Code of Practice Pursuant to the Protection of Critical Infrastructures (Computer Systems) Ordinance (for Authorized Institutions designated by the Monetary Authority as Critical Infrastructure Operators) (2026-05-28)

Code of Practice Email: HKMA E-mail Alert of 03 June 2026 (05:00 p.m. HKT)

Document Information

Title: Code of Practice Pursuant to the Protection of Critical Infrastructures (Computer Systems) Ordinance (for Authorized Institutions designated by the Monetary Authority as Critical Infrastructure Operators) (2026-05-28)

Type: Code of Practice

URL: https://brdr.hkma.gov.hk/eng/doc-ldg/current/20260527-25-EN

Email Received: 2026-06-03 19:11

Summary Created: 2026-06-03 14:00

English Summary
Quick section switch
Management Summary
  • Purpose / Background: This Code of Practice (CoP) provides regulatory guidance for Authorized Institutions (AIs) designated by the HKMA as "Critical Infrastructure Operators" under the *Protection of Critical Infrastructures (Computer Systems) Ordinance*. It defines baseline security requirements for protecting Critical Computer Systems (CCSs) to ensure the stability and resilience of the banking and financial sector.
  • One-line conclusion: Designated AIs must align their cybersecurity frameworks with this CoP, specifically establishing formal management plans, performing mandated risk assessments, and conducting independent security audits for all designated CCSs.
  • Key Changes:
  • Formalizes the designation process for CCSs based on material impact, data sensitivity, and interdependencies.
  • Mandates the establishment of a dedicated "Computer-System Security Management Unit."
  • Requires Board-level (or senior management) endorsement of security management plans, reviewed at least every two years.
  • Standardizes requirements for incident monitoring, log retention (min. 6 months), and secure tertiary data backups.
  • Enforces rigorous vulnerability assessments and penetration testing conducted by qualified professionals.
  • Requires systematic management of supply chain and cloud-based risks.
  • Key Dates / Deadlines: Effective date is 2 June 2026. Ongoing compliance obligations (e.g., biennial plan reviews, annual privilege reviews) commence immediately upon designation.
  • Applicability / Impact scope: All Authorized Institutions (AIs) designated by the Monetary Authority as Critical Infrastructure Operators.
  • Recommended management actions:
  • Conduct a formal gap analysis between current IT security policies and the requirements in Sections 5 and 6.
  • Formally designate a "Computer-System Security Management Unit" with appropriately qualified personnel.
  • Establish a process for "material change" notifications for CCSs to the HKMA.
  • Implement/update the Computer-System Security Management Plan with Board-level approval.
  • Initiate a schedule for regular vulnerability assessments and penetration tests.
  • Enhance supply chain and cloud risk management frameworks in line with HKMA circulars and C-RAF maturity standards.
Detailed Summary
  1. Document overview: This CoP operationalizes the *Protection of Critical Infrastructures (Computer Systems) Ordinance*. It sets baseline security expectations for CCSs, focusing on availability, confidentiality, and integrity, while noting that these requirements do not override, but complement, existing HKMA Supervisory Policy Manual (SPM) guidance.
  1. Main requirements:
  • Governance: Maintenance of an office in HK and a dedicated security management unit.
  • Security Management Plan: Must cover all aspects of Schedule 3 of the Ordinance, including asset management, access control, and physical security.
  • Operational Controls:
  • Access: Strong password management and privileged access controls.
  • Technical: Required encryption (at-rest/in-transit/in-use) and system hardening.
  • Resilience: Secure tertiary data backup (STDB) and off-site storage.
  • Monitoring: 6-month log retention for security incidents and active threat intelligence monitoring.
  • Risk & Audit: Annual and event-based risk assessments (vulnerability scans/penetration tests) and independent security audits.
  1. Key changes: Increased emphasis on formalizing risk-based "material change" notifications and moving beyond general cybersecurity standards toward specific, auditable compliance targets aligned with the C-RAF (Cyber Resilience Assessment Framework) maturity matrix.
  1. Important dates & transition: Document is effective from 2 June 2026. While no specific "grace period" for existing systems is listed, reporting and plan submissions must align with the Ordinance's statutory timelines once a designation is received.
  1. Impact and risks: Operational impact includes increased compliance reporting, requirement for independent audit verification, and necessary infrastructure upgrades to meet specific backup and encryption standards. Non-compliance may lead to HKMA written directions; failure to comply with these constitutes an offence.
  1. Compliance action checklist:
  • [ ] Map all current CCSs against the 3.1.3 designation criteria.
  • [ ] Appoint a supervisor for the Computer-System Security Management Unit.
  • [ ] Implement/Review log management to ensure 6-month retention.
  • [ ] Update Change Management process to flag "material changes" for HKMA notification.
  • [ ] Schedule penetration tests and vulnerability assessments for all CCS-related hosts/applications.
  • [ ] Secure Board/Executive approval for the comprehensive security management plan.
  1. Appendices/attachments summary:
  • The document does not contain traditional appendices; however, the body references the C-RAF Maturity Assessment Matrix and SPM TM-G-1/G-2 extensively as the compliance standard. These references act as the technical "benchmarks" for the requirements stipulated in Section 6.
中文摘要
快速切換摘要區塊
管理層摘要
  • 目的/背景 本守則依據《保護關鍵基礎設施(電腦系統)條例》發布,旨在為被香港金融管理局(HKMA)指定為「關鍵基礎設施營運者(CIO)」的認可機構(AI),提供保護「關鍵電腦系統(CCS)」的實務指引,建立安全基準。
  • 一句話結論 被指定為關鍵基礎設施營運者的機構必須建立並嚴格執行電腦系統安全管理計畫,透過風險評估、定期審計及落實多項具體安全控制措施(如存取管理、密碼技術、供應鏈安全等),以確保其關鍵電腦系統的安全性與韌性。
  • 關鍵變更
  1. 明確了關鍵電腦系統(CCS)的認定標準(與核心功能關聯性、受損嚴重性、敏感數據處理等)。
  2. 義務分層: 區分為第 1 類義務(機構營運與通知)與第 2 類義務(安全管理計畫、風險評估與審計)。
  3. 強制安全計畫: 必須制定、實施並經董事會或高層批准電腦系統安全管理計畫。
  4. 具體合規門檻: 新增對存取控制、密碼管理、備份恢復(含離線備份)、供應鏈風險管理等領域的具體要求。
  5. 強制風險評估與審計: 必須進行包含弱點掃描及滲透測試的風險評估,並安排獨立的系統安全審計。
  • 重要日期 / 截止日 本文件於 2026 年 6 月 2 日發布。具體實施細節與截止日需參考《條例》及日後發布之合規通知;相關計畫需至少每兩年審查一次。
  • 適用對象 / 影響範圍 由香港金管局指定之認可機構(Designated AIs)。
  • 管理層建議行動
  1. 識別與清點 主動與 HKMA 進行雙邊對接,界定及清點受規管的關鍵電腦系統(CCS)。
  2. 高層授權 確保電腦系統安全管理計畫經董事會或其授權委員會批准。
  3. 建立安全單位 任命具備專業證照(如 CISA, CISSP)的專職人員監督安全管理單元。
  4. 落實審計與測試 建立包含弱點掃描與滲透測試的風險評估機制,並委任第三方進行安全審計。
  5. 供應鏈風險盤點 審視第三方服務供應商(TSP)對關鍵系統的存取與潛在風險,降低對單一供應商的過度依賴。
詳細摘要

1) 文檔概述
本守則為《保護關鍵基礎設施(電腦系統)條例》下的行業守則,適用於受 HKMA 指定的認可機構。其目的在於提供實務指導,使機構能符合第 1 類(行政/管理)與第 2 類(系統技術防護)義務。

2) 主要要求

  • 營運義務 需維持在港辦公室(需通知 HKMA 地址變更)、報告營運者變更、設立專責的電腦系統安全管理單元(人員無需駐港,但需具備適當資格)。
  • 安全管理計畫 必須制定一套包含政策、標準與準則的書面計畫,並定期(至少每兩年)審查。若無法達成特定要求,需有經記錄的替代補償性措施。
  • 技術控制要求 涵蓋存取控制(含特權帳戶)、密碼技術、物理安全、組態管理(最小權限原則)、變更管理、修補程式管理、遠端連線安全、儲存媒體銷毀、備份(需確保離線備份/STDB)、網路與應用程式安全、日誌管理(保留期至少 6 個月)。
  • 供應鏈管理 需評估地緣政治風險及單一供應商依賴風險。

3) 關鍵變更
本守則對標 HKMA 的《網絡韌性評估架構(C-RAF)》,將既有的監管期望轉化為《條例》下的法律合規義務,特別強化了對「關鍵電腦系統」物理與邏輯邊界的定義,以及對滲透測試與離線備份的具體硬性要求。

4) 重要日期與過渡安排
生效日期為 2026 年 6 月 2 日。條文中的「指定電腦系統」及「材料變更」通知均需遵照 HKMA 指定格式進行。

5) 對機構的影響與風險

  • 合規風險 未經許可或未妥善保護 CCS 可能面臨《條例》下的刑事責任。
  • 營運影響 須調整採購流程(供應鏈管理)及系統架構(物理/邏輯隔離、數據備份)。
  • 資源投入 需增加對安全專業人員的招聘與培訓開支。

6) 合規動作清單(Checklist)

  • [ ] 完成 CCS 清單核對,並經內部評估確認。
  • [ ] 委任合資格人員(CISA/CISSP 等)擔任管理單元負責人。
  • [ ] 撰寫電腦系統安全管理計畫,並由董事會簽署確認。
  • [ ] 執行年度弱點掃描與滲透測試,並編制風險處理計畫。
  • [ ] 確保關鍵日誌保留紀錄長達 6 個月,且具防竄改功能。
  • [ ] 檢查備份系統,確保至少有一份離線物理備份。

7) 附件/附錄摘要
本文不含特定附錄,但第 6 章大量引用《監督政策手冊(SPM)》中的 TM-G-1 及 TM-G-2 模組,機構必須同時參考上述手冊以確保技術控制細節達標。此外,C-RAF 成熟度矩陣被設為執行上述要求的基準指標。