SD-14.5 — Cyber & Information Security
Business Domain: BD-14 Enterprise Risk, Control & Assurance (Cross-cutting — corporate) · Applies: BOTH
Purpose
Protects the firm’s information assets and systems from cyber and information-security threats. SD-14.5 runs the firm’s security function — threat monitoring and response, access management, security testing, and the protection of the firm’s data. At an investment manager this is not a generic IT-security function: it carries an investment-management-specific weight — the protection of the investment book of record and of material non-public information, and it operates under financial-services-specific regulation (the EU Digital Operational Resilience Act — DORA, Regulation (EU) 2022/2554 — and its ICT-risk-management requirements, the SEC cybersecurity rules for advisers). It is not operational resilience and business continuity — that is SD-14.6, which keeps the firm running through disruption — though the two work closely; SD-14.5 defends the systems, SD-14.6 keeps the business services available.
Service Operations
- Monitor and respond to threats — monitor for cyber threats and run security-incident detection and response.
- Manage access and identity — control access to the firm’s systems and data — identity, authentication and the least-privilege model — including the protection of MNPI behind information barriers.
- Run security testing — penetration testing, vulnerability assessment and security assurance.
- Protect the firm’s data — apply the data-protection and information-security controls across the firm’s data estate, including the investment book of record.
- Govern the security framework — maintain the firm’s information-security framework and its security policy.
Inputs and outputs
- Inputs: the firm’s systems and data estate; the threat landscape; the cyber and data-protection regulation; the data-platform security requirements consumed by SD-13.12.
- Outputs: the security posture, incident-response records and the security framework — consumed by every domain (as the security standard they operate within), SD-14.1 and the regulators.
Entities
- Consumes: the firm’s systems and data records; the data-platform security requirements consumed by SD-13.12.
- Owns: the firm’s information-security framework — a process artefact.
Standards
- ISO 27001 — the information-security-management-system baseline (the general-enterprise standard SD-14.5 adopts).
- DORA (the EU Digital Operational Resilience Act, Regulation (EU) 2022/2554) — its ICT-risk-management requirements (Chapter II) and ICT-incident-reporting requirements (Chapter III); the SEC cybersecurity rules for investment advisers.
- UK / EU GDPR for the data-protection dimension.
Open extensions
- The investment-management-specific operations (the IBOR and MNPI protection) versus the ISO-27001 general-enterprise baseline.
- The interaction with SD-14.6 on ICT resilience.
- The Service-Operation-level input/output contracts.