2000-03-20 | 461Added · Updated
The Regulation establishes the main objectives, tasks, and organizational framework for antivirus protection within the automated banking systems of the Republic of Uzbekistan. It mandates that banks implement both individual and centralized antivirus measures, including the use of licensed or certified tools, regular updates, and scheduled inspections of servers and external storage. The document defines the roles and responsibilities of antivirus specialists, IT administrators, and bank management, requiring the creation of annual action plans and incident reporting protocols. It further specifies that violations of these requirements result in liability under current legislation.
Regulation of the Board of the Central Bank of the Republic of Uzbekistan, registered on 10.03.2000, registration number 910
Date of Entry into Force
20.03.2000
All
10.03.2020
10.04.2018
20.03.2000
View
Russian Uzbek Uzb Uzb|Russian
Document lost its force 10.03.2020
[ OKOZ: 1. 07.00.00.00 Legislation on Finance and Credit. Banking Activity / 07.21.00.00 Banking Activity / 07.21.21.00 Other Issues of Banking Activity; 2. 12.00.00.00 Information and Informatization / 12.08.00.00 Information Security, Protection of Rights of Subjects of Information and Informatization (see also 16.04.03.00))] [ TSZ: 1. Economy / Information and Informatization. Electronic Commerce (Document Circulation); 2. Finance / Banks and Other Credit Institutions. Credits]
Republic of Uzbekistan
Board of the Central Bank of the Republic of Uzbekistan
Approved by Resolution No. 461 dated February 5, 2000
Agreed by State Committee of Science and Technology
Regulations on Antivirus Protection in Automated Banking Systems of the Republic of Uzbekistan
[Registered by the Ministry of Justice of the Republic of Uzbekistan on March 10, 2000, registration number 910]
This Regulation has lost its force based on Resolution No. 2/4 dated January 25, 2020 of the Board of the Central Bank of the Republic of Uzbekistan "On Approval of the Regulation on Protection of Information in Automated Banking Systems of Commercial Banks of the Republic of Uzbekistan" (registration number 3224, 10.03.2020).
1.1. These Regulations are developed on the basis of the Laws of the Republic of Uzbekistan "On the Central Bank of the Republic of Uzbekistan", "On Banks and Banking Activity", "On Informatization", and other regulatory documents related to banking activity.
1.2. The Regulation defines the main purpose, tasks, organization of work, and liability of persons regarding antivirus protection in the banking system of the Republic of Uzbekistan.
1.3. The main purpose of work carried out on antivirus protection is to prevent the loss of information in the automated banking system.
1.4. The tasks of antivirus protection include:
defining the composition of antivirus diagnostic tools and the procedures for their use, inspection, and update;
carrying out preventive work using antivirus diagnostic tools;
ensuring continuous protection of information from the effects of malicious programs at all stages of using the automated banking system.
2.1. Computer virus is a program (set of executable codes) that has destructive properties, the ability to reproduce itself (possibly not fully matching the original copy), and the ability to introduce itself into computer systems, networks, and various resources without the user's knowledge. In this case, the copies themselves also acquire the property of further dissemination.
2.2. Antivirus program is a program that finds, neutralizes, and deletes computer viruses in computer systems, network resources, etc.
2.3. Antivirus protection is a set of measures aimed at preventing the effects of computer viruses, finding viruses, and neutralizing them using antivirus programs.
2.4. Participants in work on antivirus protection are users of personal computers, specialists engaged in antivirus protection, and administrators of information computing networks (ICN).
3.1. Bank management ensures the organization of work on antivirus protection.
3.2. In banks, planning and implementation of measures on antivirus protection are carried out by specialists specially assigned for these tasks in the informatization departments, and in the Central Bank of the Republic of Uzbekistan (hereinafter referred to as the Central Bank), specialists of the Payment Systems and Information Technologies Department and the Security and Information Protection Department are engaged. If necessary, specialists of the State Unitary Enterprise "Informatization Main Center" of the Republic of Uzbekistan may be involved.
3.3. The bank must have licensed tools for information antivirus protection or other antivirus protection tools that have been certified by authorized state bodies.
3.4. All measures on antivirus protection are carried out individually and in a centralized manner. Individual measures are carried out by each user, and centralized measures are carried out by antivirus protection specialists and ICN administrators.
3.5. Individual measures consist of checking the state of the operating system and its elements when the computer is started, as well as during the operation of the computer if necessary. Antivirus protection tools are installed and updated in a centralized manner at least once a month by antivirus protection specialists based on the action plan. Subsequently, the installation and update of antivirus protection tools are recorded in the registry. Specialists in antivirus protection are responsible for ensuring that the installed antivirus program at workplaces is up to date.
3.6. Centralized measures include preventive work on antivirus protection for the server of the bank's automated system, inspection of selected personal computers, and scheduled inspection of archives installed on external carriers.
3.7. Preventive inspection work on antivirus protection for shared servers is carried out by antivirus protection specialists in coordination with ICN administrators. The period of their implementation must coincide with the period of creating long-term archives, but these works must be carried out at least once a week. Updating antivirus protection databases is the responsibility of antivirus protection specialists.
3.8. Scheduled inspection of archives stored on external carriers is carried out by antivirus protection specialists together with ICN administrators based on an approved schedule.
3.9. Inspection of selected individual computers is carried out by antivirus protection specialists. The results of the conducted inspection are recorded in a special notebook. When a computer virus is detected, the antivirus protection specialist takes all measures to eliminate the viruses and draws up a report on the work performed, lost information, and approximate causes of the virus appearance. This report is signed by the employee using the computer, the antivirus protection specialist, the head of the department to which the computer is assigned, and the head of the information security service of the bank. The head of the information security service of the bank conducts a service inspection on the causes of the computer virus appearance and takes appropriate corrective measures in the established procedure.
3.10. When the presence of a computer virus is detected in bank departments, urgent information about the origin and type of the virus must be provided to the Main Directorates of the Central Bank in the Karakalpakstan Republic, regions, and the city of Tashkent.
3.11. Measures on antivirus protection are implemented based on the following documents:
action plan for measures on antivirus protection;
rules for individual measures on antivirus protection;
methodology for centralized implementation of antivirus protection;
job descriptions of participants in work on antivirus protection.
These documents are drawn up independently by each commercial bank and are coordinated with the Information Security Department of the Security and Information Protection Department of the Central Bank in the part of information exchange with the Central Bank's technical and software complexes.
3.12. The action plan is developed annually. This plan must include: preventive work, selected inspections, preparation of reports, and measures for distributing antivirus protection tools in the bank.
4.1. The job description of an antivirus protection specialist must reflect the requirements for the specialist, namely, knowledge of special antivirus protection technologies and experience in working with antivirus protection tools.
4.2. The job description of an ICN administrator must specify tasks for the centralized implementation of antivirus protection.
5.1. Participants in work on antivirus protection who violate the requirements of these Regulations are held liable in accordance with current legislation.
Deputy Chairman Sh.Y. PULATOV
More like this from CBU
We email you every new CBU publication the day it's published.