IOSCO published a final report that examines the application of the three internationally recognized cyber standards and frameworks by IOSCO member jurisdictions. This report, by the IOSCO Cyber Task Force, also identifies potential gaps in the application of these standards and seeks to promote sound cyber practices across the IOSCO membership.
The three cyber standards are the CPMI-IOSCO Guidance on Cyber Resilience for Financial Market Infrastructures; the National Institute of Standards and Technology Framework for improving Critical Infrastructure Cybersecurity; and the International Organization for Standardization 27000 series standards. The report does not propose new cyber standards or guidance. By highlighting the application of the Core Standards by some IOSCO members, the Cyber Task Force hopes more members will review their own cyber standards against the practices of the Core Standards and, where relevant, use the Core Standards as a model to further enhance their cyber regimes. Finally, the report sets out a series of questions that firms and regulators may use to promote awareness of cyber good practices or to guide them as they review their own practices.
The report finds that IOSCO members have made good progress in establishing appropriate cyber regimes, though there is still work to be done in key areas. The Cyber Task Force recommends that further work be considered to explore this report’s findings. It is recommended that the Cyber Task Force should consider exploring the use of sector-wide organizational surveys as part of the next phase of its work to gain a better understanding of where the gaps lie. The report is intended to serve as a resource for financial market regulators and firms, raise awareness of existing international cyber standards and frameworks, and encourage the adoption of good practices to protect against cyber risk.
Keywords: International, Banking, Insurance, Securities, PMI, Cyber Risk, Cyber Task Force, Cyber Security, Operational Risk, IOSCO
Previous ArticlePRA Issues Clarifications in Respect of Guidance on MREL Reporting
EC published the Implementing Regulation 2021/763 that lays down implementing technical standards for supervisory reporting and public disclosure of the minimum requirement for own funds and eligible liabilities (MREL).
EBA published a report that examines the convergence of prudential supervisory practices in 2020 and offers conclusions of the EBA college monitoring activity.
APRA announced the standardization of quarterly reporting due dates for authorized deposit-taking institutions.
The private sector working group of ECB on euro risk-free rates published the recommendations to address events that would trigger fallbacks in the Euro Interbank Offered Rate (EURIBOR)-related contracts, along with the €STR-based EURIBOR fallback rates (rates that could be used if a fallback is triggered).
Bundesbank published a list of "EntryPoints" that are accepted in its reporting system; the list provides taxonomy version and name of the module against each EntryPoint.
EBA published the phase 1 of its reporting framework 3.1, with the technical package covering the new reporting requirements for investment firms (under the implementing technical standards on investment firms reporting).
The Sustainable Finance Taskforce of IOSCO held two roundtables, with global stakeholders, on the IOSCO priorities to enhance the reliability, comparability, and consistency of sustainability-related disclosures and to collect views on the practical implementation of a global system architecture for these disclosures.
Asia Pacific Australia Banking APS 111 Capital Adequacy Regulatory Capital Basel RBNZ APRA
ESMA published the final guidelines on outsourcing to cloud service providers.
EBA published annual data for two key concepts and indicators in the Deposit Guarantee Schemes (DGS) Directive—available financial means and covered deposits.