2018-10-03
Added · Updated
The Central Bank of Jordan issued Cyber Resilience Instructions No. 17/2018, effective twelve months from their date, mandating compliance from all licensed exchange companies and their foreign branches. The regulations require companies to establish cybersecurity governance, implement a comprehensive cybersecurity program, and maintain a continuously updated cyber risk register. Specific obligations include appointing an independent Information Security Manager, conducting regular risk assessments, and ensuring the confidentiality, integrity, and availability of information assets through defined protection and detection controls.
Reference No.: 19/12953 Date: 23/1/1440 Corresponding to: 3/10/2018
[Logo of the Central Bank of Jordan] Central Bank of Jordan
Cyber Resilience Instructions For Licensed Exchange Companies
No. (17/2018)
Central Bank of Jordan
Table of Contents
Chapter One ................................................................................................................................................. 3 Legal Basis, Scope of Application, and Definitions ....................................................................................................................... 3 Chapter Two ................................................................................................................................................. 9 First: Cybersecurity Governance .............................................................................................................................. 9 Second: Cybersecurity Program and Policy ................................................................................................................... 10 Chapter Three ................................................................................................................................................. 13 Cyber Risk Management ................................................................................................................................... 13 First: Identification of Critical Operations and Supporting Information Assets in the Company ................................................................................. 13 Second: Cyber Risk Assessment ........................................................................................................................... 13 Chapter Four ................................................................................................................................................. 15 Protection Controls .............................................................................................................................................. 15 First: Protection of Systems, Software, Networks, and Network Devices ........................................................................................ 15 Second: Special Protection Controls for Email ....................................................................................................... 20 Third: Records ............................................................................................................................................... 22 Chapter Five ............................................................................................................................................... 22 Detection of Cyber Incidents ........................................................................................................................... 22 Chapter Six ............................................................................................................................................... 23 Response to Emergency Cyber Incidents and Recovery ................................................................................................... 23 Chapter Seven ................................................................................................................................................. 25 Tests .................................................................................................................................................... 25 Chapter Eight ................................................................................................................................................. 26 Outsourcing ............................................................................................................................................. 26 Chapter Nine ................................................................................................................................................. 28 First: Training and Awareness ............................................................................................................................... 28 Second: Exchange of Cyber Incident Information ................................................................................................................ 30 Chapter Ten ................................................................................................................................................ 31 General Provisions ................................................................................................................................................... 31
| Page 2
Central Bank of Jordan
Chapter One Legal Basis, Scope of Application, and Definitions
Article (1): These Instructions are issued pursuant to the provisions of Article (65/b) of the Central Bank of Jordan Law No. (23) of 1971 and its amendments, Article (99/b) of the Banks Law No. 28 of 2000 and its amendments, and Article (22/b) of the Electronic Transactions Law No. (15) of 2015 and its amendments. They become effective twelve months from their date, unless otherwise specified.
Article (2): These Instructions are titled "Cyber Resilience Instructions for Licensed Exchange Companies."
Article (3): a. These Instructions apply to all licensed exchange companies. b. These Instructions apply to foreign branches of exchange companies to the extent permitted by these Instructions. In cases where the instructions of the host country achieve the objectives of these Instructions to a lesser extent, the instructions of the home country shall apply.
Article (4): a. The following words and phrases shall have the meanings assigned to them below wherever they appear in these Instructions, unless the context indicates otherwise:
| Company | : | A licensed exchange company in accordance with the provisions of the Exchange Business Law. |
|---|---|---|
| Board of Directors | : | The Board of Directors of the Company and those acting in its stead. |
| Company Management | : | Includes anyone holding the position of General Manager, Assistant General Manager, Deputy General Manager, Internal Audit Director, Financial Director, Risk Director, Compliance Director, or any employee in the Company with executive authority parallel to any of the aforementioned. |
| Page 3
Central Bank of Jordan
| Information and Communications Technology (ICT) Environment | : | The set of computer equipment specific to internal and external networks, main servers, and the software running on them, along with all supporting devices at the Company's main and backup sites. |
|---|---|---|
| Information | : | Any oral or written data, records, statistics, written or visual documents, or records stored electronically or by any other method that holds value for the Company. |
| Data | : | Raw facts that can be illustrated by letters, symbols, and numbers that may represent people, objects, or events. |
| Information Assets | : | Any information, electronic or non-electronic files, devices, storage media, software, or any components of the ICT environment related to the Company's business. |
| Cyberspace | : | A virtual environment consisting of the interaction of people, software, and services on the Internet through devices and connected technology networks. |
| Cyber Attack | : | Any attempt to destroy, disclose, change, disrupt, or steal, or attempt to exploit vulnerabilities or gain unauthorized access to the Company's information assets within cyberspace. |
| Cyber Resilience | : | The Company's ability to anticipate, withstand, contain, and recover quickly from a cyber attack. |
| Cyber Security | : | Maintaining the confidentiality, integrity, and availability of the Company's information assets within cyberspace from any cyber threat through a set of means, policies, instructions, and best practices in this regard. |
| Cyber Threat | : | A circumstance or event that may exploit (intentionally or unintentionally) one or more vulnerabilities existing in the Company's ICT environment, thereby affecting its cyber security. |
| Page 4
Central Bank of Jordan
| Cyber Event | : | Any incident indicating the presence of a cyber threat to the Company's ICT environment. |
|---|---|---|
| Cyber Risk | : | A composite value resulting from calculating the probability of a cyber event occurring within the scope of the Company's information assets, and the impact of that event on the Company. |
| Cyber Governance | : | The Company's arrangements for establishing, implementing, and reviewing its approach to cyber risk management. |
| Data Governance | : | The process of managing the availability, security, ease of use, and integrity of data used in the Company. |
| Malicious Code | : | Software or harmful files containing functions that negatively affect, directly or indirectly, the ICT environment used in the Company. |
| Protection | : | The deployment of appropriate procedures, controls, and measures to provide the Company's services and business reliably. |
| Detection | : | The deployment of appropriate controls and procedures to be aware of the occurrence of a cyber event immediately. |
| Response | : | The deployment of appropriate controls and procedures to contain the cyber event upon its detection. |
| Restore | : | The process of retrieving information stored on backup media when original information is damaged, lost, or needed after a period of time to resume the Company's operations. |
| Recovery | : | A set of actions taken and followed to return the Company's business to its normal state and restart the technology resources relied upon to operate the Company's processes to their state prior to the occurrence of the event. |
| Page 5
Central Bank of Jordan
| Vulnerabilities | : | A flaw or deficiency in the protection controls used in any component of the ICT environment related to the Company's business, which can be exploited in hacking and cyber attack operations. |
|---|---|---|
| Access Control | : | Rules and mechanisms used to allow only authorized persons to use and access information assets in accordance with the nature of their responsibilities in the Company. |
| Privileges | : | The level of permissions granted to users to access/use and utilize any components of the ICT environment in the Company. |
| Change Management | : | The management, control, and documentation of any changes made to any components of the ICT environment in the Company or any changes in procedures implemented in the Company by authorized parties. |
| Information Classification | : | Determining the appropriate sensitivity level for information created, changed, transferred, modified, or stored on any media and using any possible technology, based on the risks resulting from unauthorized access and use of that information. |
| Confidentiality | : | Protecting information from unauthorized access, publication, disclosure, and use. |
| Availability | : | The ability to use, access, and retrieve information and systems in the Company upon request. |
| Integrity | : | The accuracy, completeness, and safety of information or information systems or any part thereof, and verifying that no unauthorized increase, decrease, or change has occurred. |
| Page 6
Central Bank of Jordan
| Recovery Time Objective (RTO) | : | The maximum allowed time to restart a service or process after an interruption in IT services. |
|---|---|---|
| Recovery Point Objective (RPO) | : | The maximum age allowed for data that may be lost when restoring service after an interruption. |
| Cyber Risk Management | : | Processes for identifying, measuring, controlling, and monitoring cyber risks. |
| Critical Operations | : | Operations that cannot tolerate long periods of downtime according to business impact analysis studies in the Company, and those with relative risk and importance to the Company. |
| : | The service that can be provided to users to create, send, receive, and store electronic messages using electronic communication systems. | |
| Encryption | : | The process of converting information into an unreadable or incomprehensible form. |
| Third Party | : | The entity to which the Company entrusts technical and engineering work, wholly or partially, to assist it in performing its licensed business in a manner that does not conflict with the provisions of prevailing legislation. |
| Outsourcing | : | Engaging a third party or utilizing its resources to manage the Company's business or part of its business that falls within its responsibility. |
| Physical Security | : | Protection standards and procedures that monitor or determine entry to any of the Company's facilities, resources, or information stored on physical media, or to prevent access to information resources and systems, such as |
| Page 7
Central Bank of Jordan
| Buildings, file cabinets, desktop and portable devices, servers, and equipment. | ||
|---|---|---|
| Stakeholders | : | Any interested party in the Company such as shareholders, employees, creditors, customers, external suppliers, or relevant regulatory authorities. |
| Event Log | : | Data files of security and operational events produced by system components to understand system activity and diagnose problems that may occur. |
| Audit Trail | : | Data files that provide documentary evidence of the sequence of functional and administrative processes occurring on systems. |
| Risk Assessment | : | Measuring and determining the probability of risk occurrence and its severity, and anticipating its impact on the Company. |
| Penetration Testing | : | A test in which specialized assessors attempt to find security vulnerabilities, bypass security features of information systems and security controls, and exploit them to attempt to breach those systems from outside or inside the Company to determine the effectiveness of the security controls used by the Company to protect its systems. |
| Remote Access | : | Enabling connection with the Company's systems from outside its internal network, whether for the purpose of enabling its employees to work remotely, securing connection with business partners, or by a third party. |
b. The definitions contained in the Central Bank Law, the Exchange Business Law, the Electronic Transactions Law, and any related instructions issued by the Central Bank shall be relied upon wherever cited in these Instructions, unless the context indicates otherwise.
| Page 8
Central Bank of Jordan
Chapter Two First: Cybersecurity Governance
Article (5): The Company shall comply with the following: a. The Board of Directors, its delegated committees, and/or Company Management shall include individuals possessing the appropriate skills and knowledge to understand and manage cyber risks. b. The Board of Directors, its delegated committees, and/or Company Management shall assume the following responsibilities and tasks, each according to their position:
| Page 9
Central Bank of Jordan
Second: Cybersecurity Program and Policy
Article (6): The Company shall implement and continuously update the Cyber Security Program to ensure the achievement of confidentiality, authenticity, and availability requirements for information in the ICT environment. The Program shall include, at a minimum, the following: a. Identifying internal and external cyber risk threats. b. Identifying and classifying risks and information sensitivity in the ICT environment. c. Identifying entities with the ability to access and use the ICT environment. d. Implementing cybersecurity policies and procedures and operating the necessary ICT environment to ensure the protection of the Company's information assets and sensitive information from unauthorized hacking. e. Detecting successful and failed unauthorized hacking attempts immediately upon occurrence, to the extent possible. f. Taking necessary corrective actions to control and mitigate the negative effects of cyber risks. g. Procedures for restarting the Company's operations after a stoppage, including those related to services and legal and regulatory requirements during the acceptable and specified time period within the business continuity plan, in accordance with Article (31/g) of these Instructions.
Article (7): The Cyber Security Policy must be a document dedicated to cybersecurity in the Company. When preparing and updating the policy, the contribution of all stakeholders shall be considered, and international best practices and their updates shall be adopted as references and lessons learned from cybersecurity incidents. The Company may include the Cyber Security Policy under the Information Security Policy titled "Information Security and Cyber Security Policy," and may include Cyber Security Programs within the Information Security Program, provided that all requirements of these Instructions are met.
| Page 10
Central Bank of Jordan
Article (8): The Cyber Security Policy must include, at a minimum, the following axes: a. Identifying roles and responsibilities, including decision-making responsibility within the Company regarding cyber risk management, including emergency and crisis situations. b. Data governance and classification. c. Security and management of information and the Company's ICT environment. d. Customer data privacy. e. Cyber risk management. f. Protection controls to limit and control cyber risks. g. Business continuity and disaster recovery plans. h. Cooperation with stakeholders to effectively respond to cyber attacks and recover from them. i. Monitoring, developing, and improving systems, networks, and applications. j. Physical and environmental security controls. k. Management of third-party outsourced operations. l. Employee awareness and training within the Company regarding cybersecurity to ensure all employees apply all provisions of the Cyber Security Policy. m. Identifying the mechanism for disclosing the provisions of the Cyber Security Policy to stakeholders according to their role. n. Identifying the owning entity, scope of application, review and update frequency, access and distribution rights, objectives, responsibilities, related work procedures, penalties for non-compliance, and compliance review mechanisms.
Article (9): The Company must manage information security related to cybersecurity through an Information Security Manager who does not administratively report to the Information Technology department, enjoys independence to ensure no conflict of interest, and possesses the necessary practical experience and professional knowledge to be responsible for the following tasks at a minimum:
| Page 11
Central Bank of Jordan
a. Directly supervising the development of the Cyber Security Program and Policy, ensuring their implementation, and working on reviewing and updating them continuously. b. Evaluating the adequacy and efficiency of the Cyber Security Program. c. Continuously reviewing the effectiveness of protection controls adopted in the Company's Cyber Security Policy. d. Identifying and evaluating cyber risks. e. Submitting semi-annual reports or whenever necessary to the Board of Directors and/or Company Management regarding cybersecurity in the Company. The report must include, at a minimum:
Article (10): Notwithstanding the provisions of Article (9) above, the Company may entrust the task of information security management or part of it to a third party, provided it complies with the following: a. Requiring the third party to comply with the Instructions' requirements regarding information security management. b. Checking the third party's compliance with the Instructions' requirements regarding information security management.
Article (11): The Company must verify, before making any changes to the Company's ICT environment, operations, or procedures, or after any event affecting the Company's security, whether there is a need to introduce changes or improvements to the Cyber Security Policy and Program.
| Page 12
Central Bank of Jordan
Chapter Three Cyber Risk Management
First: Identification of Critical Operations and Supporting Information Assets in the Company
Article (12): The Company must identify the following to be able to assess the cyber risks it may face: a. Critical functions and operations in the Company. b. Information assets in the Company, understanding their operations, procedures, systems, and related resources, information systems, and access methods, including internal and external systems connected to them.
Article (13): The Company must classify its functions, critical operations, and information assets in terms of their importance and sensitivity, and continuously review and update these classifications.
Second: Cyber Risk Assessment
Article (14): The Company must continuously analyze cyber risk factors, identifying the following: a. Internal threats. b. External threats. c. Vulnerabilities in managing ICT environment resources. d. Vulnerabilities in the ICT environment's ability to enable the Company's operations. e. Vulnerabilities in managing ICT environment risks.
| Page 13
Central Bank of Jordan
Article (15): The Company must continuously analyze cyber risk scenarios, identifying, at a minimum, the following: a. Source of the cyber threat: either internal or external. b. Type of cyber threat: either natural, man-made, or technological. c. Cyber Event: for example, but not limited to, disclosure of confidential information, disruption, unauthorized modification, theft, destruction, ineffective design, or unacceptable use. d. Affected Assets or Resources: for example, but not limited to, human resources, organizational structures, operations, ICT environment, or information. e. Time: time of occurrence, duration of the event, and age of the event upon discovery.
Article (16): The Company must create and continuously update the Comprehensive Cyber Risk Register, which must include, at a minimum, the following: a. Asset owner, assessment team, assessment date, subsequent assessment date, summary of cyber risk assessment, and management options. b. Cyber risk assessment in terms of calculating two risk axes: event probability (Potential) and impact size (Impact or Severity). It is preferable to use a standard paired scale for assessment axes, and to show the impact size based on the Company's IT-included objectives and operations using one of the global models' assessment axes, for example:
| Page 14
Central Bank of Jordan
Article (17): The Company may engage a third party for the purpose of assessing cyber risks, subject to the provisions of prevailing legislation.
Chapter Four Protection Controls
First: Protection of Systems, Software, Networks, and Network Devices
Article (18): The Company must provide the following protection controls, including but not limited to, for all components of its ICT environment such as systems, software, and network devices, from any cyber event: a. Network segregation to ensure the isolation of the impact of systems exposed to cyber attacks from others in the event of an occurrence, facilitating the efficient and effective restoration of services according to the Company's cyber risk assessment. b. Segregation of infrastructure sites (main sites and disaster recovery sites) for critical systems in a secure, limited-access area, documenting visitor entry logs, and having monitoring systems for infrastructure sites.
c. Segregation of the test and development environment for critical systems from the production environment. d. Continuous evaluation of the efficiency and design of network connections and network devices, including protection devices (such as Firewalls, Intrusion Prevention Systems), to meet business needs. The Company must keep an updated network connection design, an updated list of devices connected to the Company's network, and diagrams of the main site and disaster recovery site data centers in a secure location accessible only to authorized personnel. e. Providing preventive controls regarding prohibiting the connection of third-party or employee-owned devices with the Company's networks, servers, and systems, including computers, mobile devices, and any other devices, without obtaining necessary approvals. If connection is approved, information security and cybersecurity policies and rules must be applied to them. The Company must work to provide supervisory controls to detect any devices connected to the Company's networks and systems through unauthorized means. f. Providing necessary devices and software to monitor, warn, and detect |
| Page 15
Central Bank of Jordan
... [Document continues with further articles on protection controls, email security, records, incident detection, response, testing, outsourcing, training, and general provisions as outlined in the Table of Contents] ...