Code
Operational Cyber Risk Management Code of Conduct (September 2022 Revised)
In forceView on BMA's website Source document
Summary
This BMA Code of Conduct sets out mandatory and recommended standards for managing operational cyber risk. It applies to Relevant Licensed Entities (RLEs) under Bermuda's sectoral acts and is issued as part of the threshold requirement that these entities conduct business in a prudent manner with adequate systems, including systems addressing cyber risk.
- Scope: Applies to banks and deposit companies, corporate service providers, trust companies, money service businesses, investment businesses and fund administration providers.
- Governance: Boards must have oversight of cyber risk, approve a cyber risk policy at least annually, and appoint a Chief Information Security Officer (in-house or outsourced).
- Risk management programme: RLEs must implement a documented operational cyber risk management programme covering risk assessment, data governance and classification, and detection, protection, response and recovery controls, applied proportionately to the nature, scale and complexity of the business.
- Outsourcing and cloud: Outsourced and cloud-based services must be risk-assessed, with clear contractual terms, oversight and accountability retained by the RLE, which can never outsource responsibility for governance and risk.
- Technical controls: Detailed requirements cover incident management, notification of cyber reporting events to the Authority, access management, data loss prevention, malicious code protection, penetration testing, patch management, network security, logging/monitoring and cryptography.
- Business continuity: RLEs must maintain and annually test Business Continuity and Disaster Recovery plans, including regular business impact analyses.
The Code took effect on 15 March 2022 for corporate service providers, trust companies, money service businesses, investment businesses and fund administration providers, and on 26 September 2022 for banks and deposit companies. All affected RLEs were required to achieve compliance by 15 February 2023.
Key obligations
- Boards must have oversight of cyber risk and approve a cyber risk policy at least annually
- RLEs must implement an operational cyber risk management programme covering risk assessment, data governance/classification, and detection, protection, response and recovery controls
- RLEs must appoint a Chief Information Security Officer with appropriate qualifications or experience, even if outsourced
- Risk assessments must be documented and retained for at least five years and made available to the Authority on request
- RLEs must maintain oversight and accountability for all outsourced functions and ensure service agreements include compliance, cooperation and data access terms
- Cloud computing services must undergo a documented cloud risk assessment covering governance, legal, compliance and information governance issues
- New projects involving critical data or systems must undergo a technology risk assessment before implementation
- RLEs must notify the Authority of cyber reporting events
- Logging and monitoring requirements must be assessed, with security logs retained and protected, and anomalous activity investigated
- RLEs must implement Business Continuity and Disaster Recovery plans, including annual documented testing and business impact analysis
- RLEs should review the adequacy of cyber insurance coverage at least annually
- Comply with the Code by 15 February 2023
Applies to
banks, deposit companies, corporate service providers, trust companies, money service businesses, investment businesses, fund administration providers
Deadlines
- 15 March 2022: Code comes into force for corporate service providers, trust companies, money service businesses, investment businesses and fund administration providers
- 26 September 2022: Code comes into force for banks and deposit companies
- 15 February 2023: Deadline for all relevant RLEs (banks, deposit companies, corporate service providers, trust companies, money service businesses, investment businesses and fund administration providers) to comply with the Code
- at least annually: Board must approve the cyber risk policy and RLEs should review adequacy of cyber insurance coverage
- at least annually: BCP and DR plans must be tested
Related documents
- This document is made under Banks and Deposit Companies Act 1999
- This document is made under Fund Administration Provider Business Act 2019
- This document is made under Investment Business Act 2003
- This document is made under Trusts (Regulation of Trust Business) Act 2001
- Notice - Operational Cyber Risk Management Code of Conduct: Banks and Deposit Companies (2022-09-26) commences this document