2026-06-02

Added · Updated

Code of Practice Pursuant to the Protection of Critical Infrastructures (Computer Systems) Ordinance for Authorized Institutions Designated as Critical Infrastructure Operators

The Hong Kong Monetary Authority issues this Code of Practice to implement the Protection of Critical Infrastructures (Computer Systems) Ordinance for authorized institutions designated as critical infrastructure operators. The document mandates the use of specific standardized forms to notify the regulator of operator changes, the appointment of employees supervising computer-system security management units, and material changes to critical computer systems. These submissions must be made via secure email within statutory timeframes and include detailed technical and risk assessment information to ensure regulatory oversight.

Hong Kong Monetary Authority logo

Hong Kong

Hong Kong Monetary Authority

Click to view thumbnail

Page 1 of 7 FORM FOR NOTIFYING AN OPERATOR CHANGE Pursuant to section 20 of the Protection of Critical Infrastructures (Computer Systems) Ordinance HKMA’s Remark An authorized institution designated by the Monetary Authority (MA) as a CI operator (Designated AI) should submit this completed form to the MA by email (pcicso_ai@hkma.iclnet.hk) using an ICLNet secure e-mail account. The submission should be copied to the Designated AI’s usual supervisory contact at the HKMA, including both the Technology Risk Team overseeing this matter and the Case Management Team, and made within the period specified in section 20(1) the Protection of Critical Infrastructures (Computer Systems) Ordinance. A. Background information Information of the Designated AI:

  1. Full name:
  2. Reason(s) for operator change: Please tick the appropriate box(es) ☐ Sale or disposal of all or any part of its business ☐ Mergers or restructuring ☐ Resolution ☐ Others: (please specify: _______________)
  3. Impact to the essential services resulting from the operator change: Please explain how the operator change will / has impacted the provision of the essential services, including a comparison of the same prior to and after the operator change. B. Information of the new operator (if applicable):
  4. Organization Full name: Business registration number: Office address:

Page 2 of 7 2. Organization contact person Full name: Post title: Office number: Email address: 3. Effective Date (dd/mm/yyyy) C. Reporting entity information Name: Post title: Office & mobile contact: Email address: Form submission date (dd/mm/yyyy): Declaration By submitting this form, we hereby confirm that the information provided in this reporting form is valid and has been reviewed by the supervisor of the computer-system security management unit in the institution. Personal Information Collection Statement: The personal information provided to the MA in this form will be used: (i) for the purposes of administering the Protection of Critical Infrastructures (Computer Systems) Ordinance (“the Ordinance”); and (ii) for the exercise of any functions, powers or duties under the Ordinance (whether by the MA, as a designated authority specified in column 2 of Part 2 of Schedule 2 to the Ordinance, or to the extent applicable, by the Commissioner of Critical Infrastructure (Computer-system Security) (“the Commissioner”). The MA may transfer the personal information to the Commissioner in the performance of any function under the Ordinance or for carrying into effect the provisions of the Ordinance, or to such other parties or for such purposes as permitted under section 57 of the Ordinance. The MA will take all practical steps to ensure that the personal information is not kept longer than is necessary for the fulfilment of the purpose (including any directly related purpose) for which the personal information is or is to be used. The data subject or relevant persons as defined in section 2 or 17A of the Personal Data (Privacy) Ordinance (“the PDPO”) have a right of access and correction with respect to personal information as provided for in sections 18 and 22 of and Principle 6 of Schedule 1 to the PDPO. The right of access includes the right to obtain a copy of the personal information provided in this form. Enquiries concerning the personal information collected by means of this form, including access and corrections, should be addressed to the MA (email: pcicso_ai@hkma.iclnet.hk).

Page 3 of 7 FORM FOR NOTIFYING APPOINTMENT OF EMPLOYEE SUPERVISING COMPUTER￾SYSTEM SECURITY MANAGEMENT UNIT Pursuant to section 21 of the Protection of Critical Infrastructures (Computer Systems) Ordinance HKMA’s Remark An authorized institution designated by the Monetary Authority (MA) as a CI operator (Designated AI) should submit this completed form to the MA by email (pcicso_ai@hkma.iclnet.hk) using an ICLNet secure e-mail account. The submission should be copied to the Designated AI’s usual supervisory contact at the HKMA, including both the Technology Risk Team overseeing this matter and the Case Management Team, and made within the period specified in section 21(4) and section 21(6) the Protection of Critical Infrastructures (Computer Systems) Ordinance. A. Background Information Information of the Designated AI: Full name: B. Employee details Information of the employee supervising the computer-system security management unit Full name: Post title: Office & mobile contact: Email address: Relevant professional qualification(s): *Please attach the relevant documentary proof. Relevant experience: *Please attach the relevant documentary proof. Effective date (dd/mm/yyyy) *Please attach the relevant documentary proof. C. Reporting entity information Name: Post title:

Page 4 of 7 Office & mobile contact: Email address: Form submission date (dd/mm/yyyy): Declaration By submitting this form, we hereby confirm that the information provided in this reporting form is valid and has been reviewed by the supervisor of the computer-system security management unit in the institution. Personal Information Collection Statement: The personal information provided to the MA in this form will be used: (i) for the purposes of administering the Protection of Critical Infrastructures (Computer Systems) Ordinance (“the Ordinance”); and (ii) for the exercise of any functions, powers or duties under the Ordinance (whether by the MA, as a designated authority specified in column 2 of Part 2 of Schedule 2 to the Ordinance, or to the extent applicable, by the Commissioner of Critical Infrastructure (Computer-system Security) (“the Commissioner”). The MA may transfer the personal information to the Commissioner in the performance of any function under the Ordinance or for carrying into effect the provisions of the Ordinance, or to such other parties or for such purposes as permitted under section 57 of the Ordinance. The MA will take all practical steps to ensure that the personal information is not kept longer than is necessary for the fulfilment of the purpose (including any directly related purpose) for which the personal information is or is to be used. The data subject or relevant persons as defined in section 2 or 17A of the Personal Data (Privacy) Ordinance (“the PDPO”) have a right of access and correction with respect to personal information as provided for in sections 18 and 22 of and Principle 6 of Schedule 1 to the PDPO. The right of access includes the right to obtain a copy of the personal information provided in this form. Enquiries concerning the personal information collected by means of this form, including access and corrections, should be addressed to the MA (email: pcicso_ai@hkma.iclnet.hk).

Page 5 of 7 FORM FOR NOTIFYING MATERIAL CHANGES TO CERTAIN COMPUTER SYSTEMS Pursuant to section 22 of the Protection of Critical Infrastructures (Computer Systems) Ordinance HKMA’s Remark An authorized institution designated by the Monetary Authority (MA) as a CI operator (Designated AI) should submit this completed form to the MA by email (pcicso_ai@hkma.iclnet.hk) using an ICLNet secure e-mail account. The submission should be copied to the Designated AI’s usual supervisory contact at the HKMA, including both the Technology Risk Team overseeing this matter and the Case Management Team, and made within the period specified in section 22(1) the Protection of Critical Infrastructures (Computer Systems) Ordinance. A. Background information Information of the Designated AI: Full name: B. Change details

  1. Type of change(s) (Please tick the appropriate box(es)) ☐ A material change occurs to the design, configuration, security or operation of a critical computer system (CCS). (Please complete item 2) ☐ A CCS is removed (Please specify: ) ☐ A new computer system (whether under the control of the Designated AI or not) that is accessible by the Designated AI in or from Hong Kong, and is essential to the core function of the infrastructure, is added to the infrastructure ☐ A change occurs to an existing computer system (whether under the control of the Designated AI or not) that is accessible by the Designated AI in or from Hong Kong such that the system becomes essential to the core function of the infrastructure *Please refer to section 22 of the Protection of Critical Infrastructures (Computer Systems) Ordinance for reportable changes
  2. Details of material change of CCS(s) 2.1 Impacted CCS(s): 2.2 Type of material change(s) (Please tick the appropriate box(es)) ☐ Platform migration ☐ Changes to the computing platform or hardware ☐ Major version upgrade of a core component (e.g. Database) ☐ Server virtualisation ☐ Application re-design ☐ Significant code changes ☐ Integration with or change in interdependency on external systems or networks ☐ Changes to the underlying infrastructure that supports the CCS(s)

Page 6 of 7 ☐ Any system modification that fundamentally alters the characteristics or nature of the CCS ☐ Changes of mission or major functions that alters the system’s operational scope, intended purpose or requirements in security, resources or functions ☐ Others (please specify: ) *Please refer to section 22(3) of the Protection of Critical Infrastructures (Computer Systems) Ordinance for meaning of “material changes”. 3. Change detail(s) with timeframe Please provide a detailed description of the change, including the technical details. 4. Deployment date (dd/mm/yyyy) *Please refer to section 6.1.1 of the Code of Practice issued by the MA for Designated AIs for details. *All the changes should be endorsed and processed in accordance with the change management process defined in the computer￾system security management plan. 5. Description of the effect (on the computer-system security risk of the CCS(s) or risk to carrying out the core function of the CI after the deployment of the material change(s)) *Please include the relevant risk assessment documentation of the material change(s) in the submission of this form. 6. Updated system documentation

  • Please attach and list the updated system documentation, including such information as specified in section 4.1.1 of the MA's Code of Practice for Designated AIs, that is relevant to the reported changes, if any. C. Reporting entity information Name: Post title: Office & mobile contact: Email address: Form submission date (dd/mm/yyyy): Declaration By submitting this form, we hereby confirm that the information provided in this reporting form is valid and has been reviewed by the supervisor of the computer-system security management unit in the institution. Personal Information Collection Statement: The personal information provided to the MA in this form will be used: (i) for the purposes of administering the Protection of Critical Infrastructures (Computer Systems) Ordinance (“the Ordinance”); and (ii) for the exercise of any functions, powers or duties under the Ordinance (whether by the MA, as a designated authority specified in column 2 of Part 2 of Schedule 2 to the Ordinance, or to the extent applicable, by the Commissioner of Critical Infrastructure (Computer-system Security) (“the Commissioner”). The MA may transfer the personal information to the Commissioner in the performance of any function under the Ordinance or for carrying into effect the provisions of the Ordinance, or to such other parties or for such purposes as permitted under section 57 of the Ordinance. The MA will take all practical steps to ensure that the personal information is not kept longer than is necessary for the fulfilment of the purpose (including any directly related purpose) for which the personal information is or is to be used. The data subject or relevant persons as defined in section 2 or

Page 7 of 7 17A of the Personal Data (Privacy) Ordinance (“the PDPO”) have a right of access and correction with respect to personal information as provided for in sections 18 and 22 of and Principle 6 of Schedule 1 to the PDPO. The right of access includes the right to obtain a copy of the personal information provided in this form. Enquiries concerning the personal information collected by means of this form, including access and corrections, should be addressed to the MA (email: pcicso_ai@hkma.iclnet.hk ).

More like this from HKMA

HKMA published 11 documents in the last 30 days. We email you each new one the day it's published.

Share