2025-11-20 | 19/1Added
The Central Bank of Uzbekistan approved a regulation establishing minimum requirements for information and cybersecurity for commercial banks, including microfinance banks. The regulation mandates the establishment of a dedicated cybersecurity service, defines key terminology, and imposes obligations regarding the protection of confidential data, management of cybersecurity risks, and the use of licensed software. It explicitly prohibits outsourcing the management and control of information-communication technology infrastructure and cybersecurity systems to third-party service providers.
Get CBU alerts — same-day email on every new publication.
Resolution of the Board of the Central Bank of the Republic of Uzbekistan, registered on August 18, 2025, Registration No. 3669
Date of Entry into Force
November 20, 2025
All
Russian
Uzbek
O’zb
Uzb|Russian
[OKON:
1.07.00.00.00 Legislation on Finance and Credit. Banking Activity / 07.19.00.00 Banking System / 07.19.02.00 Commercial Banks. Private Banks. Foreign Banks;
2.12.00.00.00 Information and Informatization / 12.08.00.00 Information Security, Protection of Rights of Subjects in the Field of Information and Informatization (also see 16.04.03.00));
3.16.00.00.00 Security and Law Enforcement / 16.04.00.00 Public Security / 16.04.03.00 Information Security (also see 12.08.00.00)]
[TSZ:
Resolution of the Board of the Central Bank of the Republic of Uzbekistan
On Approval of the Regulation on Minimum Requirements for Information and Cybersecurity of Commercial Banks of the Republic of Uzbekistan
[Registered by the Ministry of Justice of the Republic of Uzbekistan on August 18, 2025, Registration No. 3669]
In accordance with the Law of the Republic of Uzbekistan "On the Central Bank of the Republic of Uzbekistan", the Board of the Central Bank of the Republic of Uzbekistan resolves:
Approve the Regulation on Minimum Requirements for Information and Cybersecurity of Commercial Banks of the Republic of Uzbekistan according to Appendix 1.
Recognize as having lost their force certain departmental normative legal documents according to Appendix 2.
This resolution is coordinated with the State Security Service, the Ministry of Digital Technologies, and the Ministry of Justice.
This resolution enters into force three months after the date of its official publication.
Chairman T. ISHMETOV
Tashkent,
August 1, 2025,
No. 19/1
Agreed:
Chairman of the State Security Service B. KURBANOV
July 18, 2025
Minister of Digital Technologies Sh. SHERMATOV
July 11, 2025
Minister of Justice A. TASHKULOV
July 5, 2025
Appendix 1
to the Resolution of the Board of the Central Bank of the Republic of Uzbekistan dated August 1, 2025, No. 19/1
REGULATION
on Minimum Requirements for Information and Cybersecurity of Commercial Banks of the Republic of Uzbekistan
This Regulation establishes the minimum requirements for information and cybersecurity of commercial banks of the Republic of Uzbekistan, including microfinance banks (hereinafter referred to as "the Bank" in the text).
Chapter 1. General Provisions
[OKON:
1.07.00.00.00 Legislation on Finance and Credit. Banking Activity / 07.19.00.00 Banking System / 07.19.02.00 Commercial Banks. Private Banks. Foreign Banks;
2.12.00.00.00 Information and Informatization / 12.08.00.00 Information Security, Protection of Rights of Subjects in the Field of Information and Informatization (also see 16.04.03.00));
3.16.00.00.00 Security and Law Enforcement / 16.04.00.00 Public Security / 16.04.03.00 Information Security (also see 12.08.00.00)]
automated banking system — an information system designed to collect, store, search, process, and use information in the field of banking activity;
antivirus program — a program against computer viruses, designed to detect viruses and may offer to eliminate them or be a program that eliminates them;
antivirus protection — a set of measures aimed at preventing the impact of computer viruses using antivirus programs, finding viruses, and neutralizing them;
authentication — the procedure for confirming the authenticity of a user, program, device, or data;
information assets — information important for banking activity (customer data, operational data, software, databases, event logs, etc.) and all resources serving their storage, transmission, processing, and protection (information systems and resources, servers, data warehouses, communication channels, and software applications);
information resource — information in electronic form, database, or data base that is part of an information system, including audio, video, graphic, and textual information placed or published in open form in information systems;
information system — a set of information resources, information technologies, and communication means organized in an organizational manner that allows collecting, storing, searching, processing, and using information;
[OKON:
1.12.00.00.00 Information and Informatization / 12.08.00.00 Information Security, Protection of Rights of Subjects in the Field of Information and Informatization (also see 16.04.03.00));
2.16.00.00.00 Security and Law Enforcement / 16.04.00.00 Public Security / 16.04.03.00 Information Security (also see 12.08.00.00)]
information security — the state of protection of the interests of the individual, society, and the state in the field of information;
information security adverse event — a single event or a series of adverse or unexpected events in information security, which may lead to the disclosure of information and the probability of threats to information security;
attack — destruction, disclosure, modification, blocking, capture, unauthorized use of information assets, or attempt to obtain the right to unauthorized use or use of information assets without permission;
computer virus — a program (set of executable codes) with destructive properties, the ability to replicate itself (possibly not fully matching the original copy), and the ability to introduce itself into computer systems, networks, and various resources without the user's knowledge;
monitoring — observation of the state of automated banking systems and information systems;
server room — a room where bank servers, telecommunications equipment, uninterruptible power supplies, and other computing equipment are located;
firewall — a program and/or software tool that controls incoming and/or outgoing information to/from the system;
hash sum — a checksum calculated using a cryptographic algorithm to check file integrity;
[OKON:
1.12.00.00.00 Information and Informatization / 12.03.00.00 Information Resources. Use of Information Resources / 12.03.06.00 Personal Data and Their Protection]
personal data — information recorded electronically, on paper, and/or on other physical objects that belongs to a specific natural person or allows identifying that person;
[OKON:
1.12.00.00.00 Information and Informatization / 12.03.00.00 Information Resources. Use of Information Resources / 12.03.03.00 Archival Fund. Archives]
electronic archive — a structural unit of the bank that collects, accounts for, stores, and uses the bank's electronic documents with archival status;
[OKON:
1.12.00.00.00 Information and Informatization / 12.03.00.00 Information Resources. Use of Information Resources / 12.03.02.00 Documentation of Information. Electronic Document Circulation / 12.03.02.01 Electronic Document Circulation]
electronic document — information recorded in electronic form, confirmed by an electronic digital signature, and having other requisites of the electronic document that allow identifying it;
endpoints — physical devices connected to a network system. Mobile devices, computers, virtual machines, embedded devices, or servers can be endpoints;
cybersecurity risk — the probability of financial loss, disruption of operational activities, or damage to the organization's reputation resulting from threats directed against information systems, information-communication technology infrastructure, or digital services;
DLP (Data Loss Prevention) — a system for protecting data from unauthorized distribution;
PAM (Privileged Access Management) — a system for managing, controlling, and protecting the access of users with privileged access rights to information systems;
IDS/IPS (Intrusion Detection/Prevention System) — intrusion detection and prevention systems;
Wi-Fi (Wireless Fidelity) — wireless data transmission technology;
VPN (Virtual Private Network) — virtual private network.
Chapter 2. Service for Ensuring Information Security and Cybersecurity
[OKON:
1.07.00.00.00 Legislation on Finance and Credit. Banking Activity / 07.19.00.00 Banking System / 07.19.02.00 Commercial Banks. Private Banks. Foreign Banks;
2.12.00.00.00 Information and Informatization / 12.08.00.00 Information Security, Protection of Rights of Subjects in the Field of Information and Informatization (also see 16.04.03.00));
3.16.00.00.00 Security and Law Enforcement / 16.04.00.00 Public Security / 16.04.03.00 Information Security (also see 12.08.00.00)]
[OKON:
1.07.00.00.00 Legislation on Finance and Credit. Banking Activity / 07.19.00.00 Banking System / 07.19.02.00 Commercial Banks. Private Banks. Foreign Banks;
2.12.00.00.00 Information and Informatization / 12.08.00.00 Information Security, Protection of Rights of Subjects in the Field of Information and Informatization (also see 16.04.03.00));
3.16.00.00.00 Security and Law Enforcement / 16.04.00.00 Public Security / 16.04.03.00 Information Security (also see 12.08.00.00)]
organizes the information security and cybersecurity management system, organizes and monitors the compliance of information security and cybersecurity requirements by bank subdivisions and employees;
organizes control over the storage of information;
provides methodological and practical assistance to bank subdivisions and employees on information protection issues;
participates in the design, testing, acceptance, and implementation of information protection systems for information assets, taking measures to prevent the leakage of bank secrets and other confidential information during these processes;
selects, implements, and applies methods, tools, and mechanisms for managing, ensuring, and controlling the information security and cybersecurity of the bank within its authority;
takes measures to protect information in the system if attempts to use information assets without permission, interference with them in another form, or violation of system operation rules are detected;
detects, analyzes, and takes measures to eliminate cyber threats and attacks against information assets;
collects, processes, analyzes, and stores information about information security adverse events (hereinafter referred to as "adverse events" in the text);
conducts investigations into adverse events;
analyzes the status and effectiveness of information protection measures;
monitors and ensures the correct operation of software and hardware devices for ensuring information security and cybersecurity;
carries out monitoring related to ensuring information security and cybersecurity;
prepares proposals on issues of ensuring information security and cybersecurity;
establishes requirements for taking measures to ensure information security and cybersecurity in information assets;
develops plans for the bank regarding ensuring and controlling information security and cybersecurity in information assets;
controls the storage of confidential information, including bank secrets and personal data;
participates in the process of restoring systems in case of downtime, emergency situations, cybersecurity incidents, and adverse events, and monitors the restoration of information systems to full working condition;
performs other functions in accordance with bank documents.
The duties, powers, and obligations of the Service may be defined by the bank's internal documents, taking into account the requirements of this Regulation. The Service must be provided with the technical resources necessary to perform its duties and obligations.
The number of Service employees is determined based on the tasks assigned to them, the number of information resources and information systems, and the level of automation of information security and cybersecurity assurance systems.
The Service and the information technology subdivision must be subordinate to different members of the bank's management body, with the Service reporting directly to the Chairman of the Bank's Management.
It is prohibited to involve Service employees in work unrelated to their main activities.
[OKON:
1.07.00.00.00 Legislation on Finance and Credit. Banking Activity / 07.19.00.00 Banking System / 07.19.02.00 Commercial Banks. Private Banks. Foreign Banks;
2.12.00.00.00 Information and Informatization / 12.08.00.00 Information Security, Protection of Rights of Subjects in the Field of Information and Informatization (also see 16.04.03.00));
3.16.00.00.00 Security and Law Enforcement / 16.04.00.00 Public Security / 16.04.03.00 Information Security (also see 12.08.00.00)]
Banks must systematically ensure the professional development of Service employees in specialized training courses in the field of information security and cybersecurity at least twice a year. In this regard, the training and professional development of all responsible employees of the Service in their respective fields must be taken into account.
Ensuring information security and cybersecurity is regulated by legislative acts and the bank's internal documents regarding information security and cybersecurity.
The bank must develop and adopt an internal policy on information security.
The information security policy establishes requirements for ensuring information security and cybersecurity in all existing information systems and information resources of the bank.
[OKON:
1.07.00.00.00 Legislation on Finance and Credit. Banking Activity / 07.19.00.00 Banking System / 07.19.02.00 Commercial Banks. Private Banks. Foreign Banks;
2.12.00.00.00 Information and Informatization / 12.08.00.00 Information Security, Protection of Rights of Subjects in the Field of Information and Informatization (also see 16.04.03.00));
3.16.00.00.00 Security and Law Enforcement / 16.04.00.00 Public Security / 16.04.03.00 Information Security (also see 12.08.00.00)]
All measures specified in this Regulation related to ensuring information security and cybersecurity in information systems and information resources must be confirmed in written or electronic form.
If the bank has a branch network, each branch must have a set of the bank's approved documents on ensuring information security and cybersecurity. If the characteristics of certain branches need to be taken into account, the bank ensures the development of its internal documents taking these characteristics into account.
Introducing software changes or implementing new information resources and systems to the bank's information assets must be carried out in coordination with the Service.
[OKON:
1.07.00.00.00 Legislation on Finance and Credit. Banking Activity / 07.19.00.00 Banking System / 07.19.02.00 Commercial Banks. Private Banks. Foreign Banks;
2.12.00.00.00 Information and Informatization / 12.08.00.00 Information Security, Protection of Rights of Subjects in the Field of Information and Informatization (also see 16.04.03.00));
3.16.00.00.00 Security and Law Enforcement / 16.04.00.00 Public Security / 16.04.03.00 Information Security (also see 12.08.00.00)]
Chapter 3. Protection Against Disclosure of Confidential Information
[OKON:
1.12.00.00.00 Information and Informatization / 12.08.00.00 Information Security, Protection of Rights of Subjects in the Field of Information and Informatization (also see 16.04.03.00));
2.16.00.00.00 Security and Law Enforcement / 16.04.00.00 Public Security / 16.04.03.00 Information Security (also see 12.08.00.00)]
establish and maintain the relevance of the list of confidential information belonging to the bank or its subdivisions, including bank secrets and personal data;
sign an obligation to keep confidential information with each employee for the purpose of compensating for damages;
ensure that employees who do not have permission to use confidential information do not use such information;
ensure the reliable storage of computers containing confidential information and documents on them;
[OKON:
1.12.00.00.00 Information and Informatization / 12.03.00.00 Information Resources. Use of Information Resources / 12.03.05.00 Information with Limited Access / 12.03.05.03 Bank Secret (also see 07.21.16.00);
2.12.00.00.00 Information and Informatization / 12.03.00.00 Information Resources. Use of Information Resources / 12.03.06.00 Personal Data and Their Protection]
ensure compliance with the requirements specified in the Laws of the Republic of Uzbekistan "On Bank Secret" and "On Personal Data";
take measures to prevent unauthorized use of confidential information.
Chapter 4. Organization of the Information Security and Cybersecurity Assurance System and Management of Information Security and Cybersecurity Risks
An information security and cybersecurity assurance system consisting of legal, organizational, technical measures, and sets of information protection systems (devices) is established in the bank.
Software and technical tools used in ensuring information security and cybersecurity must be licensed and certified in accordance with information security and cybersecurity requirements. In this regard, all work on technical support of software must be ensured by the owner or supplier of the software.
[OKON:
1.07.00.00.00 Legislation on Finance and Credit. Banking Activity / 07.19.00.00 Banking System / 07.19.02.00 Commercial Banks. Private Banks. Foreign Banks;
2.12.00.00.00 Information and Informatization / 12.08.00.00 Information Security, Protection of Rights of Subjects in the Field of Information and Informatization (also see 16.04.03.00));
3.16.00.00.00 Security and Law Enforcement / 16.04.00.00 Public Security / 16.04.03.00 Information Security (also see 12.08.00.00)]
detection, prevention, and elimination of information security and cybersecurity risks;
protection of all information systems and information resources;
application of advanced solutions based on international standards;
application of systems, devices, and equipment with high reliability and ease of service;
recording information on all processes and devices, detecting violations of information security, and changes in the work of programs, devices, and users;
ensuring the simplicity of the workflow and maximizing the automation of actions;
organization of protection barriers in several stages;
ensuring the continuity of information security and cybersecurity;
prevention of adverse events, elimination of arising events, and restoration of the operational activity of information systems;
continuous improvement of information security and cybersecurity.
[OKON:
1.12.00.00.00 Information and Informatization / 12.08.00.00 Information Security, Protection of Rights of Subjects in the Field of Information and Informatization (also see 16.04.03.00));
2.16.00.00.00 Security and Law Enforcement / 16.04.00.00 Public Security / 16.04.03.00 Information Security (also see 12.08.00.00)]
control of access to information security and cybersecurity assurance systems;
ensuring network security;
management and control of access to information systems;
protection from malicious software (computer viruses, etc.);
control, restoration, integrity verification, and monitoring of protected data and programs;
ensuring protection during data processing, storage, and transmission;
protection of web resources, databases, data storage warehouses, and other information resources from various information security hazards;
checking, analyzing, and assessing the level of information protection;
distribution, accounting, and management of electronic digital signature keys and certificates;
prevention of disclosure of data to third parties;
control and electronic recording of all changes related to information security and cybersecurity settings in the information system and the integrity of the information system.
[OKOS:
1.12.00.00.00 Information and informatization / 12.08.00.00 Information security, protection of the rights of subjects of information and informatization (see also 16.04.03.00));
2.16.00.00.00 Security and law enforcement / 16.04.00.00 Public security / 16.04.03.00 Information security (see also 12.08.00.00)]
identification, collection, registration, assessment, mitigation measures, monitoring, and control of information security and cybersecurity risks;
planning and management of activities to eliminate information security and cybersecurity risks;
formation of reports on the management of information security and cybersecurity risks;
review of information security and cybersecurity risks.
[OKOS:
1.12.00.00.00 Information and informatization / 12.08.00.00 Information security, protection of the rights of subjects of information and informatization (see also 16.04.03.00));
2.16.00.00.00 Security and law enforcement / 16.04.00.00 Public security / 16.04.03.00 Information security (see also 12.08.00.00)]
The Service must compile a list of known risks in information security and cybersecurity at the bank, as well as the management tools and methods applied, which must be approved by the Chairman of the Bank's Management.
The bank must ensure the relevance of the list of information security and cybersecurity risks.
The Service must provide relevant information to the Chairman of the Bank's Management regarding the increase in risks.
[OKOS:
1.07.00.00.00 Legislation on Finance and Credit. Bank Activity / 07.19.00.00 Banking System / 07.19.01.00 Central Bank, its structural divisions and institutions;
2.07.00.00.00 Legislation on Finance and Credit. Bank Activity / 07.19.00.00 Banking System / 07.19.02.00 Commercial Banks. Private Banks. Foreign Banks;
3.12.00.00.00 Information and informatization / 12.08.00.00 Information security, protection of the rights of subjects of information and informatization (see also 16.04.03.00));
4.16.00.00.00 Security and law enforcement / 16.04.00.00 Public security / 16.04.03.00 Information security (see also 12.08.00.00)]
Timely and correct (accurate) information must be entered into the rating information system by banks.
Chapter 5. Prevention and Elimination of Adverse Events and Cybersecurity Incidents
[OKOS:
1.07.00.00.00 Legislation on Finance and Credit. Bank Activity / 07.19.00.00 Banking System / 07.19.02.00 Commercial Banks. Private Banks. Foreign Banks;
2.12.00.00.00 Information and informatization / 12.08.00.00 Information security, protection of the rights of subjects of information and informatization (see also 16.04.03.00));
3.16.00.00.00 Security and law enforcement / 16.04.00.00 Public security / 16.04.03.00 Information security (see also 12.08.00.00)]
violation of information confidentiality;
violation of information integrity;
disruption of technological processes;
violation of the right to free use of information.
Monitoring systems are introduced in banks to obtain information about adverse events. In this regard, a working group that continuously operates to monitor the functioning of these systems and eliminate adverse events is established.
External experts or specialists of technical service organizations may be involved to eliminate adverse events. When external experts or specialists of technical service organizations are involved to eliminate adverse events, the bank must conclude a contract with them regarding the non-disclosure of confidential information.
[OKOS:
1.12.00.00.00 Information and informatization / 12.08.00.00 Information security, protection of the rights of subjects of information and informatization (see also 16.04.03.00));
2.16.00.00.00 Security and law enforcement / 16.04.00.00 Public security / 16.04.03.00 Information security (see also 12.08.00.00)]
In the event of an identified adverse event, the Service must use information from the information security monitoring system and store electronic journals of information systems at the time the adverse event occurred and backup copies (backup, snapshot, etc.) of the system servers where the adverse event occurred, ensuring their integrity.
[OKOS:
1.07.00.00.00 Legislation on Finance and Credit. Bank Activity / 07.19.00.00 Banking System / 07.19.02.00 Commercial Banks. Private Banks. Foreign Banks;
2.12.00.00.00 Information and informatization / 12.08.00.00 Information security, protection of the rights of subjects of information and informatization (see also 16.04.03.00));
3.16.00.00.00 Security and law enforcement / 16.04.00.00 Public security / 16.04.03.00 Information security (see also 12.08.00.00)]
prohibition of unauthorized use of technical means;
protection against unauthorized removal of technical means;
storage of monitoring and electronic records of adverse events in an electronic archive and protection against unauthorized modification or deletion;
testing of information systems and resources for compliance with cybersecurity requirements in the manner established by legislation.
Actions to be taken by the Service in the event of adverse events are specified in the bank's internal documents.
Chapter 6. Monitoring of Information Systems and Resources
[OKOS:
1.07.00.00.00 Legislation on Finance and Credit. Bank Activity / 07.19.00.00 Banking System / 07.19.02.00 Commercial Banks. Private Banks. Foreign Banks;
2.12.00.00.00 Information and informatization / 12.08.00.00 Information security, protection of the rights of subjects of information and informatization (see also 16.04.03.00));
3.16.00.00.00 Security and law enforcement / 16.04.00.00 Public security / 16.04.03.00 Information security (see also 12.08.00.00)]
accounting of software and devices used for processing, storing, and transmitting information in the information infrastructure;
implementation of SIEM (Security Information and Event Management) or other systems that enable analysis of information security and cybersecurity incidents, monitoring of the state of information security and cybersecurity, and alerting;
implementation of SOAR (Security Orchestration, Automation and Response) systems that enable automation of processes for collecting, analyzing, and responding to information about information security and cybersecurity incidents;
analysis of information from the information security and cybersecurity monitoring system and taking measures to eliminate and (or) prevent identified situations (unauthorized access to the information network and attempts to access, system downtime, lack of information resources, network outages, limitations in ensuring information security and cybersecurity, and other incidents);
organization of monitoring activities for the state of information security and cybersecurity in a 24/7 mode;
[OKOS:
1.07.00.00.00 Legislation on Finance and Credit. Bank Activity / 07.19.00.00 Banking System / 07.19.01.00 Central Bank, its structural divisions and institutions]
ensuring the connection of the information security and cybersecurity monitoring system to the monitoring system of the Central Bank's "CERT-CBU" cybersecurity center.
Chapter 7. Management of Access to Information Systems and Resources
Banks must develop procedures for accessing information systems and resources and the work order of users in these systems. In this regard, rules for granting access to information systems and resources for new users and revoking access for users whose access rights have been revoked must be taken into account.
New users are entered into information systems and resources after the Service takes necessary technical measures and grants permission.
The Service monitors the list of users granted access to information systems and resources and their compliance with the established order of use in the bank.
[OKOS:
1.07.00.00.00 Legislation on Finance and Credit. Bank Activity / 07.19.00.00 Banking System / 07.19.02.00 Commercial Banks. Private Banks. Foreign Banks;
2.12.00.00.00 Information and informatization / 12.08.00.00 Information security, protection of the rights of subjects of information and informatization (see also 16.04.03.00));
3.16.00.00.00 Security and law enforcement / 16.04.00.00 Public security / 16.04.03.00 Information security (see also 12.08.00.00)]
automatic creation of registration records for newly hired employees working in information systems;
granting employees access rights to relevant information systems based on their job responsibilities;
ensuring that employees access information systems only within the territory of the Republic of Uzbekistan through protected communication channels, complying with information security and cybersecurity requirements;
changing, blocking, and restricting registration records (accounts) of employees when they transfer to another position, go on leave, or are dismissed.
[OKOS:
1.07.00.00.00 Legislation on Finance and Credit. Bank Activity / 07.19.00.00 Banking System / 07.19.02.00 Commercial Banks. Private Banks. Foreign Banks;
2.12.00.00.00 Information and informatization / 12.08.00.00 Information security, protection of the rights of subjects of information and informatization (see also 16.04.03.00));
3.16.00.00.00 Security and law enforcement / 16.04.00.00 Public security / 16.04.03.00 Information security (see also 12.08.00.00)]
management and continuous monitoring of the entire lifecycle of employee accounts in the bank's information systems and resources, as well as regular verification of employees' job responsibilities and powers based on data in the personnel system;
management and control of role-based access models based on the bank's organizational structure, as well as dynamic assignment of information resources (accounts associated with them, access rights, and powers in information systems) based on employee attributes and status;
automatic granting of access rights and powers corresponding to the new role through a centralized system when an employee's business role or task changes;
control over the actual access rights and powers of each information system user and identification of differences between agreed access rights;
monitoring the source of emergence of access rights and powers to any of the bank's information systems and resources (direct assignment, assignment according to role model, assignment via request) and having full information about the source of emergence and chain of powers.
[OKOS:
1.07.00.00.00 Legislation on Finance and Credit. Bank Activity / 07.19.00.00 Banking System / 07.19.02.00 Commercial Banks. Private Banks. Foreign Banks;
2.12.00.00.00 Information and informatization / 12.08.00.00 Information security, protection of the rights of subjects of information and informatization (see also 16.04.03.00));
3.16.00.00.00 Security and law enforcement / 16.04.00.00 Public security / 16.04.03.00 Information security (see also 12.08.00.00)]
date (day, month, year) and time (hour, minute, second) of the performed operation;
user identifier assigned to the user in systems and information programs;
identification information of the user's device (IP address, MAC address, device name, and other identifiers);
all operations and actions performed by the user during their active session in the system must be recorded in corresponding electronic logs. In this regard, the ability to modify or delete entries in electronic logs must be available only to Service employees authorized by the order of the Chairman of the Bank's Management.
[OKOS:
1.07.00.00.00 Legislation on Finance and Credit. Bank Activity / 07.19.00.00 Banking System / 07.19.02.00 Commercial Banks. Private Banks. Foreign Banks;
2.12.00.00.00 Information and informatization / 12.08.00.00 Information security, protection of the rights of subjects of information and informatization (see also 16.04.03.00));
3.16.00.00.00 Security and law enforcement / 16.04.00.00 Public security / 16.04.03.00 Information security (see also 12.08.00.00)]
identification and authentication of users and management of this process;
detection and restriction of failed access attempts and blocking of the user's access right (account) to the bank's information systems and resources;
termination of the work session when prolonged inactivity of the user is detected;
restriction of multi-session operation of the user account on multiple devices simultaneously during the user's work on information assets and workstations;
restriction of the user's ability to change settings (parameters) of information assets that affect the operation of these information assets;
ensuring the conduct of assessments of the state of information security and cybersecurity of the bank's information systems and resources as objects of critical information infrastructure in the manner established by legislation;
elimination of deficiencies and vulnerabilities identified during the testing of information systems and resources for compliance with cybersecurity requirements and the assessment of the state of cybersecurity.
Each user must use a dedicated hardware-software device assigned to them to access the system.
[OKOS:
1.07.00.00.00 Legislation on Finance and Credit. Bank Activity / 07.19.00.00 Banking System / 07.19.02.00 Commercial Banks. Private Banks. Foreign Banks;
2.12.00.00.00 Information and informatization / 12.08.00.00 Information security, protection of the rights of subjects of information and informatization (see also 16.04.03.00));
3.16.00.00.00 Security and law enforcement / 16.04.00.00 Public security / 16.04.03.00 Information security (see also 12.08.00.00)]
Complete information about users' access to the system, information exchange, and their actions in the remote banking services system (IP and (or) MAC address, IMEI code when using a mobile phone) must be recorded in electronic logs.
Banks must prohibit all system users from connecting to the bank system outside of permitted hours. In this regard, active sessions connected to the bank system must be terminated.
All actions of administrators of the bank's information and communication technology infrastructure, information systems and resources, and information security and cybersecurity systems must be carried out through the PAM system. In this regard, recording user actions through this system and auditing privileged sessions is required.
Banks must ensure that data recorded in the PAM system regarding user actions is stored for at least six months.
Chapter 8. Database Management System
[OKOS:
1.07.00.00.00 Legislation on Finance and Credit. Bank Activity / 07.19.00.00 Banking System / 07.19.02.00 Commercial Banks. Private Banks. Foreign Banks;
2.12.00.00.00 Information and informatization / 12.08.00.00 Information security, protection of the rights of subjects of information and informatization (see also 16.04.03.00));
3.16.00.00.00 Security and law enforcement / 16.04.00.00 Public security / 16.04.03.00 Information security (see also 12.08.00.00)]
access to the database;
use of the database's special interface, command entry, and program execution;
learning administrator and user passwords;
access to the database's system files;
installation of malware;
control over the server's application programs;
remote attack on the database and server.
[OKOS:
1.07.00.00.00 Legislation on Finance and Credit. Bank Activity / 07.19.00.00 Banking System / 07.19.02.00 Commercial Banks. Private Banks. Foreign Banks;
2.12.00.00.00 Information and informatization / 12.08.00.00 Information security, protection of the rights of subjects of information and informatization (see also 16.04.03.00));
3.16.00.00.00 Security and law enforcement / 16.04.00.00 Public security / 16.04.03.00 Information security (see also 12.08.00.00)]
The operating system, antivirus software, and other software changes of workstations and other computing equipment are launched based on the results of test trials. All software changes entered into the database must be tested on a test server first and implemented on the working server only if a positive result is achieved.
Services unnecessary for the server's work process installed in the database must be stopped, and information ports must be closed. The list of information ports used is approved by the Chairman of the Bank's Management, indicating the purpose of use.
A Database Activity Monitoring (DAM) system for monitoring database activity in real-time must be implemented in the bank to quickly detect and prevent suspicious activities.
The duties, powers, and responsibilities of the database administrator and employees ensuring information security in the database are specified by the bank's internal documents.
The database administrator's password must be no less than 12 characters, using lowercase and uppercase letters, numbers, and special characters (@, #, $, &, %, etc.) as password characters. Passwords and tokens must be stored in encrypted form in the database.
The bank must ensure that other organizations connect to the database only via web services (API). Direct connection of other organizations (DB Link) is prohibited.
Chapter 9. Network Security
[OKOS:
1.07.00.00.00 Legislation on Finance and Credit. Bank Activity / 07.19.00.00 Banking System / 07.19.02.00 Commercial Banks. Private Banks. Foreign Banks;
2.12.00.00.00 Information and informatization / 12.08.00.00 Information security, protection of the rights of subjects of information and informatization (see also 16.04.03.00));
3.16.00.00.00 Security and law enforcement / 16.04.00.00 Public security / 16.04.03.00 Information security (see also 12.08.00.00)]
Uz DSt ISO/IEC 27033-1:2016 "Information technology. Security techniques. Network security. Part 1. Overview and concepts";
Uz DSt ISO/IEC 27033-2:2016 "Information technology. Security techniques. Network security. Part 2. Guidelines for network security design and implementation";
Uz DSt ISO/IEC 27033-4:2016 "Information technology. Security techniques. Network security. Part 4. Communications for inter-network security using security gateways";
Uzbek State Standard ISO/IEC 27033-5:2016 "Information Technology. Security Techniques. Network Security. Part 5. Ensuring Inter-network Security Using Virtual Private Networks".
[OKOS:
1.07.00.00.00 Legislation on Finance and Credit. Banking Activity / 07.19.00.00 Banking System / 07.19.02.00 Commercial Banks. Private Banks. Foreign Banks;
2.12.00.00.00 Information and Informatization / 12.08.00.00 Information Security, Protection of Rights of Subjects in the Field of Information and Informatization (see also 16.04.03.00));
3.16.00.00.00 Security and Law Enforcement / 16.04.00.00 Public Security / 16.04.03.00 Information Security (see also 12.08.00.00)]
ensuring uninterrupted operation and security of telecommunications and network services in the interconnection of corporate networks and information systems;
restricting unauthorized viewing or modification of network device and software configurations and their components;
segmenting networks into separate segments;
ensuring the ability to monitor, analyze, and block cyber threats in real-time;
collecting and storing detailed information about network activity;
ensuring the ability to create honeypots and emulate them;
ensuring the ability to analyze network traffic at the level of various protocols and programs;
ensuring data confidentiality in inter-network information exchange and preventing unauthorized actions on the network.
[OKOS:
1.07.00.00.00 Legislation on Finance and Credit. Banking Activity / 07.19.00.00 Banking System / 07.19.02.00 Commercial Banks. Private Banks. Foreign Banks;
2.12.00.00.00 Information and Informatization / 12.08.00.00 Information Security, Protection of Rights of Subjects in the Field of Information and Informatization (see also 16.04.03.00));
3.16.00.00.00 Security and Law Enforcement / 16.04.00.00 Public Security / 16.04.03.00 Information Security (see also 12.08.00.00)]
When allowing non-bank computers to connect to the bank's corporate network, the following must be ensured:
connection with the permission of the bank management and in agreement with the Service;
registration of the technical parameters and identifiers of the connected device;
verification of the presence of licensed antivirus software on the connected device;
installation of a Data Loss Prevention (DLP) system on the connected device;
connection via a Privileged Access Management (PAM) system if the connected device is intended to operate in information communication infrastructure and information and cybersecurity systems;
familiarization with the procedure for handling confidential information and signing an obligation letter;
preventing connection to the internet on devices connected to the corporate network;
taking additional measures established by the bank for information and cybersecurity.
An electronic log of information exchange in the corporate network must be maintained, recording the username, time, IP and/or MAC address of the device of the user entering the system.
The diagram of the corporate network organized by banks (connecting to the Central Bank network, the Internet global information network, telecommunications providers, branches, and other networks) must be agreed upon with the Central Bank.
Full control and monitoring of corporate network security is continuously carried out by the Service.
[OKOS:
1.07.00.00.00 Legislation on Finance and Credit. Banking Activity / 07.19.00.00 Banking System / 07.19.02.00 Commercial Banks. Private Banks. Foreign Banks;
2.12.00.00.00 Information and Informatization / 12.08.00.00 Information Security, Protection of Rights of Subjects in the Field of Information and Informatization (see also 16.04.03.00));
3.16.00.00.00 Security and Law Enforcement / 16.04.00.00 Public Security / 16.04.03.00 Information Security (see also 12.08.00.00)]
A protected protocol must be used in the mutual information exchange between application servers and users in the corporate network.
Connection points of the bank's local computer network to other networks and/or external communication channels are protected by inter-network firewall devices.
Telecommunications cabinets must be locked and monitored via video surveillance systems.
Local computer network cables must not be routed in an unprotected manner from telecommunications cabinets to connection points of computing equipment, ATMs, and other devices.
All departments of the bank must be separated from each other in the local computer network by creating virtual local area networks (VLAN).
The status of software and technical tools used to ensure network security in the bank must be monitored, statistical data must be collected and analyzed, emerging problems must be identified at the initial stage, and measures must be taken to prevent emergencies based on them.
Banks must implement Network Detection and Response (NDR) systems to detect threats on the network and respond to them.
[OKOS:
1.07.00.00.00 Legislation on Finance and Credit. Banking Activity / 07.19.00.00 Banking System / 07.19.02.00 Commercial Banks. Private Banks. Foreign Banks;
2.12.00.00.00 Information and Informatization / 12.08.00.00 Information Security, Protection of Rights of Subjects in the Field of Information and Informatization (see also 16.04.03.00));
3.16.00.00.00 Security and Law Enforcement / 16.04.00.00 Public Security / 16.04.03.00 Information Security (see also 12.08.00.00)]
Banks must have the ability to detect deviations in the operation of network programs in real-time, as well as unauthorized use (unauthorized access or network attacks) on computer systems or networks. Banks ensure that the database of IDS/IPS systems is up-to-date.
IPS/IDS systems are selected and implemented based on the capacity of the interfaces of network infrastructure servers and switching equipment (routers, switches, communication lines). If telecommunications equipment is fundamentally obsolete and does not allow IPS/IDS systems to operate, such equipment must be updated.
Configurations of inter-network firewall devices must be approved and based on authorized information exchange protocols. Changes to configurations are made by the bank.
Configurations of primary and backup inter-network firewall devices must be identical and stored in an electronic archive in an up-to-date state.
Electronic logs of inter-network firewall devices and proxy servers are analyzed by the Service, and the Central Bank is notified immediately when external attacks are detected.
Chapter 10. Use of Email and Internet Network
[OKOS:
1.07.00.00.00 Legislation on Finance and Credit. Banking Activity / 07.19.00.00 Banking System / 07.19.02.00 Commercial Banks. Private Banks. Foreign Banks;
2.09.00.00.00 Entrepreneurship and Economic Activity / 09.16.00.00 Communications / 09.16.07.00 Email;
3.12.00.00.00 Information and Informatization / 12.08.00.00 Information Security, Protection of Rights of Subjects in the Field of Information and Informatization (see also 16.04.03.00));
4.16.00.00.00 Security and Law Enforcement / 16.04.00.00 Public Security / 16.04.03.00 Information Security (see also 12.08.00.00)]
The use of instant messaging systems (messengers) or programs, ensuring information protection when using the internet network and email systems by the bank, employee system access, imposing restrictions on them, liability, monitoring employee actions and system information security, are determined by the bank's internal documents.
Bank employees are prohibited from transmitting information unrelated to bank activities through the bank's email.
Information exchange between bank departments and branches is carried out through electronic document management software or the bank's internal email system.
File exchange via a common directory (FTP Server) organized using the File Transfer Protocol (FTP) and placing bank secret information on the network for free reading is prohibited.
[OKOS:
1.09.00.00.00 Entrepreneurship and Economic Activity / 09.16.00.00 Communications / 09.16.07.00 Email]
A system for checking for the presence of malicious codes in information received and sent via email (Sandbox) must be implemented. The Service monitors this system.
[OKOS:
1.07.00.00.00 Legislation on Finance and Credit. Banking Activity / 07.19.00.00 Banking System / 07.19.02.00 Commercial Banks. Private Banks. Foreign Banks;
2.09.00.00.00 Entrepreneurship and Economic Activity / 09.16.00.00 Communications / 09.16.07.00 Email]
The bank determines the procedure for using its email system and internet network through its internal documents and ensures that information sent and received via email is monitored by the Service. In this case, only authorized users may use the internet network.
Measures for information and cybersecurity must be taken when using the internet network in the bank.
Computers of users handling confidential, including bank secret and personal data, are allowed to connect to the internet network via a proxy server. In this case, connection to the internet network must be organized based on a list of business-related information resources only.
[OKOS:
1.07.00.00.00 Legislation on Finance and Credit. Banking Activity / 07.19.00.00 Banking System / 07.19.02.00 Commercial Banks. Private Banks. Foreign Banks;
2.12.00.00.00 Information and Informatization / 12.04.00.00 Informatization. Information Systems, Technologies and Tools for Their Support / 12.04.03.00 Internet Global Network;
3.12.00.00.00 Information and Informatization / 12.08.00.00 Information Security, Protection of Rights of Subjects in the Field of Information and Informatization (see also 16.04.03.00));
4.16.00.00.00 Security and Law Enforcement / 16.04.00.00 Public Security / 16.04.03.00 Information Security (see also 12.08.00.00)]
Information systems and resources connected to the bank's internet network must be protected by Intrusion Detection and Prevention Systems (IDS/IPS), Web Application Firewall (WAF), and Anti-DDoS systems.
[OKOS:
1.07.00.00.00 Legislation on Finance and Credit. Banking Activity / 07.19.00.00 Banking System / 07.19.02.00 Commercial Banks. Private Banks. Foreign Banks;
2.12.00.00.00 Information and Informatization / 12.03.00.00 Information Resources. Use of Information Resources / 12.03.03.00 Archive Fund. Archives;
3.12.00.00.00 Information and Informatization / 12.08.00.00 Information Security, Protection of Rights of Subjects in the Field of Information and Informatization (see also 16.04.03.00));
4.16.00.00.00 Security and Law Enforcement / 16.04.00.00 Public Security / 16.04.03.00 Information Security (see also 12.08.00.00)]
The procedure for using the internet network must be controlled, and bank employees' use of the internet network must be determined according to their job descriptions.
Electronic logs reflecting the login, usage time, resource name, and other information of employees using the internet network must be maintained. The Service analyzes these electronic logs.
Information protection when using the internet network is implemented by using inter-network firewall devices, proxy servers, antivirus tools, Intrusion Detection and Prevention Systems (IDS/IPS), and other information and cybersecurity systems.
Banks must ensure that modems or mobile phones are not connected to the bank's network and computers, nor are external proxy servers used when working on the internet network, and that the bank's internal local network is not organized wirelessly, and wireless information exchange systems are not used on bank computers.
[OKOS:
1.07.00.00.00 Legislation on Finance and Credit. Banking Activity / 07.19.00.00 Banking System / 07.19.02.00 Commercial Banks. Private Banks. Foreign Banks;
2.12.00.00.00 Information and Informatization / 12.08.00.00 Information Security, Protection of Rights of Subjects in the Field of Information and Informatization (see also 16.04.03.00));
3.16.00.00.00 Security and Law Enforcement / 16.04.00.00 Public Security / 16.04.03.00 Information Security (see also 12.08.00.00)]
In this case, Wi-Fi technology must be physically separated from the bank's internal local network, and the following information and cybersecurity measures must be taken:
allowing access only to the internet network via the Wi-Fi network;
customer identification;
prohibiting customer-to-customer connection (client isolation);
blocking suspicious and malicious traffic via IPS/IDS or proxy filtering;
limiting speed (QoS) and sessions to prevent DoS attacks;
storing logs (MAC, IP, date/time, guest identifier) of connections to the Wi-Fi network for at least six months;
using WPA2/WPA3-PSK or WPA2-Enterprise and mandatory traffic encryption;
prohibiting the use of unprotected open-password (unencrypted) Wi-Fi networks;
monitoring anomalous activity, scanning, attack attempts, and connection to prohibited resources in real-time;
using Wireless Intrusion Detection and Prevention Systems (WIDS/WIPS) to detect and prevent Rogue AP, Spoofing, and other attacks.
[OKOS:
1.07.00.00.00 Legislation on Finance and Credit. Banking Activity / 07.19.00.00 Banking System / 07.19.02.00 Commercial Banks. Private Banks. Foreign Banks;
2.12.00.00.00 Information and Informatization / 12.04.00.00 Informatization. Information Systems, Technologies and Tools for Their Support / 12.04.03.00 Internet Global Network;
3.12.00.00.00 Information and Informatization / 12.08.00.00 Information Security, Protection of Rights of Subjects in the Field of Information and Informatization (see also 16.04.03.00));
4.16.00.00.00 Security and Law Enforcement / 16.04.00.00 Public Security / 16.04.03.00 Information Security (see also 12.08.00.00)]
fake websites created to mimic the bank's official website (phishing copies, fake domains, page copies);
fake accounts on social networks, messengers, online marketplaces, advertising platforms, and forums;
fake applications in official mobile application stores (Google Play, App Store, etc.);
phishing or fraudulent emails and SMS messages sent in the bank's name;
cases of illegal use of the bank's trademark, logo, or domain name;
negative information aimed at losing customer trust or distracting them (fake information, fabricated news, comments written in the bank's name, etc.);
other situations related to illegal use in the bank's name.
[OKOS:
1.07.00.00.00 Legislation on Finance and Credit. Banking Activity / 07.19.00.00 Banking System / 07.19.01.00 Central Bank, its structural divisions and institutions]
If the bank identifies the above situations on external information resources on the internet network, it must notify the Central Bank and the Inspection of Information and Telecommunications within the Ministry of Digital Technologies of the Republic of Uzbekistan within one day, and announce it on its official information sources.
Chapter 11. Technical Tools Management System
[OKOS:
1.07.00.00.00 Legislation on Finance and Credit. Banking Activity / 07.19.00.00 Banking System / 07.19.02.00 Commercial Banks. Private Banks. Foreign Banks;
2.12.00.00.00 Information and Informatization / 12.08.00.00 Information Security, Protection of Rights of Subjects in the Field of Information and Informatization (see also 16.04.03.00));
3.16.00.00.00 Security and Law Enforcement / 16.04.00.00 Public Security / 16.04.03.00 Information Security (see also 12.08.00.00)]
In this case, using this system ensures that employees use only programs relevant to their work activities on computers and that computer access is protected (passwords).
The list of programs allowed for use is determined by the bank. Using programs not on the list and installing additional programs are prohibited.
The management of technical tools is carried out by the administrator, and the Service must monitor all the administrator's actions in the system.
The Service must analyze the configurations and electronic logs of the technical tools management system at least once a month and monitor the fulfillment of the requirements established in the bank's information security policy regarding the use of technical tools.
Chapter 12. Security at Endpoints
All endpoints granted the right to handle confidential information must be connected to the DLP system.
[OKOS:
1.07.00.00.00 Legislation on Finance and Credit. Banking Activity / 07.19.00.00 Banking System / 07.19.02.00 Commercial Banks. Private Banks. Foreign Banks;
2.12.00.00.00 Information and Informatization / 12.08.00.00 Information Security, Protection of Rights of Subjects in the Field of Information and Informatization (see also 16.04.03.00));
3.16.00.00.00 Security and Law Enforcement / 16.04.00.00 Public Security / 16.04.03.00 Information Security (see also 12.08.00.00)]
detect unauthorized transmission of protected information through various network channels, unauthorized copying to unregistered external carriers, unauthorized printing, and provide information to bank management about this, taking measures to prevent such negative situations in the future;
monitor the storage of protected information on servers and computers.
Control rules are determined by the bank's internal documents, and Data Loss Prevention is carried out by the Service.
Antivirus protection must be organized in banks to ensure information and cybersecurity.
The installation and operation of antivirus programs in the bank are monitored by the Service.
Banks must determine measures to be taken when a computer virus is detected, with the aim of preventing its spread through the network.
If it is detected that the bank's information infrastructure has been damaged by a computer virus, banks must report information about the origin and type of the virus to the Central Bank.
[OKOS:
1.07.00.00.00 Legislation on Finance and Credit. Banking Activity / 07.19.00.00 Banking System / 07.19.02.00 Commercial Banks. Private Banks. Foreign Banks;
2.12.00.00.00 Information and Informatization / 12.08.00.00 Information Security, Protection of Rights of Subjects in the Field of Information and Informatization (see also 16.04.03.00));
3.16.00.00.00 Security and Law Enforcement / 16.04.00.00 Public Security / 16.04.03.00 Information Security (see also 12.08.00.00)]
use licensed antivirus programs and ensure the actuality of their license validity period;
centralized management of antivirus programs;
establish daily updates of antivirus program databases;
ensure the actuality (non-obsolete nature) of the antivirus program model;
install antivirus programs on all servers, computers, ATMs, info kiosks, and other computing devices where antivirus programs can be installed.
[OKOS:
1.07.00.00.00 Legislation on Finance and Credit. Banking Activity / 07.19.00.00 Banking System / 07.19.02.00 Commercial Banks. Private Banks. Foreign Banks;
2.12.00.00.00 Information and informatization / 12.08.00.00 Information security, protection of rights of subjects of information and informatization (see also 16.04.03.00));
3.16.00.00.00 Security and law enforcement / 16.04.00.00 Public safety / 16.04.03.00 Information security (see also 12.08.00.00)]
To protect against malware and exploits, EDR (Endpoint Detection and Response) technology capable of monitoring anomalous activity must be used.
Connection to Wi-Fi networks must be prohibited to ensure security at endpoints.
Mobile devices issued by the bank for working with confidential information are managed centrally and security policies are applied to them (remote device locking, remote data deletion, etc.).
The bank must use FIM (File Integrity Monitoring) systems to immediately alert about unauthorized changes to its information assets and control the integrity of configuration files.
Chapter 13. Use of Electronic Digital Signatures and Encryption Keys
[OKOZ:
1.12.00.00.00 Information and informatization / 12.03.00.00 Information resources. Use of information resources / 12.03.02.00 Documentation of information. Electronic document circulation / 12.03.02.03 Electronic digital signature;
2.16.00.00.00 Security and law enforcement / 16.04.00.00 Public safety / 16.04.03.00 Information security (see also 12.08.00.00)]
[OKOZ:
1.12.00.00.00 Information and informatization / 12.03.00.00 Information resources. Use of information resources / 12.03.02.00 Documentation of information. Electronic document circulation / 12.03.02.03 Electronic digital signature;
2.16.00.00.00 Security and law enforcement / 16.04.00.00 Public safety / 16.04.03.00 Information security (see also 12.08.00.00)]
Banks implement requirements for the use of electronic digital signatures and encryption keys in interaction with external systems, taking into account bank risks, in a mutually agreed manner.
Electronic digital signature keys of information asset users must be recorded on special or mobile devices and protected from unauthorized copying by any means.
[OKOZ:
1.03.00.00.00 Civil legislation / 03.11.00.00 Specific types of obligations / 03.11.17.00 Settlements (see also 07.21.03.00) / 03.11.17.06 Settlements via plastic cards and electronic payment systems;
1.12.00.00.00 Information and informatization / 12.03.00.00 Information resources. Use of information resources / 12.03.02.00 Documentation of information. Electronic document circulation / 12.03.02.03 Electronic digital signature;
3.16.00.00.00 Security and law enforcement / 16.04.00.00 Public safety / 16.04.03.00 Information security (see also 12.08.00.00)]
When providing remote services, all employees entering electronic payment documents, approving them, and performing relevant operations with electronic payments must approve electronic payment documents with an electronic digital signature.
[OKOZ:
1.12.00.00.00 Information and informatization / 12.03.00.00 Information resources. Use of information resources / 12.03.02.00 Documentation of information. Electronic document circulation / 12.03.02.03 Electronic digital signature;
2.16.00.00.00 Security and law enforcement / 16.04.00.00 Public safety / 16.04.03.00 Information security (see also 12.08.00.00)]
Users' electronic digital signature public keys must be registered and accounted for in the automated banking system.
[OKOZ:
1.12.00.00.00 Information and informatization / 12.03.00.00 Information resources. Use of information resources / 12.03.02.00 Documentation of information. Electronic document circulation / 12.03.02.03 Electronic digital signature;
2.12.00.00.00 Information and informatization / 12.08.00.00 Information security, protection of rights of subjects of information and informatization (see also 16.04.03.00));
3.16.00.00.00 Security and law enforcement / 16.04.00.00 Public safety / 16.04.03.00 Information security (see also 12.08.00.00)]
surname, first name, and patronymic of the physical person who is the owner of the electronic digital signature private key;
data of the document confirming the position and identity of the employee;
personal identification number of the physical person;
public key of the electronic digital signature;
name and location address of the registration center that issued this certificate;
information about the purposes of using the electronic digital signature;
electronic address of the registry of electronic digital signature key certificates.
The creation processes of electronic digital signatures and encryption keys must be protected.
The private key of an electronic digital signature must be used only by its owner.
The use of electronic digital signature keys in the bank system is controlled by the Service.
Storing the private key of an electronic digital signature in the memory of a work computer or in external storage permanently connected to the work computer is prohibited.
Electronic payments that have not been confirmed with an electronic digital signature and have not undergone encryption are prohibited from being accepted for processing.
In case of damage, loss, or other similar situations with electronic digital signature keys issued by the Central Bank, banks apply to the Central Bank indicating the reasons for updating the electronic digital signature. Based on the application, the Central Bank updates the electronic digital signature within one day.
Chapter 14. Organization of Electronic Archives and Composition of Electronic Archive Documents
An electronic archive is organized as a structural unit of the bank archive.
The electronic archive must have its own electronic archive information system, and its information resources must be formed.
[OKOZ:
1.12.00.00.00 Information and informatization / 12.03.00.00 Information resources. Use of information resources / 12.03.03.00 Archive fund. Archives;
2.12.00.00.00 Information and informatization / 12.08.00.00 Information security, protection of rights of subjects of information and informatization (see also 16.04.03.00));
3.16.00.00.00 Security and law enforcement / 16.04.00.00 Public safety / 16.04.03.00 Information security (see also 12.08.00.00)]
collecting, accounting, storing electronic documents, and ensuring their use;
preparing archive copies of information resources and submitting them to state storage within the timeframes established by legislation;
providing methodological assistance to structural units of the bank in formalizing electronic documents;
ensuring information security and cybersecurity of the electronic archive information resource.
[OKOZ:
1.07.00.00.00 Legislation on finance and credit. Banking activity / 07.19.00.00 Banking system / 07.19.02.00 Commercial banks. Private banks. Foreign banks;
2.12.00.00.00 Information and informatization / 12.03.00.00 Information resources. Use of information resources / 12.03.03.00 Archive fund. Archives;
3.12.00.00.00 Information and informatization / 12.08.00.00 Information security, protection of rights of subjects of information and informatization (see also 16.04.03.00));
4.16.00.00.00 Security and law enforcement / 16.04.00.00 Public safety / 16.04.03.00 Information security (see also 12.08.00.00)]
the full database of electronic data of the bank's business day;
public keys of expired encryption and electronic digital signature keys;
programs of the bank's business day and other sets of separately used programs;
electronic statements of all programs related to bank information systems and resources, software and hardware devices, as well as electronic statements related to adverse events;
documents related to payments received and sent via electronic mail (orders, decisions, etc.);
all incoming and outgoing electronic payment documents in encrypted and unencrypted forms;
[OKOZ:
1.07.00.00.00 Legislation on finance and credit. Banking activity / 07.19.00.00 Banking system / 07.19.02.00 Commercial banks. Private banks. Foreign banks]
data related to credit and other banking operations of commercial banks;
management documents, personnel documents, and other data of banks.
[OKOZ:
1.07.00.00.00 Legislation on finance and credit. Banking activity / 07.19.00.00 Banking system / 07.19.02.00 Commercial banks. Private banks. Foreign banks;
2.12.00.00.00 Information and informatization / 12.03.00.00 Information resources. Use of information resources / 12.03.03.00 Archive fund. Archives;
3.12.00.00.00 Information and informatization / 12.08.00.00 Information security, protection of rights of subjects of information and informatization (see also 16.04.03.00));
4.16.00.00.00 Security and law enforcement / 16.04.00.00 Public safety / 16.04.03.00 Information security (see also 12.08.00.00)]
Banks may determine the list of data stored in the electronic archive based on their policy, existing information systems, and requirements imposed on the bank.
The information resource of the electronic archive must be transferred to external storage devices and stored in a safe or iron cabinet.
[OKOZ:
1.07.00.00.00 Legislation on finance and credit. Banking activity / 07.19.00.00 Banking system / 07.19.02.00 Commercial banks. Private banks. Foreign banks;
2.12.00.00.00 Information and informatization / 12.03.00.00 Information resources. Use of information resources / 12.03.03.00 Archive fund. Archives;
3.12.00.00.00 Information and informatization / 12.08.00.00 Information security, protection of rights of subjects of information and informatization (see also 16.04.03.00));
4.16.00.00.00 Security and law enforcement / 16.04.00.00 Public safety / 16.04.03.00 Information security (see also 12.08.00.00)]
The electronic archive must automatically form (archive) the information resource daily and record the process of writing to electronic information carriers in an electronic journal. The electronic journal must record information about the data transferred to the information resource (time, name, size, etc.) and the hash sum (control numbers) of this data to determine the integrity of the electronic archive. The responsible employee of the electronic archive records in a special notebook that these operations have been performed.
[OKOZ:
1.07.00.00.00 Legislation on finance and credit. Banking activity / 07.19.00.00 Banking system / 07.19.02.00 Commercial banks. Private banks. Foreign banks;
2.12.00.00.00 Information and informatization / 12.03.00.00 Information resources. Use of information resources / 12.03.03.00 Archive fund. Archives;
3.12.00.00.00 Information and informatization / 12.08.00.00 Information security, protection of rights of subjects of information and informatization (see also 16.04.03.00));
4.16.00.00.00 Security and law enforcement / 16.04.00.00 Public safety / 16.04.03.00 Information security (see also 12.08.00.00)]
The electronic archive checks the integrity of the data of the electronic archive's information resource at least once every six months, and the results of these checks are recorded in a special notebook. If it is found that the data of the electronic archive information resources are partially or completely damaged, the relevant data must be restored, and an act must be drawn up regarding this.
The storage period of electronic documents (electronic resources) submitted to the electronic archive must not be less than the periods established for paper-based documents.
After electronic data with permanent storage periods have been stored in the departmental archive for fifteen years, one copy must be submitted to state archives in the established order.
When the activities of a bank's branches are terminated, the information resource of the electronic archive is submitted to the bank's territorial branches or, if no territorial branches exist, to the head office of the bank in the established order. When a bank's activities are terminated and it is merged into another bank, the electronic archive data is submitted to the electronic archive of the merging bank in the established order.
When a bank's activities are terminated, the information resources of the electronic archive are submitted to the state archive.
The employee(s) of the electronic archive are personally responsible for the completeness, correct formation, and reliability of the information resources.
Chapter 15. Ensuring Continuity and Recovery of Information Asset Business Processes
[OKOZ:
1.07.00.00.00 Legislation on finance and credit. Banking activity / 07.19.00.00 Banking system / 07.19.02.00 Commercial banks. Private banks. Foreign banks;
2.12.00.00.00 Information and informatization / 12.08.00.00 Information security, protection of rights of subjects of information and informatization (see also 16.04.03.00));
3.16.00.00.00 Security and law enforcement / 16.04.00.00 Public safety / 16.04.03.00 Information security (see also 12.08.00.00)]
Banks must ensure continuity of the business process of information assets in case of interruptions, technical failures, emergencies, and situations causing significant damage, and must have taken appropriate measures in advance for this.
Requirements for ensuring the continuity of information asset business processes must be developed in the bank, including the approval of a plan for work to be performed during interruptions (for all cases). The plan must describe the actions of participating employees, and these employees must have received appropriate training.
Banks must develop procedures for restoring their information assets, backup data and relevant programs, conduct recovery tests at least twice a year, and document all work performed. The recovery plan must be drawn up taking into account all existing information systems, operating systems, and technical devices.
To restore information systems in a short time, the bank must form relevant electronic data. In this case, the recoverable data of all information systems in the bank, depending on the payment system, must be stored in an up-to-date state relative to the end of the previous day.
The list of recoverable electronic data, the time of their transfer (creation), and other details are determined by the bank.
Banks must ensure the protection of recoverable electronic data.
The bank's internal audit service must check the state of the data recovery system at least once a month and record the inspection results in its special notebook. If deficiencies are identified, an act must be drawn up regarding this.
In case of failure of technical means of information assets, banks must have a backup recovery plan, programs, and equipment to ensure uninterrupted system operation.
Servers and computers in information assets must have expert-approved or licensed programs.
[OKOZ:
1.07.00.00.00 Legislation on finance and credit. Banking activity / 07.19.00.00 Banking system / 07.19.02.00 Commercial banks. Private banks. Foreign banks;
2.12.00.00.00 Information and informatization / 12.08.00.00 Information security, protection of rights of subjects of information and informatization (see also 16.04.03.00));
3.16.00.00.00 Security and law enforcement / 16.04.00.00 Public safety / 16.04.03.00 Information security (see also 12.08.00.00)]
These centers must strictly comply with requirements for information security and cybersecurity, and taking into account the prevention of leakage of confidential information, including bank secrets, they may be organized in the bank's premises, branches, other banks, the Central Bank's cloud-based data center, or state data centers.
Banks must organize a backup data processing center in urban areas located at a distance of not less than 50 km to protect information assets from emergency situations (fire, earthquake, flood, etc.).
Chapter 16. Security Requirements for Data Processing Centers and Server Rooms Organized in Banks
[OKOZ:
1.07.00.00.00 Legislation on finance and credit. Banking activity / 07.19.00.00 Banking system / 07.19.02.00 Commercial banks. Private banks. Foreign banks;
2.12.00.00.00 Information and informatization / 12.08.00.00 Information security, protection of rights of subjects of information and informatization (see also 16.04.03.00));
3.16.00.00.00 Security and law enforcement / 16.04.00.00 Public safety / 16.04.03.00 Information security (see also 12.08.00.00)]
the provider of the data processing center must have relevant licenses and certificates (PCI DSS, ISO 27001);
compliance with Tier III or Tier IV international standards;
availability of a document establishing the service level SLA (Service Level Agreement).
The bank must implement a guaranteed power supply system for its server room. In this case, there must be two input power supplies from different electrical substations and one automatically starting diesel generator. Automatic reconnection of all three sources of electrical energy to the main (backup) feeder of the power supply must be ensured.
The parameters of electrical supply lines, the automatic diesel generator, and its automatic input must be determined based on the total power consumed by the equipment and server room systems, and the power reserve must ensure at least 10 percent of the power.
The bank must be equipped with a diesel generator with a fuel reserve sufficient for at least one day of uninterrupted operation, in which case the diesel generator must start automatically in the absence of electrical power in the bank.
[OKOZ:
1.07.00.00.00 Legislation on finance and credit. Banking activity / 07.19.00.00 Banking system / 07.19.02.00 Commercial banks. Private banks. Foreign banks;
2.12.00.00.00 Information and informatization / 12.08.00.00 Information security, protection of rights of subjects of information and informatization (see also 16.04.03.00));
3.16.00.00.00 Security and law enforcement / 16.04.00.00 Public safety / 16.04.03.00 Information security (see also 12.08.00.00)]
In this case, the power of the uninterruptible power supply (UPS) must be introduced taking into account the power of all supplied equipment and future needs. The time required for autonomous operation of the uninterruptible power supply (UPS), including switching to backup lines and the automatic diesel generator, and returning, must be taken into account.
Entry into the server room is carried out only in accordance with an approved list.
In cases where persons not included in the list of employees authorized to enter the server room need to enter, their entry must be formally documented with a justified request. This request must be reviewed and signed by the head of the information technology department and agreed upon with the head of the Service. Entry into the server room is carried out under the supervision of the server administrator.
Employees must enter the server room through a control system (biometric or other methods).
When employees of organizations servicing information assets are allowed into the server room, an entry must be made in the registration journal indicating the date and time of entry and exit, the name of the work performed, the surname, first name, position, and organization name of the performer, and the signature of this employee must be affixed.
[OKOS:
1.07.00.00.00 Legislation on Finance and Credit. Banking Activity / 07.19.00.00 Banking System / 07.19.02.00 Commercial Banks. Private Banks. Foreign Banks;
2.12.00.00.00 Information and Informatization / 12.08.00.00 Information Security, Protection of Rights of Subjects of Information and Information Processes and Informatization (see also 16.04.03.00));
3.16.00.00.00 Security and Law Enforcement / 16.04.00.00 Public Security / 16.04.03.00 Information Security (see also 12.08.00.00)]
[OKOS:
1.07.00.00.00 Legislation on Finance and Credit. Banking Activity / 07.19.00.00 Banking System / 07.19.02.00 Commercial Banks. Private Banks. Foreign Banks;
2.12.00.00.00 Information and Informatization / 12.08.00.00 Information Security, Protection of Rights of Subjects of Information and Information Processes and Informatization (see also 16.04.03.00));
3.16.00.00.00 Security and Law Enforcement / 16.04.00.00 Public Security / 16.04.03.00 Information Security (see also 12.08.00.00)]
Video surveillance devices and building (corridors, rooms) access control systems data must be isolated from the bank's local payment networks and protected from external influences, as well as have the ability to operate autonomously without dependence on electricity within 12 hours from the start of a power outage, and the video archive must be at least 2 months.
The maintenance and use of video archive data is carried out by the bank's security department.
[OKOS:
1.07.00.00.00 Legislation on Finance and Credit. Banking Activity / 07.19.00.00 Banking System / 07.19.02.00 Commercial Banks. Private Banks. Foreign Banks;
2.12.00.00.00 Information and Informatization / 12.08.00.00 Information Security, Protection of Rights of Subjects of Information and Information Processes and Informatization (see also 16.04.03.00));
3.16.00.00.00 Security and Law Enforcement / 16.04.00.00 Public Security / 16.04.03.00 Information Security (see also 12.08.00.00)]
The gas fire suppression system must be located directly in a specially equipped cabinet in the bank's server room or in a specially allocated room for this purpose.
The activation of the gas fire suppression system must be carried out by smoke detectors reporting fire, as well as manually activated detectors installed outside the room on the wall at a height of 1.5 m from the floor level.
The gas fire suppression system must have a panel notifying employees of the activation of the automatic gas fire suppression device located inside and outside the room, and a sound signaling device installed outside the room.
The gas and smoke exhaust system must ensure the removal of gas and smoke from the server room after the fire suppression system is activated. This system is implemented with a separate air duct from the building's ventilation system to the roof. The system must have the ability to remove gas-air mixture with a volume three times the volume of air in the server room.
[OKOS:
1.07.00.00.00 Legislation on Finance and Credit. Banking Activity / 07.19.00.00 Banking System / 07.19.02.00 Commercial Banks. Private Banks. Foreign Banks;
2.12.00.00.00 Information and Informatization / 12.08.00.00 Information Security, Protection of Rights of Subjects of Information and Information Processes and Informatization (see also 16.04.03.00));
3.16.00.00.00 Security and Law Enforcement / 16.04.00.00 Public Security / 16.04.03.00 Information Security (see also 12.08.00.00)]
a) The following climate conditions must be observed in the server room:
b) The server room air cooling system is implemented using 100 percent redundancy (at least two independent air conditioners, each capable of independently maintaining the air regime in the room);
c) The cooling system must provide the ability to perform remote monitoring.
Chapter 17. Requirements for ensuring information security and cybersecurity in the exchange of information between the bank and external information systems
[OKOS:
1.07.00.00.00 Legislation on Finance and Credit. Banking Activity / 07.19.00.00 Banking System / 07.19.02.00 Commercial Banks. Private Banks. Foreign Banks;
2.12.00.00.00 Information and Informatization / 12.08.00.00 Information Security, Protection of Rights of Subjects of Information and Information Processes and Informatization (see also 16.04.03.00));
3.16.00.00.00 Security and Law Enforcement / 16.04.00.00 Public Security / 16.04.03.00 Information Security (see also 12.08.00.00)]
[OKOS:
1.12.00.00.00 Information and Informatization / 12.03.00.00 Information Resources. Use of Information Resources / 12.03.05.00 Information with Limited Use / 12.03.05.03 Bank Secret (see also 07.21.16.00)]
[OKOS:
1.07.00.00.00 Legislation on Finance and Credit. Banking Activity / 07.19.00.00 Banking System / 07.19.01.00 Central Bank, its structural divisions and institutions]
Before starting information exchange with the external information system, the bank must notify the Central Bank and carry out information exchange in compliance with the Central Bank's information protection requirements.
Chapter 18. Ensuring security in working with third parties
[OKOS:
1.07.00.00.00 Legislation on Finance and Credit. Banking Activity / 07.19.00.00 Banking System / 07.19.02.00 Commercial Banks. Private Banks. Foreign Banks;
2.12.00.00.00 Information and Informatization / 12.08.00.00 Information Security, Protection of Rights of Subjects of Information and Information Processes and Informatization (see also 16.04.03.00));
3.16.00.00.00 Security and Law Enforcement / 16.04.00.00 Public Security / 16.04.03.00 Information Security (see also 12.08.00.00)]
Chapter 19. Ensuring security when remotely connecting to the bank's information assets
[OKOS:
1.07.00.00.00 Legislation on Finance and Credit. Banking Activity / 07.19.00.00 Banking System / 07.19.02.00 Commercial Banks. Private Banks. Foreign Banks;
2.12.00.00.00 Information and Informatization / 12.08.00.00 Information Security, Protection of Rights of Subjects of Information and Information Processes and Informatization (see also 16.04.03.00));
3.16.00.00.00 Security and Law Enforcement / 16.04.00.00 Public Security / 16.04.03.00 Information Security (see also 12.08.00.00)]
Chapter 20. Management of vulnerabilities and configurations
[OKOS:
1.07.00.00.00 Legislation on Finance and Credit. Banking Activity / 07.19.00.00 Banking System / 07.19.02.00 Commercial Banks. Private Banks. Foreign Banks;
2.12.00.00.00 Information and Informatization / 12.08.00.00 Information Security, Protection of Rights of Subjects of Information and Information Processes and Informatization (see also 16.04.03.00));
3.16.00.00.00 Security and Law Enforcement / 16.04.00.00 Public Security / 16.04.03.00 Information Security (see also 12.08.00.00)]
[OKOS:
1.07.00.00.00 Legislation on Finance and Credit. Banking Activity / 07.19.00.00 Banking System / 07.19.02.00 Commercial Banks. Private Banks. Foreign Banks;
2.12.00.00.00 Information and Informatization / 12.08.00.00 Information Security, Protection of Rights of Subjects of Information and Information Processes and Informatization (see also 16.04.03.00));
3.16.00.00.00 Security and Law Enforcement / 16.04.00.00 Public Security / 16.04.03.00 Information Security (see also 12.08.00.00)]
Chapter 21. Ensuring information security and cybersecurity in the life cycle stages of the bank's information systems and resources
[OKOS:
1.07.00.00.00 Legislation on Finance and Credit. Banking Activity / 07.19.00.00 Banking System / 07.19.02.00 Commercial Banks. Private Banks. Foreign Banks;
2.12.00.00.00 Information and Informatization / 12.08.00.00 Information Security, Protection of Rights of Subjects of Information and Information Processes and Informatization (see also 16.04.03.00));
3.16.00.00.00 Security and Law Enforcement / 16.04.00.00 Public Security / 16.04.03.00 Information Security (see also 12.08.00.00)]
When the information system is developed independently, the compliance of the information system's information security and cybersecurity requirements must be reviewed at all stages of the life cycle model.
When purchasing a ready-made information system, the compliance of the information system's information security and cybersecurity requirements must be ensured at the following stages of the life cycle model:
Information systems must be designed and developed taking into account cybersecurity risks.
Issues related to ensuring information security and cybersecurity at all stages of the information system life cycle are carried out in agreement with and under the supervision of the Service.
[OKOS:
1.07.00.00.00 Legislation on Finance and Credit. Banking Activity / 07.19.00.00 Banking System / 07.19.02.00 Commercial Banks. Private Banks. Foreign Banks;
2.12.00.00.00 Information and Informatization / 12.08.00.00 Information Security, Protection of Rights of Subjects of Information and Information Processes and Informatization (see also 16.04.03.00));
3.16.00.00.00 Security and Law Enforcement / 16.04.00.00 Public Security / 16.04.03.00 Information Security (see also 12.08.00.00)]
The use of confidential information, including bank secret data, is prohibited during the creation and testing stages of the information system and (or) its components.
Only local (on-premise) versions of software lifecycle management platforms (such as Gitlab) are allowed in the bank. In this case, the code in the platform must be automatically analyzed (SAST/DAST).
Connecting the bank's software lifecycle management platforms to the internet network is prohibited.
Remote connection to the bank's software lifecycle management platforms is allowed only through a protected VPN network.
Documents containing a description of the protection measures implemented in the information system and (or) its components in use must be present in the bank.
[OKOS:
1.07.00.00.00 Legislation on Finance and Credit. Banking Activity / 07.19.00.00 Banking System / 07.19.02.00 Commercial Banks. Private Banks. Foreign Banks;
2.12.00.00.00 Information and Informatization / 12.08.00.00 Information Security, Protection of Rights of Subjects of Information and Information Processes and Informatization (see also 16.04.03.00));
3.16.00.00.00 Security and Law Enforcement / 16.04.00.00 Public Security / 16.04.03.00 Information Security (see also 12.08.00.00)]
Banks may analyze the protection measures implemented in information systems developed by software developers and establish additional requirements if necessary.
Banks must include terms for technical support for the entire service life of the information system in contracts with organizations developing information systems or delivering ready-made information systems. If these terms are not specified in the contract, the bank must obtain a set of documents from the provider that allow supporting the information system and its components without its participation.
[OKOS:
1.07.00.00.00 Legislation on Finance and Credit. Banking Activity / 07.19.00.00 Banking System / 07.19.02.00 Commercial Banks. Private Banks. Foreign Banks;
2.12.00.00.00 Information and Informatization / 12.08.00.00 Information Security, Protection of Rights of Subjects of Information and Information Processes and Informatization (see also 16.04.03.00));
3.16.00.00.00 Security and Law Enforcement / 16.04.00.00 Public Security / 16.04.03.00 Information Security (see also 12.08.00.00)]
[OKOS:
1.07.00.00.00 Legislation on Finance and Credit. Banking Activity / 07.19.00.00 Banking System / 07.19.02.00 Commercial Banks. Private Banks. Foreign Banks;
2.12.00.00.00 Information and Informatization / 12.08.00.00 Information Security, Protection of Rights of Subjects of Information and Information Processes and Informatization (see also 16.04.03.00));
3.16.00.00.00 Security and Law Enforcement / 16.04.00.00 Public Security / 16.04.03.00 Information Security (see also 12.08.00.00)]
Procedures for controlling the composition of software installed and (or) used during the use of the information system must be established, performed, and registered.
Procedures necessary for ensuring the security of devices storing confidential information, including bank secret data, during the use of the information system must be identified, performed, and controlled.
During the decommissioning of the information system, information that may harm bank activities is deleted from the permanent memory of information systems and external carriers using algorithms and (or) methods that exclude the possibility of restoring information using technical protection measures, except for electronic document archives and protocols (logs) that are intended to be stored for periods established by legislation and contractual documents.
Chapter 22. Requirements for ensuring information security and cybersecurity when using data center services
[OKOS:
1.07.00.00.00 Legislation on Finance and Credit. Banking Activity / 07.19.00.00 Banking System / 07.19.02.00 Commercial Banks. Private Banks. Foreign Banks;
2.12.00.00.00 Information and Informatization / 12.08.00.00 Information Security, Protection of Rights of Subjects of Information and Information Processes and Informatization (see also 16.04.03.00));
3.16.00.00.00 Security and Law Enforcement / 16.04.00.00 Public Security / 16.04.03.00 Information Security (see also 12.08.00.00)]
Data centers must regularly conduct training for their employees on ensuring information security and cybersecurity.
Data center administrators must carry out all changes through the PAM system in coordination with the bank.
Data centers must be protected by hardware and software tools of modern next-generation inter-network firewalls.
Data centers are required to connect the information security and cybersecurity assurance systems of banks' data processing centers to the monitoring system of the Central Bank "CERT-CBU" cybersecurity center.
When locating their backup data processing centers at data centers, banks must provide for the obligation to ensure information security and cybersecurity.
Banks must promptly notify the Central Bank if the location address of their data processing centers has changed.
Chapter 23. Supervision over Compliance with Requirements for Ensuring Information Security and Cybersecurity
A bank may use the services of external organizations and conduct internal audits to determine the level of assurance of information security and cybersecurity.
External organization services may be carried out in the form of audit or expertise. The bank must develop an internal document regarding the submission of confidential, including bank secret, data to organizations conducting audit or expertise work. In this case, such data must be provided on the basis of a relevant contract.
The Head Office's Service must carry out constant supervision over the compliance with the requirements of this Regulation at the bank and its branches.
Chapter 24. Final Provisions
Resolution No. 19/1-1 dated August 1, 2025 of the Management Board of the Central Bank of the Republic of Uzbekistan
Appendix 2
LIST OF DEPARTMENTAL NORMATIVE LEGAL DOCUMENTS BEING DECLARED INVALID
Resolution No. 2/4-1 dated January 25, 2020 of the Management Board of the Central Bank of the Republic of Uzbekistan "On Approval of the Regulation on Protecting Information in Automated Banking Systems of Commercial Banks of the Republic of Uzbekistan" (registry number 3224, March 10, 2020) (National Database of Legal Acts, March 10, 2020, No. 10/20/3224/0312).
Resolution No. 12/3-1 dated May 28, 2021 of the Management Board of the Central Bank of the Republic of Uzbekistan "On Amending Paragraph 1 of the Regulation on Protecting Information in Automated Banking Systems of Commercial Banks of the Republic of Uzbekistan" (registry number 3224-1, June 17, 2021) (June 17, 2021, No. 10/21/3224-1/0567).
Resolution No. 1/13-1 dated January 21, 2023 of the Management Board of the Central Bank of the Republic of Uzbekistan "On Amending the Regulation on Protecting Information in Automated Banking Systems of Commercial Banks of the Republic of Uzbekistan" (registry number 3224-2, January 31, 2023) (February 1, 2023, No. 10/23/3224-2/0064).
(August 19, 2025, No. 10/25/3669/0747)
Read the rest free
Source: Central Bank of the Republic of Uzbekistan — original document · Summary generated with machine assistance and reviewed before publication; the authoritative text is the regulator's original document. How RegAlert works
More like this from CBU
We email you every new CBU publication the day it's published.