IOSCO published a final report that examines the application of the three internationally recognized cyber standards and frameworks by IOSCO member jurisdictions. This report, by the IOSCO Cyber Task Force, also identifies potential gaps in the application of these standards and seeks to promote sound cyber practices across the IOSCO membership.
The three cyber standards are the CPMI-IOSCO Guidance on Cyber Resilience for Financial Market Infrastructures; the National Institute of Standards and Technology Framework for improving Critical Infrastructure Cybersecurity; and the International Organization for Standardization 27000 series standards. The report does not propose new cyber standards or guidance. By highlighting the application of the Core Standards by some IOSCO members, the Cyber Task Force hopes more members will review their own cyber standards against the practices of the Core Standards and, where relevant, use the Core Standards as a model to further enhance their cyber regimes. Finally, the report sets out a series of questions that firms and regulators may use to promote awareness of cyber good practices or to guide them as they review their own practices.
The report finds that IOSCO members have made good progress in establishing appropriate cyber regimes, though there is still work to be done in key areas. The Cyber Task Force recommends that further work be considered to explore this report’s findings. It is recommended that the Cyber Task Force should consider exploring the use of sector-wide organizational surveys as part of the next phase of its work to gain a better understanding of where the gaps lie. The report is intended to serve as a resource for financial market regulators and firms, raise awareness of existing international cyber standards and frameworks, and encourage the adoption of good practices to protect against cyber risk.
Keywords: International, Banking, Insurance, Securities, PMI, Cyber Risk, Cyber Task Force, Cyber Security, Operational Risk, IOSCO
Previous ArticlePRA Issues Clarifications in Respect of Guidance on MREL Reporting
A Consultative Group on Risk Management (CGRM) at the Bank for International Settlements (BIS) published a report that examines incorporation of climate risks into the international reserve management framework.
The European Banking Authority (EBA) published the final guidelines on liquidity requirements exemption for investment firms, updated version of its 5.2 filing rules document for supervisory reporting, and Single Rulebook Question and Answer (Q&A) updates in July 2022.
The Australian Prudential Regulation Authority (APRA) is seeking comments, until October 21, 2022, on the introduction of CPS 230, which is the new cross-industry prudential standard on operational risk management.
The European Commission published a Delegated Regulation 2022/1301 on the information to be provided in accordance with the simple, transparent, and standardized (STS) notification requirements for on-balance-sheet synthetic securitizations.
The Australian Prudential Regulation Authority (APRA) is announced revisions to the capital framework for authorized deposit-taking institutions to implement the "unquestionably strong" capital ratios and the Basel III reforms.
The European Banking Authority (EBA) published a report that examines the use of certain exemptions included in the large exposures regime under the Capital Requirements Regulation (CRR).
The Bank of England (BoE), the Prudential Regulation Authority (PRA), and the Financial Conduct Authority (FCA) published a joint discussion paper that sets out potential measures to oversee and strengthen the resilience of services provided by critical third parties to the financial sector in UK.
The Bank of England (BoE) issued a communication to firms to provide an update on the progress of the joint data transformation program—which is being led by BoE, the Financial Conduct Authority (FCA), and the industry—for the financial sector in UK.
The European Banking Authority (EBA) published the draft methodology, templates, and template guidance for the European Union-wide stress test in 2023.
The European Banking Authority (EBA) and the European Securities and Markets Authority (ESMA) jointly published the final guidelines on common procedures and methodologies for the supervisory review and evaluation process (SREP) for investment firms.