Manila: The Securities and Exchange Commission (SEC) on Thursday announced its ongoing efforts to collect feedback from capital market participants on proposed policies concerning a cyber resilience framework. This initiative aligns with the government's aim to safeguard investors and ensure the stability of financial markets.
According to Philippines News Agency, the SEC released a draft memorandum for public comment on Wednesday. The proposal is part of the National Cybersecurity Plan 2023 to 2028, underscoring the importance of cybersecurity in maintaining peace, security, and economic growth.
The SEC detailed that the new framework would require regulated firms to define their cyber resilience goals and risk tolerance levels, along with strategies for identifying, mitigating, and managing cyber risks effectively. These firms will also need to oversee risks associated with cybersecurity threats and establish or appoint a Computer Emergency Response Team (CERT).
Additionally, companies will be mandated to create a chief information security officer (CISO) role, responsible for acting as the chief information officer and serving as the principal contact for the company's cybersecurity matters. The proposed policies emphasize that entities will remain accountable for the cybersecurity and resilience of the computer systems they depend on, regardless of whether those systems are managed by third parties.
In the event of a significant cyber incident, the SEC requires covered entities to report the nature, scope, and timing of the incident within five days. The report should also address any material or likely material impacts on the company's financial condition and operational results.