21.12.2012 Views

Banking and Finance Sector-Specific Plan - U.S. Department of ...

Banking and Finance Sector-Specific Plan - U.S. Department of ...

Banking and Finance Sector-Specific Plan - U.S. Department of ...

SHOW MORE
SHOW LESS

You also want an ePaper? Increase the reach of your titles

YUMPU automatically turns print PDFs into web optimized ePapers that Google loves.

Implementation Action Milestone Security Partners<br />

Identify, evaluate, <strong>and</strong> update the<br />

current methodologies for validating<br />

assets, systems, <strong>and</strong> networks<br />

at the institution level.<br />

Daily Federal <strong>and</strong> State financial regulators <strong>and</strong> members<br />

<strong>of</strong> the private sector<br />

Collect data on critical assets. Annually The Treasury <strong>Department</strong>, the FBIIC agencies,<br />

<strong>and</strong> private sector partners<br />

Verify <strong>and</strong> review asset<br />

information.<br />

Annually The Treasury <strong>Department</strong>, the FBIIC agencies,<br />

<strong>and</strong> private sector partners<br />

Update asset data. As needed basis The Treasury <strong>Department</strong>, the FBIIC agencies,<br />

<strong>and</strong> private sector partners<br />

Assess Risks<br />

Conduct risk assessments <strong>and</strong><br />

mitigate vulnerabilities.<br />

Develop <strong>and</strong> review risk assessment<br />

methodologies for the<br />

sector.<br />

Establish <strong>and</strong> evaluate a screening<br />

process to identify <strong>and</strong> assess<br />

critical assets, systems, <strong>and</strong><br />

networks.<br />

Assess consequences, vulnerabilities,<br />

<strong>and</strong> threats.<br />

Identify <strong>and</strong> address sector<br />

dependencies.<br />

Prioritize<br />

Identify <strong>and</strong> prioritize systemically<br />

important assets, processes, <strong>and</strong><br />

networks.<br />

Measure Progress<br />

Daily per regulatory requirements Financial regulatory authorities <strong>and</strong> the private<br />

sector<br />

Annually The Treasury <strong>Department</strong>, the FBIIC agencies,<br />

<strong>and</strong> private sector partners<br />

Annually The Treasury <strong>Department</strong>, the FBIIC agencies,<br />

<strong>and</strong> private sector partners<br />

As-needed basis The Treasury <strong>Department</strong>, the FBIIC agencies,<br />

<strong>and</strong> private sector partners, DHS<br />

As-needed basis The Treasury <strong>Department</strong>, the FBIIC agencies,<br />

<strong>and</strong> private sector partners, DHS, <strong>and</strong> other<br />

critical sectors (Energy, Information Technology,<br />

Communications, Transportation)<br />

Annually The Treasury <strong>Department</strong>, the FBIIC agencies,<br />

<strong>and</strong> private sector partners

Hooray! Your file is uploaded and ready to be published.

Saved successfully!

Ooh no, something went wrong!