2026-01-15

Added

Decision on the Methodology for Bank's Information System Security

The Decision establishes a mandatory methodology that banks must follow for information system security, covering IT strategy, IT risk management, and information security. It requires each bank to develop and regularly update an IT strategy aligned with its business strategy, to implement an IT risk management system with annual (or more frequent after significant changes) risk assessments, to document and monitor quantitative risk indicators listed in Annex 1 and Annex 2, and to submit indicator reports to the National Bank on request. Banks must also adopt an information security policy, appoint an independent information system security officer, implement logical and physical security controls, maintain off‑site secure backup copies, conduct internal IT audits, and achieve at least the basic cybersecurity maturity level (intermediate for systemically important banks) as defined in Annex 3.

National Bank of the Republic of North Macedonia logo

North Macedonia

National Bank of the Republic of North Macedonia

Scan of the document's first page
Share

NBRM published 7 documents in the last 30 days — get each new one by email the day it lands.

Read the rest free

Source: National Bank of the Republic of North Macedonia — original document · Summary generated with machine assistance and reviewed before publication; the authoritative text is the regulator's original document. How RegAlert works

More like this from NBRM

NBRM published 7 documents in the last 30 days. We email you each new one the day it's published.

Topics