2020-08-04
Added · Updated
Circular Letter CVM/SMI 05/2020 establishes that intermediaries must notify the SMI within 72 hours of activating a Business Continuity Plan or when a relevant incident affecting critical systems occurs. It clarifies that no fixed deadline applies to cybersecurity incidents, requiring immediate notification only after the attack is confirmed and mitigation plans are established. The circular further specifies that the prohibition on applying client resources to the intermediary's own portfolio applies exclusively to securities, while other applications still require prior client authorization.
CVM published 2 documents in the last 30 days — get each new one by email the day it lands.
04/08/2020 SEI/CVM - 1068365 - Circular Letter https://sei.cvm.gov.br/sei/controlador.php?acao=documento_imprimir_web&acao_origem=arvore_visualizar&id_documento=1126904&infra_sistema=10000… 1/5 SECURITIES AND EXCHANGE COMMISSION OF BRAZIL (CVM) Rua Sete de Setembro, 111/2-5th and 23-34th Floors, Center, Rio de Janeiro/RJ – ZIP: 20050-901 – Brazil - Tel.: (21) 3554-8686 Rua Cincinato Braga, 340/2nd, 3rd and 4th Floors, Bela Vista, São Paulo/ SP – ZIP: 01333-010 – Brazil - Tel.: (11) 2146-2000 SCN Q.02 – Bl. A – Ed. Corporate Financial Center, S.404/4th Floor, Brasília/DF – ZIP: 70712-900 – Brazil -Tel.: (61) 3327-2030/2031 www.cvm.gov.br Circular Letter No. 5/2020-CVM/SMI Rio de Janeiro, August 4, 2020.
To
Directors responsible for CVM Instruction No. 505/11 at Intermediaries
Subject: I - Deadlines for communication to SMI:
a) Activation of Business Continuity Plan (BCP); b) Relevant Incidents in Critical Systems; c) Relevant Cybersecurity Incidents.
II - Scope of the prohibition on applying client resources.
Dear Directors,
This Circular Letter aims to provide guidance to intermediaries on two subjects that will be subject to CVM Instruction No. 505/11, following the changes introduced by CVM Instruction 612/19, effective as of 09/01/2020:
(I) deadlines for communication to SMI regarding situations related to BCP, Critical Systems and Cybersecurity; and (II) Scope of the prohibition on applying client resources.
I – INTRODUCTION
04/08/2020 SEI/CVM - 1068365 - Circular Letter https://sei.cvm.gov.br/sei/controlador.php?acao=documento_imprimir_web&acao_origem=arvore_visualizar&id_documento=1126904&infra_sistema=10000… 2/5
DEADLINES FOR COMMUNICATION TO SMI
Business Continuity Plan (BCP)
2. With the advent of CVM Instruction No. 612/19, intermediaries must implement a business continuity plan (BCP) that establishes procedures and estimated deadlines for resuming and recovering activities in the event of interruption of critical business processes, as well as necessary internal and external communication actions and the cases in which communication must extend to clients (art. 35-A, item II, of CVM Instruction No. 612/19).
3. Among the processes considered critical, the BCP must cover the processes of receiving and executing orders and of reconciling and updating the positions of its clients, with the objective of preserving service to clients (art. 35-A, § 1º, of CVM Instruction No. 612/19).
4. In the event of an event that triggers the BCP, the management bodies and the SMI must be notified in a timely manner, in accordance with art. 35-A, § 4º, of CVM Instruction No. 612/19.
5. And, as stipulated by § 5º of the aforementioned article, the communication must present:
I - causes of the activation of the business continuity plan, indicating the critical processes affected; II - measures already adopted by the intermediary or those it intends to adopt; III - time consumed in solving the event or expected deadline for this to occur; and IV - any other information considered important. Critical Systems
6. Defined in the 'caput' of art. 35-B of CVM Instruction No. 612/19, critical systems are all computers, networks and electronic and technological systems that are linked to critical business processes and that directly execute or indirectly provide support to functionalities whose malfunction or unavailability may cause significant impact on the intermediary's business.
7. In the event of relevant incidents that affect its critical systems and have a significant impact on clients, the management bodies and the SMI must be notified in a timely manner, in accordance with art. 35-C, § 1º, of CVM Instruction No. 612/19.
8. And, as stipulated by § 2º of the aforementioned article, the communication must present:
I - a description of the incident, indicating how clients were affected; II - assessment of the number of potentially affected clients; III - measures already adopted by the intermediary or those it intends to adopt; IV - time consumed in solving the event or expected deadline for this to occur; and V - any other information considered important. Cybersecurity
9. The intermediary must adopt a policy that encompasses a cybersecurity program, covering, among others, the measures that must be adopted to reduce the institution's vulnerability against cyberattacks, as prescribed by art. 35-H, item II, of CVM Instruction No. 612/19.
10. In the event of relevant cybersecurity incidents, the management bodies and the SMI must be notified in a timely manner, in accordance with the 'caput' of art. 35-I.
11. And, as stipulated by § 1º of the aforementioned article, the communication must present:
I - a description of the incident, including indication of the sensitive data or information affected; II - assessment of the number of potentially affected clients; III - measures already adopted by the intermediary or those it intends to adopt; IV - time consumed in solving the event or expected deadline for this to occur; and V - any other information considered important.
12. And furthermore, in accordance with § 2º of the same article, the intermediary must prepare and send to the SMI a final report containing at least:
I - description of the incident and measures taken, informing the impact generated by the incident on the institution's operation and its repercussions on client data; and II - improvements to controls identified with the objective of preventing, monitoring and detecting the occurrence of cybersecurity incidents, if applicable.
13. Finally, now in accordance with § 3º of the same article, the intermediary must keep available to the SMI a copy:
I - of communications made with its clients, if any; and II - of internal investigation reports produced by the intermediary or by third parties on the analysis of the incident and the conclusions of the examinations carried out. SCOPE OF THE PROHIBITION ON APPLYING CLIENT RESOURCES
14. Furthermore, CVM Instruction No. 612/19 brought, in its art. 35, new prohibitions on the intermediary's conduct, among them, the one contained in item XI, which prohibits the intermediary from applying client resources in the constitution and operation of its portfolio.
II – DEADLINES FOR INTERMEDIARIES TO COMMUNICATE TO SMI BCP and Critical Systems
15. Initially, it is worth highlighting that critical systems are all computers, networks and electronic and technological systems that are linked to critical business processes and that directly execute or indirectly provide support to functionalities whose malfunction or unavailability may cause significant impact on the intermediary's business.
16. And, among the processes considered critical, the BCP must cover the processes of receiving and executing orders and of reconciling and updating the positions of its clients.
17. In this context, communication to the SMI is considered timely, whether in the event of an event that triggers the BCP (art. 35-A, § 4º, of CVM Instruction No. 612/19), or in the event of relevant incidents that affect its critical systems and have a significant impact on clients (art. 35-C, § 1º, of CVM Instruction No. 612/19), the deadline of, respectively:
I - up to 72 (seventy-two hours), after the activation of the BCP;
04/08/2020 SEI/CVM - 1068365 - Circular Letter https://sei.cvm.gov.br/sei/controlador.php?acao=documento_imprimir_web&acao_origem=arvore_visualizar&id_documento=1126904&infra_sistema=10000… 4/5 II - up to 72 (seventy-two hours), after the occurrence of the incident. Cybersecurity
18. For its part, regarding the occurrence of relevant cybersecurity incidents, it must be understood that cyber threats evolve rapidly, both in volume and sophistication, which explains the difficulties each intermediary faces in the face of the multiple characteristics of cyberattacks.
19. In fact, after the confirmed occurrence of the cyberattack, it must be assumed that each intermediary will have a differentiated response, largely due to the complexity of dealing with the cyberattack on a case-by-case basis.
20. For these reasons, the SMI understands that, at the current moment, no deadline should be set for the communication of relevant cybersecurity incidents.
21. However, once the intermediary has confirmed the occurrence of the cyberattack, in its entirety, and established action plans to mitigate it, it must notify the SMI immediately, to comply with art. 35-I, 'caput', of CVM Instruction No. 612/19.
III – SCOPE OF THE PROHIBITION ON APPLYING CLIENT RESOURCES
22. It is certain that CVM Instruction No. 612/19 introduced the prohibition of the intermediary applying client resources in its portfolio operations.
23. However, it is worth emphasizing that the Instruction is intended for intermediaries in the securities market, so the aforementioned prohibition covers only the application of client resources in securities, when applied in the name of the intermediary's portfolio.
24. Despite the prohibition affecting only application in securities, still, for the purposes of art. 30, 'caput' and sole paragraph, of the current CVM Instruction No. 505/11, there must be the client's prior command to allow the intermediary to apply its resources in other applications other than in securities.
IV – CONCLUSION
25. It is worth highlighting, once again, that transparency in the brokerage market is a requirement of CVM Instruction No. 505/11, reflected in its art. 30, prohibiting the intermediary from privileging its own interests:
Art. 30. The intermediary must conduct its activities with good faith, diligence and loyalty towards its clients.
Sole paragraph. It is prohibited for the intermediary to privilege its own interests or those of persons linked to it to the detriment of clients' interests.
Sincerely,
04/08/2020 SEI/CVM - 1068365 - Circular Letter https://sei.cvm.gov.br/sei/controlador.php?acao=documento_imprimir_web&acao_origem=arvore_visualizar&id_documento=1126904&infra_sistema=10000… 5/5 Document electronically signed by Francisco José Bastos Santos, Superintendent, on 04/08/2020, at 15:01, based on art. 6º, § 1º, of Decree No. 8.539, of October 8, 2015. The authenticity of the document can be verified on the site https://sei.cvm.gov.br/conferir_autenticidade, informing the verification code 1068365 and the CRC code 29B71BDA. This document's authenticity can be verified by accessing https://sei.cvm.gov.br/conferir_autenticidade, and typing the "Verification Code" 1068365 and the "CRC Code" 29B71BDA. Reference: Process No. 19957.005135/2019-17 SEI Document No. 1068365
Read the rest free
Source: Comissão de Valores Mobiliários — original document · Summary generated with machine assistance and reviewed before publication; the authoritative text is the regulator's original document. How RegAlert works
More like this from CVM
CVM published 2 documents in the last 30 days. We email you each new one the day it's published.