TLP WHITE - FINAL To meet these goals, the G-7 Fundamental Elements for Effective Assessment set out five high-level components for entities in the financial sector to consider and embed when developing cybersecurity assessment frameworks and conducting cybersecurity assessments. Component 1: Establish clear assessment objectives. Assessors establish explicit goals for assessment activities to provide clarity of motivation to both assessor and assessed entity and to facilitate accountability. Clearly defined objectives also support continuous improvement and learning. Assessment objectives confirm the scope of the assessment, ranging from a focused evaluation of a single entity (in part or in full) to an entire sector. Assessment scope also defines the aspects of cybersecurity under review. For example, assessors may choose to evaluate performance against a broad set of effective practices, such as the G7FE, or a specific subset. A number of factors may be considered when setting scope, combining both qualitative and quantitative criteria, and minimizing gaps in the coverage. Scoping also establishes the assessment perimeter, confirming inclusions or exclusions with regards to interdependencies and supply chain relationships. When establishing assessment objectives, assessors consider approaches to ensuring that assessments are efficient and effective. In addition, variations in legal frameworks and regulations are accounted for when spanning multiple jurisdictions. For complex entities such as cross-border groups, multiple assessors may have an interest in the evaluation outputs. Assessors with mutual interests and mandates are encouraged to liaise with each other to ensure that significant interdependencies are identified, responsibilities are clearly defined in advance, and conflicting requirements avoided. Component 2: Set and communicate methodology and expectations. Taking into consideration existing cybersecurity guidance and frameworks, assessors establish clear and measurable expectations against which cybersecurity assessments are to be conducted. These expectations are communicated to, and understood by, the entity or entities before the assessment commences. The methodology selected by assessors is aligned to the stated objectives and the complexity of the entity under assessment. Proportionality of assessment can be achieved by following a risk-based approach, taking into account the complex and dynamic nature of the cyber risk. Component 3: Maintain a diverse toolkit and process for tool selection. Given the complex and diverse nature of the cyber risk, a diverse portfolio of assessment tools and techniques (‘toolkit’) permits effective cybersecurity assessments. Such a diverse toolkit contains assessment methods to reflect the specific breadth, depth of coverage, or maturity sought in a given assessment. It also gives assessors access to a variety of approaches, suitable for a wide range of circumstances. Toolkits for cybersecurity assessment may include, but are not limited to, desktop reviews, self-assessments, on-site inspections, threat-based penetration testing, technical reviews (‘deep dives’), thematic reviews, and exercises. Each tool may provide assurance on different practices and each will have its own advantages and disadvantages. Use of multiple tools and 4

Select target paragraph3