2006-04-04 | ЎРҚ-30

Added · Updated

On the Protection of Information in Automated Banking Systems

The Law regulates relations concerning the protection of information in automated banking systems, defining the system as an information system for collecting, storing, searching, processing, and using information in banking activities. It mandates that banks and the Central Bank establish information protection services, ensure the security of information systems and cybersecurity, and protect bank secrets from unauthorized access, loss, or distortion. The law requires the use of certified technical means, specifies the obligations of the system owner to coordinate with information owners and users, and establishes liability for violations of these protection rules.

Central Bank of the Republic of Uzbekistan logo

Uzbekistan

Central Bank of the Republic of Uzbekistan

Click to view thumbnail

Law of the Republic of Uzbekistan

ON THE PROTECTION OF INFORMATION IN AUTOMATED BANKING SYSTEMS

Adopted by the Legislative Chamber on November 16, 2005 Approved by the Senate on February 24, 2006

Article 1. Purpose of this Law The purpose of this Law is to regulate relations in the field of protection of information in automated banking systems.

Article 2. Legislation on the Protection of Information in Automated Banking Systems Legislation on the protection of information in automated banking systems consists of this Law and other legislative acts.

If the rules established by an international treaty of the Republic of Uzbekistan differ from the legislation of the Republic of Uzbekistan on the protection of information in automated banking systems, the rules of the international treaty shall apply.

Article 3. Automated Banking System An automated banking system is an information system designed to collect, store, search, process, and use information in the field of banking activities.

Article 4. Purposes of Protection of Information in Automated Banking Systems Protection of information in automated banking systems is carried out for the following purposes:

  • ensuring the information security and cybersecurity of banks' information systems and resources, and protecting bank secrets;
  • preventing the dissemination, theft, loss, distortion, blocking, falsification, and unauthorized use of information in a different manner, as well as copying and other forms of interference with the automated banking system.

Article 5. Organization of Protection of Information in Automated Banking Systems Organization of protection of information in automated banking systems:

  • involves developing and complying with rules for protecting information, ensuring the information security and cybersecurity of information systems and resources, and monitoring the implementation of measures aimed at protecting information processed in the automated banking system;
  • involves the use of certified technical means and information protection tools;
  • involves organizing an information protection service in the automated banking system;
  • is carried out by coordinating activities related to the collection of information in the automated banking system and the use of processing methods.

Article 6. Use of Information in Automated Banking Systems A user of an automated banking system uses information in the automated banking system with the permission of the owner of the information in the automated banking system.

Use of information in an automated banking system without the permission of the owner of the information is permitted only in cases provided for by law.

Article 7. Owner of an Automated Banking System The owner of an automated banking system must be a legal entity. The owner of an automated banking system coordinates the mutual relations between the owner of the information and the user of the automated banking system. The owner of an automated banking system must inform the owner of the information and the user of the automated banking system about the specific features of the methods of processing information in the automated banking system, and the owner of the information and the user of the automated banking system must confirm their agreement with the application of the proposed processing methods and the absence of objections. The owner of an automated banking system must ensure the protection of information in accordance with the rules established by the Central Bank of the Republic of Uzbekistan and must inform the owner of the information about all cases of violation of the protection of their information. The owner of an automated banking system must ensure the protection of information containing state secrets or considered confidential in the manner established by the Cabinet of Ministers of the Republic of Uzbekistan.

Article 8. Certification of Technical Means in Automated Banking Systems Certification of technical means in automated banking systems, as well as protection means (including cryptographic means) processing information containing state secrets or considered confidential in this system, is carried out in accordance with the legislation.

Article 9. Information Protection Service in Automated Banking Systems An information protection service in automated banking systems must be established in the Central Bank of the Republic of Uzbekistan and in banks. The information protection service in automated banking systems:

  • organizes control over the storage of information;
  • provides methodological and practical assistance on information protection issues;
  • participates in the design, testing, and acceptance of the information protection system in the automated banking system;
  • takes measures to protect information in this system if attempts to use information without permission, interference with it in a different manner, or violations of the system's operating rules are detected;
  • analyzes the status and effectiveness of information protection measures;
  • exercises other powers in accordance with the legislation.

Article 10. Resolution of Disputes Disputes in the field of protection of information in automated banking systems are resolved in the manner established by legislation.

Article 11. Liability for Violation of Legislation on the Protection of Information in Automated Banking Systems Persons found guilty of violating the legislation on the protection of information in automated banking systems are liable in the established manner.

Article 12. Entry into Force of this Law This Law enters into force from the date of its official publication.

More like this from CBU

CBU published 1 document in the last 30 days. We email you each new one the day it's published.

Topics
Share