The CRI Profile’s Strategic Plan.
We’ll work to expand the depth of the Profile through the incorporation of maturity, cloud controls, and additional cyber controls related to incident response and operational resilience. We will work on developing training materials for members. With respect to cloud, we have integrated the Cloud Security Alliance’s (CSA) Cloud Control Matrix (CCM) into the Profile.
As the Profile becomes increasingly adopted in the financial industry ecosystem, we will explore the addition of template security policies and potentially model contract language for third-party engagements. During this time, we will remain committed to the continued education of regulators and firms on the value and benefits of the Profile.
We will explore the potential to offer formal Profile certification and training, and assistance to other sectors in the development of their own Profile-based frameworks. Additionally, we plan to incorporate cyber requirements related to third-party engagements, privacy, operational resilience, and quantum computing into the Profile and its extensions.
Focus on the future.
Our strategic plan includes four main areas of focus for the CRI Profile.
NEAR-TERM
Update the Profile regularly
Develop benchmarking program.
Incorporate risk taxonomy.
MEDIUM-TERM
Develop policies, procedures, and organizational chart templates for users.
LONG-TERM
Develop a training and certification program.
NEAR-TERM
Sustain planned revision cycle.
Expand cyber-related controls (e.g., cloud, incident response, privacy, technology).
MEDIUM-TERM
Explore mapping automation capabilities.
Implement automated mapping capabilities.
LONG-TERM
Work with other sectors to develop Profile-like approach.
NEAR-, MEDIUM-, AND LONG-TERM
Sustain and increase pace of regulatory engagements.
Raise CRI Profile awareness via select events.
Educate/engage policymakers
(e.g., legislative and regulatory bodies).
NEAR-TERM
Develop training materials for implementation and use.
Hold regular Master Classes for members.
Create blogs and host webinars.
Expand Profile market presence through through Affiliate and Innovator Programs.
MEDIUM-TERM
Enhance the financial ecosystem through strategic partnerships.
LONG-TERM
Develop educational materials for Board reporting using the Profile.