Featured Product

    MAS Emphasizes Need to Review Security Controls Amid COVID

    November 10, 2020

    The Cyber Security Advisory Panel (CSAP) of MAS held a meeting in November 2020. At the meeting, the Panel shared insights on cyber risks in the new operating environment and made several recommendations related to the risk profiles of financial institutions and third-party vendors and the use of open-source software. Meanwhile, MAS is also consulting on the requirements to strengthen the identity verification process of financial institutions, with the comment period ending on December 09, 2020. This measure is intended to address the risk of impersonation fraud arising from the theft and misuse of an individual’s personal particulars.

    The MAS Managing Director Ravi Menon, who chaired the meeting, said that the "CSAP members have provided useful recommendations on maintaining cyber security against the backdrop of growing reliance on remote working arrangements and cloud service providers." The following are the key recommendations from the CSAP meeting:

    • Reviewing risk profiles and adequacy of risk mitigating measures. The meeting highlighted the need for financial institutions to assess if their existing risk profiles have changed and remain acceptable. This is to ensure that, in the long run, appropriate controls are implemented to mitigate any new risks.  
    • Maintaining oversight of third-party vendors and their controls. With the increased reliance on third-party vendors, the Panel emphasized the need for financial institutions to step up their oversight of these counterparts and to monitor and secure remote access by third-parties to financial institutions’ systems. This is even more important during the COVID-19 pandemic where remote working has become pervasive.
    • Strengthening governance over the use of open-source software. Vulnerabilities in open-source software are typically targeted and exploited by threat actors. The Panel recommended that financial institutions establish policies and procedures on the use of open-source software and to ensure that the code is robustly reviewed and tested before deployment in the IT environment of financial institutions.

    Over two days of virtual meetings, the Panel also exchanged views with the Association of Banks in Singapore Standing Committee on Cyber Security (SCCS) and the Insurance SCCS on enhancing cloud resiliency, monitoring insider threats, and the role of cyber insurance in risk management. Participants included representatives from government agencies such as the Ministry of Communications and Information, the Ministry of Defense, and the Government Technology Agency.

     

    Comment Due Date: December 09, 2020

    Keywords: Asia Pacific, Singapore, Banking, Securities, Cyber Risk, CSAP, COVID-19, Fintech, Regtech, Open Source Software, Cloud Computing, Third Party Vendors, MAS 

    Related Articles
    News

    FED Proposes to Extend Data Collection Under Stress Testing Guidance

    FED proposed three-year extension, without revision, of the information collection FR 4202, titled "Recordkeeping Provisions Associated with Stress Testing Guidance."

    March 08, 2021 WebPage Regulatory News
    News

    FCA Proposes Updates to Guidance on Mortgage Repossessions

    FCA updated the draft guidance for firms to ensure that mortgage customers whose homes may be repossessed are treated fairly and appropriately, particularly where there are risks of harm to customers who are vulnerable as a result of the COVID-19 pandemic.

    March 05, 2021 WebPage Regulatory News
    News

    FCA Announces Cessation Timeline for Certain LIBOR Benchmark Settings

    FCA issued a statement on the cessation or loss of representativeness of the 35 LIBOR benchmark settings published by ICE Benchmark Administration or IBA.

    March 05, 2021 WebPage Regulatory News
    News

    EBA Publishes Reporting and Disclosures Framework for Investment Firms

    EBA published a package that includes the final draft implementing technical standards on supervisory reporting and disclosures of investment firms.

    March 05, 2021 WebPage Regulatory News
    News

    BIS Examines Use of Big Data and Machine Learning at Central Banks

    BIS published a paper that provides an overview on the use of big data and machine learning in the central bank community.

    March 04, 2021 WebPage Regulatory News
    News

    APRA Finalizes Reporting Standard for Operational Risk Requirements

    APRA finalized the reporting standard ARS 115.0 on capital adequacy with respect to the standardized measurement approach to operational risk for authorized deposit-taking institutions in Australia.

    March 03, 2021 WebPage Regulatory News
    News

    ECB Publishes Guide for Determining Penalties for Regulatory Breaches

    ECB published a guide that outlines the principles and methods for calculating the penalties for regulatory breaches of prudential requirements by banks.

    March 02, 2021 WebPage Regulatory News
    News

    MAS Sets Out Good Practices to Manage Operational Risks Amid COVID

    MAS and The Association of Banks in Singapore (ABS) jointly issued a paper that sets out good practices for the management of operational and other risks stemming from new work arrangements adopted by financial institutions amid the COVID-19 pandemic.

    March 02, 2021 WebPage Regulatory News
    News

    ACPR Announces New Data Collection Application for Banks and Insurers

    ACPR announced that a new data collection application, called DLPP (Datalake for Prudential), for collecting banking and insurance prudential data will go into production on April 12, 2021.

    March 02, 2021 WebPage Regulatory News
    News

    BCB Maintains CCyB at 0%, Initiates First Cycle of Regulatory Sandbox

    BCB announced that the Financial Stability Committee decided to maintain the countercyclical capital buffer (CCyB) for Brazil at 0%, at least until the end of 2021.

    March 02, 2021 WebPage Regulatory News
    RESULTS 1 - 10 OF 6659