2024-05-09
Added · Updated
This Notice requires credit card or charge card licensees in Singapore to establish a framework for identifying critical systems and maintain high availability, limiting maximum unscheduled downtime to 4 hours within any 12-month period. Licensees must set a recovery time objective of no more than 4 hours for each critical system and validate this through testing at least annually. Additionally, licensees are mandated to notify the Authority within 1 hour of discovering a relevant incident and submit a root cause and impact analysis report within 14 days, while also implementing IT controls to protect customer information.
MAS Notice No.: FSM-N07 Notice to credit card or charge card licensees in Singapore Financial Services and Markets Act 2022 Issue Date: 09 May 2024 NOTICE ON TECHNOLOGY RISK MANAGEMENT Introduction 1 This Notice is issued pursuant to section 29(1) of the Financial Services and Markets Act 2022 (the “Act”) and applies to all credit card or charge card licensees in Singapore. Definitions 2 For the purpose of this Notice— “credit card or charge card licensee” means a person who is licensed to carry on the business of issuing credit cards or charge cards, or both, in Singapore under section 57B of the Banking Act 1970; “critical system” in relation to a credit card or charge card licensee, means a system, the failure of which will cause significant disruption to the operations of the credit card or charge card licensee or materially impact the credit card or charge card licensee’s service to its customers, such as a system which— (a) processes transactions that are time critical; or (b) provides essential services to customers; “IT security incident” means an event that involves a security breach, such as hacking of, intrusion into, or denial of service attack on, a critical system, or a system which compromises the security, integrity or confidentiality of customer information;
“relevant incident” means a system malfunction or IT security incident, which has a severe and widespread impact on the credit card or charge card licensee’s operations or materially impacts the credit card or charge card licensee’s service to its customers; “system” means any hardware, software, network, or other information technology (“IT”) component which is part of an IT infrastructure; “system malfunction” means a failure of any of the credit card or charge card licensee’s critical systems. 3 Except where defined in this Notice or if the context otherwise requires, the expressions used in this Notice have the same meanings as in the Act. Technology Risk Management 4 A credit card or charge card licensee must put in place a framework and process to identify critical systems. 5 A credit card or charge card licensee must make all reasonable effort to maintain high availability for critical systems. The credit card or charge card licensee must ensure that the maximum unscheduled downtime for each critical system that affects the credit card or charge card licensee’s operations or service to its customers does not exceed a total of 4 hours within any period of 12 months. 6 A credit card or charge card licensee must establish a recovery time objective (“RTO”) of not more than 4 hours for each critical system. The RTO is the duration of time, from the point of disruption, within which a system must be restored. A credit card or charge card licensee must validate and document at least once every 12 months, how it performs its system recovery testing and when the RTO is validated during the system recovery testing. 7 A credit card or charge card licensee must notify the Authority as soon as possible, but not later than 1 hour, upon the discovery of a relevant incident. 8 A credit card or charge card licensee must submit a root cause and impact analysis report to the Authority, within 14 days or such longer period as the Authority may allow, from the discovery of the relevant incident. The report shall contain— (a) an executive summary of the relevant incident; (b) an analysis of the root cause which triggered the relevant incident;
(c) a description of the impact of the relevant incident on the credit card or charge card licensee’s— i. compliance with laws and regulations applicable to the credit card or charge card licensee; ii. operations; and iii. service to its customers; and (d) a description of the remedial measures taken to address the root cause and consequences of the relevant incident. 9 A credit card or charge card licensee must implement IT controls to protect customer information from unauthorised access or disclosure. Effective Date 10 This Notice shall take effect on 10 May 2024.
More like this from MAS
We email you every new MAS publication the day it's published.