2010-03-18
Added · Updated
The Securities and Futures Commission issued a circular highlighting IT deficiencies identified during supervision and reminding intermediaries to implement adequate controls against unauthorized system alterations or intrusions. Registered institutions are required to assess the adequacy of their existing controls against SFC requirements and relevant Hong Kong Monetary Authority guidelines. Where necessary, institutions must make appropriate enhancements to their IT risk management measures to ensure compliance.
Our Ref: Encl. c.c. Circulars 18 Mar 2010 Circular issued by the Securities and Futures Commission (SFC) Regarding Information Technology Management B1/15C G16/1C 18 March 2010 The Chief Executive All Registered Institutions Dear Sir/Madam, Circular issued by the Securities and Futures Commission (SFC) Regarding Information Technology Management I am writing to draw your attention to a circular issued by the SFC on 16 March 2010 ("the SFC Circular"). The SFC Circular sets out certain deficiencies in information technology ("IT") areas identified in the course of the SFC's supervision. The SFC Circular reminds intermediaries of the need to implement adequate controls for guarding against unauthorised alternation of, or intrusion into, the information systems or the data. In addition, the SFC Circular puts forth some recommended control measures for managing IT risks. A copy of the SFC Circular is enclosed at Annex. Your institution is required to assess the adequacy and effectiveness of its related controls against the requirements set out in the SFC Circular as well as the relevant guidelines1 issued by the Hong Kong Monetary Authority, and where necessary, make appropriate enhancements. Yours faithfully, Nelson Man Executive Director (Banking Supervision) Annex (PDF file, 107KB) SFC (Attn: Mr Stephen Po, Senior Director of Intermediaries Supervision)
1 Including, among others, Supervisory Policy Manual modules on "General Principles for Technology Risk Management", "Supervision of E-banking", "Business Continuity Planning", and circular on "Customer data protection" (2008) Last revision date : 01 August 2011
More like this from HKMA
HKMA published 11 documents in the last 30 days. We email you each new one the day it's published.