
February 21, 2023
The Financial Services Regulatory Authority (FSRA) has published proposed guidance on information technology (IT) risk management including managing threats to IT systems, infrastructure and data. This guidance first covers FSRA’s expectations for all sectors, and includes FSRA’s interpretation of existing regulatory requirements, information on practices for effective IT risk management, and an approach for notifying FSRA of material IT risk incidents. Most notably are FSRA’s seven practices for effective IT risk management, and a three-phase protocol for responding to IT risk incidents.
The guidance then provides sector specific expectations by FSRA, and reminds pension plan administrators that they are subject to both a common law fiduciary duty, and the Pension Benefits Act.
You can find more details by clicking on more information below: