Cybersecurity Guidelines for FSTI Providers
3. Regular Compliance Checks a. Continuously monitor regulatory updates to ensure compliance with applicable laws and regulations. b. FSTI Providers can utilise any means/tools to assist them in tracking real-time compliance status with applicable laws and standards, such as Microsoft Compliance Manager 7 . c. Conduct regular meetings with key stakeholders, including compliance officers, IT security teams, and business unit leaders, to evaluate compliance status and discuss needed improvements. d. Incorporate compliance checks into software development lifecycle (SDLC). Ensure that every new release complies with relevant regulations.
4. Penetration Test a. Arrange for penetration testing by external cybersecurity experts annually or after significant network changes or critical infrastructure deployment. b. In addition to regular schedules, conduct ad-hoc penetration tests in response to new threats or after deploying new infrastructure or applications. c. Use the results from penetration testing to address vulnerabilities promptly.
7 Microsoft Purview Compliance Manager, https://learn.microsoft.com/en-us/purview/compliance- manager
44
Made with FlippingBook. PDF to flipbook with ease