← Study index · All 130 facts by topic →RES5 β Rules, Ethics and Skills for Financial Advisory Services β Cheat Sheet
Chapter 6 · quick-revision digest · narrative, key figures & core facts
π Overview
This chapter spans three distinct regulatory notices that together govern the operational safeguards a licensed financial adviser must maintainβfrom detecting fraud and managing technology risk to distributing Direct Purchase Insurance products. The first notice, FAA-N17, mandates that any suspicious activity or fraud material to the adviser's soundness must be reported to MAS within 5 working days using Form F1, and all such reports must be signed and dated by the reporting officer. Crucially, advisers must still file separate suspicious transaction reports with the Suspicious Transaction Reporting Office independentlyβsatisfying FAA-N17 does not satisfy the separate STR obligation under money laundering rules, and FAA-N17 itself is stated to take immediate effect (though a later provision dates its effect to 10 May 2024, creating a tension the underlying facts leave unresolved).
The second mosaic, formed by FSM-N23 and FSM-N24, addresses technology resilience and operational security. FSM-N23 requires each licensee to identify critical systems, keep unscheduled downtime below 4 hours in any 12-month period, and maintain a 4-hour recovery time objective that must be validated annually. Upon discovery of a relevant incidentβa system malfunction or IT security event with severe, widespread impactβthe adviser must notify MAS within 1 hour and submit a full root-cause analysis within 14 days. FSM-N24 supplements this with six cyber hygiene practices: securing administrative accounts, applying security patches, establishing baseline security standards, deploying network security devices, implementing anti-malware measures, and requiring multi-factor authentication for all critical systems and any internet-accessible system holding customer information.
The third section governs distribution of Direct Purchase Insurance products through FAA-N19, which sets out five interrelated requirement areas: safeguards to ensure clients check affordability and coverage before purchase, upfront disclosure of product information and policy wordings, avenues for queries and complaints, internal policies and processes (including training and mystery shopping exercises), and clear role definitions distinguishing representatives from customer service officers. The definitions section provides anchorsβfor Tier 1 life insurers, the online direct channel, and the limited scope of financial advisory services that are solely incidental to DPI distribution. A transitional arrangement allowed advisers already using an online channel before August 2019 to continue under the old paragraphs 12 to 14 until 31 December 2019, and non-compliance with the notice carries a fine of up to $25,000 plus $2,500 for each continuing day.
β±οΈ Key figures, limits & deadlines
| Item | Value | Type | Source |
|---|
| Technology Risk Management | 4 hours | Threshold | Ch. 7, p. 8 |
| Technology Risk Management | 4 hours | Threshold | Ch. 7, p. 8 |
| Notice on Cyber Hygiene (FSM-N24) | 29(1) section | Threshold | Ch. 19, p. 20 |
| Definitions β multi-factor authentication | 2 factors | Threshold | p. 6D-4 |
| Form and Deadline for FAA-N17 Report | 5 working days | Deadline | Ch. 2, p. 3 |
| Technology Risk Management | 12 months | Deadline | Ch. 7, p. 8 |
| Technology Risk Management | 1 hours | Deadline | Ch. 7, p. 8 |
| Technology Risk Management | 14 days | Deadline | Ch. 7, p. 8 |
| DPI Disclosure Standards β Not False or Misleading | 1 year | Deadline | p. 17 |
| DPI Document Review | 1 year | Deadline | p. 17 |
| Offences β penalty for contravening a written direction | S$25,000 | Penalty | Ch. 18, p. 18 |
| Offences β continuing offence daily fine | S$2,500 | Penalty | Ch. 18, p. 18 |
π
Key dates
| Event | Date | Source |
|---|
| Technology Risk Management | 2024-05-10 | Ch. 7, p. 8; p. 23 |
| Transitional arrangements β key dates | 2019-08-30 | Ch. 18, p. 18 |
β οΈ Exam traps (commonly confused)
- FAA-N17 report to MAS vs STR to STRO: FAA-N17 suspicious activity report to MAS (Form F1) is separate from and does not replace the suspicious transaction report (STR) filing to STRO under AML/CFT notices.
- system malfunction vs IT security incident: A system malfunction is a failure of a critical system; an IT security incident involves a security breach (hacking, intrusion, DoS) on any system compromising customer info β they are distinct triggers for a relevant incident.
- 4-hour downtime limit vs 4-hour RTO: The 4-hour limit is for maximum unscheduled downtime per critical system within any 12 months; the RTO of 4 hours is the target restoration time from the point of disruption for each critical system.
- 1-hour incident notification vs 14-day root cause report: The 1-hour deadline is for notifying MAS as soon as possible upon discovery of a relevant incident; the 14-day deadline is for submitting the root cause and impact analysis report from discovery.
- Tier 1 life insurer vs direct life insurer: A direct life insurer is a licensed insurer under the Insurance Act; a Tier 1 life insurer is a financial adviser that is a registered insurer meeting specific corporate governance conditions β different classifications.
- DPI rep/CSO product info vs DPI online channel product info: For rep/CSO channel the adviser must furnish documents under para 13 and highlight specific items; for the online channel the adviser must provide those same documents plus online policy wordings and ensure mandatory fields are completed before processing.
- DPI conditional acceptance vs DPI disclaimer/exclusion/warning: Conditional acceptance (sub-para b(ii)) refers to underwriting-imposed conditions (exclusion or premium loading); disclaimer/exclusion/warning (sub-para b(i)) covers standard policy disclaimers β two separate disclosure duties.
- DPI β Adequate standard vs DPI β Clear standard: Clear = plain language and explained jargon; Adequate = sufficient for informed decision, with prominent warnings on risks, fees, and contractual obligations.
- DPI effective date (30 Aug 2019) vs DPI transitional end date (31 Dec 2019): The FAA-N19 Amendment 2019 took effect on 30 August 2019; but para 12-14 as they stood before amendment continued to apply to existing online DPI distributors until 31 December 2019.
- administrative account MFA vs customer-information account MFA: MFA is required for all administrative accounts on critical systems (para 4.6(a)) AND for all accounts used to access customer info via the internet (para 4.6(b)) β different scopes.
β Core facts
The must-know propositions, distilled. See all 130 facts by topic →
πFaa N17 Scope And Application
- Notice FAA-N17 is issued pursuant to Section 58 of the Financial Advisers Act (the Act) and applies to all licensed financial advisers. β Ch. 2, p. 3
⚠ The Notice does not apply to representatives or exempt financial advisers β only licensed financial advisers.
- Notice FAA-N19 covers the following requirements in respect of the distribution of direct purchase insurance products: (a) Implementation of safeguards; (b) Provision of product information; (c) Provision of avenues to address general queries; (d) Implementation of internal policies and processes; (e) Roles and responsibilities of a representative or customer service officer. β Ch. 9, p. 10
⚠ This is a named enumeration of 5 requirements β all five must be recalled together as the scope of FAA-N19.
π¨Suspicious Activities And Fraud Reporting
- A licensed financial adviser shall lodge with the Monetary Authority of Singapore a report in the form, manner and within such time as specified in paragraph 4, upon discovery of any suspicious activities and incidents of fraud where such activities or incidents are material to the safety, soundness or reputation of the licensed financial adviser. β Ch. 2, p. 3
⚠ The materiality qualifier ('material to the safety, soundness or reputation') is a distinct gate β not all suspicious activities trigger the FAA-N17 reporting duty.
- The report under FAA-N17 paragraph 2 shall be in Form F1 ("Suspicious Activities & Incidents of Fraud Report") and shall be lodged not later than 5 working days after the discovery of the activity or incident by the licensed financial adviser.5 working days β Ch. 2, p. 3
⚠ Form F1 is specific to FAA-N17 β do not confuse with the STR form for STRO or with a police report.
- The Suspicious Activities and Incidents of Fraud Report is submitted under Notice No. FAA-N17 under the Financial Advisers Act (2001). β Ch. 4, p. 4
⚠ Do not confuse FAA-N17 (suspicious activity/fraud reporting) with FSM-N23 (technology risk management) which appears in the same chapter.
- The Suspicious Activities and Incidents of Fraud Report may be submitted by post, fax or encrypted email. β Ch. 4, p. 4
⚠ The email submission method specifically requires encryption β 'encrypted email' is a single condition, not just 'email'.
- The reporting officer for the Suspicious Activities and Incidents of Fraud Report must be the CEO, Principal Officer or Director of the reporting financial institution. β Ch. 4, p. 4
⚠ The Contact Officer is a separate field ('if different from Reporting Officer'), so they can be different persons but the Reporting Officer must be CEO/Principal Officer/Director.
- The report must include: (a) the date and circumstances under which the activity/incident was discovered; (b) the number of clients/users/customers affected; (c) details of persons involved in the suspicious activity; (d) the monetary amounts involved; and (e) any other relevant information. β Ch. 4, p. 4
⚠ These five items are what must be included in the report details β item (e) is a catch-all 'any other relevant information', not an exhaustive closure.
- The report must state the reasons for not lodging a police report on the incident of fraud. β Ch. 4, p. 4
⚠ This is Section 4 of the form and applies specifically to 'incident of fraud'βnot to suspicious activities that are not fraud. If a police report was lodged, the form does not appear to require this explanation (it asks for reasons for NOT lodging).
βοΈFsm N23 Scope
- FSM-N23 is issued pursuant to section 29(1) of the Financial Services and Markets Act 2022 (the 'Act'). β p. 5, 6
⚠ Do not confuse the parent Act (FSMA 2022) with the FAA 2001 under which the licensee is licensed.
- FSM-N23 applies to all financial advisers licensed under the Financial Advisers Act 2001 ('licensee'). β p. 5, 6
⚠ Do not confuse the parent Act (FSMA 2022) with the FAA 2001 under which licensees are licensed.
- FSM-N23 sets out requirements for a high level of reliability, availability and recoverability of critical IT systems. β p. 5, 6
⚠ The triad is reliability, availability and recoverability β all three are required, not just two.
- FSM-N23 sets out requirements to implement IT controls to protect customer information from unauthorised access or disclosure. β p. 5, 6
- This Notice (FSM-N23) is issued pursuant to section 29(1) of the Financial Services and Markets Act 2022 (the βActβ) and applies to all financial advisers licensed under the Financial Advisers Act 2001 (βlicenseeβ). β Ch. 7, p. 7
⚠ Do not mix up the issuing statute (FSMA 2022) with the licensing statute (FAA 2001).
π§Technology Risk Definitions
- "critical system" in relation to a licensee, means a system, the failure of which will cause significant disruption to the operations of the licensee or materially impact the licensee's service to its customers. β Ch. 7, p. 7
⚠ The definition has two alternative prongs (disruption to operations OR material impact on customer service) plus two example categories β the examples illustrate but do not exhaust the definition.
- "IT security incident" means an event that involves a security breach, such as hacking of, intrusion into, or denial of service attack on, a critical system, or a system which compromises the security, integrity or confidentiality of customer information. β Ch. 7, p. 7
⚠ An IT security incident can involve EITHER a critical system OR any system that compromises customer information β it is not limited to critical systems.
- "relevant incident" means a system malfunction or IT security incident, which has a severe and widespread impact on the licensee's operations or materially impacts the licensee's service to its customers. β Ch. 7, p. 7
⚠ A relevant incident must meet a severity threshold (severe AND widespread impact on operations, or material impact on customer service) β it is NOT every system malfunction or IT security incident.
- "system" means any hardware, software, network, or other information technology ("IT") component which is part of an IT infrastructure. β Ch. 7, p. 7
⚠ The term "system" is the broad foundational definition that feeds into "critical system" and other definitions.
- "system malfunction" means a failure of any of the licensee's critical systems. β Ch. 7, p. 7
⚠ System malfunction and IT security incident are distinct β a system malfunction is a failure of a critical system, while an IT security incident is a security breach.
π‘οΈTechnology Risk Obligations
- A licensee must put in place a framework and process to identify critical systems. β Ch. 7, p. 8
- A licensee must ensure that the maximum unscheduled downtime for each critical system that affects the licensee's operations or service to its customers does not exceed a total of 4 hours within any period of 12 months.4 hours β Ch. 7, p. 8
⚠ The 4-hour limit is for unscheduled downtime only (not total/planned downtime), per critical system, measured over any rolling 12-month period β not a calendar year.
- A licensee must establish a recovery time objective (RTO) of not more than 4 hours for each critical system.4 hours β Ch. 7, p. 8
⚠ RTO of β€4 hours is distinct from the unscheduled downtime limit of β€4 hours in 12 months. RTO is a recovery target from point of disruption; the downtime limit is a cap on actual unscheduled downtime accumulated over 12 months.
- The RTO is the duration of time, from the point of disruption, within which a system must be restored. β Ch. 7, p. 8
⚠ RTO is measured 'from the point of disruption' β not from discovery or notification.
- A licensee must notify the Authority as soon as possible, but not later than 1 hour, upon the discovery of a relevant incident.1 hours β Ch. 7, p. 8
⚠ The 1-hour notification is from discovery of the incident, not from when the incident occurred. The 'as soon as possible' qualifier means even faster than 1 hour is expected where feasible.
- A licensee must submit a root cause and impact analysis report to the Authority within 14 days, or such longer period as the Authority may allow, from the discovery of the relevant incident.14 days β Ch. 7, p. 8
⚠ The 14-day root cause report deadline runs from discovery (like the 1-hour notification), and the Authority may extend it.
- A licensee must implement IT controls to protect customer information from unauthorised access or disclosure. β Ch. 7, p. 8
πDpi Scope And Definitions
- FAA-N17 applies to a licensed financial adviser, an exempt financial adviser, or a representative of a financial adviser, when providing either or both of the following types of financial advisory service which are solely incidental to the distribution of DPI: (i) advising others, either directly or through any publication or writing (other than by issuing or promulgating any research analysis or research report), concerning any DPI; (ii) arranging any contract of insurance in respect of any DPI. β Ch. 11, p. 11
⚠ The advisory service excluding research analysis/research reports is in sub-paragraph (i) β this is not a carve-out from the whole Notice but from the definition of 'advising others'.
- FAA-N17 does not apply to a financial adviser or representative who is exempt from section 27 of the Act under regulations 32B(1) and (3) or regulation 34(1) (read with regulation 34(2)) of the FAR, in respect of the activity or activities for which the exemption applies. β Ch. 11, p. 11
⚠ The exclusion is activity-specific: a person exempt under these regulations for one activity still falls within FAA-N17 for other non-exempt activities.
- Conditional acceptance, in relation to a DPI, refers to any additional conditions or exclusions imposed by a direct life insurer in respect of the application for a DPI. β Ch. 11, p. 11
⚠ The condition is imposed by the direct life insurer, not the financial adviser or the client.
- Financial adviser means a licensed financial adviser or an exempt financial adviser. β Ch. 11, p. 11
⚠ Representative is a separate defined term β a financial adviser is not the same as a representative.
- Representative means an appointed or provisional representative. β Ch. 11, p. 11
⚠ Representative covers both appointed and provisional β not the same as financial adviser.
- Unless otherwise specified, a representative must comply with every requirement imposed on a financial adviser in this Notice when acting on the financial adviser's behalf in relation to the distribution of DPI. β p. 12
⚠ The 'unless otherwise specified' qualifier is easily overlooked β the default is full incorporation of all FA duties, not just those labelled 'representative' duties.
ποΈDpi Distribution Channels
- Subject to paragraph 9, a financial adviser must only distribute DPI through its representative or customer service officer, or by way of an online direct channel. β p. 12, 13
⚠ The rule is subject to paragraph 9 β the Tier 1 life insurer special rule is a carve-out, not a separate option.
- A financial adviser who is a Tier 1 life insurer must, at the minimum, distribute DPI either through its representative or customer service officer at the Tier 1 life insurer's principal place of business or branch office (not being a mobile branch). The financial adviser may also distribute DPI by way of an online direct channel provided that it also distributes DPI through a representative or customer service officer at its principal place of business or branch office. β p. 12, 13
⚠ This is an additional minimum requirement for Tier 1 life insurers, not a replacement of paragraph 8. Online-only distribution is not sufficient for a Tier 1 life insurer.
πDpi Client Safeguards
- Where a client intends to purchase a DPI, the financial adviser must implement safeguards so as to ensure that the client has carried out steps to check that (i) he is able to afford the premiums payable in respect of the DPI; (ii) the DPI adequately covers his protection needs; and (iii) he has not misunderstood any features or terms and conditions of the DPI. β p. 12, 13
⚠ The three checks are a named set (afford premiums, adequate coverage, no misunderstanding of features/terms). All three must be implemented.
- The five requirements a financial adviser must comply with in respect of its distribution of DPI through representatives, customer service officers, or by way of an online direct channel are: (a) implementation of safeguards; (b) provision of product information; (c) provision of avenues to address general queries, complaints and claims; (d) implementation of internal policies and processes; and (e) setting out the roles and responsibilities of a representative or customer service officer. β p. 12, 13
⚠ This is a named enumeration β all five must be recalled together. The fifth requirement (roles and responsibilities) is the most commonly dropped.
πDpi Product Information Rep Cso
- A financial adviser must, in respect of every DPI it distributes, make available to a client such tools and calculators which enable the client to calculate: (a) the coverage of the DPI, so that the client may determine if the DPI adequately covers his protection needs; and (b) the total amount of premiums payable for the DPI, so that the client may determine if he is able to afford the DPI based on his income and financial commitments. β Ch. 14, p. 14
⚠ Both limbs (a) and (b) are mandatory β exam may test whether one is optional.
- Where a financial adviser distributes DPI through its representative or customer service officer, the financial adviser must require the representative or customer service officer to highlight to the client any conditions, including special exclusions or additional premium loadings imposed by a direct life insurer as a result of underwriting the policy application, and where the client intends to purchase a DPI with a conditional acceptance, obtain the client's acknowledgement that he has read and understood such conditions before purchasing the DPI. β Ch. 14, p. 14
⚠ This is a two-part requirement: (1) highlight conditions from underwriting, (2) if conditional acceptance, obtain signed acknowledgement before purchase.
- Where a financial adviser distributes DPI through its representative or customer service officer, the financial adviser must require the representative or customer service officer, before the client completes his application for the DPI, to alert the client in a clear, simple and concise manner that: (i) the DPI is not a savings account or deposit; (ii) the client may not get back the premiums paid (partially or in full) if the client terminates or surrenders the policy early; (iii) some benefits of the DPI are not guaranteed (only if applicable); and (iv) there is a 14-day free-look period. β Ch. 14, p. 14
⚠ Item (iii) is conditional β 'only if applicable'. The other three are always required.
π»Dpi Product Information Online
- Where a financial adviser distributes DPI through its representative or customer service officer, the financial adviser must ensure that at the point of a client's application for the purchase of a DPI, the representative or customer service officer furnishes the following documents to the client: (a) the documents set out in paragraph 37(b) of the MAS Notice on Recommendations on Investment Products (FAA-N16); (b) the fact sheet and checklist that are prepared by a direct life insurer in accordance with the industry standards for DPI, as issued by the Life Insurance Association, Singapore. β Ch. 15, p. 15
⚠ Paragraph 13 (representative/customer service officer distribution) requires only (a) FAA-N16 para 37(b) docs + (b) fact sheet & checklist from insurer. The policy wordings requirement belongs to paragraph 14 (online direct channel).
- Where a financial adviser distributes DPI by way of an online direct channel, the financial adviser shall: (a) provide the information required in paragraphs 12(a) to (b) through the online direct channel to the client; (b) comply with the requirements under paragraphs 12(c) and (e) through the online direct channel; (c) ensure that all mandatory fields in the proposal form for the purchase of the DPI have been completed before processing the proposal form; and (d) at the point of a client's application for the purchase of a DPI, provide the information required in paragraph 13(a) and (b), and an online copy of, or access to the full and actual policy wordings of the DPI. β Ch. 15, p. 15
⚠ Distinguish between distribution channels: para 13 (rep/CSO) vs para 14 (online direct). The online channel has additional obligations: mandatory fields completion and providing policy wordings.
- Where a financial adviser distributes DPI by way of an online direct channel, at the point of a client's application for the purchase of a DPI, the financial adviser must provide the information required in paragraph 13(a) and (b), and an online copy of, or access to, the full and actual policy wordings of the DPI. β Ch. 15, p. 15
⚠ Policy wordings are only required for the online direct channel (para 14(d)), not for representative/CSO distribution. Also note the format: 'online copy of, or access to' the wordings.
πDpi Internal Policies And Training
- A financial adviser must implement internal policies and processes, including adequate control systems and procedures, relating to the distribution of DPI. β Ch. 16, p. 16
⚠ The word 'must' makes this mandatory β do not confuse with a recommendation.
- The internal policies and processes must include: (a) policies and processes which set out the respective responsibilities of the representative and customer service officer, in relation to their respective distribution of DPI on behalf of the financial adviser, including clear guidelines relating to the manner of distribution of DPI and informing clients the manner in which and the locations at where a DPI may be purchased. β Ch. 16, p. 16
⚠ This names two specific roles (representative and customer service officer) and their respective DPI responsibilities β not just one role.
- The internal policies and processes must include training for every representative or customer service officer who distributes DPI on behalf of the financial adviser, and the training must, at the minimum, cover the role and scope of responsibilities of a representative or customer service officer in relation to his distribution of DPI on behalf of the financial adviser, and the risks and features of DPI. β Ch. 16, p. 16
⚠ Training is mandatory but only for those who distribute DPI, not all staff. Two minimum content areas: (i) role/responsibilities and (ii) risks/features.
- The internal policies and processes must include, in relation to the online direct channel, policies and processes for distribution of DPI, including instituting controls and safeguards to adequately address information security risks, and putting in place an appropriate business continuity plan to minimise system downtime or component failures to the online direct channel, and to ensure the functionality and continued operation of the online direct channel at all times. β Ch. 16, p. 16
⚠ This requirement is specifically about the online direct channel β distinct from the general policies in (a).
π’Dpi Disclosure Standards
- A financial adviser or representative who provides a recommendation in relation to a DPI which is not solely incidental to the distribution of the DPI must comply with Part I Chapter 6C of the Act, as well as the Regulations and Notices which apply to the provision of financial advice. β p. 16, 17
⚠ The 'not solely incidental' condition is key β if the recommendation is merely incidental to distribution, this obligation may not arise.
- A financial adviser, or a representative or customer service officer of the financial adviser, is expected to meet the following general standards in all product information disclosures and information provided to clients in relation to a DPI: (a) Clear, (b) Adequate, (c) Not False or Misleading. β p. 17
⚠ There are exactly three named standards β Clear, Adequate, Not False or Misleading. Do not add a fourth or substitute 'Accurate' or 'Concise'.
β³Dpi Transitional And Penalties
- Notwithstanding the effective date of FAA-N19 (Amendment) 2019, paragraphs 12 to 14 of the Notice in force immediately before 30 August 2019 continue to apply to financial advisers who have distributed DPI on an online direct channel prior to 30 August 2019 as if the amendments to paragraphs 12 to 14 in FAA-N19 (Amendment) 2019 have not been made, until 31 December 2019. β Ch. 18, p. 18
⚠ The transitional arrangement preserves the old (pre-amendment) paragraphs 12-14, not the new ones β candidates often invert which version applies during the transition.
- Any person who contravenes any requirement specified in a written direction issued by the Authority (which would include this Notice), shall be guilty of an offence and shall be liable on conviction to a fine not exceeding S$25,000 and, in the case of a continuing offence, to a further fine not exceeding S$2,500 for every day or part thereof during which the offence continues after conviction.S$25,000 β Ch. 18, p. 18
⚠ The penalty under s58(5) is a fine only (no imprisonment term), unlike some other FAA offence provisions. The continuing offence daily fine is S$2,500, not a percentage of the maximum.
πFsm N24 Scope And Cyber Obligations
- FSM-N24 is issued pursuant to section 29(1) of the Financial Services and Markets Act 2022 (the 'Act').29(1) section β Ch. 19, p. 20
⚠ Distinguish FAA (Financial Advisers Act) from FSMA (Financial Services and Markets Act) β FSM-N24 is under FSMA, not FAA.
- FSM-N24 applies to all financial advisers licensed under the Financial Advisers Act 2001 (each a 'relevant entity'). β Ch. 19, p. 20
⚠ The term 'relevant entity' is defined here as a financial adviser licensed under the FAA 2001.
- FSM-N24 sets out cyber security requirements on: securing administrative accounts, applying security patching, establishing baseline security standards, deploying network security devices, implementing anti-malware measures, and strengthening user authentication. β Ch. 19, p. 20
⚠ This is a named enumeration β the six areas form a complete set. All six must be recalled together.
- This Notice applies to all financial advisers licensed under the Financial Advisers Act 2001 (each a 'relevant entity'). β Ch. 21, p. 21
⚠ 'Relevant entity' is defined here as a financial adviser licensed under the FAA 2001.
- An "administrative account" means any user account that has full privileges and unrestricted access to any one or more of the following systems: (a) an operating system; (b) a database; (c) an application; (d) a security appliance; or (e) a network device. β p. 6D-4
⚠ The wording is 'any one or more' β access to one system on the list is sufficient, not all five.
- "Customer information" means any information relating to, or any particulars of, any customer of the relevant entity, where a named customer or group of named customers can be identified, or is capable of being identified, from such information. β p. 6D-4
⚠ Covers both named customers and groups of named customers, and includes information from which identification is merely capable (not necessarily already achieved).
- "Critical system" in relation to a relevant entity means a system the failure of which will cause significant disruption to the operations of the relevant entity or materially impact the relevant entity's service to its customers, such as a system whichβ (a) processes transactions that are time critical; or (b) provides essential services to customers. β p. 6D-4
⚠ The test is 'or' (either significant disruption to operations OR material impact on service), and the examples are illustrative ('such as'), not exhaustive.
- "Multi-factor authentication" means the use of two or more factors to verify an account holder's claimed identity. Such factors include, but are not limited toβ (a) something that the account holder knows such as a password or a personal identification number; (b) something that the account holder has such as a cryptographic identification device or token; (c) something that the account holder is such as an account holder's biometrics or his behaviour.2 factors β p. 6D-4
⚠ Multi-factor means two or more different CATEGORIES of factors (know/have/are), not just two pieces of information.
- A relevant entity need not comply with a requirement in this Notice to the extent that it is unable to exercise control over a system to ensure compliance with that requirement, where all three conditions are met: (a) the relevant entity cannot exercise direct control over the system to ensure compliance; (b) the relevant entity cannot exercise indirect control over the system by requiring the system provider to ensure compliance; and (c) it is not reasonable for the relevant entity to procure an alternative system provider over whom the relevant entity is able to exercise such indirect control. β Ch. 22, p. 22
⚠ All three conditions are conjunctive β the entity must satisfy (a) AND (b) AND (c) for the exception to apply.
- A relevant entity must ensure that every administrative account in respect of any operating system, database, application, security appliance or network device is secured to prevent any unauthorised access to or use of such account. β p. 22, 23
⚠ The obligation is limited to administrative accounts, not all accounts. Scope covers operating systems, databases, applications, security appliances, and network devices.
- A relevant entity must ensure that security patches are applied to address vulnerabilities to every system, and apply such security patches within a timeframe that is commensurate with the risks posed by each vulnerability. β p. 22, 23
⚠ The timeframe is risk-based (commensurate with the risk posed by each vulnerability), not a fixed period. Applies to 'every system', not only critical systems.
- Where no security patch is available to address a vulnerability, the relevant entity must ensure that controls are instituted to reduce any risk posed by such vulnerability to such a system. β p. 22, 23
⚠ This is an alternative obligation that kicks in only when no security patch exists. Do not confuse with the patching obligation in 4.2(a).
- A relevant entity must ensure that one or more malware protection measures are implemented on every system, to mitigate the risk of malware infection, where such malware protection measures are available and can be implemented. β p. 22, 23
⚠ The obligation is conditional β it only applies where malware protection measures 'are available and can be implemented'. Also requires 'one or more' measures, not a specific type.
- A relevant entity must ensure that multi-factor authentication is implemented for all administrative accounts in respect of any operating system, database, application, security appliance or network device that is a critical system. β p. 22, 23
⚠ MFA under (a) is only for administrative accounts on critical systems β do not confuse with (b) which covers accounts accessing customer info via the internet. Also distinct from para 4.1 which requires all admin accounts to be secured (not necessarily with MFA).
- A relevant entity must ensure that multi-factor authentication is implemented for all accounts on any system used by the relevant entity to access customer information through the internet. β p. 22, 23
⚠ This is limb (b) of the MFA requirement β covers all accounts (not just admin) on systems accessing customer info via the internet. No 'critical system' condition applies here, unlike limb (a).