Are you ready to Attest to the 12/31/21 Federal Reserve Bank’s Security Standard?

In this article, we discuss the New FedLine Standard. Starting December 31st, 2021, all institutions that use FedLine Advantage or FedLine Web are required to annually self-certify that their organization meets the Federal Reserve Bank’s security Standards. Depending on the environment and tools used, institutions may have to certify to over 50 controls. As with most modern security frameworks, the self-assessment is risk-based. However, at the discretion of the Federal Reserve Bank, independent validation by third parties or internal audit functions may be required. The requirements for the assurance program are outlined in the Federal Reserve Operating Circular No. 5. The program is focused on reducing the risk of fraudulent payments being sent through the systems. The scope of the program could extend not only to institutions but to potential service providers as well. The Federal Reserve Bank has followed in the footsteps of the SWIFT (Society for Worldwide Interbank Financial Telecommunication) CSCF and has announced the development and implementation of a Security & Resiliency Assurance Program (“Assurance Program”). The assurance program is a collection of controls that stem from both the FedLine Advantage Security and Control Procedures and the FedLine Web Security and Control Procedures. Institutions can access these documents via the EUAC Center in FedLine Home. The self-assessment consists of the following steps: Click here for an overview of how to self-certify to the FedLine Solutions Security and Resiliency Assurance Program. Need help in determining your institution’s scope and assessment of compliance with the Assurance Program? We Can Help! Our teams of IT Security and IT Compliance advisors can work with you to assess your internal environment, determine the scope of controls applicable to your institution, based on your risks, and perform a comprehensive review and validation of your controls’ in accordance with the Fedline SRAP guidelines. Call us for more information to get your organization started on the way to compliance with the Federal Reserve Banks.
PCI DSS v4.0 Update – Major Security Changes to the Payment Industry

Rapid changes in how payments are made, seemingly constant technology upgrades, and the relentless pursuit of providing secure transactions are all driving the PCI DSS v4.0. Originally scheduled for release in Q2 of 2021, the PCI Security Standards Council (SSC) has recently revised the PCI DSS v4.0 publication date to Q1 2022. After three rounds of Request for Comments (RFC) and reviewing thousands of comments, we can expect a massive impact on the standard. Given the significance of this revision, a preview of the draft standard will be provided to Participating Organizations, QSAs, and ASVs sometime in January 2022. While those involved in the review are not allowed to disclose the details, we do know that security is at the forefront. The primary drivers are: Meeting the payment industry’s security needs Providing flexibility and scalability to support evolving methodologies Making security a continuous process Enhancing security control validation methods While we don’t have specifics on the changes, we have been reassured that the 12 core PCI DSS requirements will fundamentally remain the same. Under similar standards, the requirements statements will be more “outcome-based”, the control objectives will be clear, and the guidance column will be enhanced. What do the primary drivers mean? Meeting the payment industry’s security needs – With new technologies like cloud computing and an increase in outsourcing of services, PCI will release additional guidance with cloud and third-party considerations, which will require companies to rethink and validate their own scope and approach. Ever-changing cyber risks will require additional protection of cardholder data (while at rest and in motion), additional anti-phishing and social engineering, more robust risk assessments, and stricter recommendations for authentication like multi-factor, yet adaptable to the various authentication options. Finally, the Council has mentioned that when applicable, cloud technology will be considered in the new standard. Appendix A1 where guidance for the providers of shared hosting technology will also be considered. Providing flexibility and scalability to support evolving methodologies – Historically, secure companies had difficulty meeting defined or fixed requirements and often had to find compensating controls. These instances will be reduced by providing a customized approach. This includes tailored requirements and testing procedures. As an example, companies may secure networks differently, under a plethora of solutions, settings, and controls. The customized approach will enable companies to demonstrate how the risks and objectives are met, regardless of the solutions, settings, or controls in place. Making security a continuous process – The goal of the PCI DSS requirements has always been to design a secure and sustainable environment, following best practices. While some companies adopted this mindset, others are just focused on passing. We expect the new guidance to reinforce security as part of the business-as-usual, by requiring larger sample sizes, larger periods of coverage, or increased frequency of testing. Enhancing security control validation methods – Based on the customized approach within the methodology, PCI will align the validation methods. It seems straightforward, but the switch from assessing compensating controls (in the absence of standard requirements) to customized controls may require targeted risk assessments and testing procedures, developed by the QSA, and agreed upon by the business. It’s unclear how, but we can expect consistency in the SAQ and the AOC, in alignment with the methodology updates. Customization may be more suited for companies with secure and mature environments. Revised PCI DSS v4.0 Development and Transition Timeline When PCI DSS v4.0 is first released, v3.2.1 will remain active for an 18-month grace period, to allow for companies to gradually become compliant with baseline or immediate requirements. Additional requirements will be introduced under a phased approach, with dates in the future. “Future-dated” requirements are deemed to be “best practices” until the final date is reached. What this means to companies is that best practices should be assessed, but not fully implemented until the final date. While don’t know the exact date of transition from “best practices” to required implementation for each of the new requirements, the timeline is expected to be between 2½ – 3 years after the transition period has expired. While organizations have plenty of time to implement the various phases of PCI DSS v4.0, a roadmap should be in place sooner rather than later. Embrace the change and stay tuned for updates on evolving requirements and process improvements.
Major Update – ISO/IEC 27002:2022 Published

In this article, we look at the ISO 27002 Major Update. A Brief History of ISO (ISO 27002 Major Update) The origins of the ISO 27001/2 standard go back more than 20 years stemming from the British Standard BS 7799 Part 1 and 2, first published in the late 1990s. In 2000, ISO adopted the ISO 17799 standard and then renumbered it to the current standard reference: ISO 27001/27002. In late 2013, the current standard ISO27001:2013 was published. While the name has changed a few times, the structure of this internationally revered set of control standards has remained intact until now: DIS 27002. Why is ISO Important? The rise in cyber-threats and the increased need for information security places emphasis on organizations concentrating efforts on protecting sensitive data by implementing the security standards provided by the International Organization for Standardization or specifically, ISO 27001/27002. ISO 27001 is a favored standard in establishing an Information Security Management Systems (ISMS), used in maintaining and managing technical, physical, and lawful controls. With over two decades as an established and predictable security control framework, the ISO 27001/27002 is finally getting a facelift. What are the Changes? Reorganization: The ISO 27002 major update will be a reorganization of the existing framework controls. The recognizable 14 control domain structure is no longer in use. This structure will be replaced by 4 chapters serving as the base for all framework controls. Each framework control will be classified as one of the following: organizational, people, technological, and physical. The recognizable 14 control domain structure is no longer in use. Control Reduction: Through a combination of consolidation and enhancement, the original total of 115 Annex A control has been reduced to 93. Many of the remaining controls have been revised, and the new protocol includes an introduction of 11 brand-new controls and one control was removed. Control Attributes: Each control will have 5 characteristics that will provide the ability to have alternate refined views, depending on the medium being utilized: a database, spreadsheet, or application. Do I Need to Update My ISMS? Not yet. The ISO 27002 major update is just a Code of Practice. This means you cannot certify against it. However, it is also expected that the ISO 27001:2013 will be updated shortly after. What You Need to Do Now: Now is the time to take notice of this action and have conversations on how these changes will impact your ISMS. While imminent changes are not going to be necessary – this year, it is important to look ahead and be prepared, as this might affect your company during your next re-certification time. The earliest that an organization would need to adopt and adhere to the updated framework would be one year after the new ISO 27001 code of practice has been approved and released, which is likely to occur towards the end of 2021/early 2022. The expectation is that the updated ISMS framework integration would coincide with the organization’s recertification date. There are significant alterations in the structure of the DRAFT DIS 27002, which will, in turn, impact the organization’s infrastructure, processes, and maintenance within the ISMS. Therefore, the earlier businesses can begin to analyze their existing ISMS protocol and compare this to the proposed changes in the ISMS, the smoother the transition when the time comes for recertification. For detailed information on how this change could impact your ISMS, Contact Your ISO Expert. Details on the Control Changes 4 New Control Chapters containing 93 controls: Chapter 5 Organization (37 controls) Chapter 6 People (8 controls) Chapter 7 Physical (14 controls) Chapter 8 Technological (34 controls) 5 Control Attributes: Control Type (preventive, detective, corrective) Information Security Properties (confidentiality, integrity, availability) NIST Cyber Security Concept (identify, protect, detect, respond, recover) Operational Capabilities (governance, asset management, physical security – 15 in total) Security Domains (governance and ecosystem, protection, defense, and/or resilience) 11 New Controls Added: Threat intelligence Information security for use of cloud services Information and communication technology (ICT) readiness for business continuity Physical security monitoring Configuration management Information deletion Data masking Data leakage prevention Monitoring activities Web filtering Secure coding 1 Control Removed: Removal of assets Various controls relating to the following 22 topics have been combined to reduce redundancy: Policies for information security Information security in project management User endpoint devices Inventory of information and other associated assets Acceptable use of information and other associated assets Information transfer Storage media Access control Authentication information Access rights Monitoring, review, and change management of supplier services Information security during disruption Identification of legal, statutory, regulatory, and contractual requirements Compliance with policies and standards for information security Information security event reporting Management of technical vulnerabilities Logging Installation of software on operational systems Application security requirements Security testing in development and acceptance Separation of development, test, and production environments Change management
Are You Ready for the 5-Tiered CMMC Framework this Fall?

Since November 30, 2020, the interim rule issued by the DoD initiated a 5-year phased rollout, introducing the new CMMC Framework Requirement in government RFPs, which builds upon the previous standard NIST 800-27001 by adding additional security controls. Matthew Travis, the freshly-minted CEO of the CMMC Accreditation Body, declared in April’s Town Hall that the 5-tiered CMMC Framework is ready for rollout. Starting last winter, the DoD began stating the required CMMC level in the RFP with 15 contracts expected to see the change by the end of FY2021. All DoD contractors and subcontractors will need to be certified to bid on DoD requests for proposals. Keep in mind, that self-assessment is no longer allowed. Contractors must receive independent assessments from a qualified 3rd party assessor, or a C3PAO. Applications to become a C3PAO – an entity licensed to perform CMMC Assessments – are being received steadily with hopes to have a fully operational certification program by the latter part of 2021. It is estimated that approximately 60% of all awarded contracts currently require the lowest CMMC Level 1 certification, which is considered “basic cyber hygiene” in contracts containing Federal Contract Information (FCI). Contractors who specifically create or access Controlled Unclassified Information (CUI), must qualify at the CMMC Level 3 which is considered “good cyber hygiene”. Contractors having to comply at the highest level, CMMC Level 5 requirement, is far less likely. The main focus of the advanced or progressive level is to protect CUI from Advanced Persistent Threats (APTs). The CMMC certification is not optional. The program is designed to force companies doing business with the US Government to comply with a standard baseline of cybersecurity controls. To prepare for a 3rd party CMMC assessment, you should ensure your company has a documented System Security Plan and Plan of Action in place. We recommend our four-phased approach for CMMC certification: This is where Elevate can help! We can do the legwork for you. Elevate is already familiar with all tiers of the CMMC, and can assist in evaluating your company’s current System Security Plan (SSP) and Plan of Action and Milestones (POA&M), advise on areas that need improvement, and provide a plan of action to achieve CMMC readiness. Click here to learn more about our CMMC Readiness services.
The Skinny on your SWIFT CSCF v2021 Independent Assessment

Every year since, SWIFT has been building on its Customer Security Controls Framework (CSCF), continuously fighting against existing and emerging cyber threats. But the fight is not over. From self-attestation to organizing your independent assessment, here’s the skinny on what you need to keep your systems safe and in compliance for 2021. What you need to look out for in v2021 The impacts of the CSCF v2021 are among some of the largest affecting technology systems in the banking and financial services industry, so it is essential to begin your assessment now. The CSCF v2021 is now composed of a maximum of twenty-two mandatory (22) and nine (9) advisory controls, depending on your architectural type. Not to mention, self-assessment will no longer suffice. By December 31, 2021, all SWIFT institutions must have an independent assessment to support their self-assessed compliance with SWIFT CSCF v2021. Highlights of changes in CSCF v2021 include: Independent assessments may be performed by internal or external resources or some combination of both. The assessment should include a review of existing controls and their efficiency, and a confirmation that they support the customer’s compliance with the CSP control objectives. The requirement is for an assessment, not an audit, so ensure your independent assessor is not charging you excessive audit fees. Contact Us for a reasonable quote on an independent assessment fee or find us on the SWIFT directory of CSP assessment providers. The three controls promoted to mandatory aim to protect and reduce potential vulnerabilities on critical interface components as well as critical systems where virtualization is being used more frequently. Next Steps to SWIFT CSCF v2021 Requirements The upcoming SWIFT Release’s requirements act as a catalyst for documenting the weaknesses in the structure and standards that underpin many IT systems. Often the more extensive the organization and the longer its IT history, the bigger challenges they face when updating its IT systems. As a result, organizations should take an approach that requires collaboration and strong leadership across the organization and a constant focus on improving cybersecurity controls to meet new requirements. A few considerations for the next steps are: How Can We Help? Elevate is listed as a CSP Assessment Provider in SWIFT’s official directory. We use our collective experience and in-depth knowledge of the CSCF to evaluate the risks associated with the SWIFT controls. Our team will work with you to perform a gap analysis of your SWIFT-related environment and provide a view of your controls’ current and desired state. The gap analysis can include testing controls to advise on their effectiveness and help you get ready for attestation. We will help your organization navigate the factors associated with implementing CSCF to become compliant. What is SWIFT The SWIFT system manages almost every international money and security transfer in the world. The SWIFT system is a vast messaging network used by banks and other financial institutions to quickly, accurately, and securely send and receive money transfer-related information. The system processes over 33 million transactions per day through its network. SWIFT is a member-owned cooperative that provides safe and secure financial transactions for its members. SWIFT membership consists of more than 11,000 institutions in over 200 countries. Almost all forms of financial institutions from banks, to security dealers, to asset management companies, etc., are in some way using one or more SWIFT services.
Why You Should Care About NIST SP 800-53 Rev.5

In 2017, the National Institute for Standards and Technology (NIST) released an initial draft of the NIST SP 800-53 Rev. 5. Security and Privacy Controls for Information Systems and Organizations. Three years later, on September 23, 2020, the NIST finally published revision number 5. Both the public and private sectors rely on NIST guidance to provide a standardized approach to security assessment, authorization, and continuous monitoring for cloud products/services. Specifically, this framework is key to achieving several certifications including FedRAMP, FISMA, CMMC, CMS EDE, and DE Pathway audits. It’s only a matter of time before all IT security and privacy compliance/certifications will incorporate this new guidance (e.g. HITRUST, GDPR, CCPA, etc.). To set the tone, this revision (NIST SP 800-53 Rev. 5) is long overdue, as the last major update was over seven years ago in 2013. In fact, revision 5 should be renamed “The Renovation”, as both structural issues and technical content have been addressed within. The update represents a first-in-kind comprehensive catalog of privacy and security controls that is scalable to address organizations of all sizes and is as far-reaching to cover systems ranging from supercomputers to Internet of Things (IoT) devices. The controls are systematic in nature to ensure that critical systems, components, and services are not only secured but have the resilience to defend not only the United States’ interest in both economic and national security threats but all enterprises in all industries. The following highlights the most significant changes to the framework: Controls are outcome-based (as opposed to impact-based): For those not familiar with revision 4, this may seem like wordsmithing. However, this change is by far the most impactful. The control statement is now removed from the entity responsible for satisfying the control (e.g., people, process, system) – thereby allowing the outcome of the control (i.e., ability to protect/secure) to demonstrate effectiveness. This is great news for organizations that struggle with privacy compliance (e.g. GDPR or CCPA). Typically, the regulation around those laws serves more as guidance, leaving a lot of ambiguity for individual organizations to interpret their control effectiveness. NIST 800-53 Rev. 5 provides substantially increased clarity around privacy controls. For continuity purposes, Appendix C, Control Summaries provides a map between the new guidance and revision 4 by adding the “implemented by [entity]” column. Integration of privacy controls with security controls: Privacy takes a starring role in revision 5, with the intent of integrating privacy considerations into the system design and implementation process. Whereas revision 4 contained a separate appendix for privacy controls, revision 5 integrates privacy control families into existing security controls, as well as newly-created joint security and privacy controls. The unified consolidated control catalog allows controls to serve security and privacy risks from both an assurance and functional perspective. Basically, the control catalog is more dynamic with the intent to reflect a holistic outcome of a single control that serves multiple purposes. The control catalog also provides a summary and mapping tables. Increase of controls in Program Management: The Program Management (PM) control family includes 16 new controls – almost doubled from revision 4. This increase is primarily driven by the promotion of developing privacy programs to incorporate new privacy controls. Integrating supply chain risk management: A new Supply Chain Risk Management (SR) control family has been added. Also, elements of supply chain risk management have been integrated with cybersecurity approaches. This change impacts the Cybersecurity Framework and throughout all other control families to protect the procurement of system components, products, and services that support critical infrastructure and networks. The separation between the control selection process and the controls: the consolidated control catalog allows controls to be used on a stand-alone basis by different “communities of interest” (e.g. system engineers, security architects, enterprise architects, software developers, business owners, etc.). The intention is to allow collaboration among various stakeholders where process intersects and select from a unified control catalog to consistently manage risk throughout the organization. Created a comprehensive set of security and privacy control baselines: Control baselines have been carved out into a separate document: NIST SP 800-53B, Control Baselines for Information Systems and Organizations. There are three security control baselines for low, moderate, and high impact. The privacy baseline is applied irrespective of the level of impact. Also, the guidance provides working assumptions to assist organizations with the control selection process. Finally, the guidance is designed to be scalable across various “communities of interest”, technologies, and various operating environments to promote widespread adoption. Enhanced content relationship descriptions: The description between requirements and controls as well as the difference between security and privacy controls have been enhanced to provide further clarification. The emphasis is on guiding the user on selecting versus implementing controls at the enterprise level or as part of the system development life-cycle. Incorporating new state-of-the-practice controls: To address the rapidly evolving cyber threats, new safeguards and countermeasures are added with a specific focus on protecting individuals’ privacy and personally identifiable information (PII). The new privacy controls focus on the latest threat intelligence and cyber-attack data (e.g., controls to support cyber resiliency, secure systems design, security and privacy governance, and accountability). Assigning senior IT management to the entire control family: The intent of this mandate is to assign accountability and ownership to each control and specifically to the control outcome. However, in practice, especially in project-based organizations, assigning one individual to own control that impacts multiple disciplines, products and projects may not be feasible. Expanding the definition of “systems”: To be more comprehensive of all privacy and security threats, the term “systems” was expanded from information systems to all systems including industrial or process control systems, cyber-physical systems, weapons systems, and the internet of things (IoT) devices. Removal of the word “Federal” from the title for broader adoption of the private sector: In efforts to promote widespread adoption by both the public and private sector, the word “Federal” has been removed from the title. While only federal systems require the NIST framework, the intent is to promote broader adoption by the private sector. Click here to get updates on additional supplemental NIST materials that will also be available soon, including: