Statement of Guidance
Statement of Guidance – Cybersecurity for Regulated Entities (April 2023)
In forceView on CIMA's website Source document
Summary
This is CIMA's Statement of Guidance (SOG) on Cybersecurity for Regulated Entities, dated April 2023, which supplements CIMA's separate binding Rule on the same topic. It sets out the Authority's minimum expectations for how regulated entities should manage cybersecurity risk. As guidance rather than a rule, it is not itself directly enforceable in the same way as the Rule, but CIMA uses it to interpret and assess compliance with the Rule and incorporates cybersecurity reviews into its examination process.
Scope of Application
The SOG applies to all entities regulated by CIMA, including controlled subsidiaries as defined under the Banks and Trust Companies Act, but expressly excludes regulated mutual funds (under the Mutual Funds Act) and private funds (under the Private Funds Act). Entities are expected to apply the guidance proportionately to their size, complexity, structure, and risk profile.
Areas Covered
- Governance
- Risk identification and assessment
- Monitoring and reporting
- Incident response, containment, and recovery
- IT system controls
- Data protection and encryption
- Notification of incidents to the Authority
Key Expectations
- Framework: Establishing a documented cybersecurity framework with governing-body-approved risk tolerance.
- Self-assessment: Conducting at least annual self-assessments against the framework.
- Risk identification: Maintaining risk identification and inventory processes.
- Monitoring: Implementing monitoring and detection systems.
- Incident response: Having documented incident response and containment/recovery procedures.
- Data protection: Applying encryption and access controls to protect confidential data.
- Notification: Notifying the Authority (and affected individuals/Ombudsman where applicable) as quickly as possible in the event of loss of financial assets or personal data, with ongoing updates until the incident is resolved and a post-incident review made available to CIMA on request.
Key obligations
- Regulated entities should conduct regular self-assessments of their cybersecurity framework against this Guidance, the related Rule, and relevant standards, at a minimum annually.
- Regulated entities should implement a documented cybersecurity framework with strategies, policies and procedures, including enforcement/disciplinary provisions for non-compliance.
- The governing body should approve the entity's cybersecurity risk tolerance/risk limit.
- Regulated entities should establish an internal audit function or equivalent objective assessment to provide independent, regular assurance on the cybersecurity framework to the governing body and senior management.
- Regulated entities should maintain an up-to-date inventory and criticality classification of information systems and assets, and conduct regular cybersecurity risk assessments.
- Regulated entities should implement documented monitoring/surveillance and detection systems capable of real-time threat detection and reporting to the governing body.
- Regulated entities should maintain documented incident response policies covering preparation, detection/analysis, containment/eradication/recovery, and post-incident activity, with escalation criteria and defined roles/responsibilities.
- Regulated entities should maintain logs/audit trails to support investigation of cybersecurity events.
- Regulated entities should conduct a post-incident response review for material incidents and make it available to the Authority upon request.
- Regulated entities should establish containment and recovery policies/procedures for cybersecurity events affecting data or system availability.
- Regulated entities should encrypt confidential data in transit and at rest, apply strong access controls on a least-privilege basis, and securely dispose of data on decommissioned IT systems.
- Regulated entities should notify affected individuals, the Authority, and the Ombudsman (where applicable) as quickly as possible in the event of loss of financial assets or personally identifiable/data-protection-covered information.
- Regulated entities should provide regular updates to the Authority as new information becomes available until all material details of an incident have been provided, and continue providing situation updates until the incident is contained or resolved.
- Regulated entities should periodically test and update their cybersecurity framework for effectiveness.
- Regulated entities should develop a technology refresh plan to ensure IT infrastructure remains supported and up to date.
Applies to
all entities regulated by the Cayman Islands Monetary Authority, controlled subsidiaries as defined in the Banks and Trust Companies Act