2018-03-28

Added · Updated

Guidelines on the Use of Cloud Computing Technology

The Central Bank of Jordan issues guidelines regulating the use of cloud computing technology by licensed banks, financial institutions, exchange companies, microfinance companies, and credit information companies. The document mandates specific governance structures, risk management frameworks, data security controls, and contractual requirements to ensure safe and effective adoption of cloud services. It defines key terms, cloud models, and outlines obligations for cloud consumers regarding vendor due diligence, service level agreements, and business continuity planning.

Central Bank of Jordan logo

Jordan

Central Bank of Jordan

Click to view thumbnail

1 Table of Contents Table of Contents1............................................................................................................. Introduction 3.......................................................................................................................... Scope and Objectives 4.............................................................................................................. Definitions 5.................................................................................................................... Chapter One: Cloud Computing Technology 8............................................................................. 1.1 Introduction 8............................................................................................................. 1.2 Essential Characteristics )Characteristics Essential )8................................................ 1.3 Service Models )Models Service)9....................................................................... 1.4 Deployment Models )Models Deployment)9................................................................. 1.5 Cloud Actors )Actors Cloud)11......................................................... 1.5.1 Relationship between Cloud Computing Actors 12....................................................... Chapter Two: Guidelines on the Use of Cloud Computing Technology14............................................. 2.1 Introduction 14........................................................................................................... 2.2 Cloud Computing Governance 14................................................................................... 2.3 Cloud Computing Policy15.................................................................................... 2.4 Risk Management 16................................................................................................ 2.5 Contracts and Agreements between the Company and the Cloud Provider 17.................................. 2.5.1 Cloud Service Level Agreement )Agreement Level Service Cloud)19.................... 2.6 Oversight of the Cloud Provider20............................................................................. 2.7 Data Security 20................................................................................................... 2.8 Access Management 22................................................................................................ 2.8.1 User Access Management and Segregation of Duties22................................................................. 2.8.2 Effective Data Access23....................................................................................

2 2.9 Monitoring of Security Events and Logs 23........................................................................ 2.10 Business Continuity Management24.................................................................................... 2.11 Change Management24................................................................................................... 2.12 Data Sovereignty 25................................................................................................. 2.13 Exit Plan 25........................................................................................................... Chapter Three: Cloud Computing Standards 27......................................................................... Appendix of Instructions and Circulars of the Central Bank30.................................................................................. References33........................................................................................................................

3 Introduction The financial and banking sector has recently witnessed significant development in the field of information technology and telecommunications and their use to provide financial and banking services. Since all companies and financial institutions seek to benefit from this technology to reduce their operational costs and increase profits, these institutions have turned to benefiting from third parties that provide many of the resources required by companies to manage and provide their services. This is achieved by allowing users of this technology to access all applications and services from anywhere and at any time via the Internet, ensuring continuity, which is known as cloud computing technology. This technology offers many benefits, but it may also increase the volume of risks to companies, such as strategic risks, reputational risks, compliance risks, and operational risks arising from third parties' failure to provide services at the agreed level, or security breaches. This requires companies to adopt a sound and rapid-response framework for managing these risks and maximizing the benefits of this technology. This guide clarifies the concept of cloud computing technology, its essential characteristics, deployment models, and service models related to it. It also provides guidelines on some important issues that institutions must consider carefully when using this technology, including cloud computing governance, risk management, business continuity, and the controls and mechanisms used to protect their data for safe and effective use. This guide also includes a special appendix containing the instructions and circulars issued by the Central Bank of Jordan related to outsourcing operations, given the necessity for licensed banks operating in the Kingdom to fully comply with these instructions and circulars, as cloud computing technology falls within the scope of outsourcing operations, to facilitate banks' reference to them.

4 Scope and Objectives In light of the Central Bank of Jordan's efforts to keep pace with best international practices that positively impact the components of the Jordanian financial system and ultimately achieve financial stability and enhance the resilience of the financial and banking sector in conducting its business and making its services available safely, efficiently, and effectively; this guideline is issued to regulate the use of cloud computing technology by banks, financial institutions, exchange companies, microfinance companies, and credit information companies subject to the supervision and oversight of the Central Bank of Jordan. This aims to achieve their objectives within an appropriate level of security and protection, and to assist them in understanding cloud computing technology and its risks for safe and effective use.

5 Definitions The words and phrases below shall have the meanings assigned to them wherever they appear in this guide. The definitions contained in the Central Bank Law, the Electronic Transactions Law, the Banks Law, and any other relevant instructions issued by the Central Bank shall apply wherever the text refers to them in this guide, unless the context indicates otherwise: : The Company The Bank or Islamic Bank or Financial Institution or Exchange Company or Credit Information Company or Microfinance Company. : Senior Executive Management Includes the General Manager or Regional Manager and Deputy General Manager or Deputy Regional Manager and Assistant General Manager or Assistant Regional Manager and the Financial Director, Operations Director, Risk Management Director, Treasury (Investment) Director, and Compliance Director, in addition to any employee in the Company who has executive authority equivalent to any of the aforementioned and is functionally directly subordinate to the General Manager. : Customer (Customer( Any natural or legal person who obtains financial services from the Company. Cloud Consumer (Cloud Consumer) : The entity that requests and uses the resources and services available on the cloud. Cloud Provider (Cloud Provider) : The entity that provides cloud resources and services and the activities necessary to provide these services and ensure their delivery to the cloud consumer. Cloud Computing Technology (Cloud Computing Technology) : A model for enabling convenient, on-demand network access to a shared pool of configurable computing resources )such as networks, servers, storage, applications, and services( that can be rapidly provisioned and released with minimal management effort or service provider interaction. Cloud Infrastructure (Cloud Infrastructure) : A set of physical and software components such as servers, storage media, networks, and virtualization software necessary to support cloud computing requirements.

6 Cloud Service Level Agreement (Cloud Service Level Agreement) : A contractual agreement between the cloud provider and the Company in which the Company's requirements, the level of service, and the guarantees provided by the cloud provider regarding service availability, performance, and support levels are specified. Risk Assessment (Risk Assessment) : Measuring and determining the probability of risk occurrence and its severity, and predicting the extent of its impact on the Company. Change Management )Change Management( : Managing, controlling, and documenting any change made to any of the services outsourced to the cloud provider. Access Controls (Access Control) : Rules and mechanisms used to allow only authorized persons to use and access information assets in accordance with the nature of their responsibilities. Information Classification (Information Classification) : Determining the appropriate sensitivity level for information that is created, changed, transferred, modified, or stored on any media and using any possible technology, based on the risks resulting from unauthorized access to and use of such information. Recovery (Recovery) : A set of procedures taken and followed to restore the Company's business to normal and restart the technology resources relied upon to operate the Company's operations to their state prior to the occurrence of the event. Vulnerability Scanning (Vulnerability Scanning) : A mechanism used to identify system characteristics and associated vulnerabilities. Penetration Testing )Penetration Testing( : A test in which specialized evaluators attempt to find security vulnerabilities and bypass the security characteristics of information systems and security controls, and exploit them to attempt to breach those systems from outside or inside the Company to determine the effectiveness of the security controls used by the Company to protect its systems.

7 Recovery Time Objective )RTO( The maximum allowable time to restart a service or process after a service interruption occurs. Recovery Point Objective )RPO( The maximum allowable age of data that may be lost when restoring service after an interruption.

8 Chapter One: Cloud Computing Technology 1.1 Introduction Cloud computing technology is considered a model for enabling convenient, on-demand network access from anywhere to a shared pool of physical )Physical Resources( or virtual )Virtual Resources( resources such as networks, servers, storage media, applications, and services that can be rapidly provisioned and used with minimal effort. This model consists of five essential characteristics )Characteristics Essential(, three service models )Models Service(, and four deployment models )Models Deployment(. 1.2 Essential Characteristics )Characteristics Essential)  On-Demand Self-Service )Service-Self Demand-On(: A feature that enables the cloud consumer to request storage and processing services as needed and automatically, with the aim of reducing the need for direct interaction with the cloud provider.  Broad Network Access )Access Network Broad(: Includes network access from anywhere to the cloud provider's resources via corporate platforms such as: mobile phones, tablets, laptops, and workstations.  Resource Pooling )Pooling Resource(: The cloud provider pools various computing resources to serve many cloud users using a multi-tenant )model tenant-Multi( model, dynamically allocating and reallocating different physical and virtual resources according to the cloud consumer's request without the cloud consumer's need for control or knowledge of the specific location of the resources provided to them by the cloud provider, while retaining their right to specify the location at a certain level )for example, the country or data center(.  Rapid Elasticity )Elasticity Rapid(: Capabilities and processing power on the cloud can be provided flexibly and automatically, and the size of resources used can be adjusted to match the workload required by the cloud consumer, where available capacities are unlimited and can be allocated at any time through contracts concluded between the user and the cloud provider.

9 in the use of cloud resources and improving  Measured Service )Service Measured(: Usage can be automatically controlled, monitored, and audited, and reports generated regarding it, thereby providing transparency for both the provider and the cloud consumer, with the user bearing the cost according to the required resources. 1.3 Service Models )Models Service)  Software as a Service (SaaS (Service a as Software: A model for distributing software and making it available to the cloud consumer via the network, such that applications are hosted by the cloud provider without the need to install or run applications on the user's devices, where the user can use applications running on the provider's infrastructure and can access those applications through various devices and via a specific interface such as a web browser interface or program, and make limited settings on those applications without the cloud consumer managing or controlling the cloud infrastructure.  Platform as a Service (PaaS (Service a as Platform: The platform provides a complete computing environment, including the operating system, programming language execution environment, databases, and web servers, to enable the cloud consumer to develop, run, and deploy their own applications on the cloud infrastructure and control their settings without the user managing or controlling the cloud infrastructure.  Infrastructure as a Service (IaaS (Service a as Infrastructure: Physical or virtual computer devices and other resources such as networks and storage media are provided by the cloud provider to support the cloud consumer's operations, where the user is able to deploy and run some programs such as operating systems and applications, and the user does not manage or control the cloud infrastructure, but can control the operating systems, storage, and deployed applications, and perhaps have limited control over some network components )such as firewalls(. 1.4 Deployment Models )Models Deployment)  Public Cloud )Cloud Public(: The cloud infrastructure is provided for open public use and may be owned, managed, or operated by a commercial, academic, or government institution or a group thereof, and the cloud infrastructure is located at a facility belonging to the cloud provider. Data belonging to the cloud consumer may be stored in locations unknown to them and may not be easily retrievable, and the cloud consumer's data may be stored with another user's data on the same cloud.

10 the cloud consumer's data may be stored with another user's data on the same cloud.  Community Cloud (Cloud Community(: The cloud infrastructure is provided for exclusive use by a specific community of cloud users from companies that share the same interests, such as their missions, security requirements, policies, and compliance considerations. It may be owned, managed, or operated by one or more companies in that community or a third party or a combination thereof. It is more expensive than the public cloud, as the cost is distributed among a number of cloud users in exchange for a higher level of commitment, privacy, and security. It may be located inside or outside those companies' sites, and the data of each company may be stored with the data of its competitors on the same community cloud.  Private Cloud )Cloud Private(: The cloud infrastructure is provided for exclusive use by a group of cloud users, which may be owned, managed, or operated by the group or a third party or both. The cloud infrastructure may be inside the group's premises )premises-On( or outside the group's premises (premises-Off). The private cloud is considered the least risky deployment model, although the services provided through it may not be as flexible as in the public cloud.  Hybrid Cloud )Cloud Hybrid(: The cloud infrastructure consists of two or more deployment models, whether private, community, or public clouds, and is considered an independent entity but connected by a unified technology that enables data and applications to move between them. This may give rise to risks due to the integration of more than one deployment model, and here it is the responsibility of the cloud consumer to classify information to be stored on their chosen deployment model. Table No. )1( below shows a comparison between different deployment models.

11 Table 1: Comparison between different deployment models Deployment Model Cloud Infrastructure Manager Cloud Infrastructure Owner Cloud Infrastructure Location Accessible and Usable By Public )Public) Cloud Provider Cloud Provider Outside the consumer's premises Any cloud consumer Private )Private( / Community (Community) Consumer or Cloud Provider Consumer or Cloud Provider Outside or inside the consumer's premises Trusted parties Hybrid )Hybrid) Consumer and Cloud Provider Consumer and Cloud Provider Outside and/or inside the consumer's premises Trusted and untrusted parties

1.5 Cloud Actors )Actors Cloud) The entities that actively participate in operations and/or tasks related to cloud computing, whether companies or individuals, include the following: .1 Cloud Consumer )Consumer Cloud) .2 Cloud Provider )Provider Cloud) .3 Cloud Broker )Broker Cloud): Acts as an intermediary between the consumer and the cloud provider and helps cloud consumers choose and manage various cloud computing services provided by the provider, in addition to providing additional services to the user. Services provided through the cloud broker include:  Intermediation (Intermediation(: The broker enhances a specific service by improving it and providing value-added services to users. The improvement may consist of managing access to cloud computing services, identity management, and enhancing security, among other things.

12  Aggregation )Aggregation(: The broker collects and merges multiple services into one or more new services and provides them to the cloud consumer. The broker also provides data and service integration and ensures secure data movement between the consumer and cloud providers.  Arbitrage )Arbitrage(: Similar to the aggregation service, but the aggregated services are not fixed, as the broker has the flexibility to choose services from more than one cloud provider. .4 Cloud Auditor )Auditor Cloud): The cloud auditor monitors the performance of cloud services and the security controls implemented on the cloud to verify compliance with cloud computing security policies. .5 Cloud Carrier )Carrier Cloud): The cloud carrier transfers cloud services and data between consumers and providers, with the cloud provider bearing the responsibility of establishing a cloud service level agreement with the cloud carrier to ensure the delivery of data and services to the cloud consumer at the agreed level. 1.5.1 Relationship between Cloud Computing Actors  The cloud consumer can request cloud computing services directly from the cloud provider or through the cloud broker. If the cloud broker is engaged, the cloud consumer must consider that the cloud broker is subject to the same obligations as the cloud provider if contracted with.  The cloud auditor conducts audits independent of other actors and collects the necessary information for that purpose.  There are specific roles for both the provider and the cloud consumer when using different service models, as shown in Table No. )2(.

13 Table 2: Different roles for both cloud provider and cloud consumer when using the three service models Service Model Cloud Consumer Activities (Cloud Consumer Activities) Cloud Provider Activities (Cloud Provider Activities) Software as a Service )SaaS( Using applications available on the cloud to perform operations within their scope of work. Installs, manages, maintains, and supports the applications available to them and specific to the cloud consumer on their cloud infrastructure. Platform as a Service )PaaS( Developing, testing, deploying, and managing applications hosted on the cloud platform. Allocating and managing the cloud infrastructure and providing development, deployment, and management tools for cloud consumers. Infrastructure as a Service )IaaS(  Creating/installing, managing, and monitoring their own cloud infrastructure services.  Controlling the virtual machines ) Virtual Machines( used on the cloud in terms of operating systems, storage, and applications deployed at the level of those devices. Providing and managing physical processing, storage, networks, hosting environment, and cloud infrastructure for cloud consumers.

14 Chapter Two: Guidelines on the Use of Cloud Computing Technology 2.1 Introduction This chapter sets out guidelines on cloud computing governance and the Company's )cloud consumer( policy on using cloud computing technology, contracts and agreements concluded between the Company and the cloud provider, data security protection, risk management, change management, measuring the cloud provider's performance and oversight, in addition to monitoring logs and security events, access management, business continuity, and exit plans related to cloud provider arrangements, with the aim of protecting companies from risks they may face when using cloud computing technology. 2.2 Cloud Computing Governance Effective governance when using cloud computing technology is essential to guide management operations and decision-making to benefit from cloud computing services according to the Company's needs in the best possible manner. The Company's cloud computing governance strategy should be clear to the cloud provider to enable collaboration between them in terms of operational performance, problem-solving, and sharing decisions regarding risk management associated with services outsourced to the cloud provider, where the tasks and responsibilities of the Board and Senior Executive Management are determined, taking into account the following:  The Board or those delegated by its committees shall adopt the Company's cloud computing policy and monitor its implementation.  Senior Executive Management shall assume the following responsibilities and tasks, each according to their position: o Establishing an effective governance structure and cloud computing services outsourcing risk management processes properly. o Ensuring the establishment of a cloud computing policy, overseeing its implementation, and reviewing and updating it periodically and whenever necessary. o Approving agreements concluded between the Company and the cloud provider. o Ensuring that risk assessment and due diligence are conducted for cloud providers before entering into any agreement with them. o Reviewing risk assessment results for all cloud computing services outsourcing agreements based on the risk assessment framework approved by the Board of Directors.

15 o Reviewing periodic performance evaluation reports of the cloud provider. o Ensuring the establishment of disaster recovery plans based on realistic and potential failure, breach, and sabotage scenarios, and testing them periodically. o Ensuring the existence of an appropriate mechanism for continuous monitoring of the cloud provider in accordance with the terms and conditions of the cloud service level agreement between the Company and the cloud provider. o Ensuring that relevant parties in the Company review all activities and services outsourced to the cloud provider and regularly inform the Board of Directors of any risks that may arise therefrom. 2.3 Cloud Computing Policy The Company should establish a cloud computing policy and review and update it periodically, ensuring it includes at a minimum the following:  The services, processes, and data to be outsourced to the cloud provider, classified according to their importance and sensitivity level, to serve as a reference when outsourcing cloud computing services, with the Company bearing responsibility for their classification.  The most suitable deployment model )public, private, community, hybrid( and the most suitable service model )PaaS, SaaS, IaaS( for the services and processes to be outsourced, relying on: o The type of service and classification of information and processes to be outsourced to the cloud provider. o The assessment of the associated risk level.  Mechanisms for storing the Company's data, storage locations, and mechanisms for disposing of, processing, and transferring them with the cloud provider's systems.  Security controls to be followed when dealing with any cloud provider.  Criteria for evaluating and conducting due diligence on cloud providers before entering into any agreement with them.  Requirements and expected results from outsourcing to cloud providers in performing operations, in accordance with requirements and changes in the work environment.  The relationship between the Company's internal operations and processes to be transferred to the cloud provider's systems.  Mechanisms to ensure compatibility and interoperability between different services outsourced to more than one cloud provider.

16  Controls to protect customer data and disclosure to the customer if any personal data belonging to them is outsourced to the cloud provider, in accordance with relevant laws and instructions.  Minimum conditions that must be met in agreements concluded with the cloud provider.  Supervision and audit mechanisms for services outsourced to the cloud provider. 2.4 Risk Management The Company shall identify and manage any risks that may arise from outsourcing cloud computing services, taking into account the following:  Including cloud computing services outsourcing risks within the Company's comprehensive risk assessment framework and documenting and updating it continuously, ensuring it includes at a minimum the following: o Defining the cloud provider's role in the Company's business strategy. o Establishing comprehensive procedures to cover connectivity requirements with the cloud provider to identify and mitigate basic risks. o Assessing the cloud provider's ability to employ high standards for service performance to ensure efficient service delivery. o Analyzing the impact of outsourcing cloud computing services on the Company's overall risk profile. o Assessing considerations related to applicable laws and law enforcement provisions, in addition to the political and security stability of the cloud provider's country, including laws related to data protection. o Identifying financial, operational, legal, and reputational risks to the Company in the event of the cloud provider's failure to perform operations as required. o Assessing overall security risks associated with the service outsourced to the cloud provider and determining the role and responsibility of the Company and the cloud provider in managing them, and identifying the steps necessary to mitigate them and documenting this assessment.  Establishing key risk indicators )Indicators Risk Key( to monitor the level of risk related to outsourcing cloud computing services to ensure that accepted risks )Appetite Risk( and risk tolerance levels are not exceeded.

17  Identifying current best practices in the use of cloud computing technology, including information security management requirements, cyber risks, and relevant regulatory rules.  Monitoring risks and identifying actions that may be taken in the event of the cloud provider's failure to provide services at the agreed level.  Determining the impact on the Company's customers in the event of the cloud provider's failure to perform the service or breach the confidentiality of their data.  Managing security risks associated with storing the Company's data and running its applications on the cloud provider's systems.  Monitoring concentration risks arising from reliance on a single cloud provider for all services intended to be outsourced to the cloud provider and considering the actions that will be taken in the event of the provider's failure to perform operations as required. 2.5 Contracts and Agreements between the Company and the Cloud Provider The Company should ensure that the contract(s) concluded between it and the provi