IOSCO published a final report that examines the application of the three internationally recognized cyber standards and frameworks by IOSCO member jurisdictions. This report, by the IOSCO Cyber Task Force, also identifies potential gaps in the application of these standards and seeks to promote sound cyber practices across the IOSCO membership.
The three cyber standards are the CPMI-IOSCO Guidance on Cyber Resilience for Financial Market Infrastructures; the National Institute of Standards and Technology Framework for improving Critical Infrastructure Cybersecurity; and the International Organization for Standardization 27000 series standards. The report does not propose new cyber standards or guidance. By highlighting the application of the Core Standards by some IOSCO members, the Cyber Task Force hopes more members will review their own cyber standards against the practices of the Core Standards and, where relevant, use the Core Standards as a model to further enhance their cyber regimes. Finally, the report sets out a series of questions that firms and regulators may use to promote awareness of cyber good practices or to guide them as they review their own practices.
The report finds that IOSCO members have made good progress in establishing appropriate cyber regimes, though there is still work to be done in key areas. The Cyber Task Force recommends that further work be considered to explore this report’s findings. It is recommended that the Cyber Task Force should consider exploring the use of sector-wide organizational surveys as part of the next phase of its work to gain a better understanding of where the gaps lie. The report is intended to serve as a resource for financial market regulators and firms, raise awareness of existing international cyber standards and frameworks, and encourage the adoption of good practices to protect against cyber risk.
Keywords: International, Banking, Insurance, Securities, PMI, Cyber Risk, Cyber Task Force, Cyber Security, Operational Risk, IOSCO
Previous ArticlePRA Issues Clarifications in Respect of Guidance on MREL Reporting
The Office of the Superintendent of Financial Institutions (OSFI) published the strategic plan for 2022-2025 and the departmental plan for 2022-23.
The European Banking Authority (EBA) is consulting, until August 31, 2022, on the draft implementing technical standards specifying requirements for the information that sellers of non-performing loans (NPLs) shall provide to prospective buyers.
The European Council and the Parliament reached an agreement on the revised Directive on security of network and information systems (NIS2 Directive).
The European Banking Authority (EBA) published the final draft regulatory technical standards specifying information that crowdfunding service providers shall provide to investors on the calculation of credit scores and prices of crowdfunding offers.
The European Securities and Markets Authority (ESMA) published a paper that examines the systemic risk posed by increasing use of cloud services, along with the potential policy options to mitigate this risk.
The European Commission (EC) published a public consultation on the review of revised payment services directive (PSD2) and open finance.
The European Commission (EC) has issued two letters mandating the European Supervisory Authorities (ESAs) to jointly propose amendments to the regulatory technical standards under Sustainable Finance Disclosure Regulation or SFDR.
The European Banking Authority (EBA) published its annual report on convergence of supervisory practices for 2021. Additionally, following a request from the European Commission (EC),
The Swiss National Bank (SNB) published Version 1.2 of the reporting forms (NSFR_G and NSFR_P) on the net stable funding ratio (NSFR) of banks, along with the associated documentation.
The Farm Credit Administration published, in the Federal Register, the final rule on implementation of the Current Expected Credit Losses (CECL) methodology for allowances