2010-03-18
Added · Updated
The Securities and Futures Commission issued this circular to licensed corporations to address IT deficiencies that expose firms and clients to information security risks. The regulator requires firms to implement robust internal controls, including strict access management, password policies, and audit logging, to prevent unauthorized transactions and fraud. Additionally, the document provides an appendix detailing suggested control techniques for information security, access control, encryption, change management, user monitoring, and data backup to ensure operational integrity.
Annex em SECURITIES AND FUTURES COMMISSION He #srsssgezzss
16 March 2010 Circular to All Licensed Corporations on Information Technology Management In the course of our supervision, it has recently come to our attention that certain deficiencies in information technology (“IT”) areas may expose licensed corporations and their clients to information security risks. Such deficiencies include: (@) Use of certain facilities of the IT system (for example superuser account’ and testing : environment?) without adequate safeguards and controls, which may facilitate unauthorized transactions and misappropriation of client assets which are difficult to detect; and (b) Not implementing simple security measures such as password controls (for example, mandatory change of password for the first time login to the information system to prevent the use of common password initially assigned to all users), account management (for example, prompt removal of obsolete user accounts) and the activation of the audit log®. Licensed corporations are hereby reminded that they are required to (a) Have internal control procedures and financial and operational capabilities which can be reasonably expected to protect its operations, its clients and other licensed or registered persons from financial loss arising from theft, fraud, and other dishonest acts, professional misconduct or omissions*; and (b) Establish policies and procedures to ensure the integrity, security, availability, reliability and thoroughness of all information, including documentation and electronically stored data, relevant to the firm's business operations. The firm's operating and information management systems should meet the firm's needs and operate in a secure and adequately controlled environment®. Superuser account granted with privileged access rights can be used to perform a wide range of activities. Any dishonest or improper use of the superuser account may result in (i) improper amendment of clients’ particulars and transaction data (ii) disabling or removing the audit log and (iii) misappropriation of clients’ assets, e.g. through the posting of fraudulent transactions in dummy/nominee accounts. Testing environment is usually set-up to simulate the production environment for testing of system changes. Misuse of testing environment could lead to manipulation of testing data for the production of falsified clients’ information or even statements of account. Audit log records details such as user access and user activities performed in the information system. If the functionality of audit log is not properly managed, this may result in a lack of audit trail of unauthorized access or unusual activities. Paragraph 4.3 of the Code of Conduct for Persons Licensed by or Registered with the Securities and Futures Commission 5 Part IV — Information Management, Management, Supervision and Internal Control Guidelines for Persons Licensed by or Registered with the Securities and Futures Commission 10f5 Tel: (852) 2840 9222 Fax: (852) 2523 4598 Website: www.sfc.hk
2 of 5 Tel: (852) 2840 9222 Fax: (852) 2523 4598 Website: www.sfc.hk In this connection, management of licensed corporations should regularly review their existing information systems, policies and practices and consider enhancement where needed, so as to guard against unauthorized alteration of, or intrusion into, the information systems or the data. Given the significant differences that exist in the organizational structures as well as the nature and scope of the business activities conducted, there exists no single set of universally applicable control techniques and procedures which will guarantee the adequacy of information security. However, with a view to providing more guidance to licensed corporations, the Appendix has included some suggested control techniques and procedures in respect of the following key ideas: (a) Information security policy; (b) Access control; (c) Encryption; (d) Change management; (e) User activities monitoring; and (f) Data backup and continuity planning. Should you have any queries regarding the contents of this circular, please contact Coolky Sit at 2842 7767. Intermediaries Supervision Department Securities and Futures Commission
3 of 5 Tel: (852) 2840 9222 Fax: (852) 2523 4598 Website: www.sfc.hk Appendix Information Technology Management Issues to be considered by licensed corporations A. Information security policy
4 of 5 Tel: (852) 2840 9222 Fax: (852) 2523 4598 Website: www.sfc.hk authorized parties only so as to minimize possible data manipulation and unauthorized system changes 2) Grant remote access right to external parties such as system vendors only on a needs basis and monitor the user activities to detect any unusual or unauthorized activities 3) Terminate remote access connection immediately when such connection is no longer necessary 4) Avoid access to/by external network such as Internet unless proper network safeguards (such as anti-virus mechanism and firewall) are implemented C. Encryption
5 of 5 Tel: (852) 2840 9222 Fax: (852) 2523 4598 Website: www.sfc.hk 5) Access to data restoration functions should be restricted to authorized personnel only 6) Implement an effective business continuity plan. Based on the business continuity plan, IT disaster recovery plan should be formulated to ensure critical information systems can be resumed to support business operations End SFO/IS/004/2010
More like this from HKMA
HKMA published 11 documents in the last 30 days. We email you each new one the day it's published.