CHILE Law and Practice Contributed by: Claudio Magliona, Bárbara Reyes and Diego Lisoni, Magliona Abogados
3.3 Key Operational Resilience Obligations According to Chapter 20-10, the implementation of an adequate risk management process should include as a minimum: • a risk analysis process, which considers elements such as the assessment of the probability of occur - rence of incidents and their consequence or impact on information assets, based on the degree of damage or costs caused by an information security and cybersecurity event, thus determining its level of risk; • a risk assessment process; • a risk treatment plan; and • at least an annual review of the information security and cyber security risk management process. Moreover, Chapter 20-10 contains a robust set of cybersecurity defensive measures. Within the meas - ures, it is important to highlight the following: • inventory of critical cybersecurity assets; • change management process that allows modifica - tions made to the ICT infrastructure to be carried out in a secure and controlled manner; • capabilities management process; • technological obsolescence management process; • configuration management process that ensures adequate controls to the configurable elements of the ICT infrastructure; • patch management programme to ensure that patches are applied to both software and firmware in a timely manner; • implementation of tools such as firewalls, web application firewalls (WAF), intrusion prevention systems (IPS), data loss prevention systems (DLP), anti-denial of service systems, email filtering, anti- virus and anti-malware; • back-up management process to ensure the integ - rity and availability of information and processing media in the event of an incident or disaster; • mechanisms to cover the costs associated with possible cyber-attacks; and • a Security Operation Centre (SOC), either in-house or through an external service, which operates 24 hours a day, with facilities, technological tools, pro - cesses and dedicated and trained personnel.
securely delete customer data once the contractual relationship ends or the data is no longer necessary for the intended purpose. Treatment of Subcontracting and Chain Outsourcing Chapter 20-7 of the RAN requires that risks arising from chain outsourcing be addressed in the primary contract. Financial entities must include veto clauses that allow them to control the selection of subcon - tractors by their main service provider. Subcontracted companies are contractually obligated to comply with the same security conditions and standards agreed upon between the financial institution and the initial provider. Location of Data and Services The RAN establishes that data, platforms and applica - tions used in outsourced services must reside at spe - cific and known processing sites. If data processing occurs in a foreign jurisdiction, the financial institution must know the specific city where the data centres are located. Institutions outsourcing critical process - ing abroad must maintain a contingency data centre within Chile and demonstrate a recovery time compat - ible with the service’s criticality, unless they obtain a specific exemption from the CMF based on robust risk management. Exit Strategies Financial institutions are required to develop exit plans that allow them to resume operations internally or through another provider in the event of a contract termination or provider failure. These strategies must be included in the institution’s Plan of Business Con - tinuity and Disaster Recovery. Concentration Risk Management The board of directors is responsible for managing risks associated with a high concentration of services with a single provider. Concentration risk is evaluated both at the institutional and industry level, as a failure in a provider used by multiple banks could trigger a systemic crisis. Institutions must establish formal pro - cedures to identify and mitigate risks related to high barriers to exit, such as excessive dependency on a provider’s specific technology or the potential loss of internal technical expertise.
67 CHAMBERS.COM
Powered by FlippingBook