2023-09-17 | 31816

Added · Updated

Cybersecurity Best Practices Guideline Industry Comments Table of Responses – September 2023

The Central Bank of Trinidad and Tobago amended its Cybersecurity Best Practices Guideline to require licensed and registered institutions to conduct annual self-assessments and submit them by March 31st of each year. The revisions clarify that the self-assessment must be signed by the Chief Executive Officer or a designated approved officer, such as the CISO or CCO, and include detailed action plans for material deficiencies. While the guideline remains compulsory for regulated entities, it explicitly excludes non-regulated institutions from reporting requirements and allows the frequency of independent third-party reviews to be determined by the institution based on its risk profile.

Central Bank of Trinidad and Tobago logo

Trinidad and Tobago

Central Bank of Trinidad and Tobago

Scan of the document's first page
Share

CBTT published 6 documents in the last 30 days — get each new one by email the day it lands.

Read the rest free

Lineage: In force

Financial Institutions Act, 20082008Financial Institutions Act, 2008 (2008-12-19)Insurance Act, 20182018Insurance Act, 2018 (2018-06-04)Cybersecurity Best PracticesGuideline Industry Comments T…2023-09-17 · this documentCybersecurity Best Practices Guideline Industry Comments Table of Responses – September 2023 (2023-09-17)
amendssupersedesissued underrefers toproposed or not in RegAlertarrows run from the older text to the one that changes it

Source: Central Bank of Trinidad and Tobago — original document · Summary generated with machine assistance and reviewed before publication; the authoritative text is the regulator's original document. How RegAlert works

More like this from CBTT

CBTT published 6 documents in the last 30 days. We email you each new one the day it's published.

Topics