2019-03-12

Added

Decision on the Methodology for Bank Information System Security

The decision mandates that each bank establish an information system security management process and adopt a written Information System Security Policy that includes asset classification, risk assessment, implementation of administrative, technical and physical security controls, training, incident handling, audit trails and procedures for permitted exceptions. It requires banks to prepare an annual risk assessment summary, conduct independent cybersecurity resilience testing at least once every two years, submit biannual reports from an independent Information System Security Officer to the Supervisory Board, and perform annual business continuity testing with a results report to the National Bank. Additionally, banks must develop an IT management strategy, appoint an independent Information System Security Officer, implement strong customer authentication for electronic payment channels using at least two of knowledge, possession or inherence factors (with exemptions for certain internal or low‑value transfers), and ensure secure user authentication, transaction monitoring and protection of payment data.

National Bank of the Republic of North Macedonia logo

North Macedonia

National Bank of the Republic of North Macedonia

Scan of the document's first page
Share

NBRM published 7 documents in the last 30 days — get each new one by email the day it lands.

Read the rest free

Lineage: In force

Decision No. 31 of 2008Decision No. 31 of 2008Decision on the Methodologyfor Bank Information System S…2019-03-12 · this documentDecision on the Methodology for Bank Information System Security (2019-03-12)
amendssupersedesissued underrefers toproposed or not in RegAlertarrows run from the older text to the one that changes it

Source: National Bank of the Republic of North Macedonia — original document · Summary generated with machine assistance and reviewed before publication; the authoritative text is the regulator's original document. How RegAlert works

More like this from NBRM

NBRM published 7 documents in the last 30 days. We email you each new one the day it's published.

Topics