Risk Associated with Third-party IT Solutions

九 27, 2024
Latest News HKMA Risk Associated with Third-party IT Solutions

On 27 Sep 2024, the HKMA issued a circular urging Authorized Institutions to strengthen third-party IT risk management following a global cybersecurity incident, directing them to implement good practices from the Annex to reinforce existing C-RAF and third-party risk frameworks. The HKMA stressed that senior management must integrate these industry standards into current controls to enhance operational resilience against third-party solution failures.

This article was generated using SAMS, an AI technology by Timothy Loh LLP.

Introduction

On 27 Sep 2024, the Hong Kong Monetary Authority (HKMA) issued a circular reminding Authorized Institutions (AIs) to strengthen risk management practices concerning third-party IT solutions following a global incident involving a cybersecurity provider's faulty update.

Context and Incident Analysis

The HKMA highlighted that the widespread impact of the recent global IT incident stemmed from the service provider's inadequate testing protocols, automatic update mechanisms lacking user controls, and insufficient third-party risk management frameworks. This incident underscored systemic vulnerabilities in third-party IT dependencies.

HKMA's Regulatory Expectations

The HKMA expects senior management of all AIs to incorporate the good industry practices outlined in the Annex into their existing risk management controls. These practices reinforce the HKMA's existing supervisory requirements under the Cyber Risk Assessment Framework (C-RAF), third-party risk management circulars, and the Supervisory Policy Manual, specifically addressing third-party software failure scenarios.

Action Required

AIs must review and enhance their operational resilience measures to mitigate risks associated with third-party IT solutions, ensuring controls align with the referenced industry best practices. The HKMA emphasized that these measures are not new regulatory requirements but an application of existing frameworks to address identified vulnerabilities.

View the full article:Source

我们使用 Cookie 来提升您使用本网站的体验,并在必要时让您完成注册。继续使用本网站即表示您同意使用这些 Cookie。欲了解更多信息及如何更改 Cookie 设置,请参阅我们的 Cookie 政策和隐私声明。