2023-12-21

Added · Updated

Managing cyber risk associated with third-party service providers

The Hong Kong Monetary Authority issued this circular to provide authorized institutions with sound practices for managing cyber risks linked to third-party service providers. The guidance mandates that institutions integrate third-party cyber risk into their governance frameworks, conduct holistic assessments throughout the vendor lifecycle, and evaluate supply chain vulnerabilities. Additionally, the regulator requires expanded threat intelligence sharing, scenario-based incident response drills, and continuous enhancement of cyber defense capabilities through international standards.

Hong Kong Monetary Authority logo

Hong Kong

Hong Kong Monetary Authority

Click to view full text

More like this from HKMA

HKMA published 11 documents in the last 30 days. We email you each new one the day it's published.

Share