2024-04-12

Added

Decision on the security measures for the operational and security risks related to payment services

The decision requires payment service providers to establish, document, and annually revise an operational and security risk management framework approved by their management body, covering a security policy, risk appetite, defined roles, risk identification, measurement, monitoring, incident management, and a three‑line‑of‑defense model that is independent and adequately resourced. Providers must maintain registries of business functions, processes and information assets, classify them by criticality, conduct comprehensive risk assessments and partial assessments before significant changes, submit annual assessments to the National Bank, and implement preventive, defense‑in‑depth security measures—including confidentiality, integrity and availability controls, least‑privilege access, privileged‑access supervision, physical protection, continuous monitoring, incident reporting, and business continuity planning that is tested at least once a year and updated after tests or changes. They must also establish a testing framework for security measures with at least annual testing of critical systems (or every three years for non‑critical systems), monitor test results and promptly remediate weaknesses, provide annual security‑awareness training for all staff (with specialized training for key‑role employees), and ensure user support procedures that allow users to be informed of incidents, cancel functionalities, and limit transaction amounts as agreed.

National Bank of the Republic of North Macedonia logo

North Macedonia

National Bank of the Republic of North Macedonia

Scan of the document's first page
Share

NBRM published 7 documents in the last 30 days — get each new one by email the day it lands.

Read the rest free

Source: National Bank of the Republic of North Macedonia — original document · Summary generated with machine assistance and reviewed before publication; the authoritative text is the regulator's original document. How RegAlert works

More like this from NBRM

NBRM published 7 documents in the last 30 days. We email you each new one the day it's published.