2018-02-06

Added · Updated

Central Bank of Jordan Cyber Resilience Instructions

The Central Bank of Jordan issues the Cyber Resilience Instructions, effective twelve months from their date, applying to all licensed banks, financial institutions, credit reporting companies, and microfinance companies under its supervision. The document mandates comprehensive cyber security governance, requiring boards and senior management to adopt specific policies, programs, and risk registers while establishing an independent Chief Information Security Officer role. It imposes detailed obligations for identifying critical operations, conducting continuous cyber risk assessments, and implementing protection controls such as network segregation and infrastructure site security. Additionally, the Instructions define strict procedures for incident detection, emergency response, recovery, testing, and the outsourcing of third-party activities.

Central Bank of Jordan logo

Jordan

Central Bank of Jordan

Click to view thumbnail

Number: 1/1/26/1984 Date: 6/2/2018 Corresponding Date: 20 Jumada al-Awwal 1439

[Logo of the Central Bank of Jordan]

Central Bank of Jordan

Cyber Resilience Instructions


Table of Contents

  • Chapter One: Legal Basis, Scope of Application, and Definitions
  • Chapter Two:
    • First: Cyber Security Governance
    • Second: Cyber Security Program and Policy
  • Chapter Three: Cyber Risk Management
    • First: Identification of Critical Operations and Supporting Information Assets in the Company
    • Second: Cyber Risk Assessment
  • Chapter Four: Protection Controls
    • First: Protection of Systems, Software, Networks, and Network Devices
    • Second: Specific Protection Controls for Email
    • Third: Records
  • Chapter Five: Detection of Cyber Incidents
  • Chapter Six: Emergency Response to Cyber Incidents and Recovery
  • Chapter Seven: Testing
  • Chapter Eight: Outsourcing
  • Chapter Nine:
    • First: Training and Awareness
    • Second: Exchange of Cyber Incident Information
  • Chapter Ten: General Provisions

Chapter One

Legal Basis, Scope of Application, and Definitions

Article (1): These Instructions are issued pursuant to the provisions of Articles (4/b/3 and 4) and Articles (50/c, 65/b) of the Central Bank of Jordan Law No. (23) of 1971 and its amendments, Article (99/b) of the Banks Law No. 28 of 2000 and its amendments, and Article (22/b) of the Electronic Transactions Law No. (15) of 2015 and its amendments, and shall become effective twelve months from their date, unless otherwise provided.

Article (2): These Instructions shall be known as the "Cyber Resilience Instructions."

Article (3): a. These Instructions shall apply to all licensed banks, financial institutions, credit reporting companies, and microfinance companies subject to the supervision and oversight of the Central Bank of Jordan. b. Branches of foreign banks operating in the Kingdom shall comply with these Instructions to the extent applicable to them, or alternatively, with the governance and management policies for information and technology issued by the parent bank or the supervisory authority in the home country, whichever better achieves the objectives of these Instructions. In the event that the Instructions issued by the parent bank or the supervisory authority in the home country better achieve the objectives of these Instructions, the branch must provide evidence thereof to the Central Bank. In case of any conflict, the branch must inform the Central Bank and the parent company, provide the necessary clarification regarding such conflict, and obtain the Central Bank's approval on the method of addressing this conflict.

Article (4): The Bank shall consider all provisions contained in the Information and Technology Governance and Management Instructions No. (65/2016) dated 25/10/2016, particularly those related to the management of information security and risks, and shall read them in an integrated manner. The financial institution, credit reporting company, and microfinance company shall apply the aforementioned Instructions to the extent that they align with and satisfy these Instructions.

Article (5): a. The following words and phrases shall have the meanings specified below wherever they appear in these Instructions, unless the context indicates otherwise:

TermDefinition
Financial InstitutionAny public or private joint-stock company licensed to provide payment services or manage and operate electronic payment systems.
Credit Reporting CompanyA company licensed in accordance with the provisions of the Credit Information Law No. (15) of 2010 and the regulation issued thereunder.
Microfinance CompanyA financial company engaged in microfinance activities and licensed in accordance with the provisions of the Microfinance Companies System No. (5) of 2015.
CompanyThe Bank, Islamic Bank, Financial Institution, Credit Reporting Company, or Microfinance Company.
BoardThe Board of Directors of the Company and those equivalent to it.
Senior Executive ManagementIncludes the General Manager or Regional Director, Deputy General Manager or Deputy Regional Director, Assistant General Manager or Assistant Regional Director, Chief Financial Officer, Chief Operating Officer, Risk Management Director, Treasury (Investment) Director, Compliance Director, as well as any employee in the Company who holds executive authority parallel to any of the aforementioned and is functionally linked directly to the General Manager.
Information and Communications Technology (ICT) EnvironmentThe set of computer equipment specific to internal and external networks, main servers, and the software running on them, along with all supporting devices at the Company's main and backup sites.
InformationAny oral or written data, records, statistics, written or visual documents, or records stored electronically or by any other method that holds value for the Company.
DataRaw facts that can be clarified by letters, symbols, and numbers that may represent persons, objects, or events.
Information AssetsAny information, electronic or non-electronic files, devices, storage media, software, or any components of the ICT environment related to the Company's business.
CyberspaceA virtual environment consisting of the interaction of people, software, and services on the Internet through devices and connected technology networks.
Cyber AttackAny attempt to destroy, disclose, change, disrupt, or steal, or attempt to exploit vulnerabilities or gain unauthorized access to the Company's information assets within cyberspace.
Cyber ResilienceThe Company's ability to anticipate, withstand, contain, and recover quickly from a cyber attack.
Cyber SecurityMaintaining the confidentiality, integrity, and availability of the Company's information and information assets within cyberspace from any cyber threat through a set of means, policies, instructions, and best practices in this regard.
Cyber ThreatA circumstance or event that may exploit (intentionally or unintentionally) one or more vulnerabilities existing in the Company's ICT environment, thereby affecting its cyber security.
Cyber EventAny incident indicating the presence of a cyber threat to the Company's ICT environment.
Cyber RiskA composite measure resulting from calculating the probability of a cyber event occurring within the scope of the Company's information assets, and the impact of that event on the Company.
Cyber GovernanceThe Company's arrangements for establishing, implementing, and reviewing its approach to managing cyber risks.
Data GovernanceThe process of managing the availability, security, ease of use, and integrity of data used in the Company.
Malicious CodeSoftware or harmful files containing functions that negatively affect, directly or indirectly, the ICT environment used in the Company.
ProtectionThe deployment of appropriate procedures, controls, and measures to provide the Company's services and business reliably.
DetectionThe deployment of appropriate controls and procedures to become aware of the occurrence of a cyber event immediately.
ResponseThe deployment of appropriate controls and procedures to contain the cyber event upon its detection.
RestoreThe process of retrieving information stored on backup media when original information is damaged, lost, or needed after a period of time to resume the Company's operations.
RecoveryA set of actions taken and followed to return the Company's business to its normal state and restart the technology resources relied upon to operate the Company's processes to their pre-event state.
VulnerabilitiesA defect or deficiency in the protection controls used in any components of the ICT environment related to the Company's business, which can be exploited in hacking and cyber attack operations.
Access ControlThe rules and mechanisms used to allow only authorized persons to use and access information assets in accordance with the nature of their responsibilities in the Company.
PrivilegesThe level of permissions granted to users to access/use and utilize any components of the ICT environment in the Company.
Change ManagementThe management, control, and documentation of any changes made to any components of the ICT environment in the Company or any changes in the procedures implemented in the Company by authorized parties.
Information ClassificationDetermining the appropriate sensitivity level for information created, changed, transferred, modified, or stored on any media and using any possible technology, based on the risks resulting from unauthorized access to and use of that information.
ConfidentialityProtecting information from unauthorized access, publication, disclosure, and use.
AvailabilityThe ability to use and access/retrieve information and systems in the Company upon request.
IntegrityThe accuracy, completeness, and soundness of information or information systems or any part thereof, and verifying that no unauthorized increase, decrease, or change has occurred.
Recovery Time Objective (RTO)The maximum allowable time to restart a service or process after an interruption in IT services.
Recovery Point Objective (RPO)The maximum allowable age of data that may be lost when restoring service after an interruption.
Cyber Risk ManagementThe processes of identifying, measuring, controlling, and monitoring cyber risks.
Critical OperationsOperations that cannot tolerate long periods of downtime according to business impact analysis studies in the Company, and those operations with relative risk and importance to the Company.
E-mailThe service that can be provided to users to create, send, receive, and store electronic messages using electronic communication systems.
EncryptionThe process of converting information into an unreadable or incomprehensible form.
Third PartyThe entity to which the Company entrusts technical and operational activities wholly or partially to assist it in performing its licensed activities in a manner that does not conflict with the provisions of prevailing legislation.
OutsourcingEngaging a third party or utilizing its resources to manage the Company's business or part of its business that falls within its responsibility.
Physical SecurityProtection standards and procedures that monitor or determine entry to any of the Company's facilities, resources, or information stored on physical media, or to prevent access to information resources and systems, such as buildings, file cabinets, office and portable devices, servers, and equipment.
StakeholdersAny interested party in the Company, such as shareholders, employees, creditors, customers, external suppliers, or relevant regulatory authorities.
Event logData files of security and operational events produced by system components to understand system activity and diagnose problems that may occur.
Audit TrailData files that provide documentary evidence of the sequence of functional and administrative processes occurring on systems.
Risk AssessmentMeasuring and determining the probability and severity of risks and anticipating their impact on the Company.
Penetration TestingA test in which specialized evaluators attempt to find security vulnerabilities, bypass security features of information systems and security controls, and exploit them to attempt to breach those systems from outside or inside the Company to determine the effectiveness of the security controls used by the Company to protect its systems.
Remote AccessEnabling connection with the Company's systems from outside its internal network, whether for the purpose of enabling employees to work remotely, securing connection with business partners, or by a third party.

b. The definitions contained in the Central Bank Law, Electronic Transactions Law, Banks Law, and any related Instructions issued by the Central Bank shall be adopted wherever the text refers to them in these Instructions, unless the context indicates otherwise.


Chapter Two

First: Cyber Security Governance

Article (6): The Company shall comply with the following: a. The Board of Directors, its delegated committees, and Senior Executive Management shall include individuals possessing the appropriate skills and knowledge to understand and manage cyber risks. b. The Board or its delegated committees shall assume the following responsibilities and tasks, each according to its position:

  1. Adopting the Cyber Security Policy.
  2. Adopting the Cyber Security Program.
  3. Reviewing compliance with the Cyber Security Policy and Program. c. Senior Executive Management shall assume the following responsibilities and tasks, each according to its position:
  4. Ensuring the implementation and updating of the Cyber Security Policy.
  5. Ensuring the implementation of the Cyber Security Program so that it is integrated with the overall IT risk management framework, and continuing to update and develop it.
  6. Ensuring the existence of a comprehensive Cyber Risk Register and ensuring its continuous updating in alignment with the Company's IT Risk Profile.
  7. Continuously monitoring the level of cyber risks.
  8. Adopting lists of authorities related to the management of cyber security and risks, specifying the primary responsible party (Responsible), the consulted party (Consulted), and the informed party (Informed) for all processes of managing, controlling, and auditing those risks.

Second: Cyber Security Program and Policy

Article (7): The Company shall implement and continuously update the Cyber Security Program to ensure the achievement of confidentiality, authenticity, and availability requirements for information in the ICT environment. The Program shall include, at a minimum, the following: a. Identifying internal and external threats to cyber risks. b. Identifying and classifying risks and information sensitivity in the ICT environment. c. Identifying entities with the ability to access and use information and the ICT environment. d. Implementing cyber security policies and procedures and operating the necessary ICT environment to ensure the protection of the Company's information assets and sensitive information from unauthorized hacking. e. Detecting successful and failed hacking attempts immediately upon occurrence, to the extent possible. f. Taking necessary corrective actions to control and mitigate the negative effects of cyber risks. g. Procedures for restarting the Company's operations after downtime, including those related to services and legal and regulatory requirements during the acceptable and defined time period within the business continuity plan, in accordance with Article (32/g) of these Instructions.

Article (8): The Cyber Security Policy must be a dedicated document for cyber security in the Company. When preparing and updating the policy, all relevant parties shall be considered, and international best practices and their updates shall be adopted as references and lessons learned from cyber security incidents. The Company may include the Cyber Security Policy within the Information Security Policy under the title "Information Security and Cyber Security Policy," and may include Cyber Security Programs within the Information Security Program, provided that all provisions of these Instructions are met.


Article (9): The Cyber Security Policy must include, at a minimum, the following axes: a. Defining roles and responsibilities, including the responsibility for decision-making within the Company regarding cyber risk management, including emergency and crisis situations. b. Data governance and classification. c. Security and management of information and the ICT environment in the Company. d. Customer data privacy. e. Cyber risk management. f. Protection controls to limit and control cyber risks. g. Business continuity and disaster recovery plans. h. Cooperation with relevant parties to effectively respond to cyber attacks and recover from them. i. Monitoring, developing, and improving systems, networks, and applications. j. Physical and environmental security controls. k. Management of outsourced third-party operations. l. Awareness and training of Company employees regarding cyber security to ensure all employees apply all provisions of the Cyber Security Policy. m. Defining a mechanism for disclosing the provisions of the Cyber Security Policy to relevant parties according to their role. n. Defining the owning entity, scope of application, frequency of review and update, access and distribution rights, objectives, responsibilities, related work procedures, penalties for non-compliance, and compliance review mechanisms.

Article (10): The Company must manage information security related to cyber security through a Chief Information Security Officer (CISO) who does not administratively report to the IT department, enjoys independence, and ensures no conflict of interest. The CISO must have the necessary practical experience and professional knowledge to be responsible for the following tasks at a minimum: a. Directly supervising the development of the Cyber Security Program and Policy, ensuring their implementation, and working on their continuous review and update. b. Evaluating the adequacy and efficiency of the Cyber Security Program and Policy. c. Continuously reviewing the effectiveness of the protection controls adopted in the Company's Cyber Security Policy. d. Identifying and evaluating cyber risks. e. Submitting semi-annual reports or as needed to the Board and Senior Executive Management regarding cyber security in the Company. The report must include, at a minimum:

  1. Deviations related to the application of the Cyber Security Policy and its procedures.
  2. Results of cyber risk assessments.
  3. Results of the evaluation of the adequacy and efficiency of the Cyber Security Program and Policy.
  4. Recommendations, procedures, and requirements to be implemented.
  5. A summary reviewing the most important cyber threat and breach events the Company has been exposed to during the reporting period.

Article (11): Notwithstanding the provisions of Article (10) above, the Company has the right to outsource the management of information security or part of it to a third party, provided it complies with the following: a. Requesting the third party to comply with requirements that satisfy the Instructions regarding information security management. b. Reviewing the third party's compliance with the Instructions regarding information security management.

Article (12): The Company must, before making any changes to the ICT environment, operations, or procedures, or after any event affecting the Company's security, ensure whether there is a need to introduce changes or improvements to the Cyber Security Policy and Program.


Chapter Three

Cyber Risk Management

First: Identification of Critical Operations and Supporting Information Assets in the Company

Article (13): The Company must identify the following to be able to assess the cyber risks it may face: a. Critical functions and operations in the Company. b. Information assets in the Company, understanding their processes, procedures, systems, and related resources, information systems, and access methods, including internal and external systems associated with them.

Article (14): The Company must classify its functions, critical operations, and information assets in terms of their importance and sensitivity, and continuously review and update these classifications.

Second: Cyber Risk Assessment

Article (15): The Company must continuously analyze cyber risk factors, identifying the following: a. Internal threats. b. External threats. c. Vulnerabilities in the management of ICT environment resources. d. Vulnerabilities in the ICT environment's ability to enable the Company's operations. e. Vulnerabilities in the management of ICT environment risks.


Article (16): The Company must continuously analyze cyber risk scenarios, identifying, at a minimum, the following: a. Source of the cyber threat: either internal or external. b. Type of cyber threat: either natural, man-made, or technological. c. Cyber event: for example, but not limited to, disclosure of confidential information, malfunction, unauthorized modification, theft, destruction, ineffective design, or unacceptable use. d. Affected assets or resources: for example, but not limited to, human resources, organizational structures, operations, ICT environment, or information. e. Time: time of occurrence, duration of the event, and age of the event upon discovery.

Article (17): The Company must create and continuously update the Cyber Risk Register, which must include, at a minimum, the following: a. Asset owner, evaluation team, evaluation date, subsequent evaluation date, summary of cyber risk assessment, and management options. b. Cyber risk assessment in terms of calculating two risk axes: event probability (Potential) and impact size (Impact or Severity). It is preferable to use a standard paired scale for evaluation axes, and to show the impact size based on the Company's IT-included objectives and operations using one of the following global models as an example:

  1. COBIT Information Criteria
  2. Balanced Scorecard (BSC)
  3. Extended BSC
  4. Wester man
  5. COSO ERM
  6. FAIR (Factor Analysis of Information Risk) c. Acceptable risk level (Risk Appetite). d. Risk management options (acceptance, mitigation, avoidance, transfer). e. Risk management plan items and their follow-up (implemented or in progress according to the plan). f. Key Risk Indicators (KRI) to ensure risks do not exceed acceptable levels and to measure risk tolerance (percentage of deviation added to acceptable risks). g. Criteria for evaluating the confidentiality, integrity, security, and availability of systems and sensitive information. h. Defining the responsibilities of Company employees regarding those risks.

Article (18): The Company has the right to engage a third party for the purpose of cyber risk assessment, subject to the provisions of prevailing legislation.


Chapter Four

Protection Controls

First: Protection of Systems, Software, Networks, and Network Devices

Article (19): The Company must provide the following protection controls, including but not limited to, for all components of the ICT environment such as systems, software, networks, and network devices, against any cyber event: a. Network segregation to ensure the isolation of the impact of systems exposed to cyber attacks from others in the event of an attack, facilitating the efficient and effective restoration of services according to the Company's cyber risk assessment. b. Segregation of infrastructure sites (main sites and disaster recovery sites) for critical systems in a limited-access secure area, documenting visitor entry logs, and having monitoring systems for infrastructure sites. c. Segregation of the test and development environment for critical systems from the production environment. d. Continuous evaluation of the efficiency and design of network connections and network devices, including protection devices (such as Firewalls, IPS (Intrusion Prevention Systems)), to meet business needs. The Company must keep an updated network connection design, an updated list of devices connected to the Company's network, and diagrams of the main site and disaster recovery site data centers in a secure location accessible only to authorized personnel. e. Providing preventive controls regarding the prohibition of connecting third-party or employee-owned devices with the Company's networks, servers, and systems, including computers, mobile devices, and any other devices, without obtaining necessary approvals. If connection is approved, information security and cyber security policies and rules must be applied to them. The Company must work to provide supervisory controls to detect any devices connected to the Company's networks and systems through illegal means. f. Providing necessary devices and software to monitor, warn, and detect electronic hacking and unauthorized access, such as Intrusion Detection Systems and antivirus software, ensuring they are continuously updated and effectively deployed in monitoring and detection operations. g. Updating operating systems and software installed on devices and servers for the Company's critical systems with the latest updates recommended by the vendor, particularly updates related to closing security vulnerabilities provided by vendors for those systems to avoid risks of unupdated systems. This must be in accordance with the Company's "Patch Management Policy," with emphasis on applying change policies and procedures as quickly as possible, making decisions based on IT and cyber risks, and providing effective alternative controls if this is not possible. Additionally, any software or files stored on critical system servers unrelated to the Company's operational software must be deleted, with necessary tests conducted before implementing these updates on systems. h. Restricting employee internet access to trusted sites only.

i. Separating employee access to critical systems from their internet access. If other access is necessary, necessary approval must be obtained and documented. j. Setting standards for ICT environment security settings according to best practices and documenting them. k. Developing procedures and guidelines designed to ensure the security of software and application development processes within the Company, as well as procedures for evaluating or testing the security of software and applications developed outside the Company's environment. l. Periodically reviewing and updating all procedures and guidelines designed to ensure the security of software and application development practices by qualified persons according to international standards in this regard. m. The Company must identify activities that may pose a risk to its systems, especially financial systems, and disseminate them to employees to prevent engagement in them. n. Working with sufficiently reliable encryption systems for sensitive files stored on devices or transmitted across networks.

Article (20): The Company must use protection systems from diverse sources within different security tiers on all of the Company's critical systems.

Article (21): The Company must provide the following protection controls for critical systems and sensitive data in the Company regarding user authentication/verification: a. Using strong and effective access controls through two or more authentication categories (Multi-factor Authentication) according to the risk level, ensuring their proper separation in a way that reduces the likelihood of others knowing one of their categories through necessary means and technologies, ensuring accountability and non-repudiation.

b. In case of urgent need for remote access; it must be used to the narrowest extent, with the necessity of providing access controls through multi-factor authentication means, using highly reliable encryption technologies, and other accompanying controls to limit the risks of unauthorized hacking. c. Applying international security standards and global best practices when choosing password specifications.

Article (22): The Company must provide the following protection controls regarding information related to its business: a. Disposing of any sensitive information that is no longer necessary for the operation of processes