2017-11-28 | 12725Added · Updated
Banque Libanaise issued Basic Decision No. 12725 to mandate banks and financial institutions to implement comprehensive administrative, technical, and judicial policies against cybercrime. The decision requires these entities to establish dedicated working groups, allocate budgets for information security, adopt multi-factor authentication and encryption protocols, and enforce strict internal procedures for electronic fund transfers. Furthermore, it obligates institutions to promptly notify customers of risks, report incidents to the Special Investigation Commission, and ensure rapid corrective actions including fund cancellation and refunds upon confirmed cyber fraud.
1171 Text/ Section 2, Circular No. 144, Date: December 31, 2017
Basic Circular for Banks No. 144 Also addressed to Financial Institutions
We enclose herewith a copy of the Basic Decision No. 12725 dated November 28, 2017 Concerning the Prevention of Cybercrime.
Beirut, on November 28, 2017 Governor of Banque Libanaise Riad T. Salamé
1172
Basic Decision No. 12725 Prevention of Cybercrime
The Governor of Banque Libanaise, Based on the Monetary and Loan Law, particularly Articles 174, 70, and 182 thereof, Based on Anti-Money Laundering and Counter-Terrorist Financing Law No. 44 dated November 24, 2015, Based on Basic Decision No. 7818 dated May 18, 2001, and its amendments concerning the system for monitoring financial and banking operations to combat money laundering and terrorist financing, attached to Basic Circular No. 83, And based on the "Guidelines for Prevention of Cybercrime via Electronic Mail" issued by Banque Libanaise, the Special Investigation Commission, the Association of Lebanese Banks, and the Information Crimes Combating and Intellectual Property Protection Office under the Judicial Police Unit, launched on October 20, 2016, And based on the decision taken by the Central Council of Banque Libanaise in its meeting held on November 21, 2017,
Decrees as follows:
First: Policies and Procedures for the Prevention of Cybercrime Article 1: Banks and financial institutions shall prepare policies and adopt preventive measures and procedures against cybercrime, including at least: First: General policies include:
Second: Technical measures include:
1173 Text/ Section 2, Circular No. 144, Date: December 31, 2017
Second: Measures specific to the prevention of cybercrime with a financial nature Article 2: Banks and financial institutions, each within its competence, shall generally and under their own responsibility adopt appropriate administrative, technical, and judicial measures to alert, monitor, and combat financial cybercrime, specifically:
1174 Second: Measures specific to the prevention of cybercrime with a financial nature Article 3: Banks and financial institutions, upon discovering, knowing, or being notified that any of their customers has fallen victim to cybercrime with a financial nature, shall take swift and effective measures including at least the corrective measures set forth in paragraph (3) of Part One of the aforementioned Guidelines, specifically:
Article 4: The "Compliance Department" established at each bank and financial institution shall apply the provisions of this decision.
Article 5: This decision shall take effect upon its issuance.
Article 6: This decision shall be published in the Official Gazette.
Beirut, on November 28, 2017 Governor of Banque Libanaise Riad T. Salamé
More like this from BDL
BDL published 2 documents in the last 30 days. We email you each new one the day it's published.