information used by an activity is to be restored to enable the activity to objective (RPO) operate on resumption. Source: Adapted from ISO 22300:2018 Recovery time Period of time following an incident within which a product or service or an activity is to be objective (RTO) resumed, or resources are to be recovered. Source: Adapted from ISO 22300:2018 Red team testing A controlled attempt to compromise the cyber resilience of an entity by simulating the tactics, techniques and procedures of real-life threat actors. It is based on targeted threat intelligence and focuses on an entity’s people, processes and technology, with minimal foreknowledge and impact on operations. Source: G-7 Fundamental Elements/FSB Cyber Lexicon Reliability Property of consistent intended behaviour and results. Source: ISO/IEC 27000:2018/FSB Cyber Lexicon Resilience by design The embedding of security in technology and system development from the earliest stages of conceptualisation and design. Source: CPMI-IOSCO Guidance CYBER RESILIENCE FOR FINANCIAL MARKET INFRASTRUCTURES • 41 Resumption To recommence functions following a cyber incident. An FMI should resume critical services as soon as it is safe and practicable to do so without causing unnecessary risk to the wider sector or further detriment to financial stability. Source: CPMI-IOSCO Guidance Security operations A function or service responsible for monitoring, detecting and isolating incidents. centre (SOC) Source: CPMI-IOSCO Guidance Situational The ability to identify, process and comprehend the critical elements of information through a awareness cyber threat intelligence process that provides a level of understanding that is relevant to act upon to mitigate the impact of a potentially harmful event. Source: CPMI-IOSCO Guidance/FSB Cyber Lexicon Social engineering A general term for trying to deceive people into revealing information or performing certain actions. Source: Adapted from FFIEC/FSB Cyber Lexicon Tactics, techniques The behaviour of a threat actor. A tactic is the highest-level description of this behaviour, and procedures while techniques give a more detailed description of behaviour in the context of a tactic, and (TTPs) procedures an even lower-level, highly detailed description in the context of a technique. Source: Adapted from NIST 800-150/FSB Cyber Lexicon Threat actor An individual, a group or an organisation believed to be operating with malicious intent. Source: Adapted from STIX/FSB Cyber Lexicon Threat intelligence Threat information that has been aggregated, transformed, analysed, interpreted or enriched to provide the necessary context for decision-making processes. Source: NIST 800-150/FSB Cyber Lexicon Threat vector A path or route used by the threat actor to gain access to the target. Source: Adapted from ISACA Fundamentals/FSB Cyber Lexicon Vulnerability A weakness, susceptibility or flaw of an asset or control that can be exploited by one or more threats. Source: Adapted from CPMI-IOSCO Guidance and ISO/IEC 27000:2018/FSB Cyber Lexicon Vulnerability Systematic examination of an information system and its controls and processes, to determine assessment the adequacy of security measures, identify security deficiencies, provide data from which to predict the effectiveness of proposed security measures and confirm the adequacy of such measures after implementation. Source: Adapted from NIST/FSB Cyber Lexicon 42 • FINANCIAL INCLUSION GLOBAL INITIATIVE