2026-06-02
Added · Updated
The Hong Kong Monetary Authority issues this Code of Practice to implement the Protection of Critical Infrastructures (Computer Systems) Ordinance for authorized institutions designated as critical infrastructure operators. The document mandates the use of specific standardized forms to notify the regulator of operator changes, the appointment of employees supervising computer-system security management units, and material changes to critical computer systems. These submissions must be made via secure email within statutory timeframes and include detailed technical and risk assessment information to ensure regulatory oversight.
Page 1 of 7 FORM FOR NOTIFYING AN OPERATOR CHANGE Pursuant to section 20 of the Protection of Critical Infrastructures (Computer Systems) Ordinance HKMA’s Remark An authorized institution designated by the Monetary Authority (MA) as a CI operator (Designated AI) should submit this completed form to the MA by email (pcicso_ai@hkma.iclnet.hk) using an ICLNet secure e-mail account. The submission should be copied to the Designated AI’s usual supervisory contact at the HKMA, including both the Technology Risk Team overseeing this matter and the Case Management Team, and made within the period specified in section 20(1) the Protection of Critical Infrastructures (Computer Systems) Ordinance. A. Background information Information of the Designated AI:
Page 2 of 7 2. Organization contact person Full name: Post title: Office number: Email address: 3. Effective Date (dd/mm/yyyy) C. Reporting entity information Name: Post title: Office & mobile contact: Email address: Form submission date (dd/mm/yyyy): Declaration By submitting this form, we hereby confirm that the information provided in this reporting form is valid and has been reviewed by the supervisor of the computer-system security management unit in the institution. Personal Information Collection Statement: The personal information provided to the MA in this form will be used: (i) for the purposes of administering the Protection of Critical Infrastructures (Computer Systems) Ordinance (“the Ordinance”); and (ii) for the exercise of any functions, powers or duties under the Ordinance (whether by the MA, as a designated authority specified in column 2 of Part 2 of Schedule 2 to the Ordinance, or to the extent applicable, by the Commissioner of Critical Infrastructure (Computer-system Security) (“the Commissioner”). The MA may transfer the personal information to the Commissioner in the performance of any function under the Ordinance or for carrying into effect the provisions of the Ordinance, or to such other parties or for such purposes as permitted under section 57 of the Ordinance. The MA will take all practical steps to ensure that the personal information is not kept longer than is necessary for the fulfilment of the purpose (including any directly related purpose) for which the personal information is or is to be used. The data subject or relevant persons as defined in section 2 or 17A of the Personal Data (Privacy) Ordinance (“the PDPO”) have a right of access and correction with respect to personal information as provided for in sections 18 and 22 of and Principle 6 of Schedule 1 to the PDPO. The right of access includes the right to obtain a copy of the personal information provided in this form. Enquiries concerning the personal information collected by means of this form, including access and corrections, should be addressed to the MA (email: pcicso_ai@hkma.iclnet.hk).
Page 3 of 7 FORM FOR NOTIFYING APPOINTMENT OF EMPLOYEE SUPERVISING COMPUTERSYSTEM SECURITY MANAGEMENT UNIT Pursuant to section 21 of the Protection of Critical Infrastructures (Computer Systems) Ordinance HKMA’s Remark An authorized institution designated by the Monetary Authority (MA) as a CI operator (Designated AI) should submit this completed form to the MA by email (pcicso_ai@hkma.iclnet.hk) using an ICLNet secure e-mail account. The submission should be copied to the Designated AI’s usual supervisory contact at the HKMA, including both the Technology Risk Team overseeing this matter and the Case Management Team, and made within the period specified in section 21(4) and section 21(6) the Protection of Critical Infrastructures (Computer Systems) Ordinance. A. Background Information Information of the Designated AI: Full name: B. Employee details Information of the employee supervising the computer-system security management unit Full name: Post title: Office & mobile contact: Email address: Relevant professional qualification(s): *Please attach the relevant documentary proof. Relevant experience: *Please attach the relevant documentary proof. Effective date (dd/mm/yyyy) *Please attach the relevant documentary proof. C. Reporting entity information Name: Post title:
Page 4 of 7 Office & mobile contact: Email address: Form submission date (dd/mm/yyyy): Declaration By submitting this form, we hereby confirm that the information provided in this reporting form is valid and has been reviewed by the supervisor of the computer-system security management unit in the institution. Personal Information Collection Statement: The personal information provided to the MA in this form will be used: (i) for the purposes of administering the Protection of Critical Infrastructures (Computer Systems) Ordinance (“the Ordinance”); and (ii) for the exercise of any functions, powers or duties under the Ordinance (whether by the MA, as a designated authority specified in column 2 of Part 2 of Schedule 2 to the Ordinance, or to the extent applicable, by the Commissioner of Critical Infrastructure (Computer-system Security) (“the Commissioner”). The MA may transfer the personal information to the Commissioner in the performance of any function under the Ordinance or for carrying into effect the provisions of the Ordinance, or to such other parties or for such purposes as permitted under section 57 of the Ordinance. The MA will take all practical steps to ensure that the personal information is not kept longer than is necessary for the fulfilment of the purpose (including any directly related purpose) for which the personal information is or is to be used. The data subject or relevant persons as defined in section 2 or 17A of the Personal Data (Privacy) Ordinance (“the PDPO”) have a right of access and correction with respect to personal information as provided for in sections 18 and 22 of and Principle 6 of Schedule 1 to the PDPO. The right of access includes the right to obtain a copy of the personal information provided in this form. Enquiries concerning the personal information collected by means of this form, including access and corrections, should be addressed to the MA (email: pcicso_ai@hkma.iclnet.hk).
Page 5 of 7 FORM FOR NOTIFYING MATERIAL CHANGES TO CERTAIN COMPUTER SYSTEMS Pursuant to section 22 of the Protection of Critical Infrastructures (Computer Systems) Ordinance HKMA’s Remark An authorized institution designated by the Monetary Authority (MA) as a CI operator (Designated AI) should submit this completed form to the MA by email (pcicso_ai@hkma.iclnet.hk) using an ICLNet secure e-mail account. The submission should be copied to the Designated AI’s usual supervisory contact at the HKMA, including both the Technology Risk Team overseeing this matter and the Case Management Team, and made within the period specified in section 22(1) the Protection of Critical Infrastructures (Computer Systems) Ordinance. A. Background information Information of the Designated AI: Full name: B. Change details
Page 6 of 7 ☐ Any system modification that fundamentally alters the characteristics or nature of the CCS ☐ Changes of mission or major functions that alters the system’s operational scope, intended purpose or requirements in security, resources or functions ☐ Others (please specify: ) *Please refer to section 22(3) of the Protection of Critical Infrastructures (Computer Systems) Ordinance for meaning of “material changes”. 3. Change detail(s) with timeframe Please provide a detailed description of the change, including the technical details. 4. Deployment date (dd/mm/yyyy) *Please refer to section 6.1.1 of the Code of Practice issued by the MA for Designated AIs for details. *All the changes should be endorsed and processed in accordance with the change management process defined in the computersystem security management plan. 5. Description of the effect (on the computer-system security risk of the CCS(s) or risk to carrying out the core function of the CI after the deployment of the material change(s)) *Please include the relevant risk assessment documentation of the material change(s) in the submission of this form. 6. Updated system documentation
Page 7 of 7 17A of the Personal Data (Privacy) Ordinance (“the PDPO”) have a right of access and correction with respect to personal information as provided for in sections 18 and 22 of and Principle 6 of Schedule 1 to the PDPO. The right of access includes the right to obtain a copy of the personal information provided in this form. Enquiries concerning the personal information collected by means of this form, including access and corrections, should be addressed to the MA (email: pcicso_ai@hkma.iclnet.hk ).
More like this from HKMA
HKMA published 11 documents in the last 30 days. We email you each new one the day it's published.