Learning Objectives:
-
Understand the end-to-end ICT risk management lifecycle.
-
Apply ICT risk identification techniques to central bank operations.
-
Conduct ICT risk assessments using established methodologies.
-
Develop and implement risk treatment strategies.
2.1 ICT Risk Identification
Risk identification is the first step in the ICT risk management lifecycle. Financial entities must identify threats to their information assets, vulnerabilities that can be exploited by threats, existing controls, and the potential consequences in different scenarios if threats exploit the identified vulnerabilities .
Key Elements of ICT Risk Identification:
Threat Identification: Financial entities should identify threats to their information assets . Threats can include cyberattacks, natural disasters, system failures, human error, and insider threats. The SEACEN course notes that cyber threats have become more sophisticated and borderless, fuelled by increased digitisation, third-party dependencies, and geopolitical tensions .
Vulnerability Identification: Financial entities should identify vulnerabilities that can be exploited by threats . Vulnerabilities can include technical weaknesses (software flaws, misconfigurations), process weaknesses (inadequate controls, lack of segregation of duties), and human weaknesses (lack of awareness, poor training).
Control Identification: Financial entities should identify existing controls . This includes preventive controls (firewalls, access controls), detective controls (monitoring, logging), and corrective controls (incident response, backup and recovery).
Consequence Analysis: Financial entities should identify the potential consequences in different scenarios if threats exploit the identified vulnerabilities . When identifying potential consequences, the financial institution should consider financial, operational, legal, reputational, and regulatory factors .
2.2 ICT Risk Assessment
Risk assessment involves evaluating the likelihood and impact of identified risks. Financial entities should assess the likelihood of threats exploiting identified vulnerabilities and the magnitude of the consequences if threats exploit the identified vulnerabilities . A risk level metric should be assigned to each risk based on these assessments .
The EBA’s Guidelines on ICT and security risk management provide detailed requirements for risk assessment, including that financial entities must perform risk assessments upon each ‘major change’ in the network and information system infrastructure .
The Regulation on Information Systems and Cyber Risk Management requires that, at least once a year or in the event of any significant changes to the ICT security requirements, financial institutions shall conduct a risk analysis of the ICT systems to ensure that this risk is kept within the tolerance limits in relation to the institution’s activity .
Risk Categories:
The ECB’s SREP methodology identifies four ICT risk level modules:
-
ICT Security Risk: The extent to which the institution is exposed to ICT security risk .
-
ICT Availability and Continuity Risk: The extent to which the institution is exposed to ICT availability and continuity risk .
-
ICT Change Risk: The extent to which the institution is exposed to ICT change risk .
-
ICT Data Integrity Risk: The extent to which the institution is exposed to ICT data integrity risk .
2.3 ICT Risk Treatment
Risk treatment involves developing and implementing risk mitigation measures consistent with the criticality of information assets and the accepted level of risk tolerance . Financial institutions should assess whether the risks have been reduced to an acceptable level after the implementation of the mitigating measures .
Risk Treatment Options:
-
Risk reduction through controls
-
Risk acceptance based on documented risk tolerance
-
Risk avoidance by ceasing the activity
-
Risk transfer through insurance or outsourcing
The Regulation on Information Systems and Cyber Risk Management requires that the criteria and approval authorities for accepting the residual risk should be clearly defined and should be consistent with the financial institution’s risk tolerance . Where possible, financial institutions should consider insurance coverage for various insurable technologies to mitigate financial impacts, such as recovery and compensation costs .
2.4 Risk Monitoring, Review, and Reporting
Risk monitoring involves continuous assessment and monitoring of changes in risk. The Regulation on Information Systems and Cyber Risk Management establishes that a process for assessing and monitoring changes in risk should be established . Significant risks should be closely monitored and reported to the Board and senior management .
Technology Risk Metrics: To facilitate risk reporting to management, technology risk metrics should be developed to highlight information assets with the highest risk exposure . These metrics should take into account risk events, audit findings, and relevant regulatory requirements .
Documentation Requirements: Financial institutions must comprehensively document all iterations of the risk management process and their results, such as assessment criteria, data used, risk registers and remediation plans . A summary report on the results of the risk management process, a risk register, and a detailed remediation plan should be prepared for board approval each year .