2018-04-30

Added · Updated

Circular to Licensed Exchange Companies on Email Security and Phishing Prevention

The Central Bank of Jordan mandates that licensed exchange companies implement specific email security controls to mitigate phishing and fraud risks. These requirements include enforcing multi-factor authentication, using strong encryption protocols like TLS, activating reverse DNS and SPF checks, blocking open mail relays, and scanning attachments for malware. Companies must also conduct periodic penetration tests by neutral parties, adopt a defense-in-depth strategy, and incorporate email risk examination into internal and external audit programs. Additionally, email usage policies must be integrated into the broader information security framework, with system logs retained for at least three months.

Central Bank of Jordan logo

Jordan

Central Bank of Jordan

Click to view full text