2024-09-27
Added · Updated
The regulator issues guidance on managing risks associated with third-party IT solutions by enhancing risk assessment processes throughout the vendor life cycle. Institutions are required to implement robust IT change management, privileged access controls, and preparedness protocols for IT incidents to mitigate operational and security impacts. These measures include adopting gradual deployment strategies, ensuring least-privilege access, and establishing clear communication and recovery procedures for large-scale outages.
More like this from HKMA
HKMA published 11 documents in the last 30 days. We email you each new one the day it's published.