2022-09-15 | Instrução Normativa BCB 305

Added · Updated

Normative Instruction BCB No. 305 — Publishes Version 4.0 of the Open Finance Security Manual

Participating institutions must comply with the mandatory Open Finance Security Manual v4.0, effective October 1, 2022, replacing Instruction No. 134. Obligations include maintaining governance processes, segregating networks, enforcing TLS 1.2+ with PFS, and using ICP-Brasil certificates. Institutions must implement vulnerability analysis, patch management, and multi-factor authentication for remote access. Audit trails and incident response plans are required, with mandatory sharing of compromise details with the Structure Responsible for the Governance of Open Finance.

Banco Central do Brasil logo

Brazil

Banco Central do Brasil

Scan of the document's first page
Share

BCB published 19 documents in the last 30 days — get each new one by email the day it lands.

Annotated text · 85 obligations · 3 permissions · 0 reporting items
  • Obligation 85
  • Permission 3
  • Definition / condition 40
  • Reporting template 0
  • background, boilerplate

Read the rest free

Lineage: Superseded

amendssupersedesissued underrefers toproposed or not in RegAlertarrows run from the older text to the one that changes it

Source: Banco Central do Brasil — original document · Summary generated with machine assistance and reviewed before publication; the authoritative text is the regulator's original document. How RegAlert works

More like this from BCB

BCB published 19 documents in the last 30 days. We email you each new one the day it's published.

Topics
open-banking
infosec