OSFI Guideline B-13, Technology and Cyber Risk Management
OSFI Guideline B-13, Technology and Cyber Risk Management
Guidance, not a law: the Office of the Superintendent of Financial Institutions's reading of Prudential supervision of banks: the Office's objects and the Superintendent's directions to a bank. It binds nobody by itself; the law it reads does.
Guidance on a sector security regimes rule, addressed to private bodies.
- Criminal exposure
- No
- Instrument type
- guidance published by a regulator
- Obligation class
- Security, Governance
As of .
What the regulator expects
- It reaches you if you operate as a federally regulated financial institution (FRFI): a bank, foreign bank branch, foreign insurance company branch, life insurance or fraternal company, property and casualty company, or trust and loan company, with branches covered to the extent the guideline is consistent with your obligations in Canada. It applies from a risk-based perspective, and every line below states what OSFI expects.
- Assign responsibility for technology and cyber risk to senior officers, with an organizational structure, resources and training suited to managing that risk across the institution.
- Define, document, approve and implement a strategic technology and cyber plan aligned to your business strategy, and establish a technology and cyber risk management framework that sets a risk appetite and defines how technology and cyber risks are identified, assessed, managed, monitored and reported.
- Maintain an updated inventory of the technology assets that support business processes or functions, which may include third-party assets that store or process your information or provide critical business services, and classify the assets by criticality.
- Implement a system development life cycle framework for the secure development, acquisition and maintenance of technology systems, with security risk assessments for acquired software and systems and coding principles that cover the use of third-party and open-source code.
- Apply patches in a controlled and timely way across your technology environment to address vulnerabilities and flaws.
- Detect, log, manage, resolve, monitor and report on technology incidents, and minimize their impact.
- Establish and maintain an enterprise disaster recovery program, and validate it against severe but plausible scenarios that test your backup and recovery capabilities and critical third-party technologies and integration points.
- Maintain practices, capabilities, processes and tools to identify and assess cyber security weaknesses that external and insider threat actors could exploit, and design, implement and maintain multi-layer preventive controls and continuous security detection capabilities.
- Implement approved, risk-based security configuration baselines for technology assets and security defense tools, including those provided by third parties.
- Respond to, contain, recover from and learn from cyber security incidents affecting your technology assets, including incidents that originate at third-party providers.
Who enforces it
Enforcement body
Office of the Superintendent of Financial Institutions, which supervises financial institutions to make sure they are following its guidance.
What this law does
Guideline B-13 sets out OSFI's expectations for the sound management of technology and cyber risk by federally regulated financial institutions. OSFI released the final Guideline B-13 on . OSFI set as the date the guideline is effective.
The guideline is applicable to all federally regulated financial institutions, including foreign bank branches and foreign insurance company branches, to the extent it is consistent with applicable requirements and legal obligations related to their business in Canada. OSFI's guidance library lists the sectors the guideline reaches as banks, foreign bank branches, foreign insurance branches, life insurance and fraternal companies, property and casualty companies, and trust and loan companies.
The guideline is organized around three domains: governance and risk management, technology operations and resilience, and cyber security. The guideline says a technology asset inventory may include third-party assets that store or process institution information or provide critical business services. For software and systems that are acquired, the guideline says institutions should ensure that security risk assessments are conducted.
The guideline says institutions should define coding principles and best practices that cover the use of third-party and open-source code. It says disaster recovery scenarios should test critical third-party technologies and integration points with upstream and downstream dependencies, including both on- and off-premises technology.
It says institutions should implement approved, risk-based security configuration baselines for technology assets and security defense tools, including those provided by third parties. Principle 17 says institutions should respond to, contain, recover and learn from cyber security incidents impacting their technology assets, including incidents originating at third-party providers. The guideline lists Guideline B-10 among the OSFI guidance an institution should read alongside it.
OSFI describes its guidelines as outlining expectations for financial institutions. OSFI says it uses its guidance as a basis for its supervision.