2023-11-21 | Circular 11/2023Added · Updated
Circular 11/2023 amends Circular 13/2017 to impose obligations on participants in the US Dollar Interbank Payment System (SPEI) regarding the designation of Information Security Officers. Participants must maintain designated officers, verify their compliance, provide them with updated access lists, and conduct periodic security checks on their technology infrastructure. The circular also mandates periodic verification of incident response requirements for electronic channels and repeals previous provisions, entering into force on April 4, 2024.
Wednesday, November 22, 2023 OFFICIAL GAZETTE 199 BANCO DE MEXICO CIRCULAR 11/2023 addressed to Credit Institutions and other companies that professionally provide the service of fund transfers, regarding the Modifications to Circular 13/2017 (Information Security Officer of the US Dollar Interbank Payment System).
At the margin a logo, which says: Bank of Mexico.- “2023, Year of Francisco Villa, the revolutionary of the people”.
CIRCULAR 11/2023 TO CREDIT INSTITUTIONS AND OTHER COMPANIES THAT PROFESSIONALLY PROVIDE THE SERVICE OF FUND TRANSFERS:
SUBJECT: MODIFICATIONS TO CIRCULAR 13/2017 (INFORMATION SECURITY OFFICER OF THE US DOLLAR INTERBANK PAYMENT SYSTEM)
The Bank of Mexico, with the purpose of continuing to promote the sound development of the financial system, protect the interests of the public and foster the proper functioning of payment systems, has resolved to establish the obligations of participants in the US Dollar Interbank Payment System related to the designation of information security officers and the activities that such officers will perform, without submitting these modifications to public consultation, since the purpose of these modifications is the inclusion of the figure of the information security officer in the US Dollar Interbank Payment System, a topic that is the result of the public consultation formulated on the modifications to the Rules of the US Dollar Interbank Payment System, provided for in Circular 4/2016.
For the above, based on articles 28, paragraphs sixth and seventh, of the Political Constitution of the United Mexican States, 2, 3, fraction I, 24 and 35 Bis of the Bank of Mexico Law, 10 and 19 of the Payment Systems Law, 22 of the Law for Transparency and Ordering of Financial Services, 4, first paragraph, 8, fourth and eighth paragraphs, 10, first paragraph, 15 Bis 1, first paragraph, in relation to 28 Bis 1, fraction IX, 17, fraction I, 20 Quáter, fraction IV, and 29 Bis, fraction VIII, of the Internal Regulations of the Bank of Mexico, which grant it the authority to issue provisions through the General Directorate of Information Technologies, the Directorate of Central Banking Provisions, the Directorate of Policy and Studies of Payment Systems and Market Infrastructures and the Directorate of Cybersecurity, respectively, Second, fractions II, IX, X and XVII, of the Agreement on the Attachment of Administrative Units of the Bank of Mexico, as well as numeral 13, fraction IV, of the Policies for public consultation of general provisions issued by the Bank of Mexico, has resolved to modify the 15th, fraction XV; add fractions II Bis, II Ter, II Quáter and II Quinquies to the 13th, as well as repeal fractions XII, XIII and XIV of the 15th, of the “General provisions applicable to credit institutions and other companies that professionally provide the service of fund transfers, as well as to participants in payment systems administered by the Bank of Mexico and to other interested parties in acting as participants in said systems”, contained in Circular 13/2017, to remain in the following terms:
GENERAL PROVISIONS APPLICABLE TO CREDIT INSTITUTIONS AND OTHER COMPANIES THAT PROFESSIONALLY PROVIDE THE SERVICE OF FUND TRANSFERS, AS WELL AS TO PARTICIPANTS IN PAYMENT SYSTEMS ADMINISTERED BY THE BANK OF MEXICO AND TO OTHER INTERESTED PARTIES IN ACTING AS PARTICIPANTS IN SAID SYSTEMS
“13th. Obligations of Participants.- … I. and II. … II Bis.- At all times have information security officers designated in accordance with what is provided in Internal Norms and inform the Administrator of the appointment; II Ter.- Perform periodic verifications of the compliance of the information security officer’s functions; II Quáter.- Make available to the information security officer the updated list of persons who have access to information related to the operations in which the Participant itself intervenes, both those located abroad and technology infrastructure users who have high privileges; II Quinquies.- Perform periodic verifications of compliance with information security requirements in its technological infrastructure or the technological infrastructure of any third party that could affect the operation or the technological infrastructure of the Participant; III. to XXIV. …”
“15th. Obligations of SPEI Participants.- … I. to XI. … XII.- Repealed. XIII.- Repealed. XIV.- Repealed. XV.- Perform periodic verifications of compliance with information security incident response requirements in their electronic channels; XVI. to XXVI. …”
TRANSITORY SINGLE.- The provisions of this Circular shall enter into force on April 4, 2024.
Mexico City, November 9, 2023.- BANK OF MEXICO: General Director of Information Technologies, Octavio Bergés Bastida.- Rubric.- Director of Central Banking Provisions, María Teresa Muñoz Arámburu.- Rubric.- Director of Policy and Studies of Payment Systems and Market Infrastructures, Othón Martino Moreno González.- Rubric.- Director of Cybersecurity, Alejandro de los Santos Santos.- Rubric.
For any queries regarding the content of this Circular, the Bank of Mexico is at your disposal through the Directorate of Central Banking Authorizations and Sanctions at phone (55) 5237-2000 extension 3200. 3200.
More like this from BANXICO
We email you every new BANXICO publication the day it's published.