2026-01-15
Added
The Decision establishes a mandatory methodology that banks must follow for information system security, covering IT strategy, IT risk management, and information security. It requires each bank to develop and regularly update an IT strategy aligned with its business strategy, to implement an IT risk management system with annual (or more frequent after significant changes) risk assessments, to document and monitor quantitative risk indicators listed in Annex 1 and Annex 2, and to submit indicator reports to the National Bank on request. Banks must also adopt an information security policy, appoint an independent information system security officer, implement logical and physical security controls, maintain off‑site secure backup copies, conduct internal IT audits, and achieve at least the basic cybersecurity maturity level (intermediate for systemically important banks) as defined in Annex 3.
NBRM published 7 documents in the last 30 days — get each new one by email the day it lands.
NATIONAL BANK OF THE REPUBLIC OF NORTH MACEDONIA PUBLIC Pursuant to Article 47 paragraph 1 item 6 of the Law on the National Bank of the Republic of North Macedonia (Official Gazette of the Republic of Macedonia No. 158/10, 123/12, 43/14, 153/15, 6/16 and 83/18 and Official Gazette of the Republic of North Macedonia No. 43/14, 74/24 and 16/25) and Article 68 paragraph 1 item 6 of the Banking Law (Official Gazette of the Republic of Macedonia No. 67/07, 90/09, 67/10, 26/13, 15/15, 153/15, 190/16 and 7/19 Official Gazette of the Republic of North Macedonia No. 101/19, 122/21 and 37/25), the National Bank of the Republic of North Macedonia Council has adopted the following DECISION on the Methodology for bank's information system security
I. GENERAL PROVISIONS
2.4. “Log” shall mean recording of the sequence of activities performed by the IT
system.
2.5. "Significant IT incident" shall mean an operational and security incident that is
classified as significant, in accordance with the act regulating the guidelines for the classification of operational and security incidents and the manner and procedure for reporting incidents and fraud, and thereby meeting the criterion for network or information system security impairment.
2.6. “Integrity“ shall mean protection of accuracy and completeness of data stored,
transmitted or processed by the IT system, including the services provided by that system;
2.7. “Information assets“ shall mean a collection of valuable information for the
bank, tangible and non-tangible, that needs to be protected.
2.8. "Information and communication system“ (hereinafter: IT system) shall
mean information and communication technology that functions independently or as an integral part of interrelated networks that support the bank’s operations.
2.9. “Information and communication technology” (hereinafter: IT) shall mean
the technology that enables automatic collection, processing, preparation, storage, transfer and display of information (data).
2.10. "IT architecture" shall mean a specially designed and flexible infrastructure that
can be managed and that includes IT assets and data that are processed or stored on them, the manner they are interrelated and their technical characteristics.
2.11. "IT incident" shall mean one or more interrelated unplanned events that may
disrupt the security of the bank's information system.
2.12. "IT operations" shall mean activities required to manage and maintain IT
systems to prevent disruption of the security of the bank's information system (information security) when providing IT services.
2.13. "IT project" shall mean a project that involves changes to IT systems and/or IT
services, including their replacement.
2.14. "IT risk" shall mean an identified potential for an event related to the use of the
IT system, which, if occur, could disrupt the information system security and/or have a negative impact on providing digital IT services and/or on the bank's operations;
2.15. "IT asset" shall mean a software or hardware asset in a business environment.
2.16. "IT services“ shall mean services such as: entry, storage and processing of data,
reporting, operating support and decision-making services, which the IT systems provide to the users.
2.17. "Logical security controls" shall mean controls incorporated into the software
components of an IT system.
2.18. "Physical security controls" shall mean controls that safeguard an IT system
from unauthorized physical access, theft, physical damage, or destruction.
2.19. "IT system users" shall mean all users of the IT system, such as employees,
outsourcing entities, clients, etc.
2.20. "IT Outsourcing" shall mean IT services provided by an outsourcing entity on
the basis of a concluded contract, and are related to the performance of financial activities.
2.21. "Critical IT system" shall mean an IT system classified as critical, according to
the risk assessment performed, taking into account the requirements for confidentiality, integrity and availability, and may cause serious disruption to the bank's operations.
2.22. "Cybersecurity maturity level" shall mean established security measures and
activities listed in Annex No. 3, which is an integral part of this Decision.
2.23. “Operational function“ shall mean service, process or activity that the bank
performs during its operating.
2.24. "Cyber Resilience" shall denote the ability of the bank to anticipate cyber-attacks
in order to establish timely functionality of the disrupted business processes.
2.25. “Availability“ shall mean unhindered access of authorized users of the IT system
to the data stored, transmitted or processed by the IT system, including the services this system provides;
2.26. “Cybersecurity” shall define the bank's ability to ensure protection of the
information assets, IT assets from attacks that can cause disruption, disabling, destruction or their malicious downloading that would violate the information system security.
2.27. "Bank's information system security (information security)" shall mean
the ability of an information and communication system to ensure resilience to events that may impair the availability, integrity or confidentiality of data stored, transmitted or processed by it, including the services this system provides.
2.28. “Severe business process disruption” shall mean a situation in which the bank
is incapable of meeting the undertaken business obligations due to factors beyond its control, or a situation when it is physically or communicationally impaired, i.e.
information assets and IT systems for IT financial activities support operations are not available.
2.29. "Information system security testing" shall refer to procedures that enable
identification, analysis and assessment of information security vulnerabilities in accordance with established standards in the relevant area, verification of the compliance with the current legislation and bylaws, internal and external IT systems audits, examination of the established physical security measures, checks to identify weaknesses in IT systems, security testing of resilience to cyber-attacks.
2.30. “Cloud computing” shall mean IT services provided on a basis of a model that
enables a network access to a joint set of configurable IT assets (networks, servers, data storage devices, applications and services).
2.31. “Recovery Time Objective (RTO)” shall mean a timeframe necessary to
establish the business processes with adequate technological support, in case of severe business process disruption.
2.32. “Recovery Point Objective (RPO)” shall denote the last data recovery point in
order to resume the business process, in case of severe business process disruption.
3. Issues not defined in this Decision shall have the meaning of the terminology defined in
the Banking Law and the bylaws thereof.
III. IT STRATEGY
4. The bank shall establish a process of planning and development of an adequate IT strategy,
which is appropriate to the nature, scope and complexity of its IT activities. The bank shall regularly assess the need to revise the adopted IT strategy.
5. The process of planning and development of an appropriate IT strategy shall include:
− identifying and assessing the risks associated with its successful implementation, as well as taking measures for their reduction; − defining an operational plan with activities and the necessary budget to support its implementation; − procedures for monitoring and measuring its efficiency.
6. The bank shall align the IT strategy with its business strategy and it should contain at least:
− guidelines for IT development for efficient support in the attaining the business strategy which includes organizational changes, changes in IT systems, including dependence on outsourced IT services, as well as the use of cloud services; − goals and activities for the development of IT architecture; and − clear goals for ensuring information security of IT systems and IT services.
With the operational plan of activities referred to in item 5, paragraph 1, indent 2 of this
Decision, the bank shall define activities for attaining the objectives of the IT strategy. When defining the activities, the bank should appropriately plan its resources and provide adequate financial resources for the successful implementation of the adopted IT strategy. The bank shall regularly review the operational plan of activities in order to confirm its applicability.
The bank should establish procedures for monitoring and measuring the efficiency of the
implementation of the IT strategy and the planned budget, in accordance with item 5, paragraph 1, indent 3 of this Decision, by introducing quantitative indicators and their tolerance thresholds and regular reporting to the bank's bodies.
IV. IT RISK MANAGEMENT SYSTEM
GENERAL REQUIREMENTS
IT risk management is a part of the overall bank's risk management system and meets the
risk management requirements defined in the Banking Law and the National Bank’s risk management methodology regulation.
The IT risk management system shall also encompass the procedures for:
− determining the acceptable level of IT risk, in accordance with the bank’s acceptable risk level; − IT risk management, which includes identification, classification of information and IT assets, assessment of the identified IT risk and measures to overcome it; − monitoring the efficiency of the measures referred to indent 2 of this item and the number of reported IT incidents and taking actions to overcome them; − regular reporting on the status of the IT risk and measures for its management; − identifying and assessing the occurrence of IT risk due to major changes in the IT system or IT services and/or after a significant IT incident.
The bank shall document and improve the procedures for managing IT risk, at least once
a year.
IT RISK MANAGEMENT PROCEDURES
As part of the IT risk management system, the bank shall determine the IT-supported
operational functions and document the information and IT assets for their support. The classification of the information and IT assets referred to in paragraph 1 of this item shall be carried out according to their criticality, taking into account the requirements for confidentiality, integrity and availability and their interdependence.
The bank shall determine the IT risk that affects the IT-supported determined operational
functions and the classified information and IT assets according to their criticality.
The bank shall conduct an IT risk assessment and document it, annually or more frequently
in the event of significant IT changes, and if necessary, update the IT risk assessment. The bank should prepare a summary report on the performed IT risk assessment, where the IT risks shall be categorized according to the table provided in Annex No. 1, which is an integral part of this Decision. Whenever assesses the IT risk, the bank shall previously update the existing identification and classification of information and IT assets.
The bank shall constantly monitor threats, including the vulnerabilities that these threats
can exploit and their impact on the operational functions supported by IT and, if necessary, it shall apply a scenario analysis approach, especially for specific, complex IT systems.
The bank shall use quantitative indicators for monitoring exposure and their tolerance
thresholds when assessing and monitoring the IT risk.
For the purposes of paragraph 1 of this item, the bank shall establish and document at least the indicators listed in Annex No. 2, which is an integral part of this decision, in accordance with the defined frequency for determining their value. At the request of the National Bank, the bank shall prepare a report on the value of the indicators from paragraph 1 of this item and submit it to the National Bank.
Based on the results of the assessment and monitoring of IT risk, the bank shall define
and take measures to mitigate them to an acceptable level of risk.
The bank's Management Board shall be informed of the results of the assessment of IT
risks and monitor the implementation of the measures to mitigate them, in order to ensure efficient implementation of the IT risk management system. IT AUDIT
The bank's internal audit department shall regularly audit the IT risk and the bank's
compliance with the applicable policies, procedures and the legislation and bylaws in the area of IT, in accordance with the annual internal audit plan. The individuals performing the audit referred to in paragraph 1 of this item should have the necessary knowledge, skills and expertise in the IT area in order for the bank's Supervisory Board to obtain impartial assurance on the efficiency of the established IT risk management system.
The realization of the internal audit of IT risk, including the scope and frequency of its
implementation, should correspond to the IT risk assessment.
V. INFORMATION SECURITY
21. For establishing information security purposes, the bank should prepare and adopt an
information security policy and establish security protection measures. These measures should include at least:
− organizational set-up and description of the main roles and responsibilities for information security management; − logical security controls; − physical security controls; − IT operations; − security monitoring; − information security testing; − information security training and awareness; − IT incident management; − IT project and change management; − business continuity management and − IT outsourcing. INFORMATION SECURITY POLICY
22. The bank shall develop and document the information security policy that defines the
objectives, principles and rules for protecting the confidentiality, integrity and availability of IT assets and critical data, regardless of whether they are used, transferred or stored. The information security policy should be in concordance with the bank's information security objectives and the results of the IT risk assessment conducted under item 14 of this Decision.
23. The bank shall inform all employees and contracted IT outsourcing entities about the
information security policy.
ORGANIZATIONAL STRUCTURE
24. The bank shall organizationally set up the information security management, which implies
clearly defined competencies and responsibilities of the bank's bodies.
25. The bank’s Supervisory Board shall be required to:
− adopt an IT strategy aligned with the business strategy and supervise its implementation; − adopt an appropriate IT risk management system, taking into account the provisions of Section IV of this Decision, and establish its supervision; − within the framework of the bank's organizational structure, define responsibilities for managing information and communication technology, IT risk, information system security and business continuity.
26. The bank’s Management Board shall provide the following:
− implementation of the adopted IT strategy, through the development of an operational plan for its fulfillment; − efficient implementation of the IT risk management system; − sufficient number of employees with knowledge and skills for continuous support of IT operations, IT risk management processes, implementation of the adopted IT strategy and its monitoring; − appropriate training of all employees, including employees involved in the IT risk management process, at least on an annual basis or more frequently if necessary; and − sufficient amount of funds for meeting the requirements referred to in indents 1, 2, 3 and 4 of this item.
27. In order to manage the information system security, the bank should appoint a person
responsible for the information system security who will coordinate the information security policy and processes related to different technological platforms and tasks. The bank shall ensure independence and objectivity of this control function by separating it from the IT operations. The person responsible for the information system security shall inform the Supervisory Board on the activities related to the information security at least twice a year.
28. The informing under item 27 paragraph 3 of this Decision shall contain at least the following
elements:
− data on the identified IT risk and its control; − registered cases of exceptions to the information security policy and the risks associated with those exceptions; − information related to IT services outsourcing contracts; − results of the completed tests to the information system security and measures undertaken by the bank’s Management Board; − security incidents and measures taken by the bank's Management Board and − identified needs for amending the bank's information security policy, for the purpose of its improvement. LOGICAL SECURITY CONTROLS
29. The bank shall define, document, implement, monitor and regularly review procedures for
controlling access to information assets and IT systems for their appropriate management. The procedures should include controls for monitoring deviations from granted access rights and unusual activities. The procedures should encompass at least the following elements:
− adherence to the need to know principle, the least privilege principle and the segregation of duties principle; − unique identification and the ability to determine the responsibility of the IT system user during his access and performance of activities within its frames; − the right to privileged, administrative access to critical IT systems using multifactor authentication;
− recording of activities and protection of generated records from unauthorized change or deletion, at least for users with the right to privileged access; − managing access rights for their timely approval, revocation or change; − periodically reviewing granted access rights for verification and confirmation, in accordance with the frequency determined by the conducted IT risk analysis. PHYSICAL SECURITY CONTROLS
30. The Bank shall define, document and implement physical security measures to protect IT
assets located in data centers from unauthorized access and harmful environmental influences, proportionate to their significance. The Bank shall allow physical access to IT assets located in data centers only to authorized persons in accordance with their tasks and responsibilities. IT OPERATIONS
31. The bank shall appropriately manage its IT operations based on documented, adopted and
established processes and procedures.
Pursuant to paragraph 1 of this item, the bank shall define the use, the monitoring and the control of IT systems, including the documentation of critical IT operations and the maintenance of up-to-date records of IT assets. The records of IT assets referred to in paragraph 2 of this item should be sufficiently detailed to:
− enable their rapid identification, classification according to significance, location, custody and their interdependence; − enable the recording of the current configuration for the purpose of appropriate change management and − help in dealing with IT incidents.
32. The bank shall:
− monitor and manage the lifecycle of IT assets to ensure compliance with business, security and risk management requirements; − monitor whether IT assets are supported by the manufacturer or by contracted outsourcing entity providing maintenance services; − monitor whether all relevant upgrades are in place; and − appropriately manage the risks arising from IT assets that are outdated or unsupported.
33. The bank shall establish procedures for planning and monitoring the performance and
capacities of IT systems in order to timely prevent, detect and overcome significant difficulties in their operation.
34. The bank shall:
− define and establish procedures for backing up data on critical IT systems (backup) and restore them, in order to verify the reliability of the copies;
− to determine the backup scope and frequency in accordance with the risk assessment and the emergence of new threats, the criticality of data and IT systems and business continuity requirements; − regularly test the procedures for restoring data from backup copies.
35. The bank shall ensure that backup copies are stored in a secure manner and are sufficiently
remote from the primary location so that they are not exposed to the same risk. The backup copy of data and critical IT systems, in the scope and frequency defined in item 34, paragraph 1 indent 2 of this Decision, should also be kept at a location outside the digital space or on a dedicated IT asset that provides adequate protection against threats and isolation of the backup copy from the digital space.
36. The bank shall define and establish procedures for preventing IT systems operational
problems and reduce their impact on providing IT services. These procedures should ensure at least the following:
− regular updating of system software, including software used by the bank's employees or customers, with regular and timely installation of critical security upgrades or compensating controls; − application of secure baselines to critical IT systems, workstations and mobile devices; − establishment of network segmentation, encryption of network traffic and application of data loss prevention systems, in accordance with a risk assessment and the level of data classification; − protection of data stored at the data location and, if necessary, their encryption in accordance with the level of classification.
37. The bank shall ensure that IT operations are carried out in accordance with business
requirements, regularly maintain and improve their efficiency, especially in the event of changes in the business environment and new risks. The bank shall establish a change management process, which will include their planning, testing, documentation, approval and implementation.
38. The bank shall record, monitor and keep records of the performance of critical IT
operations in order to enable timely detection, analysis and error correction.
39. In addition to the requirements referred to in items from 29 to 38 of this Decision, in order
to ensure cyber resilience, banks should put in place additional security measures in order to attain and maintain the appropriate cybersecurity maturity level as follows:
− basic level for all banks and
− intermediate level for systemically important banks.
The additional security measures from paragraph 1 of this item, necessary to achieve the basic, i.e. the intermediate cybersecurity maturity level are listed in Annex no. 3, which is an integral part of this Decision. Taking into account the assessments for increased risks of cyber threats, the bank shall determine the achievement and maintenance of a higher cybersecurity maturity level, if necessary.
A bank that is identified as a systemically important bank for the first time shall comply with the requirements of paragraph 1 indent 2 of this item within twelve months after receiving notification from the National Bank that it has been identified as a systemically important bank. SECURITY MONITORING
40. The bank shall establish a process and implement procedures for regular monitoring and
detection of activities that have an impact on its information security, in order to respond on time when they occur. To this end, the bank shall introduce appropriate and efficient mechanisms for detecting violations of physical or logical security that may affect the confidentiality, integrity and availability of information and IT assets. The procedures for regular monitoring and detection shall include:
− the existence of relevant internal and external factors that may cause disruptions referred to in paragraph 2 of this item, taking into account the manner of performing operational functions and IT operations; − records of detection of access right violation by contracted outsourcing entities, as well as internal access violation; − records of detection of unauthorized transfer of information; − detection of publicly known vulnerabilities in the bank's IT systems; − detection of malicious software and its overcoming; and − emergence of potential external and internal threats that may significantly affect the bank's operations.
41. The bank shall actively monitor technological development in order to raise awareness of
new security risks and to take measures to overcome them.
INFORMATION SECURITY TESTING
42. The bank shall test information security in order to detect weaknesses in IT systems
effectively.
The bank shall define and implement information security testing that corresponds to the assessment of the level of IT risk in accordance with item 14 of this Decision and the threats and weaknesses determined by the security monitoring procedures, defined in item 40 of this Decision.
43. The bank shall ensure that the information security testing referred to in item 42 paragraph
2:
− is performed by an independent person(s) with sufficient knowledge, skills and expertise in the area and who is not involved in the design, development and implementation of the security measures that are being tested;
− vulnerability scans and testing of the cyber resilience.
44. The bank shall regularly test the established security measures with the following scope
and frequency:
− testing of all critical IT systems, at least once a year and − testing of IT systems, which according to the risk assessment are not critical for the bank, at least once every three years. Testing of security measures should take into account relevant, different and realistic attack scenarios.
45. The bank shall test security measures in cases of significant changes in its IT infrastructure,
processes or procedures and/or in case of changes due to significant IT incidents and/or before the launch of new or significantly changed critical applications available online (on the Internet).
46. The bank shall monitor and analyze the results of the conducted tests and update security
measures accordingly. In case of critical IT systems, it should be performed instantly, without any delay. INFORMATION SECURITY TRAINING AND AWARENESS
47. The bank shall develop and implement a training plan that includes periodic activities to
raise awareness of information security of its employees and contracted IT outsourcing entities, for the proper performance of their duties in accordance with the information security policy and the acquisition of knowledge and skills to overcome IT risks. The bank shall implement the training referred to in paragraph 1 of this item at least once a year for all employees, and if it deems it necessary, also for contracted IT outsourcing entities. IT INCIDENT MANAGEMENT
48. The bank shall define, document and establish procedures and the appropriate process for
efficient IT incident management. In the IT incident management process, the bank shall include:
− procedures for determining and their recording, including the category of the materialized IT risk, in accordance with Annex No. 1, which is an integral part of this Decision; − monitoring, analysis, classification of IT incidents in accordance with the defined criteria and reporting procedures in accordance with the act regulating the guidelines for the classification of operational and security incidents and the manner and procedure for reporting incidents and fraud;
− roles and responsibilities in the event of the occurrence of different categories of IT incidents; − activities to overcome the main causes of IT incidents, in order to prevent their recurrence; − procedures for dealing with IT incidents, in order to reduce their impact on business continuity; − a communication plan that includes procedures for internal reporting of incidents, their escalation and informing affected outsourcing entities. IT PROJECT MANAGEMENT
49. The bank shall establish an IT project management process by defining the roles and
responsibilities necessary to support the implementation of the IT strategy.
50. The bank shall appropriately monitor and mitigate the risks arising from the management
of IT projects, as well as the risks from their interconnection and dependence on the same resources.
51. The bank shall establish, define and implement an IT project management process that
should include at least:
− project objectives;
− roles and responsibilities;
− the procedure for assessing the risk that affects their successful implementation; − the development of the implementation plan, the time frame and the phases; − the definition of the key milestones and − change management requirements.
52. The bank shall provide a prior analysis of the information security requirements related to
the IT project and their approval by the person responsible for the security of the information system.
53. The bank shall include in the project team representatives from all business lines that may
be affected by the IT project. The project team should have the necessary knowledge for the safe and successful implementation of the IT project.
54. In accordance with the determined significance and scope of the IT project, the bank shall
timely inform the Management Board about its implementation status and the risks thereof.
IT CHANGE MANAGEMENT
55. The bank shall be obliged to define and establish a process for procurement, development,
upgrading and maintenance of IT systems, as part of the change management process. The bank shall be obliged to define and approve at least the following requirements before any procurement or development of an IT system:
− the characteristics of the IT system;
− the function it should perform;
− the required performances;
− the possibility of its upgrade and maintenance; − the adaptability and compatibility with other IT systems and − the necessary information security standards.
56. The bank shall be obliged to establish measures to control the risk of changes to the IT
system during its development and its launching in order to achieve the business objectives for which it is intended.
57. The bank shall:
− define procedures for testing and approval of the IT system before its launching; − use IT testing systems that match production IT systems and − confirm by testing that the changed IT systems perform the operational functions for which they are planned. As an exception to paragraph 1 of this item in case of an urgent need for a change in the IT system, the bank may not test the IT changes, if it has taken appropriate protective measures.
58. The bank shall:
− separate production IT systems on which operational functions are performed from development, testing systems and other non-production IT systems and shall ensure appropriate segregation of duties; − reduce the possibility of making changes to production IT systems that have not been adequately tested; − protect the integrity and confidentiality of production data in non-production IT systems and shall limit access to production data from authorized persons, in accordance with the risk assessment conducted, and − protect the integrity of the source code of internally developed IT systems.
59. The bank shall be obliged to document the change made to the IT system and shall have
up-to-date user and technical documentation, where applicable.
BUSINESS CONTINUITY MANAGEMENT
60. The bank shall be obliged to establish a business continuity management process for the
purpose of uninterrupted provision of IT services and reduction of the losses due to an interruption in the operations. The business continuity management process referred to in paragraph 1 of this item shall be regulated by the provisions of the National Bank regulation on the methodology for risk management. To meet the requirements for recovery of IT systems and information security when ensuring business continuity, the bank shall also make:
− business impact analysis;
− IT system recovery plan and its testing.
BUSINESS IMPACT ANALYSIS
61. The bank shall be obliged to regularly carry out a business impact analysis, taking into
account the criticality and interdependence of the operating functions supported by IT, the IT assets and the IT outsourcing services, in order to ensure confidentiality, integrity and availability.
62. The bank shall be obliged to ensure functionality of the IT systems and provision of the IT
services in accordance with the conducted business impact analysis referred to in item 61 of this Decision. IT SYSTEM RECOVERY PLAN
63. The bank shall be obliged, according to the conducted business impact analysis referred to
in item 61 of this Decision and the possible scenarios, to prepare and implement an IT system recovery plan that will ensure availability of the critical IT systems, within the defined values for the Recovery Time Objective and the Recovery Point Objective.
64. In cases of serious disruption of the operations, the bank shall be obliged, on the basis of
the risk assessment carried out in accordance with item 14 of this Decision, to define priorities of the activities it will undertake for recovery of the critical IT systems.
65. In the IT system recovery plan, the bank shall be obliged to anticipate several different
and real scenarios, including scenarios of cyber-attacks it could be exposed to, as well as an assessment of their impact on the operations. According to the scenarios defined in paragraph 1 of this item, the bank shall also be obliged to indicate the procedures for recovery of the IT system and to ensure information security.
66. In the IT system recovery plan, the bank shall be obliged to define:
− protection and recovery of the data necessary for the business process continuity at the disaster recovery location.
− disaster recovery location where the data will be protected, at an adequate geographical distance from the primary location, in order to minimize the risk of simultaneous unavailability of both locations and − cyber resilience plan.
67. The bank shall be obliged to ensure the adequate capacity and availability of the IT systems
at the disaster recovery location, according to the values defined in item 63 of this Decision.
68. In the IT system recovery plan, the bank shall also be obliged to anticipate measures in
case of an interruption of the availability of the critical IT systems that provide an IT service from an outsourcing entity. TESTING OF THE IT SYSTEM RECOVERY PLAN
69. The bank shall be obliged to regularly, at least once a year, test the IT system recovery
plan that supports important operational functions, including those provided by outsourcing entities.
70. With the testing of the IT system recovery plan, the bank shall be obliged:
− to conduct testing of various and real scenarios that can cause a serious impact on its operations; − to confirm the functionality of the disaster recovery location and the possibility of reverting to a normal regime of operation at the primary location; − to implement the plan so that it will check the assumptions stated in it; − to check and assess the readiness of the employees, the outsourcing entities and the IT systems according to the previously defined success criteria amid given scenarios and testing goals.
71. The bank shall be obliged to document the results of the testing, to anticipate measures
for overcoming the identified weaknesses and to submit an aggregate report to the National Bank.
72. The bank shall be obliged, according to the results of the testing, the knowledge and
experiences acquired from the previous testing and on the basis of the information about the emergence of new threats, at least once a year to identify the need for updating the IT system recovery plan. When updating the IT system recovery plan, the bank shall be obliged to take into account the changes in the operational functions, the IT assets for their support and the need for changes in the values defined in item 63 of this Decision. IT OUTSOURCING
73. The bank shall be obliged to establish a process of managing the risks associated with the
use of an IT service from outsourcing entities.
VII. TRANSITIONAL AND CLOSING PROVISIONS
77. This Decision shall enter into force on the eighth day from the day of its publication in the
Official Gazette of the Republic of North Macedonia, and shall apply from 1 January 2026. The bank shall be required to comply with item 39 paragraphs 1 and 2 of this Decision as of 30 June 2026.
78. The implementation of this Decision shall supersede the Decision on the Methodology for
bank's information system security (Official Gazette of the Republic of Macedonia No. 78/18 and 27/25). Anita Angelovska Bezhoska Governor and Chairman of the Council of the National Bank of the Republic of North Macedonia
IT RISK CATEGORY DEFINITION
I. IT availability and continuity risks Risk of events that may adversely affect the operation and availability of IT systems
and data, including the inability to timely establish the services of the institution due to malfunctions in the hardware and software components of IT systems, weaknesses in the management of IT systems or other events.
II. IT security risks Risk arising from unauthorized access to IT systems and data inside the bank and
outside the bank (e.g. intrusions from the digital space).
III. IT change risks Risk arising from the bank's inability to manage the changes in IT systems in a
timely and controlled manner, especially when it comes down to major and complex changes in the applications. IV.IT data integrity risks Risk that data stored and processed in IT systems is incomplete, inaccurate or inconsistent in different IT systems, for example due to weak or non-existent controls over the life cycle of the data (designing the data topology, developing the data model and/or data dictionary, verification of the data entry, control over the data extraction, transmission and processing, including also output data), thereby disturbing the bank's ability to provide services and information related to the (risk) management with the bank in a right and timely manner.
V. IT outsourcing risks Risk arising from the engagement of an outsourcing entity or part of a group that
operates an IT system in which bank data is stored and bank and financial activities are processed, whereby such manner of work adversely affects the bank’s operations and the manner of its risk management.
Annex 1 - IT risk categorization (recommendations for unification of the IT risk categories in the EU 1
)
The definitions of all IT risk categories also include examples of IT risks with their description which are stated in the following table attached to Annex 1.
Annex: IT risk categories and a certain number of IT risks that have great potential and may cause operational interruptions with
material and financial damage and/or damage the bank's reputation Categories of IT risk IT risk 2 Risk description Examples IT availability and continuity risk Inadequate capacity management A lack of resources (e.g. hardware, software, staff, service providers) can result in an inability to scale the service to meet business needs, system interruptions, degradation of service and/or operational mistakes.
1 Guidelines on ICT Risk Assessment under the SREP (European Banking Authority - EBA/GL/2017/05). ICT risks are listed under the risk category they most impact but they may impact other risk categories.
Inadequate IT continuity and disaster recovery planning Failure of IT planned availability and/or continuity solutions and/or disaster recovery (e.g. fallback recovery datacenter) when activated in response to an incident.
Attacks on communication connections and conversations of all kinds or IT systems with the objective of collecting information and/or committing frauds.
Security threats due to lack of security awareness whereby employees do not understand, neglect or fail to adhere to IT security policies and procedures.
and IT development managed change due to a lack of testing or improper change management practices) to e.g. software, IT systems and data. corruption, deletion) and/or IT system performance (e.g. breakdown, performance degradation).
Inadequate lifecycle and patch management
The failure to maintain an adequate inventory of all IT assets, the lack of management of their lifecycle and the upgrades can lead to unpatched and outdated IT systems that may not support business needs.
Poorly projected and/or poorly managed data architecture Ill managed data architectures, data model and transfer, occurrence of multiple versions of the same data, which are no longer consistent due to differently applied data models or definitions, and/or differences in the underlying data generation and change process. The existence of different customer databases per product or business unit with different data definitions and fields, which can lead to unreconciled data, their comparison and/or integration. IT outsourcing risk Inadequate dependence on using services from an outsourcing entity Non-availability of critical IT services, telecommunication services and other IT services from outsourcing entities. Loss of or damage to the critical data entrusted to the outsourcing entity.
Annex 2 - List of quantitative IT risk indicators
Quantitative indicators - KRI green yellow red Frequency of determining the value of the indicator Availability of the critical IT systems in case of unplanned activities (according to the definition of a critical IT system) >= 99.81 % 99.80 % - 99.51% <= 99.50% quarterly Number of IT incidents (including failed jobs), failed backup, etc. <15 15 ‒ 31 > 31 quarterly Percentage of workstations updated with critical security patches issued in the quarter >90% 85 % - 90% <85% quarterly Percentage of critical IT systems without up-todate patches <10% 10 % - 20% >20% quarterly Percentage of updated workstations with antivirus definitions >90% 85 % - 90% <85% quarterly Percentage of individual IT systems whose support from the producer has expired <0.5% 0.5% - 1.1% >1.1% annually Percentage of employees who have successfully undergone the information security training in the last year. >90% 80% - 90% <80% annually Percentage of employees whose privileges for the right of access to the critical IT systems have been revised in the current year >80% 50% - 80% <50% annually Tolerance level − GREEN - there is no need for taking additional measures; − YELLOW - a plan with improvement measures needs to be prepared. There is a need for monitoring the implementation of the measures and reporting thereon and − RED - appropriate improvement measures need to be taken immediately, without unnecessary delay.
Annex 3 - List of measures to achieve the target cybersecurity maturity level
LIST OF MEASURES TO ACHIEVE THE BASIC CYBERSECURITY MATURITY LEVEL (BL1-BL115) Ref. No. Area Maturity level Measure description BL1 1. Cyber risk management 1. basic The risks associated with information security are discussed with the Management and/or the Supervisory Board in case of major, visible incidents or at request of the National Bank. BL2 1. Cyber risk management 1. basic The responsible officer for information security shall prepare a report on the status of information security at least twice a year. BL3 1. Cyber risk management 1. basic The budgeting process shall also include costs related to information security. BL4 1. Cyber risk management 1. basic The bank shall also take into account the risks arising from major suppliers (e.g. telecommunications, electricity supply). BL5 1. Cyber risk management 1. basic The bank shall undertake activities for self-assessment / assessment of risks in order to check the readiness and status of implementation of the controls that ensure an adequate level of readiness. BL6 1. Cyber risk management 1. basic The bank has an information security policy that includes technologies, procedures, training and measures for reduction of risks. BL7 1. Cyber risk management 1. basic The information security policy is adjusted to the level of risk and the level of complexity of the bank in the IT risk management. BL8 1. Cyber risk management 1. basic A process of management of the risks associated with the use of an IT service from an outsourcing entity is defined, according to the criticality and complexity of the services it provides. BL9 1. Cyber risk management 1. basic The bank has defined procedures for management of security incidents related to cyber-attacks. BL10 1. Cyber risk management 1. basic The bank shall record and classify according to their criticality and value all IT assets, hardware (final devices, including transferable and mobile; network devices; IOT devices; and servers), related to IT infrastructure (physically, virtually and in cloud) and software (operating systems and applications). BL11 1. Cyber risk management 1. basic IT assets have assigned owners/custodians. BL12 1. Cyber risk management 1. basic The changes in the IT systems (hardware, software, banking systems and configurations) shall be made in accordance with a defined process in order to reduce the risks of inadequate IT changes.
BL13 1. Cyber risk management 1. basic The lists of the IT assets shall be updated at least once a year. BL14 1. Cyber risk management 1. basic The bank shall determine, record and plan on time the activities for replacement of End-Of-Life systems. BL15 1. Cyber risk management 1. basic The bank has established a process of management of the risks associated with information security. BL16 1. Cyber risk management 1. basic The Management Board shall take care of the timely implementation of the audit recommendations related to information security, especially in the area of improving cyber security. BL17 1. Cyber risk management 1. basic A process of assessment of the risk of the occurrence of internal and external threats and the probability of their materialization, has been established. BL18 1. Cyber risk management 1. basic Partial risk analyses shall be made when introducing new technologies, products, services and network connections. BL19 1. Cyber risk management 1. basic The risk assessment shall also take into account the cyber risks arising from new banking products, services and business relations. BL20 1. Cyber risk management 1. basic The risk assessment shall also take into account the risk of using end of life (EOL) software and hardware. BL21 1. Cyber risk management 1. basic The Internal Audit Department shall carry out a periodic check on the established IT risk management system. BL22 1. Cyber risk management 1. basic The Internal Audit Department shall carry out a periodic check on the scope and efficiency of the system of filing the records of the executed information system procedures (audit trail). BL23 1. Cyber risk management 1. basic The audit findings shall be presented to the Management Board and the Auditing Committee and timely corrective activities shall be undertaken to overcome them. BL24 1. Cyber risk management 1. basic The annual training plan shall also include trainings for employees that are intended for improving and increasing information security. BL25 1. Cyber risk management 1. basic The candidates for new job positions, the employees with the outsourcing entities (suppliers) who have access to the information system shall be subject to evaluation appropriate to the level of access to confidential data, the business requirements and the acceptable level of risk. BL26 1. Cyber risk management 1. basic There is an annual plan for information security trainings that includes current cyber threats. BL27 1. Cyber risk management 1. basic The responsible officer for information security shall prepare informative materials for certain increasing threats and may jeopardize the bank and its clients.
BL28 1. Cyber risk management 1. basic
The bank has established a process of regular informing the clients about the protection measures when using financial services especially those with a higher level of risk or in case of a new threat. BL29 1. Cyber risk management 1. basic The employees with administrator privileges shall have additional trainings according to the assigned right of privileged access and the need for a higher security level. BL30 1. Cyber risk management 1. basic When performing their business activities, the employees shall be acquainted and shall act in compliance with the information security policy. BL31
2. Collecting, processing and
analyzing relevant threats obtained from accurate and verified sources
BL41 3. Cybersecurity controls 1. basic The bank shall use systems to prevent and detect network attacks (such as IDS/IPS). BL42 3. Cybersecurity controls 1. basic Wireless networks shall be configured with security settings that require strong encryption for authentication and transmission. BL43 3. Cybersecurity controls 1. basic The bank's network infrastructure shall be divided into multiple zones with different protection levels (VLAN segmentation, separate isolated networks) in order to minimize damage. BL44 3. Cybersecurity controls 1. basic Security controls shall be used for remote access to all admin consoles. BL45 3. Cybersecurity controls 1. basic The guest Wi-Fi network shall be completely segmented from the internal network (if any). BL46 3. Cybersecurity controls 1. basic Critical IT systems that are built on outdated technologies shall be subject to regular review in order to identify potential vulnerabilities, consider the possibility of upgrading and replacing them, and establish new protection levels. BL47 3. Cybersecurity controls 1. basic When granting employees access to IT systems, applications and data necessary to perform business activities, the need to know principle and the principle of least privilege shall be respected. User access right verification for all IT systems, applications and data shall be performed periodically according to their riskiness. BL48 3. Cybersecurity controls 1. basic All physical and logical access granted to employees upon termination of employment shall be immediately revoked/changed. BL49 3. Cybersecurity controls 1. basic Admin profiles shall be limited in number, recorded, protected and strictly controlled. They shall be used in a secure environment. General admin profiles shall not be used without their business need and established control. BL50 3. Cybersecurity controls 1. basic Admins shall be divided into three segments: operating systems, computer network and database. BL51 3. Cybersecurity controls 1. basic Confidential data shall be encrypted when sent over a public or external network. BL52 3. Cybersecurity controls 1. basic Portable devices (laptop, tablet, USB flash drives) shall be encrypted if they contain confidential data. BL53 3. Cybersecurity controls 1. basic Employees, suppliers, and outsourcing parties shall establish a remote access to critical IT systems through a multifactor authentication. BL54 3. Cybersecurity controls 1. basic Administrative, physical, and technical controls shall be established to prevent unauthorized software installation.
BL55 3. Cybersecurity controls 1. basic The call center shall use adopted user authentication procedures in accordance with the riskiness of the request/transaction. BL56 3. Cybersecurity controls 1. basic Admins shall use 2 (two) accounts (one for everyday work - nonadmin and one admin). BL57 3. Cybersecurity controls 1. basic Physical access to critical IT systems and confidential data shall be limited. BL58 3. Cybersecurity controls 1. basic The procedures carried out in critical IT systems shall be documented. BL59 3. Cybersecurity controls 1. basic Unauthorized access to critical IT systems shall be blocked. BL60 3. Cybersecurity controls 1. basic The bank shall establish controls to prevent unauthorized access to the cryptographic keys and codes used by the bank. BL61 3. Cybersecurity controls 1. basic Employees cannot connect unauthorized devices to the IT infrastructure. BL62 3. Cybersecurity controls 1. basic Programmers working for the bank shall adhere to security industry practices as part of the software development cycle (SDLC). BL63 3. Cybersecurity controls 1. basic The security of applications, especially those exposed to the internet, shall be verified by testing against the most common cyberattacks before their release and/or significant modification. BL64 3. Cybersecurity controls 1. basic Independent testing (vulnerability scanning and system resilience testing) shall be performed in accordance with the assessment of the cyber risk exposure of IT systems and the internal network. BL65 3. Cybersecurity controls 1. basic The firewall rule sets shall be reviewed at least once every six months. BL66 3. Cybersecurity controls 1. basic IT systems have been established to filter and protect electronic communication from most common cyberattacks (such as: detecting and blocking malicious PDF documents or links to malicious websites). BL67 3. Cybersecurity controls 1. basic Upon notification, client transactions that deviate from normal behavior pattern shall be monitored. BL68 3. Cybersecurity controls 1. basic The access to critical IT systems from an external (Internet) network shall be monitored to protect against unauthorized access or unusual activities. BL69 3. Cybersecurity controls 1. basic The use of admin privileges shall be monitored and recorded in the audit trail system. BL70 3. Cybersecurity controls 1. basic Security log reports shall be reviewed regularly. BL71 3. Cybersecurity controls 1. basic Transactions executed through modern (alternative) channels shall be monitored for unusual client behavior.
BL72 3. Cybersecurity controls 1. basic Normal network activity rules have been established. BL73 3. Cybersecurity controls 1. basic Processes and tools are in place to alert about unauthorized users, devices, connections, and software. BL74 3. Cybersecurity controls 1. basic Responsibilities have been established for monitoring and reporting suspicious and unusual activities. BL75 3. Cybersecurity controls 1. basic Physical controls are in place to detect unauthorized access. BL76 3. Cybersecurity controls 1. basic A process for critical software updates has been established within a specified time frame. BL77 3. Cybersecurity controls 1. basic Upgrades shall be tested before being made to IT systems. BL78 3. Cybersecurity controls 1. basic Information (reports) on the update status (completed, not completed, and the reasons for it) shall be reviewed by the management. BL79 3. Cybersecurity controls 1. basic Prior to update, the operational risk shall be assessed. BL80 3. Cybersecurity controls 1. basic Updates for high-risk vulnerabilities have been tested and implemented upon their release or risk acceptance. BL81 3. Cybersecurity controls 1. basic Findings determined by IT risk assessment shall be addressed according to their criticality within established time frames (action plan). BL82 3. Cybersecurity controls 1. basic Data shall be destroyed or deleted from the hardware or a portable device in case of its decommission or theft. BL83 3. Cybersecurity controls 1. basic A process has been established to overcome vulnerabilities identified through system resilience testing. BL84 4. Managing interdependence 1. basic The bank shall approve networking with IT systems of outsourcing parties. BL85 4. Managing interdependence 1. basic The network diagram shall present all external network connections. BL86 4. Managing interdependence 1. basic The list of providers (outsourcing parties) with whom an IT outsourcing agreement has been concluded shall be maintained and regularly updated. BL87 4. Managing interdependence 1. basic The IT risk assessment shall also estimate the criticality of IT services and outsourcing services. BL88 4. Managing interdependence 1. basic A process has been established to inform the bank about the use of subcontractors by IT service providers (outsourcing party). BL89 4. Managing interdependence 1. basic The valid contracts concluded with outsourcing parties (providers) who provide IT services related to receiving, processing and storing banking data shall include security requirements.
BL90 4. Managing interdependence 1. basic The contracts state that the controls on the outsourcing party (provider) shall be revised and confirmed by an independent team. BL91 4. Managing interdependence 1. basic The contracts provide for data recovery or destruction by the outsourcing entity upon completion/termination of the contract. BL92 4. Managing interdependence 1. basic The Bank shall establish notifications on IT incidents registered at the provider (outsourcing party) that are related to the service it provides in accordance with the agreement. BL93 4. Managing interdependence 1. basic The Bank shall use certificates or audit reports issued by third parties or internal audit reports which the provider (outsourcing entity) has put on disposal. BL94 4. Managing interdependence 1. basic The Bank shall check the accomplishment of the IT system recovery plan of the outsourcing entity (provider) on the important operational function it provides for the bank. BL95 4. Managing interdependence 1. basic The supervision of external persons shall be formally regulated by appointing an authorized person (guardian). BL96 4. Managing interdependence 1. basic The access of outsourcing entities to the bank's confidential data shall be recorded in the system of record and audit trails. These reports shall be monitored regularly. BL97 Managing interdependence 1. basic The outsourcing entities access to confidential data shall be established by respecting the need to know principle and the least privilege principle. BL98 5. Cyber incident management and resilience 1. basic The bank has defined procedures to respond to cyber-attacks. BL99 5. Cyber incident management and resilience 1. basic The Bank shall establish communication channels for the employees to report an IT incident within a certain time frame. BL100 5. Cyber incident management and resilience 1. basic Roles and responsibilities of the IT Incident Management Team shall be defined. BL101 5. Cyber incident management and resilience 1. basic The IT Incident Management Team shall include experts in various fields (law, public relations, management, IT, etc.). BL102 5. Cyber incident management and resilience 1. basic There are procedures in place to protect and recover all IT important operational functions. BL103 5. Cyber incident management and resilience 1. basic The Bank shall use an IT system recovery plan and procedures for data protection and recovery in the event of an IT incident and/or advanced cyber threat (e.g. Ransomware). BL104 5. Cyber incident management and resilience 1. basic Testing the IT system recovery plan involves collaboration with outsourcing entities who have been granted with an important operational function.
BL105 5. Cyber incident management and resilience 1. basic Testing of the IT system and data recovery plan shall be performed at least once a year. BL106 5. Cyber incident management and resilience 1. basic Periodic checks and backup testing shall be performed to determine whether they can be used in case of a business need. BL107 5. Cyber incident management and resilience 1. basic IT incident notifications shall be established. BL108 5. Cyber incident management and resilience 1. basic A plan for dealing with IT incidents is in place, which places them into categories with а different resolution priority. BL109 5. Cyber incident management and resilience 1. basic The Bank shall establish a process to enable a rapid and appropriate response to significant IT incidents and cyber threats, in order to limit damage, ensure minimal interruption of business activities, and take measures to mitigate the risks of their recurrence. BL110 5. Cyber incident management and resilience 1. basic Employees know their roles and responsibilities for reducing IT risks and reporting IT incidents. BL111 5. Cyber incident management and resilience 1. basic Responsible officers shall be appointed to make analysis and take measures in the event of IT incidents. BL112 5. Cyber incident management and resilience 1. basic The procedures envision notification of the competent authorities in accordance with the legal regulations and/or the concluded memorandum/protocol for cooperation with third parties (if any) in the event of a significant IT incident. BL113 5. Cyber incident management and resilience 1. basic The Supervisory Board shall be notified on IT incidents at least twice a year. BL114 5. Cyber incident management and resilience 1. basic IT incidents shall be classified, recorded, and their status shall be monitored until they are resolved. BL115 5. Cyber incident management and resilience 1. basic The Bank shall establish criteria for informing of bank's bodies about possible cyber incidents, according to the potential damage and risks.
LIST OF MEASURES TO ACHIEVE THE INTERMEDIATE CYBERSECURITY MATURITY LEVEL (IL1-IL56) Ref. No. Area Level of readiness Measure description IL1 1. Cyber risk management 2. intermediate The Management Board shall review, while the Supervisory Board shall approve the information security policy, which shall include protective mechanisms against cyber-attacks, if needed, and at least once every three years. IL2 1. Cyber risk management 2. intermediate The budgeting process shall include hiring qualified persons with the necessary specialized tools and knowledge to ensure cyber security. IL3 1. Cyber risk management 2. intermediate The bank has established a cybersecurity risk appetite. IL4 1. Cyber risk management 2. intermediate Risks that exceed the cybersecurity risk appetite shall be reported to the bank's bodies, which take improvement measures. IL5 1. Cyber risk management 2. intermediate The information security policy shall provide protection against cybersecurity attacks. IL6 1. Cyber risk management 2. intermediate The Bank has prescribed minimum technical standards for IT asset security. IL7 1. Cyber risk management 2. intermediate All system configuration changes shall be implemented through a formal request, documented approval, and an assessment of their impact on information security. IL8 1. Cyber risk management 2. intermediate The cybersecurity risk management shall include identification, assessment, mitigation measures, monitoring and reporting. IL9 1. Cyber risk management 2. intermediate The annual information security risk analysis and assessment shall use a scenario analysis approach to assess complex IT systems/processes where there is a concentration and interconnection of risks from individual IT systems (such as:
virtualization, use of cloud infrastructure, ATM infrastructure).
IL10 1. Cyber risk management 2. intermediate
In the process of IT risk assessment and monitoring, the bank shall use internal exposure monitoring quantitative indicators and their tolerance thresholds. IL11 1. Cyber risk management 2. intermediate The Internal Audit Department shall check the established outsourcing management system IL12 1. Cyber risk management 2. intermediate The Internal Audit Department shall check the established system for security incident response. IL13 1. Cyber risk management 2. intermediate The person responsible for information system security shall also take into account new cyber threats and new technologies.
IL14 1. Cyber risk management 2. intermediate
The bank’s Management Board and other management bodies shall have a specialized training according to their responsibilities, the granted right to access IT systems and the required level of protection of the data they access. IL15 1. Cyber risk management 2. intermediate The effectiveness of training shall be verified through testing. IL16 1. Cyber risk management 2. intermediate Employees can identify and recognize potential cyber threats. IL17 1. Cyber risk management 2. intermediate The risk assessment shall take into account risks related to cyber threats, which shall be discussed by the Risk Management Committee and the Management Board. IL18
2. Collecting, processing and
analyzing relevant threats obtained from accurate and verified sources
2. intermediate
A process has been established for collecting, processing and analyzing information obtained from external relevant sources (subscription to relevant external sources, information from the banking sector and relevant government institutions, social networks, platforms and forums for online communication) and internal sources (e.g. audit trail systems, IPS/IDS, fraud monitoring systems, etc.). IL19
2. Collecting, processing and
analyzing relevant threats obtained from accurate and verified sources
2. intermediate
The Bank shall maintain data warehouse/location to store analyzed threat data collected from external and internal sources. IL20
2. Collecting, processing and
analyzing relevant threats obtained from accurate and verified sources
2. intermediate
The method of accessing, using and sharing the collected, processed and analyzed threat data shall be defined by an internal act. IL21 3. Cybersecurity controls 2. intermediate The bank shall implement a system for protection against DDoS attacks at its own or its internet service provider, in accordance with the risk analyses conducted. IL22 3. Cybersecurity controls 2. intermediate Technical measures have been established to prevent the execution of unauthorized applications on authorized devices connected to the network. IL23 3. Cybersecurity controls 2. intermediate The responsible person shall be notified of changes in user access privileges. IL24 3. Cybersecurity controls 2. intermediate Confidential data in non-production environments shall be anonymous according to technical capabilities and acceptable risk levels. IL25 3. Cybersecurity controls 2. intermediate The new, unauthorized connections to workstations connected to the network shall be blocked. IL26 3. Cybersecurity controls 2. intermediate The bank shall use a centralized solution to manage upgrades, configurations and IT security vulnerabilities. IL27 3. Cybersecurity controls 2. intermediate Any unpatched workstation shall be automatically blocked or prevented from accessing the network infrastructure.
IL28 3. Cybersecurity controls 2. intermediate Antivirus and Antimalware programs shall be installed on all devices (such as workstations, laptops, mobile phones, etc.). IL29 3. Cybersecurity controls 2. intermediate The bank shall remotely delete data on mobile devices if they are lost or stolen. IL30 3. Cybersecurity controls 2. intermediate A process has been established to identify vulnerabilities discovered during the design and testing phase of new applications in order to reduce threats and risks. IL31 3. Cybersecurity controls 2. intermediate All interdependencies between applications and services shall be determined and recorded. IL32 3. Cybersecurity controls 2. intermediate Executable programs and scripts shall be digitally signed (where possible and within the acceptable level of risk) to verify the author and to guarantee the integrity of the code (that it has not been modified). IL33 3. Cybersecurity controls 2. intermediate Independent testing of the computer network perimeter and critical Internet applications shall be performed regularly to identify security vulnerabilities. IL34 3. Cybersecurity controls 2. intermediate Prior to its connecting to the network, each new device shall be subject to testing, whereby the results shall be analyzed, and the identified security vulnerabilities shall be overcome. IL35 3. Cybersecurity controls 2. intermediate Data loss prevention tools have been established to detect potential unauthorized or unintentional transmissions of confidential data. IL36 3. Cybersecurity controls 2. intermediate An automated tool shall be used to determine unimplemented security updates and the number of days since the update was released by the manufacturer. IL37 3. Cybersecurity controls 2. intermediate Upgrades that have not been made shall be assigned a different priority and shall be tracked according to the assigned status. IL38 4. Managing interdependence 2. intermediate The network diagram shall be regularly updated in case of new network connections to external IT systems. IL39 4. Managing interdependence 2. intermediate Network and system diagrams and schemes shall be stored in a secure manner with appropriate access control. IL40 4. Managing interdependence 2. intermediate Primary and secondary communication lines to outsourcing entities and the introduced controls shall be tested on a regular basis. IL41 4. Managing interdependence 2. intermediate The ability of the established security controls to detect and prevent potential attacks coming from outsourcing or internal network has been confirmed (verified). IL42 4. Managing interdependence 2. intermediate The Management Board shall review the summary analyses from the due diligence performed, together with the opinions of the responsible employees on the use of outsourcing IT services and how this affects the inherent risk profile.
IL43 4. Managing interdependence 2. intermediate The agreements stipulate the geographical boundaries within which banking data can be sent and stored. IL44 5. Cyber incident management and resilience 2. intermediate Alternative processes are in place to restore an important operational function within a reasonable time frame. IL45 5. Cyber incident management and resilience 2. intermediate The analysis of IT system outages impact on the bank's operations shall also take into account the impact of cyber-attacks. IL46 5. Cyber incident management and resilience 2. intermediate An in-depth analysis of technical sources, consultants or companies has been conducted with the necessary expertise that could assist the bank in the event of a possible cyber-attack. IL47 5. Cyber incident management and resilience 2. intermediate Identified vulnerabilities and previously learned lessons shall be taken into account to improve the way risks related to cyber threats are managed and to enhance digital resilience. IL48 5. Cyber incident management and resilience 2. intermediate The IT system recovery plan shall include recovery activities in the event of data destruction or loss of data integrity and loss of availability of IT systems and/or data in one or both computer centers. IL49 5. Cyber incident management and resilience 2. intermediate Global and regional trends related to IT incidents and new cyber threats shall be monitored and, in accordance with the assessments, protective measures shall be improved to prevent similar IT incident. IL50 5. Cyber incident management and resilience 2. intermediate In the event of unusual activities according to known attack patterns, IT incident responders shall be alerted. IL51 5. Cyber incident management and resilience 2. intermediate The IT incident response team in the bank has detection and reporting processes related to unauthorized employee activity that could lead to data theft or destruction. IL52 5. Cyber incident management and resilience 2. intermediate IT incident analysis shall be performed in the early stages of a cyberattack to minimize the damage it would cause. IL53 5. Cyber incident management and resilience 2. intermediate The procedures provide for informing the outsourcing parties on the possibility of being affected by the incident. IL54 5. Cyber incident management and resilience 2. intermediate The Bank shall use outsourcing to reduce the harmful impacts of incidents and resolve them, if necessary. IL55 5. Cyber incident management and resilience 2. intermediate To improve the cyber security, the Bank shall carry out an analysis of IT incidents and prepare a summary report with proposed measures. IL56 5. Cyber incident management and resilience 2. intermediate In order to inform the bank's bodies, an analysis of recorded cyber incidents and their global trends shall be conducted.
Read the rest free
Source: National Bank of the Republic of North Macedonia — original document · Summary generated with machine assistance and reviewed before publication; the authoritative text is the regulator's original document. How RegAlert works
More like this from NBRM
NBRM published 7 documents in the last 30 days. We email you each new one the day it's published.