2023-09-23 | 24007

Added · Updated

Cybersecurity Best Practices Guideline

The Central Bank of Trinidad and Tobago requires authorized financial institutions to conduct annual self-assessments against cybersecurity guidelines and submit them by March 31st of the following year, accompanied by action plans for any material deficiencies. Institutions must establish governance, risk management, training, business continuity, testing, and incident management frameworks, with specific mandates such as deploying multi-factor authentication for customer access and conducting regular vulnerability and penetration testing. Material cybersecurity incidents must be reported to the Central Bank within 24 hours of awareness, with a detailed template submission required within 72 hours, followed by regular updates until resolution.

Central Bank of Trinidad and Tobago logo

Trinidad and Tobago

Central Bank of Trinidad and Tobago

Scan of the document's first page
Share

CBTT published 6 documents in the last 30 days — get each new one by email the day it lands.

Read the rest free

Lineage: In force

Financial Institutions Act, 20082008Financial Institutions Act, 2008 (2008-12-19)Insurance Act, 20182018Insurance Act, 2018 (2018-06-04)Cybersecurity Best PracticesGuideline2023-09-23 · this documentCybersecurity Best Practices Guideline (2023-09-23)
amendssupersedesissued underrefers toproposed or not in RegAlertarrows run from the older text to the one that changes it

Source: Central Bank of Trinidad and Tobago — original document · Summary generated with machine assistance and reviewed before publication; the authoritative text is the regulator's original document. How RegAlert works

More like this from CBTT

CBTT published 6 documents in the last 30 days. We email you each new one the day it's published.