Responsibilities:
Clearly identify the systems, networks, applications, and sensitive data types for assessment in collaboration within Bank,
Evaluate the Bank's existing asset inventory, data classification schemes to ensure accuracy and completeness for risk assessment purposes,
Identify relevant cyber threats and assess technical, procedural, and people control gaps relevant to the scoped environment,
Analyze the likelihood and potential business impact based on identified control gaps,
Assess design and operating effectiveness of controls aligned to NIST CSF 2.0 and applicable GLBA requirements,
Compile a comprehensive, prioritized risk register,
Recommend actionable measures to address control gaps and reduce risk exposure.
Deliverables:
Risk assessment report and risk register,
Recommendations for risk mitigation,
Control gap assessment report,
Executive presentation.
Primary Objective:
The primary objective of this Risk assessment is to deliver the following:
Conduct an independent assessment of Bank's cybersecurity program against the NIST Cybersecurity Framework (CSF) 2.0 and applicable GLBA security requirements.,
Evaluate the effectiveness and maturity of the Bank's people, process, and technology controls across the NIST CSF 2.0 functions.,
Perform a risk assessment of the identified gaps using NIST Risk Management Framework (RMF) principles and NIST SP 800-30 methodology to determine risk exposure and prioritization.
Provide assessment results, identified gaps, and a risk register detailing the associated risk ratings and observations.