2024-04-12
Added
The decision requires payment service providers to establish, document, and annually revise an operational and security risk management framework approved by their management body, covering a security policy, risk appetite, defined roles, risk identification, measurement, monitoring, incident management, and a three‑line‑of‑defense model that is independent and adequately resourced. Providers must maintain registries of business functions, processes and information assets, classify them by criticality, conduct comprehensive risk assessments and partial assessments before significant changes, submit annual assessments to the National Bank, and implement preventive, defense‑in‑depth security measures—including confidentiality, integrity and availability controls, least‑privilege access, privileged‑access supervision, physical protection, continuous monitoring, incident reporting, and business continuity planning that is tested at least once a year and updated after tests or changes. They must also establish a testing framework for security measures with at least annual testing of critical systems (or every three years for non‑critical systems), monitor test results and promptly remediate weaknesses, provide annual security‑awareness training for all staff (with specialized training for key‑role employees), and ensure user support procedures that allow users to be informed of incidents, cancel functionalities, and limit transaction amounts as agreed.
NBRM published 7 documents in the last 30 days — get each new one by email the day it lands.
Pursuant to Article 47 paragraph 1 item 6 of the Law on the National Bank of the Republic of North Macedonia (Official Gazette of the Republic of North Macedonia No. 158/10, 123/12, 43/14, 153/15, 6/16, 83/18 and Official Gazette of the Republic of North Macedonia No. 110/21) and Article 123 paragraph 9 of the Law on Payment Services and Payment Systems (Official Gazette of the Republic of North Macedonia No. 90/22), the National Bank of the Republic of North Macedonia Council has adopted the following DECISION on the security measures for the operational and security risks related to payment services
I. GENERAL PROVISIONS
2.4. “Principle of ‘least privilege’” shall denote a minimal set of access
privileges granted for the purpose of carrying out the necessary activities, as well as access to the data necessary for the successful implementation of the business process.
III. SECURITY MEASURES FOR OPERATIONAL AND SECURITY RISKS
3. To establish the security measures for operational and security risks, the payment
service providers shall be obliged to establish an operational and security risk management framework, appropriate and proportionate to the nature, volume and complexity of the activities related to the provision of the payment service.
4. The framework referred to in item 3 of this Decision, shall be approved by the
management body of the payment service provider and shall be revised at least once a year, depending on the changes in the environment and the risk profile. The payment service providers shall be obliged to provide appropriate documentation of the operational and security risk management framework during its implementation.
5. The operational and security risk management framework shall at least include:
appropriate security measures that match the criticality, significance and the characteristics of the service that the payment service provider transfers to the outsourcing provider. The payment service providers shall be obliged to monitor the level of harmonization of the outsourcing providers, with their operational and security risk management framework. Identification and recording of functions, processes and assets
9. The payment service providers shall be obliged to identify and to regularly update
their business functions, the key roles of the performers of the business functions and the processes for support of the business functions in a special registry for that purpose, for their full recording, identification of their significance and interconnectedness with the operational and security risks.
10. The payment service providers shall be obliged to identify and to regularly update
the information systems they use, the communication technology systems, the configurations, their interconnectedness with other internal and external IT systems, for their full recording in the registry and appropriate management of the key business functions and processes referred to in item 9. Classification of functions, processes and assets
11. The payment service providers shall be obliged to classify the recorded business
functions, processes for support and information assets from the registry referred to in item 9, according to their criticality. Assessment of the risks associated with functions, processes and assets
12. The payment service providers shall be obliged to constantly monitor the threats
and vulnerabilities, and to regularly revise the scenarios associated with the risks that affect the business functions, critical processes and information assets. The payment service providers shall be obliged to carry out a comprehensive assessment of the exposure to the operational and security risks associated with the payment services they provide and of the appropriateness of the implemented measures and control mechanisms for managing operational and security risks. The payment service providers shall be obliged to submit an updated and comprehensive assessment of the exposure to the operational and security risks referred to in paragraph 2 of this item, to the National Bank, at least once a year, and at request of the National Bank and in shorter time intervals. The payment service providers shall be obliged to carry out partial risk assessments before the introduction of significant changes in the infrastructure, processes or procedures that affect the security of payment services.
13. On the basis of the risk assessment referred to in item 12 of this Decision, the
payment service providers shall be obliged to determine the appropriateness of
the implemented security measures and control mechanisms, as well as the need for their improvement. Implementation of security measures
14. The payment service providers shall be obliged to establish and implement
preventive security measures, as a safeguard against the identified operational and security risks. The measures referred to in paragraph 1 of this Decision shall provide a level of security, in accordance with the identified risk appetite.
15. The payment service providers shall be obliged to establish and implement
security measures in several layers, i.e. to use the approach of the so-called “defense-in-depth”.
16. The payment service providers shall be obliged to ensure confidentiality, integrity
and availability of their critical information and communication assets, as well as of the sensitive payment data.
17. The payment service providers shall be obliged to constantly monitor the impact
of the changes in the environment on the introduced protective security measures, in order to identify the need for establishment of additional measures to mitigate the risks. In order to reduce the risks associated with the impact of the changes referred to in paragraph 1 of this item, the payment service providers shall be obliged to establish a process of management of the changes, which provides their adequate planning, testing and recording, in accordance with the granted authorizations.
18. The payment service providers shall be obliged to establish a principle of division
of the responsibilities, by separating the information systems, i.e. the system environments for development, test and production operations in the part of the provision of payment services. Measures for ensuring integrity and confidentiality of data and systems
19. The payment service providers shall be obliged to ensure accuracy and relevance
of the collection, transfer, processing, storage, archiving and the manner of presenting the sensitive payment data of the payment service users, as well as their limitation only to what is necessary to provide the payment service.
20. The payment service providers shall be obliged to carry out regular checks for
the purpose of timely implementation of the critical security upgrades of the software that is used to provide payment services, including of the user software that is related to the payment. The payment service providers shall be obliged to establish mechanisms for verification of the integrity of the software, the incorporated programs and the information related to payment services.
Physical protection measures
21. The payment service providers shall be obliged to establish security measures for
physical protection of the information systems and the communication technology systems that are used to provide payment services, and in order to protect the sensitive payment data. Access control measures
22. The access to the information systems and the communication technology
systems shall be granted only to the authorized officers with justified business needs. The authorizations shall be granted in accordance with the work tasks of the employees, according to the principle “least privilege”. The payment service providers shall be obliged to establish control over the access and records of the activities that take place on the information and communication protection systems.
23. The payment service providers shall be obliged to implement enhanced control
over the privileged access to the information and communication technology systems, through strict limitation and more detailed supervision of the activities with such access.
24. The records in accordance with item 22 paragraph 2 of this Decision shall be kept
in a period that matches the criticality of the business functions, the processes for their support and information assets, in accordance with items 9 and 10 of this Decision. The payment service providers shall be obliged to use the information referred to in paragraph 1 of this item to identify and carry out investigations into unusual activities when providing payment services.
25. The remote access to the critical information systems and the communication
technology systems is granted in accordance with the principle “least privilege” and by applying strong authentication.
26. The functioning of the products, tools and procedures related to the access
control process shall be protected against being compromised or circumvented. Measures for continuous monitoring and detection
27. The payment service providers shall be obliged to establish processes and
functions to constantly monitor the business functions, auxiliary processes and information assets for their support, for the purpose of timely detection of the unusual activities when providing payment services. The payment service providers shall be obliged to establish appropriate and efficient functionalities to detect physical and logical disturbances on the security which affect the confidentiality, integrity and availability of the information assets that are used for payment services.
business continuity plans for the purpose of taking an appropriate
response in case of extraordinary situations and ensuring continuity of its critical business activities and
measures that would be implemented in case of an interruption in the
payment services, in order to reduce the adverse effect on the payment systems and to enable the payment service users to execute the payment transactions that are in progress. Planning of business continuity through analysis of applicable scenarios
The payment service provider shall be obliged to inform the payment service users about the manner in which it will provide the necessary support.
53. The payment service provider shall be obliged to enable the payment service
user to cancel the use of certain functionalities that are related to payment services, and are placed at the user's disposal.
54. The payment service provider, who agreed with the payer to limit the amount
spent on the payment transactions that are carried out through a certain payment instrument, shall be obliged to enable the payer to adjust those limitations to the amount of the highest agreed limitation.
55. The payment service providers shall be obliged to warn the payment service
users about initiating or unsuccessful attempts to initiate payment transactions, in order to detect fraudulent or malicious use of their payment accounts.
56. The payment service providers shall be obliged to inform the payment service
users about the updates of the security measures and procedures that affect the users when providing payment services.
IV. TRANSITIONAL AND CLOSING PROVISIONS
57. The payment service providers shall be obliged to comply their operations with
the requirements of this Decision not later than 19 February 2024. The payment service providers that are founded until the day of commencement of implementation of this Decision and which have a license for founding and operating a bank, shall be obliged to properly harmonize the existing operational risk management system established in accordance with the Decision on the methodology for risk management (Official Gazette of the Republic of Macedonia No. 113/19, 69/20 and 314/20), with the provisions of this Decision.
58. This Decision shall enter into force on the date of its publication in the Official
Gazette of the Republic of North Macedonia.
D No. 02-15/XXII-8/2022 Anita Angelovska Bezhoska 28 December 2022 Governor and Chairperson of Skopje the Council of the National Bank of the Republic of North Macedonia
Read the rest free
Source: National Bank of the Republic of North Macedonia — original document · Summary generated with machine assistance and reviewed before publication; the authoritative text is the regulator's original document. How RegAlert works
More like this from NBRM
NBRM published 7 documents in the last 30 days. We email you each new one the day it's published.