Rajah & Tann Regional Round-Up
your snapshot of key legal developments in Asia
Issue 3 - Jul/Aug/Sep 2023
 

Securities Commission Malaysia Issues New Guidelines on Technology Risk Management

In August 2023, the Securities Commission Malaysia ("SC") issued the Guidelines on Technology Risk Management ("TRM Guidelines") to enhance the management of technology risks by capital market entities ("CMEs"), in response to the growing adoption of technology among CMEs in recent years.


The TRM Guidelines are applicable to all CMEs licensed or registered under the Capital Market Services Act 2007. The guidelines are expected to come into effect by the third quarter of 2024, subject to further announcements from SC on the effective date of the TRM Guidelines.


Once the TRM Guidelines take effect, it will supersede existing requirements under SC's Guidelines on Management of Cyber Risk.


The TRM Guidelines introduce more detailed and enhanced requirements, including the requirements for CMEs to:


  1. ensure that their workforce undergoes annual cybersecurity awareness training;
  2. establish a technology audit plan and a comprehensive Technology Risk Management Framework that addresses specific areas identified in the TRM Guidelines;
  3. comply with the minimum requirements outlined in the TRM Guidelines about technology operations management, which encompass elements such as network and operational resilience, system security requirements, change management and patch management;
  4. conduct due diligence before selecting third-party service providers, and ensure that the Service Level Agreements executed with these providers contain the mandatory provisions outlined in the TRM Guidelines;
  5. implement a comprehensive cybersecurity framework with cybersecurity controls that align with their risk profile and business needs;
  6. notify SC upon detecting either (i) technology incidents that may potentially affect their business operations or clients; or (ii) cyber incidents that fall within the parameters defined in the TRM Guidelines, on the day of the occurrence of the incident through SC's Vault Portal; and
  7. be guided by the guiding principles relating to the adoption of artificial intelligence (AI) and machine learning prescribed by the TRM Guidelines when adopting such technologies.

CMEs are encouraged to proactively establish the necessary controls, policies and procedures to comply with the TRM Guidelines, pending the effective date or coming into legal effect of the TRM Guidelines. 



Please note that whilst the information in this Update is correct to the best of our knowledge and belief at the time of writing, it is only intended to provide a general guide to the subject matter and should not be treated as a substitute for specific professional advice.

 

Christopher & Lee Ong
Level 22, Axiata Tower ,
No. 9 Jalan Stesen Sentral 5
Kuala Lumpur Sentral,
50470 Kuala Lumpur, Malaysia
www.christopherleeong.com


Contacts:

Kuok Yew Chen
Partner
D +603 7958 8310
F +603 7958 8311
yew.chen.kuok@christopherleeong.com

John Mathew
Partner
D +603 2267 2626
F +603 2273 8310
john.mathew@christopherleeong.com

Yon See Ting
Partner
D +603 2278 8311
F +603 2278 8322
see.ting.yon@christopherleeong.com

Yau Yee Ming
Partner
D +603 2278 8311
F +603 2273 8322
yee.ming.yau@christopherleeong.com

Deepak Pillai
Partner
D +603 2267 2675
F +603 2273 8310
deepak.pillai@christopherleeong.com

Sri Sarguna Raj
Partner
D +603 2267 2737
F +603 2273 8310
sri.sarguna.raj@christopherleeong.com

Chor Jack
Partner
D + 603 2267 2729
F +603 2273 8310
jack.chor@christopherleeong.com

Rubini Murugesan
Partner
D +603 2267 2616
F +603 2273 8310
rubini.murugesan@christopherleeong.com

Lim Siaw Wan
Partner
D +603 2267 2731
F +603 2273 8310
siawwan.lim@christopherleeong.com

Rajah & Tann Asia is a network of legal practices based in Asia.

Member firms are independently constituted and regulated in accordance with relevant local legal requirements. Services provided by a member firm are governed by the terms of engagement between the member firm and the client.

This update is solely intended to provide general information and does not provide any advice or create any relationship, whether legally binding or otherwise. Rajah & Tann Asia and its member firms do not accept, and fully disclaim, responsibility for any loss or damage which may result from accessing or relying on this update.