Notice
Notice - Digital Asset Business - Operational Cyber Risk Management Code of Practice (2022-04-05)
Issued 2022-04-05View on BMA's website Source document
Summary
This is a BMA notice announcing that it has posted for public consultation a draft new Digital Asset Business Operational Cyber Risk Management Code of Practice, together with a revised Digital Asset Business Custody Code of Practice and revised Digital Asset (Cybersecurity) Rules. These are proposals, not yet final binding requirements, and are intended to harmonise DAB cyber risk obligations with those of other BMA-regulated sectors while adding more stringent, DAB-specific requirements given the sector's heightened cyber risk profile.
- Enhanced areas versus other sectors: Audit trails (system logs) and audits, both in periodicity and scope of controls.
- Enhanced areas versus other sectors: Systems and code testing, change management, and incident reporting.
- DAB-specific additions: New requirements addressing smart contracts and blockchain security.
- Underlying expectations described: DABs are expected to implement their own technology risk assessment programmes, identify top risks, decide on appropriate risk responses, and be able to evidence adequate board visibility and governance of cyber risk.
The Authority states that failure to comply with the provisions in these Consultation Documents (once adopted) will be an important factor in assessing whether a registrant is conducting its business in a sound and prudent manner. The DAB industry and other interested parties are invited to comment on the proposals via a survey link, with comments due no later than 6 May 2022.
Key obligations
- Interested parties, including DAB registrants, wishing to comment must submit their views via the provided survey link no later than 6 May 2022.
- Once adopted, DABs would be required to implement their own technology risk assessment programmes and evidence adequate board visibility and governance of cyber risk, per the draft Code described in the notice.
Applies to
Digital Asset Business (DAB) registrants
Deadlines
- 6 May 2022: Deadline for the DAB industry and other interested parties to submit comments on the Consultation Documents (draft Operational Cyber Risk Management Code of Practice, revised Custody Code of Practice, and revised Digital Asset (Cybersecurity) Rules) via the survey link.