FSB全球金融稳定委员会-Public-responses-to-consultation-on-Effective-Practices-for-Cyber-Incident-Response-and-Recovery_4页_124kb
报告摘要
AIMA's Response to FSB's Consultation on Cyber Incident Response and Recovery
Core Content
The Alternative Investment Management Association (AIMA) has submitted a response to the Financial Stability Board (FSB) consultation on developing a toolkit for effective cyber incident response and recovery practices for financial institutions. The response highlights the importance of cyber security in the financial ecosystem and emphasizes the need for tailored, risk-based approaches that consider the diverse needs of different financial institutions.
Main Views and Key Information
1. Proportionality
AIMA encourages the FSB and public authorities to apply the principle of proportionality when developing new cyber-related practices or rules. This means that the requirements should be aligned with the type of institution, considering factors such as business model, size, and risk profile. Larger, systemic institutions may require more complex regulations, while smaller ones can benefit from less burdensome measures.
2. Principles and Risk-Based Approach
AIMA supports a principles and risk-based approach to cyber security regulation and supervision. Overly prescriptive and process-driven practices may not be suitable for all institutions, particularly smaller ones that may lack the resources to implement complex systems. Instead, guidance should be provided to help firms develop their own cyber incident response and recovery (CIRR) strategies based on their specific circumstances.
3. Lessons from the COVID-19 Pandemic
The pandemic has highlighted the importance of cyber security in a remote working environment. Key areas of focus include:
- Remote access solutions
- Remote work policies and access controls
- Home office setup
AIMA members have implemented several measures to enhance cyber security, such as:
- Simulated phishing scams and online training
- Use of Security Information and Event Management (SIEM) software and Dark Web Monitoring
- Implementation of multi-factor authentication (MFA) and strong passwords
- Web filtering and firewalls for remote networks
- WiFi management practices
These practices have helped to safeguard both onsite and remote operations, demonstrating the importance of adapting cyber security measures to new working environments.
4. Role of Authorities in Supporting Firms
Public authorities play a crucial role in supporting firms' cyber incident response activities. They should:
- Establish relationships with the private sector
- Provide early warning alerts and information on cyber risks
- Support firms by producing detailed incident reports
- Ensure cross-border cooperation in the event of incidents affecting multiple countries
AIMA also highlights the challenge of recruiting skilled cyber security professionals. Governments and industry partners should collaborate to address the cyber security capability gap, including integrating cyber security education into relevant academic courses.
AIMA's Cyber Security Guide
AIMA believes that there is no one-size-fits-all solution for cyber incident response planning. Instead, each financial institution should tailor its approach to its specific needs. To assist its members, AIMA has published a Guide to Sound Practices for Cyber Security, which provides a framework for internal discussions and strategy development. The guide is not a comprehensive solution but aims to frame the debate and help implementers understand the range of issues and develop appropriate strategies.
Conclusion
AIMA fully supports the FSB's initiative to develop a toolkit for effective cyber incident response and recovery practices. The association emphasizes the need for proportionality, a principles-based and risk-driven approach, and the importance of public-private collaboration in addressing cyber security challenges. The guide provided by AIMA is a valuable resource for investment managers seeking to enhance their cyber resilience.
试读结束,高清完整版pdf/doc/ppt,请点下载