SINGAPORE Law and Practice Contributed by: Lim Chong Kin, David N Alfred, Albert Pichlmaier and Goh Boon Yeow, Drew & Napier LLC
and complying with codes of practices and directions that may be issued or approved by the Commissioner. 3.3 Key Operational Resilience Obligations The key obligations relating to governance and risk management can be derived from Part 3 and 4 of the TRM Guidelines relating to Technology Risk Gov - ernance and Oversight. The best practices that FIs should aim to comply with include (non-exhaustive): • ensuring that the board of directors and senior management implement effective internal controls and risk management practices; • ensuring that the board of directors and senior management have members with sufficient knowl - edge to understand and manage technology risks; • establishing and implementing a technology risk management strategy, and ensuring key IT deci - sions are made in accordance with the FI’s risk appetite; and • maintaining up-to-date technology risk policies, standards and procedures, with compliance moni - toring and disciplined management of deviations through approved risk assessments. The key obligations relating to digital operation resil - ience generally in the financial sector can be derived from Part 8 of the TRM Guidelines relating to IT resil - ience. The best practices that FIs should aim to com - ply with include (non-exhaustive): • establishing system availability commensurate with their business needs; • establishing system recoverability aligned to their business resumption and system recovery priori - ties; and • regularly testing their disaster recovery plans to validate their effectiveness and ensure that they meet the defined recovery objectives. FIs should establish cyber-incident response and management plans to swiftly isolate and neutralise cyber threats and to securely resume affected ser - vices. The plan should describe communication, co-ordination and response procedures to address plausible cyber threat scenarios. Each FI should seek to understand their exposure to technology risks and
place a robust risk management framework to ensure cyber-resilience. FIs may also be a designated entity under the Cyber - security Act. For more information on the designation of entities and their obligations under the Cybersecu - rity Act, please refer to 1.2 Cybersecurity Laws , 1.3 Cybersecurity Regulators and 2.2 Critical Infrastruc- ture Cybersecurity Requirements . 3.4 Operational Resilience Enforcement There are no specific obligations relating to operation resilience in relation to critical ICT service providers. However, critical ICT service providers in the finan - cial sector can take guidance from Part 8 of the TRM Guidelines (please refer to 3.3 Key Operational Resil- ience Obligations for further details). Generally, under Section 29 (1) of the Financial Ser - vices and Markets Act, MAS has the power to issue directions or make regulations concerning any FI or class of FIs as the MAS considers necessary for: • the management of technology risks, including cyber security risks; • the safe and sound use of technology to deliver financial services; and • the safe and sound use of technology to protect data. An FI that fails to comply with a direction issued to it under Section 29 (1) or contravenes any regulation mentioned in that subsection shall be guilty of an offence and shall be liable on conviction to a fine not exceeding SGD1 million and, in the case of a continu - ing offence, to a further fine of SGD100,000 for every day or part of a day during which the offence contin - ues after conviction. Under the Cybersecurity Act, the Commissioner has broad powers under Sections 19 and 20 to investigate and prevent cybersecurity incidents and “serious” cybersecurity incidents respectively. These include powers to require persons to attend interviews, require the production of relevant information, give directions to carry out remedial measures or cease activities, enter premises, access and inspect computer sys - tems, among others.
290 CHAMBERS.COM
Powered by FlippingBook