Consultation Paper
Cyber Security Rules and Guidance Consultation Paper (September 2020)
DraftView on GFSC's website Source document
Summary
This is a Guernsey Financial Services Commission consultation paper seeking feedback on proposed Cyber Security Rules, 2020 and an accompanying draft Cyber Security Guidance Paper. The draft Rules would apply directly to all licensees under the Bailiwick's Regulatory Laws (investors protection, banking, fiduciary/company administration, insurance business, and insurance managers/intermediaries legislation) and set out baseline requirements for identifying, protecting against, detecting, responding to and recovering from cyber security events, plus a duty to notify the Commission of significant events.
- Identify: Licensees would need to identify material assets and assess significant associated cyber risks.
- Protect: Licensees would need appropriate policies and controls (e.g. cyber security software, timely IT updates, staff training, user awareness policies) to mitigate identified risks and maintain critical infrastructure.
- Detect: Licensees would need mechanisms to identify the occurrence of a cyber security event.
- Respond and Recover: Licensees would need a plan to mitigate disruption from a cyber security event, including awareness of group or outsourced provider plans, and steps to restore business capabilities afterward.
- Notify: Licensees would need to notify the Commission upon becoming aware of a cyber security event causing significant loss of data, IT availability, cost, business capability or service to users, providing specified details.
- Governance and review: The Board (or equivalent) would be responsible for ensuring compliance, licensees must be able to evidence implementation proportionate to size, nature and complexity, and measures must be reviewed after trigger events, after identified cyber security events, or at least periodically.
The accompanying guidance paper explains how firms might satisfy each rule, including expectations on periodic review frequency (recommended no less often than every 24 months) and considerations for remote working risks. As a consultation document, the Rules and Guidance are not yet in force; the commencement date in the draft Rules is left blank pending finalisation, and the Commission may grant case by case derogations from specific provisions.
Key obligations
- Licensees would be required to identify material assets and assess significant associated cyber risks (proposed Rule 2.1)
- Licensees would be required to have appropriate policies and controls to protect IT services and critical infrastructure, including cyber security software, timely system updates, employee training, and user awareness policies (proposed Rule 3.1)
- Licensees would be required to have mechanisms to detect the occurrence of cyber security events (proposed Rule 4.1)
- Licensees would be required to maintain a plan to mitigate disruption from cyber security events, including awareness of group-level or outsourced provider plans (proposed Rule 5.1)
- Licensees would be required to be able to demonstrate awareness of steps needed to restore business capabilities following a cyber security event (proposed Rule 6.1)
- Licensees would be required to notify the Commission upon becoming aware of a cyber security event causing significant loss of data, IT availability, cost, business capability, or service to users, and to provide specified details of the event (proposed Rule 7.1)
- The Board of Directors or equivalent would be responsible for ensuring the Rules are followed and licensees must be able to provide evidence of implementation on request (proposed Rule 1.1)
- Licensees would be required to review compliance measures in response to trigger events, following identified cyber security events, or at least periodically, and record such reviews (proposed Rule 1.1(5))
Applies to
licensees under the Protection of Investors (Bailiwick of Guernsey) Law, 1987, licensees under the Banking Supervision (Bailiwick of Guernsey) Law, 1994, licensees under the Regulation of Fiduciaries, Administration Businesses and Company Directors, etc (Bailiwick of Guernsey) Law, 2000, licensees under the Insurance Business (Bailiwick of Guernsey) Law, 2002, licensees under the Insurance Managers and Insurance Intermediaries (Bailiwick of Guernsey) Law, 2002, Prescribed Businesses (guidance only, non mandatory), Non-Regulated Financial Services Business (guidance only, non mandatory)