2005-05-01 | 23999

Added · Updated

Guideline on Security Systems for Safeguarding Customer Information

Financial institutions must develop, document, and implement a written information security programme comprising administrative, technical, and physical safeguards appropriate to their size and complexity. The Board of Directors is required to approve the programme, set oversight policies, and receive annual reports on risk assessments, testing results, and security breaches. Management must establish internal controls, including independent testing, employee training, and contingency plans, while ensuring sensitive data is protected via encryption, firewalls, and secure server storage. Institutions are also obligated to exercise due diligence in selecting service providers, enforce contractual security measures, and maintain records for at least six years under the Proceeds of Crime Act, 2000.

Central Bank of Trinidad and Tobago logo

Trinidad and Tobago

Central Bank of Trinidad and Tobago

Scan of the document's first page
Share

CBTT published 6 documents in the last 30 days — get each new one by email the day it lands.

Read the rest free

Source: Central Bank of Trinidad and Tobago — original document · Summary generated with machine assistance and reviewed before publication; the authoritative text is the regulator's original document. How RegAlert works

More like this from CBTT

CBTT published 6 documents in the last 30 days. We email you each new one the day it's published.

Topics
infosec
privacy