- Purpose / Background: This document provides standardized notification templates for Authorized Institutions (AIs) designated as Critical Infrastructure (CI) operators under the *Protection of Critical Infrastructures (Computer Systems) Ordinance*. It facilitates mandatory regulatory reporting to the Monetary Authority (MA).
- One-line conclusion: Designated AIs must use these prescribed forms to report operational changes, security management appointments, and material changes to computer systems via secure ICLNet email.
- Key Changes:
- Standardized notification templates for three specific regulatory triggers: Operator Changes (s.20), Appointment of Security Unit Supervisors (s.21), and Material Changes to Critical Computer Systems (s.22).
- Formalized requirement for cross-copying the Technology Risk Team and Case Management Team at the HKMA.
- Mandatory requirement to attach documentary evidence for personnel appointments and risk assessment documentation for system changes.
- Implementation of a formal "Declaration" section requiring sign-off by the supervisor of the computer-system security management unit.
- Key Dates / Deadlines: Submissions must be made within the specific statutory timeframes stipulated under sections 20(1), 21(4/6), and 22(1) of the Ordinance.
- Applicability / Impact scope: All Authorized Institutions (AIs) designated by the MA as operators of critical computer systems.
- Recommended management actions:
- Update internal compliance workflows to incorporate these specific forms for all statutory notifications.
- Ensure the "supervisor of the computer-system security management unit" is clearly identified and authorized to validate these filings.
- Establish a secure communication channel via ICLNet for all regulatory filings directed to
pcicso_ai@hkma.iclnet.hk. - Integrate the requirement for accompanying risk assessment documentation and system updates into the change management lifecycle.
- Map internal reporting triggers to the specific sections of the Ordinance to ensure adherence to statutory deadlines.
1) Document Overview
The document serves as the official template suite for Designated AIs to fulfill their notification obligations under the *Protection of Critical Infrastructures (Computer Systems) Ordinance*. It ensures uniformity in data collection for critical oversight functions.
2) Main Requirements
- Submission Protocol: All forms must be submitted via ICLNet secure email to
pcicso_ai@hkma.iclnet.hk. - Copying Recipients: Submissions must be copied to the AI’s usual supervisory contact, the Technology Risk Team, and the Case Management Team.
- Verification: Every form requires a declaration confirming the information is valid and reviewed by the supervisor of the computer-system security management unit.
3) Key Notification Areas
- Operator Change (s.20): Reports changes such as M&A, disposal of business, or restructuring, including impact assessments on essential services.
- Security Supervisor Appointment (s.21): Reports the identity, qualifications, and experience of the employee supervising the security management unit (documentary proof required).
- Material Changes (s.22): Details changes to the design, configuration, or security of Critical Computer Systems (CCS), including platform migrations, major upgrades, or integration changes.
4) Important Dates & Transition
Submissions are triggered by the events defined in the Ordinance. AIs must adhere to the specific notification windows stated in sections 20, 21, and 22 of the Ordinance.
5) Impact and Risks
- Operational: Increased administrative burden for managing documentation during system updates.
- Compliance: High risk of non-compliance if statutory timelines are missed; requires strict alignment between IT change management and the Compliance/Legal departments.
- Data/Reporting: Requires maintenance of updated system documentation to support submissions.
6) Compliance Action Checklist
- [ ] Configure ICLNet accounts for secure submission.
- [ ] Maintain a repository of "documentary proof" for security personnel appointments.
- [ ] Align internal IT Change Management processes with the "Material Change" criteria (Section B, Form 3).
- [ ] Brief the "supervisor of the computer-system security management unit" on their new declaration responsibilities.
7) Appendices/Attachments Summary
The document consists of three specific reporting templates:
- Form for Notifying an Operator Change: Captures business structural changes and their impact on essential services.
- Form for Notifying Appointment of Employee Supervising Computer-System Security Management Unit: Collects professional credentials and experience for key security personnel.
- Form for Notifying Material Changes to Certain Computer Systems: Details technical modifications to CCS, requiring supporting risk assessments and updated system documentation.