Learning Objectives:
-
Identify key security controls for protecting banking systems.
-
Explain multi-factor authentication, encryption, and monitoring.
-
Understand the principles of Zero Trust architecture.
3.1 Core Security Controls
The IIBF IT Security syllabus outlines several categories of security controls required in banking environments .
Asset Classification & Controls:
The IIBF syllabus covers “Asset Classification & Controls” including hardware/software protection and the OSI model . Protecting information, hardware, and software assets is fundamental to security.
Physical & Environmental Controls:
The IIBF syllabus covers “Physical & Environmental Controls” including physical security equipment, intrusion prevention systems, environmental threat controls, and e-waste management .
Software Security Controls:
The IIBF syllabus covers “Software Security Controls” including operating system security, database security, and application-level security for mobile and internet banking .
Network Controls:
The IIBF syllabus covers “Network Controls” including VLANs, intrusion detection systems, firewalls, unified threat management, and secure protocols .
3.2 Authentication and Access Controls
Authentication is the gateway to financial services and the final safeguard before completing a transaction.
Multi-Factor Authentication (MFA):
MFA requires users to provide two or more independent verification elements to log in. The SUSS course covers “Transaction security” as a core topic . The academic literature identifies multi-factor authentication as a commonly used method to address cybersecurity risks .
Biometric Authentication:
The H.L. College of Commerce syllabus covers “Biometric Authentication” as a security measure in digital banking . Biometric authentication methods include fingerprint recognition, facial recognition, and behavioural biometrics.
Adaptive Authentication:
Adaptive authentication methods, which analyze factors such as login time, browser type, and geographic location, offer an additional layer of protection by detecting high-risk login attempts .
3.3 Data Protection and Encryption
The SUSS course covers “Information security” as a core topic . The IIBF syllabus covers “Data vs Information” and “Information Classification” .
Data Encryption:
Encrypting sensitive financial data both in transit and at rest using robust algorithms ensures confidentiality even if data is intercepted or storage systems are breached .
Secure Communication Channels:
The IIBF syllabus covers “Network Controls” including secure protocols .
Data Classification:
The IIBF syllabus covers “Information Classification” including physical and logical security .
3.4 Zero Trust Architecture and Network Security
Zero Trust is an emerging security model for banking institutions. Its principles include:
-
Never trust, always verify: No user or device is trusted by default.
-
Micro-segmentation: Dividing networks into smaller segments to limit lateral movement.
-
Continuous monitoring: Real-time verification of user and device identity.
-
Adaptive access control: Access decisions based on risk signals.
Network Controls:
The IIBF syllabus covers “Network Controls” including VLANs, intrusion detection systems, and firewalls .
3.5 Security Awareness Training
Comprehensive employee education programs build human firewall capabilities, teaching staff to recognise phishing attempts, social engineering tactics, and security best practices . The academic literature identifies employee awareness training as a commonly used method to address cybersecurity risks .