INS 3081 - Cyber Risk & Insurtech Assignment Neil Camilleri ID: 416201(L) Contents Section A ................................................................................................................................................. 3 Question 1 ........................................................................................................................................... 3 Question 2 ........................................................................................................................................... 4 Question 3 ........................................................................................................................................... 5 Section B ................................................................................................................................................. 6 Question 1 ........................................................................................................................................... 6 A) ..................................................................................................................................................... 6 B) ..................................................................................................................................................... 7 C) ..................................................................................................................................................... 7 Question 2 ........................................................................................................................................... 8 Question 3 ........................................................................................................................................... 9 Question 4 ......................................................................................................................................... 10 Section C ............................................................................................................................................... 12 Question 1 ......................................................................................................................................... 12 Question 2 ......................................................................................................................................... 12 Question 3 ......................................................................................................................................... 12 References ............................................................................................................................................ 13 Section A Question 1 Money laundering is the illegal activity of disguising funds obtained through illegal actions such as prostitution into funds that appear to be legitimate and have been earned through legal means. As a result, the criminals can spend the money without raising any red flags since the money looks to have originated from a clean source. (FATF, n.d.) The three stages of money laundering are placement, layering and integration. The placement stage of money laundering is believed to be the most challenging stage for criminals. At this stage the money launder is extremely vulnerable and must be patient and cautious, as introducing a large sum of money into the system at once raises suspicion about where the cash originated from. (Anon., 2020). Over the years criminals have found unique and different ways of how to place their money. By adding the illicit funds to the revenue earned from cash-based business with low variable costs, such as a car wash or a car park, is a frequent tactic utilised to introduce the money into the system (ICAS, 2019). Another method of placing the funds is by sending those funds to offshore accounts in countries which do not have a reputable jurisdiction such as Panama and the Cayman Islands. Furthermore, launders also carry large amounts of illicit funds and deposit them into foreign banks which operate with less rigid regulation. (Business Money, 2020). Layering is the process of moving the funds around to further disguise the true source of the illicit funds. For instance, the launder will undergo different and complex transactions and move the money through different bank accounts in different countries through different financial institutions, each time a transaction is completed the source of the funds gets further complex for authorities to trace back to the original launder and crucially to the original source of income. (Anon., n.d.) Another common tactic used by launders to layer the funds is by exchanging cash for financial instruments such as shares, bonds and life insurance policies (Comply Advantage, n.d.). Layering is considered to be the most complex stage out of the three as it tries to confuse and bypass any form of anti-money laundering tests. The final stage in money laundering is integration. Here the illicit funds deposited in the placement stage are re-injected into the economy after being made to look like (laundered) funds from legal and legitimate sources. The way that the funds are reintroduced in the economy is either through a business investment on the markets, the sale of an asset which was bought during the layering stage or property purchases. (Sanction Scanner, 2020) At this stage it becomes extremely difficult to determine the differences between the legal and illegal wealth of the money launderer. Question 2 It is understood that insurance companies are exposed to a high number of risks when taking on business. Money laundering risk has become one of the predominant risks an undertaking needs to assess and evaluate when onboarding new clients. Money laundering risk is only relevant for insurance companies that sell life policies with an investment link.. (Lawrence, 2008). In light of ever-increasing financial crime, more specifically money laundering and terrorist financing, the Financial Action Task Force issued a set of recommendations to financial institutions on how to mitigate the risk of money laundering and terrorism financing. Recommendation 10 of the FATF guidelines highlights the importance of undergoing customer due diligence process on a riskbased approach (Know your customer) prior to onboarding a new client. (FATF , 2022). Customer due diligence is the process that employees working in the financial services industry go through to ensure that their client is actually who they claim to be and not a fraudulent person. In the case of an insurance broker, the broker will undergo a customer due diligence check on a risk-based approach on the proposer. (Mutiullah Olasupo, 2017). The financial institution will prompt a series of questions in order to get to know the customer, the institution will also request some documents from the potential client for verification purposes. The rationale for these questions and documents is so that the financial institution verifies and ensures that the client is of good faith and that the client is not involved in any legal proceeds such as corruption or terrorism financing. At the start of the process, the broker will prompt identification questions such as: name, addresses and an ID card number. The broker will request some verification to ensure that the information provided is accurate. At this stage, the proposer would be asked to provide an ID card and an electricity bill among other items as proof. Once this stage is completed the undertaking will undergo a risk assessment on the proposer ensuring no association with criminal activity. (Comply Advantage , n.d.). When dealing with high net-worth individuals or big transactions, standard due diligence checks may not be sufficient to quantify the increased risks, thus financial institutions undergo enhanced due diligence processes. When asking clients questions and documentation, enhanced due diligence requires more rigorous and robust information and proof. Furthermore, detailed documentation about the entire enhanced due diligence process needs to be made available to the local regulatory authority (Nicolls, 2019). Albeit customer due diligence is not something which is only completed at onboarding stage but rather something ongoing. Insurance undertakings monitor their clients through an ongoing due diligence process whereby transactions are monitored to determine any changes in the client’s risk profile which might indicate the possibility of fraud (SWIFT , n.d.) Due diligence processes are also conducted when dealing with businesses, this process is known as Know Your Business (KYB). The concept of KYB is the same as KYC; verifying that the company is the company which it is claiming to be. However, KYB processes are not as straightforward as KYC, the institution needs to gather more information about the business (client), information which is not easily accessible and not timely. (The Ramp Team , n.d.) Through a rigid and proper customer due diligence process, financial institutions are mitigating money launders introducing illicit funds gained from illegal activities into the financial system. If there aren’t proper anti money laundering tools in a given jurisdiction, illegal activities such as drug trafficking and prostitution will surge. Regulators and non-governmental bodies such as the financial action task force have been increasing the fines given to financial institutions who were found operating with inadequate anti money laundering and counter financing of terrorism processes. Therefore, apart from being subject to a regulatory risk, financial institutions are also exposed to a reputational risk if their AML/CFT processes are not sufficient with regulations. (Dakeyne, 2022) Question 3 In an effort to further fight money laundering and terrorism financing the Financial Action Task Force, the leading money laundering watchdog recommends (Recommendation 20) that every financial institution has in place internal controls to detect and report a suspicious activity. In Malta’s case a suspicious transaction report needs to be submitted with the Financial Intelligence Analysis Unit (FIAU) (FATF, 2022). A suspicious transaction or person is one which raises questions and alarm bells in any financial institution. However, there aren’t any standard characteristics which outline what exactly makes a transaction or person suspicious. One action could seem suspicious within the context of one account, and it could appear perfectly normal within the context of another account. Albeit through monitoring these transactions may be spotted. For instance, if a transaction is unlike any previous transactions in a particular account, that will start to raise some questions. In the case of an insurance broker, if a client who has an average salary of €30,000 wishes to assure his own life for €500,000 this will clearly raise some serious questions by the undertaking. When undergoing general KYC questions, the broker may also suspect that the proposer is linked to some criminal proceedings or terrorist financing. (Unit 21, 2022). The class of business which is prone the money laundering and terrorist financing is life assurance. This particular class of business requires large sums of premiums paid by the policyholder making them an ideal product for criminals to launder their proceeds. The financial action task force (FATF) along with recommendations has provided life insurance undertakings guidelines on mitigating money laundering and terrorism financing. Guideline 71-72 highlights the importance of monitoring the client’s products and determining any changes in their risk profile. The guidelines also explain how monitoring can be undergone manually or automated. Guidelines 73-75 highlight guidance on reporting any suspicious transactions. (FATF, 2018). When financial institutions identify and confirm a suspicion about a transaction or person, the financial institution is obliged to fill in a suspicious transaction report to the local financial intelligence unit. In the case of Malta, the report would be done with the financial intelligence unit (FIAU). This report may be filled electronically by the money laundering officer or the reporting officer of the undertaking. The first section of the report would require details about the entity submitting the report. Following this section, the money laundering reporting officer would be prompted to describe what type of suspicious activity is suspected. The report provides a list of a series of potential offences and the MLRO would tick the according offence. Afterwards, the report asks the MLRO for the main sign that the institution thinks there is suspicious transaction. Finally, the report asks for details of the business or subject person who is being suspected as being fraudulent. (FIAU, n.d.). As previously mentioned, life insurance undertakings are considered to be the most exposed to money laundering and terrorism financing. A pure example of a suspicious transaction is when a proposer takes out a life insurance policy on his/her own life. Life assurance policies require large sums of premiums especially if the sum assured is very high. The money launder would then benefit from a cooling off period where the policyholder would be able to revoke his contract. Albeit the criminal would be subject to a fee however the insurance company will refund a large amount of the initial premium paid in the form of a cheque of bank transfer. Through this process the money launderer would have used a life assurance policy to launder illicit proceeds (Central Bank of Bahrain, n.d.). The word Fintech represents two essential pillars in the financial services industry: finance and technology. In a world of rapidly changing technology, Fintech is relevant for all the financial services providers in the industry such as banks, investment firms and insurance. Financial service providers may be safer, more effective, and faster by incorporating artificial intelligence, blockchain technologies and other financial system technologies in their business model. Big data is a rather new technological tool which allows entities to capture analyse very large volumes of data whether it is structured or unstructured. Big data and artificial intelligence in combination helps financial service providers in detecting fraud by monitoring and identifying unusual patterns with regards to a suspicious transaction (Șcheau, et al., 2022). The Financial Action Task Force (FATF) published a report in 2021 that highlighted both the benefits and difficulties that technology presents in terms of money laundering and terrorist financing. The report highlights the importance of technology in light of combatting money laundering and terrorist financing. Technology can facilitate faster and more accurate data collection which results in easier management regarding money laundering and terrorist financing. The report further explains how artificial intelligence may be incorporated in business models to identify new potential risks and to identify suspicious activity and how technology has introduced faster payment systems and transactions helping regulators and money laundering combaters trace the true source of the origins of the illicit funds during the second stage of the money laundering process. Technology will also benefit the regulators and supervisory authorities as it improves risk assessments for financial institutions and auditability. (FATF, 2021). Section B Question 1 A) Organic marketing is a relatively new marketing strategy that businesses are increasingly employing. Organic marketing refers to any type of digital marketing that does not rely on paid advertisements and is usually associated with social media such as ‘Instagram’ or ‘TikTok’ and search engine optimisations. (Bold Eye Media, 2021). An example of organic marketing is when a firm, rather than paying for a sponsored Instagram advert, creates its own advert and posts it on the company’s own Instagram page. Organic marketing also includes search engine optimisation, which is the process of configuring a website so that it can be easily accessed by search engines. (Anon., 2019). Similar to organic marketing, paid digital marketing campaigns are also very popular. When marketers choose to invest in a sponsored digital marketing campaign, they are looking for rapid results. Marketers want to transform their social media followers into customers. From a financial and sales standpoint, a company views this strategy as an investment, and like any investment, the company expects a return. Examples of a paid digital marketing campaign includes paid adverts on social media and investing in directing traffic towards the company’s website. (Anon., n.d.) Organic marketing does come with its fair share of benefits; it is a really good way to advertise a company’s products at incredibly low cost to set up and to maintain. Furthermore, since organic marketing is more natural than paid advertising, it is perceived as being more genuine and trustworthy. (Rock Content, 2021) Albeit organic marketing does have its drawbacks. It is time consuming; competition is also very high so business must post new content frequently. Another drawback is the fact that marketers can’t target a specific audience for their product, they have little control over who sees their content. (Cormier, 2020). A paid digital marketing campaign has the advantage of providing marketers with critical data such as where sales are originating from, this can be achieved using platforms such as Google Analytics. Another benefit is that it helps build brand awareness fast; sponsored adverts provide quick recognition, whereas organic marketing takes months to develop. (Burt, n.d.) One disadvantage of a sponsored digital marketing campaign is that the target audience often disregards it as consumers believe they are being forced to view their advert. Another disadvantage is cost; paid digital adverts are usually not cheap and have an expiry date, so marketers must make their adverts stand out and credible in order to maximise their return. (Burt, n.d.) Porto Insurance brokers should use a mixture of both organic and paid digital marketing campaigns. Since the institution is new to Malta, it will have little to no brand recognition. As a result, PIB should pursue a paid digital marketing strategy involving a sponsored social media advert on ‘Facebook’ or ‘Instagram’. Additionally, PIB can also pay to have search engine traffic directed to their website creating brand awareness with potential customers. Furthermore, PIB should also undergo an organic marketing strategy by creating social media pages for Porto Insurance Brokers to further enhance the organisation’s brand awareness and to familiarise the company with the target audience of the company in the long run. (Mehta, 2020). B) C) Relevant data is considered to be a very important asset for organisations especially ones which operate in the financial services industry. A database is a collection of organized data (reduced redundancy) used by the firm to analyse, retrieve, facilitate easier search, and manipulate data. Most business use relational databases because they provide faster data access. Data is organised in tables made up of rows and columns, and these tables connect similar data objects. (Wang, 2021). As the name implies, a data warehouse is a place where businesses store large amounts of historical data. As previously stated, data is a valuable asset and is becoming an increasingly crucial tool for management to make important choices. A fundamental distinction between a database and a data warehouse is that whilst a database is used to perform vital operations while running the business, a data warehouse is used by the management body in data analysis. (Lithmee, 2018). Moreover, unlike a database only a few key personnel within the firm would have access to the data in a data warehouse. A data warehouse, unlike a regular database, can retain large amounts of data from previous years. (Anon., 2019). For Porto Insurance Brokers it is definitely a necessity to have both a data warehouse and a database. For insurance companies such as PIB, it would be effective to use a different database for different departments within the undertaking such as claims and underwriting which will store important data gathered every day. Furthermore, PIB should include a primary key in their database, which serves as a unique form of identification for database users to analyse data from the table swiftly. The primary key field must not contain any null values and the data must be unique. An example of a primary key for PIB would be “Policyholder Number” or “Claim Number”. (Rabelo, 2020). Because PIB is a relatively new insurance broker, it will have little to no data in its warehouse; but as the company undertakes more business and it starts to grow, every piece of data will become increasingly vital for their future. In the case of an insurance company, a data warehouse combines and integrates data to display historic trends which help risk managers in assessing the undertaking’s risk appetite and calculate different premium rates for several types of insurance business something which wouldn’t be possible with a normal database. (Shakeel, 2022). Big data is data which is considered too big for standard computer programs to process, this data can be both structured and unstructured. Data is of utmost importance for every company especially insurance companies. Undertakings are nowadays bombarded with structured and unstructured data; the challenge is how to transform this big data into something which the undertaking can actually benefit from. Combining artificial intelligence and machine learning allows undertakings to transform big data into something which can be computed and analysed in an effective manner. (Artifical , 2020). There are a number of diverse ways how PIB can benefit from using big data. For instance, using big data effectively makes the premiums charged more accurate as underwriters can benefit from enhanced risk transparency and understand their customer behaviour more accurate. (Rakowsky, 2020). Undertakings especially those that offer life insurance products are subject to money laundering and terrorism financing frauds. The combination of big data and artificial intelligence will also help PIB in detecting any suspicious transactions (Șcheau, et al., 2022). Question 2 Cryptography is a technological process that uses codes to protect data and communications. This is done so that the information and communications can only be read, processed, and understood by the intended receiver. (Richards, n.d.). A basic encryption system is better known as systematic encryption. Data is encrypted by scrambling it so that it cannot be understood by anybody other than the receiver. Both the sender and the receiver must have access to the same key. As a result, the receiver must decrypt the message using the same key used initially by the sender. Once the receiver enters the key, the data is decrypted back into a readable format. (Tiwari, 2020). With regards to the key, this may either be a password, code or a random combination of number and letters generated by a secure random number generator. Predominantly there are two different types of systematic encryption algorithms: block algorithms and stream algorithms (Smirnoff & Turner, 2019). Moreover, asymmetric encryption uses two types of keys: a public key and a private key, these keys are separate, but they are still mathematically linked together. The public key is the key which would be publicly available to anyone who wishes to encrypt a message within the organisation. However, the message or data is then decrypted by a private key. For asymmetric encryption to work, the private key must be safeguarded and kept in secret which is why only the software, server or authorised employee would have accesses to a private key. (Mehta, 2020). Systematic encryption moves larger amounts of data and moves it a faster rate compared to asymmetric encryption. (Tiwari, 2020). An insurance company such as PIB is subject to high levels of regulatory requirements. Cyber risk has become one of the predominant risks that undertakings need to manage. As mentioned above asymmetric encryption transfers data more securely which is why PIB should utilise an asymmetric encryption system for their data transfers. Question 3 Governance: Governance is the process that an organisation goes through to make decisions that will ultimately meet the organisation’s long-term goals. At the basis of good governance is dependent data entity, this data entity will provide the directors of the organisation to take and make well informed decisions. (Mcmenemy, 2019). The shareholders of the respective organisations are considered to be in the driving seat and are expected to establish good governance by choosing an adequate board of directors, they will go on implementing the corporate strategy. Organisations especially financial services providers are exposed to a high degree of risk, having good governance in place will help in mitigating those risks. (Careers In Audit , 2020). IT Governance: Nowadays, practically every organisation no matter how big or small is dependent on some form of information technology. According to research performed by the institute for Businesses Value (IBM), executives, employees, and consumers throughout the world selected technology as the leading external force for 2022, posing a threat to productivity and profitability. (IBM, n.d.). Given the importance of technology and how reliant organisations are on it, the management body must strike a perfect balance between how much to invest and when to invest in technology as well the risks that come with it, such as misuse or underuse. Decisions on investments on an organisation’s information technology systems are no longer solely made by the IT department but rather by the management body using a risk-based approach. This is where IT governance comes into play. (Mathenge, 2022) ISO 38,500 provides the management body of organisations with instructions on how to use information technology in a way that is effective, efficient, and suitable to their corporate strategy. Furthermore, IT governance is defined as a framework to ensure directed and proper control over the usage of information technology applications as per ISO 38,500. (ISO , n.d.). Poor IT governance can essentially bring a company on its knees. The result of poor IT governance was a consequence that the board of directors of Knight Capital suffered back in 2012. Knight Capital was an electronic trading and market making organisation and in 2012 it suffered an software glitch, the software purchased hundreds of millions worth of stocks from a number of different companies without anyone telling it to do so. This resulted in the company loosing 440 million dollars in a matter of 2 days. (Tabbaa, 2018) The incident was simply a result of poor IT governance, Knight Capital had just implemented a new software however the software was not stress evaluated effectively. The organisation also lacked an effective disaster recovery plan that would have helped to reduce the overall impact. Furthermore, the board of directors were not assessing the impact of a technological risk in relation to business performance, they were concerned with their software going out of date and loosing big customers. (Heusser, 2012) Information Security Governance: Information security governance isn’t something solely implemented by the chief information security officer but rather something more holistic. It includes employees, processes, and technology as well as a clearly defined organisational structure, assigned roles, responsibilities and mechanisms responsible for overall oversight. (Bellero, 2020). The international standard for information security governance (IS0 27,014) explains how essential information security is in a time of increased cyber attacks and increased regulatory requirements. Moreover, the standard explains the consequences of an organisation failing to implement information security protocols on its stakeholders. The standard defines information security governance as an organisation in the financial services industry utilising all of its resources mentioned earlier (employees etc) to ensure information security. Moreover, ISO 27,014 stresses assurance that all directives with regards to information security governance are complied with and that the governing body of the organisation receives dependable data and adequate reporting on information security. (ISO, 2020). IT Audits & IT Governance: Due to large volumes of data and information security breaches, technology is one of the most significant hazards that organisations face, particularly insurance companies. Organisations are heavily dependent on technology, non – compliance with rules and regulations may lead to hefty fines and potentially an insurance company may have its license revoked. An Information technology audit will analyse the organisations technological assets. It will analyse software and hardware operations alongside technological processes which the company uses to ensure compliance with regulations and polices. (Kuhn, n.d.). Information technology auditing is at the heart of proper Information technology governance since the audit is analysing processes, structure and mechanisms which formulate IT governance. An IT audit fosters positive IT governance therefore, an IT audit should not be perceived as something negative or an extra cost for the organisation. Moreover, an IT audit provides the management body of the organisation with piece of mind regarding compliance and governance assurance. (Merhout & Havelka, 2008). The IT audit will provide the management body with what can be improved with regards to technology and ultimately what the organisation needs to change and improve regarding the IT governance system the organisation has in place. (Pacholczyk, 2022). Question 4 Organisations in every industry no matter how big or small they are always prone to certain risks. These are external risks that the organisation would have no control over and hence will not have an answer on how to mitigate that particular risk. Examples of such risks include the Covid-19 pandemic, the Russia – Ukraine war and 9/11 Terrorist attacks among other events. Both the pandemic and the war negatively impacted all organisations, some companies were impacted more than others and those organisations that lacked some sort of plans could not partially reduce the impact. (Anon., 2019). The management body of PIB should tailor make a business continuity plan for their insurance company. This plan is essentially a document which sets out a number of preventative strategies in the event that a risk materialises, and the organisations normal operations are disrupted as a result of that external peril. A business continuity plan should incorporate distinct types of risks that the organisation is exposed to such as regulatory risks, a fire materialising at the premises and technological risks with respect to data loss and even website and server downtime. The undertaking should appoint a business continuity manager and a representative from each department. By doing so the business continuity plan would involve an appropriate strategy for business continuity in a holistic manner across the organisation. (Magret, n.d.). Moreover, the BCP needs to be something which is reviewed regularly. Organisations are constantly faced with new risks that if were to materialise can lead to sever disruptions on the organisation’s operations and financial stability. The first step in developing a successful business continuity plan is to conduct a business impact analysis (BIA). The business impact analysis involves the business continuity team brainstorming all possible risks that the organisations is exposed to. It needs to consider various types of risks such as market risks, natural disasters and perhaps the most important; technological risks including cyber risks and loss of data. An assessment of the risks mentioned will provide the BCP team with a picture of how the organisation would fair if any of the risks were to materialise. However, the business impact analysis is not simply a risk assessment of some of the risks that the organisation is vulnerable to. (MacNeil, 2021) The BIA will identify the risks, assess the risks, and measure the risks impact on the organisation’s operations and financial stability. Perhaps the most important feature of conducting a business impact analysis on a riskbased approach is that BCP team will be able to determine the most crucial functions and commence a recovery plan for the organisation to maintain operation. (ZHAO, 2022). The BCP will make sure that employees can work in a safe environment in the event of a crisis materialising. For instance, when the pandemic commenced in 2020, many organisations offered teleworking for their employees, reducing exposure to the virus whilst miniating a safe working environment. In the event of teleworking, the organisation needs to be initiative-taking. The BCP should highlight communication channels as well as regular reporting on the situation. (Hout, 2020) As mentioned throughout this assignment, data is one of the essential pillars of any organisations especially insurance undertakings such as PIB. Natural disasters and negative events such as hurricanes and floods can cause an organisation’s entire IT infrastructure to be completely destroyed. Organisations need to take pre-cautionary measures to try and reduce the impact by developing a reliable disaster recovery plan within the business continuity plan. Disaster recovery plans have gained importance following Hurricane Katrina in New Orleans, many organisations in the state had their entire IT systems wiped out due to floods. Organisations could have taken a step forward instead of starting all over again had they had in place an adequate disaster recovery plan. In the event of a crisis, the fundamental principles of a disaster recovery plan are to assist the organisation in getting the system back online in the quickest possible time. By not having an effective disaster recovery plan, organisations are vulnerable against data loss. PIB will undoubtedly have large amounts of data, one important disaster recovery mitigation measure is storing important data in a remote location rather than in the same office building. Some other important factors that PIB should outline in their disaster recovery document is details regarding communication channels and the network infrastructure. (Omar, et al., 2011). The business continuity document needs to be stress tested and reviewed on a continuous basis. Testing is a very important component of the business continuity life cycle. PIB needs to perform drills and evacuation and processes as the business continuity plan. PIB should assign tasks to individual employees so that in the event of a disaster, every will know who and what needs to be done. The IT department has a crucial role in testing, they need to continuously monitor and test their normal IT systems as well as their back-ups in the event of a crisis materialising. Following the tests, the business continuity plan needs to be reviewed. The team should ask for feedback on how they believe the tests where. The review will highlight areas which the BCP mitigated well and areas which need improvement. (Milano, 2021). Section C Question 1 Question 2 ISMS stands for information security management system. ISMS is a framework implemented within an organisation which provides a systematic approach in managing the entity’s information security. Through an information security management system, the management body is able to manage, monitor, review and implement improvements regarding the entities information security system. Policies, procedures and controls are used to construct an information security management system that meets the three information security goals: integrity, availability, and confidentiality. (Irwin, 2021). The international organisation for standards (ISO) has delivered organisations with a set of guidelines on preparing, establishing, implementing, maintaining and enhancing the organisation’s information security management system. ISO 27,001 highlights the importance of having an information security management system well established within the entities structure. (ISO, 2013). ISO 27,001 provides organisations with a cyclic model better known as “Plan-do-check-act” (PDCA). This cyclic model’s objective is to ensure organisations establish, implement and monitor the information security management framework of the respective organisation. (Susanto, et al., 2011). Question 3 Risk management has always been a crucial factor for organisations however, after recent economic events such as the financial crisis of 2007/2008, risk management became extremely important. Today organisations are continuously exposed to new risks that they to assess and manage. Moreover, organisations are also heavily dependent on information technology hence the need for risk management on risks such as information security alongside cyber security. Both Cyber security and information security are two areas of growing concerns for the management body of an organisation. (Darby, 2019). In continuation with the above, information security risk management is essentially a systematic risk-based approach process ensuring that risks relating to information security are adequately managed. The process requires risk managers to identify, analyse and assess potential risks that the organisation is exposed to with regards to IT risks such as cyber security. Furthermore, risk managers must understand the organisation’s own risk appetite and try to tailor their approach to eliminate those risks which aren’t tolerated by the organisation. (Rapid7, n.d.) The first step risk managers must take when doing an information security risk assessment is identify all of the organisation’s technological assets such as the organisation’s confidential data and employee’s personal data among other assets. Secondly, risk managers must safeguard those assets which were established during the first step. This may be done through education regarding proper handling of the organisations confidential data and appointing a security officer whose role would be assigned to focus on data security risk assessment followed by creating risk mitigation techniques. Thirdly risk managers must implement data security mechanisms alongside formal policies. Afterwards, risk managers must assess the security controls implemented in the step before, risk managers need assurances that security controls are all working as they should be and are all updated. The risk management framework implemented needs to be monitored on a continuous basis ensuring the safety of the organisation’s technical assets. (Dobran, 2019) The international organisation for standards (ISO) provides organisations with guidelines on information security risk management: ISO 27,005. This standard was updated in 2018 and at the time of writing is currently being reviewed for another update. Moreover, ISO 27,005 supports the main guidelines outlined in ISO 27,001 and in ISO 27,002 on a risk management approach. What is worth mentioning is that IS0 27,005 does not provide organisations with one method on how organisations should manage their information security, but it provides guidelines regarding information security risk management. (ISO , 2018). References Anon., 2019. 4 Major Risks of Not Having a Business Continuity Plan. [Online] Available at: https://www.agilityrecovery.com/article/4-major-risks-not-having-business-continuityplan#:~:text=Financial%20loss%20may%20be%20among,is%2C%20the%20higher%20the%20losses. [Accessed 8 May 2022]. Anon., 2019. Difference between Database System and Data Warehouse. [Online] Available at: https://www.geeksforgeeks.org/difference-between-database-system-and-datawarehouse/ [Accessed 13 April 2022]. Anon., 2019. What is organic marketing and why should you be using it?. [Online] Available at: https://the-oop.com/why-you-need-organicmarketing/#:~:text=Organic%20marketing%20refers%20to%20any,video%20sharing%2C%20influenc ers%20and%20SEO. [Accessed 15 April 2022]. Anon., 2020. 3 Stages of Money Laundering and 5 Ways to Combat It. [Online] Available at: https://www.blockpass.org/2020/08/06/3-stages-of-money-laundering-and-5-ways-tocombat-it [Accessed 12 April 2022]. Anon., n.d. Layering in Money Laundering: Everything You Need To Know. [Online] Available at: https://www.tookitaki.ai/compliance_hub/layering-in-money-laundering/ [Accessed 12 April 2022]. Anon., n.d. What is the difference between organic and paid marketing?. [Online] Available at: https://businessdegrees.uab.edu/blog/what-is-the-difference-between-organic-andpaid-marketing/ [Accessed 13 Apri 2022]. Artifical , 2020. What is big data in insurance?. [Online] Available at: https://artificial.io/company/blog/what-is-big-data-in-insurance [Accessed 7 May 2022]. Bellero, L., 2020. Information Security Governance: 5 Tips for New CISOs [Cheat Sheet]. [Online] Available at: https://deltarisk.com/blog/information-security-governance-5-tips-for-new-cisoscheat-sheet/ [Accessed 7 May 2022]. Bold Eye Media, 2021. What is organic digital marketing?. [Online] Available at: https://boldeyemedia.com/blog/what-is-organic-digital-marketing/ [Accessed 15 April 2022]. Burt, S. J., n.d. Organic vs. Paid Marketing: Where Should You Invest?. [Online] Available at: https://www.writeraccess.com/blog/2020-06-organic-vs-paid-marketing/ [Accessed 13 April 2022]. Business Money, 2020. Anti-money laundering – the three stages of money laundering explained. [Online] Available at: https://www.business-money.com/announcements/anti-money-laundering-the-threestages-of-money-laundering-explained/ [Accessed 12 April 2022]. Careers In Audit , 2020. The Importance of Corporate Governance in an Organisation. [Online] Available at: https://www.careersinaudit.com/article/the-importance-of-corporate-governance-inan-organisation/ [Accessed 7 May 2022]. Central Bank of Bahrain, n.d. Examples of Suspicious Transactions. [Online] Available at: https://cbben.thomsonreuters.com/sites/default/files/net_file_store/CBB_Vol3_AppendixFC_iv_Exa mples_Jan2007.pdf [Accessed 30 April 2022]. Comply Advantage , n.d. What is KYC?. [Online] Available at: https://complyadvantage.com/insights/kyc/ [Accessed 30 April 2022]. Comply Advantage, n.d. Layering in AML - What Is Layering In Money Laundering?. [Online] Available at: https://complyadvantage.com/insights/money-launderinglayering/#:~:text=There%20are%20numerous%20approaches%20to,accounts%20within%20the%20s ame%20institution. [Accessed 12 April 2022]. Cormier, L., 2020. Organic vs. Paid Social Media: Pros and Cons. [Online] Available at: https://blog.imageworksllc.com/blog/organic-vs.-paid-social-media-pros-and-cons [Accessed 13 April 2022]. Dakeyne, O., 2022. The importance of customer due diligence. [Online] Available at: https://www.wealthadviser.co/2022/03/04/309616/importance-customer-duediligence [Accessed 30 April 2022]. Darby, M., 2019. Information Security Risk Management Explained – ISO 27001. [Online] Available at: https://www.isms.online/iso-27001/information-security-risk-management-explained/ [Accessed 10 May 2022]. Dobran, B., 2019. Information Security Risk Management: Build a Strong Program. [Online] Available at: https://phoenixnap.com/blog/information-security-risk-management [Accessed 10 May 2022]. FATF , 2022. The FATF Recommendations. [Online] Available at: https://www.fatfgafi.org/media/fatf/documents/recommendations/pdfs/FATF%20Recommendations%202012.pdf [Accessed 30 April 2022]. FATF, 2018. GUIDANCE FOR A RISK-BASED APPROACH. [Online] Available at: http://www.fatf-gafi.org/media/fatf/documents/recommendations/pdfs/RBA-LifeInsurance.pdf [Accessed 30 April 2022]. FATF, 2021. Opportunities and Challanges of New Technologies for AML/CFT. [Online] Available at: https://www.fatf-gafi.org/media/fatf/documents/reports/Opportunities-Challenges-ofNew-Technologies-for-AML-CFT.pdf [Accessed 7 May 2022]. FATF, 2022. FATF Reccomendations. [Online] Available at: https://www.fatfgafi.org/media/fatf/documents/recommendations/pdfs/FATF%20Recommendations%202012.pdf [Accessed 30 April 2022]. FATF, n.d. Money Laundering. [Online] Available at: https://www.fatf-gafi.org/faq/moneylaundering/ [Accessed 12 April 2022]. FIAU, n.d. Suspicious Transaction Report. [Online] Available at: https://fiaumalta.org/wp-content/uploads/2020/06/STR.pdf [Accessed 30 April 2022]. Heusser, M., 2012. Software Testing Lessons Learned From Knight Capital Fiasco. [Online] Available at: https://www.cio.com/article/286790/software-testing-lessons-learned-from-knightcapital-fiasco.html [Accessed 7 May 2022]. Hout, O., 2020. 5 Essential Steps to Business Continuity Planning. [Online] Available at: https://www.agilityrecovery.com/article/5-essential-steps-business-continuity-planning [Accessed 9 May 2022]. IBM, n.d. 5 trends for 2022 and beyond. [Online] Available at: https://www.ibm.com/thought-leadership/institute-business-value/report/businesstechnology-trends-2022 [Accessed 13 April 2022]. ICAS, 2019. AML Awareness: Three stages of money laundering. [Online] Available at: https://www.icas.com/professional-resources/anti-money-laundering-resources/latest- developments/aml-awareness-three-stages-of-money-laundering [Accessed 12 April 2022]. Irwin, L., 2021. What an ISMS is and 5 reasons your organisation should implement one. [Online] Available at: https://www.itgovernance.eu/blog/en/what-is-an-isms-and-why-does-yourorganisation-need-one [Accessed 11 May 2022]. ISO , 2018. Information security risk management. [Online] Available at: https://www.iso.org/obp/ui/#iso:std:75281:en [Accessed 10 May 2022]. ISO , n.d. Information technology — Governance of IT for the organization. [Online] Available at: https://www.iso.org/obp/ui/#iso:std:iso-iec:38500:ed-2:v1:en [Accessed 15 April 2022]. ISO, 2013. Information security management systems — Requirements. [Online] Available at: https://www.iso.org/obp/ui/#iso:std:iso-iec:27001:ed-2:v1:en [Accessed 11 May 2022]. ISO, 2020. ISO/IEC 27014:2020(en). [Online] Available at: https://www.iso.org/obp/ui/#iso:std:iso-iec:27014:ed-2:v1:en [Accessed 7 May 2022]. Kuhn, J., n.d. Information Technology Audits: Definition & Example. [Online] Available at: https://study.com/academy/lesson/information-technology-audits-definitionexample.html [Accessed 8 May 2022]. Lawrence, S., 2008. Money Laundering in the Insurance Industry. [Online] Available at: https://www.worldcheck.com/media/d/content_pressarticle_reference/aisaninsurance_08.pdf [Accessed 30 April 2022]. Lithmee, 2018. Difference Between Database and Data Warehouse. [Online] Available at: https://pediaa.com/difference-between-database-and-data-warehouse/ [Accessed 13 April 2022]. MacNeil, C., 2021. What is a business impact analysis (BIA)? 4 steps to prepare for anything. [Online] Available at: https://asana.com/resources/business-impact-analysis [Accessed 9 May 2022]. Magret, A., n.d. Business Continuity Planning: What Is It All About?. [Online] Available at: https://www.unitrends.com/blog/business-continuity-planning [Accessed 8 May 2022]. Mathenge, J., 2022. IT Governance: An Introduction. [Online] Available at: https://www.bmc.com/blogs/it-governance/ [Accessed 15 April 2022]. Mcmenemy, L., 2019. What Is Organizational Governance?. [Online] Available at: https://www.diligent.com/insights/entity-governance/organizational-governance/ [Accessed 7 May 2022]. Mehta, R., 2020. The Difference Between Paid Marketing And Organic Marketing. [Online] Available at: https://www.linkedin.com/pulse/difference-between-paid-marketing-organic-riamehta [Accessed 13 April 2022]. Merhout, J. W. & Havelka, D., 2008. Information Technology Auditing. Information Technology Auditing: A Value-Added IT Governance Partnership between IT, 23(1), pp. 3-5. Milano, S., 2021. How to Conduct Testing of a Business Continuity Plan. [Online] Available at: https://smallbusiness.chron.com/recovery-phase-business-continuity-plan-66507.html [Accessed 10 May 2022]. Mutiullah Olasupo, A. S., 2017. African Resarch Review. Corruption and Public Governance: Implication for Customer, 11(1), pp. 5-7. Nicolls, D., 2019. Enhanced Due Diligence for Banks and Financial Institutions: KYC & AML Recommendations. [Online] Available at: https://www.jumio.com/enhanced-due-diligencebanks/#:~:text=Enhanced%20due%20diligence%20(EDD)%20is,obtaining%20the%20customer's%20i dentity%20and [Accessed 30 April 2022]. Omar, A., Alijani, D. & Mason., R., 2011. Information Technology Disaster Recovery: Case Study. Academy of Strategic Management Journal , 10(2), pp. 133-138. Pacholczyk, D., 2022. IT Audit – Definition, Examples & Types. [Online] Available at: https://codete.com/blog/it-audit-definition-examples-and-types [Accessed 8 May 2022]. Rabelo, J., 2020. Primary Key. [Online] Available at: https://www.techopedia.com/definition/5547/primarykey#:~:text=A%20primary%20key%20is%20a,more%20than%20one%20primary%20key. [Accessed 13 April 2022]. Rakowsky, P., 2020. Big Data and the Insurance Industry: Using Data to Increase Your Bottom Line. [Online] Available at: https://www.dataart.com/en/blog/big-data-and-the-insurance-industry-using-data-toincrease-your-bottom-line [Accessed 7 May 2022]. Rapid7, n.d. Information Security Risk Management. [Online] Available at: https://www.rapid7.com/fundamentals/information-security-riskmanagement/#:~:text=Information%20security%20risk%20management%2C%20or,availability%20of %20an%20organization's%20assets. [Accessed 10 May 2022]. Richards, K., n.d. Cryptography. [Online] Available at: https://www.techtarget.com/searchsecurity/definition/cryptography [Accessed 14 May 2022]. Rock Content, 2021. How to Get Started with an Effective Organic Marketing Strategy. [Online] Available at: https://rockcontent.com/blog/organic-marketing-strategy/ [Accessed 13 April 2022]. Sanction Scanner, 2020. How Does Money Laundering Work?. [Online] Available at: https://sanctionscanner.com/blog/how-does-money-laundering-work271#:~:text=Integration%20money%20laundering%20is%20the,it%2C%20and%20profit%20from%20 it. [Accessed 12 April 2022]. Șcheau, M. C., Rangu, C. M., Vasile, F. & Leu, D. M., 2022. FinTech Advancements: Big Data, Artificial Intelligence, Blockchain. Key Pillars for FinTech and Cybersecurity, 18(1), pp. 198-201. Shakeel, F., 2022. Insurance Data Analytics: The Gold Mine for Insurers. [Online] Available at: https://www.damcogroup.com/blogs/insurance-data-analytics-for-insurers/ [Accessed 13 April 2022]. Smirnoff, P. & Turner, D. M., 2019. Symmetric Key Encryption - why, where and how it’s used in banking. [Online] Available at: https://www.cryptomathic.com/news-events/blog/symmetric-key-encryption-whywhere-and-how-its-used-in-banking [Accessed 14 May 2022]. Susanto, H., Almunawar, M. N. & Tuan, Y. C., 2011. Information Security Management System Standards: A Comparative Study of the Big Five. International Journal of Electrical & Computer Sciences, 11(5), pp. 2-4. SWIFT , n.d. What is Customer Due Diligence (CDD)?. [Online] Available at: https://www.swift.com/your-needs/financial-crime-cyber-security/know-yourcustomer-kyc/customer-due-diligence-cdd [Accessed 30 April 2022]. Tabbaa, B., 2018. The Rise and Fall of Knight Capital — Buy High, Sell Low. Rinse and Repeat.. [Online] Available at: https://medium.com/dataseries/the-rise-and-fall-of-knight-capital-buy-high-sell-lowrinse-and-repeat-ae17fae780f6 [Accessed 7 May 2022]. The Ramp Team , n.d. What are KYB and KYC?. [Online] Available at: https://ramp.com/blog/what-are-kyb-and-kyc-tips [Accessed 30 April 2022]. Tiwari, A., 2020. Difference Between Symmetric and Asymmetric Key Encryption. [Online] Available at: https://www.geeksforgeeks.org/difference-between-symmetric-and-asymmetric-keyencryption/ [Accessed 14 May 2022]. Unit 21, 2022. Types and Examples of Suspicious Transactions: A Closer Look. [Online] Available at: https://www.unit21.ai/blog/types-and-examples-of-suspicious-transactions-a-closerlook [Accessed 30 April 2022]. Wang, C., 2021. Data Warehouse vs. Database. [Online] Available at: https://www.fivetran.com/blog/data-warehouse-vs-database [Accessed 13 April 2022]. ZHAO, J., 2022. Business Impact Analysis: What to Know. [Online] Available at: https://hyperproof.io/resource/business-impact-analysis/ [Accessed 9 May 2022].
0
You can add this document to your study collection(s)
Sign in Available only to authorized usersYou can add this document to your saved list
Sign in Available only to authorized users(For complaints, use another form )