Cybersecurity Guidelines for Financial Sector Te…

Cybersecurity Guidelines for FSTI Providers

6.

Cloud Use

If FSTI Providers use cloud provider services, data centres and data recovery centres also refer to points 4 and 5 above.

7. Business Continuity Plans

a. Comprehensive Policy: - Possess comprehensive policies related to Business Continuity Plans (BCPs) that cover business impact analysis, business continuity management, and recovery strategy including all critical aspects of operations, such as IT systems, management roles, personnel, and communication strategies. - Ensure that BCPs are regularly updated to reflect changes in business processes, technologies, and internal/external threats. b. Training and Awareness - Provide annual training to employees on their roles and responsibilities in executing the business continuity plan. - Conduct awareness programs to ensure that all staff understand the importance of business continuity and their part in maintaining it. - Undertake annual review and improve business continuity plans based on lessons learned from drills, real incidents, and changes in the business environment. - Engage with stakeholders to ensure BCPs align with organisational goals and regulatory requirements. c. Continuous Improvement:

38

Made with FlippingBook. PDF to flipbook with ease