BUSINESS CONTINUITY MANAGEMENT REQUIREMENTS FOR SGX MEMBERS NEW RULES FOR INCLUSION IN SGX-ST RULES



Similar documents
: Chief Executive Officers of all Licensed Commercial Banks, Primary Dealers, Central Depository Systems (Pvt) Ltd. and LankaClear (Pvt.) Ltd.

Guideline on Business Continuity Management

Business Continuity and Disaster Recovery Policy

Monetary Authority of Singapore BUSINESS CONTINUITY MANAGEMENT GUIDELINES

Clinic Business Continuity Plan Guidelines

Attachment N CPIC Vendor Resiliency Business Continuity Planning Questionnaire

Business Continuity Planning and Disaster Recovery Planning

Clinic Business Continuity Plan Guidelines

BUSINESS CONTINUITY MANAGEMENT GUIDELINES FOR BANKS AND FINANCIAL INSTITUTIONS

CENTRAL BANK OF KENYA (CBK) PRUDENTIAL GUIDELINE ON BUSINESS CONTINUITY MANAGEMENT (BCM) FOR INSTITUTIONS LICENSED UNDER THE BANKING ACT

Statement of Guidance

Attachment #2. BUSINESS CONTINUITY PLAN Plan Development Guidelines

Business Continuity and Disaster Recovery Planning

Federal Financial Institutions Examination Council FFIEC. Business Continuity Planning BCP MARCH 2003 MARCH 2008 IT EXAMINATION

Virginia Commonwealth University School of Medicine Information Security Standard

The Weill Cornell Medical College and Graduate School of Medical Sciences. Responsible Department: Information Technologies and Services (ITS)

Vendor Management. Outsourcing Technology Services

NAIT Guidelines. Implementation Date: February 15, 2011 Replaces: July 1, Table of Contents. Section Description Page

IT Disaster Recovery Plan Template

<Client Name> IT Disaster Recovery Plan Template. By Paul Kirvan, CISA, CISSP, FBCI, CBCP

Smart Meters Programme Schedule 8.6. (Business Continuity and Disaster Recovery Plan) (CSP North version)

Disaster Recovery Policy

INSURANCE REGULATORY AUTHORITY IRA/PG/ GUIDELINE TO THE INSURANCE INDUSTRY ON THE BUSINESS CONTINUITY MANAGEMENT

Offsite Disaster Recovery Plan

SUPERVISORY AND REGULATORY GUIDELINES: PU BUSINESS CONTINUITY GUIDELINES

(Mr. Krirk Vanikkul) Assistant Governor, Financial Institutions Policy Group Governor For

NHS Lancashire North CCG Business Continuity Management Policy and Plan

Disaster Recovery Business Continuity Premium Edition

Desktop Scenario Self Assessment Exercise Page 1

EMERGENCY MANAGEMENT POLICY

How To Manage A Disruption Event

Disaster Recovery Plan (Business Continuity) Template - Version 8.2

Business Continuity Overview

BUSINESS CONTINUITY PLAN (TEMPLATE)

GUIDELINES FOR BUSINESS CONTINUITY IN WHOLESALE MARKETS AND SUPPORT SYSTEMS MARKET SUPERVISION OFFICE. October 2004

Public Health Emergency Preparedness Protocol, 2015

BSBCCO501B Develop business continuity strategy

Business Continuity Policy

Federal Financial Institutions Examination Council FFIEC BCP. Business Continuity Planning MARCH 2003 IT EXAMINATION H ANDBOOK

Prudential Standard CPS 232 Business Continuity Management

CITY UNIVERSITY OF HONG KONG Business Continuity Management Standard

Assessment Framework Business Continuity Planning (BCP) Financial Core Infrastructure

De Nederlandsche Bank N.V. May Assessment Framework for Financial Core Infrastructure Business Continuity Management

Post-Class Quiz: Business Continuity & Disaster Recovery Planning Domain

Prudential Practice Guide

Business Continuity Plan (BCP)

UNION COLLEGE SCHENECTADY, NY EMERGENCY MANAGEMENT PROCEDURES

Business Continuity & Recovery Plan Summary

PAPER-6 PART-5 OF 5 CA A.RAFEQ, FCA

University of Nottingham Emergency Procedures and Recovery Policy

Schneps, Leila; Colmez, Coralie. Math on Trial : How Numbers Get Used and Abused in the Courtroom. New York, NY, USA: Basic Books, p i.

Disaster Recovery Plan (Business Continuity) Template

BUSINESS CONTINUITY PLAN OVERVIEW

How to Plan for Disaster Recovery and Business Continuity

MEDIA RELEASE. IOSCO reports on business continuity plans for trading venues and intermediaries

All-Hazard Continuity of Operations Plan. [Department/College Name] [Date]

Business Continuity Management

Business Continuity Plan

Operational Risk Management Policy

Appendix J: Strengthening the Resilience of Outsourced Technology Services

Final Draft Guidelines

NexTrend Securities, Inc. Business Continuity Plan (BCP)

2014 NABRICO Conference

COMCARE BUSINESS CONTINUITY MANAGEMENT

Business Continuity Plan

South West Lincolnshire NHS Clinical Commissioning Group Business Continuity Policy

University of Prince Edward Island. Emergency Management Plan

Business Continuity Management Policy and Plan

THORNBURG INVESTMENT MANAGEMENT THORNBURG INVESTMENT TRUST. Business Continuity Plan

Consultative report. Committee on Payment and Settlement Systems. Board of the International Organization of Securities Commissions

How To Assess A Critical Service Provider

Business Continuity Management

Business Continuity and Disaster Planning

SAMPLE IT CONTINGENCY PLAN FORMAT

PAPER-6 PART-3 OF 5 CA A.RAFEQ, FCA

Appendix 3 Disaster Recovery Plan

Overview of Business Continuity Planning Sally Meglathery Payoff

Prudential Practice Guide

Title: DISASTER RECOVERY/ MAJOR OUTAGE COMMUNICATION PLAN

CISM Certified Information Security Manager

BUSINESS CONTINUITY PLAN

Business Continuity Management Review

BUSINESS CONTINUITY MANAGEMENT IN THE PUBLIC SECTOR A ROUGH GUIDE

External Supplier Control Requirements BCM

TABLE OF CONTENTS CHAPTER TITLE PAGE

BUSINESS CONTINUITY PLAN

Business Continuity Policy

Transcription:

BUSINESS CONTINUITY MANAGEMENT REQUIREMENTS FOR SGX MEMBERS NEW RULES FOR INCLUSION IN SGX-ST RULES New rule Current Rule Proposed Rule 4.6.21 Business Continuity Requirements The following requirements apply: (1) a Member must assess its business and operational risks and maintain adequate business continuity arrangements. New rule (2) a Member must document its business continuity arrangements in a business continuity plan. New rule (3) a Member s senior management shall be responsible for the Member s business continuity plan. Sufficient awareness of the risks, mitigating measures and state of readiness must be demonstrated by way of an attestation to the Member s Board of Directors. New rule (4) a Member must review and test its business continuity plan regularly. New rule (5) a Member must appoint emergency contact persons, and furnish the contact information of such persons to SGX- ST. The Member s emergency contact persons must be contactable at all times, and must immediately notify SGX-ST in the event of emergencies.

Practice Note BUSINESS CONTINUITY MANAGEMENT REQUIREMENTS FOR SGX MEMBERS NEW PRACTICE NOTE FOR INCLUSION IN SGX-ST RULES 4.6.21 Business Continuity Requirements Issue Date Cross Reference Enquiries 22 January 2009 Rule 4.6.21 Please contact Member Supervision: Facsimile No : 6538 8273 E-Mail Address: membersup@sgx.com 1. INTRODUCTION 1.1 Rule 4.6.21 requires Members to: (iii) (iv) maintain adequate business continuity arrangements; document business continuity arrangements in a business continuity plan; test and review business continuity plans regularly; and appoint emergency contact persons. 1.2 The objective is to ensure that Members have the ability to: react swiftly to emergency situations; and maintain critical functions and fulfill obligations to customers and counterparties in the event of major operational disruptions. 2. BUSINESS CONTINUITY PLAN 2.1 Critical Elements of a Business Continuity Plan 2.1.1 Rule 4.6.21(1) requires Members to maintain adequate business continuity arrangements, and document such arrangements in a business continuity plan. As a guide, a Member s business continuity plan should document the following elements: Risk assessment: This includes a comprehensive assessment of business continuity risks (including financial and operational risks) and threat scenarios which may severely disrupt a Member s operations. Such scenarios may include prolonged power outages, IT system software or hardware failures, Page 2 of 6

loss of voice or data communication links, acts of terrorism, and outbreak of infectious diseases; (iii) (iv) (v) (vi) (vii) Business impact analysis: This is an evaluation of the impact of the risks and threat scenarios identified in above. The business impact analysis should identify critical business functions (including support operations and related information technology systems) and potential losses (monetary and nonmonetary) to enable the Member to determine recovery strategies/priorities and recovery time objectives; Work area recovery: This refers to continuity arrangements for a Member s critical functional capabilities in the event that the Member s primary office becomes inaccessible, for example, availability of a disaster recovery site ready for activation within a reasonable period of time; Crisis communications: This refers to a communications plan for the Member to liaise with its internal and external stakeholders such as employees, customers and regulatory authorities during a crisis; Roles and responsibilities: This refers to the identification of a Member s key personnel and management staff, their roles and responsibilities, and reporting lines. Alternates should be identified to cover the responsibilities of absent key personnel. Backup for critical functions 1, information technology systems and data; Key service providers 2 : This refers to assessing a Member s dependencies on key service providers in recovery strategies and recovery time objectives, and taking steps to ensure that key service providers are capable of supporting the Member s business, even in disruptions; (viii) Outsourcing service providers 3 : This refers to assessing whether the service provider has established satisfactory Business Continuity Plans commensurate with the nature, scope and complexity of the outsourced services; and (ix) Any other elements that the Member deems necessary to be included in its business continuity plan or which SGX-ST may prescribe from time to time. 2.2 Emergency Response During Crisis 2.2.1 A Member should establish and maintain a crisis management plan as part of its business continuity plan. The crisis management plan should include (but not be limited to): 1 Critical functions refer to business functions whose failure or disruption may incapacitate the firm. 2 Key service providers refer to third-parties who are performing functions that are not normally carried out by Member firms internally, but are critical to Member firms ability to carry on business operations. For example, IT system hardware/software vendors. 3 Outsourcing service providers refer to third parties who are performing functions that would normally be performed by Members firms internally. For example, Operations and Technology. Page 3 of 6

(iii) (iv) Emergency response procedures; Roles and responsibilities of the crisis management team; Command and control structures; and Salvage and restoration procedures. 2.2.2 SGX-ST may declare a wide-area crisis in the event of a major and widespread incident. When such declaration is made, SGX-ST may require a Member to submit status reports to SGX-ST. A wide-area crisis may include any incident where the operations of a large number of market participants are disrupted simultaneously. 2.3 Regular Review, Testing and Training 2.3.1 Rule 4.6.21(4) requires a Member to review and test its business continuity plan regularly. Members should do so at least once a year to ensure that their business continuity plans remain relevant. 2.3.2 Where there are material changes to a Member s business activities and operations, the Member should update its business continuity plan accordingly. Regular training should be conducted for staff to be updated and aware of any relevant changes to the Member s business continuity arrangements. As a principle, training should be conducted when: changes have been made to the Member firm s BCP; and new staff are recruited. Member firms should also conduct refresher courses for existing staff where appropriate. 3. EMERGENCY CONTACT PERSONS 3.1 Rule 4.6.21(5) requires a Member to appoint emergency contact persons and furnish the contact information of such persons to SGX-ST. Members may appoint an emergency contact person and up to two (2) alternates. A template is attached as Appendix A to this Practice Note for the notification of contact information (postal address, email, telephone, mobile telephone and facsimile numbers) to SGX-ST. 3.2 Members are to ensure that the contact information provided to SGX-ST is updated on a semi-annual basis. Nonetheless, where there are changes to a Member s emergency contact persons and contact information, the Member should notify SGX- ST immediately in writing. 3.3 A Member s authorized emergency contact person should immediately notify SGX- ST in the event where: Page 4 of 6

A Member s business operations are or will be significantly disrupted; and/or A Member s business continuity plan is activated. Page 5 of 6

APPENDIX A Business Continuity Management Emergency Contact Person(s) Company Name: Name Department Designation Office No. Mobile No. E-mail address Prepared by: Name: Designation: Page 6 of 6