2021-01-18
Added · Updated
These revised Technology Risk Management Guidelines set out principles and best practices for financial institutions (FIs) to establish sound technology risk governance and oversight and maintain cyber resilience. FIs' boards of directors and senior management must ensure effective internal controls and risk management practices, including appointing a Chief Information Officer or Head of IT and a Chief Information Security Officer or Head of Information Security. Financial institutions are required to establish policies and procedures, manage technology risks from third-party services, perform background checks on personnel with IT system access, and conduct annual IT security awareness training for all relevant staff and contractors. The extent of implementation should be commensurate with the level of risk and complexity of the financial services offered.
More like this from MAS
We email you every new MAS publication the day it's published.