Tandem
Board Member's Guide to Cybersecurity Assessments
Pages
6
Time to read
7 mins
Publication
Language
English
Pages
6
Time to read
7 mins
Publication
Language
English
This guide provides an overview of the role of a financial institution's Board of Directors in overseeing cybersecurity risk. It explains the importance of cybersecurity assessments as a tool for management to communicate the institution's cybersecurity program effectively. The document details the transition from the FFIEC Cybersecurity Assessment Tool (CAT) to new frameworks, emphasizing that while the CAT will sunset, the need for cybersecurity assessments remains critical. The guide outlines various frameworks that institutions may adopt, such as the NIST Cybersecurity Framework and the CIS Critical Security Controls, and discusses how these frameworks can help evaluate cybersecurity controls and identify areas for improvement. Additionally, it describes the Board's oversight responsibilities, including understanding assessment results, risk coverage, gap analysis, and remediation planning. The document also specifies the types of reports that Board members should expect to receive during this transition period.