Cyber Risk Management - Getting Started - Establishing a Security Baseline
The equipment, devices, software, systems and networks that store and transmit your information and data may be continually under attack with the potential for corruption, theft or loss of the data and/or network service interruption. Cyber attacks can come from both domestic and international sources. A serious attack could shut down business operations for hours, days or weeks resulting in significant cost to business and adverse impact on market reputation.
To achieve an acceptable level of cyber security, it is a best practice to develop a written cyber security program that incorporates a defense in-depth strategy. This is a strategy based on the military principle that it is more difficult for an enemy to defeat a complex and multi-layered defense system than to penetrate a single barrier.
The Cyber Risk Management Customer Portal technical bulletins and self-assessment tool have been organized using the defense-in-depth strategy to provide security guidance within four key security disciplines: Program Administration, Information Security, Network Security, and Incident Response and Recovery. The security goal and technical guidance provided within each discipline include:
Program administration
To help you maintain a security program and controls that are aligned with your business strategy and needs.
- Cyber security team.
- Cyber security policies.
- Physical access controls for Information Technology (IT) security.
- Third-party cyber security vendor management.
Information security
To develop access privileges and control policies to help you maintain access to information that is commensurate with job responsibilities.
- Data inventory and classification.
- User access privileges and control policies.
- Password management.
- Cyber security training for employee.
- Human resource controls for data security.
Network security
To incorporate technological controls designed to help you maintain a balance between protecting against cyber breaches and not restricting business transaction needs.
- Information Technology (IT) equipment and systems inventory.
- Map and secure your network.
- Administrator privileges.
- Malicious software and malware prevention.
- Cyber risk and your company website.
- Network logging and monitoring.
Incident prevention and recovery
Implementing prevention and mitigation plans and establishing an incident response team to help you proactively respond if needed.
- Business continuity for data management.
- IT Incident response plan.
Management commitment and administration
An effective cyber security program begins with the commitment of management on both the business and technology sides of the house to develop and maintain a cyber security program, process and culture.
Senior leadership is responsible for setting the organizational strategic direction and assigning resources for the cyber security program. The direction should be aligned to support your business strategy. Similar to your business strategy, the program will require the support of all employees who have access to the company network or data. Management must communicate to all employees that information security is an important, routine part of their business process and each employee’s responsibility.
A budgeting process should be established specifically for cyber security to support development, implementation and maintenance of the program, including funding to correct discovered vulnerabilities.
Getting started
Travelers Cyber Risk Management Self-Evaluation Guide is a Word document that can be downloaded and maintained on your computer. To get started, we recommend that you use this self-assessment tool to enter completion dates for cyber risk management controls that you have already implemented. Do not enter dates for controls until they have been fully implemented. This will allow you to identify and assess potential gaps. A comment section is also provided for each control to assist you with tracking the status.
The self-assessment is intended to be a dynamic document that will allow you to make updates to the dates or comments as needed. As controls are completed or updated, enter the date of completion. At a minimum, we recommend you review and reconfirm all controls are properly implemented on an annual basis and re-date the item when completed.
The technical bulletins have been aligned with the self-assessment tools to provide additional guidance.
Establishing a security baseline
- Because many controls are dependent on the completion of a baseline set of controls, we recommend the following controls be given a higher priority for completion. Designate a Chief Information Security Officer (CISO) or equivalent.
- Develop comprehensive and clearly written cyber security policies to describe employee and third-party responsibilities for protecting sensitive information.
- Complete an inventory of all information, classify it by sensitivity level and assign user access privileges.
- Complete an inventory of all software, applications and equipment and assign owners for each.
- Confirm your information security controls are in compliance with all state and federal regulations and industry standards.
- If your company accepts payment by credit or debit cards, confirm the security is in compliance with PCI Security Standards Council standards.
Keeping your security program current
Information assurance and computer security is not a one-time activity. It is a continuous risk management process. The IT security objectives and policies can be reviewed regularly and adjusted to your business needs. Periodically conduct reviews of your cyber security program to verify the technological and administrative actions are working as intended. In addition, the program can be reevaluated whenever significant business, regulatory or technological changes have occurred and after any incident that required changes in your cyber program.
Third-party audits
Consider conducting scheduled audits of the cyber security program by a qualified auditor to reconfirm compliance with applicable security standards and your company’s cyber security policies.