2018-02-06

Added · Updated

Central Bank of Jordan Cyber Resilience Instructions

The Central Bank of Jordan issued the Cyber Resilience Instructions, effective twelve months after publication, mandating licensed banks, financial institutions, credit information companies, and microfinance companies to implement comprehensive cyber security governance, risk management, and protective controls. The regulations require entities to establish a Cyber Security Program and Policy, appoint an independent Chief Information Security Officer, maintain a Cyber Risk Register, and enforce strict access controls including multi-factor authentication and network segmentation. Additionally, the instructions impose obligations for continuous risk assessment, incident detection and response, disaster recovery planning, and the secure management of third-party outsourcing and physical security.

Central Bank of Jordan logo

Jordan

Central Bank of Jordan

Click to view thumbnail

Number: 1/1/26/1984 Date: 6/2/2018 Corresponding to: 20 Jumada al-Awwal 1439

[Logo of the Central Bank of Jordan]

Central Bank of Jordan

Cyber Resilience Instructions


Table of Contents

  • Chapter One: Legal Basis, Scope of Application, and Definitions
  • Chapter Two:
    • First: Cyber Security Governance
    • Second: Cyber Security Program and Policy
  • Chapter Three: Cyber Risk Management
    • First: Identification of Critical Operations and Supporting Information Assets in the Company
    • Second: Cyber Risk Assessment
  • Chapter Four: Protective Controls
    • First: Protection of Systems, Software, Networks, and Network Devices
    • Second: E-mail Specific Protective Controls
    • Third: Records
  • Chapter Five: Cyber Incident Detection
  • Chapter Six: Emergency Cyber Incident Response and Recovery
  • Chapter Seven: Testing
  • Chapter Eight: Outsourcing
  • Chapter Nine:
    • First: Training and Awareness
    • Second: Exchange of Cyber Incident Information
  • Chapter Ten: General Provisions

Chapter One

Legal Basis, Scope of Application, and Definitions

Article (1): These Instructions are issued pursuant to the provisions of Articles (4/b/3 and 4) and Articles (50/c, 65/b) of the Central Bank of Jordan Law No. (23) of 1971 and its amendments, Article (99/b) of the Banks Law No. 28 of 2000 and its amendments, and Article (22/b) of the Electronic Transactions Law No. (15) of 2015 and its amendments, and shall become effective twelve months from their date, unless otherwise specified.

Article (2): These Instructions shall be known as the "Cyber Resilience Instructions."

Article (3): a. These Instructions shall apply to all licensed banks, financial institutions, credit information companies, and microfinance companies subject to the supervision and oversight of the Central Bank of Jordan. b. Branches of foreign banks operating in the Kingdom shall comply with these Instructions to the extent applicable to them, or with the IT governance and management policies and procedures accompanying them issued by the parent bank or the home country supervisory authority, whichever better achieves the objectives of these Instructions. In the event that the Instructions issued by the parent bank or the home country supervisory authority better achieve the objectives of the Instructions, the branch must provide evidence thereof to the Central Bank. In case of any conflict, the branch must inform the Central Bank and the parent company, provide the necessary clarification regarding such conflict, and obtain the Central Bank's approval on the method of addressing this conflict.

Article (4): The Bank shall consider all provisions contained in the IT Governance and Management Instructions No. (65/2016) dated 25/10/2016 when applying these Instructions, and in particular those related to IT security and risk management, reading them together as an integrated whole. The financial institution, credit information company, and microfinance company shall apply the aforementioned Instructions to the extent that they align with and satisfy these Instructions.

Article (5): a. The following words and phrases shall have the meanings assigned to them below wherever they appear in these Instructions, unless the context indicates otherwise:

Financial InstitutionAny public or private joint-stock company licensed to provide payment services or manage and operate electronic payment systems.
Credit Information CompanyThe company licensed in accordance with the provisions of the Credit Information Law No. (15) of 2010 and the regulation issued pursuant thereto.
Microfinance CompanyThe financial company that conducts microfinance activities and is licensed in accordance with the provisions of the Microfinance Companies System No. (5) of 2015.
CompanyThe Bank, Islamic Bank, Financial Institution, Credit Information Company, or Microfinance Company.
BoardThe Board of Directors of the Company and those in its stead.
Senior Executive ManagementIncludes the General Manager of the Company or Regional Director, Deputy General Manager or Deputy Regional Director, Assistant General Manager or Assistant Regional Director, Chief Financial Officer, Operations Director, Risk Management Director, Treasury (Investment) Director, Compliance Director, as well as any employee in the Company who holds executive authority parallel to any of the aforementioned and is functionally linked directly to the General Manager.
Information and Communications Technology (ICT) EnvironmentThe set of computer equipment specific to internal and external networks, main servers, and the software running on them, and all supporting devices at the Company's main and backup sites.
InformationAny oral or written data, records, statistics, written or visual documents, or records or stored electronically or by any other method that has value to the Company.
DataRaw facts that can be illustrated by letters, symbols, and numbers that may represent people, objects, or events.
Information AssetsAny information or electronic or non-electronic files, devices, storage media, software, or any components of the ICT environment related to the Company's business.
CyberspaceA virtual environment consisting of the interaction of people, software, and services on the Internet through devices and connected technology networks.
Cyber AttackAny attempt to destroy, disclose, change, disrupt, or steal, or attempt to exploit vulnerabilities or gain unauthorized access to the Company's information assets within cyberspace.
Cyber ResilienceThe Company's ability to anticipate, withstand, contain, and recover quickly from a cyber attack.
Cyber SecurityMaintaining the confidentiality, integrity, and availability of the Company's information and information assets within cyberspace from any cyber threat through a set of means, policies, instructions, and best practices in this regard.
Cyber ThreatA circumstance or event that may exploit (intentionally or unintentionally) one or more vulnerabilities existing in the Company's ICT environment, thereby affecting its cyber security.
Cyber EventAny incident indicating the presence of a cyber threat to the Company's ICT environment.
Cyber RiskA composite measure resulting from calculating the probability of a cyber event occurring within the scope of the Company's information assets, and the impact of that event on the Company.
Cyber GovernanceThe Company's arrangements for establishing, implementing, and reviewing its approach to managing cyber risks.
Data GovernanceThe process of managing the availability, security, ease of use, and integrity of data used in the Company.
Malicious CodeSoftware or malicious files that include functions with capabilities that negatively affect, directly or indirectly, the ICT environment used in the Company.
ProtectionThe deployment of appropriate procedures, controls, and measures to provide the Company's services and business reliably.
DetectionThe deployment of appropriate controls and procedures to be aware of the occurrence of a cyber event immediately.
ResponseThe deployment of appropriate controls and procedures to contain a cyber event upon its detection.
RestoreThe process of retrieving information stored on backup media when original information is damaged, lost, or needed after a period of time to resume the Company's business operations.
RecoveryA set of measures taken and followed to return the Company's business to its normal state and restart the technology resources relied upon to operate the Company's processes to their state prior to the occurrence of the event.
VulnerabilitiesA flaw or deficiency in the protective controls used in any components of the ICT environment related to the Company's business that can be exploited in cyber intrusion and attack operations.
Access ControlThe rules and mechanisms used to allow only authorized persons to use and access information assets in accordance with the nature of their responsibilities in the Company.
PrivilegesThe level of permissions granted to users to access/use and utilize any components of the ICT environment in the Company.
Change ManagementThe management, control, and documentation of any change made to any components of the ICT environment in the Company or any change in the procedures implemented in the Company by authorized parties.
Information ClassificationDetermining the appropriate sensitivity level for information that is created, changed, transferred, modified, or saved on any media and using any possible technology, based on the risks resulting from unauthorized access to and use of that information.
ConfidentialityProtecting information from unauthorized access, publication, disclosure, and use.
AvailabilityThe ability to use, access, and retrieve information and systems in the Company upon request.
IntegrityThe accuracy, completeness, and integrity of information or information systems or any part thereof, and verifying that no unauthorized increase, decrease, or change has occurred to them.
Recovery Time Objective (RTO)The maximum allowed time to restart a service or process after an IT service interruption occurs.
Recovery Point Objective (RPO)The maximum allowed age of data that may be lost when restoring service after an interruption.
Cyber Risk ManagementProcesses for identifying, measuring, controlling, and monitoring cyber risks.
Critical OperationsOperations that cannot tolerate long periods of downtime according to business impact analysis studies in the Company, and those operations with relative risk and importance to the Company.
E-mailThe service that can be provided to users to create, send, receive, and store electronic messages using electronic communication systems.
EncryptionThe process of converting information into an unreadable or incomprehensible form.
Third PartyThe entity to which the Company entrusts technical and operational activities wholly or partially to assist it in performing its licensed activities in a manner that does not conflict with the provisions of prevailing legislation.
OutsourcingEngaging a third party or utilizing its resources to manage the Company's business or part of its business that falls within its responsibility.
Physical SecurityProtection standards and procedures that monitor or determine entry to any of the Company's facilities, resources, or information stored on physical media, or to prevent access to information resources and systems, such as buildings, file cabinets, desktop and portable devices, servers, and equipment.
StakeholdersAny interested party in the Company such as shareholders, employees, creditors, customers, external suppliers, or relevant regulatory authorities.
Event logData files of security and operational events produced by system components to understand system activity and diagnose problems that may occur on it.
Audit TrailData files that provide documentary evidence of the sequence of functional and administrative operations occurring on systems.
Risk AssessmentMeasuring and determining the probability and severity of risks and predicting their impact on the Company.
Penetration TestingA test in which specialized evaluators attempt to find security vulnerabilities and bypass security features of information systems and security controls, and exploit them to attempt to breach those systems from outside or inside the Company to determine the effectiveness of the security controls used by the Company to protect its systems.
Remote AccessEnabling connection with the Company's systems from outside its internal network, whether for the purpose of enabling its employees to work remotely, securing connection with business partners, or by a third party.

b. The definitions contained in the Central Bank Law, Electronic Transactions Law, Banks Law, and any related instructions issued by the Central Bank shall be relied upon wherever the text refers to them in these Instructions, unless the context indicates otherwise.


Chapter Two

First: Cyber Security Governance

Article (6): The Company shall comply with the following: a. The Board of Directors, including its delegated committees and Senior Executive Management, shall include individuals possessing the appropriate skills and knowledge to understand and manage cyber risks. b. The Board or its delegated committees shall assume the following responsibilities and tasks, each according to its position:

  1. Approving the Cyber Security Policy.
  2. Approving the Cyber Security Program.
  3. Reviewing compliance with the Cyber Security Policy and Program. c. Senior Executive Management shall assume the following responsibilities and tasks, each according to its position:
  4. Ensuring the implementation and updating of the Cyber Security Policy.
  5. Ensuring the implementation of the Cyber Security Program so that it is integrated with the general framework of IT risk management, and continuing to update and develop it.
  6. Ensuring the existence of a comprehensive Cyber Risk Register and ensuring its continuous updating so that it is compatible with the Company's IT Risk Profile.
  7. Continuously monitoring the level of cyber risks.
  8. Approving the lists of responsibilities related to cyber security and risk management in terms of identifying the entity or entities or person or parties primarily responsible (Responsible), those consulted (Consulted), and those to be informed (Informed) for all processes of managing and controlling those risks, oversight, and auditing.

Second: Cyber Security Program and Policy

Article (7): The Company shall implement and continuously update the Cyber Security Program to ensure the achievement of confidentiality, integrity, and availability requirements for information in the ICT environment. The Program shall include, at a minimum, the following: a. Identifying internal and external threats to cyber risks. b. Identifying and classifying risks and information sensitivity in the ICT environment. c. Identifying entities with the ability to access and use information and the ICT environment. d. Implementing cyber security policies and procedures and operating the necessary ICT environment to ensure the protection of the Company's information assets and sensitive information from unauthorized intrusion. e. Detecting successful and failed unauthorized intrusion attempts immediately upon occurrence, if possible. f. Taking necessary corrective measures to control and mitigate the negative effects of cyber risks. g. Procedures for restarting the Company's operations after their interruption, including those related to services and legal and regulatory requirements during the acceptable and specified time period within the business continuity plan, in accordance with Article (32/g) of these Instructions.

Article (8): The Cyber Security Policy must be a document dedicated to cyber security in the Company. When preparing and updating the policy, all relevant parties shall be considered, and international best practices and their updates shall be adopted as references and lessons learned from cyber security incidents. The Company may include the Cyber Security Policy within the Information Security Policy under the title "Information Security and Cyber Security Policy," and may include Cyber Security Programs within the Information Security Program, provided that all provisions of these Instructions are achieved.

Article (9): The Cyber Security Policy must include, at a minimum, the following axes: a. Identifying roles and responsibilities, including the responsibility for decision-making within the Company regarding cyber risk management, including emergency and crisis situations. b. Data governance and classification. c. Security and management of information and the Company's ICT environment. d. Customer data privacy. e. Cyber risk management. f. Protective controls to mitigate and control cyber risks. g. Business continuity and disaster recovery plans. h. Cooperation with relevant parties to effectively respond to cyber attacks and recover from them. i. Monitoring, securing, and developing systems, networks, and applications. j. Physical and environmental security controls. k. Management of outsourced third-party operations. l. Employee awareness and training within the Company regarding cyber security to ensure all employees in the Company apply all provisions of the Cyber Security Policy. m. Identifying the mechanism for disclosing the provisions of the Cyber Security Policy to relevant parties according to their role. n. Identifying the owning entity, scope of application, frequency of review and update, access and distribution rights, objectives, responsibilities, related work procedures, penalties for non-compliance, and compliance review mechanisms.

Article (10): The Company must manage information security related to cyber security through a Chief Information Security Officer (CISO) who does not administratively report to the IT department, enjoys independence, and ensures no conflict of interest. The CISO must have the necessary practical experience and professional knowledge to be responsible for the following tasks at a minimum: a. Directly supervising the development of the Cyber Security Program and Policy, ensuring their implementation, and working on reviewing and updating them continuously. b. Evaluating the adequacy and efficiency of the Cyber Security Program and Policy. c. Continuously reviewing the effectiveness of the protective controls adopted in the Company's Cyber Security Policy. d. Identifying and evaluating cyber risks. e. Submitting semi-annual reports or whenever necessary to the Board and Senior Executive Management regarding cyber security in the Company. The report must include, at a minimum:

  1. Deviations related to the implementation of the Cyber Security Policy and its procedures.
  2. Results of cyber risk assessments.
  3. Results of the evaluation of the adequacy and efficiency of the Cyber Security Program and Policy.
  4. Recommendations, procedures, and requirements to be implemented.
  5. A summary reviewing the most important cyber threat and intrusion events the Company has been exposed to during the reporting period.

Article (11): Notwithstanding the provisions of Article (10) above, the Company has the right to outsource the tasks of information security management or part thereof to a third party, provided it complies with the following: a. Requesting the third party to comply with what meets the Instructions' requirements regarding information security management. b. Reviewing the third party's compliance with the Instructions' requirements regarding information security management.

Article (12): The Company must, before making any changes to the Company's ICT environment, operations, or procedures, or after any event affecting the Company's security, ensure whether there is a need to introduce changes or improvements to the Cyber Security Policy and Program.


Chapter Three

Cyber Risk Management

First: Identification of Critical Operations and Supporting Information Assets in the Company

Article (13): The Company must identify the following to be able to assess the cyber risks it may face: a. The Company's critical functions and operations. b. The Company's information assets and understanding their processes, procedures, systems, and related resources, information systems, and means of access, including internal and external systems associated with them.

Article (14): The Company must classify its functions and critical operations and information assets in terms of their importance and sensitivity, and continuously review and update the classifications.

Second: Cyber Risk Assessment

Article (15): The Company must continuously analyze cyber risk factors by identifying the following: a. Internal threats. b. External threats. c. Vulnerabilities in managing ICT environment resources. d. Vulnerabilities in the ICT environment's ability to enable the Company's operations. e. Vulnerabilities in managing ICT environment risks.

Article (16): The Company must continuously analyze cyber risk scenarios by identifying, at a minimum, the following: a. Source of the cyber threat: either internal or external. b. Type of cyber threat: either natural, man-made, or technological. c. Cyber event: for example, but not limited to, disclosure of confidential information, malfunction, unauthorized modification, theft, destruction, ineffective design, or unacceptable use. d. Affected assets or resources: for example, but not limited to, human resources, organizational structures, operations, ICT environment, or information. e. Time: time of occurrence, duration of the event, and age of the event at the time of discovery.

Article (17): The Company must create and continuously update the Cyber Risk Register, which must include, at a minimum, the following: a. Asset owner, evaluation team, evaluation date, subsequent evaluation date, summary of cyber risk assessment, and risk management options. b. Cyber risk assessment in terms of calculating two risk axes: event probability (Potential) and impact size (Impact or Severity). It is preferable to use a standard paired scale for evaluation axes, and to show the impact size based on the Company's IT-included objectives and operations using the evaluation axes of one of the following global models, for example:

  1. COBIT Information Criteria
  2. Balanced Scorecard (BSC)
  3. Extended BSC
  4. Wester man
  5. COSO ERM
  6. FAIR (Factor Analysis of Information Risk) c. Acceptable risk level (Risk Appetite). d. Risk management options (accept, mitigate, avoid, transfer). e. Risk management plan items and their monitoring (implemented or in progress according to the plan). f. Key Risk Indicators (KRI) to ensure risks do not exceed acceptable levels and the degree of risk tolerance (percentage of deviation added to acceptable risks). g. Criteria for evaluating the confidentiality, integrity, security, and availability of systems and sensitive information. h. Identifying Company employees' responsibilities regarding those risks.

Article (18): The Company has the right to engage a third party for the purpose of cyber risk assessment, subject to the provisions of prevailing legislation.


Chapter Four

Protective Controls

First: Protection of Systems, Software, Networks, and Network Devices

Article (19): The Company must provide the following protective controls, including but not limited to, for all components of the ICT environment such as systems, software, networks, and network devices it possesses, from any cyber event: a. Network segregation to ensure the isolation of the impact of systems exposed to cyber intrusion from others in the event of occurrence, and to facilitate the efficient and effective restoration of services according to the Company's cyber risk assessment. b. Segregation of infrastructure sites (main sites and disaster recovery sites) for critical systems in a secure area with limited access, documenting visitor entry logs, and the presence of monitoring systems for infrastructure sites. c. Segregation of the test and development environment for critical systems from the production environment. d. Continuously evaluating the efficiency and design of network connections and network devices, including protection devices (such as Firewalls, IPS (Intrusion Prevention Systems)), to meet business needs, and maintaining an updated network connection design in the Company, in addition to maintaining an updated list of devices connected to the Company's network and diagrams of the main site and disaster recovery site data centers in a secure location accessible only to relevant personnel. e. Providing preventive controls related to preventing the connection of third-party devices or devices owned by employees with the Company's networks, servers, and systems, including computers and mobile devices and any other devices, without obtaining necessary approvals, and applying information security and cyber security policies and rules to them in case of approval to connect, and working to provide supervisory controls to detect any devices connected to the Company's networks and systems through unauthorized means. f. Providing necessary devices and software to monitor, warn, and detect electronic intrusion and unauthorized access, such as Intrusion Detection Systems and antivirus software, and ensuring their continuous updating and effective deployment in monitoring and intrusion detection operations. g. Updating operating systems and software installed on devices and servers for the Company's critical systems with the latest updates recommended by the supplier, especially updates related to closing security vulnerabilities by providers of those systems to avoid risks of unupdated systems, in accordance with the Company's "Patch Management Policy," while striving to apply change policies and procedures as quickly as possible, and making decisions based on IT and cyber risks, and providing effective alternative controls in case this is not possible, in addition to deleting any software or files stored on critical system servers that are not related to the software used by the Company, with the necessity of conducting necessary tests before implementing these updates on systems. h. Restricting employees' internet access to trusted sites only.

i. Segregating employees' access to critical systems from their internet access, and if other access is needed, necessary approval must be obtained and documented. j. Setting standards for ICT environment security settings according to best practices and documenting them. k. Developing procedures and guidelines designed to ensure the security of software and application development operations within the Company, in addition to procedures for evaluating or testing the security of software and applications developed outside the Company's environment. l. Periodically reviewing and updating all procedures and guidelines designed to ensure the security of software and application development practices by qualified persons according to international standards in this regard. m. The Company must identify activities that may pose a risk to its systems, especially financial systems, and disseminate them to employees to prevent engagement in them. n. Working with sufficiently reliable encryption systems for sensitive files stored on devices or transmitted across networks.

Article (20): The Company must use protection systems from diverse sources within different security tiers on all the Company's critical systems.

Article (21): The Company must provide the following protective controls for critical systems and sensitive data in the Company regarding user identity authentication/verification for those systems: a. Using strong and effective access controls through two or more authentication categories (Multi-factor Authentication) according to the risk level, ensuring their appropriate separation in a way that reduces the likelihood of others knowing one of their categories through necessary means and technologies to ensure accountability and non-repudiation.

b. In case of urgent need for remote access; it must be used to the narrowest extent, with the necessity of providing access controls through multi-factor authentication means and using highly reliable encryption technologies and other accompanying controls to mitigate the risks of unauthorized intrusion. c. Applying international security standards and global best practices when selecting password specifications.

Article (22): The Company must provide the following protective controls regarding information related to its business: a. Disposing of any sensitive information that is no longer necessary for operating operations...