2016-03-03

Added · Updated

PSD Circular No. 02: To ensure appropriate Cyber Security Protection for Financial sector

The Payment Systems Department of Bangladesh Bank advises all scheduled banks operating in Bangladesh to implement specific cyber security measures, including establishing cyber security governance, conducting comprehensive risk assessments, and deploying 24/7 Security Operations Centers. The circular mandates the adoption of advanced authentication methods such as EMV certificates and one-time passwords, requires the collection and retention of logs for all perimeter and core devices for three months, and calls for staff training and public awareness campaigns. These preventive actions are to be implemented immediately to mitigate risks from organized cyber attacks targeting the digital financial infrastructure.

Bangladesh Bank logo

Bangladesh

Bangladesh Bank

Click to view thumbnail

Payment Systems Department Bangladesh Bank Head Office Dhaka PSD Circular No: 02/2016 Date: ------------------- 20 Falgun, 1422

Managing Director / Chief Executive Officer All Scheduled Banks operating in Bangladesh

Dear Sir,

Regarding appropriate Cyber Security Protection for the Financial Sector.

On one hand, the financial system itself is becoming modern and digital; on the other hand, organized criminal groups are continuously launching more efficient cyber attacks targeting the financial system. Without adequate preparation against new and emerging technological attacks such as Zero-Day and Advanced Persistent Threats (APT), cyber attacks may cause financial losses and damage to Bangladesh. In fact, cyber attackers can be any individual, any organized group, or even foreign institutions. In this changing situation, it is advised that all financial institutions take the following preventive measures seriously:

  1. Implement Cyber Security Governance under the supervision of the Board of Directors;
  2. Conduct comprehensive Cyber Security Risk Assessment;
  3. Conduct Technical Vulnerability Assessment and develop Disaster Recovery Plans;
  4. Develop plans to counter any cyber or technical attacks;
  5. Develop plans to counter risks associated with services obtained through third parties;
  6. Conduct awareness and training programs on cyber security for all employees;
  7. Take initiatives to increase public awareness regarding transactions through Information Technology;
  8. Establish a 24/7 Security Operations Center (SOC) for continuous monitoring of the entire system;
  9. Obtain EMV certification for service provision through Magnetic Stripe Cards, issue Chip and PIN-based cards, and take initiatives to provide One-Time Passwords (OTP);
  10. Collect and retain logs of all perimeter and core devices, web servers, and mission-critical servers for the last three months.

This advice will be implemented immediately.

(Md. Iskander Mia) General Manager Phone: 9530174

More like this from BB

BB published 33 documents in the last 30 days. We email you each new one the day it's published.

Topics
Share