Anomalous Activity Detection
- Implement robust log monitoring and analysis processes.
- Establish effective security information and event management systems.
- Monitor and review customer transactions for anomalous activity alerts.
Cyber Incident Detection
- Assign responsibilities for monitoring and reporting suspicious system activities.
- Establish processes to correlate event information from multiple sources.
- Develop a normal network activity baseline.
- Implement continuous detection and response capabilities
Threat Monitoring and Analysis
- Implement processes to monitor threat intelligence and identify emerging threats.
- Assign threat intelligence and analysis processes to a specific group or individual.
- Prioritize and monitor threat intelligence sources.
- Analyse threat intelligence to develop summary reports and predict potential future attacks
Governance and Preparation of Incident Response and Recovery
- Define clear accountability and responsibilities for incident response and recovery.
- Ensure relevant stakeholders are aware of their roles and have sufficient expertise and training.
- Establish processes for proper reaction and response to cyber incidents.
- Develop comprehensive incident response and recovery plans and playbooks.
- Diversify and isolate backup facilities to avoid concentration risks.
Analysis, Mitigation, and Restoration
- Implement processes to identify and classify cybersecurity incidents.
- Establish mitigation processes to contain and eradicate cyber incidents.
- Develop restoration and quality assurance testing processes to validate system operations and ensure business continuity.
Cyber Forensics
- Implement processes to properly collect and preserve the integrity of digital and forensic evidence.
- Establish procedures for investigating and analysing evidence.
- Ensure protection of digital and forensic evidence from unauthorized access, modification, and deletion.
Communication and Improvement
- Establish communication and escalation channels for prompt reporting of cyber events.
- Implement procedures for notifying regulators, law enforcement agencies, customers, and third-party service providers.
- Ensure timely reporting of incidents
- Classify, log, and track all cyber incidents.
- Develop continuous improvement processes to enhance cybersecurity measures and policies.
Threat Intelligence & Threat Intelligence Sharing
- Subscribe to threat intelligence sharing sources.
- Use threat intelligence to monitor relevant cyber threats and enhance cyber risk management.
- Implement protocols for collecting information from industry peers and government.
- Maintain a centralized read-only repository of cyber threat intelligence.