TLP WHITE - FINAL
To meet these goals, the G-7 Fundamental Elements for Effective Assessment set out five
high-level components for entities in the financial sector to consider and embed when
developing cybersecurity assessment frameworks and conducting cybersecurity assessments.
Component 1: Establish clear assessment objectives.
Assessors establish explicit goals for assessment activities to provide clarity of motivation to
both assessor and assessed entity and to facilitate accountability. Clearly defined objectives
also support continuous improvement and learning.
Assessment objectives confirm the scope of the assessment, ranging from a focused
evaluation of a single entity (in part or in full) to an entire sector. Assessment scope also
defines the aspects of cybersecurity under review. For example, assessors may choose to
evaluate performance against a broad set of effective practices, such as the G7FE, or a
specific subset.
A number of factors may be considered when setting scope, combining both qualitative and
quantitative criteria, and minimizing gaps in the coverage. Scoping also establishes the
assessment perimeter, confirming inclusions or exclusions with regards to interdependencies
and supply chain relationships.
When establishing assessment objectives, assessors consider approaches to ensuring that
assessments are efficient and effective. In addition, variations in legal frameworks and
regulations are accounted for when spanning multiple jurisdictions. For complex entities such
as cross-border groups, multiple assessors may have an interest in the evaluation outputs.
Assessors with mutual interests and mandates are encouraged to liaise with each other to
ensure that significant interdependencies are identified, responsibilities are clearly defined in
advance, and conflicting requirements avoided.
Component 2: Set and communicate methodology and expectations.
Taking into consideration existing cybersecurity guidance and frameworks, assessors
establish clear and measurable expectations against which cybersecurity assessments are to
be conducted. These expectations are communicated to, and understood by, the entity or
entities before the assessment commences.
The methodology selected by assessors is aligned to the stated objectives and the complexity
of the entity under assessment. Proportionality of assessment can be achieved by following a
risk-based approach, taking into account the complex and dynamic nature of the cyber risk.
Component 3: Maintain a diverse toolkit and process for tool selection.
Given the complex and diverse nature of the cyber risk, a diverse portfolio of assessment
tools and techniques (‘toolkit’) permits effective cybersecurity assessments. Such a diverse
toolkit contains assessment methods to reflect the specific breadth, depth of coverage, or
maturity sought in a given assessment. It also gives assessors access to a variety of
approaches, suitable for a wide range of circumstances.
Toolkits for cybersecurity assessment may include, but are not limited to, desktop reviews,
self-assessments, on-site inspections, threat-based penetration testing, technical reviews
(‘deep dives’), thematic reviews, and exercises. Each tool may provide assurance on different
practices and each will have its own advantages and disadvantages. Use of multiple tools and
4