The information security capability is the necessary systems, processes, and people to meet the requirements of the 24 information security requirements of the Consumer Data Right (CDR).
Traditional enterprises require experts in security and compliance to support their information security program. With modern cloud products, advanced supporting software, and democratised security and compliance knowledge, this is no longer the case for modern cloud services businesses. What’s more important than people with the skills and expertise, are the resources, time, and commitment to security and compliance objectives. These are covered in more detail in Step 1: Security governance.
Of course, if your CDR environment is more complex, you’ll need the relevant expertise to have sufficient knowledge and skills to achieve the security requirements for that environment. Aside from the people capabilities, it's a matter of identifying the systems and processes you have in place to support the 24 information security requirements of the CDR and addressing any gaps.
The easy way to do this is with AssuranceLab’s free readiness software. This also identifies the system components to support Step 2: Define the boundaries of the system. Our software runs through a series of logic-driven questions to collect inputs on how your business operates, your scope, and the detailed practices in place. By comparison to the requirements of the CDR (and other standards), it identifies gaps and provides recommendations based on industry-standard approaches and software solutions.
The CDR requires that the information security capability is reviewed and adjusted in response to risks and material changes. These are covered as implicit parts of Step 4: Controls Assessment Program. This program includes performing a periodic, often quarterly, risk assessment process and reviewing the controls that address the CDR requirements and any other standards you are required or choose to maintain compliance with.
The other elements that commonly make up part of your information security capability include:
If you're wondering what this all looks like "on paper" - get in touch with our team <info@assurancelab.com.au>. We're happy to share examples and guide you through how this may look for your business.
The CDR Perspective
The CDR Schedule 2, Part 1 requires the following in relation to having and maintaining an information security capability:
About AssuranceLab
AssuranceLab is a modern cybersecurity audit firm that provides assurance reports (ASAE 3150, SOC 1/2). We're experts in the latest software and cloud providers. We guide your team through the compliance practices in a way that fits your environment and culture. We work closely with clients through our agile and collaborative approach; saving time, costs, and headaches along the way.