PAGE HEADING

New AICPA Cybersecurity Risk Management Reporting Framework Explained

May 17, 2017
cybersecurity lock data

Public and private organizations of all sizes have come to terms with an unfortunate new normal: cybersecurity attacks are not a matter of “if,” but “when.” The American Institute of CPAs (AICPA) has been rigorously exploring ways the profession can help companies evaluate and report on their cybersecurity risk management programs, and supply key stakeholders with crucial information about those programs.

While organizations use any number of methods, controls and frameworks to develop their cybersecurity risk management programs, until now, no common language existed for communicating and reporting on companies’ efforts. To address this, the AICPA’s Assurance Services Executive Committee (ASEC) and Auditing Standards Board (ASB) recently released a cybersecurity risk management reporting framework that aligns with those existing methods, controls and frameworks companies currently employ to manage cybersecurity risks.

“Our market-driven, flexible and voluntary cybersecurity risk management reporting framework builds upon the profession’s experience in auditing system and organization controls,” said AICPA Executive Vice President Susan S. Coffey, CPA, CGMA. “It creates a common language for reporting that enables companies to demonstrate that they are taking a strategic, agile approach to addressing cybersecurity that is integrated with broader enterprise risk management efforts.”

Resources for Implementing the Framework

To help organizations use the framework to communicate and CPAs to report on cybersecurity risk management programs, the AICPA has produced three resources: two sets of distinct but complementary criteria and an attestation guide.

The AICPA’s description criteria are for use by an organization’s management to explain its cybersecurity risk management program in a consistent manner, as well as for use by CPAs to report on management’s description. CPAs will use control criteria to provide advisory or attestation services to evaluate and report on the effectiveness of the controls within a client’s program.

“We developed our criteria to promote consistency and comparability of cybersecurity information provided by different entities. They constitute what is analogous to a US GAAP or IFRS for financial reporting, but in this case, for cybersecurity risk management reporting,” said Coffey. “Cybersecurity experts, regulators and senior leaders of organizations and firms informed our efforts. Additionally, we looked at the information needs of board members, analysts, investors, business partners, regulators and other users.”

In May, the AICPA will release the third resource, an attestation guide entitled Reporting on an Entity’s Cybersecurity Risk Management Program and Controls, which will assist CPAs engaged to examine and report on an entity’s cybersecurity risk management program. 

Many Ways to Support Stakeholders

Using the framework, CPAs can better serve client needs and protect the public interest. “We’ve created an engagement that takes a consistent profession- and market-driven approach, allowing CPAs to examine and report on an entity's cybersecurity measures in a way that addresses the information needs of a broad range of users,” said Coffey. “We think this will provide organizations with a level of comfort that they’ve adequately considered the best practices covered by the most commonly referenced control and cybersecurity frameworks, regardless of which cybersecurity risk management frameworks they’ve chosen to implement internally.”

Recognizing that companies’ risk management maturity varies across the market, the AICPA developed the framework so that CPAs can better advise clients on cybersecurity readiness and prepare companies that are considering a cybersecurity attestation engagement. Within businesses, CPAs and CGMAs can provide risk management insight and introduce stakeholders to the framework as a means of strengthening and communicating about cybersecurity risk management programs.

Learn More

Look for the reporting framework at aicpa.org/cybersecurityriskmanagement. There, you’ll find the free description criteria, plus a fact sheet, backgrounder, illustrative report and other valuable free resources. In addition, the site contains links to the control criteria and attestation guide. For additional information, events and news on cybersecurity, visit the AICPA’s Cybersecurity Resource Center.

Icon_MemberBenefits_MID
CPACharge
CPACharge was developed specifically for CPAs, enrolled agents and accountants, providing a simple, affordable online payment solution that allows you to securely accept credit, debit, and eCheck/ACH payments from anywhere. 
NJCPA_Icn_4C
On-Site Training

NJCPA on-site training programs offer the same outstanding content and expert instruction as our seminars but are led at your location.

Icon_MemberBenefits_MID
Accounting Today
Save 20 percent on an Accounting Today subscription and stay up to date on the latest issues affecting the profession.
Icon_3_people_circle_SKY-04
Join the Accounting Educators Community

Connect and share with other accounting educators about curriculum, trends and the profession. Learn about NJCPA initiatives that are valuable for your students including information on obtaining the CPA designation, student membership, scholarships, volunteer opportunities and events.

Icon_4_cube_connection_SKY-04
Earn an AICPA Robotic Process Automation Certificate
Recognize what RPA is and its business value, with specific focus on accounting and finance functions. Understand how RPA provides a significant competitive advantage.
Icon_MemberBenefits_MID
Guaranteed Rate/Marc Demetriou
Marc Demetriou of Guaranteed Rate is offering NJCPA members a “no lender fee mortgage” ($1,440 lender fee credit), competitive low rates and a dedicated team to deliver world class service.
Icon_3_people_circle_SKY-04
Join the Women's Leadership Forum

Join our online forum that enables female CPAs at all career levels and industries to make meaningful connections with each other and discuss career goals.

Icon_Monitor_magnify_SKY-04
Earn an AICPA Single Audit Certificate
Learn how to plan, perform and evaluate single audits in accordance with the latest requirements of the new Uniform Guidance.
Icon_MemberBenefits_MID
Wolters Kluwer
NJCPA members save 25 percent on CCH CPELink subscriptions, live webinars and on-demand self-study (mobile friendly) CPE courses.
Icon_MemberBenefits_MID
SMI

SMI has negotiated special discounts for the NJCPA members with all the major technology carriers and providers.

Icon_3_people_circle_SKY-04
Join the Business & Industry Professionals Interest Group

Stay connected to your peers and share knowledge on corporate finance topics.

Wolters Kluwer CCH
Save on COVID Tax Resources
NJCPA members save 25 percent on Wolters Kluwer's new book, COVID and Taxpayer Certainty Acts of 2020: Law, Explanation & Analysis.
NJCPA_Icn_4C
Shop the NJCPA store
Are you NJCPA proud? Purchase NJCPA merch to show your pride and help support our scholarship program.
Icon_Shooting_up_arrows_MID-03
Real Estate Classified Ads
View classified ad postings for office space for sale or rent.
Icon_Handshake_MID-03
Mergers & Acquisitions Classified Ads
View classified ad postings from CPA firms looking to be acquired and those looking to acquire or merge with other firms.
Icons_3_gears_midnight-03
Professional Services Classified Ads
View classified ad postings from companies providing services to CPAs.
Icon_3_people_circle_SKY-04
Join the Cannabis Interest Group
New Jerseyans have voted to legalize cannabis. Join the NJCPA's Cannabis Interest Group to gain information, insights and best practices for serving clients in this promising new industry.
NJCPA_Icn_4C
Zoom Backgrounds
Download our virtual backgrounds for Zoom meetings.
Icon_certificate_SKY-04
Earn an AICPA Certificate
When you’re ready to show your competencies, expand your career opportunities or enter new areas of practice, start by earning an AICPA certificate. Choose a certificate that matches your next career goal.
Icon_4_cube_connection_SKY-04
Earn the AICPA Blockchain Fundamentals Certificate
Build a foundation toward becoming a strategic business partner within your organization and with your clients. Learn how to anticipate potential benefits and risks of the technology, structure and functionality, and to translate them into relevant business application and value.