SD-14.5 — Cyber & Information Security

Business Domain: BD-14 Enterprise Risk, Control & Assurance (Cross-cutting — corporate) · Applies: BOTH

Purpose

Protects the firm’s information assets and systems from cyber and information-security threats. SD-14.5 runs the firm’s security function — threat monitoring and response, access management, security testing, and the protection of the firm’s data. At an investment manager this is not a generic IT-security function: it carries an investment-management-specific weight — the protection of the investment book of record and of material non-public information, and it operates under financial-services-specific regulation (the EU Digital Operational Resilience Act — DORA, Regulation (EU) 2022/2554 — and its ICT-risk-management requirements, the SEC cybersecurity rules for advisers). It is not operational resilience and business continuity — that is SD-14.6, which keeps the firm running through disruption — though the two work closely; SD-14.5 defends the systems, SD-14.6 keeps the business services available.

Service Operations

  • Monitor and respond to threats — monitor for cyber threats and run security-incident detection and response.
  • Manage access and identity — control access to the firm’s systems and data — identity, authentication and the least-privilege model — including the protection of MNPI behind information barriers.
  • Run security testing — penetration testing, vulnerability assessment and security assurance.
  • Protect the firm’s data — apply the data-protection and information-security controls across the firm’s data estate, including the investment book of record.
  • Govern the security framework — maintain the firm’s information-security framework and its security policy.

Inputs and outputs

  • Inputs: the firm’s systems and data estate; the threat landscape; the cyber and data-protection regulation; the data-platform security requirements consumed by SD-13.12.
  • Outputs: the security posture, incident-response records and the security framework — consumed by every domain (as the security standard they operate within), SD-14.1 and the regulators.

Entities

  • Consumes: the firm’s systems and data records; the data-platform security requirements consumed by SD-13.12.
  • Owns: the firm’s information-security framework — a process artefact.

Standards

  • ISO 27001 — the information-security-management-system baseline (the general-enterprise standard SD-14.5 adopts).
  • DORA (the EU Digital Operational Resilience Act, Regulation (EU) 2022/2554) — its ICT-risk-management requirements (Chapter II) and ICT-incident-reporting requirements (Chapter III); the SEC cybersecurity rules for investment advisers.
  • UK / EU GDPR for the data-protection dimension.

Open extensions

  • The investment-management-specific operations (the IBOR and MNPI protection) versus the ISO-27001 general-enterprise baseline.
  • The interaction with SD-14.6 on ICT resilience.
  • The Service-Operation-level input/output contracts.

Built from open-investment-model v0.3.0 · f7452ad