MAS revised the guidelines that address technology and cyber risks of financial institutions, in an environment of growing use of cloud technologies, application programming interfaces, and rapid software development. Post a consultation, the enhancements include new guidance on effective cyber surveillance, secure software development, adversarial attack simulation exercise, and management of cyber risks posed by the emerging technologies such as Internet of Things. MAS also published a response to the feedback received during the consultation process, in addition to a set of the frequently asked questions (FAQs) on the guidelines.
The guidelines on technology risk management set out the risk management principles and best practices to guide financial institutions, including banks, to establish sound and robust technology risk governance and oversight and to maintain cyber resilience. In particular, for financial institutions, the guidelines set out:
- Expectations to have in place effective technology risk management practices and controls to protect the information technology infrastructure: the institutions are required to test and validate the effectiveness of the recovery process once every 12 months.
- Enhanced risk mitigation strategies to establish a robust process for the timely analysis and sharing of cyber threat intelligence within the financial ecosystem and to conduct cyber exercises to allow institutions to stress test their cyber defenses by simulating the attack tactics, techniques, and procedures used by real-world attackers.
- Expectations to exercise strong oversight of arrangements with third-party service providers, to ensure system resilience as well as maintain data confidentiality and integrity.
- Additional guidance on the roles and responsibilities of the board of directors and senior management: the board and senior management should ensure that a Chief Information Officer and a Chief Information Security Officer, with the requisite experience and expertise, are appointed and accountable for managing technology and cyber risks and the board should include members with the relevant knowledge to provide effective oversight of technology and cyber risks.
- Expectations to establish and continuously improve IT processes and controls to preserve confidentiality, integrity and availability of data and information technology systems. Security measures should be implemented to prevent and detect the use of unauthorized internet services that allow users to communicate or store confidential data; examples of such services include social media, cloud storage, and file sharing, e-mails, and messaging applications.
MAS expects financial institutions to observe the guidelines on technology risk management as this will be considered in the risk assessment of MAS with respect to the financial institutions. The guidelines provide general guidance and are not intended to be comprehensive nor replace or override any legislative provisions. They should be read in conjunction with the provisions of the relevant legislation, the subsidiary legislation made under the relevant legislation, as well as written directions, notices, codes, and other guidelines that MAS may issue from time to time pursuant to the relevant legislation and subsidiary legislation. In particular, the guidelines should be read with the Notice on Technology Risk Management and Notice on Cyber Hygiene.
Keywords: Asia Pacific, Singapore, Banking, Insurance, Securities, Technology Risk, Cyber Risk, FAQ, Internet of Things, Governance, Cyber Resilience, MAS
Previous ArticleESAs Publish Reporting Templates for Financial Conglomerates
The European Banking Authority (EBA) published its work program for 2023 as well as the technical package for phase 3 of version 3.2 of its reporting framework.
The Board of Governors of the Federal Reserve System (FED) announced a pilot climate scenario analysis exercise for six largest banks in the U.S.
The Bank for International Settlements (BIS) published a paper that studies impact of fintech lending on credit access for small businesses in U.S.
The Prudential Regulation Authority (PRA) issued the policy statement PS8/22 to amend the Own Funds and Eligible Liabilities (CRR) Part of the PRA Rulebook and update the supervisory statement SS7/13 titled "Definition of capital (CRR firms).
The European Banking Authority (EBA) launched the EU-wide transparency exercise for 2022, with results of the exercise expected to be published at the beginning of December, along with the annual Risk Assessment Report.
The Single Resolution Board (SRB) welcomed the adoption of the review of the Capital Requirements Regulation, or CRR, also known as the "CRR quick-fix."
The European Commission (EC) recently adopted the Delegated Regulation 2022/1622, which sets out the regulatory technical standards to specify the countries that constitute advanced economies for the purpose of specifying risk-weights for the sensitivities to equity.
The European Banking Authority (EBA) published the final draft regulatory technical standards specifying and, where relevant, calibrating the minimum performance-related triggers for simple.
The European Central Bank (ECB) is undertaking the integrated reporting framework (IReF) project to integrate statistical requirements for banks into a standardized reporting framework that would be applicable across the euro area and adopted by authorities in other EU member states.
The European Banking Authority (EBA) has been awarded the top European Standard for its environmental performance under the European Eco-Management and Audit Scheme (EMAS).