Foreign Banking Organization operating in NYC
-
72
Countries
-
202K
Employees
-
€42.5B
revenue (2018)
-
600+
Branches & Business Centers
A foreign banking organization required insight into the adequacy of existing cybersecurity policies especially since there was no clear relationship between their policies, standards, guidelines and procedures.
The content of available policies also needed reconciliation with NYS DFS 23 NYCRR 500 requirements and industry leading practices to ensure they provided appropriate coverage for the policy domain.
Our approach centered around identifying how the organization was using applicable regulations, enterprise policies, standards, and procedures to better govern cybersecurity as an enterprise wide, strategic issue.
ISO/IEC 27001 formally defines the mandatory requirements for an Information Security Management System (ISMS) and was used as the policy benchmark for the Policy Review. DFS policy requirements were mapped and then overlaid with available/relevant client policies
Impact
- Increased Policy adherence rate
- Higher regulatory compliance score
- Higher patching and vulnerability management score
- Higher user training completion rate