DFSA’s Thematic Review on Cyber Security Controls
DFSA’s Thematic Review on Cyber Security Controls
Last week, the DFSA published the 2nd edition of its Cyber Thematic Review Report, a document which summarised the improvements Firms have made since their first review concluded in 2020. The DFSA has been looking to improve cybersecurity awareness in the Dubai International Financial Centre (DIFC) by promoting the sharing of cyber threat information and supporting the continued development of cyber resilience within Firms in the DIFC. Overall, the DFSA has said they believe the latest results demonstrate that their efforts are paying off.
The Review identified that Firms did not improve their practices in three areas:
- Incident response testing programme
- Vulnerability Assessments and Penetration Testing
- IT asset identification and classification
For existing or more mature firms, it is a reminder that cyber is a risk that continues to evolve and there is a need to ensure businesses not only understand their cyber risk profile, but that they continue to invest in controls to protect their business and meet regulatory expectation.
- Incident response testing
- Ensure roles and responsibilities for the management of IT and cyber incidents is clearly defined, both in terms of their identification, management and closure
- Ensure all incidents are subject to thorough root cause analysis
- Consider possible trends that may emerge from seemingly small, innocuous events – use these to inform how IT improvements are prioritised
- Test response plans to an agreed schedule and based upon the likely scenarios that could impact the firm
- Vulnerability Assessments and Penetration Testing
- Use a wide range of assessment tools and processes, such as vulnerability assessments, scenario-based testing, penetration tests as well as formal exercises
- Consider the extent the firm has the appropriate skills -in-house to adequately identify and apply the right tooling based upon the firm’s risk profile
- Consider independent third party assurance to confirm the arrangements in place are fit-for-purpose
- IT asset identification and classification
- Review asset registers for completeness to ensure it captures areas such as applications, software, data, etc.
- Ensure the asset register is maintained to an agreed schedule given the risks to the firm
- Ensure the process used to classify assets is based on a recognised standard (e.g. ISO/IEC 19770-1:2017)
- Conduct a Business Impact Analysis (BIA) to determine their criticality of these assets, based upon the firm’s business processes
Whilst the DFSA does not require Firms to adhere to one cyber framework or standard, the regulator appreciates that there are many different standards and frameworks related to IT and cyber risk that Firms can benefit from. Some of the more commonly used frameworks/standards include:
- CPMI-IOSCO Guidance on cyber resilience for financial market infrastructures
- ISO/IEC 27000 set of standards
- NIST Cybersecurity Framework
- CIS Critical Security Controls for Effective Cyber Défense
- CSA Cloud Controls Matrix
At J. Awan & Partners, our cyber security and risk management teams are comprised of experts whose primary goal is to help you identify and manage cyber and other related risks.
Please contact us at [email protected] for any cyber security related needs.