U.S. SEC releases cyber security examination blueprint

Image
Reuters WASHINGTON
Last Updated : Apr 17 2014 | 3:47 AM IST

By Sarah N. Lynch

WASHINGTON (Reuters) - U.S. securities regulators have unveiled a road map that lays out how they plan to make sure Wall Street firms are prepared to detect and prevent cyber security attacks.

The nine-page document, posted April 15, contains examples of the questions Securities and Exchange Commission examiners might ask brokerages and asset managers during inspections.

The document puts firms on alert to be prepared, for instance, to provide a comprehensive list of when they detected malware, suffered a "denial of service" attack or discovered a network breach since January 2013. The SEC also plans examinations of more than 50 firms that will focus on cyber security-specific issues.

The document's release comes several months after Jane Jarcho, an associate director in the SEC's investment adviser examination program, announced in a speech the agency planned to scrutinize whether firms have policies to prevent cyber attacks. [ID:nL2N0L416A]

The SEC subsequently followed up with a March 26 roundtable where experts debated how public companies, brokerages, asset managers and exchanges can protect themselves from cyber threats, and what role the U.S. government should play to ensure such attacks are adequately disclosed. [ID:nL1N0MN0RB]

The heightened focus on cyber attacks comes at a time when several major companies, from Target Corp to Neiman Marcus Group, have suffered major data breaches.

The incidents have sparked a public policy debate about how customers should be alerted, who should bear the cost of breaches, and how such information should be disclosed both to government and the public.

John Reed Stark, the SEC's former chief of Internet enforcement and now a managing director with digital risk management consultancy Stroz Friedberg, said the SEC's detailed list of questions is both unusual and "forward-thinking."

"With the public disclosure of this questionnaire, the SEC is giving up the surprise of one aspect of their exam program and opting to provide to SEC-registered financial firms a rare chance to prepare," he said.

In addition to asking questions about past attacks, the SEC document also indicates that examiners might gather information about how firms protect private customer information. This includes checking to see how customers are authenticated to access online accounts and what security measures are in place to protect PIN numbers.

The list of possible questions can be found here: http://www.sec.gov/ocie/announcement/Cybersecurity+Risk+Alert++%2526+Appendix+-+4.15.14.pdf

(Reporting by Sarah N. Lynch. Editing by Andre Grenon)

*Subscribe to Business Standard digital and get complimentary access to The New York Times

Smart Quarterly

₹900

3 Months

₹300/Month

SAVE 25%

Smart Essential

₹2,700

1 Year

₹225/Month

SAVE 46%
*Complimentary New York Times access for the 2nd year will be given after 12 months

Super Saver

₹3,900

2 Years

₹162/Month

Subscribe

Renews automatically, cancel anytime

Here’s what’s included in our digital subscription plans

Exclusive premium stories online

  • Over 30 premium stories daily, handpicked by our editors

Complimentary Access to The New York Times

  • News, Games, Cooking, Audio, Wirecutter & The Athletic

Business Standard Epaper

  • Digital replica of our daily newspaper — with options to read, save, and share

Curated Newsletters

  • Insights on markets, finance, politics, tech, and more delivered to your inbox

Market Analysis & Investment Insights

  • In-depth market analysis & insights with access to The Smart Investor

Archives

  • Repository of articles and publications dating back to 1997

Ad-free Reading

  • Uninterrupted reading experience with no advertisements

Seamless Access Across All Devices

  • Access Business Standard across devices — mobile, tablet, or PC, via web or app

More From This Section

First Published: Apr 17 2014 | 3:40 AM IST

Next Story