On May 31, the FFIEC released an update to its Cybersecurity Assessment Tool (CAT). The official press release can be found here: https://www.ffiec.gov/press/pr053117.htm
While there were no changes to the questions of the Inherent Risk Profile Input or the declarative statements of the Cybersecurity Maturity Input, there were other changes worth noting:
- The most significant is that the additional answer of “Yes with Compensating Controls” has been added to the possible selections for declarative statements on the Cybersecurity Maturity Input. FFIEC defines a compensating control as “A management, operational, and/or technical control (e.g., safeguard or countermeasure employed by an organization in lieu of a recommended security control in the low, moderate, or high baselines that provides equivalent or comparable protection for an information system.)”In practice, this update will allow financial institutions to achieve higher maturity levels regardless of size and complexity. Previously, a declarative statement at even an “innovative” level may have been financially or operationally unobtainable or unpractical given the resources at the institution. With the addition of a new “Yes with Compensating Controls” answer, financial institutions will be able to more accurately assess their maturity level without being restricted by the black and white nature of the declarative statements.
- Also in the Cybersecurity Maturity Input, the mapping of declarative statements has also been updated to reflect the previous update of the FFIEC’s its Information Security Handbook from September 2016.
What you should do now:
Review your current CAT and specifically examine the declarative statements that you have answered “No” to. Is there a compensating control that would allow you to answer that question differently now?
The updated CAT and associated documents can be found here:
Related articles
The NSA Cybersecurity Guide for Remote Workers
In this blog post, we cover a few key recommendations for remote workers from the NSA guide, ‘Best Practices for Securing Your Home Network.’
GraVoc Recognized on CRN’s 2023 MSP 500 List
CRN®, a brand of The Channel Company, has named GraVoc to its Managed Service Provider (MSP) 500 list in the Pioneer 250 category for 2023!
The Cybersecurity Implications of ChatGPT
Is ChatGPT a security risk? In this blog post, we explore the cybersecurity implications of ChatGPT, including the benefits and challenges.