Code
Digital Asset Business - Operational Cyber Risk Management Code of Practice (January 2024)
In forceView on BMA's website Source document
Summary
This Code of Practice, issued by the Bermuda Monetary Authority under Section 6 of the Digital Asset Business Act 2018, sets out mandatory and recommended standards for operational cyber risk management applicable to all Digital Asset Business (DAB) registrants. It is not exhaustive: DABs must build their own risk-based cyber programmes, and the Authority applies the Code proportionately based on each DAB's nature, scale and complexity. Non-compliance is treated as a factor in assessing whether a registrant conducts business in a sound and prudent manner.
- Governance: Boards and senior management must oversee cyber risk, approve a cyber risk policy at least annually, and appoint a suitably senior CISO (who may be outsourced, though board oversight remains).
- Risk management programme: DABs must run an operational cyber risk management programme covering risk assessment, data governance/classification, and detection, protection, response and recovery controls, following a Three Lines of Defense model.
- Audits and records: An annual IT audit plan approved by the audit committee is required, and risk assessments must be documented and retained for at least five years for production to the Authority on request.
- Outsourcing, cloud and third parties: Outsourced cyber functions, cloud computing arrangements, and third-party blockchain/smart contract services must be risk-assessed, with contracts specifying compliance, cooperation and data access obligations.
- Technical controls: Detailed detect and protect requirements cover incident management, mandatory notification of cyber reporting events to the Authority, multi-factor authentication, logical access, data protection, malware defence, penetration testing, patch management, network security, smart contract and DLT/blockchain security, logging, cryptography, and physical security of storage facilities.
- Response and recovery: DABs must maintain and annually test business continuity and disaster recovery plans, including documented business impact analyses.
- Staff and project controls: Staff vetting processes and security reviews of new projects/IT systems involving critical data are mandatory.
The Code entered into force on 1 January 2024, with a compliance deadline of 30 June 2024 for existing DABs to align their operational cyber risk practices with its requirements.
Key obligations
- Boards must approve a cyber risk policy document at least annually and receive regular updates on cyber risk status.
- DABs must appoint an appropriately qualified CISO (internal or outsourced) to deliver the operational cyber risk management programme.
- DABs must implement an operational cyber risk management programme covering risk assessment, data governance/classification, and detection, protection, response and recovery controls.
- DABs must employ adequate cyber risk personnel and keep them current on cybersecurity threats and countermeasures.
- Risk assessments must be documented and retained for at least five years and made available to the Authority on request.
- An annual IT audit plan must be developed and approved by the audit committee of the board or equivalent.
- DABs should review the adequacy of cyber insurance coverage at least annually.
- An asset inventory of all information assets must be maintained, with each asset owned by a designated part of the business and classified appropriately.
- Outsourcing and third-party service agreements must include terms on compliance with laws, cooperation with the Authority, and timely access to data and records.
- A risk assessment must be completed before using any third-party blockchain applications, smart contracts, platforms or services.
- Cloud computing use must be risk-assessed, including governance, legal, compliance/audit and information governance considerations, with roles and responsibilities for each control defined.
- DABs must implement a staff vetting process for personnel.
- New projects involving critical data or systems must undergo a technology risk assessment before implementation.
- DABs must notify the Authority of cyber reporting events as specified in the Code.
- Multi-factor authentication and logical access management controls must be implemented.
- Security logs must be protected and monitored, and anomalous activity must be detected and investigated.
- Cryptographic modules used must be based on authoritative standards and reputable protocols, tested before production use.
- DABs must implement and annually test business continuity and disaster recovery plans, documenting any issues for remediation.
- DABs must demonstrate storage facilities meet appropriate industry physical security standards.
- DABs must be in full compliance with the Code by 30 June 2024.
Applies to
Digital Asset Business (DAB) registrants
Deadlines
- 1 January 2024: The Code comes into force.
- 30 June 2024: Deadline by which DABs are required to be in compliance with the Code.
- at least annually: Board must approve the cyber risk policy document; IT audit plan must be developed and approved; cyber insurance coverage should be reviewed; BCP and DR plans must be tested.
- at least five years: Retention period for documented risk assessments, to be available to the Authority upon request.
Related documents
- This document is made under Digital Asset Business Act 2018