2013-10-24
Added · Updated
The Central Bank of Jordan mandates that licensed exchange companies implement specific technical and administrative controls to secure remittance systems against hacking. The circular requires the use of licensed software, regular updates, network firewalls, physical security, and strict access controls, while prohibiting the use of untrusted external storage media. These obligations apply to all personal computers and devices used in remittance operations, with designated technical departments responsible for monitoring compliance and managing user permissions.
In the Name of Allah, the Most Gracious, the Most Merciful
[Logo of the Central Bank of Jordan]
Number: 12229 Date: 14/12/1434 AH Corresponding to: 6/10/2013 AD
Circular to Licensed Exchange Companies Subject: Guidelines to Mitigate Risks of Hacking in Remittance Systems
Greetings,
With the Central Bank of Jordan's commitment to the safety and efficiency of banking transactions executed by exchange companies and to safeguarding the rights of customers, please adhere to the following guidelines to mitigate the risks facing your transactions in the field of remittance services:
It is essential that all personal computers used in remittance systems are properly equipped with all necessary software, such as the operating system, antivirus and malware protection, and remittance system software, using original and licensed software installed according to the steps specified by the software manufacturers.
It is essential to continue updating operating systems, antivirus and malware protection, and remittance systems periodically and properly according to the recommendations of the manufacturers.
It is essential to use remittance systems according to the recommendations and directives of the manufacturer and to provide adequate training for employees on the proper usage of the system.
It is essential that computers used for remittance systems do not contain unnecessary operating systems and programs, and that these computers are not used for other purposes.
It is essential not to allow the use of external storage media, such as optical discs and USB flash drives, from untrusted sources due to the possibility of containing malicious software.
It is essential to keep original storage media and any documents containing passwords or secret numbers provided by all device and system suppliers in a secure place after the installation of systems, and not to allow them to be removed or copied except when necessary.
It is essential to protect the network connection with devices used in remittance systems by installing various protection devices between them and the connection point with these systems, such as firewalls and intrusion prevention/detection systems (IPS/IDS). There must be a technical department within your organization to define, manage, and monitor these installations according to the requirements of the manufacturers.
It is essential to protect the equipment used for remittance systems securely, ensuring that physical access is allowed only to authorized personnel (Physical Security).
It is essential to manage device and system usage permissions, specifying who can use any device and when (Access Controls), as well as user authentication processes. There must be a technical department within your organization to monitor the granting and revocation of permissions. It is also necessary to confirm to all users that usernames and passwords are not shared among multiple persons, and to deactivate accounts and change passwords upon any staff changes, such as resignation.
It is essential that the connection with remittance companies is protected, according to the security requirements issued by the manufacturer (Security Requirements), such as the use of encryption technologies.
It is essential to provide adequate specialized training to employees working on devices regarding proper methods for using devices and systems, as well as to increase employee awareness regarding the risks of malicious software and methods of prevention.
Please accept our highest regards,
The Governor Dr. Ziad Fariz
P.O. Box 2700, Amman 11118 - Jordan Phone: 9 * 4630301 / Fax: 4638889, 4639730 Website: www.cbj.gov.jo Email: info@cbj.gov.jo
Generated by CamScanner from intsig.com