Currently, some sectors are already regulated (e.g. through a licensing regime) by statutory sector regulators ("regulators") and these regulators are well familiar with the operations and needs of the relevant sectors. As such, these regulators are specified as designated authorities under the Ordinance to regulate the discharging of organizational (Category 1) and preventive (Category 2) obligations by CI operators of these sectors. The Commissioner's Office will take charge of regulating the operators of all sectors in compliance of incident reporting and response (Category 3) obligations.

In this way, designated authorities may establish a set of standards and requirements on organizational and preventive obligations under the Ordinance that best suit the sectors' needs. Relevant operators need not duplicate efforts in fulfilling requirements of the Commissioner's Office separately for these two categories of obligations. Meanwhile, the Commissioner's Office can fully grasp the incident reporting and response arrangements of all operators for co-ordination, investigation and assistance, and to prevent the spread of the incident to other sectors.

The Monetary Authority and the Communications Authority are specified as designated authorities under the Ordinance. They are responsible for regulating operators currently under their regulation in the banking and financial services sector as well as the telecommunications and broadcasting services sector respectively.

In the aspect of Designated Authorities, the Monetary Authority is responsible for regulating CI operators in the banking and financial services sectors. It oversees the fulfillment of organizational (Category 1) and preventive (Category 2) obligations. The Communications Authority regulates operators in the telecommunications and broadcasting sectors with similar responsibilities. The incident reporting and response (Category 3) obligations of all sectors are centrally regulated by the Office of the Commissioner for Critical Infrastructure (Computer-system Security).

Functions and powers of designated authorities

For CI operators under their purview in the Ordinance:

#For details, please refer to the Protection of Critical Infrastructures (Computer Systems) Ordinance.