2026-10-01

Added · Updated

Guidelines on the Submission of the Cybersecurity Controls Self Assessment (CCSA) through the Advanced SupTech Engine for Risk based Compliance (ASTERisC*) Platform

Bangko Sentral ng Pilipinas requires covered Banks and Supervised Institutions (BSIs) to submit the Cybersecurity Controls Self-Assessment (CCSA) via the ASTERisC* platform. Covered entities are those classified with a Moderate or Complex IT Profile, as well as any others specifically designated by the regulator. The initial submission is due sixty calendar days from the memorandum's issuance, with subsequent annual submissions required on or before March 31 following the reference year. The Single Point of Contact designated in ASTERisC* is responsible for accomplishing and submitting the assessment, which evaluates maturity across information security governance, risk management, control implementation, and cyber threat intelligence.

Bangko Sentral ng Pilipinas logo

Philippines

Bangko Sentral ng Pilipinas

Scan of the document's first page
Share

BSP published 8 documents in the last 30 days — get each new one by email the day it lands.

Read the rest free

Source: Bangko Sentral ng Pilipinas — original document · Summary generated with machine assistance and reviewed before publication; the authoritative text is the regulator's original document. How RegAlert works

More like this from BSP

BSP published 8 documents in the last 30 days. We email you each new one the day it's published.

Topics