ASIC introduces market integrity rules imposing new information security and operational resiliency obligations
Earlier this month, ASIC introduced the ASIC Market Integrity Rules (Securities Markets and Futures Markets) Amendment Instrument 2022/74 (the Amendment Instrument), amending the ASIC Market Integrity Rules (Securities Markets) 2017 and the ASIC Market Integrity Rules (Futures Markets) changes. 2017 (together the Rules). For more background on the changes, see Report 719: Response to Submissions to CP 314 Market Integrity Rules for Technological and Operational Resilience.
Rules begin March 10, 2023 and:
- introducing additional obligations for market participants and operators in terms of technological and operational resilience;
- increase the broader regulatory focus on deterring deficient systems and operational governance and controls (e.g. ASIC’s ongoing litigation against RI Advice Group Pty Ltd – see our legal briefing here);
- seek greater alignment with international standards and other national standards; and
- complement the existing requirements for companies in terms of information security and operational resilience, such as B. the Prudential Standard CPS 234: Information Security from APRA.
WHAT ARE THE MAIN CHANGES UNDER THE RULES?
- Market participants and operators must create business continuity plans in order to1. respond to major events that have the potential to cause significant business disruption or significantly impact their services. These include pandemics, natural disasters, cyber attacks or power outages. Business continuity plans shall be reviewed and tested at least annually and whenever there is a significant change.
- The board of directors or the management must have overall supervision of the business2. Continuity plans (a postponement after consultation with ASIC’s original proposal that the board and senior management have oversight).
- Market participants and operators must have appropriate means of identification in place,3. Risk assessment, management and monitoring to ensure the resilience, reliability, integrity and security of [their] Critical business services.’ Critical business services are broadly defined – “functions, infrastructure, processes, or systems that, in the event of a failure in effective operations, would or would cause significant business disruption or material service impact”. The failure of a critical business service does not automatically mean that a market participant or operator has not taken reasonable precautions.
- Market participants and operators must have adequate safeguards and controls4 in place. established to ensure the confidentiality, integrity and protection of information. This includes recovery backup systems. Records must be retained for at least seven years after unauthorized access.
- Outsourcing arrangements involving a third party that either operates or supports critical business services are governed by the Rules. Due diligence must be performed to ensure that the third party has the ability and capacity to provide the Services effectively. The performance of the third party must be monitored to ensure that the services covered by the outsourcing agreement are being performed and that the third party has the ability and capacity to continue to perform the services effectively throughout the term of the agreement. Conflict management systems must also be in place for outsourcing agreements.
- Trading controls (market operators only). A market operator is required after the6. Trading controls rules, including automated controls, that allow for the immediate suspension, restriction or prohibition of trading message entry by a market participant where this is necessary to ensure that the market is fair, orderly and transparent.
- Reporting Obligations. There are a number of reporting requirements:
major events. Both market participants and operators must notify ASIC immediately when they become aware of a significant event. This includes natural disasters, cyber attacks, power outages, or the failure or disruption of a critical business service (including a service operated by a third party).
Within seven days of notification of a major event or unexpected disruption, the reporter must provide ASIC with a written report detailing the circumstances and steps taken to address the major event or unexpected disruption.
Unauthorized Access or Use. Market operators are also required to notify ASIC in writing as soon as reasonably practicable, but no later than 72 hours after becoming aware of any unauthorized access or use of their critical business services affecting their operations or resulting in unauthorized access or use market sensitive services, confidential or personal information.
Unexpected disruptions. Market operators are also required to notify ASIC immediately upon becoming aware of any unexpected disruption to the normal operation of a critical business service that could affect the fair, orderly or transparent operation of a market.
COMPARISON WITH APRA STANDARDS
Market participants may need to comply with both the rules and existing obligations in APRA Prudential Standards CPS 231 (Outsourcing), 232 (Business Continuity Management) and 234 (Information Security) where they are APRA-regulated entities (such as banks and insurance companies). Below we have provided a brief overview of some of the most important differences.
WHAT’S NEXT?
It will be important for market participants and operators to ensure that steps are taken to implement the new obligations under the rules in time for their entry into force on 10 March 2023.
ASIC has indicated that regulatory guides will be updated to provide guidance on the changes and expectations regarding their application in practice: notably Regulatory Guides 265 (Guide to ASIC Market Integrity Rules for Securities Market Participants), 266 (Guide to ASIC Market Integrity Rules for Participants). on futures markets) and 172 (financial markets: domestic and foreign operators).
Later this year, APRA plans to consult on enhanced operational risk management requirements (including minimum expectations for systems, controls and remediation, business continuity and third-party arrangements). The new Prudential Standard CPS 230 (Operational Risk Management) is intended to update and replace the existing requirements in CPS 231 and 232 and the corresponding pension standards. APRA anticipates that CPS 230 will come into effect in 2024.
Comments are closed.