Results of Public Comments on Proposed Supervisory Guideline Revisions
Overview
The Financial Services Agency published the results of public comments and other information concerning the proposed partial revisions to the Comprehensive Supervisory Guidelines for Major Banks and Others. Following the revision on September 15, Reiwa 8, of the Agreement on Reporting Procedures, etc. When Damage Occurs from a Cyberattack, the Other Cyberattack and Similar Incident Common Form was newly established. The revised supervisory guidelines and other materials will apply from October 1, Reiwa 8.
Key points
- The existing reporting forms for cyberattacks and similar incidents will be replaced by common forms based on an agreement among the relevant ministries and agencies.
- A total of 7 comments related to the proposed partial revisions were submitted during the public comment period.
- The revised supervisory guidelines and other materials will apply from October 1, Reiwa 8.
- The common forms and supplementary information on their use are provided through related links for businesses in the financial sector.
Overview
The Financial Services Agency solicited comments on the proposed partial revisions to the Comprehensive Supervisory Guidelines for Major Banks and Others from August 7 to September 7, Reiwa 8, and published an overview of the relevant comments and the agency's views.
The background is that, on September 15, Reiwa 8, the Agreement on Reporting Procedures, etc. When Damage Occurs from a Cyberattack was revised, and the Other Cyberattack and Similar Incident Common Form was established in addition to the existing DDoS Attack Incident Common Form and Ransomware Incident Common Form.
Impact
As a result of the revisions to the supervisory guidelines and other materials, the forms used to report computer system failures and cybersecurity incidents to the supervisory authorities will be replaced by common forms based on an agreement among the relevant ministries and agencies.
Details
The common forms consist of three types: the DDoS Attack Incident Common Form, the Ransomware Incident Common Form, and the Other Cyberattack and Similar Incident Common Form. For businesses in the financial sector, the Financial Services Agency provides the common forms and supplementary information on their use through related links, including the correspondence between items in the old and new forms. The revisions are included in Appendices 2 to 18 and cover the supervisory guidelines and administrative procedure guidelines for major banks, small and regional financial institutions, insurance companies, financial instruments business operators, and other entities.
The revised supervisory guidelines and other materials will apply from October 1, Reiwa 8. Comments that are not directly related to this matter will be used as a reference for future financial administration.