Featured Product

    MAS Issues Measures to Strengthen Cyber Resilience in Financial Sector

    August 06, 2019

    MAS has set out the measures that financial institutions must take to mitigate the growing risk of cyber threats. To this end, MAS issued a set of legally binding requirements to raise the cyber security standards and strengthen cyber resilience of the financial sector in Singapore. The measures will come into effect on August 06, 2020. MAS also published the frequently asked questions (FAQs) on these measures. These recently issued cyber hygiene measures are intended for financial holding companies (Notice 1119), all banks in Singapore pursuant to section 55(1) of the Banking Act (Notice 655), merchant banks (Notice 1118), financial advisers (Notice FAA-N21), capital market entities (Notice CMG-N03, insurance brokers (Notice 507), finance companies (Notice 834), and insurance agents (Notice 132).

    These measures make compulsory the key elements in the existing MAS Technology Risk Management guidelines. The technology risk management guidelines are a set of best practices that provide financial institutions with guidance on the oversight of technology risk management, security practices, and controls to address technology risks. MAS expects financial institutions to observe the technology risk management guidelines, as this will be taken into account in MAS’ risk assessment of the financial institutions. As per the now-published measures on cyber hygiene, financial institutions must:

    • Establish and implement robust security for IT systems
    • Ensure updates are applied to address system security flaws in a timely manner
    • Deploy security devices to restrict unauthorized network traffic
    • Implement measures to mitigate the risk of malware infection
    • Secure the use of system accounts with special privileges to prevent unauthorized access
    • Strengthen user authentication for critical systems as well as systems used to access customer information

    MAS, in September 2018, had sought feedback from the public on the proposal to make this suite of cyber security measures into legally binding requirements. Financial institutions generally welcomed these measures and provided some suggestions about implementation of the requirements. These suggestions include focusing on strengthening user access to systems that store or access customer data and allowing more time for financial institutions to design, acquire, and integrate robust user authentication technology into their critical systems.

     

    Keywords: Asia Pacific, Singapore, Banking, Insurance, Securities, Cyber Resilience, Cyber Security, Cyber Risk, Technology Risk, MAS

    Related Articles
    News

    SEC Finalizes Capital and Margin Requirements for Security-Based Swaps

    SEC adopted a package of rules and rule amendments to establish capital, margin, and segregation requirements for security-based swaps, under Title VII of the Dodd-Frank Act.

    August 22, 2019 WebPage Regulatory News
    News

    ECB Revises Prudential Provisioning Expectations for New NPEs

    ECB is revising its supervisory expectations for prudential provisioning of new non-performing exposures (NPEs) specified in the “Addendum to the ECB Guidance to banks on non-performing loans” (Addendum)

    August 22, 2019 WebPage Regulatory News
    News

    CFTC Proposes to Revise Information Collection on Margin Requirements

    CFTC is requesting comments on the burdens associated with certain aspects of the Margin Requirements for Uncleared Swaps for Swap Dealers and Major Swap Participants (final rule).

    August 21, 2019 WebPage Regulatory News
    News

    FASB to Delay Effective Date for Insurance Contracts Standard

    FASB issued a proposed Accounting Standards Update that would grant all insurance companies that issue long-duration contracts, such as life insurance and annuities, additional time to apply the standard that addresses this area of financial reporting.

    August 21, 2019 WebPage Regulatory News
    News

    EBA Publishes Phase 2 of Technical Package on Reporting Framework 2.9

    EBA published phase 2 of its technical package on the reporting framework 2.9, which includes validation rules, Data Point Model (DPM) data dictionary, and XBRL taxonomies.

    August 21, 2019 WebPage Regulatory News
    News

    FSB Publishes Responses to Its Consultation Related to SME Financing

    FSB published responses received to the consultation on a report on the evaluation of the effects of financial regulatory reforms on small and medium-sized enterprise (SME) financing.

    August 21, 2019 WebPage Regulatory News
    News

    APRA Revises Related Entities Standard for Banks

    APRA published a strengthened prudential standard APS 222 on associations with related entities, with the aim to mitigate contagion risk within banking groups.

    August 20, 2019 WebPage Regulatory News
    News

    EBA and ESMA Issue Joint Response to EC Letter on Crypto-Assets

    EBA and ESMA issued a joint response to the EC letter, from July 19, 2019, on crypto-assets.

    August 20, 2019 WebPage Regulatory News
    News

    FSB on Responses to Consultation on Wind-Down of Trading Portfolios

    FSB published responses received to the consultation on the solvent wind-down of the derivatives and trading book portfolio of a global systemically important bank (G-SIB).

    August 19, 2019 WebPage Regulatory News
    News

    FSB Publishes Responses to Consultation on Resolvability Disclosures

    FSB published responses received to the consultation on disclosures for resolution planning and resolvability of banks.

    August 19, 2019 WebPage Regulatory News
    RESULTS 1 - 10 OF 3681