TLP WHITE - FINAL example, they can help inform Board discussions and Board oversight. The G-7 Fundamental Elements for Effective Assessment are not meant to be prescriptive, and serve to inform entities, supervisors and independent assessors alike. They can also be of use in regulatory examinations, self-assessments, and independent review by third parties. Furthermore, these elements can promote conversations across jurisdictions and sectors to drive both technical and cultural conversations around effective practices for cyber risk management. PART A: Outcomes associated with effective cybersecurity Acknowledging that there are many ways to describe cybersecurity, the five desirable outcomes below set out broad characteristics that a financial sector entity with a mature understanding, delivery, and oversight of cybersecurity can demonstrate to an assessor. Outcome 1: The Fundamental Elements (G7FE) are in place. The G7FE provide the foundational elements for cybersecurity, both for entities who are in the early stages of building cyber resilience and for those who are more mature. The G7FE are wide ranging, reflecting the nature of the challenge. Effective cybersecurity requires entities to maintain a cybersecurity strategy and framework (Element 1) and adapt or reinforce their governance processes (Element 2). It requires risk and control frameworks, including the relevant set of mitigation controls and protection mechanisms (Element 3) and effective monitoring (Element 4). Clearly defined and regularly exercised response (Element 5) and recovery (Element 6) procedures are in place in case of disruptive cyber events. Finally, information sharing (Element 7) and continuous learning (Element 8) reinforce each G7FE and contribute towards strengthening overall cybersecurity. Outcome 2: Cybersecurity influences organizational decision making. Building on Element 1 (Cybersecurity Strategy and Framework) and 2 (Governance), incorporating cybersecurity into entities’ normal decision-making processes, specifically by including cyber risk management into these processes early, informs and facilitates strategic outcomes across the organization. Cybersecurity should not be viewed as separate from the concept, design, and operation of entities’ core business processes but as into a key strategic consideration, both when developing new products and services, and when assessing the effectiveness of business operations that utilize existing technology or infrastructures. Active senior management or board-level engagement implies oversight of the design, implementation and effectiveness of cybersecurity programs. Informed by information on threats and vulnerabilities and their entity’s risk appetite, boards and senior management can drive risk-management decisions, oversight, and accountability in both the short and long term. As such, boards and senior management can use decision making to drive cybersecurity programs beyond the traditional views of compliance. Outcome 3: There is an understanding that disruption will occur. Building on Element 3 (risk and control assessment), the layering of detective and protective controls is critical, and reduces the likelihood of loss of availability, integrity or confidentiality. However, mature entities recognize that it is impossible to guarantee a zerofailure environment. By adopting a mindset that operational disruptions will occur, key decision makers understand that strategy-aligned investment choices seek a balance across all aspects of the G7FE. 2

Select target paragraph3