Tuesday, June 11, 2013

Cybersecurity Rises to Top of List at FFIEC

 
Enterprise Risk Management CEO Advises Financial Institutions to Prepare Now

(Miami, June 11, 2013) Cybercrime and “hacking” have reached epidemic proportions, but it’s not clear who’s winning the cyber wars. While corporations are primarily targeted for intellectual property, banks, health care providers, and retailers face continual breaches of their databases, putting thousands of customers at risk for financial fraud and identity theft.


Enterprise Risk Management CEO Silka Gonzalez advises clients, and especially financial institutions, to prepare now for more rigorous examinations and to toughen their internal security. “It’s not enough today to just have a firewall and an anti-virus program,” Gonzalez explained. “You need to make sure that your employees are trained to protect your sensitive data and that access to that data is limited.” Employees have become the weakest link in the security chain.


Gonzalez recommends that all organizations, and especially banks, perform “social engineering” tests. This provides the institutions with a training opportunity, once they see how easily their employees are unintentionally “fooled” into providing sensitive data to outsiders. Most companies are surprised to find out how vulnerable they are internally.


The FFIEC (Federal Financial Institutions Executive Council), recognizing the growing sophistication and volume of cyber attacks and the global importance of critical financial infrastructure, announced the formation of a working group to coordinate efforts and improve communication on issues of critical infrastructure and cybersecurity. Participating in the working group will be the FFIEC’s Information Technology Subcommittee of the Task Force on [financial} Supervision, the Financial and Banking Information Infrastructure Committee, the Financial Services Sector Coordinating Council, and the Financial Services Information Sharing and Analysis Center.


“Given the unlimited resources of the organized criminal groups that perpetrate the vast majority of financial cybercrime,” Gonzalez emphasized,, “ a coordinated approach with strong communication among regulators and and financial institutions is critical.”

Monday, June 10, 2013

GRC-Daily: IT Secruity Lost in the Cloud

Enterprise Risk Management featured on GRC-Daily website


Excerpt from the article:

Florida Bar Joins Other States in Guiding Attorneys on Cloud Confidentiality

Businesses large and small have embraced the convenience of Cloud computing as a way to save money and improve efficiencies.   But what is the real cost of such “savings”?   According to Enterprise Risk Management CEO Silka Gonzalez, “Not all cloud computing services are created equal.” 
Silka Gonzalez
CEO
Enterprise Risk Management


Miami-based Enterprise Risk Management, an IT and security consulting firm has this advice,  “Know who you are working with and do your due diligence before you migrate your data to the Cloud.”   

“Larger Cloud providers should have the resources to provide strong IT security around the technology, right down to their own employees,” explained Gonzalez. “Smaller providers may not be able to offer the same level of comprehensive risk management.” In addition, most Cloud service provider agreements specify that the organization itself is still responsible for their own internal IT security.



 Read the full article here.

Friday, June 7, 2013

Test Thy BCP - Webinar

Date: Thursday, June 27, 2013
Time: 11:00 AM to 12:00 PM EDT
Industry: Banking & Finance, Education, Government & Public Services, Healthcare, Hospitality & Leisure, Legal, Manufacturing, Retailers & Wholesalers, Technology, Telecommunication
Topic: Test Thy BCP
Passcode: TBD
Presented by:  Jacques Lucas, CISA

CPE Credits: A certificate of completion will be provided upon request to those attendees that require the event to count for CPE credits.
Most organizations rely heavily on their information systems without contingency planning in the case of a disaster. Imagine an organization that never tests its business continuity plan (BCP). Is that organization ready to respond effectively and resume operations of mission critical services with minimal disruption?

With Hurricane Season closing in, take a moment to think about whether your organization is fully prepared to effectively deal with contingency situations (natural disasters such as hurricanes, tornadoes, floods, or others like extended power outages and failures) with minimal impact to operations. And if you're part of the Senior Management at your organization, what role do you need to play to ensure this?

Join ERM for this webinar on testing your organization’s BCP where we will cover the importance of testing your BCP, testing standards, and reporting test results.

 You can register here.

Test Thy BCP

Most organizations rely heavily on their information systems without contingency planning in the case of a disaster.  Imagine an organization that never tests its business continuity plan (BCP). Is that organization ready to respond effectively and resume operations of mission critical services with minimal disruption?

The objective of the BCP is to provide the information and procedures necessary to respond to a disaster, notify necessary personnel, assemble business recovery teams, recover data, and resume operations to ensure minimal disruption to the company’s operations.

The BCP identifies the information, material, facilities, personnel and procedures required to facilitate a rapid recovery from a disaster.  The successful recovery of operations depends on performing a periodic comprehensive test of the BCP.  Therefore testing your BCP is an integral component of a successful recovery of operations, if disaster strikes.

The BCP should include documented and tested procedures which will assist in ensuring the availability of critical resources and in maintaining the continuity of operations during an emergency situation.  The BCP should aid in ensuring organizational stability through an orderly recovery process in the event of significant problems and disruptions.  The plan should not be intended to be a procedures manual of how to perform all departmental functions; it should include only those high priority tasks required to ensure successful recovery from a business disruption.


Testing The BCP
Every component of the BCP should be tested annually.  Critical and/or highly volatile components should be tested at least quarterly and after any major technology change.  Call trees should be tested at least semi-annually, and any component which fails the test should be re-tested as soon as possible.  The tests to be performed should address important business processes and related systems classified as highly critical. Management should consider additional non-highly critical processes and systems to be included on future tests as previous tests of highly critical processes are successfully tested.  Under no circumstances should the testing of highly critical processes be limited or excluded.  The following considerations should be evaluated during the planning, coordination, and execution of business recovery tests.
  • Management formal approval of the costs associated with the tests, normal business deadlines, resource requirements (human, material, equipment), and impact on daily operations due to key personnel participating on tests.
  • Definition of recovery scenarios (e.g. partial or full destruction due to natural and man-made disruptions, date and time of simulated event, affected business processes, etc).
  • Definition of test objectives, scope, expected results as well as the criteria to be used to consider the results of the test as successful. The objectives must have measurable goals such as maximum time to recover, time limit to recover, amount of items completed or failed procedures to determine the effectiveness and successfulness of the tests.
  • Documentation of the test objectives, scope, expected results, and test results.
The main reasons for testing the BCP include:
  • Determining the feasibility of the business recovery process.
  • Verifying the compatibility of alternate processing sites, hardware, software, and telecommunications.
  • Identifying deficiencies in existing procedures.
  • Identifying areas in the BCP that need modification or enhancement.
  • Providing training to the Team Managers and Team Members.
  • Ensuring the adequacy of procedures relating to the various teams involved in the recovery process.
  • Demonstrating the ability of the organization to recover within a reasonable time.
  • Providing a mechanism for maintaining and updating the BCP.

Standards For Testing The BCP
An annual test of the BCP is required. Segments of this test process can be staged throughout the year to minimize disruption and yet facilitate testing of the BCP. Depending on your testing methodology and organizational strategic plans, your organization can leverage the following types of tests to ensure the effectiveness of the BCP:
  • Process Review TestingA third party evaluates whether all critical processes for services are addressed.
  • Checklist – Copies of the plan are sent to department and business unit managers to verify and review BCP procedures corresponding to their functional area. This is a simple test and should be used in conjunction with other tests.
  • Structured Walk-through – Team members and other individuals responsible for recovery meet and walk through the plan step-by-step to identify errors or assumptions.
  • Simulation – This is a simulation of an actual emergency. Members of the response team act in the same way as if there was a real emergency.
  • Parallel – This is similar to simulation testing, but the primary site is uninterrupted and critical systems are run in parallel at the alternative and primary sites.
  • Full interruption – This test involves all areas of the company in a response to an emergency. It mimics a real disaster where all steps are performed to test the plan. Systems are shut down at the primary site and all individuals who would be involved in a real emergency, including internal and external organizations, participate in the test. This test is the most detailed, time-consuming, and expensive test.

Testing Report
For item reviews, equipment, and procedures testing, a checklist will work well to illustrate what was tested and the results. The checklist should be prepared in advance. Sampling techniques can be used to review telephone numbers per critical call list, addresses of individuals, vendors, equipment, employee information, and forms.

Test Results
Test results should be reviewed and approved by Management. Tests will be analyzed on the basis of the following criteria:
  • Actual time to complete BCP recovery procedures and steps versus projected time.
  • Elapsed time to perform each activity in a recovery mode.
  • Analysis of the accuracy of each activity and event in the recovery effort.
  • Amount of work completed.
The test should be rated:
  • Satisfactory. Minimal disruption or problems noted; any exceptions would be easily overcome during a real disaster recovery situation.
  • Partially Satisfactory. In these instances, while certain aspects of the test may have been performed satisfactorily, the following situations would result in this rating: too many minor errors were noted; confusion in the process of recovery occurred during the test; slow recovery time; breakdowns in communications; the need for focused improvement.
  • Unacceptable. Significant problems occurred and the institution is at risk.  This rating reflects some aspect of resumption that did not test well, which in turn may produce problem situations in accomplishing orderly business resumption.
Senior Management should review the test results and note areas for enhancement to the BCP and Recovery Procedures. A plan and record of testing should be maintained by the BCP Coordinator to ensure that each relevant area of the BCP and Recovery Procedures are tested at least annually.

Trying Times
In trying times such as the ones we are experiencing today, an organization’s ability to get back on its feet quickly and efficiently when disaster strikes is critical to both customer retention and business reputation.  It could mean the difference between success and failure.  Test Thy BCP!