2005-05-01 | 23999Added · Updated
Financial institutions must develop, document, and implement a written information security programme comprising administrative, technical, and physical safeguards appropriate to their size and complexity. The Board of Directors is required to approve the programme, set oversight policies, and receive annual reports on risk assessments, testing results, and security breaches. Management must establish internal controls, including independent testing, employee training, and contingency plans, while ensuring sensitive data is protected via encryption, firewalls, and secure server storage. Institutions are also obligated to exercise due diligence in selecting service providers, enforce contractual security measures, and maintain records for at least six years under the Proceeds of Crime Act, 2000.