2018-04-30
Added · Updated
The Central Bank of Jordan mandates that licensed exchange companies implement specific email security controls to mitigate phishing and fraud risks. These requirements include enforcing multi-factor authentication, using strong encryption protocols like TLS, activating reverse DNS and SPF checks, blocking open mail relays, and scanning attachments for malware. Companies must also conduct periodic penetration tests by neutral parties, adopt a defense-in-depth strategy, and incorporate email risk examination into internal and external audit programs. Additionally, email usage policies must be integrated into the broader information security framework, with system logs retained for at least three months.