2017年-FSB全球金融稳定委员会_Summary_Report_on_Financial_Sector_Cybersecurity_Regulations_Guidance_and_Supervisory_Practices_11页_295kb
报告摘要
Summary Report on Financial Sector Cybersecurity Regulations, Guidance and Supervisory Practices
Introduction
This report summarises findings from the Financial Stability Board (FSB) stocktake survey and a September 2017 workshop on cybersecurity in the financial sector. Cyber attacks pose a significant threat to the financial system, as demonstrated by high-profile incidents such as the Bangladesh Bank heist, WannaCry ransomware attack, and Equifax breach. The FSB was tasked by the G20 to assess existing regulations, guidance, and supervisory practices in G20 jurisdictions and internationally, with the goal of enhancing cross-border cooperation and resilience against cyber threats.
The FSB conducted two surveys: one for member jurisdictions and one for international bodies. All 25 member jurisdictions and nine international bodies responded. The G7 Cyber Expert Group also provided input. The survey focused on publicly released materials, excluding internal supervisory practices and guidance from self-regulatory organisations.
Summary of FSB Survey Conclusions
Regulatory and Supervisory Activity
- FSB Member Jurisdictions: All 25 jurisdictions reported publicly released regulations or guidance addressing cybersecurity for at least part of the financial sector. A majority also reported supervisory practices.
- Scope of Coverage: Jurisdictions focused on banks and financial market infrastructures (FMIs), with many also addressing trading venues, insurance companies, broker-dealers, and asset managers.
- Regulatory vs. Supervisory Schemes: Jurisdictions reported more regulatory schemes than supervisory practices, though some supervisory practices were not publicly released.
- Content of Schemes: Regulatory schemes often targeted cybersecurity and IT risk (66%), while a smaller portion addressed operational risk (34%). Common elements in operational risk schemes included governance, risk assessment, information security, and third-party risk management.
Regulatory Elements
- Targeted Cybersecurity Schemes: 56 schemes addressed cybersecurity and IT risk, with common elements including:
- Risk assessment (55 schemes)
- Regulatory reporting (50 schemes)
- Role of the board (49 schemes)
- Third-party interconnections (49 schemes)
- System access controls (48 schemes)
- Incident recovery (46 schemes)
- Testing (44 schemes)
- Training (43 schemes)
- Creation of a cybersecurity role (38 schemes)
- Information sharing (31 schemes)
- Supervisory Practices: 35 schemes were reported, with common elements including:
- Review of policies and procedures (32 schemes)
- Review of monitoring, testing, and auditing programs (31 schemes)
- Review of data security controls (31 schemes)
- Review of governance arrangements (30 schemes)
- Review of risk assessment processes (30 schemes)
- Review of past incidents and responses (27 schemes)
- Testing by supervisors (21 schemes)
- Communications by supervisors (21 schemes)
- Information sharing by financial institutions (18 schemes)
International Guidance
- Common Topics: International guidance typically addresses governance, risk analysis, information security, security controls, incident prevention, expertise and training, monitoring, incident response, communications, and oversight of interconnections.
- Variability in Scope: Guidance varies in scope, with some covering specific entities and others addressing broader sectors.
Future Plans
- Regulatory Development: 72% of jurisdictions reported plans to issue new cybersecurity regulations, guidance, or supervisory practices within the next year.
- Focus Areas: Plans include self-assessment exercises for FMIs, developing a cybersecurity strategy, and issuing new regulations.
FSB Workshop on Cybersecurity
Effective Cybersecurity Practices
- Cybersecurity Objectives: Establishing clear objectives is essential, as different firms have different priorities (e.g., data availability vs. confidentiality).
- Proactive Approach: Cybersecurity should be strategic, forward-looking, and proactive, not just reactive to past incidents.
- Basic Hygiene: Up to 90% of threats can be mitigated by basic cybersecurity hygiene.
- Integration with Business: Cybersecurity must be integrated with business operations, and governance and communication with the board are critical.
- Testing and Monitoring: Continuous testing and monitoring, including self and third-party testing, penetration testing, and tabletop exercises, are important for resilience.
- Resilience: Institutions must be prepared to respond and recover from cyber incidents, with people, processes, and technology all playing a role.
- Outsourcing Risks: Outsourcing can increase or decrease risk depending on management practices. Key considerations include access control, risk tailoring, backup suppliers, and incident reporting.
Effective Regulation and Supervision
- Regulatory Approaches: Support for principles-based, risk-based, and proportional regulation was noted.
- Conflicting Requirements: Jurisdictions have different regulatory requirements, which can create conflicts and increase costs.
- Similar but Not Identical Requirements: Even similar requirements can be interpreted differently, leading to complexity.
- Unhelpful Requirements: Some requirements may hinder cybersecurity, such as overly strict encryption or unclear risk appetite definitions.
- Penetration Testing Concerns: External testing could introduce risks, such as network disruption or access to test results.
- Regulatory Oversight: Concerns were raised about the ability of authorities to protect sensitive financial data and the cost of repeated examinations.
Information Sharing
- Importance: Information sharing is critical for cybersecurity, though details on who should share and what information is appropriate remain unclear.
- Cross-Border Challenges: Cybersecurity is inherently cross-border, but establishing an effective information-sharing architecture is challenging.
- Public-Private Partnership: Information exchange between public and private sectors is important, with some advocating for permissive and protected sharing rather than mandatory.
Capacity Building
- Cybersecurity Talent: There is a growing need for trained cybersecurity professionals, as cyber threats are increasing and tools are becoming more accessible.
- Training Needs: Both firms and supervisory staff require better training.
- Awareness and Education: Awareness training for all staff and education for boards on cyber risks are essential to prevent human error and improve preparedness.
Key Themes
- Global Coordination: There is a need for greater international coordination in cybersecurity regulation.
- Resilience and Preparedness: Institutions must be resilient and prepared for cyber incidents.
- Cross-Border Cooperation: Cybersecurity is a cross-border issue requiring international collaboration.
- Balanced Regulation: Principles-based and risk-based approaches are preferred over overly prescriptive ones.
试读结束,高清完整版pdf/doc/ppt,请点下载