Govern
Owner, policy, authority এবং risk—কে সিদ্ধান্ত নেবেন এবং কোন সীমা পর্যন্ত, তা লিখিত থাকে।
AL FARSI X Business Transformation & Venture Studio
Practice-টি governance, access, readiness, response, recovery এবং learning একসাথে ধরে। কাজ পরিচালিত হয় written authorization এবং একটি পরিষ্কার technical boundary-র মাধ্যমে।
Tool কেনার আগে ঠিক হয় কে দায়ী, কোন asset critical, কী সুরক্ষিত, কীভাবে সংকেত পাওয়া যাবে এবং incident হলে কে কোন সিদ্ধান্ত নেবেন।
Owner, policy, authority এবং risk—কে সিদ্ধান্ত নেবেন এবং কোন সীমা পর্যন্ত, তা লিখিত থাকে।
Critical asset, dependency এবং exposure চিহ্নিত করা হয়; কোন system বন্ধ হলে ব্যবসা থামে তা আগে জানা থাকে।
Access control, backup discipline, patch routine এবং লিখিত SOP—preventive layer এখানেই দাঁড়ায়।
Signal, log এবং escalation path—সমস্যা কতক্ষণে চিহ্নিত হয় এবং কার কাছে যায়।
Command, containment এবং communication—চাপের মুহূর্তে সিদ্ধান্ত কে নেবেন তা আগেই ঠিক করা থাকে।
Restore, validate এবং learn—পুনরুদ্ধারের পর root cause, residual risk ও corrective owner রেকর্ড করা হয়।
প্রতিটি product স্বাধীনভাবে নেওয়া যায়—written scope, defined output এবং client acceptance সহ।
Standalone process mapping, SOP, RACI, checklist, form এবং version control।
View SOP engagementAsset ও exposure view, access review, backup check, risk register এবং priority roadmap।
Joiner-mover-leaver, privilege matrix, MFA, credential handling এবং review evidence।
Severity model, incident role, contact tree, decision rights, template এবং tabletop exercise।
Technical depth এবং response availability কেবল signed scope এবং assigned specialist team-এর মাধ্যমেই নিশ্চিত করা হয়।
Authorized triage, incident command, containment coordination, restoration priority এবং post-incident action।
Business-impact analysis, recovery objective, critical-service map, backup evidence, runbook এবং test।
Bank, NBFI ও payment business-এর জন্য governance, access, third-party, incident এবং continuity control support।
Periodic control review, readiness upkeep, risk tracking, remediation governance এবং agreed response support।
Response path প্রযোজ্য compromised website, email environment, cloud account এবং connected business system-এ—যখন authorization ও specialist scope পরিষ্কার থাকে।
Owner, system boundary, decision rights এবং evidence rule নিশ্চিত করা।
কী ঘটেছে, কী প্রভাবিত এবং প্রথমে কী রক্ষা করতে হবে তা নির্ধারণ।
Access, credential, network বা application containment coordinate করা।
Priority service restore, control validate এবং recurrence monitor করা।
Root cause, residual risk, corrective action এবং accountable owner রেকর্ড করা।
কী delivered হবে, কী specialist support চায় এবং কী কখনোই guarantee করা যায় না—তিনটিই আগে বলা হয়।
Client approval ছাড়া কোনো active testing, access বা recovery action নেওয়া হয় না।
Entity, domain, account, device, environment এবং exclusion নাম ধরে লিখিত থাকে।
Access client-approved, time-bound এবং handover-এ ফেরত বা revoke করা হয়।
Deep forensics, penetration testing, malware analysis এবং 24/7 monitoring-এর জন্য qualified assigned scope বা partner প্রয়োজন।
Financial-sector framework mapping implementation-কে support করে; এটি regulator approval, certification বা independent audit opinion নয়।
Scope-এ থাকলে cyber product গুলো align করা হতে পারে Bangladesh Bank ICT Security Guideline 2023, Bangladesh Bank Cybersecurity Framework Version 1.0 (2026), NIST CSF 2.0 এবং NIST SP 800-61r3-এর সাথে। Alignment মানে certification, endorsement বা regulator approval নয়।
প্রথম আলোচনায় critical asset, access owner, backup reality এবং authorization boundary পরিষ্কার করা হয়।