Learning Objectives:
-
Understand the principles of information security management.
-
Apply the CIA triad (Confidentiality, Integrity, Availability) to central bank operations.
-
Develop and implement information security policies and standards.
-
Recognise the importance of security awareness and training.
3.1 The CIA Triad
The CIA triad is the foundation of information security management. It represents three core principles that must be protected:
Confidentiality: Ensuring that information is accessible only to those authorised to have access. This involves protecting information from unauthorised disclosure. The ECB’s SREP methodology requires that financial entities have the information security policies, standards and guidelines properly documented, approved by management, implemented and communicated to all staff .
Integrity: Safeguarding the accuracy and completeness of information and processing methods. This involves protecting information from unauthorised modification or deletion. The ECB’s SREP methodology assesses ICT data integrity risk, including the number of significant invalid data modification incidents and the number of annual incorrect data submissions .
Availability: Ensuring that authorised users have access to information and associated assets when required. This involves protecting information from denial-of-service attacks and system failures. The ECB’s SREP methodology assesses ICT availability and continuity risk, including the annual unplanned downtime of critical ICT systems .
3.2 Information Security Policies and Standards
Financial institutions must have the information security policies, standards and guidelines properly documented, approved by management, implemented and communicated to all staff . The ECB’s SREP methodology requires that financial entities have sound ICT policies, guidelines and procedures to properly drive the work of the ICT function(s) .
Key Information Security Controls:
Access Control: Financial entities must grant access to ICT assets only to properly identified, authenticated and authorised individuals . This includes implementing the principle of least privilege and role-based access control.
Vulnerability Management: Financial entities must identify and mitigate vulnerabilities impacting ICT systems in a timely manner .
Protection Measures: Financial entities must have adequate protection measures in place to safeguard ICT systems, at the network and end-point levels, for information in transit and at rest . The Regulation on Information Systems and Cyber Risk Management requires the development and implementation of risk mitigation measures consistent with the criticality of information assets .
3.3 Security Monitoring and Incident Detection
Financial entities must have procedures in place for collecting, logging and analysing security-relevant events in order to trigger actionable security alerts or initiate the security incident process . Security monitoring involves continuous surveillance of information systems to detect security incidents.
Key Security Monitoring Activities:
Event Logging: Financial entities must collect and log security-relevant events .
Security Analysis: Financial entities must analyse security-relevant events to identify potential security incidents .
Alert Generation: Financial entities must have procedures to trigger actionable security alerts .
Incident Initiation: Financial entities must have procedures to initiate the security incident process .
3.4 Security Awareness and Training
The Regulation on Information Systems and Cyber Risk Management requires that information system risk management should include an annual awareness plan for financial institution employees on the appropriate use of services provided through the financial institution’s information system . The ECB’s SREP methodology requires that financial entities have the information security policies, standards and guidelines properly documented, approved by management, implemented and communicated to all staff .
Security awareness and training help employees understand their security responsibilities and recognise potential security threats. Regular training and awareness programmes are essential for building a security culture within the organisation.