TLP WHITE - FINAL
example, they can help inform Board discussions and Board oversight. The G-7 Fundamental
Elements for Effective Assessment are not meant to be prescriptive, and serve to inform
entities, supervisors and independent assessors alike. They can also be of use in regulatory
examinations, self-assessments, and independent review by third parties. Furthermore, these
elements can promote conversations across jurisdictions and sectors to drive both technical
and cultural conversations around effective practices for cyber risk management.
PART A: Outcomes associated with effective cybersecurity
Acknowledging that there are many ways to describe cybersecurity, the five desirable
outcomes below set out broad characteristics that a financial sector entity with a mature
understanding, delivery, and oversight of cybersecurity can demonstrate to an assessor.
Outcome 1: The Fundamental Elements (G7FE) are in place.
The G7FE provide the foundational elements for cybersecurity, both for entities who are in
the early stages of building cyber resilience and for those who are more mature.
The G7FE are wide ranging, reflecting the nature of the challenge. Effective cybersecurity
requires entities to maintain a cybersecurity strategy and framework (Element 1) and adapt or
reinforce their governance processes (Element 2). It requires risk and control frameworks,
including the relevant set of mitigation controls and protection mechanisms (Element 3) and
effective monitoring (Element 4). Clearly defined and regularly exercised response (Element
5) and recovery (Element 6) procedures are in place in case of disruptive cyber events.
Finally, information sharing (Element 7) and continuous learning (Element 8) reinforce each
G7FE and contribute towards strengthening overall cybersecurity.
Outcome 2: Cybersecurity influences organizational decision making.
Building on Element 1 (Cybersecurity Strategy and Framework) and 2 (Governance),
incorporating cybersecurity into entities’ normal decision-making processes, specifically by
including cyber risk management into these processes early, informs and facilitates strategic
outcomes across the organization. Cybersecurity should not be viewed as separate from the
concept, design, and operation of entities’ core business processes but as into a key strategic
consideration, both when developing new products and services, and when assessing the
effectiveness of business operations that utilize existing technology or infrastructures.
Active senior management or board-level engagement implies oversight of the design,
implementation and effectiveness of cybersecurity programs. Informed by information on
threats and vulnerabilities and their entity’s risk appetite, boards and senior management can
drive risk-management decisions, oversight, and accountability in both the short and long
term. As such, boards and senior management can use decision making to drive cybersecurity
programs beyond the traditional views of compliance.
Outcome 3: There is an understanding that disruption will occur.
Building on Element 3 (risk and control assessment), the layering of detective and protective
controls is critical, and reduces the likelihood of loss of availability, integrity or
confidentiality. However, mature entities recognize that it is impossible to guarantee a zerofailure environment. By adopting a mindset that operational disruptions will occur, key
decision makers understand that strategy-aligned investment choices seek a balance across all
aspects of the G7FE.
2