South Korea's FSC Mandates Financial Firms' Boards to Assume Final Responsibility for Third-Party IT Security Breaches

According to South Korea's Financial Supervisory Service (FSC), on July 29, financial institutions' boards of directors and management must assume final responsibility for cybersecurity incidents and data breaches occurring at external IT service providers they contract with.

The FSC established the guideline to manage third-party IT risks more effectively as financial firms increasingly outsource IT operations due to digitalization. Under the framework, financial companies must establish a three-tier control system comprising an oversight department, risk management department, and internal audit department. The board will oversee third-party IT risk management policies, while management must build and maintain the risk management system and conduct ongoing assessments of outsourced IT contracts and service provider financial stability.

Disclaimer: The information on this page may come from third-party sources and is for reference only. It does not represent the views or opinions of Gate and does not constitute any financial, investment, or legal advice. Virtual asset trading involves high risk. Please do not rely solely on the information on this page when making decisions. For details, see the Disclaimer.
Comment
0/400
No comments