Learning Objectives:
-
Understand the role of control frameworks in managing cyber risk.
-
Identify the key security controls for protecting information assets.
-
Apply controls to address identified cyber risks.
-
Recognise the importance of control effectiveness testing.
5.1 The Role of Control Frameworks
Control frameworks provide a structured approach to implementing and managing security controls. The Saudi Central Bank’s Cybersecurity Framework requires entities to define, approve, implement and communicate cyber security policies and procedures that are supported by detailed security standards (e.g., password standard, firewall standard)Â .
The IT Security Controls book identifies necessary controls and processes that must be implemented to secure an organisation’s infrastructure and proposes a comprehensive approach to IT security controls implementation . The implementation is designed to comply with the most relevant market standards (ISO 27001, NIST, PCI-DSS, and COBIT) .
5.2 Categories of Security Controls
Security controls can be categorised in several ways:
By Function:
-
Preventive Controls:Â Designed to prevent security incidents (e.g., firewalls, access controls, encryption).
-
Detective Controls:Â Designed to detect security incidents (e.g., intrusion detection systems, security monitoring, log analysis).
-
Corrective Controls:Â Designed to correct the effects of security incidents (e.g., incident response, backup and recovery).
By Scope:
-
Technical Controls:Â Controls implemented through technology (e.g., firewalls, antivirus, encryption).
-
Administrative Controls:Â Controls implemented through policies and procedures (e.g., security policies, training, access control policies).
-
Physical Controls:Â Controls implemented through physical measures (e.g., physical security, access control to facilities).
5.3 Key Security Controls for Central Banks
The IT Security Controls book covers a wide range of technical controls :
Unmanaged Device Controls:Â Mobile Device Management (MDM), Mobile Application Management (MAM), Network Access Control (NAC), Multi-Factor Authentication, and Secure Connections (IPsec, SSH, TLS).
Managed Device Controls:Â Directory Service Integration, Centralized Endpoint Management, Trusted Platform Module (TPM), VPN Client, NAC, Data Classification, User Activity Monitoring (UAM), Endpoint Protection (antivirus, antispyware, full-disk encryption), Application Control and Application Whitelisting.
Perimeter Security Controls:Â Firewalls, Intrusion Detection and Prevention Systems (IDS/IPS), Proxy and Content (URL) Filtering, Data Loss Prevention (DLP), Honeypot, Web Application Firewall (WAF), SSL VPN, DNS, Message Security, Sandbox, File Integrity, and Encrypted Email.
On-Premises Support Controls:Â Access Control, Secure VLAN Segmentation, Security Baselines, Redundancy, Load Balancing, Encryption, Multi-tier and Multi-layer, TLS Decryption, Perimeter Static Routing, Heartbeat Interfaces, Disaster Recovery, Time Synchronization, Log Concentrator, Routing and Management Networks, Sinkhole, Public Key Infrastructure (PKI), and Physical Network Segmentation.
5.4 Control Effectiveness Testing
The Central Bank of Nigeria’s Framework requires vulnerability management and penetration test reports, remediation efforts and challenges encountered and compensating controls implemented . This ensures that controls are tested and their effectiveness verified.
Types of Testing:
-
Vulnerability Scans:Â Automated scans to identify vulnerabilities in systems.
-
Penetration Testing:Â Simulated attacks to test the effectiveness of controls.
-
Red Teaming:Â Comprehensive, objective-based security assessments.
-
Code Review and Testing:Â Reviewing code for security vulnerabilities.
-
Compliance Scans: Scanning systems for compliance with security standards.