|
Manual of Regulations for BanksBSP
|
Banks and other BSP-supervised financial institutions within the applicable provisions |
Corporate governance, risk appetite, enterprise risk management, internal controls, compliance, internal audit, board reporting and tracked remediation. |
|
Source
|
|
Information Technology Risk Management StandardsBSP
|
BSP-supervised financial institutions within the standards’ scope |
Technology governance, cybersecurity, outsourcing, continuity, incident recording, escalation, recovery testing and independent assurance. |
|
Source
|
|
Code of Corporate Governance for Public Companies and Registered IssuersSEC
|
Public companies and registered issuers within the Code’s scope |
Board and committee accountability, risk oversight, internal-control review, internal audit, disclosure and corrective-action monitoring. |
|
Source
|
|
Data Privacy Act Implementing Rules and RegulationsNPC
|
Personal-information controllers and processors within scope |
Privacy governance, security measures, processor oversight, breach assessment, documentation, notification and remediation evidence. |
|
Source
|
|
Personal Data Breach Reporting ProceduresNPC
|
Personal-information controllers subject to breach-notification duties |
Breach recording, risk assessment, regulatory escalation, affected-person communication, root-cause analysis and corrective actions. |
|
Source
|
|
National Cybersecurity Plan 2023 to 2028DICT
|
Government, critical infrastructure and participating organisations across the national cyber ecosystem |
Cyber-risk governance, resilience, coordinated incident response, information sharing, capability assurance and service continuity. |
|
Source
|