## 1blzea2020002

## Source details

**Canonical URL:** [1blzea2020002](https://www.imf.org/-/media/files/publications/cr/2020/english/1blzea2020002.pdf)

## Other formats

- [Markdown version](/-/media/files/publications/cr/2020/english/1blzea2020002.pdf.md)
- [Structured JSON version](/-/media/files/publications/cr/2020/english/1blzea2020002.pdf.json)

---

### Mission purpose and activities
- MCM Department mission visited Belize City during April 3–12, 2019 at the request of the Central Bank of Belize (CBB).
- Purpose: (i) build cybersecurity regulation and supervision capacity, and (ii) improve the cyber resilience of the CBB by supporting a business continuity planning effort.
- Meetings with Governor and Deputy Governors, senior officials, IT and information security staff, bank supervision staff, industry representatives at a Cyber Security Committee (CSC) meeting, and CBB senior officials at a BCM workshop.
- Documentation reviewed: cybersecurity guidance note, CSC terms of reference, sample reports, plans, policies, procedures, risk assessments, internal IT and information security documents, and the physical/environmental controls of the data center.
- Activities: BCM workshop for CBB management; presentation and discussion with industry about regulation and supervision trends.

### Definitions and approach
- “Cybersecurity” and “information security” are used interchangeably per the Financial Stability Board (FSB) Cyber Lexicon.
- Guidance note alignment: principle-based, aligned with international best practices (examples listed in the report include Group of Seven Fundamental Elements of Cybersecurity for the Financial Sector; NIST; ISO 27000 series; COBIT; FFIEC Cybersecurity Assessment Tool; OSFI Cyber Security Self-Assessment Guidance).

### Executive summary — key findings
- Cybersecurity risk is embedded in the CBB’s supervisory framework but requires enhancements to formalize guidance and develop more intensive supervisory practices.
- Supervisory expectations are currently in an informal guidance note; formalization into enforceable regulation is recommended.
- CBB established a framework for cyber threat intelligence sharing via the CSC; CBB participation could be reconsidered because supervision staff presence may adversely impact timely information sharing.
- IT inspections are conducted by IT department technical experts, posing resource strain and conflict of interest risk with payment systems oversight; recommendation to establish a dedicated IT supervision team.
- Disaster recovery (DR) capability: partially redundant infrastructure, robust replication and backup, documented recovery procedures, and regular tests—supporting reliable and timely recovery of critical IT systems.
- Key redundant IT components: TechOne, APSSS, SWIFT, core network switches, firewalls, and the WAN link to the DR site in Belmopan.
- Business continuity gaps: no contingency plans for alternate work arrangements and no standby office space if the main building becomes inaccessible.

### Executive summary — concise recommendations
- Four key steps for cybersecurity regulation and supervision:
  - (i) issue enforceable cybersecurity guidelines;
  - (ii) develop a supervisory manual aligned with the supervisory guidelines;
  - (iii) set up a dedicated IT supervisory team composed of at least two inspectors; and
  - (iv) develop a rulebook for operational threat intelligence sharing between technical experts in the CSC.
- Six key steps to improve BCM of the CBB:
  - (i) enhance the BCM framework with several measures (detailed in the report);
  - (ii) designate a business continuity planning (BCP) project sponsor with sufficient authority;
  - (iii) focus the BCP project on alternative operations and standby facilities;
  - (iv) have all organizational units participate in the BCP project (main responsibilities detailed in the report);
  - (v) specialized BCP software may be used but benefits are unlikely to be fully realized for the small size of the CBB; and
  - (vi) consider external support for the BCP project.
- Three key steps to improve cybersecurity governance of the CBB:
  - (i) consider a cybersecurity function independent from IT;
  - (ii) implement a formal cyber risk assessment process; and
  - (iii) ensure staff responsible for risk assessment receive relevant training.

### Table 1 — Key Recommendations (extract)
- Selected recommendations, priorities, and timeframes:
  - Issue enforceable cybersecurity guidelines. Priority: High. Timeframe: Short-term. Reference: 9.
  - Develop a supervisory manual aligned with the supervisory guidelines. Priority: High. Timeframe: Short-term. Reference: 10.
  - Set up a dedicated IT supervisory team composed of at least two experts. Priority: High. Timeframe: Short-term. Reference: 29.
  - Develop a rulebook for operational threat intelligence sharing between technical experts in the Cyber Security Committee. Priority: Medium. Timeframe: Short-term. Reference: 20.
  - Enhance the BCM framework with several measures. Priority: High. Timeframe: Short-term. Reference: 52.
  - Designate a BCP project sponsor with sufficient authority. Priority: High. Timeframe: Short-term. Reference: 53.
  - BCP project should focus on alternative operations and standby facilities. Priority: High. Timeframe: Short-term. Reference: 54.
  - All organizational units should participate in the BCP project. Priority: High. Timeframe: Short-term. Reference: 55.
  - Plans should be regularly tested, and test results used to improve them. Priority: High. Timeframe: Short-term. Reference: 58.
  - External support for the BCP project should be considered. Priority: Medium. Timeframe: Short-term. Reference: 57.
  - Consider establishment of a cybersecurity function independent from IT. Priority: High. Timeframe: Short-term. Reference: 60.
  - Implement a formal cyber risk assessment process. Priority: High. Timeframe: High Shot-term. Reference: 61.
  - Ensure staff responsible for the risk assessment receives relevant training. Priority: High. Timeframe: Short-term. Reference: 62.
- Note: Short-term is defined as < 12 months; Medium-term: 12–24 months.

### Additional regulatory and supervisory assessments
- CBB legal authority: can promulgate mandatory rules and guidance and take enforcement action, including directives and fines for cybersecurity shortcomings within its remit.
- CSC role: national industry group for information sharing, baselines, innovations, and timely communication on cyber threats and incidents; membership includes CBB, domestic and international banks.
- Presence of supervisory authority in the CSC may limit information sharing due to perceived threat of immediate supervisory action.
- CBB membership: National Task Force for Cybersecurity (develops National Cybersecurity Policy and contemplates national/sectoral computer emergency response teams).
- Cybersecurity incident reporting: standardized template covering occurrence and detection time, attack vectors, classification, impact assessment, indicators of compromise, and response steps—containment, eradication, and recovery.

### Board and senior management responsibilities; visibility and incentives
- Board and senior management: ultimately responsible for approving and implementing the financial institution’s cybersecurity strategy.
- Boards and senior managers often underappreciate business implications of cyber risks and may subordinate cyber resilience to other objectives.
- Specific cybersecurity guidelines should specify responsibilities for the board and senior management to create incentives and visibility.

### Outsourcing, incident reporting, and testing
- Outsourcing arrangements: consider special provisions for material outsourcing including notifications, formal audit rights, and incident reporting requirements.
- Financial institutions should maintain a comprehensive outsourcing register per a predefined template; timely notification on material outsourcing and annual reporting support supervisory cyber risk assessment.
- Outsourcing agreements should require service providers to accommodate audits by institutions and the CBB and to report relevant cyber incidents.
- Incident reporting should specify a classification scheme and materiality thresholds; CBB should outline criteria and thresholds (candidate criteria: criticality of systems, value and number of transactions, downtimes, economic/reputational impact, incident category).
- Control effectiveness assessments: require regular penetration testing; leading jurisdictions base penetration tests on advanced cyber threat intelligence.

### Scenario-based resilience planning and exercising
- Principles should emphasize scenario-based cyber resilience planning and exercising.
- Institutions should develop cyber incident management plans addressing business operations impact, legal requirements, stakeholder communication, and human resources.
- Recent attack vectors (crypto-ransomware, fraudulent wholesale payments) are recommended bases for scenario-driven testing.

### Core areas to be covered by principles
- Principles should cover: (i) governance, (ii) strategy, (iii) monitoring and detection, (iv) response, (v) recovery, and (vi) information sharing.
- Emphasis on establishing, implementing and reviewing cyber risk management processes, preventing materialization of cyber risks, and enabling containment (e.g., network segmentation).

### Operational threat intelligence and information sharing
- Effective operational threat intelligence sharing requires trust between technical experts and a rulebook; CSC suited for strategic/tactical discussions, while operational intelligence should be shared among technical professionals and national computer emergency response teams.
- Agree information handling procedures such as traffic light protocols.
- CBB could participate in special platforms for information sharing between central banks, regulators, and supervisory entities.

### Supervisory practices — assessment and recommendations
- Current supervisory framework grounded on international best practices for IT supervision.
- Onsite exams: planning includes identification of IT expertise needed and preliminary information gathering; inspections are based on interviews and walkthroughs with formal follow-up of findings.
- Supervisory reporting: exception-based; institutions can comment on factual correctness before report issuance; supervisors record existing control frameworks and describe supervisory findings; currently supervisors do not rate findings.
- IT examinations are conducted in collaboration with IT Department experts; supervision department has limited expertise in information systems governance, processes, and technology.
- Reliance on internal experts can strain IT resources and pose conflict of interest with payment systems oversight.
- CBB has started hiring a dedicated IT supervisor.
- Recommended supervisory actions:
  - Develop an IT/cybersecurity supervisory manual aligned with guidelines emphasizing review of strategy, policies, effectiveness of risk identification/mitigation, oversight by independent functions, third-party management, and incident response/resilience provisions.
  - Consider technical assessments by credible third-party assurance providers and institutions’ internal audit (internal/external audit reports, penetration testing, SWIFT Customer Security Program self-assessments with independent assurance).
  - Review management’s responses to prior issues; rely on internal audit follow-up only if quality and independence are adequate.
  - Encourage cybersecurity self-assessments as part of pre-examination requests covering governance, control measures, risk identification, recent tests, situational awareness, third-party risk management, and incident management.
  - Consider including supporting evidence in reports or references in work papers and adopt a rating scheme for findings.
  - Place more emphasis on onsite control effectiveness examinations.
  - Decrease reliance on internal IT staff and establish a dedicated IT supervision team of at least two inspectors with adequate expertise and qualifications.
  - Ensure separation between supervisory/payment systems oversight and central bank IT operations.
  - Recognize certifications such as ISACA’s CISA and (ISC)² CISSP as adequate background.
  - To attract and retain cybersecurity experts, three most effective incentives: (i) significant training opportunities (including paying for security certification), (ii) improving compensation packages, and (iii) flexible work schedules.
  - Allocate capacity for ad-hoc examinations and foresee spare capacity to deal with incidents.
  - Revisiting interval of one and a half year in CBB internal supervisory objectives is considered acceptable; consider differentiated intervals based on systemic importance and cybersecurity risk posture.

### Cyber resilience — BCM assessment: key findings and specifics
- DR strengths:
  - Partially redundant infrastructure, robust replication and backup, comprehensive recovery procedures, and regular tests enable reliable and timely recovery of critical IT systems.
  - Key redundant components: TechOne, APSSS, SWIFT, core network switches, firewalls, WAN link to DR site in Belmopan.
  - Critical systems’ data replicated to DR site in real time with appropriate recovery point objective (RPOs).
  - Regular recovery tests indicate high resilience for APSSS, TechOne and SWIFT; processing can be switched to DR site within minutes without data loss, dependent on WAN link availability.
  - CBB has an up to date hurricane plan tested each year before the hurricane season; identified shortcomings are addressed timely.
  - Data center power supply: uninterruptible power supply capable of delivering enough power for 45 minutes, and two power generators at opposite ends of the building with one month’s worth of fuel reserves; generators can be activated within minutes and are regularly tested and maintained.
  - Main building design withstands hurricanes and storm surges of up to 15 feet.
  - CBB upgrading physical security management system (SMS) to support strong user authentication using smart card technology; SMS servers on segregated network accessible through dedicated firewall; security control room being retrofitted.
- DR concerns and BCM gaps:
  - Unclear whether WAN link to DR site is physically redundant between main and DR sites.
  - Physical protection weaknesses: large internally facing glass wall, inadequate fire suppression with only one handheld extinguisher, insufficient shielding against electromagnetic radiation increasing wireless exfiltration risk.
  - Non-critical systems backed up to tapes with relatively old tape technology; tape cartridges reliable if used within specifications; ongoing project consolidating data backup.
  - Business continuity measures for alternative operations lacking: no contingency plans for alternate work arrangements and no stand-by office space if main building inaccessible.
- Recommendation: obtain assurance over redundancy of WAN link to DR site by analyzing telecommunications provider information including network architecture, equipment and line redundancy, and DR plans.

### Cybersecurity governance assessment at the CBB
- Current responsibilities:
  - Cybersecurity assigned to IT Department; a security analyst reports to the IT manager; other staff perform security activities as needed.
  - Internal audit has one staff training to become a CISA.
  - IT manager reports to senior manager of corporate services who reports to the governor; reporting line considered adequate given small size and organizational simplicity.
  - Enterprise risk management (ERM) function recently established with one relatively junior ERM staff with no cybersecurity expertise.
- Governance and assurance findings:
  - Inclusion of all cybersecurity responsibilities in IT Department, combined with limited ERM and internal independent assurance expertise, increases conflict of interest risk.
  - Internal audit and external auditor do not provide adequate compensating controls currently.
  - IT policy framework is well structured and developed; key policies and procedures are up to date and actionable despite some lag.
  - Penetration testing by third parties provides independent assurance; IT department remediates findings.

### IT risk assessment and incident management — findings and recommendations
- IT risk assessment by IT department is a good start but needs improvement:
  - Risks identified are generally relevant but not sufficiently specific to the CBB.
  - Missing risk ratings based on impact and likelihood.
  - Controls listed reference procedures but their effectiveness is not assessed; residual risks are not determined.
  - No evidence of risk acceptance and senior management signoff.
  - Remedial action is missing; root cause: lack of formalized methodology-based risk assessment expertise in IT department.
- Incident management deficiencies:
  - Draft incident response plan based on NIST Computer Security Incident Handling Guide exists, but business unit involvement in development and acceptance is not evidenced.
  - Recommendation: circulate incident management plan to involved business units, address feedback, and obtain formal approval; agree specific escalation criteria, processes and contacts.

### Cybersecurity governance — recommended organizational changes and processes
- Consider establishing a cybersecurity function independent from IT to:
  - implement an independent control layer over security-critical IT activities;
  - concentrate scarce cybersecurity expertise to achieve critical mass; and
  - reduce IT department workload.
- Examples of processes/systems to be controlled by independent cybersecurity function: identity and access management, perimeter defense, endpoint protection and anti-malware, web content filtering, data loss protection, and security information and event management.
- Independent cybersecurity function could act as control point (e.g., approve firewall rules without running the firewall).
- Signoff by cybersecurity function recommended on network architecture changes, procurement/development of new systems, and use of cloud services.
- Reporting line options for cybersecurity function: governor (increases visibility but distances from IT), corporate services (balanced option given hierarchy and closeness to IT), or security (consolidates security functions but similar distancing disadvantage).
- Formal cyber risk assessment process should:
  - (i) apply a documented risk assessment methodology (usually qualitative);
  - (ii) define risk appetite (e.g., maximum acceptable residual risk);
  - (iii) require mitigation for residual risks above appetite;
  - (iv) involve business units in risk identification and rating;
  - (v) document mitigation measures in an action plan with deadlines and responsibilities;
  - (vi) ensure action plan funding;
  - (vii) ensure timely follow-up; and
  - (viii) ensure regular updates and Board reporting.
- Staff training recommendations: consider SANS Institute courses (e.g., MGT415), review of ISACA’s COBIT and COSO ERM framework, or training for CISSP or Certified Information Security Manager certifications.

### Next steps
- The CBB should develop an improvement plan to address the findings.

*Source: Preface and Executive Summary of the mission report to the Central Bank of Belize (IMF MCM mission, April 3–12, 2019).*

### Preface.................................................................................................................

### Preface

### Mission purpose and activities
- At the request of the Central Bank of Belize (CBB), a Monetary and Capital Markets (MCM) Department mission visited Belize City during April 3–12, 2019.
- The purpose of the mission was to: (i) build cybersecurity regulation and supervision capacity, and (ii) improve the cyber resilience of the CBB by supporting a business continuity planning effort.
- The mission team met with the Governor and Deputy Governors of the CBB, senior officials, and staff involved in information security, information technology (IT), and bank supervision.
- The mission also met with industry representatives at a Cyber Security Committee meeting and senior officials of the CBB from different departments at a business continuity management (BCM) workshop.
- The mission reviewed documentation including the cybersecurity guidance note, terms of reference of the CSC, sample reports, plans, policies, procedures, risk assessments, internal IT and information security documents, and reviewed the physical and environmental control environment of the data center.
- The mission held a BCM workshop for the CBB’s management and met with industry representatives to present and discuss trends in regulation and supervision.

### Definition used
- The report uses the term “cybersecurity” according to the definition of the Financial Stability Board (FSB) Cyber Lexicon. With this, “Cybersecurity” and “information security” denote the same concept.

### Executive summary — key findings
- Cybersecurity risk is embedded in the CBB’s supervisory framework, but additional enhancements are needed to formalize guidance and develop more intensive supervisory practices.
- Supervisory expectations on cybersecurity are presented in an informal guidance note, which should be formalized into regulation to ensure enforceability; and an IT/cybersecurity supervisory manual should be developed to promote effective and consistent practices.
- The guidance note is principle-based, highlights priorities in incident prevention, detection, response, and recovery, is aligned with international best practices, and can be used as a foundation for formalized guidelines.
- The CBB established a framework for timely cyber threat intelligence sharing between the financial institutions via the Cyber Security Committee (CSC); however, CBB’s participation could be reconsidered because explicit participation of the supervision staff may adversely impact timely information sharing.
- Currently IT inspections are conducted by technical experts from the IT department, which may put a strain on resources and pose a conflict of interest risk with the CBB’s payment systems oversight role; therefore, a dedicated IT supervision team should be established.
- Disaster recovery (DR) at the CBB is facilitated by a partially redundant infrastructure, a robust replication and backup system, a comprehensive set of documented recovery procedures, and regular tests—overall providing for reliable and timely recovery of critical IT systems.
- Key components of the IT infrastructure are redundant: critical servers (TechOne, APSSS, and Society for Worldwide Interbank Financial Telecommunication [SWIFT]), core network switches, firewalls, and the Wide Area Network (WAN) link to the disaster recovery (DR) site in Belmopan.
- Business continuity measures that address alternate ways to run the business processes are lacking: most notably, there are no contingency plans for alternate work arrangements and there is no standby office space available in case the main building becomes inaccessible.

### Executive summary — concise recommendations
- Four key steps to improve cybersecurity regulation and supervision:
  - (i) issue enforceable cybersecurity guidelines;
  - (ii) develop a supervisory manual aligned with the supervisory guidelines;
  - (iii) set up a dedicated IT supervisory team composed of at least two inspectors; and
  - (iv) develop a rulebook for operational threat intelligence sharing between technical experts in the Cyber Security Committee.
- Six key steps to improve the BCM of the CBB:
  - (i) enhance the BCM framework with several measures (detailed in the report);
  - (ii) designate a business continuity planning (BCP) project sponsor with sufficient authority to drive the cross-departmental work that is needed;
  - (iii) in the BCP project focus on alternative operations and standby facilities;
  - (iv) have all organizational units participate in the BCP project (their main responsibilities being detailed in the report);
  - (v) specialized BCP software may be used but its benefits are unlikely to be fully realized; and
  - (vi) consider external support for the BCP project.
- Three key steps to improve the cybersecurity governance of the CBB:
  - (i) consider the establishment of a cybersecurity function independent from IT;
  - (ii) implement a formal cyber risk assessment process; and
  - (iii) ensure staff responsible for the risk assessment receives relevant training.

### Table 1 — Key Recommendations (extract)
- Recommendation priorities and timeframes (as presented in Table 1):
  - Issue enforceable cybersecurity guidelines. Priority: High. Timeframe: Short-term. Reference: 9.
  - Develop a supervisory manual aligned with the supervisory guidelines. Priority: High. Timeframe: Short-term. Reference: 10.
  - Set up a dedicated IT supervisory team composed of at least two experts. Priority: High. Timeframe: Short-term. Reference: 29.
  - Develop a rulebook for operational threat intelligence sharing between technical experts in the Cyber Security Committee. Priority: Medium. Timeframe: Short-term. Reference: 20.
  - The BCM framework should be enhanced with several measures (detailed in the report). Priority: High. Timeframe: Short-term. Reference: 52.
  - The Board should designate a BCP project sponsor with sufficient authority to drive the cross-departmental work that is needed. Priority: High. Timeframe: Short-term. Reference: 53.
  - The BCP project should focus on alternative operations and standby facilities. Priority: High. Timeframe: Short-term. Reference: 54.
  - All organizational units should participate in the BCP project (their main responsibilities being detailed in the report). Priority: High. Timeframe: Short-term. Reference: 55.
  - The plans should be regularly tested, and the test results should be used to improve them. Priority: High. Timeframe: Short-term. Reference: 58.
  - External support for the BCP project should be considered. Priority: Medium. Timeframe: Short-term. Reference: 57.
  - Consider the establishment of a cybersecurity function independent from IT. Priority: High. Timeframe: Short-term. Reference: 60.
  - Implement a formal cyber risk assessment process. Priority: High. Timeframe: High Shot-term. Reference: 61.
  - Ensure staff responsible for the risk assessment receives relevant training. Priority: High. Timeframe: Short-term. Reference: 62.
- Note: Short-term is defined as < 12 months; Medium-term: 12–24 months.

### Additional regulatory and supervisory assessments
- The CBB can promulgate both mandatory rules and guidance and has sufficient legal authority to take enforcement action on any cybersecurity shortcoming at institutions within its remit, including issuance of directives to rectify noncompliance and fines.
- The CSC for the financial services industry is a national industry group in which the CBB, domestic, and international banks are represented by their senior officials with responsibilities related to cybersecurity. CSC roles include: (i) share information about the evolving cyber threat landscape; (ii) discuss cybersecurity baselines and innovations; and (iii) timely communicate actionable information on cyber threats and incidents.
- Presence of the supervisory authority in the CSC may limit information sharing because participation of supervisors may result in a perceived threat of (immediate) supervisory action upon disclosure of incident information.
- The CBB is a member of the National Task Force for Cybersecurity, which develops the National Cybersecurity Policy and contemplates establishment of national and sectoral computer emergency response teams.
- Cybersecurity incident reporting is standardized with a reporting template that covers occurrence and detection time, attack vectors, classification, impact assessment, indicators of compromise, and response steps—containment, eradication, and recovery.

### Regulatory guidance and supervisory ownership
- The guidance note on cybersecurity is an informational principle-based document specifying requirements aligned with international standards like the NIST Cyber Security Framework and stresses board and senior manager responsibilities and recommends establishment of a chief information security officer position.
- Recommended regulatory approach:
  - Issue formal guidelines with a hierarchical approach of stable principle-based objectives and more concrete supervisory interpretations to allow proportionality by institution size and systemic importance.
  - Supervision Department should take ownership of the formal requirements and maintain evolving supervisory expectations for cybersecurity.
  - Extend regulatory requirements to cover all areas of cybersecurity as outlined in international standards and strengthen them to provide an adequate minimum cybersecurity baseline.
  - Base principles on internationally accepted standards and good practices (examples listed in the report include Group of Seven Fundamental Elements of Cybersecurity for the Financial Sector; frameworks such as NIST, ISO 27000 series, COBIT; and tools like FFIEC Cybersecurity Assessment Tool or OSFI Cyber Security Self-Assessment Guidance).
  - Principles should emphasize continuous improvement and require realistic and comprehensive risk and control assessments, with supervisory expectations on minimum scope, timing, and follow-up, while remaining agnostic on assessment methodology.
  - Require that risk and control assessments are based on comprehensive information asset identification and classification aligned with confidentiality, integrity, and availability objectives; institutions may choose their own classification scheme provided critical assets are clearly identified.

*Source: Preface and Executive Summary of the mission report to the Central Bank of Belize (IMF MCM mission, April 3–12, 2019).*

### 14.      Cyber risk management responsibilities for the board and senior management of

### 14.      Cyber risk management responsibilities for the board and senior management of

### Board and senior management responsibilities; visibility and incentives
- The board and senior management are ultimately responsible for respectively approving and implementing the financial institution’s cybersecurity strategy.
- Boards and senior managers typically underappreciate the business implications of cyber risks and are inclined to subordinate cyber resilience to other business objectives.
- Specific cybersecurity guidelines should clearly specify responsibilities for the board and senior management to generate incentives and create visibility for cyber risk.

### Outsourcing arrangements and supervisory reporting
- Special provisions for material outsourcing arrangements should be considered, including:
  - notifications,
  - formal rights to audit, and
  - incident reporting requirements.
- Financial institutions should be required to maintain a comprehensive register on their outsourcing arrangements according to a predefined template.
- Requiring timely notification on material outsourcing and an annual reporting of the outsourcing registers supports supervisors in their cyber risk assessment and supervision planning.
- An explicit definition of material outsourcing by the CBB in line with international standards would ensure reporting consistency.
- Outsourcing agreements should explicitly require service providers to accommodate audits from the institutions and the CBB, and reporting requirements for relevant cyber incidents.

### Incident reporting: classification and materiality thresholds
- Incident reporting requirements should specify a comprehensive classification scheme for cyber incidents and materiality thresholds.
- The CBB should consider outlining criteria and specifying related thresholds to determine whether an incident is reportable and within which timeframe.
- Candidate criteria for reportability include:
  - the criticality of affected systems,
  - value and number of transactions involved,
  - downtimes,
  - economic/reputational impact, and
  - incident category.

### Control effectiveness assessments and penetration testing
- The principles should require regular control implementation effectiveness assessments like penetration testing.
- Vulnerability scanners identify weaknesses in configuration or source code; penetration testing is a more sophisticated approach where ethical hackers simulate complex attack vectors.
- Penetration testing assesses maturity of cyber incident detection and response capabilities.
- Leading jurisdictions require ethical hackers to base their attack vectors on advanced cyber threat intelligence considering tactics, techniques, and procedures of expected cyber adversaries.

### Scenario-based resilience planning and exercising
- The principles should give due attention to scenario-based cyber resilience planning and exercising.
- Cyber incidents with significant impact on confidentiality, integrity, and availability of critical assets are increasingly common.
- Financial institutions should proactively develop cyber incident management plans addressing:
  - impact on business operations,
  - legal requirements,
  - communication to stakeholders, and
  - human resources.
- Recently observed attack vectors such as crypto-ransomware or fraudulent wholesale payments are suitable bases for scenario-driven testing.

### Core areas to be covered by the principles
- Additional key areas to be covered include:
  - (i) governance,
  - (ii) strategy,
  - (iii) monitoring and detection,
  - (iv) response,
  - (v) recovery, and
  - (vi) information sharing.
- Principles should focus on establishing, implementing and reviewing cyber risk management processes, preventing materialization of cyber risks, and enabling containment of incidents (e.g., network segmentation).
- Guidelines should require development of effective detection, response, and recovery capabilities.

### Operational threat intelligence and information sharing
- Effective sharing of operational threat intelligence (e.g., indicators of compromise) requires trust relations between technical experts and a rulebook.
- The CSC membership is suited for strategic and tactical discussions on cyber threats; operational intelligence should be shared between:
  - information assurance and system/network operation professionals from financial institutions, and
  - members of national computer emergency response teams.
- Information handling procedures such as traffic light protocols should be agreed upon.
- Special platforms exist for information sharing between central banks, regulators, and supervisory entities in which the CBB could participate.

### Supervisory practices — assessment
- The CBB has adopted a general supervisory framework and methodology grounded on international best practices applicable for IT supervision.
- Onsite examination planning includes identification of IT expertise needed and preliminary information gathering.
- IT related inspections are primarily based on interviews and walkthroughs and may include on the spot correction of identified issues; the CBB formally follows up supervisory findings.
- Supervisory reporting is exception-based; institutions can comment on factual correctness before report issuance.
- Supervisors record existing control frameworks and concisely describe supervisory findings; reports detail open supervisory findings with recommendations and deadlines.
- Currently supervisors do not rate their findings.
- Supervisory IT examinations are conducted in collaboration with IT Department experts; expertise in information systems governance, processes, and technology is very limited within the supervision department.
- Reliance on internal experts may strain IT resources and pose a conflict of interest with the CBB’s payment systems oversight role.
- The CBB has started the hiring process for a dedicated IT supervisor.

### Supervisory practices — recommendations
- Develop a supervisory manual for IT/cybersecurity inspections aligned with cybersecurity guidelines and supervisory expectations that emphasizes:
  - review of cybersecurity strategies, policies, and responsibility specifications,
  - assurance on effectiveness of processes for cyber risk identification, assessment, and mitigation,
  - review of cyber risk reporting processes and effectiveness of oversight by independent functions (board of directors, internal audit, external auditors),
  - procedures probing resourcing of cybersecurity functions and third-party service provider management,
  - guidance on evaluating provisions for cyber incident response and resilience.
- Supervisory risk assessments should consider technical assessments by credible third-party assurance providers and the financial institutions’ internal audit, including:
  - internal and external audit reports,
  - independent security tests like penetration testing reports,
  - service provider mandated endpoint security assessments like SWIFT Customer Security Program self-assessments (preferably backed by independent assurance).
- Review management’s responses to prior issues to assess willingness to remediate shortcomings.
- Reliance on internal audit reports should be informed by the supervisor’s rating of internal audit quality and independence.
- Encourage cybersecurity self-assessments by financial institutions as part of pre-examination information requests addressing:
  - (i) cybersecurity governance and strategy;
  - (ii) presence of critical cybersecurity control measures and policies;
  - (iii) processes for cyber risk identification and assessment;
  - (iv) recent control effectiveness assessments;
  - (v) situational awareness of critical assets and threat landscape (e.g., up to date risk assessments);
  - (vi) third-party risk management; and
  - (vii) cybersecurity incident management.
- Consider including evidence supporting findings in examination reports or references to supporting evidence in work papers, and consider adoption of a rating scheme for findings.
- Place more emphasis on onsite control effectiveness examination procedures to understand implementation effectiveness.
- Decrease reliance on internal IT staff in the supervisory process and establish a dedicated IT supervision team composed of at least two inspectors with adequate expertise and qualifications.
- Ensure separation between supervisory/payment systems oversight activities and central bank IT operations.
- Recognize internationally recognized certifications as adequate background for IT supervisory activities, such as:
  - ISACA’s certified information systems auditor (CISA), and
  - (ISC)² Certified Information Systems Security Professional (CISSP).
- To attract and retain cybersecurity experts, the three most effective incentives identified are:
  - (i) offering significant training opportunities (including paying for security certification),
  - (ii) improving compensation packages, and
  - (iii) flexible work schedules.
- Consider relying on financial institutions’ internal audit to follow-up and report on resolution of findings if quality and independence are adequate.
- When planning the supervisory calendar, allocate capacity to ad-hoc examinations for unforeseen circumstances.
- The revisiting interval of one and a half year as specified in the CBB’s internal supervisory objectives is considered acceptable; consider differentiated intervals based on systemic importance and cybersecurity risk posture.
- Foresee spare capacity to deal with incidents and provide effective and timely supervisory response.

### Cyber resilience — BCM assessment: key findings
- DR at the CBB is facilitated by a partially redundant infrastructure, robust replication and backup system, comprehensive documented recovery procedures, and regular tests, providing reliable and timely recovery of critical IT systems.
- Key IT infrastructure components are redundant, including critical servers (TechOne, APSSS, and SWIFT), core network switches, firewalls, and the WAN link to the DR site in Belmopan; single points of failure are largely eliminated for critical IT services.
- It is unclear whether the WAN link to the DR site is physically redundant between the main and DR sites.
- The data center power supply includes an uninterruptible power supply capable of delivering enough power to the data center for 45 minutes, and two power generators at the opposite ends of the building with one month’s worth of fuel reserves; the generators can be activated within minutes and are regularly tested and maintained.
- Physical protection of the main data center is lacking: a large portion of an internally facing wall is of glass, fire suppression is inadequate with only one handheld extinguisher, and the large glass surface does not sufficiently shield electromagnetic radiation, making wireless exfiltration attacks more feasible.
- Critical systems’ data are replicated to the DR site in Belmopan in real time with appropriate recovery point objective (RPOs), minimizing data loss risk.
- Non-critical systems are backed up to tapes according to a predefined schedule; tape technology is relatively old but reliable if cartridges are used within specifications; an ongoing project is consolidating data backup.
- Regular recovery tests indicate a high degree of resilience for APSSS, TechOne and SWIFT; processing can be switched to the DR site within minutes without data loss, dependent on the WAN link availability.
- The CBB has an up to date hurricane plan tested each year before the hurricane season; shortcomings identified during tests are addressed in a timely manner.
- The CBB is upgrading the physical security management system (SMS) to support strong user authentication using smart card technology; SMS servers will run on a segregated network accessible through a dedicated firewall and the security control room is being retrofitted.
- The main building is designed to withstand major hurricanes and storm surges of up to 15 feet.
- Business continuity measures addressing alternate ways to run business processes are lacking: there are no contingency plans for alternate work arrangements and no stand-by office space if the main building becomes inaccessible.

### Cybersecurity governance assessment at the CBB
- Cybersecurity responsibilities are assigned to the IT Department; there is a security analyst who reports to the manager of the IT department and other staff perform security activities as needed.
- Internal audit has one staff training to become a CISA.
- The IT manager reports to the senior manager of corporate services who reports to the governor; this reporting line is considered adequate given the small size and organizational simplicity.
- An enterprise risk management (ERM) function has been recently established to coordinate risk management across functions; currently there is one relatively junior ERM staff with no cybersecurity expertise.

*Italic: Content derived from the source document 1blzea2020002 - 14.      Cyber risk management responsibilities for the board and senior management of*

### 47.      The inclusion of all cybersecurity related responsibilities in the IT Department,

### 1blzea2020002 - 47.      The inclusion of all cybersecurity related responsibilities in the IT Department,

### Governance and assurance findings
- The inclusion of all cybersecurity related responsibilities in the IT Department, in combination with little relevant expertise available in ERM and internal independent assurance functions increase conflict of interest risk.
- The internal audit department and the external auditor do not provide adequate compensating controls at this time.
- There is a very well structured and developed IT policy framework that addresses many cybersecurity areas. The IT department strives to maintain all policies and procedures and while some lag can be observed, key policies and procedures are up to date and actionable.
- Penetration testing by third parties provide a degree of independent assurance over the effectiveness of the cybersecurity control environment. The IT department remediates the findings of the tests.

### IT risk assessment and incident management
- The IT risk assessment done by the IT department is a good start, however improvements are necessary.
  - The risks identified are relevant in general, but not sufficiently specific to the CBB.
  - Risk ratings based on impact and likelihood assessments are missing.
  - Controls listed are more specific (for example they reference actual procedures) but their effectiveness is not assessed, and residual risks are not determined.
  - No evidence of risk acceptance and senior management signoff.
  - Remedial action cannot be defined and indeed it is missing.
  - Root cause appears to be the lack of formalized and methodology-based risk assessment expertise in the IT department.
- Incident management is not sufficiently formalized.
  - The IT department has developed a draft incident response plan based on the NIST Computer Security Incident Handling Guide.
  - While the plan requires the cooperation of other organizational units, there is no evidence on their involvement in the development of the plan nor on their acceptance thereof.
- Recommendation: The incident management plan should be circulated to involved business units, their feedback addressed, and the updated plan formally approved. Agreeing upon specific escalation criteria, processes and contacts forms an integral part of an effective incident management plan.

### Business Continuity Management (BCM) — findings and recommendations
- The BCM framework should be enhanced with several measures:
  - (i) initiating a BCP project;
  - (ii) assigning BCM responsibilities to all organizational units for the processes and resources they are responsible of;
  - (iii) providing sustained senior management support; and
  - (iv) improving the physical protection of the data center.
- The Board should designate a BCP project sponsor with sufficient authority to drive the cross-departmental work that is needed. Typically, this responsibility is often assigned to a senior executive role, such as the chief operations officer or a similar. The project sponsor should have a good understanding of the CBB’s operations and its operational risk profile.
- The BCP project should focus on alternative operations and standby facilities. At the same time, existing IT disaster recovery action plans (procedures) should be reviewed and updated as necessary. If the business impact analysis (BIA) phase of the project identifies resources lacking a recovery action plan those should be developed as well.
- As part of the project, attention should be paid to developing a BCM policy that addresses training, testing and maintenance of the plan, among others.
- All organizational units should participate in the BCP project, their main responsibilities being as follows:
  - (i) input to the BIA, such as identification and prioritization of processes and resources, setting recovery time objectives, and RPOs;
  - (ii) building action plans for alternate operations; and
  - (iii) participation in training, testing, and maintenance according to the BCM policy.
- While a specialized BCP software could be helpful, given the small size of the CBB it is unlikely that its benefits would be fully realized. Standardized templates developed with office applications can work well without any additional licensing costs. The downside of the approach is more manual work and the lack of an automatically enforced methodology.
- External support for the BCP project should be considered. Experienced BCP professionals can add value by bringing in a proven methodology, templates, techniques and practices that help avoiding common pitfalls and shorten the duration of the project.
- The plans should be regularly tested, and the test results should be used to improve them.
  - Tests should range from simple table-top exercises to more complex simulations and should be based on scenarios as realistic as possible.
  - After gaining experience, disruptive tests could be considered as well, whereby the data center is shut down and processing and key staff is transferred to disaster recovery locations. Such tests require extensive preparation and planning and are typically done less frequently.
- Assurance over the redundancy of the WAN link to the DR site should be obtained. This could be done by analyzing information from the telecommunications provider, including network architecture, equipment and line redundancy, and DR plans.

### Cybersecurity governance — recommendations
- Consideration should be given to the establishment of a cybersecurity function independent from IT.
  - The main responsibility of such a function would be to develop and maintain the cybersecurity governance framework and to control cybersecurity processes and systems.
  - Advantages of an independent cybersecurity function:
    - (i) it implements an independent control layer over security critical IT activities;
    - (ii) in the longer term it can concentrate scarce cybersecurity expertise which helps attaining critical mass needed for an effective cybersecurity function; and
    - (iii) it reduces the IT department’s workload.
  - This allocation of responsibilities is more closely aligned with how cybersecurity units operate at other central banks and many commercial banks.
  - Examples of processes and systems that could be controlled by the independent cybersecurity functions include identity and access management, perimeter defense, endpoint protection and anti-malware, web content filtering, data loss protection, and security information and event management.
  - Transfer of control from IT does not necessarily encompass transfer of ownership of the underlying infrastructure. The cybersecurity unit could act as a control point (for example, it approves firewall rules but does not run the firewall itself).
  - Other areas where the independent cybersecurity control is beneficial are IT architecture, system implementation projects, and use of third parties. For example, the unit’s signoff should be required on changes to the network architecture, on procuring or developing new systems, or on using cloud services.
- Given the CBB’s organizational structure, best options for the reporting line for the cybersecurity functions include the governor, corporate services, and security.
  - Reporting to the governor would increase visibility but distances the function from IT;
  - Reporting to security would consolidate all security related functions but has the same disadvantage.
  - Reporting to corporate services is probably the most balanced option because of the appropriate level in the hierarchy and closeness to the IT department.
- A formal cyber risk assessment process should be implemented. The process should:
  - (i) consistently apply a documented risk assessment methodology (usually qualitative);
  - (ii) define the risk appetite, for example, by setting the maximum level of acceptable residual risk;
  - (iii) require risk mitigation measures for all residual risks above the appetite;
  - (iv) ensure the involvement of the business units especially in risk identification and rating;
  - (v) require the risk mitigation measures to be documented in an action plan with deadlines and clearly identified responsibilities;
  - (vi) ensure the action plan gets appropriate funding;
  - (vii) ensure timely follow-up on the action plan; and
  - (viii) ensure regular updates and Board reporting.
- Staff responsible for the risk assessment should receive relevant training. Several development tracks for improving cybersecurity risk assessment skills could be considered, including:
  - (i) a series of courses like the ones provided by SANS Institute targeting both generalists (e.g., A Practical Introduction to Cyber Security Risk Management—MGT415) and IT experts;
  - (ii) review of international standards such as ISACA’s COBIT and Committee of Sponsoring Organizations of the Treadway Commission’s ERM framework; or
  - (iii) training for the CISSP or Certified Information Security Manager certifications.

### Next steps
- The CBB should develop an improvement plan to address the findings.

*Source: 1blzea2020002 - 47.*

---


_Source: https://www.imf.org/-/media/files/publications/cr/2020/english/1blzea2020002.pdf_
