+Security Awareness
---+Resilience Training Programs
---+Inclusion of Third-Party Providers

1. Overview

Security Awareness

Summary Standard
Resilience Training Programs Implement security awareness and digital operational resilience training as integral components of staff training schemes and ensure training extends to all staff members, including senior management. Customize training intensity based on employee roles and functions. For the training content, cover topics such as network security, insights from prior incidents, threat intelligence, defenses against intrusions, data protection measures (e.g., encryption, cryptography). Conduct the resilience training program on an annual basis. Staff shall be informed on the ICT security policies, procedures and protocols and be made aware of the reporting channels put in place for detecting anomalous activities. Upon termination of employment, all staff are required to return all ICT assets and information assets.
Inclusion of Third-Party Providers

Incorporate ICT third-party service providers as participants in relevant training programs, where appropriate. Third-parties shall be informed on the ICT security policies, procedures and protocols and be made aware of the reporting channels put in place for detecting anomalous activities. Upon termination of employment or contract termination, the third-parties are required to return all ICT assets and information assets that belong to the financial entity. 

1.1 References

1.2 Identified Requirements

1.2 Related Regulation

2. Identified Requirements

Requirements
Source Requirement

3. Related Regulations

Regulations
Source Regulation
Impressum