Featured Product

    CMF Publishes Rules on Management of Information and Cyber Security

    July 07, 2020

    CMF published a regulation that establishes a series of guidelines and best practices that certain regulated entities must comply with in their process of managing information security and cybersecurity. CMF also published a presentation and a set of frequently asked questions with respect to this regulation. The regulation will become effective on December 01, 2020 and is applicable for banks, bank affiliates, bank draft support companies, and issuers and payment card operators. CMF expects this regulation to be a frame of reference for future changes in this area for other institutions, such as credit unions and entities in the securities and insurance industry.

    The adoption of this new regulation will allow entities to be better prepared to prevent and act against operational events related to information security and cybersecurity. CMF has published the new Chapter 20-10 of the Updated Compilation of Standards (RAN); this new chapter contains a series of provisions, based on international best practices, that must be considered for the management of information security and cybersecurity. This new RAN Chapter complements the provisions of different regulations of CMF, such as those established in Chapter 1-13 on the evaluation of operational risk management; Chapter 20-7 regarding the risks that entities assume in the outsourcing of services; Chapter 20-8 on information on operational incidents; and Chapter 20-9 on business continuity management. Until December 01, 2020, when this regulation becomes effective, banks must continue to comply with the provisions of current Chapter 1-13 in the field of operational risk—particularly in relation to information security and cybersecurity. The new guidelines address the following key elements:

    • Guidelines on the role of the Board of Directors for proper management of information security and cybersecurity, granting it responsibility for approval of the institutional strategy in this matter. In addition, a Board of Directors must ensure that an entity maintains an information security and cybersecurity management system that contemplates the specific administration of these risks.
    • Banks and financial institutions shall define the minimum stages of an information security and cybersecurity risk management process, considering at least the identification, analysis, assessment, treatment, and acceptance of the risks. to which the information assets are exposed, as well as their permanent monitoring and review.
    • Entities need to define their critical assets and their protection functions, ensure detection of threats and vulnerabilities, and focus on the response to incidents and the recovery of the normal operations.
    • Entities must also have policies and procedures for the identification of assets that make up the critical infrastructure of the financial industry and the payment system and for the adequate exchange of technical information on incidents that affect, or could affect, the cybersecurity.

     

    Related Links (in Spanish)

    Keywords: Americas, Chile, Banking, Cyber Risk, Operational Risk, Information Security, Cyber Incident, CMF

    Related Articles
    News

    FED Revises Capital Planning and Stress Testing Requirements for Banks

    FED finalized a rule that updates capital planning requirements to reflect the new framework from 2019 that sorts large banks into categories, with requirements that are tailored to the risks of each category.

    January 19, 2021 WebPage Regulatory News
    News

    ECB Releases Results of Bank Lending Survey for Fourth Quarter of 2020

    ECB published results of the quarterly lending survey conducted on 143 banks in the euro area.

    January 19, 2021 WebPage Regulatory News
    News

    ESAs Publish Reporting Templates for Financial Conglomerates

    ESAs published the final draft implementing technical standards on reporting of intra-group transactions and risk concentration of financial conglomerates subject to the supplementary supervision in EU.

    January 18, 2021 WebPage Regulatory News
    News

    EBA Publishes Report on Asset Encumbrance of Banks in EU

    EBA published the annual report on asset encumbrance of banks in EU.

    January 18, 2021 WebPage Regulatory News
    News

    MAS Revises Guidelines on Technology Risk Management

    MAS revised the guidelines that address technology and cyber risks of financial institutions, in an environment of growing use of cloud technologies, application programming interfaces, and rapid software development.

    January 18, 2021 WebPage Regulatory News
    News

    US Agencies Publish Updates for Call Reports, FFIEC 101, and FR Y-9C

    FED updated the reporting form and instructions for the FR Y-9C report on consolidated financial statements for holding companies.

    January 15, 2021 WebPage Regulatory News
    News

    EBA Proposes Guidelines for Establishing Intermediate Parent Entities

    EBA issued a consultation paper on the guidelines on monitoring of the threshold and other procedural aspects of the establishment of intermediate EU parent undertakings, or IPUs, as laid down in the Capital Requirements Directive.

    January 15, 2021 WebPage Regulatory News
    News

    EC Adopts Financial Reporting Changes Arising from Benchmark Reforms

    EC published Regulation 2021/25 that addresses amendments related to the financial reporting consequences of replacement of the existing interest rate benchmarks with alternative reference rates.

    January 14, 2021 WebPage Regulatory News
    News

    BIS Bulletin Examines Key Elements of Policy Response to Cyber Risk

    BIS published a bulletin, or a note, that examines the cyber threat landscape in the context of the pandemic and discusses policies to reduce risks to financial stability.

    January 14, 2021 WebPage Regulatory News
    News

    HMT Updates List of Post-Brexit Equivalence Decisions in UK

    HM Treasury, also known as HMT, has updated the table containing the list of the equivalence decisions that came into effect in UK at the end of the transition period of its withdrawal from EU.

    January 14, 2021 WebPage Regulatory News
    RESULTS 1 - 10 OF 6462