2016-01-12

Added · Updated

Commentary on the Concept of Information Security of the Central Bank of Uzbekistan, Commercial Banks and Non-Bank Credit Organizations

This document provides a commentary on the Concept of Information Security adopted by the Central Bank of Uzbekistan on December 31, 2011. It establishes that ensuring adequate information security for automated banking systems is a critical requirement for the development and strengthening of the national banking system. The text defines information security threats as real risks to organizational assets and mandates that financial institutions maintain sufficient security measures over time to prevent systemic crises and protect client interests.

Central Bank of the Republic of Uzbekistan logo

Uzbekistan

Central Bank of the Republic of Uzbekistan

Click to view thumbnail

COMMENTARY ON THE CONCEPT OF INFORMATION SECURITY OF THE CENTRAL BANK OF UZBEKISTAN, COMMERCIAL BANKS AND NON-BANK CREDIT ORGANIZATIONS

The "Concept of Information Security of the Central Bank of Uzbekistan, Commercial Banks and Non-Bank Credit Organizations" was developed by the Central Bank of the Republic of Uzbekistan and approved by the Board of Directors of the Central Bank on December 31, 2011.

This Concept was developed on the basis of the Laws of the Republic of Uzbekistan "On the Central Bank of the Republic of Uzbekistan," "On Informatization," "On Electronic Digital Signature," "On Electronic Payments," "On Protection of Information in Automated Banking Systems," "On Bank Secrecy," as well as the "Concept of National Security of the Republic of Uzbekistan."

The rules proposed in this Concept define a single generalized main direction for developing a strategy to ensure information security in the activities of the Central Bank of the Republic of Uzbekistan, commercial banks and their branches and minibanks, credit organizations, as well as representative offices of foreign banks and non-bank credit organizations. This includes a set of basic tasks and practical measures.

One of the main goals of the Central Bank is to develop and strengthen the Republic's banking system, as well as to ensure the uninterrupted and effective operation of the payment system. An important condition for achieving this goal is ensuring adequate and necessary information security in organizations of the banking system of the Republic of Uzbekistan, which in most cases involves determining the level of information security of automated banking systems (ABS), banking technological processes (payments, data, etc.).

A specific feature of the banking system is that negative situations arising in the operations of individual organizations lead to the rapid development of a systemic crisis in the payment system, affecting the income of clients and property owners. The occurrence of incidents in information security increases the likelihood of significant damage to banking system organizations. Therefore, threats to the information assets of banking system organizations, i.e., risks to information security, represent real risks posed to the organization.

To counter such threats and ensure effective measures to eliminate unfavorable situations in information security, it is necessary to ensure that information security in banking system organizations is at an adequate level, as well as to maintain this state over a long period. For these reasons, issues of information security in banking system organizations are considered one of the most important aspects of their activities.

We believe that this Concept will serve to further raise the level of information security in the banking system and increase public confidence in the banking system.

U.K. Sultonov Head of the Department of Security and Information Protection

More like this from CBU

We email you every new CBU publication the day it's published.

Topics
Share