Cybersecurity and continuity oversight, with the evidence attached.
The Cybersecurity landing rolls up the security frameworks, findings, and controls, and Continuity (BCM) tracks plans, business impact analyses, and exercises.
| Process | Plan | Coverage |
|---|---|---|
| Core banking | IT disaster recovery | Covered |
| Wire transfers | Enterprise BCP | Covered, test due soon |
| Card processing | Department | Test overdue |
| Call center | None | No plan |
The Cybersecurity landing
The Cybersecurity screen is the information security program at a glance. It shows only the frameworks your institution has enrolled and keeps in scope. Those are the FFIEC IT and business continuity booklets, GLBA, NCUA Chapter VII, and the cybersecurity standards you follow, such as NIST CSF 2.0, the CRI Profile, ISO/IEC 27001, NYDFS Part 500, and PCI DSS. It shows their coverage, the open security incidents with the notices still due, the open findings tagged to those frameworks, and the controls crosswalked to them with each control’s test status.
- 01Security and continuity frameworks that are enrolled and in scope are shown with their coverage.
- 02Open security incidents are listed with the notices still due, for members who hold the security read permission.
- 03Open findings tagged to those frameworks are listed in one panel.
- 04Mapped controls are sorted with overdue tests first, then tests due soon.
The annual report to the board
The Interagency Guidelines ask for a report to the board on the information security program at least annually. The landing generates that report and shows when it is next due and when it was last recorded, from the obligation on the Obligations calendar.
- 01The due date and the date last reported come from the Obligations calendar.
- 02The guidelines fix the frequency, so you set the due date to your board cycle.
Continuity plans that go in force through approval
Continuity (BCM) is the oversight register for your business continuity program. Each plan has an owner, a type, an exercise cadence, and the recovery time and recovery point it commits to. A plan runs from draft to awaiting approval, in force, and retired, and it goes in force only through a maker-checker approval, never on one person’s say-so.
- 01Plan types are enterprise BCP, IT disaster recovery, pandemic, department, and other.
- 02The approval shows the plan’s commitments and any conflict with its business impact analyses.
- 03Continuity (BCM) is a second-line tracking surface. Zovos does not run a failover.
Business impact analyses and recovery-objective conflicts
A business impact analysis records what a process requires: its recovery time objective, its recovery point objective, and its maximum tolerable downtime. Because the requirement and the plan’s commitment are recorded separately, Zovos compares them and lists every recovery-objective conflict, where a plan commits to less than its process needs.
- 01Each business impact analysis names its process, its criticality, and the plan that recovers it where one exists.
- 02A conflict between a plan and its business impact analysis is listed, not buried in a document.
Exercises, coverage, and findings
The exercise log records each test with its plan, its type, its date, a summary, and a result of pass, partial, or fail. A recorded exercise moves the plan’s cadence clock forward, and the coverage tab grades every process from covered to test overdue, never tested, plan not in force, or no plan. A failed or partial exercise can be promoted to a finding.
- 01Exercise types are tabletop, walkthrough, functional, and full interruption.
- 02A failed exercise opens a High finding and a partial one a Medium finding, and the person promoting it can change that.
- 03A back-dated exercise cannot move a plan’s clock backward.
Notification linkage, with no alerts sent
Zovos sends no emergency alerts and holds no contact roster. Your mass-notification platform does that. Zovos emits a signed event when a plan goes in force and when an exercise is recorded, so that platform stays in step with the plan register.
- 01Two continuity events are sent to the endpoints you configure.
- 02The Notification linkage tab shows the endpoints and the last delivery.
Security evidence from the rest of Zovos
The landing draws on records that live elsewhere in the product. Controls sit in the Control catalogue, and automated control tests run on the security evidence connectors. Vendor SOC report reviews sit in Third parties, where complementary user entity controls are crosswalked to your own controls. The security frameworks are in the shared corpus.
- 01Tenable and Qualys test vulnerability remediation against your SLA and scan freshness.
- 02CrowdStrike tests sensor coverage and prevention policy, and Jamf tests disk encryption, screen lock, and operating-system currency.
- 03Identity, Microsoft 365, and AWS connections run further checks, such as MFA enforcement, device compliance, cloud configuration, and backups.
- 04The Cyber Hub starter control baseline maps cybersecurity objectives to the FFIEC Information Security booklet, NIST CSF 2.0, the CRI Profile, GLBA, NCUA Part 748, and ISO/IEC 27001.
- 05The corpus includes NIST CSF 2.0, the CRI Profile v2.2, NIST 800-53 Rev. 5, CIS Controls v8.1, ISO/IEC 27001:2022, SOC 2, and PCI DSS v4.0.1.
Grounded in shipped behaviour.
- A continuity plan goes in force only through a maker-checker approval.
- Four security evidence connectors (Tenable, Qualys, CrowdStrike, and Jamf) back seven automated control checks.
- The corpus behind the landing holds 54 frameworks, including FFIEC IT, GLBA, NCUA Chapter VII, and the FFIEC business continuity booklet.
Counts come from the platform's regulatory corpus, connector registry, and seed template library at release. See the documentation for the current values.
Questions, answered first.
- What is in the Cybersecurity group?
- Three screens. The Cybersecurity landing rolls up the security and continuity frameworks, findings, and controls. Security incidents records each incident with its notification deadlines, and Continuity (BCM) tracks continuity plans, business impact analyses, and exercises.
- Does Zovos run our disaster recovery or send emergency alerts?
- No. Continuity (BCM) is an oversight register. Zovos does not run a failover, sends no alerts, and holds no contact roster. It emits a signed event to your mass-notification platform when a plan goes in force and when an exercise is recorded.
- How does Zovos catch a plan that cannot meet its recovery objectives?
- Each business impact analysis records the recovery time and recovery point a process requires, and each plan records what it commits to. Zovos compares the two and lists every recovery-objective conflict.
- Where do vulnerability and endpoint results come from?
- From the Tenable, Qualys, CrowdStrike, and Jamf connectors. Each one runs automated control tests against the controls in your Control catalogue, and the landing shows those controls with their test status.
See cybersecurity on your library.
Bring your controls, a policy, and one regulator paragraph that gives you trouble. We target two-week onboarding.