Cybersecurity Guidelines for FSTI Providers
9.
Basic Incident Response Plan
9.1.
Incident Response Team
Designate a small team or individual responsible for handling cybersecurity incidents.
·
·
Provide basic training on incident response protocols.
9.2.
Simple Incident Response Steps
Develop a clear incident response plan that includes detection, isolation, containment, recovery, and learning.
·
Ensure the plan is accessible and comprehensible by all relevant personnel.
·
Third-Party Risk Management
10.
10.1.
Vendor Risk Assessments
Conduct risk assessments on vendors or third parties to ensure compliance with security standards set by the FSTI Providers.
·
Periodically review and update vendor or third-party risk management policies and procedures.
·
10.2.
Continuous Monitoring
·
Implement continuous monitoring of vendors or third parties to detect and respond to changes in the vendor security ecosystem.
94
Made with FlippingBook. PDF to flipbook with ease