2019-03-22 | 56/04Added · Updated
The National Bank of Georgia mandates that all commercial banks and branches of non-resident foreign banks operating in Georgia establish a cybersecurity management framework commensurate with their size and complexity. The framework must integrate five primary functions: risk identification, protection, discovery, response, and restoration, with specific requirements for asset management, access control, data protection, and incident handling. Banks are required to conduct annual cybersecurity training for all employees, perform annual penetration tests on network-connected systems, and complete an annual independent audit of the entire framework. This decree entered into force on April 1, 2019.
Get NBG alerts — same-day email on every new publication.
Regulation of the National Bank of Georgia on Cybersecurity Management Framework of Commercial Banks Approved by Decree N. 56/04 of March 22, 2019 of the Governor of the National Bank of Georgia On the Approval of the Cybersecurity Management Framework of Commercial Bank According to Article 15 of the Organic Law of Georgia regarding “The National Bank of Georgia”, I hereby state the following:
Article 1.
Approve the Cybersecurity Management Framework of Commercial Banks with the following text.
Article 2.
This Decree shall go into force on April 1, 2019.
Governor of the National Bank of Georgia Koba Gvenetadze Requirements for the Establishment of a Cybersecurity Management Framework by Commercial Banks
Article 1. General Provisions
e. Restoration – The development and establishment of a plan for formal restoration after the occurrence of cyber security events.
Article 3. Identification
Commercial banks must create and implement a cybersecurity risk (cyber-risk) identification process that includes the following components:
a) Asset management, which comprises of:
a. The full accounting of physical equipment, hardware and information systems of the organization; b. The full accounting of the software and potential other information systems being used by the organization.
c. The Establishment and identification of communication channels and information flows
existing within the organization; d. The establishment of a catalog of external information systems used by the organization; e. A formalized system that includes the classification of existing resources in the bank, according to criticality and business priority. f. The establishment of roles and responsibilities of all employees of the organization in a clear and understandable way in terms of cybersecurity risk management. g. In relationships with third parties, the determination of the roles and responsibilities in an understandable and clear manner, in relation to the organization’s suppliers and clients. a. The Business Environment, which includes the following:
i. Determining the role of the organization in the country’s critical infrastructure (if
any);
ii. Determining the role of cybersecurity within the organization's mission, aims and
activities;
iii. Determining attitudes and functions within the delivery of critical services /
processes;
iv. Providing high level of business continuity within the scope of critical service
delivery. b. Management:
i. The organization should have an information security policy;
ii. Within the extent of information security, all the roles and responsibilities should be
defined and in compliance with the internal roles of employees in the organization. This also applies to external parties that are connected to the organization;
iii. The legal and regulatory requirements of the organization in the field of cyber
security, In terms of civil liberties and identity protection;
iv. Executive management and risk management processes of the organization should
include cybersecurity risk (cyber-risk).
c. Cybersecurity Risk Assessment:
i. The organization's information assets should be formally identified;
ii. The bank should receive information on threats and weaknesses from different
forums and sources of exchange of information;
iii. Internal and external threats must be formally identified;
iv. The potential impact of cyber security events on the organization should be
identified;
v. The organization should use a specific methodology in order to identify the threats,
weaknesses, probabilities, and impact to determine the cybersecurity risk;
vi. Bank's risk tolerance and appetite should be in line with the role and importance of
the bank in critical infrastructure (if such a role has been established).
Article 4. Protection
v. The Bank should have a mechanism for checking the software, data / information
integrity;
vi. Software development and testing environments should be separated from each
other. d. Information security processes and procedures:
i. Baseline configuration of information technology should be created and maintained
by the Bank;
ii. Systems development lifecycle should be implemented;
iii. The organization should have a formal mechanism / process for managing the
configuration of systems;
iv. The organization must have formal mechanisms for data / information backup /
storage, which includes testing of the information restoration process;
v. Data in the bank should be destroyed according to the Bank's relevant policies;
vi. The process of protecting the information assets of the bank must be constantly
improved;
vii. The efficiency of defensive technologies should be analyzed regularly;
viii. The Bank shall have an incident response plan;
ix. The Bank shall conduct regular testing of the Incident Response Plan;
x. The bank should develop and implement a vulnerability management plan.
e. Maintenance:
i. The Bank shall be responsible for the timely maintenance and repair of
organizational assets, which are performed and logged with approved and controlled tools;
ii. Remote management / maintenance of the bank's information assets shall be
formally approved, recorded and executed so that unauthorized access is restricted; f. Protective technologies
i. The Bank shall have a formal mechanism for accounting and keeping an audit trail,
which corresponds to the Bank's policy;
ii. Portable equipment must be protected and their use in the bank should be limited
to the Bank's policy;
iii. Access to organization's systems and assets must be formally controlled,
incorporating the principle of least privilege access;
iv. The bank's communication and management network should be protected.
Article 5. Discovery
iv. The Bank shall have an incident warning mechanism, with appropriate risk
indicators and other metrics:
b. Detection processes
i. The Bank should have clear roles and responsibilities related to the discovery of
cybersecurity events;
ii. Testing of event detection processes (relevant controls) should be performed;
iii. Information relating to the discovery of specific events should be communicated to
the relevant persons and agencies;
iv. The constant improvement of the process of discovering the events of the
organization shall be performed.
Article 6. Response
Article 7. Restoration
Read the rest free
Source: National Bank of Georgia — original document · Summary generated with machine assistance and reviewed before publication; the authoritative text is the regulator's original document. How RegAlert works
More like this from NBG
We email you every new NBG publication the day it's published.