2020-03-10 | 3224Added · Updated
This resolution approves the Regulation on Information Protection in Automated Banking Systems of Commercial Banks of the Republic of Uzbekistan according to Appendix 1 and declares certain departmental normative legal documents invalid according to Appendix 2. The decision enters into force from the day of its official publication. A commentary note states that the document loses force on November 20, 2025, based on the Central Bank Board's decision dated August 1, 2025, No. 19/1.
Resolution of the Board of the Central Bank of the Republic of Uzbekistan, registered on 10.03.2020, registration number 3224
Effective Date
10.03.2020
All
Link to next version
Link to previous version
Indexing by CTUK
Indexing by CMQ
Source of amendments
Source of official publication
20.11.2025
01.02.2023
28.07.2021
17.06.2021
26.01.2021
10.03.2020
View
Russian Uzbek O'zb Uzbek|Russian
Document lost force 20.11.2025
[ OKOZ: 1. 07.00.00.00 Legislation on Finance and Credit. Banking Activity / 07.19.00.00 Banking System / 07.19.02.00 Commercial Banks. Private Banks. Foreign Banks; 2. 12.00.00.00 Information and Informatization / 12.08.00.00 Information Security, Protection of Information and Information Processes and Rights of Subjects in the Field of Informatization (see also 16.04.03.00)); 3. 16.00.00.00 Security and Law Enforcement Protection / 16.04.00.00 Public Security / 16.04.03.00 Information Security (see also 12.08.00.00)] [ TSZ: 1. Economy / Information and Informatization. Electronic Commerce (document flow); 2. Finance / Banks and Other Credit Institutions. Credits]
Resolution of the BOARD of the Central Bank of the Republic of Uzbekistan
On Approval of the Regulation on Information Protection in Automated Banking Systems of Commercial Banks of the Republic of Uzbekistan
[Registered by the Ministry of Justice of the Republic of Uzbekistan on March 10, 2020, registration number 3224]
LexUZ Commentary This decision loses force from November 20, 2025, based on the Resolution of the Board of the Central Bank of the Republic of Uzbekistan dated August 1, 2025, No. 19/1 "On Approval of the Regulation on Minimum Requirements for Information Security and Cybersecurity of Commercial Banks of the Republic of Uzbekistan" (registration number 3669, 18.08.2025).
In accordance with the Laws of the Republic of Uzbekistan "On Information Protection in Automated Banking System" and "On the Central Bank of the Republic of Uzbekistan" and the Decree of the President of the Republic of Uzbekistan dated August 8, 2018, No. PF-5505 "On Approval of the Concept for Improving Normative Creativity Activity", the Board of the Central Bank of the Republic of Uzbekistan resolves:
The Regulation on Information Protection in Automated Banking Systems of Commercial Banks of the Republic of Uzbekistan be approved according to Appendix 1.
Certain departmental normative legal documents be deemed invalid according to Appendix 2.
This resolution enters into force from the day of its official publication.
Chairman of the Central Bank M. NURMURATOV
Tashkent city,
January 25, 2020,
No. 2/4
To the Resolution of the Board of the Central Bank of the Republic of Uzbekistan dated January 25, 2020, No. 2/4
APPENDIX 1 [ OKED: 1. 07.00.00.00 Legislation on Finance and Credit. Banking Activity / 07.19.00.00 Banking System / 07.19.02.00 Commercial Banks. Private Banks. Foreign Banks]
On Information Protection in Automated Banking Systems of Commercial Banks of the Republic of Uzbekistan
REGULATION
This Regulation establishes the procedure for information protection in the automated banking systems of commercial banks (hereinafter referred to as bank in the text). (preamble edited by Resolution No. 1/13 of the Board of the Central Bank of the Republic of Uzbekistan dated January 21, 2023 (registration number 3224-2, 31.01.2023) — National Database of Legislative Information, 01.02.2023, No. 10/23/3224-2/0064)
Chapter 1. General Rules
automated banking system — an information system designed to collect, store, search, process and use information in the field of banking activity;
antivirus program — an anti-computer virus program designed to detect viruses and capable of offering to destroy them or destroying them;
antivirus protection — a set of measures aimed at preventing the influence of computer viruses, detecting and neutralizing viruses using antivirus programs;
authentication — the procedure for confirming the authenticity of a user, program, device or data;
information assets — information resources, information processing devices and other information important for the bank;
information resource — information in electronic form within the information system, data bank, database, including audio, video, graphic and text information placed or published in open form in information systems; (subparagraph seven of paragraph 1 edited by Resolution No. 12/3 of the Board of the Central Bank of the Republic of Uzbekistan dated May 28, 2021 (registration number 3224-1, 17.06.2021) — National Database of Legislative Information, 17.06.2021, No. 10/21/3224-1/0567)
information system — a totality of information resources, information technologies and communication means organized in an organized manner that allows collecting, storing, searching, processing and using information;
information security — the protection of information and supporting infrastructure from natural or artificial influences of an accidental or intentional nature that may cause unacceptable damage to subjects of information relations;
information security incident — a single event or a series of adverse or unexpected events of information security, as a result of which there is a possibility of disclosure of information and threats to information security;
attack — destruction, disclosure, modification, blocking, seizure, obtaining unauthorized use rights of information assets or attempting to use information assets without authorization;
computer virus — a program (set of executable codes) that has destructive properties, capable of multiplying its copy (may not fully match the original copy) and introducing them into various resources of computer systems, networks without the user's knowledge;
monitoring — monitoring the status of the automated banking system and information systems;
server room — a room where bank servers, telecommunication devices, uninterruptible power supplies and other computing equipment are located;
firewall — a program and (or) software tool that controls information incoming to and (or) outgoing from the automated banking system;
hash sum — a sum calculated using a cryptographic algorithm to check file integrity;
personal data — information recorded electronically, on paper and (or) on another physical object relating to a specific individual or allowing their identification;
electronic archive — a structural unit of the bank that has archive status, collects, records, stores and uses bank electronic documents.
07.00.00.00 Legislation on Finance and Credit. Banking Activity / 07.21.00.00 Banking Activity / 07.21.21.00 Other Issues of Banking Activity]
Chapter 2. Information Protection Service in Bank Activity
To ensure information security, an information protection service (hereinafter referred to as Information Security Service in the text) is established in banks and their branches.
The Information Security Service is responsible for preventing and eliminating cases of temporary suspension of the automated banking system, illegal changes in payment information, and damage to the bank or client.
The Information Security Service in its activity:
organizes the information security management system, organizes and controls the fulfillment of the bank's information security requirements by bank divisions and employees;
organizes control over the preservation of information;
provides methodological and practical assistance to bank divisions and employees on information protection issues;
participates in the processes of designing, testing and accepting the information protection system in the automated banking system, putting it into practice, and takes measures to prevent the leakage of bank secrets and other confidential information in these processes;
within its competence, selects, introduces and applies methods, means and mechanisms for managing, ensuring and controlling the bank's information security;
takes measures to protect information in this system when attempts to unauthorized use of information in the automated banking system are detected, when it is interfered with in another form, and when the system operating rules are violated;
detects, analyzes threats and attacks on information systems and takes measures to eliminate them;
collects, processes, analyzes and stores information on information security incidents;
carries out work on investigating information security incidents;
analyzes the status and effectiveness of information protection measures;
controls and ensures the correct operation of information security software and hardware;
conducts monitoring related to ensuring information security;
prepares proposals on information security issues;
establishes requirements for taking information security measures in information resources and information systems;
draws up plans for ensuring and controlling information security in the bank's information resources and information systems;
controls the preservation of confidential, including bank secrecy and personal data;
participates in the process of restoring systems when stops and emergency situations occur in information systems and controls the return of information systems to full working condition;
must perform other functions in accordance with bank documents.
The tasks, powers and obligations of the Information Security Service may be determined by the bank's internal documents, taking into account the requirements of this Regulation. The Information Security Service must be provided with the technical resources necessary to fulfill its tasks and obligations.
The number of employees of the Information Security Service is determined based on the tasks assigned to it, the number of information resources and information systems, and the degree of automation of information security systems.
The Information Security Service and information technology divisions must report to different members of the bank management body, while the Information Security Service reports directly to the bank management chairman.
Banks must ensure the improvement of qualifications of Information Security Service employees at least once a year.
Information security is ensured based on the requirements established in legislative documents and the bank's internal documents on information security. (paragraph 10 edited by Order No. 16-mh of the Minister of Justice of the Republic of Uzbekistan dated July 28, 2021 (registration number 3313, 28.07.2021) — National Database of Legislative Information, 28.07.2021, No. 10/21/3313/0724)
The bank must develop and adopt an internal policy on information security.
The policy on information security establishes requirements for ensuring information security in all information systems and information resources available in the bank.
Internal documents on information security and the requirements established in them must be introduced to each employee of the bank and employees must strictly comply with these requirements.
All measures specified in this Regulation related to ensuring information security in information resources and information systems must have their confirmation in written or electronic form.
If the bank has a network of branches, each branch must have a set of approved documents on information security of the bank. If it is necessary to take into account the characteristics of certain branches, the bank ensures the development of its internal documents taking into account these characteristics.
Chapter 3. Protection from Disclosure of Confidential Information
In this case, the bank must fulfill the following:
define a list of confidential information related to the bank or its division, including bank secrecy and personal data;
sign an obligation with each employee to keep confidential information secret for the purpose of compensating for damage caused;
ensure that employees who do not have permission to use confidential information do not use this information;
ensure reliable storage of computers storing confidential information and documents on them;
ensure compliance with the requirements specified in the Laws of the Republic of Uzbekistan "On Bank Secrecy" and "On Personal Data";
take other measures to prevent disclosure of confidential information.
Chapter 4. Organization of Information Security System and Information Security Risk Management
An information security system consisting of legal, organizational, technical measures and a set of information protection systems (devices) is organized in the bank.
Software and technical means of information protection used in the information security system must be licensed and certified.
The information security system:
identifies, prevents and eliminates information security risks;
ensures information protection of all information systems and information resources;
applies proven solutions;
uses systems, devices and equipment that are highly reliable and easy to maintain;
records data on information in all processes and devices, detects violations of information security, changes in the work of programs, devices and users;
ensures simplicity of the work process and maximum automation of actions;
organizes protection barriers in several stages;
ensures continuity of information security;
prevents incidents and eliminates them when they occur and restores the performance of information systems;
ensures continuous improvement of information security.
controls access to information security systems;
ensures network security;
manages and controls access to information systems;
protects from malicious programs (computer viruses and others);
controls, restores, detects integrity, monitors protected data and programs;
ensures protection during processing, storage and transmission of data;
protects web resources, databases, data warehouses and other information resources from various information security threats;
checks, analyzes and evaluates the level of information protection ensured;
distributes, accounts and manages electronic digital signature keys and certificates;
prevents disclosure of information to third parties.
Banks create a risk management system for information security that may arise as a result of errors and external negative influences in automated systems.
The information security risk management system must include the following functions:
identification, collection and registration, monitoring, assessment, reduction and control of information security risks;
assigning tasks to employees for information security risk management;
reviewing risks.
A list of known risks and applied management tools and methods for ensuring information security in the bank must be compiled by the Information Security Service and approved by the bank management chairman.
The bank must ensure the relevance of the list of information security risks. Risks that are unlikely but cause great damage are also included in the list of information security risks.
Information security risk is constantly assessed and analyzed by the Information Security Service. The Information Security Service must provide relevant information to the bank management chairman on increasing bank risks.
The results of measures taken on information security risk management must be documented and reviewed by the bank management chairman at least once a year, and appropriate measures must be taken to eliminate risks.
Chapter 5. Elimination of Information Security Incidents
violation of information confidentiality;
violation of information integrity;
violation of technological process;
violation of the right to free use of information.
External experts or specialists from technical service organizations may be involved to eliminate incidents. When external experts or specialists from technical service organizations are involved to eliminate incidents, the bank must conclude a contract with them on non-disclosure of confidential information.
Information on detected information security incidents must be documented by the responsible officer for information security.
The responsible officer for information security, in case an incident is detected, must use data from the information security monitoring system and ensure the integrity of the electronic logs of information systems at the time the information security incident occurred.
Actions performed by the information security service at the time incidents occur are defined in the bank's internal documents.
Chapter 6. Managing Access to the Automated Banking System
Banks must develop procedures for access to the automated banking system and the working order of users of this system. In doing so, the rules for entering new users into the automated banking system and removing users whose access rights to this system have been revoked must be taken into account.
New users are entered into the automated banking system after permission is granted by the information security service and after implementation and necessary technical measures are taken for this.
The information security service controls the list of users authorized to access the automated banking system and their compliance with the established procedure for using this system in the bank.
The bank takes measures to prevent unauthorized access to the automated banking system.
When a bank employee is dismissed, this employee's system access rights must be revoked no later than 1 day. Employees whose position has changed must be granted working rights anew.
These hardware and software devices must be issued for personal use. In this case, each user must use the hardware and software device assigned to them to access the system.
In the remote banking service system, full information on user system access, information exchange, and their actions (IP and/or MAC address, when using a mobile phone — IMEI code) must be recorded in electronic logs.
Chapter 7. Database Management System
The operating system of workstations and other computing equipment, antivirus programs, and other software changes are launched upon completion of test work. All software changes made to the database must first be checked on a test server and implemented on the working server when a positive result is achieved.
Testing software changes to the automated banking system database, entering them into this database, documenting the changes made, and keeping records of them are carried out by the information security service together with the responsible officer for information.
Services not required for the operation of the server installed in the database must be stopped and information ports must be closed. The list of information ports used, indicating the purpose of use, is approved by the chairman of the bank's board.
The duties, powers, and responsibilities of the database administrator and employees ensuring information security in the database are defined by the bank's internal documents.
The database administrator's password must be at least 12 characters, using lower and upper case letters, numbers, and special characters (@,#, $, &, % etc.) as password characters.
Chapter 8. Network Security
Only authorized devices (computing equipment) must be allowed to connect to the corporate network.
An electronic log of information exchange must be maintained in the corporate network, and the user's name (user name), time, IP and/or device MAC address who entered the system must be recorded in the electronic log.
The diagram of the corporate network organized by banks (connection to the Central Bank network, the Internet global information network, telecommunications providers, branches, and other networks) is agreed upon with the Central Bank.
Full control and monitoring of corporate network security is carried out continuously by the information security service.
Inter-network information exchange of the bank is protected by organizing virtual private networks (VPN).
In the corporate network, a protected protocol must be used in the mutual information exchange between application servers and users.
Connection (entry) points to the bank's local area network from other networks or via cables entering from outside the building are protected by an inter-network screen.
Telecommunications cabinets must be locked and monitored via video surveillance systems.
It is prohibited to lay local area network cables to telecommunications cabinets and connection points of computing equipment, ATMs, and other devices in an unprotected manner.
All departments of the bank must be separated from each other by creating virtual local networks (VLAN) in the local area network.
Network security in banks is continuously monitored (supervised).
The responsible officer for network security monitoring aggregates information security events in the network and immediately notifies the information security service about various situations such as the appearance of a new device in the network, detection of a computer virus, attempts to access from the Internet global information network (hereinafter referred to as the internet network in the text), disconnection of an ATM from the network, server overheating, etc., and ensures that all analytical data is stored electronically.
In the bank, the status of network security software and technical means must be monitored, statistical data collected and analyzed, emerging problems identified at an early stage, and emergency situations prevented based on them.
Banks must use an intrusion detection system (hereinafter referred to as IDS in the text) and an intrusion prevention system (hereinafter referred to as IPS in the text), i.e., they must implement software or software-hardware tools designed to detect, prevent, and block unusual activities within the bank network and attacks in local area networks.
In banks, deviations from the operation of network programs in real time, as well as facts of unauthorized use of the computer system or network (unauthorized access or network attacks) must be detected. IDS/IPS systems are supplementary to inter-network screens and their work is organized based on the information security policy; IDS/IPS systems monitor suspicious operations and observe them. The bank ensures that the IDS/IPS system databases are kept up to date.
IPS/IDS systems are selected and implemented based on the scale of the network infrastructure and the bandwidth of server and switching equipment (routers, switches, communication lines) interfaces. If telecommunications equipment is morally obsolete and does not allow IPS/IDS systems to function, this equipment must be updated.
Inter-network screen configurations must be approved, authorized information exchange protocols must be based, and changes made to configurations are carried out in the manner established by the bank.
It must be ensured that the configurations of the main and backup inter-network screens are identical. In the bank, inter-network screen configurations must be kept up to date in an electronic archive.
Inter-network screen and proxy-server electronic logs are analyzed by the information security service, and when external attacks are detected, the Central Bank is notified on the same day.
Chapter 9. Use of Electronic Mail and Internet Network
The use of instant messaging systems (messenger) or programs, ensuring information protection when using the internet network and electronic mail systems by the bank, entering employees into the system, imposing restrictions on them, responsibility, controlling employee actions and system information security are defined in the bank's internal documents.
When confidential data is sent by the bank via the electronic mail system, the data must be encrypted and confirmed with an electronic digital signature. Transmission of data not related to the bank's activities via electronic mail is prohibited.
Information exchange between the bank's departments and branches is carried out through electronic document circulation programs or the bank's internal electronic mail system.
It is prohibited to exchange files through a public catalog organized on a File Transfer Protocol (FTP) server and to place bank secret data on the network for free reading.
Each electronic data prepared or received by the bank for sending via the internet and electronic mail must be checked using an antivirus program. Data received via electronic mail must be checked in a special area to ensure it does not cause harm (Sandbox system).
The bank defines the procedure for using its electronic mail system and internet network with its internal documents and ensures that data sent and received via electronic mail is controlled by the information security service. In this case, only authorized users must use the internet network and information security measures must be taken when using the internet network.
The internet network and bank telecommunications network must be physically connected through separate router and separate inter-network screen (firewall) devices.
It is prohibited to physically connect computers and servers connected to the automated banking system directly to the internet network.
Automated banking system database servers, application servers, all servers processing payment system data, other servers connected to the internet network and participating in the bank's operational activities must be located in demilitarized zones (DMZ) of a separate separated local network organized and secured in the bank. Demilitarized zones (DMZ) are protected from the bank's internal local networks and external telecommunications networks using inter-network screens. In demilitarized zones (DMZ), systems for detecting and preventing attacks, antivirus, and network protection systems specified in this Regulation must be implemented.
To enhance information protection, a network address translation protocol (NAT) that allows changing IP addresses of network transit packets in the network protocol (TCP/IP) may be used. In this case, electronic logs of all connections via the network must be maintained indicating the original IP addresses and archived electronically in the established manner.
The procedure for using the internet network must be controlled and the use of the internet network by bank employees must be determined according to their job descriptions.
Electronic logs reflecting the login of the employee using the internet network, usage time, resource name, and other information must be maintained. The information security service analyzes these electronic logs.
Ensuring information protection when using the internet network is carried out by using inter-network screens, proxy-servers, antivirus, intrusion detection and prevention (IDS/IPS), and other information security systems.
The bank must ensure that modems or mobile phones are not connected to the bank network and computers, as well as the use of external proxy-servers when working on the internet network, and the organization of the bank's internal local network wirelessly and the use of wireless information exchange systems on bank computers are not allowed.
For the convenience of customers and bank consumers, Wi-Fi zones may be organized in the bank building, in which case Wi-Fi technology must be physically separated from the bank's internal local network and information security must be ensured.
Chapter 10. Technical Means Management System
In this case, using this system, only programs relevant to their work activities are used by users on computers, and computer access protection (passwords) is ensured.
The list of programs allowed for use is determined by the bank. Actions such as using all programs not on the list and installing additional programs are prohibited.
Management of technical means is carried out by the administrator, while the information security service must control all actions of the administrator in the system.
The information security service must analyze the settings and electronic logs of the technical means management system at least once a month, and monitor compliance with the bank's information security policy requirements in the use of technical means.
Chapter 11. System for Protection Against Unauthorized Distribution of Data and Antivirus Protection
Banks must take measures to prevent unauthorized transmission of data from information systems, whereby banks implement a data loss prevention system (DLP) for protection against unauthorized distribution of data.
In protecting data, banks must:
detect unauthorized transmission of protected data through various network channels, unauthorized copying to unregistered external media, and unauthorized printing, inform bank management about this, and take measures to prevent such negative situations in the future;
control the storage of protected data on servers and computers.
Control procedures are established by the bank's internal documents, whereby protection against unauthorized distribution of data is carried out by a responsible employee.
Antivirus programs must be installed in information systems in banks to ensure the security of data.
The installation of antivirus programs in the bank and their operation are controlled by the information security service and the responsible employee.
Banks must define measures to be taken to prevent the spread of computer viruses over the network when a computer virus is detected.
When a computer virus is detected in the bank, information about the origin and type of the virus is reported to the Central Bank.
Banks must have licensed programs for antivirus protection.
Banks must implement a centralized management system for antivirus programs, antivirus program databases must be updated daily, and the antivirus program version must be ensured to be current (not morally obsolete).
Antivirus programs must be installed on servers, computers, ATMs, info kiosks, and all other computing means and devices on which antivirus programs can be installed.
Chapter 12. Use of Electronic Digital Signature and Encryption Keys
Electronic digital signatures and encryption keys are used in banks to confirm the authenticity of electronic documents and protect them from external influences.
In interacting with external systems, banks implement requirements for the use of electronic digital signatures and encryption keys based on bank risks, agreed upon mutually.
Electronic digital signatures of users of the automated banking system must be written to special devices (or mobile devices) and protected from unauthorized copying by any means.
All responsible employees who enter, confirm, and perform relevant operations with electronic payments (chief accountant, final control) must be provided with an electronic digital signature and must use this electronic digital signature in automated banking systems.
Banks ensure that payment data transmitted over the network is protected using electronic digital signatures and encryption keys.
The validity period of an electronic digital signature key certificate must not exceed twenty-four months from the date of registration of the electronic digital signature. In this case, the validity period of the electronic digital signature key certificate may be extended no more than two times.
Registration and accounting of users' electronic digital signature public keys must be carried out in the automated banking system.
(Paragraph 91 edited by the Resolution of the Board of the Central Bank of the Republic of Uzbekistan dated January 21, 2023 No. 1/13 (registration number 3224-2, 31.01.2023) — National Database of Legislation, 01.02.2023, 10/23/3224-2/0064)
surname, first name, patronymic of the individual who is the owner of the electronic digital signature private key;
employee's position, identity document details;
(Third indent of paragraph 92 edited by the Resolution of the Board of the Central Bank of the Republic of Uzbekistan dated December 31, 2020 No. 28/7 (registration number 3285, 26.01.2021) — National Database of Legislation, 26.01.2021, 10/21/3285/0073)
personal identification number of the individual;
public key of the electronic digital signature;
name and location address of the registration center that issued this certificate;
information on the purposes of using the electronic digital signature;
electronic address of the registry of electronic digital signature key certificates.
The processes of creating electronic digital signatures and encryption keys must be protected.
Only the owner must use the private key of the electronic digital signature.
The use of electronic digital signature keys in the bank system is controlled by the information security service.
Electronic payments that are not confirmed with an electronic digital signature and have not undergone the encryption process are prohibited from being accepted for processing.
When electronic digital signature keys issued by the Central Bank are compromised, lost, and in other similar situations, banks apply to the Central Bank indicating in detail the reasons for updating the electronic digital signature. The Central Bank updates the electronic digital signature within 1 day based on the application.
Chapter 13. Organization of Electronic Archive, Composition of Electronic Archive Documents
The electronic archive is organized as a structural unit of the bank archive.
The electronic archive must have its own electronic archive information system and its information resources must be formed.
The main tasks of the electronic archive must consist of the following:
collection, accounting, storage of electronic documents, as well as ensuring their use;
preparation of archive copies of information resources and their transfer to state custody within the time limits established by legislative documents;
(Third indent of paragraph 99 edited by the Order of the Minister of Justice of the Republic of Uzbekistan dated July 28, 2021 No. 16-mh (registration number 3313, 28.07.2021) — National Database of Legislation, 28.07.2021, 10/21/3313/0724)
LexUZ Commentary See: Resolution of the Cabinet of Ministers dated April 5, 2012 No. 101 "On Improving Archive Work in the Republic of Uzbekistan".
providing methodological assistance to the structural units of the bank on the formalization of electronic documents;
ensuring information security of the information resource of the electronic archive.
complete database of electronic data of the bank business day;
public keys of expired encryption and electronic digital signature keys;
bank business day programs and other sets of programs used in a particular bank;
electronic logs related to programs of electronic payment systems, software and hardware-network devices, and information security incidents;
documents (orders, decisions, and others) related to payments received and transmitted via electronic mail;
all incoming and outgoing electronic payment documents in encrypted and unencrypted form;
data related to credit and other banking operations of commercial banks;
data related to the bank's management system.
Banks may determine the list of data stored in the electronic archive based on their policy, existing information systems, and requirements placed on the bank, whereby this list must take into account the requirements of this Regulation.
The electronic archive must be provided with appropriate technical devices and programs to perform its established tasks.
The information resource of the electronic archive must be copied to external storage media and stored in a safe or iron cabinet.
Data in the main work process and data stored in its memory (server disks) are not considered the information resource of the electronic archive.
Banks must organize at least two storage locations for storing copies of the information resource of the electronic archive.
The electronic archive must form (archive) the information resource programmatically every day, and the process of writing to electronic information carriers must be recorded in an electronic journal. The electronic journal must record information about the data copied to the information resource (time, name, volume, and others) and the hash sum (control numbers) of this data to determine the integrity of the electronic archive. The responsible employee of the electronic archive must record in a special book that these works have been carried out.
An employee of the bank's internal audit service must check the work of the electronic archive at least once a month and enter the results of the check into a special book for recording archive work. If deficiencies are identified, an act must be formalized by the bank's internal audit service and measures to eliminate the deficiencies must be organized.
The integrity of the data of the information resource of the electronic archive is checked by the electronic archive once every six months, and the results of this check are kept in a special book. If it is found that the data of the electronic archive information resources is partially or completely damaged, the relevant data must be restored and an act must be drawn up about this.
The retention period of electronic documents (electronic resources) submitted to the electronic archive must not be less than the established periods for paper-based documents.
Electronic data with a permanent retention period stored by the bank must be submitted to state archives in one copy after being stored in the departmental archive for fifteen years, in the established manner.
When the activities of the bank's branches are terminated, the information resource of the electronic archive is submitted to the territorial branches of the bank, and for banks without territorial branches, to the Head Bank in the established manner. When the bank's activities are terminated and it is merged with another bank, the electronic archive data is submitted to the electronic archive of the merging bank in the established manner.
When the bank's activities are terminated, the information resources of the electronic archive are submitted to the State Archive.
The employee(s) of the electronic archive are personally responsible for the completeness, correct formation, and reliability of the information resources.
Chapter 14. Ensuring Continuity and Recovery of Automated Banking System Workflow
Banks must ensure business continuity and have taken appropriate measures in advance in case of interruptions, technical failures, emergency situations, and situations causing major damage in the automated banking system workflow.
Requirements for ensuring the continuity of automated banking system workflows in the bank must be developed, including a plan of measures for actions to be taken during interruptions (stoppages) (for all cases) must be approved. The plan must outline the actions of participating employees and these employees must be appropriately prepared.
Banks must develop a procedure for recovering subsystems of the automated banking system, back up data and relevant programs, carry out recovery test work at least twice a year, and document all work performed. The recovery measures plan must be drawn up taking into account all existing information systems, operating systems, and technical devices.
The bank must form relevant electronic data for the purpose of quickly restoring information systems. In this case, recoverable data of all information systems in the bank related to the payment system must be kept up-to-date relative to the end of the previous day.
The list of recoverable electronic data, the time of their copying (creation), and others are determined by the bank.
Banks must ensure the protection of recoverable electronic data.
An employee of the bank's internal audit service must check the status of the data recovery system at least once a month and record the results of the check in a special book. If deficiencies are identified, an act must be formalized about this.
In cases of failure of technical means of automated banking systems, banks must have a backup recovery plan, programs, and equipment to ensure uninterrupted operation of the system.
Servers and computers in the automated banking system must have programs that have undergone expert approval or are licensed. Data on the hard disks of servers in the payment center is protected through Redundant Array of Independent Disks (RAID) technologies.
The Head Bank must organize a backup center (ABS servers) at a distance of no less than 5 km to protect automated banking systems from emergency (fire, earthquake, flood, and others) situations, this center may be organized in the bank's branch(es) or in other commercial banks.
The security of the backup center room must be ensured by the bank and access of third parties to the bank's backup servers without permission must be restricted. The backup center room is monitored by the bank through a video surveillance system. Organizing a backup center in another bank is carried out on the basis of an agreement concluded with this bank.
Chapter 15. Security Requirements for Server Rooms
If servers are located in branches, requirements for the security of the rooms where they are located must be determined separately by the bank.
The bank must implement a guaranteed power supply system for the server room, whereby there must be two inputs of power supply from various electrical substations and one automatically starting diesel power station. Automatic reconnection of all three sources of electricity to the main (backup) feeder of the power supply must be ensured.
The parameters of the power supply lines, automatic diesel power station, and its backup automatic input must be determined based on the total power consumed by the equipment and server room systems and must provide a power reserve of at least 10 percent.
The bank must be provided with a diesel power station with a fuel reserve lasting at least one day for uninterrupted operation, whereby the diesel power station must start automatically when there is no electricity in the bank.
Banks must equip the server room with an uninterruptible power supply (UPS).
In this case, the power of the power supply source (UPS) must be implemented taking into account all equipment being supplied and a reserve for future needs. The autonomous operating time through the power supply source (UPS) takes into account needs, as well as the time required for switching to and from backup lines and the automatic diesel power station.
In cases where persons not on the list of employees permitted to enter the server room need to enter the server room, their entry must be formalized with a justified request. This request must be reviewed and signed by the head of the information technology department, as well as agreed with the head of the information security service. Access to the server room is carried out under the supervision of the server administrator.
Employees must enter the server room through an access control system (biometric or other methods).
When employees of organizations servicing the automated banking system are admitted to the server room, the date and time of entry and exit to the server rooms, the name of the work performed, the surname, first name, position of the performer, the name of the organization must be entered in the registration log, and the signature of this employee must be affixed.
The server room must meet the following equipment requirements:
Video surveillance devices must be easy to install and dismantle and the video system must be scalable.
Management and use of video archive data is carried out by the bank's security department.
The server room must be equipped with an automatic gas fire extinguishing device not connected to the building's fire extinguishing system.
The bank must ensure the placement of the gas fire extinguishing system directly in the bank server room (in a specially equipped cabinet) or in a specially equipped room for this.
Activation of the gas fire extinguishing system must be carried out from smoke detectors reporting a fire, as well as from manually activated detectors installed outside the room, on the wall at a height of 1.5 m from the floor level.
The gas fire extinguishing system must have a panel inside and outside the room notifying employees that the automatic gas fire extinguishing device has been activated, and a sound signaling device installed outside the room.
The gas fire extinguishing system must ensure that a command is given to close the protective valves of the ventilation system and to cut off the equipment supply.
The gas and smoke exhaust system must ensure the removal of gas and smoke from the server room after the fire extinguishing system is activated. This system is performed separately from the building's ventilation system with an air duct brought out to the building roof. The system must have the ability to discharge a gas-air mixture in a volume exceeding the air volume in the server room by three times.
Main requirements for the cooling and ventilation system:
a) the following climate conditions must be observed in the server room:
b) the server room air cooling system is performed using 100% reservation (at least two independent air conditioners, each capable of independently ensuring the room's air regime);
c) the cooling system must provide the ability to carry out remote monitoring.
Chapter 16. Requirements for Ensuring Information Security in Information Exchange of the Bank with External Information Systems
The bank's information exchange with the information system of another legal entity (hereinafter referred to in the text as an external information system) is carried out on the basis of a contract.
The following information security requirements must be established for information exchange between the bank and the external information system:
Chapter 17. Control over Information Security Requirements
To determine that information security is ensured, the bank may use the services of external organizations and carry out internal audits.
External organization services may be carried out in the form of an audit or expertise. The bank must develop an internal document on providing confidential information, including bank secret information, to organizations conducting audit or expertise work, whereby such information must be provided on the basis of an appropriate contract.
Employees of the Head Bank's Information Security Service must carry out continuous monitoring over the compliance with the requirements of this Regulation in the bank and its branches.
Chapter 18. Final Provisions
Persons guilty of violating the requirements of this Regulation shall be liable in accordance with the procedure established by legislative documents. (Paragraph 144 as amended by Order No. 16-mh of the Minister of Justice of the Republic of Uzbekistan dated July 28, 2021 (registration number 3313, 28.07.2021) — National Database of Legislative Information, 28.07.2021, No. 10/21/3313/0724)
This Regulation is coordinated with the Ministry of Information Technologies and Communications Development of the Republic of Uzbekistan, the Ministry of Innovative Development of the Republic of Uzbekistan and the Agency "UzArchive" of the Republic of Uzbekistan.
Minister of Information Technologies and Communications Development Sh. SADIKOV
January 20, 2020
Minister of Innovative Development I. ABDURAKHMONOV
January 20, 2020
Director of the Agency "UzArchive" U. YUSUPOV
January 20, 2020
To Resolution No. 2/4 dated January 25, 2020 of the Board of the Central Bank of the Republic of Uzbekistan
APPENDIX 2
List of Departmental Normative Legal Documents Deemed Invalid
Regulation on Antivirus Protection in Automated Banking Systems of the Republic of Uzbekistan approved by Resolution No. 461 of the Board of the Central Bank of the Republic of Uzbekistan dated February 5, 2000 (registration number 910, March 10, 2000) (Bulletin of Normative Documents of Ministries, State Committees and Departments of the Republic of Uzbekistan, 2000, No. 5).
Resolution No. 12/4 dated March 31, 2018 of the Board of the Central Bank of the Republic of Uzbekistan "On Amendments to the Regulation on Antivirus Protection in Automated Banking Systems of the Republic of Uzbekistan" (registration number 910-1, April 9, 2018) (National Database of Legislative Information, 10.04.2018, No. 10/18/910-1/1032).
Resolution No. 14/13 dated June 23, 2001 of the Board of the Central Bank of the Republic of Uzbekistan "On Approval of the Instruction on Organizing the Protection of Electronic Information in Banks in the Territory of the Republic of Uzbekistan" (registration number 1047, July 9, 2001) (Bulletin of Normative Documents of Ministries, State Committees and Departments of the Republic of Uzbekistan, 2001, No. 13).
Resolution No. 21/10 dated October 2, 2004 of the Board of the Central Bank of the Republic of Uzbekistan "On Amendments to the Instruction on Organizing the Protection of Electronic Information in Banks in the Territory of the Republic of Uzbekistan" (registration number 1047-1, October 22, 2004) (Collection of Legislative Documents of the Republic of Uzbekistan, 2004, No. 42, Article 450).
Resolution No. 1/9 dated January 17, 2006 of the Board of the Central Bank of the Republic of Uzbekistan "On Amendments to the Instruction on Organizing the Protection of Electronic Information in Banks in the Territory of the Republic of Uzbekistan" (registration number 1047-2, February 8, 2006) (Collection of Legislative Documents of the Republic of Uzbekistan, 2006, No. 6-7, Article 45).
Resolution No. 10/10 dated April 20, 2006 of the Board of the Central Bank of the Republic of Uzbekistan "On Amendments to the Instruction on Organizing the Protection of Electronic Information in Banks in the Territory of the Republic of Uzbekistan" (registration number 1047-3, May 6, 2006) (Collection of Legislative Documents of the Republic of Uzbekistan, 2006, No. 19, Article 165).
Resolution No. 18/18 dated August 10, 2019 of the Board of the Central Bank of the Republic of Uzbekistan "On Amendments to Paragraph 6 of the Instruction on Organizing the Protection of Electronic Information in Banks in the Territory of the Republic of Uzbekistan" (registration number 1047-4, August 26, 2019) (National Database of Legislative Information, 26.08.2019, No. 10/19/1047-4/3638).
Resolution No. 1/8 dated January 17, 2006 of the Board of the Central Bank of the Republic of Uzbekistan "On Approval of the Regulation on Information Security in Automated Banking Systems of Commercial Banks of the Republic of Uzbekistan" (registration number 1552, March 13, 2006) (Collection of Legislative Documents of the Republic of Uzbekistan, 2006, No. 11, Article 89).
Resolution No. 10/7 dated April 20, 2006 of the Board of the Central Bank of the Republic of Uzbekistan "On Amendments and Additions to the Resolution on Approval of the Regulation on Information Security in Electronic Systems of Commercial Banks of the Republic of Uzbekistan" (registration number 1552-1, August 3, 2006) (Collection of Legislative Documents of the Republic of Uzbekistan, 2006, No. 31-32, Article 324).
Resolution No. 37/3 dated November 13, 2010 of the Board of the Central Bank of the Republic of Uzbekistan "On Amendments and Additions to the Regulation on Information Security in Automated Banking Systems of Commercial Banks of the Republic of Uzbekistan" (registration number 1552-2, December 9, 2010) (Collection of Legislative Documents of the Republic of Uzbekistan, 2010, No. 49, Article 463).
Resolution No. 1/10 dated January 17, 2006 of the Board of the Central Bank of the Republic of Uzbekistan "On Approval of the Regulation on the Procedure for Using Electronic Digital Signatures and Encryption Keys in the Banking System of the Republic of Uzbekistan" (registration number 1553, March 13, 2006) (Collection of Legislative Documents of the Republic of Uzbekistan, 2006, No. 11, Article 90).
Resolution No. 31/1 dated September 6, 2014 of the Board of the Central Bank of the Republic of Uzbekistan "On Amendments to the Regulation on the Procedure for Using Electronic Digital Signatures and Encryption Keys in the Banking System of the Republic of Uzbekistan" (registration number 1553-1, September 23, 2014) (Collection of Legislative Documents of the Republic of Uzbekistan, 2014, No. 39, Article 493).
Resolution No. 11/3 dated April 14, 2007 of the Board of the Central Bank of the Republic of Uzbekistan "On Approval of the Instruction on the Procedure for Maintaining Electronic Archive Works in Banks of the Republic of Uzbekistan" (registration number 1685, June 2, 2007) (Collection of Legislative Documents of the Republic of Uzbekistan, 2007, No. 23, Article 243).
Resolution No. 37/2 dated November 13, 2010 of the Board of the Central Bank of the Republic of Uzbekistan "On Amendments to the Instruction on the Procedure for Maintaining Electronic Archive Works in Banks of the Republic of Uzbekistan" (registration number 1685-1, December 9, 2010) (Collection of Legislative Documents of the Republic of Uzbekistan, 2010, No. 49, Article 465).
(National Database of Legislative Information, 10.03.2020, No. 10/20/3224/0312; 26.01.2021, No. 10/21/3285/0073, National Database of Legislative Information, 17.06.2021, No. 10/21/3224-1/0567; National Database of Legislative Information, 28.07.2021, No. 10/21/3313/0724; 01.02.2023, No. 10/23/3224-2/0064 )
More like this from CBU
CBU published 1 document in the last 30 days. We email you each new one the day it's published.