Featured Product

    MAS Issues Measures to Strengthen Cyber Resilience in Financial Sector

    August 06, 2019

    MAS has set out the measures that financial institutions must take to mitigate the growing risk of cyber threats. To this end, MAS issued a set of legally binding requirements to raise the cyber security standards and strengthen cyber resilience of the financial sector in Singapore. The measures will come into effect on August 06, 2020. MAS also published the frequently asked questions (FAQs) on these measures. These recently issued cyber hygiene measures are intended for financial holding companies (Notice 1119), all banks in Singapore pursuant to section 55(1) of the Banking Act (Notice 655), merchant banks (Notice 1118), financial advisers (Notice FAA-N21), capital market entities (Notice CMG-N03, insurance brokers (Notice 507), finance companies (Notice 834), and insurance agents (Notice 132).

    These measures make compulsory the key elements in the existing MAS Technology Risk Management guidelines. The technology risk management guidelines are a set of best practices that provide financial institutions with guidance on the oversight of technology risk management, security practices, and controls to address technology risks. MAS expects financial institutions to observe the technology risk management guidelines, as this will be taken into account in MAS’ risk assessment of the financial institutions. As per the now-published measures on cyber hygiene, financial institutions must:

    • Establish and implement robust security for IT systems
    • Ensure updates are applied to address system security flaws in a timely manner
    • Deploy security devices to restrict unauthorized network traffic
    • Implement measures to mitigate the risk of malware infection
    • Secure the use of system accounts with special privileges to prevent unauthorized access
    • Strengthen user authentication for critical systems as well as systems used to access customer information

    MAS, in September 2018, had sought feedback from the public on the proposal to make this suite of cyber security measures into legally binding requirements. Financial institutions generally welcomed these measures and provided some suggestions about implementation of the requirements. These suggestions include focusing on strengthening user access to systems that store or access customer data and allowing more time for financial institutions to design, acquire, and integrate robust user authentication technology into their critical systems.

     

    Keywords: Asia Pacific, Singapore, Banking, Insurance, Securities, Cyber Resilience, Cyber Security, Cyber Risk, Technology Risk, MAS

    Related Articles
    News

    FED Adopts Proposal to Implement Reporting Form for SCCL

    FED adopted a proposal to implement the Single-Counterparty Credit Limits (SCCL) reporting form (FR 2590; OMB No. 7100-NEW).

    November 20, 2019 WebPage Regulatory News
    News

    FED Proposes to Extend Initial Compliance Dates Under SCCL Rule

    FED published a proposal to extend, by 18 months, the initial compliance dates for foreign banks subject to the single-counterparty credit limit (SCCL) rule.

    November 20, 2019 WebPage Regulatory News
    News

    CBIRC to Strengthen Supervisory and Policy Support for SME Services

    CBIRC released a notification on strengthening supervision and guidance to enhance the quality and efficiency of financial services for "small and micro-enterprises" (SMEs).

    November 20, 2019 WebPage Regulatory News
    News

    APRA Publishes Approach to Regulating and Supervising GCRA Risks

    APRA published an information paper that sets out a more intensive regulatory approach to transform governance, culture, remuneration, and accountability (GCRA) practices across the prudentially regulated financial sector.

    November 19, 2019 WebPage Regulatory News
    News

    US Agencies Update Rule on Derivative Contracts Exposure Calculation

    US Agencies (FDIC, FED, and OCC) announced a final rule updating the way certain banking organizations are required to measure counterparty credit risk for derivative contracts under their regulatory capital rules.

    November 19, 2019 WebPage Regulatory News
    News

    US Agencies Finalize Rule to Amend Treatment of HVCRE Exposures

    US Agencies (FDIC, FED, and OCC) finalized a rule to modify the treatment of high volatility commercial real estate (HVCRE) exposures, as required by the Economic Growth, Regulatory Relief, and Consumer Protection (EGRRCP) Act.

    November 19, 2019 WebPage Regulatory News
    News

    US Agencies Finalize Changes to Rule on Supplementary Leverage Ratio

    US Agencies (FDIC, FED, and OCC) finalized changes to the capital requirement for banking organizations predominantly engaged in custodial activities, as required by the Economic Growth, Regulatory Relief, and Consumer Protection (EGRRCP) Act.

    November 19, 2019 WebPage Regulatory News
    News

    IAIS Consults on Guidance on Liquidity Risk Management for Insurers

    IAIS is seeking feedback on the draft application paper on liquidity risk management for insurers.

    November 19, 2019 WebPage Regulatory News
    News

    IAIS Publishes Application Paper on Recovery Planning

    IAIS published the final application paper on recovery planning, along with the resolution of comments on the draft application paper.

    November 18, 2019 WebPage Regulatory News
    News

    FSB Publishes Summary of November Meeting of RCG for MENA Region

    FSB published a summary of the November meeting of the Regional Consultative Group (RCG) for Middle East and North Africa (MENA).

    November 17, 2019 WebPage Regulatory News
    RESULTS 1 - 10 OF 4174