Critical baseline security practices for today’s threat landscape
featured
FS-ISAC Explained
The fundamentals of cybersecurity are essential to financial services firms’ security and business operations. FS-ISAC developed these 15 recommendations appropriate for all levels of cyber maturity, using a risk-based approach and Defense-in-Depth principles. Though some fundamentals are regulatory requirements, all are necessary, and will help financial services institutions at any level of cyber maturity remain secure and resilient. Click on the title for basic guidance and use the arrows for more advanced insights.
Know your network
Regularly update and patch software
Encrypt data at rest and in transit
Use strong passwords for every employee, device, and account
Require MFAs
Use a zero-trust, least privilege policy with MFA
Use VPNs
Use backup systems to duplicate data and system configurations
Develop an incident response plan specific to attack type
Use firewalls, configured closed by default, with active blocking
Train employees on their role in cybersecurity
Keep a log of system activity
Use secure configuration management
Incorporate application security controls
Harden your API controls
5
of 15
Resources
Related Reports
© Copyright 1999 - FS-ISAC, Inc. All Rights Reserved.