Lead and perform industry-wide horizontal assessments of adopted cyber security risk management models, methodologies or practices with the aim to uncover common practices and potential gaps or areas of improvement
Develop and enhance effective surveillance infrastructure, supervisory tools and framework for early detection of emerging cyber risks to aid in macro / micro supervisory monitoring and risk mitigation strategies for the financial sector
...
Appraises the IT risk nature and IT health/condition of FIs, by undertaking IT risk assessment for effective supervision, to timely detect supervisory concerns and emerging risks, and effectively communicate any concerns together with the appropriate recommendations on supervisory measures to be undertaken. Also ensures that the agreed standards and deadlines are met, which allows all necessary supervisory documentations of FIs being assessed be duly completed and timely made available.
Performs continuous off-site monitoring activities to facilitate detection of potential problems, risk exposures and emerging supervisory concerns pertaining to IT. Ensures that FIs comply with the IT risk aspects of various regulations, rules and policies issued by BNM, and recommends remedial actions arising from concerns and/or breaches of compliance.
Undertakes IT risk assessment of formal applications received from FIs, and provides the appropriate recommendations in a timely manner. Ensures assessment of applications is comprehensive, appropriate and consistent with applicable laws, regulations and all applicable Policy Standards, and decisions are to be in accordance with approved supervisory and governance framework of the Bank.
...