2018-03-28
Added · Updated
The Central Bank of Jordan issues guidelines regulating the use of cloud computing technology by banks, financial institutions, exchange companies, microfinance companies, and credit information companies. The document mandates specific governance structures, requiring the Board to adopt cloud policies and Senior Executive Management to oversee risk assessments, provider due diligence, and performance monitoring. It establishes detailed obligations for data security, access management, business continuity, and exit plans, while explicitly classifying cloud services as outsourcing operations subject to existing Central Bank circulars.
1 Table of Contents Table of Contents 1............................................................................................................. Introduction 3.......................................................................................................................... Scope and Objectives 4.............................................................................................................. Definitions 5.................................................................................................................... Chapter One: Cloud Computing Technology 8............................................................................. 1.1 Introduction 8............................................................................................................. 1.2 Essential Characteristics 8................................................................................ 1.3 Service Models 9....................................................................................................... 1.4 Deployment Models 9.................................................................................................. 1.5 Cloud Actors 11......................................................................................................... 1.5.1 Relationship Between Cloud Computing Actors 12....................................................................................... Chapter Two: Guidelines on the Use of Cloud Computing Technology 14............................................................................. 2.1 Introduction 14........................................................................................................... 2.2 Cloud Governance 14.................................................................................................. 2.3 Cloud Policy 15........................................................................................................ 2.4 Risk Management 16................................................................................................ 2.5 Contracts and Agreements Between the Company and the Cloud Provider 17.......................................................................................... 2.5.1 Cloud Service Level Agreement 19.................................................................................... 2.6 Oversight of the Cloud Provider 20............................................................................................................................................ 2.7 Data Security 20........................................................................................................ 2.8 Access Management 22................................................................................................ 2.8.1 User Access Management and Segregation of Duties 22.................................................................................................................................... 2.8.2 Effective Data Access 23....................................................................................................................................................
2 2.9 Monitoring of Security Events and Logs 23........................................................................ 2.10 Business Continuity Management 24.................................................................................................................................... 2.11 Change Management 24................................................................................................ 2.12 Data Sovereignty 25.................................................................................................. 2.13 Exit Plan 25................................................................................................................. Chapter Three: Cloud Computing Standards 27.................................................................................................................................... Appendix of Instructions and Circulars of the Central Bank 30.................................................................................................................................... References 33........................................................................................................................
3 Introduction The financial and banking sector has recently witnessed significant development in the field of information and communication technology and its use in providing financial and banking services. As all companies and financial institutions seek to benefit from this technology to reduce operational costs and increase profits, these institutions have turned to benefiting from third parties that provide the necessary resources for companies to manage and provide their services. This is done by allowing users of this technology to access all applications and services from anywhere and at any time via the Internet, ensuring continuity, which is known as cloud computing technology. This technology offers many benefits, but it may also increase the volume of risks to companies, such as strategic risks, reputational risks, compliance risks, and operational risks arising from the failure of third parties to provide services at the agreed level, or security breaches. This requires companies to adopt a sound and responsive framework for managing these risks and maximizing the benefits of this technology. This guide clarifies the concept of cloud computing technology, its essential characteristics, deployment models, and service models, as well as guidelines on some important issues that institutions must consider carefully when using this technology. These include cloud governance, risk management, business continuity, and the controls and mechanisms used to protect data for safe and effective use. This guide also includes a special appendix containing the instructions and circulars issued by the Central Bank of Jordan related to outsourcing operations, given the necessity for licensed banks operating in the Kingdom to fully comply with these instructions and circulars, as cloud computing technology falls under outsourcing operations, to facilitate banks' reference to them.
4 Scope and Objectives In light of the Central Bank of Jordan's efforts to keep pace with best international practices that positively impact the components of the Jordanian financial system and ultimately achieve financial stability and strengthen the resilience of the financial and banking sector in conducting its business and making its services available securely, efficiently, and effectively; this guideline is issued to regulate the use of cloud computing technology by banks, financial institutions, exchange companies, microfinance companies, and credit information companies subject to the supervision and oversight of the Central Bank of Jordan. This aims to achieve their objectives within an appropriate level of security and protection, and to assist them in understanding cloud computing technology and its risks for safe and effective use.
5 Definitions The words and phrases below shall have the meanings assigned to them wherever they appear in this guide. The definitions provided in the Central Bank Law, the Electronic Transactions Law, the Banks Law, and any other relevant instructions issued by the Central Bank shall apply wherever the text refers to them in this guide, unless the context indicates otherwise:
: Company The Bank or Islamic Bank, financial institution, exchange company, credit information company, or microfinance company.
: Senior Executive Management Includes the General Manager or Regional Manager, Deputy General Manager or Deputy Regional Manager, Assistant General Manager or Assistant Regional Manager, Chief Financial Officer, Operations Manager, Risk Management Director, Treasury (Investment) Director, Compliance Director, in addition to any employee in the company who has executive authority equivalent to any of the aforementioned and is functionally directly linked to the General Manager.
: Customer Any natural or legal person who obtains financial services from the Company.
: Cloud Consumer The entity that requests and uses the resources and services available on the cloud.
: Cloud Provider The entity that provides cloud resources and services and the activities necessary to provide these services and ensure their delivery to the cloud consumer.
: Cloud Computing Technology A model for enabling network access from anywhere, on demand, to a shared pool of configurable computing resources (such as networks, servers, storage media, applications, and services) from the cloud provider.
: Cloud Infrastructure A set of physical and software components such as servers, storage media, networks, and virtualization software necessary to support cloud computing requirements.
6 Cloud Service Level Agreement A contractual agreement between the cloud provider and the Company, in which the Company's requirements, the level of service, and the guarantees provided by the cloud provider regarding service availability, performance, and support levels are specified.
: Risk Assessment Measuring and determining the probability of risk occurrence and its severity, and anticipating the extent of its impact on the Company.
: Change Management Managing, controlling, and documenting any changes made to any of the services outsourced to the cloud provider.
: Access Controls Rules and mechanisms used to allow only authorized persons to use and access information assets in accordance with the nature of their responsibilities.
: Information Classification Determining the appropriate sensitivity level for information that is created, changed, transferred, modified, or stored on any media and using any possible technology, depending on the risks resulting from unauthorized access to and use of such information.
: Recovery A set of procedures taken and followed to restore the Company's business to normal and restart the technology resources relied upon to operate the Company's operations to their state before the event occurred.
: Vulnerability Scanning A mechanism used to identify system characteristics and associated vulnerabilities.
: Penetration Testing A test in which specialized evaluators attempt to find security vulnerabilities and bypass the security characteristics of information systems and security controls, and exploit them to attempt to breach those systems from outside or inside the Company to determine the effectiveness of the security controls used by the Company to protect its systems.
7 Recovery Time Objective (RTO) The maximum allowable time to restart a service or process after a service interruption occurs.
Recovery Point Objective (RPO) The maximum allowable age of data that may be lost when restoring service after an interruption.
Chapter One: Cloud Computing Technology 1.1 Introduction Cloud computing technology is considered a model for enabling network access from anywhere, on demand, to a shared pool of physical or virtual resources (such as networks, servers, storage media, applications, and services) that can be provisioned and used quickly with minimal effort. This model consists of five essential characteristics, three service models, and four deployment models.
1.2 Essential Characteristics • On-Demand Self-Service: A feature that enables the cloud consumer to request storage and processing services as needed and automatically, to reduce the need for direct interaction with the cloud provider. • Broad Network Access: Includes network access from anywhere to the cloud provider's resources through the Company's platforms such as mobile phones, tablets, laptops, and workstations. • Resource Pooling: The cloud provider pools various computing resources to serve many cloud users using a multi-tenant model, dynamically and automatically allocating and reallocating different physical and virtual resources according to the cloud user's request without the cloud user's control or knowledge of the specific location of the resources provided to them by the cloud provider, while retaining the right to specify the location at a certain level (e.g., country or data center). • Rapid Elasticity: Capabilities and processing power on the cloud can be provisioned flexibly and automatically, and the size of resources used can be adjusted to match the workload required by the cloud user, where available capabilities are unlimited and can be allocated at any time through contracts concluded between the user and the cloud provider.
8 • Measured Service: Usage can be automatically controlled, monitored, and reported, thereby providing transparency for both the cloud provider and the cloud consumer, with the user bearing the cost based on the resources required.
1.3 Service Models • Software as a Service (SaaS): A model for distributing software and making it available to cloud users via the network, so that applications are hosted by the cloud provider without the need to install or run applications on the user's devices. Users can use applications running on the provider's infrastructure and can access these applications through various devices and via a specific interface such as a web browser or program, making limited settings on those applications without the cloud user managing or controlling the cloud infrastructure. • Platform as a Service (PaaS): The platform provides a complete computing environment, including the operating system, programming language execution environment, databases, and web servers, to enable the cloud user to develop, run, and deploy their own applications on the cloud infrastructure and control their settings without the user managing or controlling the cloud infrastructure. • Infrastructure as a Service (IaaS): Physical or virtual computers and other resources such as networks and storage media are provided by the cloud provider to support the cloud user's operations, where the user is able to deploy and run some programs such as operating systems and applications. The user does not manage or control the cloud infrastructure, but can control the operating systems, storage, and deployed applications, and may have limited control over some network components (such as firewalls).
1.4 Deployment Models • Public Cloud: Cloud infrastructure is provided for open public use and may be owned, managed, or operated by a commercial, academic, or government institution or a combination thereof. The cloud infrastructure is located at a facility belonging to the cloud provider. Data belonging to the cloud user may be stored in locations unknown to them and may not be easily retrievable. Data of one cloud user may be stored with data of another user on the same cloud.
9 • Community Cloud: Cloud infrastructure is provided for exclusive use by a specific community of cloud users from companies that share the same interests, such as missions, security requirements, policies, and compliance considerations. It may be owned, managed, or operated by one or more companies in that community, a third party, or a combination thereof. It is more expensive than the public cloud as the cost is distributed among a number of cloud users in exchange for a higher level of commitment, privacy, and security. It may be located inside or outside the facilities of those companies, and data of each company may be stored with data of its competitors on the same community cloud. • Private Cloud: Cloud infrastructure is provided for exclusive use by a group of cloud users. It may be owned, managed, or operated by the group, a third party, or both. The cloud infrastructure may be inside the group's premises (On-premises) or outside the group's premises (Off-premises). The private cloud is considered the least risky deployment model, although the services provided through it may not be as flexible as in the public cloud. • Hybrid Cloud: Cloud infrastructure consists of two or more deployment models, whether private, community, or public, and is considered an independent entity but connected by unified technology that enables data and applications to move between them. This may give rise to risks due to the integration of more than one deployment model. In this case, it is the responsibility of the cloud user to classify information to be stored on their chosen deployment model. Table No. (1) below shows a comparison between different deployment models.
Table 1: Comparison Between Different Deployment Models
| Deployment Model | Cloud Infrastructure Manager | Cloud Infrastructure Owner | Cloud Infrastructure Location | Accessible and Usable By |
|---|---|---|---|---|
| Public Cloud | Cloud Provider | Cloud Provider | Outside the user's premises | Any cloud user |
| Private / Community Cloud | User or Cloud Provider | User or Cloud Provider | Outside or inside the user's premises | Trusted parties |
| Hybrid Cloud | User and Cloud Provider | User and Cloud Provider | Outside and/or inside the user's premises | Trusted and untrusted parties |
1.5 Cloud Actors The entities that participate in processes and/or tasks related to cloud computing, whether companies or individuals, actively involved in the cloud include:
10 • Aggregation: The broker collects and merges multiple services into one or more new services and provides them to the cloud user. The broker also provides data and service integration and ensures secure data movement between the user and cloud providers. • Arbitrage: Similar to the aggregation service, but the aggregated services are not fixed, as the broker has the flexibility to choose services from more than one cloud provider.
Cloud Auditor: The cloud auditor monitors the performance of cloud services and the security controls implemented on the cloud to verify compliance with cloud computing security policies.
Cloud Carrier: The cloud carrier transfers cloud services and data between users and providers of cloud services, with the cloud provider bearing the responsibility of establishing a cloud service level agreement with the cloud carrier to ensure the delivery of data and services to the cloud consumer at the agreed level.
1.5.1 Relationship Between Cloud Computing Actors • The cloud consumer can request cloud computing services directly from the cloud provider or through the cloud broker. If the cloud broker is engaged, the cloud consumer must consider that the cloud broker is subject to the same requirements as the cloud provider if contracted. • The cloud auditor conducts audits independent of other actors and collects the necessary information for that purpose. • There are specific roles for both the provider and the cloud consumer when using different service models, as shown in Table No. (2).
Table 2: Different Roles for Cloud Provider and Cloud Consumer When Using the Three Service Models
| Service Model | Cloud Consumer Activities | Cloud Provider Activities |
|---|---|---|
| Software as a Service (SaaS) | Using applications available on the cloud to perform operations within the scope of their work. | Installs, manages, maintains, and supports the applications available to them and specific to the cloud consumer on their cloud infrastructure. |
| Platform as a Service (PaaS) | Developing, testing, deploying, and managing applications hosted on the cloud platform. | Provisioning and managing cloud infrastructure and providing development, deployment, and management tools for cloud users. |
| Infrastructure as a Service (IaaS) | • Creating/installing, managing, and monitoring their own cloud infrastructure services. | |
| • Controlling the virtual machines used on the cloud in terms of operating systems, storage, and applications deployed at the level of those devices. | Providing and managing physical processing, storage, networks, hosting environment, and cloud infrastructure for cloud users. |
11
12
13
14 Chapter Two: Guidelines on the Use of Cloud Computing Technology 2.1 Introduction This chapter sets out guidelines on cloud governance and the Company's (cloud consumer) policy on using cloud computing technology, contracts and agreements concluded between the Company and the cloud provider, data security protection, risk management, change management, measuring the performance of the cloud provider and oversight of it, in addition to monitoring logs and security events, access management, business continuity, and exit plans related to cloud provider arrangements. This is aimed at protecting companies from risks they may face when using cloud computing technology.
2.2 Cloud Governance Effective governance when using cloud computing technology is essential to guide management processes and decision-making to benefit from cloud computing services according to the Company's needs in the best possible manner. The Company's cloud governance strategy should be clear to the cloud provider to enable collaboration between them in terms of operational performance, problem-solving, and sharing decisions regarding risk management associated with services outsourced to the cloud provider. The tasks and responsibilities of the Board and Senior Executive Management are determined, taking into account the following: • The Board or its delegated committees shall adopt the Company's cloud computing policy and monitor its implementation. • Senior Executive Management shall assume the following responsibilities and tasks, each according to their position: o Establishing an effective governance structure and cloud computing service outsourcing risk management processes properly. o Ensuring the establishment of a cloud computing policy, overseeing its implementation, review, and periodic update, and whenever necessary. o Approving agreements concluded between the Company and the cloud provider. o Ensuring that assessment and due diligence of cloud providers are conducted before entering into any agreement with them. o Reviewing risk assessment results for all cloud computing service outsourcing agreements based on the risk assessment framework approved by the Board of Directors.
15 o Reviewing periodic performance evaluation reports of the cloud provider. o Ensuring the establishment of disaster recovery plans based on realistic and potential failure, breach, and sabotage scenarios, and testing them periodically. o Ensuring the existence of an appropriate mechanism for continuous monitoring of the cloud provider in accordance with the terms and conditions of the cloud service level agreement between the Company and the cloud provider. o Ensuring that relevant parties in the Company review all activities and services outsourced to the cloud provider and regularly inform the Board of Directors of any risks that may arise therefrom.
2.3 Cloud Policy The Company should establish a cloud computing policy and review and update it periodically. It should include at a minimum the following: • The services, operations, and data to be outsourced to the cloud provider, classified according to their importance and sensitivity level, to serve as a reference when outsourcing cloud computing services. The Company bears the responsibility for classification. • The most suitable deployment model (public, private, community, hybrid) and the most suitable service model (PaaS, SaaS, IaaS) for the services and operations to be outsourced, relying on: o The type of service and classification of information and operations to be outsourced to the cloud provider. o The assessment of the associated risk level. • Mechanisms for storing the Company's data, their storage locations, and mechanisms for disposal, processing, and transmission with the cloud provider's systems. • Security controls to be followed when dealing with any cloud provider. • Basis for assessment and due diligence of cloud providers before entering into any agreement with them. • Requirements and expected results from outsourcing to cloud providers in performing operations, in accordance with requirements and changes in the work environment. • The relationship between the Company's internal operations and operations to be transferred to the cloud provider's systems. • A mechanism to ensure compatibility and interoperability between different services outsourced to more than one cloud provider.
16 • Controls to protect customer data and disclosure to the customer if any personal data is outsourced to the cloud provider, in accordance with relevant laws and instructions. • Minimum conditions that must be met in agreements concluded with the cloud provider. • Supervision and audit mechanisms for services outsourced to the cloud provider.
2.4 Risk Management The Company should identify and manage any risks resulting from outsourcing cloud computing services, taking into account the following: • Including cloud computing service outsourcing risks in the Company's comprehensive risk assessment framework, documenting and updating it continuously. It should include at a minimum the following: o Defining the role of the cloud provider in the Company's business strategy. o Establishing comprehensive procedures to cover connectivity requirements with the cloud provider to identify and mitigate basic risks. o Assessing the cloud provider's ability to employ high standards for service performance to ensure efficient service delivery. o Analyzing the impact of outsourcing cloud computing services on the Company's overall risk profile. o Assessing considerations related to applicable laws and law enforcement provisions, as well as the political and security stability of the cloud provider's country, including laws related to data protection. o Identifying financial, operational, and legal risks to the Company and its reputation in the event of the cloud provider's failure to perform operations as required. o Assessing overall security risks associated with the service outsourced to the cloud provider and determining the role and responsibility of the Company and the cloud provider in managing them, and identifying the steps necessary to mitigate them and documenting this assessment. • Establishing Key Risk Indicators (KRIs) to monitor the level of risk related to outsourcing cloud computing services to ensure that acceptable risk appetite and risk tolerance levels are not exceeded.
17 • Identifying current best practices in the use of cloud computing technology, including information security management requirements, cyber risks, and relevant regulatory rules. • Monitoring risks and identifying actions that may be taken in the event of the cloud provider's failure to provide services at the agreed level. • Determining the impact on the Company's customers in the event of the cloud provider's failure to perform services or breach the confidentiality of their data. • Managing security risks associated with storing data and running the Company's applications on the cloud provider's systems. • Monitoring concentration risks arising from reliance on a single cloud provider for all services intended to be outsourced, and considering actions to be taken in the event of the provider's failure to perform operations as required.
2.5 Contracts and Agreements Between the Company and the Cloud Provider The Company should ensure that the contract(s) concluded between it and the cloud
18 provider include clear and precise terms regarding the scope of services, performance standards, security obligations, data ownership, and rights of access and audit. The agreement must specify the responsibilities of both parties in the event of a security breach, service interruption, or data loss. It should also include provisions for regular reporting, dispute resolution, and termination clauses that allow the Company to exit the arrangement smoothly without compromising data integrity or business continuity. Furthermore, the contract must comply with all applicable laws and regulations, including those related to data protection and privacy, and must explicitly state that the cloud provider is subject to the oversight and audit rights of the Central Bank of Jordan.
2.5.1 Cloud Service Level Agreement (SLA) The Cloud Service Level Agreement is a critical component of the contract between the Company and the cloud provider. It defines the specific metrics for service availability, performance, and support. The SLA should include: • Service Availability: The percentage of time the service is expected to be operational. • Performance Metrics: Response times, throughput, and other technical performance indicators. • Support Levels: Definitions of support tiers, response times for different severity levels, and escalation procedures. • Remedies and Penalties: Consequences for the cloud provider in case of failure to meet the agreed service levels, including service credits or financial penalties. • Data Backup and Recovery: Specifications for backup frequency, retention periods, and recovery time objectives. • Security Standards: Detailed security controls and compliance certifications required from the cloud provider.
2.6 Oversight of the Cloud Provider The Company must establish a robust oversight mechanism for the cloud provider. This includes: • Regular Performance Reviews: Conducting periodic assessments of the cloud provider's performance against the SLA. • Security Audits: Performing regular security audits and penetration tests to ensure the cloud provider maintains adequate security controls. • Incident Management: Establishing clear procedures for reporting and managing security incidents and service disruptions. • Continuous Monitoring: Implementing tools and processes for continuous monitoring of the cloud environment. • Relationship Management: Maintaining open communication channels with the cloud provider to address issues promptly and foster a collaborative relationship.
2.7 Data Security The Company must ensure the security of data stored and processed in the cloud. This includes: • Data Classification: Classifying data based on sensitivity and applying appropriate security controls. • Encryption: Encrypting data at rest and in transit using strong encryption algorithms. • Access Control: Implementing strict access control mechanisms to ensure only authorized personnel can access data. • Data Residency: Ensuring data is stored in locations that comply with legal and regulatory requirements. • Data Disposal: Establishing secure methods for data disposal when it is no longer needed.
2.8 Access Management Effective access management is crucial for protecting cloud resources. This includes: • User Access Management: Managing user identities and access rights throughout their lifecycle. • Segregation of Duties: Ensuring that no single individual has excessive privileges that could lead to fraud or error. • Multi-Factor Authentication: Requiring multi-factor authentication for accessing cloud services. • Session Management: Implementing secure session management practices to prevent unauthorized access.
2.8.1 User Access Management and Segregation of Duties The Company must implement policies and procedures for managing user access to cloud services. This includes: • Role-Based Access Control (RBAC): Assigning access rights based on job roles. • Periodic Access Reviews: Regularly reviewing and updating user access rights. • Privileged Access Management: Implementing special controls for users with administrative privileges.
2.8.2 Effective Data Access The Company must ensure that data access is controlled and monitored. This includes: • Data Loss Prevention (DLP): Implementing DLP solutions to prevent unauthorized data exfiltration. • Logging and Monitoring: Logging all data access events and monitoring for suspicious activities.
2.9 Monitoring of Security Events and Logs The Company must monitor security events and logs to detect and respond to security incidents. This includes: • Log Management: Collecting, storing, and analyzing logs from cloud services. • Security Information and Event Management (SIEM): Implementing SIEM solutions to correlate security events. • Incident Response: Establishing an incident response plan to handle security incidents.
2.10 Business Continuity Management The Company must ensure business continuity in the event of a cloud service disruption. This includes: • Business Impact Analysis (BIA): Conducting a BIA to identify critical business processes and their dependencies on cloud services. • Disaster Recovery Plan: Developing a disaster recovery plan that includes cloud services. • Testing and Exercises: Regularly testing the disaster recovery plan and conducting exercises.
2.11 Change Management The Company must manage changes to cloud services and infrastructure. This includes: • Change Control Process: Implementing a change control process for all changes to cloud services. • Impact Assessment: Assessing the impact of changes on security and performance. • Rollback Plan: Developing a rollback plan in case of failed changes.
2.12 Data Sovereignty The Company must comply with data sovereignty laws and regulations. This includes: • Data Location: Ensuring data is stored in jurisdictions that comply with data sovereignty laws. • Legal Compliance: Ensuring that cloud providers comply with data sovereignty laws.
2.13 Exit Plan The Company must have an exit plan for cloud services. This includes: • Data Portability: Ensuring data can be easily transferred to another provider or back to on-premises infrastructure. • Service Transition: Planning for the transition of services to another provider. • Contract Termination: Defining procedures for terminating contracts with cloud providers.
Chapter Three: Cloud Computing Standards This chapter outlines the standards for cloud computing, including: • Security Standards: Standards for securing cloud services and data. • Performance Standards: Standards for measuring and ensuring cloud service performance. • Compliance Standards: Standards for ensuring compliance with laws and regulations. • Interoperability Standards: Standards for ensuring interoperability between different cloud services.
Appendix of Instructions and Circulars of the Central Bank This appendix contains the instructions and circulars issued by the Central Bank of Jordan related to cloud computing and outsourcing. Banks and financial institutions must comply with these instructions and circulars.
References This section lists the references used in the development of this guide, including international standards, best practices, and regulatory documents.