2018年-SWIFT环球同业银行金融电讯_Cyber_Security_Risk_Management_in_Securities_Services_43页_1mb
报告摘要
Cyber Security Risk Management in Securities Services - Summary
Core Content
This document, Cyber Security Risk Management in Securities Services, published by the International Securities Services Association (ISSA) in October 2018, outlines the cyber threats faced by firms in the securities services industry and provides guidance on risk mitigation strategies. It is aimed at senior management, information security professionals, and risk managers in the securities services sector, particularly those working in Central Securities Depositories (CSDs), Global and Sub Custodians, and industry utilities such as SWIFT.
The report highlights that cyber attacks are increasing in frequency, sophistication, and impact, with the World Economic Forum (WEF) ranking them as the third most likely and sixth most impactful global risk in 2018. These attacks can disrupt critical financial services and undermine the security and confidence of the financial system.
Main Points
Cyber Attack Threats
- Threat Landscape: The report outlines various types of cyber attacks, including malware, ransomware, DDoS, and APTs.
- Threat Actors: Includes nation states, organized crime, hactivists, malicious insiders, and unwitting insiders. Their motivations range from financial gain to political and national security.
- Kill Chain Phases: The report explains the stages of a cyber attack, from reconnaissance to exfiltration, and emphasizes the importance of detecting and disrupting the attack early in the chain.
Risk Assessment
- Susceptibility Factors: The securities services industry is vulnerable due to its concentration of high-value assets, predictable flows, reliance on centralized systems, and use of third-party services.
- Risk Clusters: Four main clusters of cyber risk are identified:
- Cluster A: Utility disruption / ransom
- Cluster B: Asset theft
- Cluster C: Information theft
- Cluster D: Market manipulation
- Comparative Risk Assessment: The report evaluates the likelihood, impact, and execution difficulty of different cyber threats using a three-axis model.
Risk Mitigation
-
The ISSA Working Group recommends several internal controls and frameworks for managing cyber risks, including:
- Threat intelligence and information sharing
- Vulnerability and patch management
- Penetration testing
- Security architecture design
- Identity and Access Management (IAM)
- Intrusion protection management
- Security awareness and training
- Independent reconciliation
- Third-party risk management
-
The report also suggests leveraging external frameworks such as the ISO 27000 series, NIST Cybersecurity Framework, and SWIFT's Customer Security Programme (CSP).
Key Information
Threats and Impacts
- Ransomware: A growing threat that can lock systems and demand payment, with examples like WannaCry and NotPetya.
- DDoS Attacks: Can disable internet-facing services and disrupt market liquidity.
- APT Attacks: Sophisticated, long-term attacks often aimed at stealing information or assets.
- SWIFT Experience: Shows that threat actors may spend months on reconnaissance and then execute attacks rapidly, emphasizing the need for quick detection and response.
Susceptibility Factors
- High-value assets and predictable cash flows make the securities industry an attractive target.
- Reliance on centralized systems and third-party vendors increases vulnerability.
- Use of automation and STP can create opportunities for attacks if not properly secured.
Risk Clusters and Impacts
- Cluster A: Disruption or ransom attacks can lead to market liquidity issues and are difficult to execute but have high systemic impact.
- Cluster B: Asset theft can result in localized financial loss.
- Cluster C: Information theft can cause reputational damage and competitive disadvantage.
- Cluster D: Market manipulation can lead to significant financial gains for attackers.
Recommendations
- Securities servicers should implement robust cyber security frameworks.
- They should conduct due diligence on third-party service providers and ensure they meet the same security standards.
- The report emphasizes the need for ongoing investment in cyber security and the development of collaborative intelligence networks.
Conclusion
The securities services industry is a critical part of the financial system and is increasingly exposed to cyber threats. The report underscores the importance of proactive risk management, including the use of established frameworks and internal controls, to mitigate these risks. It also highlights the evolving nature of cyber attacks and the need for continuous adaptation and improvement in security practices.
Appendices
- Appendix 3 lists the names of participating firms and individual contributors.
- Additional information on SWIFT's experience with cyber attacks is provided in Appendix 1.
This document serves as an informative reference rather than a prescriptive standard and is subject to periodic updates.
试读结束,高清完整版pdf/doc/ppt,请点下载