NIST Proposes Update to Cybersecurity Framework to Address Service Provider Oversight

Many investment advisers and broker-dealers have embraced the NIST Cybersecurity Framework since it was first released in 2014, using it to formalize the mapping of risks and controls as part of a comprehensive cybersecurity program. Alas, cybersecurity risks continue to grow, and so too must the response to those risks keep pace. What has become clear from the SEC’s cybersecurity enforcement actions to date is that vendors and service providers to advisers and broker-dealers have access to a wealth of information and data about a firm and its clients, and that a breach or security incident involving the service provider can have privacy impacts for the IA or BD.

Recognizing the significance of service provider relationships and interdependencies on operational risk, the National Institute of Standards and Technology (NIST) proposed an update to its Cybersecurity Framework on January 10, 2017. The proposed changes in version 1.1 are in draft form pending a comment period which is open until April 10, 2017. The draft proposes to amend the Cybersecurity Framework by:

  • Adding a new section on cybersecurity measurement to help define consistent terminology for aligning business actions, results, cybersecurity expenditures, and cybersecurity metrics
  • Updating the Framework Core by adding a new category within the Identify function for Supply Chain Risk Management (ID.SC), which is essentially a focus on the policies, procedures, and controls to manage the risks posed by a firm’s third party vendors and service providers. The new category will include, among other things, an assessment of whether vendors are appropriately identified, prioritized, required to adhere to certain contractual obligations for information security, monitored for compliance with such terms, and included within the scope of business continuity testing.
  • Enhancing the Protect -> Access Control category (PR.AC) to include authentication, authorization, and identity verification, and renaming the category as “Identity Management and Access Control” to reflect that access is closely tied to an understanding of the identity of the party requesting access
  • Adding explanatory text throughout the Framework to describe how Implementation Tiers can be used in conjunction with the Current Profile and Target Profile. A tier is a way to benchmark the strength of a firm’s cybersecurity program, with higher tiers reflecting a more comprehensive and proactive program. The tiers are: Tier 1 (Partial), Tier 2 (Risk Informed), Tier 3 (Repeatable), and Tier 4 (Adaptive).

A redlined version of the NIST Cybersecurity Framework as updated by the proposed draft is available here.

Related Content

Latest Content

SEC’s Latest Risk Alert Focuses on Electronic Communications

The SEC’s most recent risk alert, “Observations from Investment Adviser Examinations Relating to Electronic Messaging,” issued on December 14, 2019, focuses on the use and maintenance of electronic communications for business purposes. The purpose of the alert is to remind advisers of their obligations related to personal use of electronic messaging and the requirements for … Continued

SEC OCIE Issues 2019 Examination Priorities

Well ahead of the New Year, the SEC Office of Compliance Inspections and Examinations (OCIE) announced its 2019 examination priorities. In keeping with OCIE’s four “pillars” of promoting compliance, preventing fraud, identifying and monitoring risk, and informing policy, the Dec. 20 release provides a preview of key areas where OCIE intends to focus its limited … Continued

Highlights of 2018: Predictions for 2019

Our annual year-end review covers investment adviser compliance highlights from 2018, and makes 2019 predictions. We will highlight enforcement actions and SEC risk alerts for retail advisers, private fund managers, and institutional wealth managers. Using these as road markers, our predictions are designed to lead reasonable and effective compliance program development. Evaluate 2018 Compliance and … Continued

A New View of How Technology Will Change the Emerging Crytpo-Economy

From the top of the world, it’s amazing what you can see.  I recently had the opportunity to travel to the United Arab Emirates to speak in Dubai at the 7th Edition of the Alternative Investment Management Summit. While I was there, I took a few moments to ride to the top of the Burj … Continued

SEC Retail Investor Focus Turns Towards Registered Investment Companies

Earlier this year when the SEC’s Office of Compliance Inspections and Examinations (“OCIE”) announced its 2018 examination priorities, OCIE stated that a core priority was to protect retail investors, including seniors and individuals saving for retirement. OCIE is now continuing this effort by focusing on mutual funds and exchanged-traded funds (together, the “Funds”) as the … Continued

Mailing List

Subscribe to the Ascendant Compliance email list for the latest compliance resources, conferences, ComplianceCasts™, and more.

Loading form...

Contact Us

Ascendant works together with clients to identify and assess critical needs through customized plans. If you need assistance with compliance functions, regulatory services, cybersecurity or technology tools, we’d love to speak with you.