ABA Position Paper on Promoting Cooperation in Cyber Security Management
Promoting Cooperation in Cyber Security Management
Introduction


Cyber Security Cooperations
(5.1) Introducing the Cybersecurity Fortification Initiative (“CFI”) to the banking industry – In collaboration with the banking industry, the Hong Kong Monetary Authority (“HKMA”) has introduced a three-pillar programme on cyber resilience framework, professional development and intelligence sharing since 2016i. The HKMA has also revampedii its cyber resilience framework in response to new security areas including cloud technology and virtualization, etc.
(5.2) Uplifting the cyber security services to critical infrastructure – In addition to the upgrade of Cyber Security and Technology Crime Bureau (“CSTCB”) by the Hong Kong Police Force (“HKPF”) in 2015iii, HKPF is committed to enhance the cyber security of critical infrastructure in Hong Kong since 2016 through proactive cyber security monitoring iv , cyber security drill v , communication channels on cyber security trend and dedicated security trainings for the industry practitionersvi.
(5.3) Establishing dedicated taskforces and working groups for various industries – Besides the Hong Kong Computer Emergency Response Team Coordination Centre (“HKCERT”) vii , multiple task forces and working groups have been established with active participation by industry leaders for each industry, especially for the banking industry, to streamline cyber-attack analysis and expand the cyber security defense frontier.
Cyber Security Information Sharing

Driving Innovation
Talent Development
(18.a) Uplifting the competency standards – While banks are looking for talents with appropriate cyber security skills, the HKMA had implemented the Enhanced Competency Framework on Cybersecurity (“ECF-C”) xiv in collaboration with the banking industry. The framework was designed and benchmarked against the Council of Registered Ethnical Security Testers (“CREST”), an international cybersecurity standard initiated by the CREST organisation in the United Kingdomxv.
(18.b) Enabling effective trainings – A Cyber Range facility has been established by the Hong Kong Applied Science and Technology Research Institute (“ASTRI”) in collaboration with the HKPF to provide cybersecurity training services to professionals from law enforcement agencies as well as the financial services industry since 2016xvi.
Conclusion
The presentation file can be downloaded HERE.

Eric Wong
Group Chief Information Officer
General Manager and Head of Technology and Productivity Division
The Bank of East Asia, Limited
References:
i Circular on Cybersecurity Fortification Initiative, Hong Kong Monetary Authority, 24 May 2016
https://www.hkma.gov.hk/media/eng/doc/key-information/guidelines-and-circular/2016/20160524e1.pdf
ii Circular on Cybersecurity Fortification Initiative 2.0, Hong Kong Monetary Authority, 3 Nov 2020
https://www.hkma.gov.hk/media/eng/doc/key-information/guidelines-and-circular/2020/20201103e1.pdf
iii LCQ22: Enhancing Cyber Security and Combating Technology Crimes, The Government of the HKSAR, 22
Nov 2017 https://www.info.gov.hk/gia/general/201711/22/P2017112200672.htm
iv LCQ19: Information Security in Hong Kong, The Government of the HKSAR, 14 Dec 2016
https://www.info.gov.hk/gia/general/201612/14/P2016121400637.htm
v Issues Relating to Protection of Personal Data and Cyber Security, Legislative Council, 14 Nov 2018
https://www.legco.gov.hk/yr18-19/english/panels/itb/papers/caitbse20181114cb2-222-3-e.pdf
vi Press Release – CSTCB hosts Online Service Providers Symposium, The Hong Kong Police Force, 17 Apr 2018
https://www.police.gov.hk/offbeat/1108/eng/6502.html
vii Hong Kong Computer Emergency Response Team Coordination Centre (HKCERT)
https://www.hkcert.org
viii Regulatory Keynote Speech – Balancing Innovation and Risk, Hong Kong Monetary Authority, 22 Mar 2019
https://www.hkma.gov.hk/media/eng/doc/key-information/speeches/s20190322e1.pdf
ix Update on Information Security, Legislative Council, 13 Jan 2020
https://www.legco.gov.hk/yr19-20/english/panels/itb/papers/itb20200113cb1-306-5-e.pdf
x Circular on Coronavirus disease (COVID-19) and Anti-Money Laundering and Counter- Financing of
Terrorism (AML/CFT) measures, Hong Kong Monetary Authority, 7 Apr 2020
https://www.hkma.gov.hk/media/eng/doc/key-information/guidelines-and-circular/2020/20200407e1.pdf
xi Report on “Artificial Intelligence in Banking: The Changing Landscape in Compliance and Supervision”,
Hong Kong Monetary Authority, 21 Aug 2020
https://www.hkma.gov.hk/eng/news-and-media/press-releases/2020/08/20200821-3/
xii Regtech Watch Issue No. 1, Hong Kong Monetary Authority, Nov 2019
https://www.hkma.gov.hk/media/eng/doc/key-information/guidelines-and-rcular/2019/20191112e1a1.pdf
xiii State of Cybersecurity 2020 – Part 1: Global Update on Workforce Efforts and Resources, Information
Systems Audit and Controls Association, https://www.isaca.org/go/state-of-cybersecurity-2020
xiv Circular on Enhanced Competency Framework on Cybersecurity, Hong Kong Monetary Authority, 19 Dec
2016 https://www.hkma.gov.hk/media/eng/doc/key-information/guidelines-andcircular/
2016/20161219e1.pdf
xv Cybersecurity Advancement Programme for Banking Industry in Hong Kong, The Hong Kon Institute of
Bankers, 15 Apr 2019 http://www.hkib.org/storage/files/65/HKIB_report20190601.pdf
xvi Cyber Range Overview, Hong Kong Applied Science and Technology Research Institute
https://www.astri.org/technologies/joint-research-laboratories/rd-centres/cyber-range