enterprisesecuritymag

OCTOBER - 2021ENTERPRISE SECURITY| | 9these breaches were due to basic control failures, such as weak access controls. The root cause may be poor threat awareness, lack of training or unclear data protection responsibilities. MSSP's monitor, detect, investigate and respond to threats 24X7. Such services are essential in today's threat environment but introduce another cost to the business. Optimising spend on security services requires a trusting partnership. The client is responsible for identifying their most critical digital assets (crown jewels), whilst the MSSP is best placed to identify the most likely threats to those assets. This should lead to prioritised security requirements, which help ensure the most critical data is protected against the most likely threats. An increasing cost of digital services can be attributed to security. This is money which might be spent on other business priorities, such as product innovation. Therefore, organizations have to define their risk appetite, which ensures security investments deliver the right level of risk reduction, and do not attempt to eliminate risk altogether. It is the role of Internal Audit to provide assurance to Senior Management that Enterprise Risks are managed in accordance with the risk appetite of the organisation. As the cyber security risk has become more threatening to businesses, audit functions have evolved their capabilities to ensure in-depth coverage of this control environment. When it comes to Third Party risk, Audit functions have historically had a strong focus on ensuring third parties have adequate security practices, evidenced by independent assessments and certifications. Whilst this is still important, it provides limited assurance, and could Steve Williamsoneven give a false impression that security risk is within tolerance. Internal Audit increasingly are increasingly focusing on client responsibilities, because this is more likely to be the source of control weaknesses. Control Objectives, for each IT process involving third parties may include:· A shared responsibilities agreement has been defined and is it being followed· Our staff have the necessary skills to fulfil their responsibilities· We have agreed our security requirements with the service provider, and these are aligned to our business risks· We have classified our organisational data (including what is being collected by the service provider), and specified retention and deletion requirements· Service performance metrics monitored, and can these be used to inform Key Risk Indicators In summary, CSP's and MSSP's provide capabilities beyond which most organisations can achieve on their own. The business value is risk reduction, achieved through lower likelihood of cyber-attack and improved data breach detection. Critical to success is commonly understood shared responsibility agreement. Senior Management require assurance that their investment in security is delivering the necessary risk reduction, and it is the role of Internal Audit to provide that assurance. Increasingly, Internal Audit focus on client responsibilities as this is often the source of control weakness. ES
< Page 8 | Page 10 >