2021-01-25
Added · Updated
The Central Bank of Jordan requires microfinance companies operating in the Kingdom to report any detected cyber incidents or attack attempts, whether successful or thwarted, by submitting detailed information via a prescribed notification form. The circular mandates that companies provide specifics regarding the incident's nature, affected infrastructure, impact assessment, and response measures, accompanied by a guide for completing the form. Reports must be sent to the designated email address MFISCB.Supervision@cbj.gov.jo in accordance with the Cyber Risk Adaptation Instructions.
Get CBJ alerts — same-day email on every new publication.
In the name of Allah, the Most Gracious, the Most Merciful
Central Bank of Jordan
Reference: 1/28/1633
Date: 13/6/1442 AH
Corresponding to: 25/1/2021 AD
Circular to Microfinance Companies Operating in the Kingdom
Greetings,
With reference to the Cyber Risk Adaptation Instructions No. (26/1/1984) dated 6/2/2018 and in accordance with the provisions of Article (49) of these Instructions, we emphasize the necessity of notifying the Central Bank of Jordan upon discovering any cyber incident or any attempt at a cyber attack—whether successful or repelled. We inform you of the requirement to provide us with details of the cyber incidents, their impacts, response measures, and preventive measures taken, according to the attached form, by sending it to the email address below:
In this context, you will find attached the "Guide for Filling Out the Cyber Incident Notification Form" as a guidance document for completing the required data in that form.
Please accept our highest regards,
The Authorized Signatory
Dr. Ziad Freiz
P.O. Box 37, Amman 11118, Jordan • Phone: 4630301 • Fax: 4638889 • Website: www.cbj.gov.jo • Email: info@cbj.gov.jo
CENTRAL BANK OF JORDAN
البنك المركزي الأردني
Cyber Incident Notification Form
| Company Name | ||
|---|---|---|
| Time and Date of Incident Occurrence | Time and Date of Incident Discovery | Time and Date of Incident Correction |
| Contact Person Information | |
|---|---|
| Contact Person Name | |
| Phone Number | |
| Mobile Number |
| Incident Details | |
|---|---|
| Incident Type | |
| Infrastructure Components Affected by the Incident | |
| Incident Location | |
| Incident Severity Classification | |
| Causes Leading to the Incident | |
| Has this incident occurred before? (Yes or No) | |
| Department or Entity Responsible for Incident Management |
| Incident Impact Assessment | |
|---|---|
| Impact of the Incident on Company Operations Regarding Service Availability | |
| Channels Affected by the Incident | |
| Impact of the Incident on Company Systems and Technologies (Disruption of critical systems, disruption in any infrastructure components) | |
| Impact of the Incident on the Company's Information System (Confidentiality, Integrity, and Availability) | |
| Impact of the Incident on the Company's Financial Status and Market Position | |
| Impact of the Incident on Stakeholders such as (Company Clients, Partners, ...) |
| Response and Recovery Measures | |
|---|---|
| Incident Response Measures | |
| Corrective Measures for the Incident Cause | |
| Preventive Measures | |
| Incident Status (Closed, In Progress) |
Form (1/1/09)
CENTRAL BANK OF JORDAN
البنك المركزي الأردني
Guide for Filling Out
Cyber Incident Notification Form
Form (1/1/09)
CENTRAL BANK OF JORDAN
البنك المركزي الأردني
| Time and Date of Incident Occurrence | : | The time and date when the incident occurred, in the format (minute : hour, day/month/year) |
|---|---|---|
| Time and Date of Incident Discovery | : | The time and date when the incident was discovered, in the format (minute : hour, day/month/year) |
| Time and Date of Incident Correction | : | The time and date when the problem was corrected or expected to be corrected, in the format (minute : hour, day/month/year) |
| Contact Person Information | ||
|---|---|---|
| Contact Person Name | : | The name of the authorized contact person responsible to the Central Bank for providing the Cyber Incident Notification Form (primary or alternate), who must be among those previously provided to the Central Bank |
| Phone Number | : | The company's phone number and the extension of the designated contact person |
| Mobile Number | : | The mobile number of the designated contact person |
| Incident Details | ||
|---|---|---|
| Incident Type | : | The type of incident that affected the company, including but not limited to (Ransomware, Data breach, DDOS,...) |
| Infrastructure Components Affected by the Incident | : | The company's infrastructure components affected by the incident, including but not limited to (Network Level, Hardware Level, Database Level, Server Level, Application Level, OS Level, ......) |
Form (1/1/09)
CENTRAL BANK OF JORDAN
البنك المركزي الأردني
| Incident Location | : | The physical location affected by the incident (Main Site, DR Site, HA Site) |
|---|---|---|
| Incident Severity Classification | : | Incident severity classification (Crisis, Major, Minor, Negligible) |
| Causes Leading to the Incident | : | State the cause of the incident if known by the company, for example (Unpatched Operating Systems, ......) |
| Has this incident occurred before? | : | Answer Yes or No regarding the recurrence of the incident |
| Department or Entity Responsible for Incident Management | : | The department, entity, or third party responsible for monitoring and resolving the incident, including but not limited to (IT Department, Information Security Department....) |
| Incident Impact Assessment | ||
|---|---|---|
| Impact of the Incident on Company Operations Regarding Service Availability | : | Did the cyber incident cause any of the company's services to be interrupted? Specify them |
| Channels Affected by the Incident | : | What are the channels affected by the cyber incident? For example (Online, Mobile Application,...) |
| Impact of the Incident on Company Systems and Technologies (Disruption of critical systems, disruption in any infrastructure components) | : | The impact of the incident on the company's systems, network, and classified sensitive infrastructure |
Form (1/1/09)
CENTRAL BANK OF JORDAN
البنك المركزي الأردني
| Impact of the Incident on the Company's Information System (Confidentiality, Integrity, and Availability) | : | Was the company's information system affected by the cyber incident in terms of Confidentiality, Integrity, and Availability? And to what extent? |
|---|---|---|
| Impact of the Incident on the Company's Financial Status and Market Position | : | The extent of the company's impact from the incident financially, reputationally, and in terms of market presence |
| Impact of the Incident on Stakeholders such as (Company Clients, Partners, ...) | : | The extent of the impact on stakeholders (Stakeholders), including but not limited to (Customers, Service providers, Business partners, .....) |
| Response and Recovery Measures | ||
|---|---|---|
| Incident Response Measures | : | What measures were followed immediately upon discovering the incident to limit its spread and expansion and prevent further damage? |
| Corrective Measures for the Incident Cause | : | What measures were followed subsequently to discover the incident in terms of correcting the cause or fault that led to the incident? |
| Preventive Measures | : | Measures taken to prevent the occurrence/recurrence of similar incidents in the future |
| Incident Status (Closed, In Progress) | : | Has the correction and resolution of the problem been completed? Or is work still ongoing? |
Form (1/1/09)
Read the rest free
Source: Central Bank of Jordan — original document · Summary generated with machine assistance and reviewed before publication; the authoritative text is the regulator's original document. How RegAlert works
More like this from CBJ
We email you every new CBJ publication the day it's published.