2007-09-19 | CD-SIBOIF-500-1-SEP19-2007Added · Updated
The Board of Directors of the Superintendence of Banks and Other Financial Institutions establishes minimum prudential criteria for the identification, measurement, limitation, control, and reporting of technology risks by supervised financial institutions. The regulation mandates that institutions implement specific governance structures, including Board and senior management responsibilities, organizational segregation of duties, and formal IT planning and project management procedures. It further requires strict controls over the acquisition, development, and implementation of IT systems, as well as comprehensive administration of software, databases, hardware, and operations to ensure reliability, confidentiality, and availability of information.
1 NORM ON TECHNOLOGY RISK MANAGEMENT Resolution No. CD-SIBOIF-500-1-SEP19-2007 Dated September 19, 2007 The Board of Directors of the Superintendence of Banks and Other Financial Institutions, CONSIDERING I That it is the objective of this Superintendence to promote that supervised institutions have a risk control system that allows them to identify, measure, limit, control, and report the risks they face, in order to mitigate or eliminate the possible negative impact of such risks; II That among the risks faced by supervised institutions in the development of their activities are operational risks, which can be generated by deficiencies or failures in internal processes, in Information Technology (IT), in people, or by the occurrence of external events; III That it is necessary to establish minimum prudential criteria for the identification and administration of risks associated with Information Technology (IT), in order to positively contribute to the stability and efficiency of the financial system; IV That based on the powers conferred by article 3, numeral 13 and article 10 of Law No. 316, Law of the Superintendence of Banks and Other Financial Institutions, reformed by Law No. 552, Law of Reforms to the aforementioned Law 316; and articles 40 and 134 of Law No. 561, General Law of Banks, Non-Bank Financial Institutions and Financial Groups; In exercise of its powers, HAS ISSUED, The following:
2 NORM ON TECHNOLOGY RISK MANAGEMENT Resolution No. CD-SIBOIF-500-1-SEP19-2007 CHAPTER I CONCEPTS, OBJECT AND SCOPE Art. 1. Concepts.- For the purposes of this regulation, the following concepts are established: a) Senior Management: The person who in the institutions holds the position of principal executive (Executive President, General Director, Executive Director, General Manager), or their equivalents. b) Business Impact Analysis: Stage of business continuity planning in which events that could have an impact on the continuity of operations and their financial, human, and reputational impact on the institution are identified. c) Database: Series of data organized and related to each other, which are collected and exploited by the institution's information systems. d) Log: Manual or electronic record that provides necessary information to identify and investigate any activity, problem, or incident. e) Structured Cabling: A cabling system planned to handle re-configurations, fault detection, and future growth in a network that takes into account security, labeling, ordering, and flexibility requirements. f) IT Governance: Structure of relationships and processes to direct and control the institution with the objective of achieving its goals, adding value while there is a balance between IT risks and benefits and their processes. g) Information: Any form of electronic, optical, magnetic, or other similar media recording, susceptible to being processed, distributed, and stored. h) Incident: Any event that is not part of the normal operation of a service and that causes or may cause an interruption or a reduction in quality of the same. This does not include requirements for changes to the technological infrastructure. i) Institutions: Banks and non-bank financial institutions subject to the authorization, supervision, surveillance, and audit of the Superintendence of Banks and Other Financial Institutions.
3 j) Applicable Best Practices: Best practices shall be understood as control frameworks, international standards, or other studies that help monitor and improve critical IT activities, increase business value, and reduce risks such as; COSO, COBIT, ITIL, ISO 17799, ISO 9001, CMM and PRINCE2, among others. k) Contingency Plan: Document where procedures to be followed in case of a contingency are detailed, in order not to affect the normal functioning of the institution. Its objective is to ensure an acceptable level of operationality of critical processes, in the face of major internal or external failures. l) Business Continuity Planning: A process designed to reduce the business risk of the organization arising from an unexpected interruption of its critical functions or operations, regardless of whether these are manual or automated, which are necessary for the survival of the organization. m) Policies: Set of practices established by the institution's board of directors, through which the courses of action to be followed by management are defined. n) Procedure: Method or structured system to execute instructions. Detailed list of the logical and consistent sequence of activities and courses of action, through which compliance with an operational function is ensured. o) Critical Process: Process considered indispensable for the continuity of the institution's operations and services, whose lack or deficient execution can have a significant financial impact on the institution. p) Information Technology Risks: Damage, interruption, alteration, or failures derived from the use of IT that supports the critical processes of the Institution and that lead to potential financial loss. q) Information Technology (IT): Hardware, Software, Information Systems, Technological Research, Local Networks, Databases, Software Engineering, Telecommunications, Services and IT Organization. Art. 2. Object.- This regulation aims to establish minimum evaluation criteria on the administration of risks, security, the use, and the controls applied to the Information Technology of supervised entities, in order to ensure the stability and efficiency of the financial system.
4 Art. 3. Scope.- The provisions of this regulation are applicable to all financial institutions subject to the authorization, supervision, and surveillance of the Superintendence of Banks, insofar as they are relevant. CHAPTER II INFORMATION CRITERIA Art. 4 Information Criteria.- For the purposes of this regulation, the following information criteria must be taken into consideration for the control and management of information technologies and their associated risks: a) Reliability: Systems must provide correct, complete, timely, and accurate information, which will be used in the entity's operation and decision-making, the preparation of financial statements and managerial information, and its submission to regulatory bodies. b) Confidentiality: Protection must be provided to sensitive information against unauthorized disclosure. c) Availability: Resources and information must be available in a timely manner, whenever required by users. d) Effectiveness: Information and processes must be relevant and pertinent to the business process, in addition to being presented in a correct, coherent, complete manner, and that can be used timely. e) Efficiency: The information process must be carried out through an optimal (more productive and economical) use of resources. f) Integrity: Refers to the precision and sufficiency of information, as well as its validity according to the values and expectations of the business. g) Compliance: Those laws, regulations, and contractual agreements to which the business process is subject must be complied with, i.e., externally imposed business criteria, as well as internal policies. CHAPTER III PLANNING, ORGANIZATION AND MANAGEMENT Art. 5. Responsibility of the Board of Directors and Senior Management.- The Board of Directors shall be responsible, at a minimum, for the following: a) Ensuring the existence of an Information Technology Governance.
5 b) Approving the objectives, guidelines, and general policies to adequately and prudently administer the security and risks of information technology, positively influencing the critical processes associated with said risk. c) Strengthening the content of the referred policies considering what is established in applicable best practices and the guidelines on the matter issued by the Superintendent. d) Providing the necessary resources to achieve compliance with the referred policies and the provisions contained in this regulation. e) Evaluating the content and applicability of the institution's IT policies with a frequency not greater than one (1) year. f) Ensuring the implementation of own or acquired information systems that meet the information criteria mentioned in this regulation. g) Approving IT plans. h) Ensuring the availability, capacity, and performance of the information systems required for the continuity of critical business processes. i) Ensuring the responsible use of IT resources. j) Adequately administering IT risks. These responsibilities may be delegated to a committee or designated instance, which must be integrated at least by the person in charge of IT, a member of the Board of Directors who is not the principal executive, and the main representatives of the user areas considered necessary according to the topics to be addressed. It shall be the responsibility of senior management to comply with the provisions emanating from the aforementioned bodies. Art. 6. Organizational structure and procedures.- Institutions in which critical processes are automated and whose business continuity depends on their information systems must at least: a) Guarantee the existence of an IT area that has independence, authority, and adequate segregation of functions from the areas to which it provides services.
6 b) Formally define the functions of IT personnel guaranteeing segregation of functions among personnel and excluding the possibility that a single person controls critical processes or operations related to IT. c) Define procedures for the hiring of new IT personnel. d) Implement controls to ensure that IT personnel carry out only the functions corresponding to their respective positions. e) Have technically qualified personnel or hire them externally. The institution that, due to its size or nature of business, cannot have this organizational unit, may request from the Superintendent to be exempted totally or partially from compliance with the provisions established in this article. Art. 7. Information technology planning.- Institutions must carry out operational and strategic IT planning (Short and long term) whose objectives are in accordance with institutional goals. Such planning must consider at least: a) IT cooperation with relevant user areas. b) The definition of how IT will support investment programs and the delivery of operational services. c) The definition of a technological infrastructure plan. d) The compliance with a pre-established policy for the acquisition and maintenance of technological infrastructure. e) The definition of how objectives will be met and measured, and how formal authorization from stakeholders will be received. f) A budget for IT investment and sources of financing. g) Acquisition strategies. h) Legal and regulatory requirements. Art. 8. Plan updates.- The operational and strategic plans referred to above must be updated and their performance evaluated in terms of their contribution to business objectives, their functionality, their stability, their complexity, their costs, their strengths and weaknesses. Such evaluation must be carried out at least annually.
7 CHAPTER IV ACQUISITION, DEVELOPMENT AND IMPLEMENTATION OF INFORMATION TECHNOLOGIES Art. 9. Approval of new projects.- Institutions must define their own IT project approval policies where the instances and levels of approval of the same are defined according to the nature and scope of the project. Art. 10. Administration of new projects.- Any project related to information technology must have the appropriate documentation on all its basic stages; initiation, planning, execution, control/monitoring, and final delivery and/or final reception. Project management must consider at least the following aspects: a) A written and approved project feasibility study by both the technology area and the affected user areas when applicable. b) The establishment of a work team with representation from the technology area and affected user areas, with assigned responsibilities. c) The establishment of a formal plan for the execution of the project. d) The determination of all phases required in the project including the testing, user training, conversion, and implementation phases. e) Procedures to verify the execution of the plan within the estimated time and budget and that guarantee that any deviation from the initial plan is duly approved and documented. f) Procedures for quality management and risk management associated with the project. g) The participation of the audit unit in a proactive manner, carrying out the evaluation of results during the execution and post-implementation of the project. h) Criteria for acceptance of results and post-implementation reviews. i) Preparation of project delivery or reception minutes. Art. 11. System development life cycle.- Any institution whose system development is carried out internally must have formal documentation of a development methodology that governs the processes, analysis, design, development, implementation, and maintenance of computerized systems and technology.
8 The system development life cycle, in addition to the considerations for project management, must contain at least the following aspects: a) The documentation of the detailed analysis and design of software considering user requirements. b) The determination of additional requirements for hardware, software, or other auxiliary elements. c) Implementation of controls on the entry, processing, and output of information. d) Definition and development of audit trails. e) The determination on the use of encryption techniques on critical information that must be protected. f) The determination of training needs and the plans for their timely execution. g) Existence of separate development environments (including testing and certification) and production. h) The execution of an integral test plan for the developed software, and the documentation of the results obtained from the test as support. i) The determination to execute parallel tests and the criteria to end this process. j) The determination on the performance of volume (stress) tests. k) The determination of certification, acceptance, and approval criteria by the user. l) The determination of conversion or transfer procedures to production. m) Procedures to ensure the timely update of technical and user information. Art. 12. Development and maintenance standards.- Any software development or programming function must have standards and naming conventions in its source codes in order to guarantee the operational continuity of development processes and the integration capacity between developed software applications.
9 Art. 13. Change control.- Adequate change procedures to production must be defined to protect application programs from unauthorized changes. The control objectives to consider are, at a minimum: a) Access to program libraries must be restricted. b) Supervisory reviews must be carried out. c) Change requests must be approved and documented. d) The potential impact of changes must be evaluated and documented. e) The change request must be documented in a standard form, paying particular attention to the following:
10 It is the responsibility of Internal Audit to monitor that emergency changes are carried out properly. CHAPTER V ADMINISTRATION OF INFORMATION TECHNOLOGIES Art. 15. Intellectual property rights.- Institutions must have documented policies and procedures to ensure that their technological platform is not used for the safeguarding, copying, distribution, or use of any application program, office software, multimedia content, or any other material in digital form whose rights have not been acquired by the institution and whose use is not authorized. Art. 16. Software administration.- Institutions must define policies and procedures for the adequate installation, maintenance, and administration of duly authorized software. For this, the entity must consider at least: a) Establish prohibitions and controls on the installation of software not authorized by the institution or that does not correspond to the user's profile. b) Update all software with the latest security improvements published by the provider, of the version it is using and that still has support from the provider. The foregoing is excepted for updates that may affect or negatively impact the institution's production computer systems. c) In the case of business applications, keep their technical and user documentation updated according to the latest changes made. d) Keep updated an inventory of contracts with software development service companies and of the software licenses acquired with their supporting documents. e) Version control procedures. Art. 17. Database administration.- The institution must adequately administer its databases, for which it must consider at least: a) Define the information architecture to organize and take advantage of information systems in the best way. b) Establish updated policies and procedures related to the installation, administration, migration, maintenance, backup, and security of databases. c) Define mechanisms to control the integrity, availability, capacity, and performance of databases.
11 d) Establish procedures for the activation, management, and review of logs, audit trails, etc. e) Define storage and information elimination periods, in accordance with internal, legal, and regulatory requirements. f) Keep the technical information of the design and functioning of databases updated. Art. 18. Hardware and communications administration.- The entity must adequately administer the hardware, networks, and critical communication lines, considering at least the following: a) Carry out capacity and performance studies of hardware and communication lines, which allow determining in a timely manner, needs for capacity expansion or equipment updates. b) Establish procedures for monitoring and reporting the efficient and effective use of equipment. c) Establish mechanisms to ensure that all installed networks, whether electrical, voice, or data, meet the current minimum structured cabling requirements. d) Ensure the existence of documentation and labeling of equipment and cabling. e) Establish preventive maintenance plans according to what is recommended by providers or the minimum required to prevent damage. f) Ensure that the climatic and environmental conditions of the processing and communications installations are appropriate for their proper functioning. g) Keep provider contracts, network diagrams, and communications, physical distribution diagrams, inventories, technical configuration, and any other required information updated. h) Equipment disposal procedures must consider that storage media containing sensitive material must be physically destroyed or securely overwritten instead of using standard deletion functions. Art. 19. Operations administration.- The institution must guarantee that any internal IT task or process is duly documented, this with the objective of achieving an operational environment that has an adequate level of maturity.
12 The documentation to be prepared may include among others the processes related to: a) The development, maintenance and implementation of IT. b) The acquisition of hardware and software. c) Administration of IT operations. d) Day-to-day operations. e) Centralized batch operations and accounting closing processes. f) Technical support or help desk operations. g) Problem resolution operations. h) Security. i) Human resources administration. j) Procedures to monitor the efficient and effective use of resources. k) General administration. These processes must be evaluated and updated in a period no greater than two (2) years, to guarantee their quality and adjustment to the reality of the institution. It is the responsibility of internal audit to ensure that functions are documented and are exercised according to their definition to produce the desired results. Art. 20. Administration and monitoring of service levels.- Institutions shall establish strategies and work procedures oriented to guarantee that internal users and clients of the institution receive the minimum required levels of availability and response times on the services provided with information technology. This provision applies to services provided internally or those provided by third parties. CHAPTER VI ADMINISTRATION OF SERVICES PROVIDED BY THIRD PARTIES Art. 21. Decentralized services.- Institutions that require decentralizing total or partial information technology processes, excluding software development services, outside their own facilities or direct supervision, must inform the Superintendent of this situation at least thirty (30) business days in advance of the start of operations at the remote site; this information must include at least: a) The reasons for this requirement. b) The detail of the processes or activities that will be decentralized. c) A copy of the agreement, contract or any document where the relationship with the entity responsible for providing the service is established.
13 d) The description of the processing environment, the remote site, those in charge of its operation and control responsibilities. The institution must adjust all decentralized processing activities, in accordance with the regulation governing the matter on the hiring of service providers. Art. 22. Subcontracting of services.- When certain functions or processes can be subject to subcontracting or outsourcing, the institution must proceed in accordance with the regulation governing the matter on the hiring of service providers. Art. 23. Acquisition of third-party software.- When an institution acquires or has plans to acquire computer applications to support business processes, it must take into consideration at least the following: a) The definition of initial requirements and their comparison with the strengths of the product: The product to be selected must meet the defined needs as best as possible. b) Request client references: References supplied by the seller must be verified to validate assertions about the functioning of the product and the work performed by the seller. c) Analyze the financial viability and stability of the seller: The seller who supplies or supports the product must have a good reputation and therefore, must be able to provide evidence of its financial stability. New sellers and products present a substantially higher risk to the organization. d) Guarantee the availability of complete and reliable documentation: The seller must be willing and able to supply the technical and user documentation of the system for review before acquisition. The level of detail and precision found in the documentation can be an indicator of the detail and precision used within the design and programming of the system itself. e) Guarantee the existence of seller support: The seller must have available a complete line of support products for the software package. This may include a permanent help line, local training/formation during implementation, product updates, automatic notification of new versions and local maintenance when requested. f) Guarantee the availability of source code: The source code must be received from the seller at the beginning, or there must be provisions for the acquisition of the source code including its updates, in case the seller leaves the business.
14 g) Verify the number of years of experience in the offered product: More years indicate stability and familiarity with the business that the product supports. h) Obtaining a list of recent updates: A short list of updates could suggest a lack of continuous updating of the product. i) Obtain a list of clients using the product: The list could indicate the acceptance of the product in the market. j) Product acceptance tests: Tests must be able to be performed on the product before acquiring purchase commitments to verify if it really satisfies the established requirements. CHAPTER VII SECURITY ADMINISTRATION Art. 24. Responsibilities in matters of security.- For the purposes of this standard and without prejudice to other applicable provisions, it is the responsibility of each institution in matters of information security the following: a) Ensure the integrity of information stored in its computer systems. b) Preserve the confidentiality of sensitive data. c) Ensure compliance with the trust placed and the obligation regarding any information relating to an identified or identifiable person (i.e., data subject) in conformity with its privacy policy or applicable privacy laws and regulations. d) Ensure the continuous availability of its information systems. e) Ensure compliance with applicable laws, regulations and standards. Art. 25. Security policies and procedures.- The institution must establish and maintain information security policies and procedures, whose structure and content includes, as a minimum: A) Structure or scheme:
15 B) Security Policies:
16 f) Reward employees who report suspicious cases. g) Periodic audits. Art. 27. Logical security.- Institutions must define a policy for limiting and controlling access to programs, databases, network services and operating systems. Among other aspects, the following must be contemplated: a) User identification and authentication controls. b) Formal procedures for granting, administering and revoking rights, profiles and users. c) Monitoring of resource use and event logging. d) Policies prohibiting the use of Generic Users and control of non-repudiation of responsibilities. e) Special controls on the proper use of user accounts with high privileges in information systems and related technologies. f) Controls to guarantee the permanent effectiveness of authentication means and passwords. g) Protection of network ports and services. h) Controls on the use of utility programs that could bypass controls established in information systems. i) Disconnection or locking of workstations due to inactivity time. Art. 28. Personnel security.- Institutions must define procedures to reduce risks associated with human error, theft, fraud or misuse of assets, linked to IT risk. In establishing these procedures, the following aspects must be taken into consideration, among others: a) Define adequate roles and responsibilities regarding information and its processing. b) Define adequate personnel hiring procedures, especially for the handling of critical IT processes. c) Establish the signing of confidentiality agreements by employees and external personnel granted access to processing facilities or information systems. d) Definition of other employment terms and conditions.
17 e) Establish policies for job rotation and vacations. f) Cross-control and shared control of sensitive operations. g) Constant training of personnel in security matters. Art. 29. Physical and environmental security.- The processing facilities for critical or sensitive company information must be physically protected against unauthorized access, damage and intrusions. The protection provided must be proportional to the identified risks; among the control objectives to consider are: a) Identification and access control over restricted areas. b) Implement clean desk and screen policies to reduce the risk of unauthorized access or damage to documents, storage media and information processing facilities. c) Visitors to restricted access areas must be supervised or inspected and the date and time of their entry and exit must be recorded. Access to them should only be allowed for specific and authorized purposes, instructing the visitor at that moment on the area's security requirements and emergency procedures. d) Computing equipment must be located or protected in such a way that risks caused by environmental threats and dangers, and opportunities for unauthorized access are reduced. e) Computing equipment must be protected with respect to possible failures in power supply or other electrical anomalies. An adequate power supply must be available that is in accordance with the specifications of the manufacturer or supplier of the equipment. Art. 30. Remote users and mobile computing.- The use of computing equipment to process information outside the scope of the organization must be authorized by the managerial level, regardless of who owns it. The level of security for these equipment must be equivalent to that provided within the scope of the organization, taking into account the risks associated with the form of work. This provision includes all types of personal computers, organizers, mobile phones, or any other type of device that can be transported and used for this purpose outside the institution. Art. 31. Protection against malicious software.- Detection and prevention controls must be implemented for protection against malicious software such as; computer viruses, Trojans, network worms and other similar threats.
18 Art. 32. Threats and security through the use of the Internet.- Institutions must identify the risks to which they are exposed by the use of the Internet and implement appropriate security controls for the use of this resource. The controls to be implemented must consider at least the following threats: a) Passive attacks or information search, for example: • Network analysis. • Eavesdropping • Network Traffic Analysis b) Active attacks or an attack to achieve full access to the systems, or enough to carry out particular threats, for example: • Brute force attacks. • Masking • Packet replay • Message modification • Unauthorized access through the Internet or Web-based services • Denial of service • Penetration attacks via telephone call • Email Bombardment and Spamming • Spoofing or email impersonation Art. 33. Security classification.- Institutions must perform a periodic inventory of physical assets and information assets, which aims to provide the basis for subsequent security classification according to a classification policy dictated by the board of directors or the competent instance. This classification must indicate the level of criticality, sensitivity and security required by the institution. CHAPTER VIII PROBLEM MANAGEMENT, CONTINGENCY PLANNING AND RECOVERY STRATEGIES Art. 34. Problem management.- Due to the complex nature of technology, there must be mechanisms to manage incidents, problems, errors or any abnormal condition in IT operations, these mechanisms must allow the identification, analysis, solution and documentation of errors, as detailed below: a) Errors that must be entered in the log include, among others: • Program errors, • System errors, • Operation errors, • Network errors,
19 • Telecommunication errors, • Hardware errors. b) Documentation on these events that must be kept must consider at least the following: • Date of the error, • Description of the error resolution, • Error code, • Description of the error, • Source of the error, • Initials of the person responsible for maintaining the record, • Initials of the person responsible for closing the entry to the register, • Department or center responsible for error resolution, • Status code of the problem resolution (for example, open problem, problem closed pending a specific future date or the problem has no solution in the current environment), • Narrative of the error resolution situation. c) For control purposes: • The ability to add to the error log must not be restricted. • The ability to update the error log must be restricted to authorized persons. • The ability to close a log entry assigned to a person different from the one responsible for maintaining or initiating the entry to the error log. Art. 35. Backup and restoration procedures.- Institutions must establish regular backup procedures for information periodically validated to ensure that normal information processing is resumed in the event of a short-term interruption and/or if there is a need to process or restart a process. Among the controls to consider in said procedures are the following: • Documentation and approval of the procedure. • Performing analysis on backup requirements for configurations, databases, source codes, office files, etc. • Establishing backup periodicity according to business requirements and contingency plans. • Safekeeping of storage media and their restoration procedures for predefined times according to internal, legal and regulatory requirements. • Performing tests on storage devices to verify the existence of backed-up information.
20 • Establishing backup procedures with reasonable frequency at a remote location, far enough away not to be compromised in the event of damage to the main processing center. • Implementation and testing of recovery and restoration procedures for backups in contingency cases. Art. 36. Information technology participation in business continuity.- As part of business continuity planning, institutions whose processing of data from their critical processes is implemented on information systems, must consider the participation of information technology in their contingency and disaster recovery plans. These institutions must have the ability to continue and restore normal processing of information systems, in case the primary information processing facilities are not available for a significant period of time. An information technology contingency planning process must be carried out, which contemplates the following stages: a) The formation of a multidisciplinary committee in charge of the process: the participation of those responsible for critical business areas is important. b) The creation of a contingency planning policy: which identifies the requirements for the contingency plan, which is approved by the board of directors or the competent authority, and which is published to personnel. c) Risk and business impact analysis: in which critical IT resources are identified, the impact of system downtimes and permissible downtime times are identified and recovery priority development is defined. d) Identify preventive controls: preventive controls must be implemented and maintained. e) Develop recovery strategies: recovery strategies must be identified and integrated into the system architecture. f) Develop an IT contingency plan: where the recovery strategy for the processing of information systems is documented. g) Develop a test plan, training program, dissemination and awareness of the plans: test objectives, test success criteria must be defined, lessons learned must be documented and incorporated into the plans and personnel trained to achieve successful execution thereof. The documentation of the tests and their results must be properly documented and this available when required. Tests must be performed with a frequency no greater than one (1) year. h) Implement plan maintenance: the plan must be reviewed and updated, coordination with internal areas and external organizations that may be necessary must exist, controls on the distribution of the plan must be established and change controls must be incorporated. Recovery strategies must allow the restitution of systems, critical applications and information processing activities, at the main processing site or at an alternate site under adequate operating conditions. The plans developed by the institution must consider the best balance for the institution between the cost of contingency and the cost of recovery of services. Art. 37. Use of insurance.- Institutions must have insurance coverage for the main computing and communications equipment that allows mitigating at least risks caused by fire, accidents, natural phenomena, strikes, riots, and theft. CHAPTER IX INTEGRATED TECHNOLOGICAL RISK MANAGEMENT Art. 38. Technological Risk Assessment.- Institutions must implement internal procedures that allow self-assessment in accordance with this standard, the results of said assessment and the evaluation of the level of technological risk exposure must be presented at least once a year to the board of directors of the institution. Art. 39. Methodology for integrated technological risk management.- Without prejudice to what is established in the regulation governing the matter on integrated risk management, with regard to operational risk and technological risk, institutions to whom compliance with said regulation corresponds, must formally approve and document a technological risk management methodology that considers risk analysis in a quantitative and qualitative manner. Art. 40. Quantitative risk analysis.- The quantitative analysis must consider the performance of the following activities: a) The formation of a historical database of loss events or frustration of gain resulting from the materialization of technological risks. b) The determination of the frequency of occurrence of said events.
22 c) The determination of its impact or severity. d) The estimation and provisioning of risk value based on reasonable historical information.
Art. 41. Qualitative Risk Analysis.- The qualitative risk analysis methodology must consider the following: a) The categorization of risks. b) The determination of risks inherent to each process involving the use of information technology, describing its composition in threats and/or vulnerabilities, its probability of occurrence and impact. c) The identification of controls that mitigate identified risks, their classification (For example: detective, deterrent, preventive, and/or corrective), their level of effectiveness and compliance. d) The determination of the residual risk resulting from the application of controls to inherent risks. e) The determination of acceptable risk levels. f) The identification and monitoring of improvement plans when required. g) The creation of risk and/or severity matrices and/or maps.
Art. 42. Information to the Superintendent.- 1 The institution must formally inform the Superintendent, immediately, of the occurrence of any of the following events, and within the subsequent twenty-four (24) hours detail the result and the actions taken to correct it: a) The occurrence of Security Incidents related to the successful completion of external attacks or penetration into the institution's systems through network and communication services. b) The activation of IT contingency plans and/or recovery strategies, as well as the strategy to be followed; c) The interruption in the normal functioning of main operating systems and application software that affect the provision of services to the institution's clients; d) The formal decision to make changes to the central operations platform and computerized systems; 1 Art. 42, amended on August 26, 2011 - Resolution CD-SIBOIF-690-2-AGOS26-2011
23 e) The formal decision to implement or change the technological platform used to provide financial services through electronic means; and f) Other events that, in their capacity as a regulated institution, are considered necessary to notify.
CHAPTER X OTHER PROVISIONS
Art. 43. Transitional.- Institutions must comply with the provisions contained in the following Chapters of this standard, at the latest, within the deadlines established below:
Deadline until Planning, organization and management December 2007 Acquisition, development and implementation of information technologies December 2008 Administration of information technologies December 2008 Administration of services provided by third parties December 2007 Security administration December 2008 Problem administration, contingency planning and recovery strategies December 2009 Comprehensive technological risk management December 2009
CHAPTER
Art. 44. Repeal.- The Norm on Technological Risk Management contained in Resolution CD-SIBOIF-437-1-AGOS14-2006 of August 14, 2006, published in La Gaceta, Official Journal No. 183 of September 21, 2006; and the Norm on Extension of the Deadline for the Application of the Provisions Contained in the Norm on Comprehensive Risk Management, contained in Resolution CD-SIBOIF-483-1-JUN13-2007 of June 13, 2007, published in La Gaceta, Official Journal No. 151 of August 09, 2007, are repealed.
Art. 45. Validity.- This standard will enter into force upon its notification, without prejudice to its subsequent publication in La Gaceta, Official Journal. (f) Antenor Rosales B. (f) V. Urcuyo V. (f) Gabriel Pasos Lacayo (f) Roberto Solórzano Ch. (f) A. Cuadra G. (f) U. Cerna B. URIEL CERNA BARQUERO Secretary of the SIBOIF Board of Directors
More like this from SIBOIF
We email you every new SIBOIF publication the day it's published.