Department of Labor Cybersecurity Program Best Practices
ERISA-covered pension plans and health and welfare plans often hold millions of dollars or more in assets, and they store and transfer participant personally identifiable data — making them tempting targets for cybercriminals. Responsible plan fiduciaries have an obligation to ensure proper mitigation of cybersecurity risks.
The U.S. Department of Labor's Employee Benefits Security Administration (EBSA) has published cybersecurity program best practices for recordkeepers and other service providers responsible for plan-related IT systems and data, and for plan fiduciaries making prudent decisions about the service providers they hire. Ascend helps plan sponsors and service providers assess their programs against these twelve best practices:
- A formal, well documented cybersecurity program — one that identifies and assesses internal and external risks, implements documented policies and standards (covering data governance, access controls, business continuity, configuration and asset management, incident response, vendor management, MFA, training, and encryption), is approved by senior leadership, reviewed at least annually, and validated by an independent third-party auditor.
- Prudent annual risk assessments — codified in scope, methodology, and frequency; identifying and categorizing threats; documenting how existing controls address identified risks; and kept current as technology and threats change.
- A reliable annual third-party audit of security controls — providing a clear, unbiased report of existing risks, vulnerabilities, and weaknesses, with documented correction of any findings.
- Clearly defined and assigned information security roles and responsibilities — managed at the senior executive level (typically by a CISO) and executed by qualified, trained, background-checked personnel.
- Strong access control procedures — role-based, need-to-access privileges reviewed at least quarterly; unique strong passwords; and multi-factor authentication (preferably phishing-resistant) on internet-facing systems and areas holding sensitive information.
- Security reviews of cloud and third-party managed assets — risk assessments of service providers, defined minimum cybersecurity practices, and contractual protections covering access control, encryption, and breach notification.
- Periodic cybersecurity awareness training — conducted at least annually for all personnel and updated to reflect the most recent risk assessment, with emphasis on identity theft and social engineering.
- A secure system development life cycle (SDLC) program — embedding penetration testing, code review, and architecture analysis into development, with vulnerability management and annual penetration tests of customer-facing applications.
- An effective business resiliency program — addressing business continuity, disaster recovery, and incident response, with defined roles, communication protocols, remediation plans, after-action reviews, and annual testing.
- Encryption of sensitive data — both stored and in transit, using current, prudent standards for encryption keys, message authentication, and hashing.
- Strong technical controls — up-to-date hardware and software, vendor-supported firewalls and intrusion detection/prevention, current antivirus, routine (preferably automated) patching and backups, network segregation, and system hardening.
- Appropriate responses to past cybersecurity incidents — informing law enforcement and insurers, investigating, notifying affected participants without unreasonable delay, honoring contractual and legal obligations, and fixing root causes.
Whether you are a plan fiduciary evaluating service providers or a recordkeeper preparing for scrutiny, Ascend can assess your cybersecurity program against the DOL/EBSA best practices and help you close the gaps. Contact us to get started.