Back to category

Week 1

Author a Baseline NIST SP 800-30 Risk Assessment for a Fintech Cross-Border Expansion

Beginner
GRC Analyst
Security Analyst
Risk Manager
NIST SP 800-30
NIST SP 800-39
PIPEDA
FINTRAC RBM
Quebec Law 25
ISO 31000
OSFI Guideline B-13
CPPA
NIST CSF 2.0
Risk Assessment
NIST SP 800-30
Risk Register Authoring
Fintech Compliance
OSFI B-13
CPPA

Client Background

Brightline Pay is a 90-person, venture-backed fintech offering real-time USD remittance through a partner bank. The company was founded in Austin in 2022. The team is preparing to launch Canadian remittance corridors through a Canadian bank partner and will become subject to PIPEDA, FINTRAC MSB registration, and Quebec Law 25. Until now, security has been handled ad hoc by the engineering team.

Business Environment

Single-account AWS in us-east-1, ~30 microservices on ECS/Fargate, RDS Postgres, Stripe + Plaid integrations, GitHub Cloud for source management, Slack for collaboration. No formal GRC function; the head of engineering acts as security lead by default.

Security Incident

The Canadian partner bank's compliance questionnaire revealed Brightline has not performed a formal risk assessment. Brightline's SOC 2 Type I attestation is due in 90 days. No risk register exists. The platform has had two unrecorded incidents this year that the team is recalling after a kickoff workshop.

Scope

Platform AWS account (us-east-1), partner integrations (Stripe, Plaid, Canadian bank), the SaaS application layer (frontend + ~30 microservices), and HR/admin tooling. On-prem assets and the marketing site are out of scope.

Objectives

  • Conduct a baseline risk assessment using NIST SP 800-30r1
  • Develop a risk register with at least 12 risks, each scored using a 5-level likelihood/impact rubric
  • Define a treatment decision (Accept/Mitigate/Transfer/Avoid) and a mitigation owner for every risk
  • Map cross-border fintech regulatory references to OSFI Guideline B-13 and the CPPA (successors to legacy PIPEDA framing) and align the risk assessment to NIST CSF 2.0.

Required Deliverables

Risk register with at least 12 risks
Executive summary for VP Eng and Canadian bank partner compliance team
Treatment plan with owners and due dates
3 hrs estimated