2024-08-26
Added · Updated
The Superintendence of the Securities Market of the Dominican Republic approves the Instruction on the Cybersecurity and Information Security Regulation, which establishes technical procedures and requirements for the elaboration, implementation, and management of cybersecurity programs by Securities Market Participants. The document mandates specific policies and procedures including information classification, identity and access control, continuous system monitoring, and intrusion detection. It also requires regular employee training, awareness campaigns, and the maintenance of signed security commitments from employees and contractors.
Superintendence of the Securities Market of the Dominican Republic CIRCULAR No. 03/2024 To: The Securities Market Participants indicated in the scope of the Draft Regulation on Cybersecurity and Information Security in the Securities Market. Subject: Instruction on the Regulation on Cybersecurity and Information Security in the Securities Market.
HAVING SEEN: a. Law No. 249-17, on the Securities Market of the Dominican Republic, which repeals and substitutes Law No. 19-00 of May 8, 2000, promulgated on December 19, 2017 (hereinafter, "Law No. 249-17"). b. Law No. 167-21, on Regulatory Improvement and Simplification of Procedures, dated August 12, 2021. c. Law No. 107-13, on the Rights of Persons in their Relations with the Administration and Administrative Procedure, dated August 6, 2013. d. Law No. 200-04, General Law on Free Access to Public Information, dated July 28, 2004. e. Regulation on Integrated Risk Management for Securities Intermediaries. f. Second Resolution dated November 1, 2018, of the Monetary Board, which authorizes the Regulation on Cybersecurity and Information Security. g. Regulation on Cybersecurity and Information Security, approved by the National Securities Market Council through Second Resolution R-CNMV-2024-08-MV, dated July 16, 2024.
CONSIDERING: a. That Article 17, numeral 14), of Law No. 249-17, empowers the Superintendent of the Securities Market to "issue the resolutions, circulars, and instructions required for the development of this law and its regulations". b. That the Superintendence of the Securities Market, in its capacity as the regulatory body of the Securities Market and in accordance with Article 7 of Law No. 249-17, shall have as its objective to promote an orderly, efficient, and transparent securities market, protect investors, ensure compliance with this law, and mitigate systemic risk, through the regulation and supervision of natural and legal persons operating in the securities market. c. That the Superintendent of the Securities Market is the highest executive authority of the Superintendence of the Securities Market, having under his/her charge the direction, control, and representation thereof. d. That it is the criterion of the Superintendence of the Securities Market the standardization of formats and content of documents, which has proven to be effective and has contributed enormously to the good development and good organization of the market. e. That Article 60 of the Regulation on Cybersecurity and Information Security in the Securities Market provides that: "The Superintendent, through technical or operational norms, shall issue the content and other applicable requirements for the elaboration, implementation, and management of the Cybersecurity and Information Security Program of the Securities Market Participants". f. That, for its part, Law No. 167-21, on Regulatory Improvement and Simplification of Procedures, has as its objective to define and articulate public policies directed toward regulatory improvement and the simplification of administrative procedures. g. That, pursuant to the aforementioned Law, public consultation is defined as a mechanism of citizen participation used to transparent the process of production and review of regulations, allowing for the receipt of comments from different stakeholder groups and the general public. h. That, in compliance with the current legal framework, the draft instruction of the Regulation on Cybersecurity and Information Security in the Securities Market was submitted to public consultation from July 20, 2023, to September 22, 2023. i. That from the consultative process, comments were received from the Dominican Association of Investment Fund Management Companies, Inc. (ADOSAFI), CEVALDOM Central Securities Depository, S.A., BHD Financial Center, SCRiesgo, Risk Rating Society, S.R.L., Securities and Markets of the Dominican Republic, S.A. (BVRD), and Cibao Savings and Loans Association (ACAP). j. That from said process, a matrix was prepared that collects the observations and comments presented, which were duly analyzed and responded to by the technical team of the Superintendence of the Securities Market; subsequently, as part of the administrative procedure and in attention to the principles of transparency and participation, a working group -in virtual mode- with interested sectors was held on July 3, 2024. k. That as a result of the consultative process, the following improvements were contemplated, namely: - The wording of the Scope is adapted, in consonance with what is provided in the Regulation on Cybersecurity and Information Security in the Securities Market. - The minimum requirements to be adopted by issuers, external auditors, and risk rating societies from the cybersecurity governance framework are eliminated. - The wording of the article on Continuous Monitoring of the capacity of systems and Information Technology Infrastructure is modified. - "personal computing devices" is changed to "end devices". - The effective date and the adaptation period are modified.
Therefore: The Superintendent of the Securities Market, in the exercise of the powers conferred by Article 17, numeral 14) of Law No. 249-17, resolves:
"INSTRUCTION ON THE REGULATION ON CYBERSECURITY AND INFORMATION SECURITY IN THE SECURITIES MARKET"
Chapter I General Aspects
Article 1. Objective. This Instruction has as its objective to establish the technical procedures and requirements applicable that will complement the elaboration, implementation, and management of the Cybersecurity and Information Security Program of the Securities Market Participants.
Article 2. Scope. The Securities Market Participants subject to compliance with the Regulation on Cybersecurity and Information Security in the Securities Market (hereinafter, the "Regulation") are subject to the formalities provided in this Instruction.
Chapter II Content of Policies and Procedures of Securities Market Participants
Article 3. Scheme of policies. The Information Security Management policies of the Securities Market Participants shall refer, at least, to the following scheme:
Article 4. Content. Securities Market Participants must elaborate policies and procedures for the management of Cybersecurity and Information Security which will be incorporated into the Cybersecurity and Information Security Program, which must be aligned with their strategy, applicable current regulations, and include, by way of example but not limitation, the following:
Paragraph I. Securities Market Participants must have declarations signed by employees, contractors, suppliers, and other persons as applicable, in which they commit to comply with the documented security policies and Procedures.
Paragraph II. Information Asset shall be understood as the tangible or intangible good that stores, processes, and/or transmits information.
Article 5. Education and awareness. In accordance with what is established in Article 11 (Education and awareness) of the Regulation, the Securities Market Participant must have different mechanisms to raise security awareness among employees, service providers, and contractors, among which, at a minimum, the following are cited:
Paragraph. In addition to the preceding numerals, the company's security officer must carry out simulated campaign exercises directed at employees to improve security procedures.
Article 6. Classification and labeling of Information. The policies and Procedures developed by Securities Market Participants, pursuant to Article 15 (Classification and labeling of Information) of the Regulation, must, at a minimum, contemplate the following:
Article 7. Identity Management and Access Control Mechanisms. The policies and Procedures for identity management and Access Control Mechanisms that apply to Securities Market Participants for employees, contracted personnel, and third parties who have Access to Information Systems and Technological Infrastructure pursuant to the Framework chosen by the Participant, must include:
Paragraph. The Access Control Mechanisms must be based on: a) Results of the Technological Risk Evaluations of the Securities Market Participant; b) Access Control Requirements; c) Evaluation of the functionality of the Access Control Mechanisms; and, d) The identification of other additional factors related to the manufacturers of the equipment and systems that make up the Technological Infrastructure, as well as their levels of interconnection and interoperability with physical security systems.
Article 8. Continuous Monitoring of the capacity of systems and Information Technology Infrastructure. In addition to what is provided in Article 35 (Continuous Monitoring) of the Regulation, the Continuous Monitoring of Securities Market Participants must, at a minimum, contemplate the following aspects:
Article 9. Prevention and detection of intruders. In addition to what is established in Article 36 (Prevention and detection of intruders) of the Regulation, Securities Market Participants must implement the prevention and detection of intruders contemplating, at a minimum, the following aspects:
SC-07-03-05 Superintendence of the Securities Market of the Dominican Republic
a) Identification of unauthorized activities; b) Analysis of suspicious intrusions; c) Response to different types of attacks; and, d) Procedures for collaboration with those responsible for technological operations.
Article 10. Protection against Malicious Software. Securities Market Participants must have policies and procedures for the detection, prevention, and protection against Malicious Software, which include, by way of example but not limitation, the following:
SC-07-03-05 Edition 2 Page 9 of 16 AV. César Nicolás Penson No. 66, Gascue, Santo Domingo. Dominican Republic Telephone: 809.221.-4433 http://www.simv.gob.do | info@simv.gob.do | RNC: J-01-4314372-3
Superintendence of the Securities Market of the Dominican Republic
g) Incoming and outgoing network traffic to the corporate network.
Article 11. Network Management. In addition to what is established in Article 38 (Network Management) of the Regulation, the configuration of network devices and the physical network management of the Securities Market Participant must consider the following:
Configuration of network devices: the controls to be considered, by way of example but not limitation, are: a) Network devices configured according to standard and known practices for the administration of security of such devices and the principles of Cybersecurity and Information Architecture; b) Procedure for segmentation between networks with different security levels; c) Restriction of Access to the configuration console of network devices, located in protected data centers or secure storage rooms; and, d) Adequate security configurations of network devices, according to manufacturer recommendations or internal procedures defined for these purposes.
Physical network management: network access points must be protected by Access Control mechanisms, such as: a) Physical controls for the protection of telecommunications cables and network Access points, including labeling of equipment and cabling, concealment of cabling, use of armored conduits, locking of network points to prevent unauthorized hosts from connecting to the LAN, and the provision of alternative power sources. b) Documentation of the network architecture, contemplating the following: i. Diagrams of the networks showing all nodes and connections of internal networks for each local environment; ii. Inventory of communication equipment, critical systems and associated applications, links, and external service providers; iii. Schematics of telephone exchanges, cabling matrix, and deployed equipment; iv. Procedure for periodic update and review of the network architecture; and,
SC-07-03-05 Edition 2 Page 10 of 16 AV. César Nicolás Penson No. 66, Gascue, Santo Domingo. Dominican Republic Telephone: 809.221.4433 | http://www.simv.gob.do | info@simv.gob.do | RNC: J-01-4314372-3
SC-07-03-05 Superintendence of the Securities Market of the Dominican Republic
v. Physical inspections, verifying Network Integrity and any improper or suspicious use, as applicable.
Article 12. Electronic Communications. Electronic communications include Voice over Internet Protocol (VoIP) communication services, whose procedures must, at a minimum, contemplate:
Article 13. External Provider Management. Securities Market Participants that enter into contractual obligations with external providers of technological products or services must ensure the integration of Cybersecurity and Information Security requirements, taking into consideration the following aspects:
Outsourcing: This process must contemplate, by way of example but not limitation, the following aspects: a) Documented procedures for the management of Risks associated with the hiring of external providers of technological products or services, which must include the following: i. Identification and evaluation of Critical Information to be shared with external providers. This evaluation process must include the classification of Information that may or may not be shared with external providers according to the Securities Market Participant's privacy policies; ii. Assistance to the acquisitions units in drafting request for proposal documents for the acquisition of goods and services to ensure the inclusion of Cybersecurity and Information Security requirements; iii. Selection of reliable providers that comply with the security standards established in the chosen framework; iv. Review of received technical proposals to ensure compliance with Cybersecurity and Information Security requirements of the Securities Market Participant; and, v. Assistance to acquisitions committees in contract negotiation processes, incorporating Cybersecurity and Information Security requirements into them.
Security requirements for external providers: Among the security requirements that Securities Market Participants must implement are the following: a) Review the Cybersecurity and Information Security aspects of the critical provider's relationships; b) Validate that the provider maintains sufficient service capacity along with feasible plans designed to ensure that agreed service continuity levels are maintained after major failures or disasters; and, c) Request that the critical provider periodically deliver a report on the effectiveness of controls and agreement on the timely correction of relevant issues raised therein.
Acquisition or lease of technological equipment and systems: The process of acquisition or lease of technological equipment and systems must be based on reference guides for the selection and approval of equipment, application, and service providers, as well as anticipate the approved technical security requirements by the Cybersecurity and Information Security functional committee or the corresponding body, ensuring that they provide the required functionality and do not compromise the Cybersecurity and Sensitive Information of the Securities Market Participant during its lifecycle; and,
Inclusion of Cybersecurity and Information Security aspects in contracts with service providers, specifying the following: a) Restrictions on the exchange of Information of the Securities Market Participant with third parties; b) Commitment by providers and subcontractors to comply with the Cybersecurity and Information Security requirements established by the Securities Market Participant and regulatory bodies; c) Requirements for ensuring the continuous protection of Business Information before, during, and after the provision of a service; d) Obligations of each contractual party to implement an agreed set of controls including Access Control, performance evaluation, supervision, reporting, and auditing, as applicable; and, e) Rights to verify the processes and controls of critical providers related to the agreement.
SC-07-03-05 Edition 2 Page 12 of 16 AV. César Nicolás Penson No. 66, Gascue, Santo Domingo. Dominican Republic Telephone: 809.221.4433 | http://www.simv.gob.do | info@simv.gob.do | RNC: J-01-4314372-3
Superintendence of the Securities Market of the Dominican Republic
Article 14. System Development Management. Securities Market Participants that maintain a system development area in their organizational structure must establish policies and Procedures for system development management, which must contemplate, at a minimum, the following provisions:
SC-07-03-05 Edition 2 Page 13 of 16 AV. César Nicolás Penson No. 66, Gascue, Santo Domingo. Dominican Republic Telephone: 809.221.4433 | http://www.simv.gob.do | info@simv.gob.do | RNC: J-01-4314372-3
Superintendence of the Securities Market of the Dominican Republic
d) i. Notification to the area responsible for Cybersecurity and Information Security regarding the start of a new project; ii. Evaluations of the needs for the Confidentiality, Integrity, and availability of Information; iii. Application of the Securities Market Participant's Information classification schemes in the development of business systems, services, and applications. e) Training for developers on the application of security techniques in the development of systems, services, and digital applications; f) Use by external software development providers of the development methodology approved by the Securities Market Participant; and, g) Continuous Monitoring of adherence to the defined methodology by development teams in each of its phases.
System development environments: System development environments must implement mechanisms to ensure the privacy and protection of personal data in pre-production (quality assurance) and production environments, including: a) Controls for the protection of source code against Unauthorized Access, modification, and disclosure through the Securities Market Participant's system development environments, as well as the removal of Information, such as: authentication details, developer comments in applications, and sensitive information prior to their deployment in production environments; b) Strict application of version control through configuration management, logging of source code access, and maintenance of a properly documented repository of previous versions; c) Mechanisms to prevent the download and execution of malicious code in development environments; d) Policy for backing up source code copies, when developed by third parties, through digital custody mechanisms; e) Version control through configuration management, logging of source code access, and maintenance of a properly documented repository of previous and experimental versions.
Quality Assurance: System development must be carried out following quality standards and tests that ensure that the agreed Cybersecurity and Information Security controls and requirements are implemented during the development lifecycle, which includes:
SC-07-03-05 Edition 2 Page 14 of 16 AV. César Nicolás Penson No. 66, Gascue, Santo Domingo. Dominican Republic Telephone: 809.221.4433 | http://www.simv.gob.do | info@simv.gob.do | RNC: J-01-4314372-3
SC-07-03-05 Superintendence of the Securities Market of the Dominican Republic
a) Documented quality assurance procedures, contemplating security verification activities during the development lifecycle of systems and applications, which must include the following: i. Verification of application security requirements according to Risk assessment; ii. Mechanisms to ensure the correct functioning of developed security controls according to requirements; and, iii. Mechanisms to ensure the use of the Securities Market Participant's system development methodologies by employees involved in development. b) Identification and documentation of security defects or failures found in systems, as well as the patches applied, prior to their deployment in production environments; and, c) Documentation of defects and Vulnerabilities found in the Securities Market Participant's systems, applications, and digital services, with the purpose that they be corrected in a timely manner and validated by the system development responsible.
Chapter III Final Provisions
Article 15. Sanctioning Regime. The provisions established in this Circular are mandatory, and in case of non-compliance, the sanctions provided for in Law No. 249-17 and the Regulation on Sanctioning Administrative Procedure will be applied.
Article 16. Validity. The provisions of this Circular enter into force once the Regulation is in force.
Article 17. Adaptation Period. Securities Market Participants must adapt to the provisions of this Circular within the adaptation period established in the Regulation.
Inform Securities Market Participants that the Securities Market Superintendence may request audits in the matter of Cybersecurity and Information Security, through inspection reports, based on any finding or if an event occurs that requires it.
Inform Securities Market Participants and the public that the terms defined by Law No. 249-17 and its implementing regulations are incorporated into this Instruction.
SC-07-03-05 Edition 2 Page 15 of 16 AV. César Nicolás Penson No. 66, Gascue, Santo Domingo. Dominican Republic Telephone: 809.221.4433 | http://www.simv.gob.do | info@simv.gob.do | RNC: J-01-4314372-3
SC-07-03-05 Superintendence of the Securities Market of the Dominican Republic
In Santo Domingo, National District, capital of the Dominican Republic, on the sixth (06) day of the month of August of the two thousand twenty-four (2024).
Er esto Bournigal Read K Superintendent
SC-07-03-05 Edition 2 Page 16 of 16 AV. César Nicolás Penson No. 66, Gascue, Santo Domingo. Dominican Republic Telephone: 809.221.4433 | http://www.simv.gob.do | info@simv.gob.do | RNC: J-01-4314372-3
More like this from SIMV
SIMV published 2 documents in the last 30 days. We email you each new one the day it's published.