Cybersecurity Guidelines for Financial Sector Te…

Cybersecurity Guidelines for FSTI Providers

Business Continuity Plans Possess a comprehensive policy related to Business Continuity Plans (BCP) Update BCP regularly Conduct annual training on the role and responsibilities in carrying out BCP and the importance of implementing BCP

2.1. 2.

Risk Assessment Risk Management Carry out vulnerability assessment regularly Apply quantitative and qualitative risk assessment models (e.g. ISO 27001) Monitor regulatory changes periodically to ensure compliance with applicable laws and regulations Conduct penetration testing by external cybersecurity experts regularly or when there are significant system changes

2.2. Risk Mitigation

Increase Security Control Implement advanced security solutions such as next-generation firewalls, intrusion prevention systems (IPS), intrusion detection systems (IDS), and endpoint detection and response (EDR). Conduct periodic audits using internal and/or external auditors to ensure all systems and controls meet the standards

110

Made with FlippingBook. PDF to flipbook with ease