2015-07-09
Added
The Decision establishes a mandatory information system security management process for savings houses, requiring them to conduct risk assessments, adopt an Information System Security Policy covering risk management, employee training, incident handling, access control, and other specified elements, and assign an IT officer with defined responsibilities. Savings houses must implement administrative, technical and physical security controls proportionate to their size and activities, conduct independent testing of these controls, and establish a security incident management process that obliges notification of the National Bank within three days for the highest‑severity incidents. They are also required to develop, test and periodically update a business continuity plan that identifies critical operations, alternative mechanisms, data recovery, and a remote backup location, with the plan’s provisions becoming applicable from 1 January 2017. The Decision takes effect eight days after publication and is applicable to savings houses from 1 January 2016.
NBRM published 7 documents in the last 30 days — get each new one by email the day it lands.
NATIONAL BANK OF THE REPUBLIC OF MACEDONIA Pursuant to Article 47 paragraph 1 item 6 of the Law on National Bank of the Republic of Macedonia ("Official Gazette of the Republic of Macedonia" No. 158/10, 123/12 and 43/14), Article 68 paragraph 1 item 5 and Article 172 paragraph 2 of the Banking Law ("Official Gazette of the Republic of Macedonia" No. 67/07, 90/09, 67/10, 26/13 and 15/15), the National Bank of the Republic of Macedonia Council adopted the following DECISION on information security of savings houses ("Official Gazette of the Republic of Macedonia" No. 74/15)
I. GENERAL PROVISIONS
2
3
4
The plan under paragraph 1 of this item shall contain at least the following elements:
Read the rest free
Source: National Bank of the Republic of North Macedonia — original document · Summary generated with machine assistance and reviewed before publication; the authoritative text is the regulator's original document. How RegAlert works
More like this from NBRM
NBRM published 7 documents in the last 30 days. We email you each new one the day it's published.