Featured Product

    BNM Proposes Guideline on Cloud Technology Risk Assessment

    June 03, 2022

    The Bank Negara Malaysia (BNM) is seeking feedback, until July 15, 2022, on the guideline to assess common key risks and considerations of control measures when financial institutions adopting cloud services. The proposed guideline will be applicable to Islamic as well as non-Islamic banks and insurers, operators of a designated payment system, and across various cloud service models, among others.

    The proposed guideline, which complements the Risk Management in Technology (RMiT) policy document to strengthen cloud risk management capabilities of financial institutions, consists of two parts:

    • Cloud Governance, which describes the considerations governing the cloud usage policy and technology skills capacity to implement cloud services securely and effectively. This part covers areas related to cloud risk management, cloud usage policy, due diligence, access to third-party certifications, contract management, and oversight over cloud service providers and skilled persons with knowledge on cloud services.
    • Cloud Design and Control, which describes the considerations related to designing robust cloud infrastructure and in operationalizing the cloud environment. This part covers aspects on cloud architecture, cloud application delivery model, high velocity software development, cloud backup and recovery, business continuity management, cryptographic key management, user access management, data protection, and cyber-security management.

    With a heightened focus on the aforementioned areas, the proposed guideline states that the financial institutions should:

    • develop and implement a cloud risk management framework, for the Board’s approval, proportionate to the materiality of cloud adoption in its business strategy, to assist in the identification, monitoring and mitigating of risks arising from cloud adoption.
    • regularly review and update the cloud usage policy at least once every three years.
    • review their cloud service providers’ certifications prior to cloud adoption.
    • set out clearly and where relevant, measurable, contractually agreed terms and parameters on the information security and operational standards expected of the cloud service provider.
    • ensure effective oversight over cloud service providers and the cloud service providers’ sub-contractor(s).
    • design a robust cloud architecture and ensure such design is in accordance with the relevant international standards for the intended application.
    • review its risk management policies and practices to ensure effective oversight over the cloud application delivery model.
    • ensure its existing change management process is extended to cover cloud services to promote effective and secure system development.
    • ensure existing backup and recovery procedures are extended to cover cloud services.
    • establish a robust cloud exit strategy as part of its cloud risk management framework to prepare for extreme adverse events such as the unplanned failure or termination of cloud service providers.
    • implement appropriate and relevant encryption techniques to protect the confidentiality and integrity of sensitive data stored on the cloud.
    • ensure the governance and management of cybersecurity operations is extended to cover cloud services, with appropriate control measures to prevent, detect and respond to cyber incidents in the cloud environment to maintain the overall security posture of the institution.
    • ensure the data loss prevention strategy and processes are extended to protect data hosted in cloud services.
    • enhance existing cyber crisis management policies and procedures to remain in a state of readiness to respond to cyber threats in a cloud environment.

      

    Related Links

     

    Keywords: Asia Pacific, Malaysia, Banking, Cloud Service Providers, Operational Risk, Cyber Risk, Insurance, Regtech, Cloud Computing, BNM

    Related Articles
    News

    BIS and Central Banks Experiment with GenAI to Assess Climate Risks

    A recent report from the Bank for International Settlements (BIS) Innovation Hub details Project Gaia, a collaboration between the BIS Innovation Hub Eurosystem Center and certain central banks in Europe

    March 20, 2024 WebPage Regulatory News
    News

    Nearly 25% G-SIBs Commit to Adopting TNFD Nature-Related Disclosures

    Nature-related risks are increasing in severity and frequency, affecting businesses, capital providers, financial systems, and economies.

    March 18, 2024 WebPage Regulatory News
    News

    Singapore to Mandate Climate Disclosures from FY2025

    Singapore recently took a significant step toward turning climate ambition into action, with the introduction of mandatory climate-related disclosures for listed and large non-listed companies

    March 18, 2024 WebPage Regulatory News
    News

    SEC Finalizes Climate-Related Disclosures Rule

    The U.S. Securities and Exchange Commission (SEC) has finalized the long-awaited rule that mandates climate-related disclosures for domestic and foreign publicly listed companies in the U.S.

    March 07, 2024 WebPage Regulatory News
    News

    EBA Proposes Standards Related to Standardized Credit Risk Approach

    The European Banking Authority (EBA) has been taking significant steps toward implementing the Basel III framework and strengthening the regulatory framework for credit institutions in the EU

    March 05, 2024 WebPage Regulatory News
    News

    US Regulators Release Stress Test Scenarios for Banks

    The U.S. regulators recently released baseline and severely adverse scenarios, along with other details, for stress testing the banks in 2024. The relevant U.S. banking regulators are the Federal Reserve Bank (FED), the Federal Deposit Insurance Corporation (FDIC), and the Office of the Comptroller of the Currency (OCC).

    February 28, 2024 WebPage Regulatory News
    News

    Asian Governments Aim for Interoperability in AI Governance Frameworks

    The regulatory landscape for artificial intelligence (AI), including the generative kind, is evolving rapidly, with governments and regulators aiming to address the challenges and opportunities presented by this transformative technology.

    February 28, 2024 WebPage Regulatory News
    News

    EBA Proposes Operational Risk Standards Under Final Basel III Package

    The European Union (EU) has been working on the final elements of Basel III standards, with endorsement of the Banking Package and the publication of the European Banking Authority (EBA) roadmap on Basel III implementation in December 2023.

    February 26, 2024 WebPage Regulatory News
    News

    EFRAG Proposes XBRL Taxonomy and Standard for Listed SMEs Under ESRS

    The European Financial Reporting Advisory Group (EFRAG), which plays a crucial role in shaping corporate reporting standards in European Union (EU), is seeking comments, until May 21, 2024, on the Exposure Draft ESRS for listed SMEs.

    February 23, 2024 WebPage Regulatory News
    News

    ECB to Expand Climate Change Work in 2024-2025

    Banking regulators worldwide are increasingly focusing on addressing, monitoring, and supervising the institutions' exposure to climate and environmental risks.

    February 23, 2024 WebPage Regulatory News
    RESULTS 1 - 10 OF 8957