2018-04-30

Added · Updated

Circular to Licensed Exchange Companies on Ransomware Protection

The Central Bank of Jordan mandates Licensed Exchange Companies to implement specific cybersecurity measures to mitigate ransomware risks. The circular requires the application of operating system updates, continuous antivirus scanning, strict privilege management, and the disabling of macro scripts in email attachments. It further obligates entities to maintain secure offline backups, conduct annual penetration tests, and immediately report any security breaches to the regulator.

Central Bank of Jordan logo

Jordan

Central Bank of Jordan

Click to view thumbnail

[Central Bank of Jordan Logo]

Number: 5/4/9/104 Date: 14/8/1438 AH Corresponding to: 14/5/2017 AD

Circular to Licensed Exchange Companies

In light of the attack operations targeting institutions and individuals around the world under what is known as (Ransomware) and its updated versions such as (WannaCry, WCry, Wanna Decryptor), we emphasize the necessity of acting in accordance with our previous circulars No. (3347/4/9) dated 22/3/2012 and No. (12329/7/9) dated 6/10/2013, and taking the following measures:

  1. Apply the latest updates for the operating system (Windows), specifically update (MS 010-017 SMB), on all devices running the aforementioned operating system, while observing the application of change procedures according to sound practices in this regard.

  2. Ensure continuous updating of antivirus software on all devices, and enable permanent scanning operations for incoming and outgoing email.

  3. Activate the principle of granting minimum permissions and privileges as needed for work, and review the need for users with high privileges (Administrators).

  4. Do not enable (Macro Scripts) for Microsoft files sent via email, and ensure opening such files through (Office Viewer) instead of (Full Office Suite Applications).

  5. Implement security and protection software that detects malicious software based on its behavior (Behavioral Anomaly) where possible.

  6. Follow a backup policy for sensitive data to ensure that backups are taken and stored in secure locations inaccessible via networks, along with applying procedures to verify the integrity and reliability of data and its storage media.

  7. Inspect links and attachments in incoming email to ensure there are no malicious files, and do not open unwanted links and attached files.

  8. Download software from the internet only when necessary, within the narrowest permissible limits, and from trusted sources, ensuring compliance with your approved change procedures after obtaining the necessary approvals in this regard.

  9. Activate the (Automated Patches) feature for operating systems and search engines on all devices.

  10. Work on developing an continuously updated awareness program for users regarding methods of detecting and dealing with fraudulent and suspicious email messages, specifically including phishing attempts and social engineering.

  11. Activate network examination procedures (Penetration Tests and Vulnerability Assessment) at least once a year.

  12. Review and verify the reliability and update incident response and handling procedures for information security, and business continuity plans for the company and its service providers.

  13. Inform the Central Bank immediately upon any breach or attempted breach, in accordance with our instructions in this regard.

Please accept our highest regards,,,

The Governor Dr. Ziad Fariz

P.O. Box 370 Amman 11118 - Jordan Tel 4630301 / 9 * Fax 4638889, 4639730 Website www.cbj.gov.jo Email info@cbj.gov.jo