2023-06-02 | A 7783Added
The Central Bank of Argentina amends its technology and information security risk regulations by approving new minimum requirements for digital financial services, derogating Section 11 of the previous norms, and extending the scope of these norms to systemic payment system infrastructures (INTERBANKING, COELSA, LINK, and PRISMA). The document also repeals the norms on minimum operational requirements for information systems technology and establishes an effective date of 180 calendar days from the date of dissemination. Financial entities, payment service providers, electronic clearing houses, ATM networks, and financial market infrastructures are required to implement these controls, including specific authentication, device security, and client identification measures.
BCRA published 13 documents in the last 30 days — get each new one by email the day it lands.
1983/2023 - 40 YEARS OF DEMOCRACY
COMMUNICATION “A” 7783 02/06/2023
TO FINANCIAL ENTITIES,
TO ELECTRONIC CLEARING HOUSES,
TO ATM NETWORKS,
TO PAYMENT SERVICE PROVIDERS,
TO FINANCIAL MARKET INFRASTRUCTURES:
Ref.: Circular
RUNOR 1-1799:
“Minimum Requirements for the Management and Control of Technology and Information Security Risks”. Adaptations. “Minimum Requirements for the Management and Control of Technology and Information Security Risks Associated with Digital Financial Services.” Regulation. ___________________________________________________________________________ We address you to inform you that this Institution has adopted the following resolution:
“1. Approve the norms on “Minimum Requirements for the Management and Control of Technology and Information Security Risks Associated with Digital Financial Services” which are contained in the annex and form part of this communication.
2. Repeal Section 11 of the norms on “Minimum Requirements for the Management and Control of Technology and Information Security Risks”.
3. Extend the scope of the norms on “Minimum Requirements for the Management and Control of Technology and Information Security Risks” to Financial Market Infrastructures known as Systemically Important Payment Systems: INTERBANKING, COELSA, LINK and PRISMA.
4. Render ineffective the norms on “Minimum Operational Requirements for the Information Systems (IS) area – computer technology”.
5. Establish that these provisions will enter into force 180 calendar days from the date of their dissemination.”
Finally, we send you the sheets that, in replacement of those previously provided, will need to be incorporated into the norms on “Minimum Requirements for the Management and Control of Technology and Information Security Risks”. Likewise, we remind you that on this Institution’s website www.bcra.gob.ar, by accessing “Financial System - LEGAL AND REGULATORY FRAMEWORK - Orders and summaries - Consolidated texts of general regulations”, the modifications made with text highlighted in special characters (strikethrough and bold) will be found. We salute you attentively.
-2-
CENTRAL BANK OF THE ARGENTINE REPUBLIC
Mara I. Misto Macias María D. Bossio Signature 2 Signature 1 Principal Manager of Security Standards for Information in Entities General Submanager of Financial Regulation Functional Position Functional Position
ANNEX
-Index
Section 1. General Provisions.
1.1. Obligated Subjects.
1.2. General Aspects.
Section 2. Risk Management of Financial Services Provided via Digital Means.
Section 3. Protection of Financial Services Provided via Digital Means.
3.1. Guidelines to Consider in Digital Financial Transactions.
3.2. Devices and Applications Provided by the Organization.
3.3. Digital Identification of Clients.
3.4. Access Control. Requirements for Authentication Factors.
3.5. Training and Awareness.
Section 4. Detection and Monitoring.
4.1. Detection and Analysis of Events.
4.2. Monitoring of Client Activity and Transactions.
Section 5. Glossary.
Correlation Table
B.C.R.A.
CONSOLIDATED TEXT OF THE NORMS ON “MINIMUM REQUIREMENTS FOR THE MANAGEMENT OF TECHNOLOGY AND INFORMATION SECURITY RISKS ASSOCIATED WITH DIGITAL FINANCIAL SERVICES” Version: 1st. COMMUNICATION “A” 7783 Validity:
29/11/2023 Page 1
1.1. Obligated Subjects.
1.1.1. Financial Entities.
1.1.2. PSPs.
1.2. General Aspects.
A digital financial service is defined as any provision of financial services to clients via digital means to perform at least, transfers, payments, withdrawals, queries or other online operations, permitted by current regulations. The Board of Directors or equivalent authority of the covered subject is primarily responsible for establishing organizational structures, control models and risk management related to the provision of financial services via digital means, and for supervising the application of these, with Senior Management being responsible for their implementation. In accordance with what is established in the norms on “Minimum Requirements for the Management and Control of Technology and Information Security Risks”, the covered subjects must implement, in addition to the set of processes that support the financial service solutions provided to clients via digital means, adequate management of:
The following sections establish a set of minimum requirements applicable to financial services provided via digital means. According to the results of their risk management, covered subjects must identify and implement additional controls to those established in this communication. Covered subjects must notify the External Systems Audit Management of their knowledge regarding all projects that involve a new product or type of service in the provision of financial services via digital means to clients. They must inform, at least 60 days before going into production, including the characteristics of the product or service, the protection measures adopted, authentication factors used, planned monitoring activities, activities for cyber incident management, among others. B.C.R.A. MINIMUM REQUIREMENTS FOR THE MANAGEMENT OF RISKS OF TECHNOLOGY AND INFORMATION SECURITY ASSOCIATED WITH DIGITAL FINANCIAL SERVICES
Section 1. General Provisions.
Version: 1st. COMMUNICATION “A” 7783 Validity:
29/11/2023 Page 2
Covered subjects must apply principles and practices that allow them to identify, analyze and mitigate risks linked to the provision of financial services via digital means, in accordance with what is established in the norms on “Minimum Requirements for the Management and Control of Technology and Information Security Risks”. Risk analyses must consider, at a minimum, the following:
a. Operational risks, especially those related to internal and client fraud, and those linked to technology and information security. b. Risks inherent to the means by which digital financial services are provided.
c. Risks linked to the non-presential account opening of clients, the authentication factors of clients and the authorization or confirmation of instructions performed by clients in digital services.
d. The impact on the organization's integral risks. e. Scenarios that affect operational resilience.
B.C.R.A.
MINIMUM REQUIREMENTS FOR THE MANAGEMENT OF RISKS OF TECHNOLOGY AND INFORMATION SECURITY ASSOCIATED WITH DIGITAL FINANCIAL SERVICES
Section 2. Risk Management of Financial Services Provided via Digital
Means.
Version: 1st. COMMUNICATION “A” 7783 Validity:
29/11/2023 Page 1
3.1. Guidelines to Consider in Digital Financial Transactions.
Covered subjects must have duly identified and documented the digital services provided and the functionality of each of them. Likewise, they must design and implement controls for transactions in accordance with the results of risk management and threat and vulnerability management. These controls must be adapted based on the defined transactional monitoring scenarios. In this framework, they must consider, at a minimum, the following criteria:
a. The client must be identified and authenticated to perform any type of transaction. b. Implement multi-factor authentication techniques appropriate to risk levels, the result of transactional monitoring and/or when exceeding thresholds established by the organization.
3.1.1. Confirmation of Critical Actions.
They must apply multi-factor authentication techniques or digital identification of the client, in the confirmation or authorization for the execution of at least the following critical actions:
a. Creation, enablement and rehabilitation of authentication factors. b. Subscription to new products or services, request for pre-approved credits or acceptance of new terms of use.
c. Changes of contact points or parameters related to transactional operation.
d. Agenda of third-party accounts for transfers. e. Confirmation of transactions that deviate from predetermined patterns in transactional monitoring systems.
3.1.2. Confirmation of Non-Critical Actions.
For low-risk actions, they may use questionnaires preconfigured by the client with random presentation, or the exchange of a non-predictable and single-use secure code.
3.1.3. Services Based on Telephone Attention or Messaging Platforms.
When, to operate with their accounts, services based on telephone attention or messaging platforms are used, they must:
a. Enable functionality in accordance with the results of risk analyses and the strength of authentication factors.
B.C.R.A.
MINIMUM REQUIREMENTS FOR THE MANAGEMENT OF RISKS OF TECHNOLOGY AND INFORMATION SECURITY ASSOCIATED WITH DIGITAL FINANCIAL SERVICES
Section 3. Protection of Financial Services Provided via Digital Means.
Version: 1st. COMMUNICATION “A” 7783 Validity:
29/11/2023 Page 1
b. Implement a real-time record of all information linked to the execution of transactions.
c. Avoid the exposure of the authentication factors employed in other digital financial services.
d. Effect immediate return of the amounts involved in case of client unawareness of a transaction performed via this channel, being able to subsequently conduct the investigations they deem necessary.
3.2. Devices and Applications Provided by the Organization.
Covered subjects must design and implement security measures for devices and/or applications provided to clients to offer digital financial services that are appropriate to the results of risk management and threat and vulnerability management. Devices and applications provided by the organization refer to any digital medium offered to the client to access digital financial services. By way of example, among the provided devices are ATMs, self-service terminals and digital kiosks; while, among the provided applications, are mobile banking, internet banking and digital wallets. In accordance with what is established in Section 9 of the norms on “Minimum Requirements for the Management and Control of Technology and Information Security Risks”, they must consider information security aspects throughout the lifecycle of devices and applications provided to clients. They must apply controls such as:
a. the data exchanged must remain encrypted throughout the interaction with the client, b. implement measures to detect and terminate unauthorized client sessions,
c. disable the service and prevent the entry of client authentication factors when failures that compromise the security of the service occur, and
d. when redirecting the client of the digital financial service to third-party sites that allow the execution of banking transactions, the client's authentication factors must not be shared with those third parties.
3.2.1 Applications Provided by the Organization.
In the implementation of applications in environments controlled by the client, the covered subject must establish at a minimum the following controls:
B.C.R.A.
MINIMUM REQUIREMENTS FOR THE MANAGEMENT OF RISKS OF TECHNOLOGY AND INFORMATION SECURITY ASSOCIATED WITH DIGITAL FINANCIAL SERVICES
Section 3. Protection of Financial Services Provided via Digital Means.
Version: 1st. COMMUNICATION “A” 7783 Validity:
29/11/2023 Page 2
a. Use installation methods that limit the exposure of personal, financial data or client authentication factors. b. Inform the client of the criteria for device admissibility, as well as hardware, software, connectivity and environment limitations for their use. Likewise, they must inform the security requirements applicable to the client's own devices.
c. Prevent access through a device that does not satisfy the established admissibility criteria.
d. Apply measures that mitigate risks linked to the operating system configurations of mobile devices. e. Request exclusively the minimum permissions necessary to operate in the application. f. As part of the identification elements, associate the application with the mobile device and with the client, both at the time of registration or in a subsequent reinstallation. g. Validate that the device in use is the one associated by the client and implement SIM change and line used controls. h. Provide mechanisms for blocking access to the application and automatic session blocking due to inactivity (“timeout”).
3.2.2. Devices Provided by the Organization.
Devices must be identified and authenticated to operate.
The homologation processes of the devices that allow interaction with the client must include a formal verification and approval before their enablement. When devices use physical or virtual keyboards, authentication factors must be encrypted immediately after entry. Furthermore, authentication data must not be stored on the device provided by the organization nor kept in the activity log.
3.2.2.1. Protection of Audit Logs.
They must implement protection measures for audit logs, both digital and printed. The applied controls must be appropriate to the results of risk analyses and evaluate at a minimum:
a. storage conditions, b. mechanisms for their transfer, B.C.R.A.
MINIMUM REQUIREMENTS FOR THE MANAGEMENT OF RISKS OF TECHNOLOGY AND INFORMATION SECURITY ASSOCIATED WITH DIGITAL FINANCIAL SERVICES
Section 3. Protection of Financial Services Provided via Digital Means.
Version: 1st. COMMUNICATION “A” 7783 Validity:
29/11/2023 Page 3
c. techniques or methods for secure erasing and/or destruction of the supports used, and
d. access control measures.
3.2.2.2. Physical Controls on Provided Devices.
Devices must incorporate features that reduce the risk of copying, obstruction, third-party viewing or illegal retention of authentication factors and monetary values, considering, but not limited to, the application of the following controls:
a. Object detectors attached to devices provided by the organization. b. Anti-skimming components in the entry of authentication factors.
c. Mechanisms for detecting opening, violation or alteration of the physical and/or logical conditions of the device.
3.2.2.3. Controls in the Maintenance, Configuration, Opening, Loading and Balancing of
Provided Devices.
The maintenance, configuration, opening, loading and balancing processes of devices provided by the organization must:
a. Implement physical and logical segregation between administration activities (installation, configuration and parameter adjustment in the operating system and application) and device operation (execution of operational tasks for query, balancing and reporting). b. Apply dual control in the opening and closing of the device and treasury for the use and temporary possession of physical and/or logical keys.
c. Provide control tasks from the organization between backup documentation and registered operational activities.
3.2.2.4. Transaction Receipt.
Devices provided by the organization must provide the client with the possibility to print or send the receipt of the transaction performed to the previously indicated contact point. B.C.R.A. MINIMUM REQUIREMENTS FOR THE MANAGEMENT OF RISKS OF TECHNOLOGY AND INFORMATION SECURITY ASSOCIATED WITH DIGITAL FINANCIAL SERVICES
Section 3. Protection of Financial Services Provided via Digital Means.
Version: 1st. COMMUNICATION “A” 7783 Validity:
29/11/2023 Page 4
3.3. Digital Identification of Clients.
When covered subjects admit the identification of natural persons in a digital and non-presential manner, they must design processes that allow corroborating the unique correspondence of the required data or elements with the data of the natural person intended to be identified. During the client identification process, they must apply controls to determine at a minimum the following:
a. validation of the real presence of the natural person with proof of life, b. validation of declared contact points and the mobile device associated with the client, and
c. validation of biometric elements and documentation presented with public bodies.
Complementary techniques must be used to verify the identity of the financial service client in the digital registration process in accordance with the results of risk analyses and the effectiveness of implemented controls.
3.3.1. Uncompleted Registration Process.
In case the registration process is not completed, the following controls must be applied to the data collected during the process:
a. Do not communicate to the client the reasons for errors or failures that occurred in the identification process. b. The collected data must be deleted through a secure erasure process.
c. Data retained for statistical purposes must be dissociated or anonymized.
3.4. Access Control. Requirements for Authentication Factors.
The values associated with access identifiers used in digital financial services cannot include personal or public data of the client and options allowing their modification must be offered. They must establish the following minimum measures for the protection of authentication factors of digital financial service clients throughout their lifecycle:
a. they cannot be known by the organization's staff or third parties, b. they can only be stored for verification, implementing additional measures to safeguard their confidentiality, and B.C.R.A. MINIMUM REQUIREMENTS FOR THE MANAGEMENT OF RISKS OF TECHNOLOGY AND INFORMATION SECURITY ASSOCIATED WITH DIGITAL FINANCIAL SERVICES
Section 3. Protection of Financial Services Provided via Digital Means.
Version: 1st. COMMUNICATION “A” 7783 Validity:
29/11/2023 Page 5
c. they must implement cryptographic techniques for their protection.
The implemented authentication factors must consider the provisions established in point 5.7.2 of the norms on “Minimum Requirements for the Management and Control of Technology and Information Security Risks”. In addition, the particular provisions defined below must be applied.
3.4.1. Memorized Secret:
Authenticators based on memorized secrets (or something “you know”) must comply with the following controls:
a. Minimum length, not less than 8 characters. b. Character composition including lowercase and uppercase letters, numbers and special characters.
c. Change in the first use of memorized secrets generated by the organization.
d. Limitation of the exposure of memorized secrets during their entry. e. Limitation of entry speed through automated access under certain scenarios (e.g.: Captcha). f. Limitation of failed entry attempts. Define a failed attempt counter reset policy in accordance with the risk analysis. g. In creation or modification, detailed information must be provided to clients on minimum requirements for the strength of the memorized secret and the reasons for rejection.
3.4.2. Out-of-Band Authentication.
Out-of-band authenticators must comply with the following controls:
a. Not be visible when the receiving device is locked. b. Comply with the requirements defined for One-Time Passwords (OTP).
c. The use of a registered device for reading graphic cryptograms displayed on screen.
3.4.3. One-Time Passwords (OTP).
When authenticators based on One-Time Passwords (OTP) are used, they must implement the following controls:
a. Measures to detect possession and control of the device where the OTP is displayed.
B.C.R.A.
MINIMUM REQUIREMENTS FOR THE MANAGEMENT OF RISKS OF TECHNOLOGY AND INFORMATION SECURITY ASSOCIATED WITH DIGITAL FINANCIAL SERVICES
Section 3. Protection of Financial Services Provided via Digital Means.
Version: 1st. COMMUNICATION “A” 7783 Validity:
29/11/2023 Page 6
b. The definition of a validity time for the generated value not exceeding 120 seconds.
c. The definition of a minimum length of 6 digits.
d. Definition of a seed length that ensures the generation of unique values. e. Channel or transmitted information encryption.
3.4.4. Payment cards (debit, credit, or prepaid) and physical authentication elements.
The distribution processes for payment cards or physical tokens must consider, at a minimum, the following controls:
a. Authentication factors that are associated shall not be distributed through the same medium. b. Traceability of actions performed must be ensured.
c. Authentication elements must be disabled during their distribution.
3.4.4.1. Replacement of provided authentication factors
Based on the results of risk analyses, the authentication factors provided to the affected subjects must be replaced, at a minimum, when situations such as the following occur:
a. Expiration. b. Report of theft, loss, or deterioration.
c. Unrecognized transactions.
d. Detection of possible cyber incidents or compromise points affecting them. e. Detection of manufacturing or generation failures, loss during distribution, and/or storage.
3.4.4.2. Authentication factors retained or not delivered to the client.
These factors must be destroyed or disconnected from the client and their accounts within a period not exceeding 30 business days.
3.4.4.3. Authentication factors based on cards with integrated circuits (chips).
For the secure use of these factors, the following controls must be considered at a minimum:
a. Dynamic card authentication mechanisms. b. Mechanisms that prevent duplication or alteration.
c. Encryption of data stored in the integrated circuits.
d. Inclusion of holograms, security codes, brand identification, and issuer organization. e. Operation with magnetic stripe reading on cards must be limited and justified for those with a dual system (magnetic stripe and chip). f. Contactless cards that do not have an additional authentication factor must strengthen usage and transactional monitoring.
3.4.4.4. Authentication factors based on magnetic stripe cards
For the secure use of these factors, organizations must consider at least the following controls:
a. The card verification code (CVV) must not be stored on the magnetic stripe. b. Monitoring of the usage and transactional activity of cards that do not have an additional authentication factor must be strengthened. Additionally, the memorized secret (PIN) associated with payment cards must:
c. Have a length of at least 4 digits.
d. Not consist of the same number. e. Not be consecutive. f. The PIN must be authenticated online.
3.5. Training and awareness.
Based on what is established in point 5.5 of the regulations on “Minimum Requirements for the Management and Control of Technology and Information Security Risks,” organizations must develop specific training and awareness plans for digital financial services that include at least:
a. Information on contact points established by the organization and guidelines for verifying if they are genuine. b. Information on communication channels used by the organization to notify clients of situations that could compromise their security. In particular, the precautions to be taken to identify the organization's official social media accounts.
c. Information regarding configurable or parameterizable aspects that the client has in the digital financial service.
d. Specific recommendations on the secure use and configuration of devices belonging to the digital financial service client. e. Information on social engineering techniques and regarding security measures to protect against these techniques. f. Specific recommendations on the secure use of devices or applications provided by the organization. g. Information on the procedure the client should follow in the event of unrecognized transactions, such as how to file complaints, how to act in cases of suspected fraud, or in situations of ongoing fraud, among others. Plans must be updated based on changes to products and services made available to clients. For updates, the results of transactional monitoring, new attack techniques, and cyberincident management must also be considered.
3.6. Communication channels.
The affected subjects must provide communication channels, available 24 hours a day, to their financial service clients for receiving, attending to inquiries and complaints, and notifying of cyber incidents and/or suspicious situations. The organization must provide the client with a receipt so that they can follow up on the communication made. Additionally, organizations must implement alternative communication mechanisms with their clients to notify alarms or alerts arising from the implemented transactional monitoring. Communication channels must be documented, use previously validated client contact points, and inform about events such as:
a. Activation, deactivation, linking, or rehabilitation of authentication factors. b. Modification of personal data or parameters for transacting.
c. Transactional information.
The affected subjects must make the following information available to their clients in digital financial services:
4.1. Detection and analysis of events.
The affected subjects must establish a process for recording and analyzing information related to security events of systems, networks, and the technological infrastructure supporting digital financial services, in accordance with point 5.8 of the regulations on “Minimum Requirements for the Management and Control of Technology and Information Security Risks.” Additionally, all systems and applications supporting digital financial services must generate audit logs that ensure the traceability of each action performed, in accordance with point 9.1 of the regulations on “Minimum Requirements for the Management and Control of Technology and Information Security Risks.”
4.2. Monitoring of client activity and transactions.
In accordance with point 3.1, the affected subjects must define a monitoring strategy that allows detecting unusual activities or suspicious transactions by their clients in digital financial services. The implemented transactional monitoring solutions must consider the results of risk analyses, behavior patterns, and the usual circumstances of service usage and the authentication factors used. Furthermore, they must apply at least the following criteria:
a. The classification of initiators and recipients based on account characteristics for the determination of thresholds, patterns, and dynamic alerts. b. Frequency of transactions by type, transaction amounts, and usual account balances.
c. Compromised authentication factors, known fraud patterns, and signs of malicious programs on the devices used.
d. Client behavior patterns in the use of the device or application provided by the organization. e. The identification of common compromise points that may affect transactions processed by clients.
Additionally, transactional monitoring on authentication factors delivered by the organization must facilitate the detection, recording, and control of situations that establish a compromise of sensitive data. Based on the detected alerts, they must define action models in accordance with the results of risk analyses, behavior patterns, and the usual circumstances of application usage and authentication factors. The models may combine preventive, reactive, and assumed measures. Namely:
The following definitions complement the regulations on “Minimum Requirements for the Management and Control of Technology and Information Security Risks” and the glossary published online at the following URL:
https://www.bcra.gob.ar/SistemasFinancierosYdePagos/Ciberseguridad.asp#Glosario
Anti-skimming: refers to systems to combat crimes at ATMs or similar, prevent identity theft, and reduce fraud.
Fake applications: refers to applications that appear to be legitimate. Generally, they may be available in application stores or official or unofficial websites for the different mobile operating systems in the market. Cybercriminals design and name them in such a way that they appear to be real. Financial service client: the term “financial service client” refers to the human or legal person who is identified and subscribed to the services of one or more affected subjects. Journal or audit trail: comprises the physical or logical mechanisms established for recording access activity to services and instruction of operations of devices provided by the organization. Transactional monitoring action models: guidelines and/or measures to be applied upon the detection of unusual or suspicious transactions. They may combine measures of the type:
TEXTO ORDENADO NORMA DE ORIGEN OBSERVACIONES Secc. Punto Párr. Com. Anexo Sec. Punto Párrafo.
1.
1.1. “A”
7783
1.
1.2. “A”
7783
1.
2
“A”
7783
3.
3.1. “A”
7783
1.
3.1. “A”
7783
1.
3.3. “A”
7783
1.
3.4. “A”
7783
1.
3.5. “A”
7783
1.
4.
4.1. “A”
7783
1.
4.2. “A”
7783
1.
5. “A”
7783
1.
-Index
Section 7. Technological infrastructure and processing.
7.1. Technological infrastructure management.
7.2. Change management.
7.3. Technological infrastructure update.
7.4. Communications management.
7.5. Data processing.
7.6. Data backup management.
7.7. Monitoring of technological infrastructure and processing.
Section 8. Cyberincident management.
8.1. Cyberincident response preparation.
8.2. Cyberincident response exercises and tests.
8.3. Management control and reports.
Section 9. Development, acquisition, and maintenance of “software.”
9.1. Requirements for systems and applications.
9.2. “Software” lifecycle management.
Section 10. Third-party relationship management.
10.1. Third-party relationship management framework.
10.2. Formalization of the relationship.
10.3. Control and monitoring.
10.4. Internal and external audit reports.
Section 11. Glossary of terms.
Correlation table.
1.1. Obligated subjects
1.1.1. Financial entities.
1.1.2. Financial Market Infrastructures known as Systemically Important Payment Systems: INTERBANKING, COELSA, LINK, and PRISMA.
1.2. General aspects
The obligated subjects indicated in point 1.1., hereinafter referred to as “entities” for the purposes of this regulation, must ensure the implementation of effective practices for internal control and risk management of their technology and information security operational environment. To this end, they must demonstrate understanding of the risks and establish a framework for their management in accordance with the complexity of the financial services offered and the technology supporting them. The following sections establish a set of minimum requirements, applicable to processes, structures, and information assets, which entities must implement with the purpose of:
Asset: tangible or intangible resource of value that should be protected, comprising people, information, infrastructure, finances, and reputation.
Information asset: data, information, software (programs, applications, information systems, databases), hardware.
Threat: circumstance that could exploit one or more vulnerabilities and affect cybersecurity.
Anomaly: unexpected event, behavior, or operation.
Risk appetite: estimate indicating how much risk the organization is willing to accept within its usual operations.
Machine learning: branch of artificial intelligence consisting of enabling a computer to draw conclusions from the statistical analysis of input data, through a process that improves automatically as more evidence is incorporated into the algorithm. Enterprise architecture: model that describes the complete set of an entity's information systems: how they are configured, how they are integrated, how they interact with the external environment, how they are operated to support the mission, and how they contribute to strategic objectives. Authentication: process designed to establish the source of information, the validity of a transmission, message, or issuer, or a method to verify an individual's authorization to receive or access specific categories of information. Out-of-band authentication: use of physical devices in the user's possession, which have a unique identification and communicate with the entity through a channel different from the application in which the user operates. Its objective is to prove possession and control of the device by the requester. Multi-factor authentication (MFA): authentication process that requires more than one factor for the requester to obtain access to resources or information. For authentication to be successful, all presented factors must be correct. Multi-factor authentication can be implemented in three (3) ways:
Cybersecurity: preservation of the confidentiality, integrity, and availability of information and/or information systems through a cyber medium. Additionally, other properties, such as authenticity, accountability, non-repudiation, and reliability, may also be involved.
One-Time Passwords (OTP): key, password, or one-time codes generated by software or via a device.
Malicious code (malware): software with a malicious objective that contains characteristics or capabilities that could cause direct or indirect damage to entities or their information systems.
Governance components: the processes, organizational structure; the people, skills, and competencies; the policies, standards, and procedures, and the culture and leadership that are part of a governance framework.
Reliability: uniformity in terms of behavior and desired results.
Confidentiality: the property of information not being made available or disclosed to unauthorized individuals, entities, or processes.
Business continuity: the capacity of an organization to continue providing products and services within acceptable timeframes, and with a predefined capacity, during a disruption.
Data: A piece of information.
Customer data: customer information that allows revealing or inferring their identity, personal credentials, commercial relationship, and/or financial position, limited, restricted, and/or protected by the Personal Data Law (Law 25.326), the Financial Entities Law (Law 21.526), and specific norms of the BCRA.
Accounting data: information referring to balances, statements, and assets of the financial entity or its clients, not individualized.
Transactional data: individual or related instructions that order financial movements in the accounts of one or more clients, capable of verification and approval before their completion or confirmation.
Availability: the property of information being accessible and usable when required by an authorized entity.
Cryptographic devices: devices that contain one or more secret keys (symmetric or asymmetric) that they use to perform a cryptographic operation for authentication (usually a signature). Cryptographic devices can also be of one or multiple factors:
One-time code generation devices: devices that generate one-time codes. A device is considered multifactor when it requires a prior authentication factor to access the one-time code.
Disruption: an event that causes an unplanned negative deviation in the delivery of products or services according to the organization's objectives.
Event: occurrence or change of a particular set of circumstances.
Information security event: any observable occurrence that is relevant to information security. This may include attack attempts or failures that reveal existing security vulnerabilities. Security events sometimes indicate that a cyber incident is occurring.
BCRA.
MINIMUM REQUIREMENTS FOR THE MANAGEMENT AND CONTROL OF TECHNOLOGY AND INFORMATION SECURITY RISKS
Section 11. Glossary of Terms
Version: 2nd. COMMUNICATION "A" 7783 Validity:
29/11/2023 Page 2
Explainability: the capacity to provide meaningful, context-appropriate, and coherent information that allows understanding the results of applying machine learning and artificial intelligence techniques.
Authentication Factors (AF): evidence that serves to demonstrate the applicant's identity and, therefore, overcome authentication. Authentication factors are divided into three (3) categories:
Data management: development of activities to establish policies, procedures, and best practices that ensure data is understandable, reliable, visible, accessible, and interoperable.
Project management: coordinated management of the set of projects to achieve specific business objectives.
Identification: the process by which someone or something previously unknown becomes known.
Technological infrastructure / IT infrastructure: subset of the infrastructure comprising hardware, networks, software, and firmware.
Integrity: quality of being exact and complete.
Artificial Intelligence (AI): set of theories and algorithms that allow carrying out tasks that typically require capabilities inherent to human intelligence.
Threat intelligence: information about threats that has been aggregated, transformed, analyzed, interpreted, or enriched to provide the necessary context for decision-making processes.
Management framework: refers to a coordinated set of planning, implementation, operation, monitoring, and continuous improvement processes.
Three Lines Model: scheme that defines 3 levels for the assignment of roles and responsibilities for effective risk management and control by opposition.
Business continuity plan: documented collection of procedures and information for use in an incident with the objective of allowing an organization to continue delivering its critical products and services at an acceptable level.
Policy: a document that records high-level principles or an agreed course of action; general direction and intention expressed formally.
Practice: activity performed in a recurrent manner.
Procedure: method composed of a sequence of steps that must be followed to complete a task or process.
Information owner: within the organization, the formal person responsible for defining and ensuring the integrity, confidentiality, and availability of certain information.
RPO (Recovery Point Objective): maximum tolerable loss of information in case of interruption.
RTO (Recovery Time Objective): Time during which an organization can tolerate the lack of functioning of its applications and the associated drop in service level, without affecting business continuity.
Memorized secret (key or password): data used for authentication. It can be created by a user, or created by the entity and delivered for use.
BCRA.
MINIMUM REQUIREMENTS FOR THE MANAGEMENT AND CONTROL OF TECHNOLOGY AND INFORMATION SECURITY RISKS
Section 11. Glossary of Terms
Version: 2nd. COMMUNICATION "A" 7783 Validity:
29/11/2023 Page 3
Information security: the preservation of the integrity, availability, and confidentiality of information. Additionally, it may include authenticity, traceability, accountability, non-repudiation, and reliability.
Shadow IT: refers to software, hardware, services, and devices not authorized by the organization that operate within the IT environment.
Outsourcing: practice under which a third party entrusts a subcontractor with part of what has been entrusted to them.
Third party: who provides processes, services, and/or activities that have been formally delegated by the entity according to what is established in Section 2 of the norms on "Expansion of financial entities". Included within this definition are entities belonging to a corporate group (global or domestic) or an entity external to the corporate group, with which a contract has been established for the performance of processes, services, and/or activities.
Risk tolerance: acceptable level of variation with respect to the defined risk appetite in the achievement of the entity's objectives.
Vulnerability: weakness of an asset or control that can be exploited by one or more threats.
BCRA.
MINIMUM REQUIREMENTS FOR THE MANAGEMENT AND CONTROL OF TECHNOLOGY AND INFORMATION SECURITY RISKS
Section 11. Glossary of Terms
Version: 2nd. COMMUNICATION "A" 7783 Validity:
29/11/2023 Page 4
ORDERED TEXT ORIGIN NORM OBSERVATIONS Section Point Paragraph Comm. Chap. Point Paragraph 1.
1.1. "A" 7724 2. According to Comm. "A" 7783.
1.2. "A" 7724 2.
2.
2.1. "A" 7724 2.
2.2. "A" 7724 2.
2.3. "A" 7724 2.
3. "A" 7724 2.
4.
4.1. "A" 7724 2.
4.2. "A" 7724 2.
4.3. "A" 7724 2.
4.4 "A" 7724 2.
4.5. "A" 7724 2.
4.6. "A" 7724 2.
4.7. "A" 7724 2.
5.
5.1. "A" 7724 2.
5.2. "A" 7724 2.
5.3. "A" 7724 2.
5.4. "A" 7724 2.
5.5. "A" 7724 2.
5.6. "A" 7724 2.
5.7. "A" 7724 2.
5.8. "A" 7724 2.
6.
6.1. "A" 7724 2.
6.2. "A" 7724 2.
6.3. "A" 7724 2.
6.4. "A" 7724 2.
6.5. "A" 7724 2.
6.6. "A" 7724 2.
6.7. "A" 7724 2.
6.8. "A" 7724 2.
7.
7.1. "A" 7724 2.
7.2. "A" 7724 2.
7.3. "A" 7724 2.
7.4. "A" 7724 2.
7.5. "A" 7724 2.
7.6. "A" 7724 2.
7.7. "A" 7724 2.
8.
8.1. "A" 7724 2.
8.2. "A" 7724 2.
8.3. "A" 7724 2.
9. 9.1. "A" 7724 2.
9.2. "A" 7724 2.
10.
10.1. "A" 7724 2.
10.2. "A" 7724 2.
10.3. "A" 7724 2.
10.4. "A" 7724 2.
BCRA.
ORIGIN OF THE PROVISIONS CONTAINED IN THE NORMS ON "MINIMUM REQUIREMENTS FOR THE MANAGEMENT AND CONTROL OF TECHNOLOGY AND INFORMATION SECURITY RISKS"
Read the rest free
Source: Banco Central de la Republica Argentina — original document · Summary generated with machine assistance and reviewed before publication; the authoritative text is the regulator's original document. How RegAlert works
More like this from BCRA
BCRA published 13 documents in the last 30 days. We email you each new one the day it's published.