Learning Objectives:
-
Understand the role of cybersecurity policies in establishing governance and control.
-
Identify the key elements of effective cybersecurity policies and standards.
-
Recognise the importance of policy review and updating.
-
Understand the relationship between policies, procedures, and standards.
5.1 The Role of Cybersecurity Policies
Cybersecurity policies establish the governance framework for managing cyber risks. The Saudi Central Bank’s Cybersecurity Framework requires entities to “define, approve, implement and communicate cyber security policies and procedures that is supported by detailed security standards (e.g. password standard, firewall standard)” .
The Central Bank of Nigeria’s Framework requires that the cybersecurity policy clearly conveys its intent and the institution’s approach to achieving the cybersecurity objectives . The policy should be reviewed annually at a minimum, or when there are significant changes to the institution’s cyber-risk exposure .
Policies serve several key functions:
-
Establishing Expectations:Â Policies set clear expectations for behaviour and controls.
-
Providing Guidance:Â Policies provide guidance for decision-making and action.
-
Ensuring Consistency:Â Policies ensure consistent application of controls across the organisation.
-
Demonstrating Compliance:Â Policies demonstrate compliance with regulatory requirements.
5.2 Key Policy Elements
Comprehensive cybersecurity policies typically address several key areas:
Security Standards:Â Entities should define, approve, implement, and communicate cyber security policies and procedures supported by detailed security standards (e.g., password standard, firewall standard)Â . These standards provide specific technical requirements for implementing policies.
Password Policy: Entities should establish and implement strong password policy for users’ access to its information assets, such as change of password upon first logon, minimum password length and history and password complexity, revoking the access after the three successive incorrect passwords, and use non-caching techniques .
Policy Review: Entities should periodically review and update cyber security policies, procedures, and standards taking into consideration the evolving cyber threat landscape . This ensures that policies remain effective in addressing emerging threats.
Business Integration: Entities should incorporate cyber security requirements in their new and/or existing business operating model, including evaluation of cyber security and fraud risks that could target business operating models and adoption and evaluation of cyber security measures for the protection against adversarial attacks .
5.3 Policy Development and Implementation
Effective policy development requires a structured approach. The Central Bank of Nigeria’s Framework requires that the cybersecurity governance documents such as cybersecurity strategy, framework, and policies are established and aligned with the institution’s business goals and objectives .
The board is responsible for ensuring that the approved cybersecurity framework aligns with business objectives and technological approaches to mitigate cyber risks and clearly defines key cybersecurity roles and responsibilities .
Policy implementation requires:
-
Communication:Â Policies must be communicated to all relevant stakeholders.
-
Training:Â Employees must be trained on policy requirements.
-
Enforcement:Â Policies must be enforced consistently.
-
Monitoring:Â Compliance with policies must be monitored.
5.4 International Standards and Frameworks
The adoption of internationally recognised standards is common practice in financial institutions. A study on cybersecurity governance in banking and financial institutions highlights the widespread adoption of internationally recognised standards, noting that ISO 27001, the NIST Cybersecurity Framework, and CIS Controls are the most common frameworks for implementing cybersecurity governance .
While these global standards provide a foundational structure, regional regulatory bodies have developed complementary frameworks tailored to local contexts and requirements, such as the Central Bank of Kuwait’s Cybersecurity Framework and the Saudi Central Bank’s (SAMA) regulations . This reflects the importance of adapting global standards to local regulatory requirements.