2021-02-26 | Resolução CMN 4893Added
CMN Resolution No. 4,893 establishes cybersecurity policies and requirements for data processing, storage, and cloud computing services for institutions authorized by the Central Bank of Brazil. It mandates that institutions implement cybersecurity policies tailored to their risk profiles and business models, covering authentication, encryption, intrusion detection, and vulnerability management. The resolution explicitly excludes payment institutions, consortium administrators, and securities brokers from its scope, directing them to separate Central Bank regulations. Additional security requirements are imposed for communications on the National Financial System Network, including multi-factor authentication and logical isolation for Pix and STR environments.
BCB published 15 documents in the last 30 days — get each new one by email the day it lands.
NO. 4,893, OF FEBRUARY 26, 2021
Establishes the cybersecurity policy and the requirements for contracting data processing and storage services and cloud computing services to be observed by institutions authorized to operate by the Central Bank of Brazil.
The Central Bank of Brazil, in accordance with Article 9 of Law No. 4,595, of December 31, 1964, makes public that the National Monetary Council, in a session held on February 25, 2021, based on Articles 4, item VIII, of the aforementioned Law, 9 of Law No. 4,728, of July 14, 1965, 7 and 23, item "a", of Law No. 6,099, of September 12, 1974, 1, item II, of Law No. 10,194, of February 14, 2001, and 1, § 1, of Complementary Law No. 130, of April 17, 2009,
Read the rest free, and get an email when BCB publishes again
Amended 2 times · last 2025-12-18
Source: Banco Central do Brasil — original document · Summary generated with machine assistance and reviewed before publication; the authoritative text is the regulator's original document. How RegAlert works
More like this from BCB
BCB published 15 documents in the last 30 days. We email you each new one the day it's published.