2018-04-30

Added · Updated

Circular to Licensed Exchange Companies on Email Security and Phishing Prevention

The Central Bank of Jordan mandates that licensed exchange companies implement specific email security controls to mitigate phishing and fraud risks. These requirements include enforcing multi-factor authentication, using strong encryption protocols like TLS, activating reverse DNS and SPF checks, blocking open mail relays, and scanning attachments for malware. Companies must also conduct periodic penetration tests by neutral parties, adopt a defense-in-depth strategy, and incorporate email risk examination into internal and external audit programs. Additionally, email usage policies must be integrated into the broader information security framework, with system logs retained for at least three months.

Central Bank of Jordan logo

Jordan

Central Bank of Jordan

Click to view thumbnail

[Logo of the Central Bank of Jordan]

Number: 8412 Date: 16/9/1438 AH Corresponding to: 11/6/2017 AD

Circular to Licensed Exchange Companies

In light of fraud operations conducted via fake, forged, or spoofed emails impersonating trusted individuals, whether internal or external, which aim to access sensitive information or deliver malicious files to facilitate more harmful electronic breaches affecting the company, its operations, and its reputation, I emphasize the necessity of providing the necessary controls in this regard, including taking the following measures:

First: Implement a policy for managing and defining email applications, protocols, and domains bearing the name of the exchange company on the internet, including the following minimum controls:

  1. Activate email protocols so that users can only access their accounts after identity verification through an authentication/verification policy that is difficult for others to breach, such as using a unique and unknown identifier and a password that forces the user to change it at specific time intervals, consisting of at least 8 characters including numbers, letters, and symbols, and not resembling a specific number of previously used historical symbols or any component of the identifier or user identity data. Multi-Factor Authentication (MFA) may be used, especially for email users whose nature of work is sensitive and has an impact and risk on the company and its reputation.

  2. Use strong encryption protocols (such as TLS) that are continuously updated according to the latest issued version, as much as possible, to ensure the protection of email communication processes.

  3. Activate the (Reverse DNS Check) feature to verify that the digital address (IP) of the sender of the incoming email matches the domain name and device from which it was issued.

  4. Take all possible technical measures to prevent receiving emails from sources that allow passing incoming mail via what is known as the (Open Mail Relay) technique.

  5. Take the necessary technical measures to prevent receiving emails via the (Open Mail Relay) technique as much as possible.

  6. Activate the (Real-time Blocking List (RBL) Check) feature, through which incoming messages from suspicious sources are blocked based on reliable and updated data lists for this purpose, in addition to internal lists built to achieve the same purpose.

  7. Activate the (Sender Policy Framework (SPF) Check) feature to reduce the probability of receiving emails from non-original sources.

  8. Block suspicious attachments and links within emails by scanning them with approved software for this purpose, and ban executable files, and set an allowed limit for attachment size, with the necessity of activating an appropriate policy on the email system to deal with such messages based on their risk level.

  9. Consider the possibility of defining limits for the number of connections to the email server from a single source, commensurate with the specifications of the email server and work requirements where necessary, with the necessity of utilizing availability features and business continuity plans for email services.

  10. Consider the possibility of activating the (DNSSEC) feature within your technical environment components as much as possible.

  11. Keep tracking logs of email systems for a time period determined within the data retention policy, not less than three months.

Second: Conduct necessary penetration tests by a neutral party periodically to ensure the activation of protection features, including those mentioned in the first item above.

Third: Work according to the principle of Defense in Depth by running protection systems from diverse sources within different levels (Different Security Tiers).

Fourth: Include email usage policy in the information security policy based on best international practices in this field, while adhering to the data classification policy when sending messages with confidential content and encrypting those messages where necessary.

Fifth: Include procedures for examining email risks in internal and external audit programs, including the matters mentioned above as a minimum.

Please accept our highest regards,

The Governor Dr. Ziad Frieze


Studies and Legislation Department Copy P.O. Box 27, Amman 11118 - Jordan Phone 94630301 / 4 Fax 4638889, 4639720 Website www.cbj.gov.jo Email info@cbj.gov.jo