2023-09-23 | 24220Added · Updated
The document establishes a self-assessment framework requiring companies to implement defined cybersecurity plans involving the Board, senior management, and internal lines of defense. It mandates specific obligations across governance, risk management, training, business continuity, testing, and incident reporting, including annual security training for all employees and prompt notification of material incidents to the Central Bank. Affected entities must submit their completed assessments via email to cyberguides@central-bank.org.tt.
CBTT published 6 documents in the last 30 days — get each new one by email the day it lands.
SELF-ASSESSMENT:
Best Practices on Cybersecurity
A. GOVERNANCE – The Board, senior management and all ‘internal lines of defense’ - Business, Risk, and Internal Audit Departments must be involved in the implementation of a defined cybersecurity plan. Roles, responsibilities and reporting lines for all functional areas or person involved in the cybersecurity strategy should be clearly defined.
D. BUSINESS CONTINUITY AND DISASTER RECOVERY – The company should have business continuity and recovery plans which incorporate dealing with cyber-related occurrences, including information technology system failures and unavailability.
Read the rest free
Source: Central Bank of Trinidad and Tobago — original document · Summary generated with machine assistance and reviewed before publication; the authoritative text is the regulator's original document. How RegAlert works
More like this from CBTT
CBTT published 6 documents in the last 30 days. We email you each new one the day it's published.