2018-03-28

Added · Updated

Guidelines on Cloud Computing Technology

The Central Bank of Jordan issues guidelines regulating the use of cloud computing technology by banks, financial institutions, exchange companies, microfinance companies, and credit information companies. The document establishes governance frameworks, defines key terminology, and mandates risk management, data security, access control, and service level agreements for cloud service providers. It outlines specific obligations for entities to ensure secure, compliant, and resilient cloud adoption, including requirements for business continuity, change management, and data sovereignty.

Central Bank of Jordan logo

Jordan

Central Bank of Jordan

Click to view thumbnail

Contents

  1. Contents
  2. Introduction
  3. Scope and Objectives
  4. Terminology
  5. Chapter One: Cloud Computing Technology
  6. 1.1 Introduction
  7. 1.2 Essential Characteristics
  8. 1.3 Service Models
  9. 1.4 Deployment Models
  10. 1.5 Cloud Actors
  11. 1.5.1 Relationship Between Cloud Actors
  12. Chapter Two: Guidelines on the Use of Cloud Computing Technology
  13. 2.1 Introduction
  14. 2.2 Cloud Computing Governance
  15. 2.3 Cloud Computing Policy
  16. 2.4 Risk Management
  17. 2.5 Contracts and Agreements Between the Company and the Cloud Provider
  18. 2.5.1 Cloud Service Level Agreement
  19. 2.6 Oversight of the Cloud Provider
  20. 2.7 Data Security
  21. 2.8 Access Management
  22. 2.8.1 User Access Management and Segregation of Duties
  23. 2.8.2 Effective Access to Data
  24. 2.9 Monitoring Security Events and Logs
  25. 2.10 Business Continuity Management
  26. 2.11 Change Management
  27. 2.12 Data Sovereignty
  28. 2.13 Termination Plan
  29. Chapter Three: Standards for Private Cloud Computing
  30. Appendix: Instructions and Circulars of the Central Bank
  31. References

3 Introduction In recent times, the financial and banking sector has witnessed significant development in the field of information technology. Companies and all financial institutions seek to utilize this technology to reduce operational costs and increase profitability, while providing and managing all applications and services to users through the internet, ensuring continuity of services anytime and anywhere. This technology is known as Cloud Computing.

Although this technology offers many benefits, it may increase risks on companies, including strategic risks, compliance risks, operational risks arising from third-party failures, and reputation risks. These risks require companies to adopt a quick, sound, and responsive framework to manage these risks and maximize the benefits from this technology.

This guide addresses the concept of cloud computing technology, clarifying its basic characteristics, deployment models, and service models. It provides guidelines on important issues for institutions to consider, including cloud computing governance, risk management, and the continuity of their operations. It also covers the protection of data used and the mechanisms and controls for its secure and effective use.

This guide also includes an appendix containing instructions and circulars issued by the Central Bank of Jordan. In light of the obligation of full compliance with these instructions and circulars regarding outsourcing operations, and given that cloud computing technology falls within outsourcing operations, licensed banks operating in the Kingdom are referred to these materials for facilitation.

4 Scope and Objectives In the light of the Central Bank of Jordan's efforts to keep pace with best international practices and achieve positive impact on the components of the Jordanian financial system, leading to the achievement of financial stability and strengthening the financial sector, this guide comes to regulate the use of cloud computing technology by banks, financial institutions, exchange companies, microfinance companies, and credit information companies under the supervision and control of the Central Bank of Jordan. Its objectives include helping them understand the technology and its risks, providing a suitable level of security protection, and ensuring the effective and secure use of cloud computing technology.

5 Terminology The following words and expressions have the meanings assigned to them below wherever they appear in this guide, unless the context indicates otherwise. The definitions contained in the Central Bank Law, the Electronic Transactions Law, and the Banks Law shall apply to the definitions in this guide, unless otherwise stated.

Company: A bank, Islamic bank, financial institution, exchange company, or microfinance company, or credit information company.

Senior Executive Management: Includes the General Manager or Regional Manager or their deputies, the General Director and Regional Director assistants, the Director of Operations, the Director of Finance, the Director of Risk Management, the Treasurer (Investment), and the Compliance Director. It also includes any employee in the company with executive authority parallel to those mentioned, who reports functionally to the General Manager.

Customer: Any natural or legal person who receives financial services from the Company.

Cloud Consumer: The entity that requests and uses the available services and resources on the Cloud.

Cloud Provider: The entity that provides the necessary resources and activities to provide cloud services and ensures the delivery of these services to the Cloud Consumer.

Cloud Computing Technology: A model that enables convenient and on-demand network access to a shared pool of configurable computing resources (such as networks, servers, storage, media, applications, and services) from the Cloud Provider.

Cloud Infrastructure: A group of physical components such as servers and media, and software, networks, and storage programs that support the necessary virtual emulation for Cloud Computing.

Cloud Service Level Agreement: A contractual agreement between the Company and the Cloud Provider that specifies requirements regarding the service provided by the Cloud Provider, including guarantees, service levels, performance, availability, and support levels.

Risk Assessment: A measurement that determines the likelihood and severity of risk occurrence and anticipates its impact on the Company.

Change Management: The management and documentation of control over any change made to any of the services delegated to the Cloud Provider.

Access Control: Rules and mechanisms that allow authorized persons to use the used resources in accordance with the nature of their responsibilities.

Information Classification: Determining the appropriate sensitivity level of information that is created or modified, depending on the risks associated with its unauthorized access, use, modification, or transfer, by any means or techniques possible.

Recovery: A group of procedures adopted and taken to restore the Company's operations to their normal state and reinstate the approved technology resources to their state before the occurrence of the event.

Vulnerability Scanning: A mechanism used to identify system characteristics and associated vulnerabilities.

Penetration Testing: Tests conducted by qualified evaluators who attempt to search for security vulnerabilities, bypass security characteristics and controls of information systems, and exploit them in an attempt to breach those systems, whether inside or outside the Company, to determine the effectiveness of the used security controls in protecting the Company's systems.

Recovery Time Objective (RTO): The maximum time allowed to restore the operation or service after an incident occurs.

Recovery Point Objective (RPO): The maximum age of data that may be lost when restoring the service after an incident occurs.

8 Chapter One: Cloud Computing Technology 1.1 Introduction Cloud computing technology is considered a model that enables convenient and on-demand network access to a shared pool of configurable computing resources (physical or virtual resources) such as networks, servers, storage, media, applications, and services, which can be provided quickly, used with minimal effort, and managed with minimal interaction from the Cloud Provider. This model consists of five essential characteristics, three service models, and four deployment models.

1.2 Essential Characteristics

  • On-Demand Self-Service: A property that enables the Cloud Consumer to obtain computing capabilities automatically as needed, without requiring direct interaction with the service provider, thereby reducing the need for manual processing of storage service requests according to need.
  • Broad Network Access: Includes network access from any location through company platforms such as mobile phones, tablets, and portable computers.
  • Resource Pooling: Computing resources are aggregated by the provider to serve multiple cloud consumers using a multi-tenant model. Physical and virtual resources are dynamically assigned and reassigned according to consumer demand, without the consumer needing to control or know the exact location of the resources provided by the provider (e.g., specifying location at the country or data center level), while maintaining the right to retain data in a specific location if required.
  • Rapid Elasticity: Capabilities can be provided and scaled rapidly and automatically to match the required workload size. Resources can be provisioned and released at any time, offering seemingly unlimited capacity to the Cloud Consumer, which can be adapted to the contracted agreements between the provider and the consumer.
  • Measured Service: The use of cloud resources can be monitored, controlled, and reported automatically, providing transparency from the provider. The Cloud Consumer pays for the required resources based on consumption.

1.3 Service Models

  • Software as a Service (SaaS): A model for distributing software to users, where applications are hosted by the Cloud Provider via the network, eliminating the need for installation on the user's devices. Users can access these applications through specific interfaces such as web browsers or application interfaces, without the user managing or controlling the underlying cloud infrastructure, network, servers, operating systems, or storage.
  • Platform as a Service (PaaS): Provides a comprehensive computing environment for the Cloud Consumer, enabling the development, testing, and deployment of applications on the cloud platform. It provides development and deployment tools and manages the cloud infrastructure, without the user managing or controlling the underlying cloud infrastructure.
  • Infrastructure as a Service (IaaS): Provides computing devices (virtual or physical resources) such as networks, storage, and other resources from the Cloud Provider. The Cloud Consumer can install and run operating systems and applications on these resources. The user does not manage or control the underlying cloud infrastructure but may have limited control over operating systems, storage, and deployed applications (e.g., firewalls).

1.4 Deployment Models

  • Public Cloud: Provides cloud infrastructure for general use, owned, managed, or operated by a commercial, academic, or government organization. The cloud infrastructure is located at the provider's premises. Data may be stored in known or unknown locations, and the consumer's data may be stored on the same cloud as other users.
  • Community Cloud: Provides cloud infrastructure for exclusive use by a specific community of consumers from companies sharing common concerns (e.g., mission, security requirements, compliance, and policies). It may be owned, managed, or operated by one or more companies in the community, a third party, or a combination. It is more costly than the public cloud, with costs distributed among the number of community consumers in exchange for a higher level of commitment. Data may be stored inside or outside the companies' premises, and each company's data may be stored on the same cloud as its competitors.
  • Private Cloud: Provides cloud infrastructure for exclusive use by a group of cloud consumers. It may be owned, managed, or operated by the group, a third party, or a combination. The cloud infrastructure may be located inside (On-premises) or outside (Off-premises) the group's premises. The private cloud is considered less risky than the other deployment models. It may not be as flexible as the public cloud.
  • Hybrid Cloud: Consists of two or more cloud infrastructures (private, community, or public) that remain distinct entities but are bound together by standardized or proprietary technology that enables data and application portability. This integration may introduce additional risks. The responsibility for classifying information for storage lies with the Cloud Consumer, as shown in Table 1 below comparing the different deployment models.

Table 1: Comparison of Different Deployment Models

Deployment ModelInfrastructure OwnerInfrastructure ManagerInfrastructure LocationAccessible By
Public CloudCloud ProviderCloud ProviderOutside Consumer PremisesAny Cloud Consumer
Private CloudCloud Provider or ConsumerCloud Provider or ConsumerInside or Outside Consumer PremisesCloud Consumer
Community CloudCloud Provider or ConsumerCloud Provider or ConsumerInside or Outside Consumer PremisesCloud Consumer, Trusted Parties
Hybrid CloudCloud Provider or ConsumerCloud Provider or ConsumerInside and/or Outside Consumer PremisesCloud Consumer, Trusted Parties, Untrusted Parties

1.5 Cloud Actors The entities involved in tasks and/or operations related to cloud computing include:

  1. Cloud Consumer
  2. Cloud Provider
  3. Cloud Broker: Acts as an intermediary between the Cloud Consumer and the Provider. In addition to selecting and managing various cloud computing services provided by the Provider, the Cloud Broker provides additional services to the user, including:
    • Intermediation: Enhancing a specific service through the Broker. It can also provide value-added services to users, such as identity management, security enhancement, and cloud computing services.
    • Aggregation: Combining multiple services and one or more services into a single service. The Broker ensures data integration and secure data movement between the Cloud Consumer and Providers.
    • Arbitrage: Unlike aggregated services, the arbitrage service is not fixed. It provides flexibility in choosing services from multiple Cloud Providers.
  4. Cloud Auditor: Monitors the performance of cloud services and verifies compliance with security policies implemented on the cloud.
  5. Cloud Carrier: Transfers cloud services and data between Cloud Consumers and Providers. The Cloud Provider bears the responsibility of establishing a Cloud Service Level Agreement with the Carrier to ensure the delivery of data and services to the Cloud Consumer within the agreed level.

1.5.1 Relationship Between Cloud Actors

  • The Cloud Consumer can request cloud computing services directly from the Cloud Provider or through a Cloud Broker. In the latter case, the Cloud Consumer must consider that the Cloud Broker applies to the Cloud Provider what applies to it.
  • The Cloud Auditor performs independent audit processes to collect information about other actors. Therefore, it does not rely on the Cloud Consumer.
  • There are specific roles for each Cloud Consumer and Provider when using different service models, as shown in Table 2 below.

Table 2: Different Roles of Cloud Consumer and Provider When Using the Three Service Models

Service ModelCloud Consumer ActivitiesCloud Provider Activities
Software as a Service (SaaS)Use applications available on the cloud. Perform specific operations within their scope.Install, manage, and maintain applications and support them. Manage the cloud infrastructure available to the consumer.
Platform as a Service (PaaS)Develop, test, deploy, and manage applications.Provide development and deployment tools. Manage and provision the cloud infrastructure.
Infrastructure as a Service (IaaS)Install/create and manage/monitor infrastructure services. Control virtual devices (machines) where operating systems and applications are published.Provide physical processing, storage, and infrastructure hosting and network environment for the cloud consumer.

14 Chapter Two: Guidelines on the Use of Cloud Computing Technology 2.1 Introduction This chapter provides guidelines on cloud computing governance, the company's policy, contracts and agreements between the company and the cloud provider, data security and protection, oversight of the cloud provider's performance, risk management, change management, access management, security events and logs monitoring, business continuity arrangements, and termination plans. The aim is to protect companies from the risks they may face when using cloud computing technology.

2.2 Cloud Computing Governance Effective governance is essential when using cloud computing technology to guide management decisions and ensure optimal utilization of cloud services according to the company's needs. The company's cloud computing governance strategy should enable collaboration among stakeholders, including operational performance issues, problem-solving, and risk management decisions related to delegated services. The Board of Directors or a committee delegated by it assumes the following tasks and responsibilities, taking into account the following:

  • Establish an effective governance structure for outsourcing operations and risk management of cloud services.
  • Ensure the establishment, implementation, review, and periodic update of the cloud computing policy as needed.
  • Approve agreements with cloud providers.
  • Ensure the conduct of due diligence assessments of cloud providers before entering into any agreement with them.
  • Review risk assessment results for all cloud service outsourcing agreements based on the risk assessment framework approved by the Management Board.
  • Review periodic evaluation reports of the cloud provider's performance.
  • Ensure the establishment and periodic testing of disaster recovery plans based on realistic and potential scenarios of disruption and sabotage.
  • Ensure the existence of an appropriate mechanism for continuous monitoring of the cloud provider according to the terms and conditions of the Cloud Service Level Agreement between the company and the provider.
  • Ensure that relevant parties in the company review all activities and services delegated to the provider and regularly inform the Management Board of any risks arising therefrom.

2.3 Cloud Computing Policy The company should periodically establish, review, and update its cloud computing policy, including at least the following:

  • Classification and prioritization of services, data, and processes to be outsourced to the Cloud Provider, considering their sensitivity and importance, to serve as a reference for the company's responsibility for their classification.
  • Selection of the most appropriate deployment model (public, private, community, hybrid) and service model (IaaS, SaaS, PaaS) for the services and data to be outsourced, depending on:
    • The type of service and data classification.
    • The level of risk assessment associated with it.
  • Mechanism for storing, processing, transferring, and disposing of the company's data with the Cloud Provider.
  • Security controls to be followed when dealing with any cloud provider.
  • Basis for due diligence assessments of cloud providers before entering into any agreement with them.
  • Expected results and requirements from outsourcing to cloud providers in terms of operational performance and changes in the work environment, in compliance with requirements.
  • Mechanism to ensure compatibility and interrelation between the company's internal processes and those transferred to the cloud provider, and between different delegated services to the cloud provider.
  • Controls to protect customer data and disclose them to the client, especially if any personal data is outsourced, in compliance with applicable laws and instructions.
  • Minimum standards of due diligence conditions in agreements with the Cloud Provider.
  • Audit and control mechanisms for services delegated to the Cloud Provider.

2.4 Risk Management The company must identify and manage any risks that may arise from outsourcing cloud computing services, taking into account the following:

  • Include the risks of outsourcing cloud computing services in the company's comprehensive risk assessment framework and document it. It should include at least:
    • Determining the role of the Cloud Provider in the company's work strategy.
    • Establishing comprehensive procedures to cover requirements linked to the Cloud Provider to mitigate and reduce risks.
    • Evaluating the Cloud Provider's ability to ensure high service performance standards with high efficiency.
    • Analyzing the impact of outsourcing cloud computing services on the company's comprehensive risk file.
    • Evaluating considerations related to current laws, including legal enforcement provisions and laws related to data protection, in light of the Cloud Provider's country and its political and security stability.
    • Identifying financial, operational, and legal risks to the company's reputation and the Cloud Provider's failure to perform operations as required.
    • Conducting a comprehensive security risk assessment related to the services delegated to the Cloud Provider, determining roles and responsibilities, and documenting the steps to be followed to mitigate and manage these risks.
  • Establish key performance indicators to monitor the risk level related to outsourcing cloud computing services and ensure that the acceptable risk level (Risk Appetite) is not exceeded (Key Risk Indicators).

17 • Identify best current practices in using cloud computing technology in relation to information security risks, cyber risks, and applicable regulatory rules. • Identify the actions that may be taken in the event of a cloud service provider's failure in providing services, and monitor risks. • Identify the impact on the company's customers in the event of a cloud service provider's failure in service performance or violation of data confidentiality. • Manage security risks associated with storing data and running the company's specific applications on the provider's cloud systems. • Monitor concentration risks arising from relying on a single cloud provider for all intended services, considering the actions that will be taken in the event of the cloud provider's failure in operations performance as required.

2.5 Cloud Service Provider Agreements The company must ensure that the contract(s) or agreement(s) between the cloud provider and the company are consistent with the cloud computing policy. Considering the following minimum requirements, the contracts must include: • The cloud provider's name, the company's name (if found), full contact information, and address. • The activities and services to be outsourced to the provider. • The contract duration. • The cloud provider's commitment to the confidentiality of the company's data and security. • The cloud provider's commitment to business continuity plans at the company. • Audit and control procedures on the cloud provider. • Performance standards for operations, internal controls, and risk management. • Service Level Agreement (SLA) requirements and cloud provider performance. • Roles and responsibilities of both parties. • Dispute resolution procedures.

18 • Reporting mechanism to the company. • The applicable law governing the contract. • The legal and regulatory arrangements required of the cloud provider. • Technical support requirements and responsibilities, including maintenance. • Penalty conditions in the event of the cloud service provider's failure in providing cloud computing services. • The contract allows for renewal and negotiation to enable the company to maintain an appropriate level of oversight over outsourcing arrangements with the cloud provider. • The company must take necessary measures to prevent unauthorized access to any person or entity other than the company to the company's data and information security and confidentiality, without prior consent. • The cloud provider must notify the company of any proposed changes to the contracted services or contracts that may affect its ability to fulfill its responsibilities, and the agreement must allow the company a period to assess the risks and impacts of these changes before implementing the proposed changes. • When the cloud provider changes, the company must obtain approval to determine the geographical location of data storage, including data centers or work locations for the outsourced services. • The agreement must ensure the adequacy and effectiveness of security policies and practices and operational security requirements. Each party has the right to change those requirements based on prevailing circumstances. • If this party's scope of work overlaps with the scope of services outsourced to the cloud provider, the cloud provider must not engage with any third party in cooperation with the company. • In the event of the provider contracting with a third party regarding the outsourced service, the provider must immediately notify the company and maintain its approval and request for the effectiveness of the controls and security and operational requirements established between them. • Define communication and escalation procedures and mechanisms to ensure immediate notifications to the company about any incidents or violations arising from any disruption in cloud computing services, or the actions taken/proposed by the provider to address the disruption.

19 • Clauses enabling the Central Bank to perform its supervisory duties and obligate the cloud provider to comply with any requirements, directives, and instructions issued by the Central Bank regarding the outsourced services. • The contract should clearly specify the circumstances under which either party has the right to terminate the contract, including but not limited to: o Occurrence of a security or confidentiality breach. o Failure by the cloud provider to notify the company of security events that may affect the company's operations. o Inability of the cloud provider to perform the contracted service within the agreed-upon level. o Change of ownership of the cloud provider. o Bankruptcy or entry into liquidation of the cloud provider. o Subject to judicial attachment in the country or another location. • No restrictions in the contract that could prevent the company from terminating the contract immediately.

2.5.1 Cloud Service Level Agreement (SLA) Cloud Service Level Agreements are considered among the most important elements in managing the relationship between the cloud provider and the company. Given the complex and changing nature of cloud computing technology, which requires advanced tools, the company needs SLAs to ensure the agreed service quality between the company and the provider. These agreements contain minimum requirements to determine the performance requirements of cloud services, including: • The type of service level, its performance, and required security controls. • The availability level of the service outsourced to the provider, including its integrity and confidentiality. • A mechanism for separating the provider's data from the company's data. • A mechanism for preserving and processing the company's specific data and its customers. • A mechanism for backup copies and record retention. • A disaster recovery and business continuity mechanism. • Details of the infrastructure and standards to be maintained by the provider before review. • Periodic checks by the cloud provider to ensure compliance with the agreed service performance level and security standards.

2.6 Cloud Service Provider Oversight The company's responsibility does not transfer to the provider for some of its services; the provider remains fully responsible for the service outsourced to it under the applicable laws and regulations issued by the Central Bank. The company must, therefore, undertake the following with the Central Bank: • Notify the Central Bank when contracting with any cloud provider. • Define the continuous oversight and monitoring duties, ensuring that the company's staff have the necessary skills, training, resources, and capabilities for monitoring and testing these services. This right should not be restricted to field visits to the provider's headquarters, with prior agreement between both parties. • Establish procedures enabling the Central Bank to perform its supervisory duties, including: o Ensuring that all company data and cloud computing services are available for inspection or audit by the Central Bank at any time. o Obtaining any records, documents, data, or information deemed necessary by the Central Bank related to the company's activities outsourced to the cloud provider. o Access to any report or audit results conducted by internal or external auditors on the cloud provider or the relationship with the outsourced service.

2.7 Data Security Ensuring data security is one of the most important issues when outsourcing to a provider. Therefore, given the distributed nature of the cloud computing environment, the company must follow the required procedures to protect data during transfer, processing, and storage, considering the cloud security procedures and controls, including: • Ensuring the availability of physical security requirements for the provider's data centers. • The company bears the responsibility of adopting a defined data classification based on its sensitivity, with periodic reviews of the need to update these classifications. • Identifying the data to be transferred to the cloud based on the company's approved information classification, considering the risks associated with classifying data as sensitive on public or hybrid clouds. • Ensuring the provider provides the company with a mechanism to separate the company's specific data from other users' data. • Identifying the responsible entity for taking backup copies of data and their storage locations and mechanisms. • Taking appropriate steps to mitigate security risks associated with transferring data to the cloud. • Determining the nature and scope of risks resulting from the loss of the company's specific data and reducing those risks through: o Distributing data and applications across multiple locations. o Adhering to best practices in business continuity and disaster recovery. • Subjecting this data, whether stored or in transit, to appropriate encryption controls, including: o Establishing detailed policies and procedures for the creation, use, storage, archiving, renewal, expiration, and revocation of encryption keys. o Reviewing details regarding encryption algorithms, key lengths, and tools used for encryption with specialists to identify potential vulnerabilities. o Ensuring that secret keys used in encryption are created and managed securely, for example, using Hardware Security Modules (HSM). o Ensuring the existence of appropriate controls for managing encryption keys and digital certificates. o Placing adequate security equipment, such as the security unit of encryption tools and other devices, on separate secure networks with controlled access, so that only authorized personnel can access them, and these networks are not used by the provider or other companies dealing with the provider. • Encryption keys used for the company's data must be unique and dedicated only to the company's data and not used for data of other companies dealing with the provider.

22 • In the case of using tokenization, which aims to reduce the quantity of sensitive data shared with the cloud provider, the company must consider the following when outsourcing to the cloud provider: o Conducting an accurate risk assessment, especially regarding the solutions used for tokenization and the unique characteristics of the data used to access the data. o Ensuring that the cloud provider cannot retrieve the tokenized data back to the system with the specific token. o Having procedures to handle breaches and other events with negative impacts on cloud computing services. • Conducting penetration tests on the systems specific to the services outsourced to the provider, especially the operating systems in the cloud's virtual environment, due to the exposure to many risks because of shared physical components with cloud users. • Conducting vulnerability scanning processes on systems and software periodically, in coordination with the provider, to detect vulnerabilities and weaknesses in the services' systems and proactively avoid exposing those systems to risk.

2.8 Access Management 2.8.1 User Access Management and Segregation of Duties When the cloud provider has access to the systems or software specific to the service, the company must consider the following: • Ensuring the cloud provider applies its adopted access management policies. • Segregating duties among users of software systems, especially for critical and sensitive roles. • Logging user access to software or systems in the cloud provider's access logs and reviewing them at least annually. • Ensuring the existence of controls for user access management, including privileged users and access to service accounts and general accounts of the company's affiliated systems, and recording activities performed on those systems for review. • Developers affiliated with the cloud provider should not have any right to access the live environment of the company's systems.

2.8.2 Effective Access to Data It is necessary for the company to be able to effectively access its data associated with the services, including: • Ensuring access to data as agreed with the cloud provider. • Ensuring the absence of restrictions on the number of requests by the company to access or obtain data. • Ensuring the absence of data storage in countries or locations that prevent the company's effective access to its specific data.

2.9 Security Events Monitoring and Logs For the purpose of monitoring security events that the outsourced services may be exposed to, the company must ensure the existence of appropriate detection mechanisms at the provider's network, applications, and systems. The company usually keeps records of events that affect the security and stability of the outsourced service. The company must ensure the availability of logs related to the service, its data, and applications at the provider, and it is incumbent upon the company to have unrestricted access rights to these logs, including: • Providing what is necessary to monitor and analyze logs related to the outsourced services automatically. • Continuously reviewing event logs according to the classification of the event's importance. • Reviewing access logs to ensure that only authorized users enter and retain them. • Ensuring access to security event logs for all services outsourced to the cloud provider.

24 2.10 Business Continuity Management The company must take appropriate measures to ensure business continuity related to the services outsourced to the provider. These measures include, at a minimum: • Developing and reviewing business continuity and disaster recovery plans in coordination with the provider, considering the provider's commitments and requirements regarding continuity planning at the time of contracting. This includes defining the Target Recovery Time (RTO) and Target Recovery Point (RPO). • Ensuring that the company's crisis management team is fully aware of the provider's disaster recovery plan. • Considering the probability of non-interruption and the expected impact on the company's operations for the outsourced services. • Ensuring the preservation of backup copies of data and software in an alternative site for recovery. • Developing an emergency plan documenting the procedures to be followed in the event of a sudden inability of the current provider to fulfill its obligations or the termination of the contract with the current provider for any reason.

2.11 Change Management Some risks may occur when making changes in the cloud computing environment. To avoid these risks, the company should consider: • Agreeing with the cloud provider on the methodology for identifying changes to the environment. • Facilitating the company's ability to review these changes to facilitate oversight. • Ensuring oversight of major changes that can affect the stability and security of the operational environment in the cloud, including detecting incorrect or unauthorized changes. • The agreement with the cloud provider regarding change management procedures should include standard procedures for changes, roles and responsibilities, emergency procedures, reporting, approval procedures, and how to test changes that have been approved.

2.12 Data Sovereignty The company must consider the following before placing its data in the cloud provider's country: • The regulatory requirements of the provider's country. • The political, social, and economic conditions of the provider's country. • Diplomatic relations and government policies and requirements in the provider's country. • Events and disasters that may limit the provider's ability to provide its services. • The company does not allow entry into arrangements for outsourcing services with cloud providers in countries whose laws allow immediate mandatory access to information and data in them. • The company must establish contractually binding requirements obligating the cloud provider to notify it before disclosing specific data about the company in the country of the data center, in accordance with the law, to ensure the protection of the company's data from third parties.

2.13 Termination Plan The company must have a documented and specific plan for terminating outsourcing agreements to ensure that the termination does not affect compliance with the directives and regulations issued by the Central Bank or disrupt the provision of its services in cloud computing. Therefore, the company must: • Develop, understand, document, and periodically review termination arrangements in full coordination with the cloud provider. • Identify a mechanism for transitioning to an alternative cloud provider or returning to the company's system to maintain business continuity. • A specific mechanism for retrieving and deleting all company-specific data and records, including backup copies stored wherever they may be, at the time of contract termination with the cloud provider, as well as data storage media via the Internet. • Monitor risks and consider the actions that may be taken in the event of the cloud provider's cessation of operations. • Establish special arrangements to ensure the company obtains its data or transfers it to an alternative provider in the event of non-compliance or for any reason leading to contract termination or inability of the current provider to fulfill its obligations, in cooperation with the current provider to complete the transfer process.

Chapter Three: Cloud Computing Standards Given the challenges companies face in adopting cloud computing technology, and to reduce their exposure to resulting risks, companies must enable the use of this technology in a secure manner by adopting all necessary measures to protect themselves through the use of common security standards worldwide. These standards support cloud computing technology and allow maintaining data security and confidentiality, offering many benefits, such as: • Enhancing compatibility between the company's systems and any other systems, making it easier to transition to another cloud provider. • Ensuring companies follow best practices with cloud providers. • Standards are considered an effective means for companies to compare cloud providers and choose the most suitable provider. • Using standards facilitates the path to regulatory compliance.

There are many recently published standards related to cloud computing security, such as ISO/IEC 27017 and ISO/IEC 27018, which provide more detailed guidelines for each company and provider. Additionally, there is a number of general information technology standards that can be applied when using cloud computing. Although these standards are general and not specific to cloud computing, the company and provider should give them importance by applying them in the cloud environment. These standards provide guidance and recommendations specifically and in detail for each company and provider. The following standards are classified according to several topics, as shown in Table (3) below.

Table 3: Key Standards Used in Cloud Computing Technology

SubjectStandards
Governance and Risk Management and Compliance• COBIT<br>• ISO/IEC 20000<br>• SSAE 16 or ITIL depending on type of workload<br>• ISO/IEC 27001 and ISO/IEC 27002<br>• ISO/IEC 27017 & ISO/IEC 27018<br>• ISO/IEC 38500 – IT Governance<br>• Cloud Security Alliance (CSA) Cloud Controls Matrix<br>• National Institute of Standards and Technology (NIST) Cybersecurity Framework (CSF)
Operational and Business Processes• SSAE 16<br>• ISO/IEC 27000
Identity Management• LDAP, SAML 2.0, OAuth 2.0, WS-Federation, OpenID Connect, SCIM<br>• XACML<br>• PKCS, X.509, OpenPG
Information and Data Protection• HTTPS, SFTP, VPN using IPSec or SSL<br>• OASIS KMIP<br>• US FIPS 140-2
Privacy Policies• ISO/IEC 27018
Network Security and Protection• ISO/IEC 27033 or FIPS199/200 standards
Security Controls on Infrastructure• ISO/IEC 27002<br>• ISO/IEC 27017 & ISO/IEC 27018
Service Level Agreement Security Terms• ISO/IEC 19086<br>• ISO/IEC 27004:2009, TM Forum TR 178, NIST Special Publication 800-55, CIS Consensus Security Metrics V1.1.0, and ENISA Procure Secure<br>• CWE list<br>• CSA STAR registry<br>• PCI DSS<br>• FedRAMP program
Termination Processes• ISO/IEC 19086

Annex: Central Bank Directives and Instructions A compilation of directives and instructions issued by the Central Bank regarding outsourcing to third parties for licensed banks operating in the Kingdom, to regulate the process of outsourcing cloud computing services.

  1. Circular No. (65/2016) dated 25/10/2016 accompanying the Governance of Information Technology and Resources Instructions. Article 3 (C/3): When signing outsourcing agreements, banks must ensure that the application of the provisions of these instructions to third parties is proportional to the nature and importance of the information technology infrastructure, hardware, software, and human resources provided to support the bank's operations. The Board of Directors cannot exempt the senior executive management and administration from the ultimate responsibility for achieving the instructions' requirements, including audit requirements, during the contract period and before and after the provision of infrastructure, hardware, software, and services. The contract period or the effective period of the instructions is considered the time period to be fulfilled, whichever is earlier, to harmonize the status of currently contracted companies.

Attachment No. (6) of the Instructions (Outsourcing Policy): "Adopting a general policy for outsourcing resources, specifically information technology resources, to third parties. The policy covers resources owned by the bank (In-sourcing) or owned by third parties (Outsourcing), taking into account applicable laws and regulations, best international practices, and the operational location of production (On-site, Off-site, Near-site, Off-shore). It also considers Service Levels (Service Levels) monitoring requirements, Audit Rights, necessary protection controls, business continuity requirements, and additional requirements for reliability, efficiency, and effectiveness, as well as confidentiality requirements, verified by a reliable, neutral third party."

Attachment No. (8) of the Instructions (Hosting Security and Controls, Information Technology Infrastructure, Hardware, and Software): Physical and Environmental Security. The company must provide physical and environmental security controls at a minimum, including: • Rooms housing main servers and communication rooms must be designed to be remote from threats and protected. Rooms should be located away from the building's end or bottom, considering potential floods, sewage, and water leaks. • Room space must be sufficient to accommodate another location or surface exposed to potential future expansion, considering current bank needs. • The room location should be generally accessible and not restricted, considering the nature of the geographical location, and not under exclusive contractual agreements with any telecommunications companies before all diverse providers. • Rooms housing main servers and communication rooms (e.g., Routers, Switches, etc.) must have physical and environmental protection, including armed walls without windows, isolated from electromagnetic effects that negatively affect data on computer devices. The room must be serviced with an emergency backup entrance and fire extinguishing devices (e.g., FM 200) powered by electricity. The floor must be raised (Raised Floor), and the room must contain smoke detectors for water, heat, and humidity at a high sensitivity level. CCTV coverage must be evenly distributed across the room area, and devices must be provided to remove dust from the room to protect devices from high heat and humidity. Access must be controlled and monitored to prevent unauthorized entry, and the presence of non-authorized persons in sensitive bank rooms must be prevented without authorized escorts. • Communication and server rooms must be supplied with multiple power sources, including automatic batteries (UPS) and sufficient capacity power generators to operate sensitive bank and operational devices in case of main power source interruption, considering the requirements of the Civil Defense Department and Jordanian Standards. • The above-mentioned applies to Disaster Recovery (Sites) for server rooms with alternative electricity and communications.

  1. Circular No. (1/10/9943) dated 17/08/2014 regarding the Business Continuity Plan Instructions. Article (11): Agreements signed with external providers for technical support must include, under the terms of the required support provision, specific responsibilities for general and critical services, ensuring the highest availability levels through a Service Level Agreement (SLA) attached to the agreement.

32 Banks are required to have business continuity plans consistent with their operations and details across all circumstances. "Specifically regarding this:" Article (12): Outsourcing Policies - The following shall be observed: • Banks must ensure that approved third-party providers offer independent periodic verification, at least annually, to guarantee data availability and confidentiality during any occurrence. This criterion is important when selecting providers subject to this rule. In the event of a disruption leading to the cessation of such services, contracts and agreements signed with providers must include provisions reflecting these requirements, addressing the current status of existing providers and meeting these needs accordingly.

Instruction No. (35) dated 10/6/2007 on Internal Control and Supervision Systems. 3. Article (9/e): Quality of Services Provided Before External Parties - The mechanism for providing them where maintained: • These conditions are monitored by ensuring the principles of accuracy, availability, integrity, and confidentiality through documented formal agreements.

Circular regarding Principles of Managing Risks of Electronic Banking Operations Instruction No. (3344/1/10) dated 21/3/2005. 4. Article (3/a/First): Action - The Management Board and Executive Management shall establish a system and mechanism for managing services provided by external parties (Outsourcing relationships) to support the electronic banking service provision process and develop its continuity.

Instructions on Banks' Practice of Operations via Electronic Means Instruction No. (8) dated 26/7/2001. 5. Article (7): Necessity of Regulating Agreements Concluded Between the Bank and Any Supporting or Providing Companies: • Ensuring the security of banking systems and information, and not contradicting the provisions of banking secrecy.

More like this from CBJ

CBJ published 1 document in the last 30 days. We email you each new one the day it's published.

Share