2023-06-23 | 24230

Added · Updated

Draft Cybersecurity Best Practices Guidelines

The Central Bank of Trinidad and Tobago proposes that companies authorized under the Financial Institutions Act, 2008, and the Insurance Act, 2018, establish cybersecurity frameworks proportional to their business models and risks. These entities must conduct annual self-assessments using a traffic signal format, submit them by January following the assessment period, and attach action plans for material deficiencies. The guidelines require the Board to approve cybersecurity strategies and receive quarterly updates, while Senior Management implements policies and ensures regular independent reviews. Additionally, companies must report material cyber incidents to the Central Bank within 24 hours of awareness and complete a detailed reporting template within 48 hours.

Central Bank of Trinidad and Tobago logo

Trinidad and Tobago

Central Bank of Trinidad and Tobago

Scan of the document's first page
Share

CBTT published 6 documents in the last 30 days — get each new one by email the day it lands.

Read the rest free

Lineage: In force

Financial Institutions Act, 20082008Financial Institutions Act, 2008 (2008-12-19)Insurance Act, 20182018Insurance Act, 2018 (2018-06-04)Draft Cybersecurity BestPractices Guidelines2023-06-23 · this documentDraft Cybersecurity Best Practices Guidelines (2023-06-23)
amendssupersedesissued underrefers toproposed or not in RegAlertarrows run from the older text to the one that changes it

Source: Central Bank of Trinidad and Tobago — original document · Summary generated with machine assistance and reviewed before publication; the authoritative text is the regulator's original document. How RegAlert works

More like this from CBTT

CBTT published 6 documents in the last 30 days. We email you each new one the day it's published.